This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.
All Episodes

Latest Episodes

All Episodes →
#31

Resilience, AI Governance, and Practical Zero Trust - Elie Hachem - Cyber Smokehouse - Episode #31

Take your cybersecurity leadership and operational strategy to the next level with practical insights on AI-driven planning, risk-based zero trust, and framework execution. It’s time to stop chasing unachievable 100% security and start building resilient, business-aligned security programs that maximize risk tolerance and protect core operations. Who better to guide you through this transition than CISO and Director of Cybersecurity at Select Sires, Elie Hachem? You will learn how to leverage AI to accelerate security roadmaps, implement CIS Controls v8.1 for tangible gap analysis, apply sales psychology to navigate executive boardrooms, and scope zero trust practically around high-value assets rather than blanket mandates. Get motivated to engage business partners, build proactive incident containment, and align security investments directly with organizational ROI! Takeaways: Shifting from 100% Security to Resilience: Achieving total security is unrealistic; CISOs must focus on minimizing detection-to-response time and building proactive quarantine controls. Accelerating Security Roadmaps with AI: Read-only tenant integration allows security leaders to rapidly analyze internal processes, identify pain points, and condense traditional multi-year planning horizons. Practical Scoping for Zero Trust: Blanket zero trust across entire enterprises often fails due to executive friction and BYOD demands; focus zero trust controls tightly on privileged accounts and core infrastructure. Structuring Frameworks with CIS Controls: Utilizing structured frameworks like CIS Controls v8.1 gives security teams a measurable, tangible baseline to assess gaps and map directly to NIST standards. Applying Sales Psychology to Security Leadership: Leveraging transactional sales experience and human behavior analytics helps CISOs communicate risk effectively and secure executive buy-in. Quote of the Show: "Security is an enabler to the business, and it is impossible to be a hundred percent secure. What you can do is maximize your risk tolerance and build proactive resilience." - Elie Hachem Links: LinkedIn: https://www.linkedin.com/in/eliehachem/ Website: https://www.selectsires.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#30

The Shift to Cloud-Native Security - Chris Goosen - Cyber Smokehouse - Episode #30

Take your enterprise Microsoft architecture and AI strategy to the next level with practical insights on Copilot deployment, agentic governance, and modern cloud security. It’s time to slow down, eliminate data sprawl, and secure your foundational permission structures before turning loose generative AI across your organization. Who better to guide you through it than 13-time Microsoft MVP, Cloud Architects co-host, and principal technology consultant Chris Goosen? You will learn how to navigate the 70+ Copilot product variations, contain sensitive data leaks using isolated enterprise models, govern unmonitored agent sprawl, and transition away from legacy Active Directory infrastructure. Get motivated to evaluate your M365 licensing efficiency, adopt automated patch management, and implement a "best of platform" security approach that saves budget while maximizing protection! Takeaways: Cutting Through Copilot Branding: With dozens of distinct Copilot products across M365, GitHub, and Power Platform, organizations must distinguish between consumer chat tools and isolated enterprise models that prevent data leakage. Addressing AI-Exposed Data Sprawl: AI tools don't create new security holes; they expose legacy over-permissioned files and old SharePoint archives using natural language queries. The Rise of Agentic Governance: As organizations face "agent sprawl," tools like Agent 365 and conditional access policies are becoming essential to track, identity-tag, and govern autonomous AI agents. Transitioning Off Legacy Active Directory: On-premises Active Directory remains a primary target for attackers; migrating to cloud-native identity architectures eliminates decades of technical debt. Best of Platform vs. Best of Breed: Leveraging built-in M365 Business Premium or E5 security features prevents double-paying for third-party tools and unifies security telemetry in one place. Quote of the Show: "Copilot or any of the AI models aren't discovering stuff that was hidden before - they are just surfacing what was previously over-permissioned and making it easier to find." - Chris Goosen Links: Website: https://gooseco.au LinkedIn: https://www.linkedin.com/in/ctgoosen/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#29

