This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Greg Schaffer, founder of vCISO Services, LLC and a returning guest on Security Confidential, who brings over 35 years of experience in IT and security and with 15 years as a CISO. He hosts the Virtual CISO Moment podcast and is the author of Information Security for Small and Midsized Businesses.
Chapter Titles:
00:00 Intro
00:58 Our Guest
01:59 What’s new with Greg?
03:37 Changes in the vCISO world
11:29 People, Process, and Technology
15:00 Information Security for Small and Midsized Businesses
Audio:
Important Links:
Transcript
Manoj Tandon (00:01.574)
Hello everyone, welcome to another episode of Dark Rhiino Security, Security Confidential. This is your host, Manoj Tandon, and I am joined by a Security Confidential alumni, Mr. Greg Schaffer, who has his own podcast, The Virtual CISO Moment. If you haven’t checked it out, please do check it out. It’s a really good show with a lot of knowledgeable information exchange there. But for those of you who…might not recall just in brief, Greg is a great sizzle. He’s got over 35 years of experience. He knows a thing or two about information security and he’s the author of the book, Information Security for Small and Mid -sized Businesses, which is now in its third edition. And we’re gonna talk about that here in just a moment.
Greg Schaffer (00:37.988)
I’m old.
Greg Schaffer (00:52.902)
That’s right.
Manoj Tandon (00:57.756)
But Greg, welcome back here. Give us a little update since 2022. It’s been two years since you were last here.
Greg Schaffer (01:05.062)
Well, thank you for having me back. And it’s amazing to think that it’s been actually two years. It almost seems like a lifetime has passed since then. that’s about like 7%, I guess, in my career, if I think about it. Doing this like 35 years, I guess two years might be around 7%. That’s back of the napkin, not even back of the napkin. It’s back of the brain math there. So. Well.
Manoj Tandon (01:26.32)
Yeah. It’s good enough for a government work.
Greg Schaffer (01:33.018)
pretty much doing a lot of the same. So VCSO services still exists, going strong. We are a small, really targeted, I used to say boutique, I don’t know if I like that as much anymore, but we’re just, we’re a very specialized consulting firm for small and mid -sized businesses providing information security risk management services. And as such, we are very picky with who we work with. And we,
want to really just work with folks that want to build information security programs. So if you have like someone who comes to us that are looking for it to become just compliant with some sort of regulation or they want to SOC 2 readiness, that’s all that they’re looking for, they don’t want to build up their program, then we politely say, well, you know, it’s nice talking to you, but we’re not the ones for you.
And I think a lot of that has to deal with lot of the changes that have happened in the virtual CCO field too. We see a lot of that.
Manoj Tandon (02:32.336)
Please tell us a little bit about some of those changes.
Greg Schaffer (02:37.306)
Well, know, back in the day, it seems so long ago, because like I said, I’m old. But when I first started the company over seven years ago, your typical virtual CISOs were those that were CISOs beforehand, or at least the most senior information security risk management executive for whatever business they were in. And they decided, like me, that they wanted to or had a calling or what have you to do something different.
to help small and mid -sized businesses with the experience that they had already gained over years and years of their career. If you do the math for me, that would be about over 28 years of career. But nowadays, you have a lot of folks that are claiming that they’re virtual CISOs or organizations that provide virtual CISO services that are more in line with being an IT security manager. And I probably talked about this somewhat
two years ago as well too, because that had already been coming out more and more. And I think the trend has accelerated. So what’s happened then is for the SMBs, the small and mid -sized businesses, I always just tell them, it’s like, there’s nothing wrong with those services per se, but make sure that you understand what it is that you’re getting. Because virtual CISO or VCISO means a lot of different things to a lot of different people. So we’re more…
Manoj Tandon (03:57.114)
to different things.
Greg Schaffer (04:02.022)
virtual CISO traditional, I guess you could say. It’s like we are security officers. We have done that before in the past. That’s the experience we bring. But again, like I said, there’s nothing wrong with some of the others out there that it’s just a different type of service. even that’s starting to change now, too. You’re starting to see a split between those where I think actually it’s going back the other way, where now businesses are expecting that if you’re
saying that you’re going to provide virtual or fractional CSO services for us, they’re expecting that risk management, that strategy. They’re not looking for someone to manage the firewalls.
Manoj Tandon (04:39.892)
See that I’m really glad to hear you say that because there is a whole bunch of let’s manage the firewall crowd out there and what we have seen is Especially in the small business It’s the s part of SMB, you know, they are very They’re often just getting cybersecurity from their MSP, you know and
Greg Schaffer (04:49.733)
Yeah.
Greg Schaffer (05:06.071)
Mm
Manoj Tandon (05:06.83)
And it’s just a pure play technology. The effectiveness of that is fairly limited, not because they’re bad people. But it’s a specialized area and they don’t know how to create a multi -layered defensive architecture that actually reduces risk. It has nothing to do with capability. It’s just ignorance, if you will. The knowledge base hasn’t developed in them to be able to provide that service.
So especially the small business, I think is getting, still getting a lot of bad advice out.
Greg Schaffer (05:42.028)
I agree. And there is a somewhat of a nefarious angle, if you will, in some ways to some of this as well, too. The virtual see -saw field has become quite lucrative and for good reason. mean, you get a good virtual see -saw in, whether it be me or anybody out there. They’re worth their weight in gold. But you’ve now have some MSPs and MSSPs that offer the service, but they offer it
And I’m saying this is a minority. Let me just start out by saying the minority of MSSP’s do this, but there are some that do this and SMB’s need to be aware of this, that they almost function as an inside sales rep. And let me explain how this works. Just very simple example. Your MSSP VC will come in and do a gap assessment and they’ll say, well, you’re doing some monitoring, but you really need to be doing better monitoring. by the way, we offer a SIM service at a discount.
for our virtual CISO customers for you to meet this gap. So what’s happened here? A couple of things have happened here. First of all, the virtual CISO now has actually acted as a salesperson. They’ve produced a solution for a problem that they’ve identified. The second thing that’s happened is that, is that problem really one of the highest risks out there? Or is it that they’ve been incentivized to sell something? So you’ve lost that objectivity.
