Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
History
Music
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/b0/ba/a7/b0baa7e5-fbc1-e85e-7d64-c2dc9ba46569/mza_7465228042771424499.jpg/600x600bb.jpg
Caffeinated Risk
McCreight & Leece
53 episodes
2 weeks ago
20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is dest...
Show more...
Management
Technology,
Business,
News,
Tech News
RSS
All content for Caffeinated Risk is the property of McCreight & Leece and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is dest...
Show more...
Management
Technology,
Business,
News,
Tech News
Episodes (20/53)
Caffeinated Risk
Integrated Assurance with Patrick Hayes
20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is dest...
Show more...
2 weeks ago
34 minutes

Caffeinated Risk
The Summer Show - 2025, (pt 2)
Part 2 of this summer break episode takes a bit of a light hearted look at the cyber security industry predictions that become the norm in late December and early January. Eight or nine months later, how accurate where they? Take a listen, there are a couple surprises. The conversation uncovers a few ongoing challenges with the cyber security industry, from the digital divide associated with aging to organizational shifts away from engineering principles. A book by security pionee...
Show more...
2 months ago
27 minutes

Caffeinated Risk
The Summer Show - 2025, (pt 1)
The summer show started with the light hearted goal of evaluating the top security predictions that fill the internet in late December each year. Forever unscripted, Tim and Doug wind up reflecting on the growing gap between physical and virtual information systems. While it is easy to lament, from a cognitive perspective there is little hope, the BSides movement, alive and well in Western Canada, is helping address that. It is almost inevitable that security and risk conversation...
Show more...
2 months ago
26 minutes

Caffeinated Risk
ESRM roots, revelations & resilience with John Petruzzi
Enterprise Security Risk Management (ESRM) principles appear in almost every episode and this one is a bit more overt because it features two of the three people responsible for promoting ESRM in the early days of it's reintroduction through ASIS. John Petruzzi is now the CEO of Unlimited Technology and leading them toward an expanded influence in the enterprise security industry, sharing insights for what works with fortune 250 organizations, government and even local school boards. As...
Show more...
3 months ago
35 minutes

Caffeinated Risk
Global Risk Management as Strategic Advantage with Dominic Bowen
The Caffeinated Risk hosts navigate time zones and catch up with Dominic Bowen traveling between meetings to discuss risk management with an international expert on the subject. Mr. Bowen is a partner and Head of Strategic Advisory at 2Secure, one of Europe's leading risk management consulting firms, as well as the host of the International Risk Podcast. Political tensions are higher than they have been for years and there is seldom a month that goes by without a technical disruption th...
Show more...
4 months ago
35 minutes

Caffeinated Risk
Simplifying risk analysis using FAIR and Wiley Coyote with Jack Freund
A while back we were fortunate enough to spend time with Jack Freund, coauthor and thought leader responsible for bring the FAIR methodology and practice into the main stream. A bonus from that original recording is now an espresso shot discussing how to fast track an assessment when the threat vectors are numerous. While the metaphor Jack used is somewhat unexpected it's both memorable and an excellent approach to dealing with an entire class of attacks in a single assessment. A pro ti...
Show more...
6 months ago
8 minutes

Caffeinated Risk
SMB Resilience and lessons for larger organizations with Rochelle Clarke
At 45-50%, depending on your statistical source, there is no denying that small to medium sized businesses are a significant economic engine from both an employment and innovation perspective. In 1978 Microsoft numbered 11 people. Unfortunately small businesses are also the least likely to survive a major disruption, an experience that changed Rochelle Clarke's corporate leadership trajectory to a business founder. The Continuity Strength founder shares insights on the needs of small to...
Show more...
7 months ago
30 minutes

Caffeinated Risk
Addressing Risk and Cyber Resilience, the Alberta Approach - with Rachel Hayward
A surprising number of digital innovations began in Alberta, be it the world's first public digital cellular network in 1985, the DNP3 industrial controls protocol and becoming the first Google international research lab in 2017. CyberAlberta is another innovative collaboration focused on strengthening the cyber resilience of Alberta organizations. At almost 330 billion annually, protecting the Alberta economy and it's citizens from digital attacks is an important mission.&...
Show more...
8 months ago
36 minutes

Caffeinated Risk
Security Risk Management in an Open Data Environment with Michael Spaling
Ever wondered how top universities protect their cutting-edge research from prying eyes while ensuring seamless access for their scholars? Join us as Michael Spaling, Principal Security Architect at the University of Alberta, takes us behind the scenes of this high-stakes balancing act. Just like any other large organization, research universities have many different stakeholder, operational and regulatory requirements, thousands of employees and tens of thousands of customers. In a strange ...
Show more...
10 months ago
36 minutes

Caffeinated Risk
Engineering, Risk Management for Cyber-Physical Systems with Andrew Ginter
The practice of engineering dates back thousands of years, incorporating science and mathematics to solve problems in the ancient world, and remains a key requirement for developing the complex digital systems controlling the physical systems core to our modern way of life. Unfortunately connectivity and complexity have created a vulnerability we must now engineer our way out of, and just like risk management, engineering is about balancing constraints.Andrew Ginter is a recognized thought le...
Show more...
11 months ago
29 minutes

