Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
Caffeinated Risk

Caffeinated Risk

McCreight & Leece

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.
bookmark
Share icon

All episodes

Best episodes

Seasons

Top 10 Caffeinated Risk Episodes

Goodpods has curated a list of the 10 best Caffeinated Risk episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to Caffeinated Risk for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite Caffeinated Risk episode by adding your comments to the episode page.

Serial entrepreneur, author and futurist Scott Klososky explores some new approaches to physical and cyber security that are innovative, potentially controversial and necessary as more and more of our daily way of life is affected by these security problems.
Ten years before Youtube Mr. Klososky founded a startup that delivered webcasted media for commercial, government, sports and entertainment. Scott has consistently demonstrated the ability to identify market opportunities and technology trends well in advance. Following the success of Webcasts.com with a second generation online banking platform that enabled smaller financial companies to compete head to head with the majors.
Today Scott Kolosky supports business leaders and boards by merging hard won success in technology with forward looking analysis to create concepts and models needed in today's hyper competitive markets. Whether those needs are the fusion of humans and technology within an organization, data intelligence or risk management and the development of an integrated security model.

bookmark
plus icon
share episode

Realtors have long advocated "location, location, location" as a path to investment success. Fast forwarding a few generations, location intelligence applied to risk management is paying dividends well beyond real-estate and Esri is a world leader in this fascinating application of geo-spatial information. Esri business solutions leader Alex Martonik shares examples of businesses making improvements to resilience and the bottom line by combining GIS, financial, technological and political data into risk calculations. Mr. Martonik also shares Esri's approach to "democratizing risk insights", helping solve the all to common problem of procuring buy-in.

bookmark
plus icon
share episode
Caffeinated Risk - Infrastructure Resilience and Ethical Considerations
play

07/21/22 • 31 min

Recorded two days after the July 2022 nationwide telecom outage, co-hosts Tim and Doug explore the deeper ramifications of losing access to the very services that are so tightly integrated into our lifestyle. While the complete root cause of the Rogers' outage may never be publicly shared, most organizations face similar constraints, leading to a discussion about ethics and our shared commitment to the common good.
Documents referenced in the show:
ACM Code of Ethics
Energy sector asset management

bookmark
plus icon
share episode

Technological change is inevitable and often one of the aspects that attracts people toward careers in information and operational technology. Although risk management is a part of navigating advancement in any area, the fundamental flaw in any management system is our human tendencies.
This episode explores how organizations can make slow, steady migration from first principles to risky undertakings without noticing. Marco Ayala, an operational technology cybersecurity expert and current Houston InfraGard president, joins this episode to further explore the reasons behind this normalization of deviance, a concept first introduced to OT cyber specialists at S4 in 2024.
Mr. Ayala is also CCE proponent and facilitator leading to a discussion on possible options for course correction back off the normalization path. Although solutions must always be tailored to work within organizational constraints, the early contributors to catastrophic outcomes associated with the Challenger space shuttle and Boeing 737 Max warrant exploration or we will inevitably repeat.

bookmark
plus icon
share episode

Whether it's the NIST CSF, 8276 or the new European Cyber Resilience Act there is no denying the expectation that supply chain management (SCM) is a risk management area no organization can ignore. While SolarWinds is recent common reference in many SCM discussions, this episode's guest takes us back to Target's major data breach that resulted in significant changes to the PCI-DSS standard.
Darren Gallop, a serially successful Canadian tech entrepreneur, recounts the early journey into the software as a service business up to his current role as CEO of Carbide. The episode talks frankly about the current challenges with supply chain management, but Mr. Gallop also shares where he sees bright lights on the horizon and a path forward for organizations willing to consider the shift.

bookmark
plus icon
share episode
Caffeinated Risk - ESRM and Data Science with Rachelle Loyear
play

05/25/23 • 31 min

One of the original authors of the ESRM framework, now in it's tenth year, and Caffeinated Risk's first guest returns to discuss how data science is changing security and risk management. While alchemy may be a bit of a stretch, Ms. Loyear ongoing focus of including human behaviour in the risk equation is leading to the development of data science based detection capabilities that would have appeared magical even 5-10 years ago.
Rachelle Loyear is the Vice President of Integrated Security Solutions for Allied Universal and co-author of The Manager's Guide to Enterprise Security Risk Management.

bookmark
plus icon
share episode
Caffeinated Risk - Attack Tree Calibration with Terry Ingoldsby
play

03/23/23 • 7 min

Threat modeling expert and inventor of one of the world's first attack tree modeling products talks about how to integrate subject matter expertise into the risk equation, the answer may be surprising.
Bonus content not included in the original interview with Terry which dove deep into the history of attack trees, modern applications and exploring why there is no AI magic when it comes to identifying events that could end your organization. Well worth a listen if you missed it.

bookmark
plus icon
share episode

Factor Analysis of Information Risk (FAIR) and Enterprise Security Risk Management (ESRM) took different evolutionary paths yet share a lot more commonality than catchy 4 letter acronyms and mainstream adoption by notable organizations like NIST, The Open Group and ASIS international. Jack Freund personifies the term "risk management thought leader" with professional qualifications and public recognitions too long to list, but co-author of Measuring and Managing Information Risk can't go unmentioned since industry peers inducted this seminal title into the Cybersecurity Cannon.
With risk management discussions ranging from banking to defeating door locks, Dr. Freund was consistently insightful, humorous, and a delightful guest.

bookmark
plus icon
share episode
Caffeinated Risk - Cyber-Physical Convergence Revisited
play

01/19/23 • 34 min

In addition to hybrid work and regular time in the office being the new normal, 2023 marks the year Caffeinated Risk's co-host Tim McCreight serves as the president of ASIS international. ASIS has long been a proponent of both physical and cyber security professionalism and one of the first organizations to explore and embrace Enterprise Security Risk Management (ESRM) as an integral element of security.
Scholarly articles on cyber-physical security convergence started appearing in the late 1990s, more than 25 years later the convergence buzz has ebbed and flowed but silo's remain. In this episode Tim shares his insights from the past 40 years, the benefits to a converged approach as well as some of the paths toward success.

bookmark
plus icon
share episode

Co-author of Enterprise Security Risk Management: Concepts and Applications , Rachelle Loyear has spent her career managing programs in corporate security organizations. Focusing strongly on security risk management, she has been responsible for ensuring enterprise resilience in the face of many different types of risks, both physical and cyber.
She is currently active on a number of projects including:
- refining and releasing a Global ESRM approach to customer solution development for G4S
- working with customer focus groups to understand what the security industry really needs to manage risk – using Design Thinking principles
Rachelle also shares lessons learned on identifying and effectively communicating with the correct stakeholders for risk acceptance.

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does Caffeinated Risk have?

Caffeinated Risk currently has 44 episodes available.

What topics does Caffeinated Risk cover?

The podcast is about Management, Podcasts, Technology, Business and Cybersecurity.

What is the most popular episode on Caffeinated Risk?

The episode title 'Attack Tree Calibration with Terry Ingoldsby' is the most popular.

What is the average episode length on Caffeinated Risk?

The average episode length on Caffeinated Risk is 29 minutes.

How often are episodes of Caffeinated Risk released?

Episodes of Caffeinated Risk are typically released every 28 days, 14 hours.

When was the first episode of Caffeinated Risk?

The first episode of Caffeinated Risk was released on Jan 17, 2021.

Show more FAQ

Toggle view more icon

Comments