Who Audits the Auditors? - Bernie Wedge - Cyber Smokehouse - Episode #29

Take your technology risk and compliance strategies to the next level with powerful insights on independent control validation, third-party risk management, and the evolving audit ecosystem. It’s time to move past rubber-stamp compliance, navigate the alphabet soup of IT frameworks, and understand how AI is transforming sampling into full-population testing. Who better to guide you through it than retired EY partner, Americas Technology Risk practice leader, and senior cybersecurity advisor Bernie Wedge? You will learn how to evaluate auditor credibility through peer reviews, avoid the marketing trap of "instant" SOC 2 tools, and streamline multi-framework testing into a single efficient audit cycle. Get motivated to ask tougher questions of your third-party providers, align controls across the business, and build a trust center that provides real transparency! Takeaways: The Reality of SOC 2: While lower-cost auditors and automated GRC tools have created instances of "security theater," SOC 2 remains a robust, vital assurance mechanism when executed with proper governance and independent testing. Auditing the Auditors: Organizations must exercise due diligence by requesting peer review reports from their auditing firms to verify credentials and ensure proper quality control standards. Navigating Framework Proliferation: Rather than siloing SOC 2, ISO, HITRUST, and PCI efforts, leaders should adopt a "test once, use many" approach to audit overlapping foundational controls simultaneously. Asking the Right TPRM Questions: Vendor risk management requires reading the actual details of a SOC 2 report, challenging sample sizes, testing depth, and even interviewing the signing audit partner, rather than just filing the document away. AI's Impact on the Future of Auditing: Generative AI tools allow auditors to move away from small sample sets and analyze entire populations of system logs and access requests in real time. Quote of the Show: "SOC 2 is not a security theater for those who put time and effort into doing reports correctly, but it is sort of what the company puts into it." - Bernie Wedge Links: LinkedIn:https://www.linkedin.com/in/bernie-wedge-jr-59817583/ Website: http://www.openhandatlanta.org arc360.com https://s2guild.org/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#28

Agentic Development and the Evolution of DevSecOps - Ken Toler - Cyber Smokehouse - Episode #28

Take your application security strategy to the next level with powerful insights on securing fast-paced agentic development, navigating abstracted SaaS platforms, and bridging the gap between engineers and security teams. It’s time to move past rigid no-saying, embrace "vibe coding" as a shared collaborative workspace, and build resilient security systems that stand the test of time. Who better to guide you through it than DevSecOps podcast host, blockchain application security expert, and Founder & Managing Principal Consultant at Asgard Security, Ken Toler? You will learn how AI-driven tools are accelerating threat modeling and supply chain management, why abstracted "squishy middle" infrastructure presents new attack vectors, and how to foster a curious, error-friendly engineering culture. Get motivated to enable your developers, simplify system abstractions, and build collaborative bridges across your entire organization! Takeaways: The Pace of Agentic Development: AI tools and agentic development aren't changing core security fundamentals; rather, they are accelerating execution and making practices like threat modeling and supply chain fixes faster to implement. Preserving Systems Thinking: While AI lowers barriers to coding, engineers and security teams must still maintain deep reading and architectural comprehension to diagnose complex system vulnerabilities. The Danger of the "Squishy Middle": Modern abstracted platforms (like Replit or Lovable) consolidate credentials and environment variables into shared SaaS infrastructure, creating lucrative targets for attackers. Embracing Citizen Developers & "Vibe Coding": When non-technical departments prototype apps using AI, security and engineering teams should engage collaboratively rather than dismissively to build organizational alignment. Enabling Over Blocking: Security leaders thrive by finding creative, positive ways to enable business goals securely instead of being the transactional "no guy". Quote of the Show: "I've gotten so much further figuring out how to enable people securely rather than trying to tell people why they are insecure. Nobody wants to talk to the angry security guy." - Ken Toler Links: X: Relotnek LinkedIn: https://www.linkedin.com/in/kentoler/ Website: https://www.asgardsec.com Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#27

Building Security Programs from the Ground Up - Eddie Younker - Cyber Smokehouse - Episode #27

Take your cybersecurity program to the next level with powerful insights on structuring security reporting lines, combating shadow risk, and building an engaged, transparent team culture from scratch. It’s time to move past organizational blind spots, establish top-down AI guardrails, and align vulnerability management directly with business priorities. Who better to guide you through it than Fortune 100 security leader, former CISO at Hyundai Capital America, and former VP & CISO at LIV Golf, Eddie Younker? You will learn how reporting directly to executive leadership eliminates conflicts of interest, why effective vulnerability management relies on business support rather than just IT execution, and how to foster a "family away from family" culture that achieves industry-leading employee engagement. Get motivated to build cross-functional relationships, educate leadership teams, and take a business-first approach to security! Takeaways: The Power of Reporting Structure: Reporting directly to the CEO gives security leaders the visibility and authority needed to embed security into operational processes, whereas reporting under a CTO can create conflict between speed-to-market and risk management. Mitigating Shadow IT and AI Risks: Emerging tools and ad-hoc AI adoption create shadow risk across organizations; mitigating this requires clear corporate guardrails, top-down governance, and strong cross-departmental relationships. Business-Centric Vulnerability Management: Successfully patching high-priority vulnerabilities isn't just an IT task, it requires educating business stakeholders, managing tech debt, and securing executive buy-in to prevent operational downtime. Transparent and Inclusive Leadership: High-performing security teams are built on transparency, mutual respect, and hiring for complementary skill sets rather than redundant backgrounds. Practical Advice for Rising Security Leaders: Gaining broad experience across multiple security domains gives rising professionals the holistic perspective needed to apply security frameworks to real-world business environments. Quote of the Show "Building a security culture starts with the reporting structure... You need a structure that enables you to own security for the entire organization and drive governance that gets support from the business." - Eddie Younker\ Links: LinkedIn: https://www.linkedin.com/in/eddie-younker-19559a96/ Website: https://www.livgolf.com/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550