Caffeinated Risk
Deviance Normalization & Risk Management with Marco Ayala
Technological change is inevitable and often one of the aspects that attracts people toward careers in information and operational technology. Although risk management is a part of navigating advancement in any area, the fundamental flaw in any management system is our human tendencies. This episode explores how organizations can make slow, steady migration from first principles to risky undertakings without noticing. Marco Ayala, an operational technology cybersecurity expert and current Hou...
Show more...
1 year ago
34 minutes

Caffeinated Risk
Managing Supply Chain Risk Management - with Darren Gallop
Whether it's the NIST CSF, 8276 or the new European Cyber Resilience Act there is no denying the expectation that supply chain management (SCM) is a risk management area no organization can ignore. While SolarWinds is recent common reference in many SCM discussions, this episode's guest takes us back to Target's major data breach that resulted in significant changes to the PCI-DSS standard. Darren Gallop, a serially successful Canadian tech entrepreneur, recounts the early journey...
Show more...
1 year ago
32 minutes

Caffeinated Risk
Metawar and Fostering Resilience with Winn Schwartau
Long before the Matrix captured peoples imaginations, Winn Schwartau was steadily offering red pills for those reading his many books on information warfare. A scholastic level researcher without the pretense, Mr. Schwartau has been recognized internationally as one of the leading security thinkers of our time and has a special capability for distilling complex security concepts into every day language and metaphor. In this episode Tim and Doug talk with Winn about the battle big ...
Show more...
1 year ago
34 minutes

Caffeinated Risk
Resilience and I.R. Lessons Learned (the hard way) - with Adam McMath
Almost all incident response plans include a "lessons learned" step, and in the post adrenalin phase that follows many breaches, reviewing what worked and what needs improving doesn't excite a lot of people. Adam McMath is clearly the exception, leading incident response activities in both the cyber realm and physical. How do resilience and incident response lessons learned while literally fighting fires translate into risk management practices within cyber security, is a go...
Show more...
1 year ago
34 minutes

Caffeinated Risk
ESRM a Transformation Catalyst with Radek Havlis
Amongst the industry verticals classified as critical infrastructure, few would argue that telecommunications belongs in the top that list, placing even more weight on a risk management program due to cascading impacts. Consequently, safe reliable operations are essential for success while continuing to grow in a highly competitive marketplace. A security risk management challenge across many dimensions that has become an ESRM success story. This episode features Radek Havlis, Vice...
Show more...
1 year ago
29 minutes

Caffeinated Risk
Contingency Planning, Cyber Resilience and Incident Response
Regulatory frameworks from PCI-DSS to NERC-CIP to the newly minted NIST CSF 2.0 each require organizations of all sizes to have cyber incident response plans. Most of us who have spent any time in cubicle filled office towers are familiar with fire drills to clear the building and gather staff at muster points, and that is as close as we get to the real thing. Unfortunately that same lucky streak will Unlike a fire drill, recent research estimates 85% of b...
Show more...
1 year ago
28 minutes

Caffeinated Risk
The Business Context of Cyber Resilience with Steven J Ross
Those running a business today who have not experienced disruption due to cyber issues or attacks know it is only a matter of time. Even if their organization is not directly targeted, the modern marketplace comprised of multiple, interconnected supply chains, means impact is unavoidable but this episode's guest, Steven J Ross contends planning, design and clear priorities can provide mitigating resilience.Steven J Ross, executive principal of Risk Masters International, is a reco...
Show more...
1 year ago
30 minutes

Caffeinated Risk
Building a Cyber Risk Management Program with Brian Allen
The U.S. Security Exchange Commission defined new rules for cyber risk matters facing publicly traded corporations in July of 2023. Although the SEC's mandate is limited to publicly traded companies in the United States, where one regulator goes others are apt to follow. Brian Allen is the co-author of a brand new book putting form, structure and traceability around the SEC mandated requirement for a Cyber Risk Management Program. Mr. Allen was on of the original creators a...
Show more...
1 year ago
30 minutes

Caffeinated Risk
CyberPHA - OT Risk management With John Cusimano
The ISA 99 standards body is one of the most recognized authorities on cyber physical security covering many aspects of a cyber security management system for industrial control systems including risk management. This episode features John Cusimano, former chairman of the ISA subcommittee responsible for authoring the risk management portion of the standard 62443-3-2:2020 Mr. Cusimano takes us back to the origins of the OT specific risk assessment process, originally dubbed ...
Show more...
1 year ago
31 minutes

Caffeinated Risk
Science, Crime and Workforce Development with Dr. Martin Gill
Security and crime are often in close proximity but not always studied together. This month's episode features Martin Gill a criminologist who made the study of crime and security his life's work. After a decade as a lecturing professor at the University of Leichester, Mr. Gill started Perpetuity Research in 2002 and continues to provide very high quality research, both qualitiative and quantitiative, on what works -- and more importantly what does not -- on many diffe...
Show more...
1 year ago
31 minutes

Caffeinated Risk
20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is dest...