Now again, that’s not to say that this happens all the time. There could be a virtual CISO service from an MSP or MSSP that has the interests and the best interests rather of the SMB first and foremost. But the SMB needs to understand that there could be some conflict of interest. Personally and professionally for me, I prefer to stick with the three lines of defense model. If you’re a MSP or an MSSP,
you’re providing something in first line pretty much. You’re providing the technology services to do the firewalls, for example, the configuration and all that, and the monitoring. Second line is risk management. That’s traditionally where the CSO has always been. And then third line is audit, which checks first and second line. So if you take that, I recommend that if an MSP or an MSSP is offering a virtual CSO service, at the very least,
Greg Schaffer (08:06.146)
encourage the SMB to go for their first line services somewhere else. In some cases, I think that they should require it, but I’m not going to be that authoritarian.
Manoj Tandon (08:18.938)
Well, you know, I think the thing is maybe one takeaway here is, you know, a lot of the SMB space still is just enormously behind from an education perspective on what it is that they need to buy. And a foundational question for me would be, is anyone you’re considering, I don’t care who it is, whether it’s Dark Rhino or it’s you or anybody that are looking to hire, there’s a prime question to ask is, are you…
selling me information security or cybersecurity and see how they answer that because there is a big difference between the two things.
Greg Schaffer (08:51.877)
Mmm.
Mm
Greg Schaffer (08:59.758)
Now you’re opening up a can of worms, you understand by saying that. you’ll store a conlin, because that’s one of my soapbox items. Probably talked about it two years ago as well, too. There is a difference between InfoSec and cybersecurity, but people tend to use the words interchangeably and incorrectly, therefore, sometimes. And first of all, I want to emphasize to everybody that words matter.
Manoj Tandon (09:03.448)
Well, I was hoping I might and I might stir a comment.
Greg Schaffer (09:26.424)
And it’s important that we be clear. Don’t just say, well, it doesn’t really matter if we call it InfoSec or cybersecurity. It does. Because cybersecurity, my point of view, is the subset of InfoSec. It’s the technical subset. And so something like business continuity planning, that doesn’t fit in cybersecurity. That fits in information security. Information security is risk management. At the end of the day, if you’re talking to somebody and
Manoj Tandon (09:31.578)
Matters a lot.
Manoj Tandon (09:36.316)
It’s a subset.
Greg Schaffer (09:56.362)
Somebody just is insistent on wanting to use cybersecurity to describe everything just so long as they understand How they’re using the word because really we’re talking about communication when all is said and done get that straight first and forward But to your point if you have an SMB that contracts with an organization that says we’ll take care of all your cybersecurity needs Guess what there might just take care of all your cybersecurity needs and not the other broader part of info set
Manoj Tandon (10:25.196)
which I would argue, Greg, I don’t know how you feel about it, is the bigger part of it. So to me, before you even place a purchase order for a technology, a monitoring service, a firewall, mean, umpteen number of gadgets and gizmos that are available out there.
You got to understand how you make money. What makes the sausage factory run? What assets are important in that?
and how can they be compromised? Look at that. And not just the assets could be hardware, but it’s also a process as an asset. Can you compromise the process? Can you compromise the people? And if you don’t look at the people side of this equation and the process side of this equation that feeds your revenue chain first, I would argue that your information security
Greg Schaffer (11:09.498)
Right.
Manoj Tandon (11:24.604)
program is likely not going to be effective.
Greg Schaffer (11:28.804)
No, and I would agree. A colleague of mine, when I was at CISO for a bank and he was an operational risk manager there, he wanted to instill in everybody in the bank a risk management mindset. That was his goal. And everybody is a risk manager, I think was his tagline. And that’s true. And that goes a little bit beyond, like, cybersecurity is everybody’s responsibility, which is what people tend to say.
Manoj Tandon (11:54.575)
Yeah.
Greg Schaffer (11:55.994)
Well, that’s okay. That’s right. It is. It’s like, don’t click on that link. That’s a cyber thing. Make sure you have antivirus and all that. Yeah, that’s all true. But if you look at it from a risk management standpoint, everybody is a risk manager. That starts off by trying to understand, you don’t have to understand the entire business if you’re an employee for a company, but at least understand the business of what you’re doing and how that impacts the business. You might not need to understand how marketing does their stuff just that they do do their stuff. And I think it’s important.
that businesses understand that it is a broader topic. And to drill down into the cyber is one thing, and as we said before, it’s a broader topic. I kind of lost my train of thought there. I don’t know. It left the station, I think.
Manoj Tandon (12:39.088)
No, that’s okay. Well, we’ll get you back on track here. So, no, it’s, we were talking about, you know, InfoSec versus CyberSec and InfoSec is involving people, process, and then technology, if I was to summarize it, right? And if you don’t address the people process part of it, you got a train wreck that’s eventually going to happen. It’s just a question of time.
Greg Schaffer (12:44.169)
Okay
Greg Schaffer (12:57.836)
Mm. Right, right. That’s where we’re going, that the people…
Greg Schaffer (13:07.066)
Absolutely. So now we have two train analogies there. Train has left the station and then it’s wrecked. So it’s just like, that’s what happens when we get derailed. it gets, there we go, keep going. That’s probably about it. I think that’s all that I have. But yeah, people in process in addition to the technology. And part of the problem I think with SMBs, and I’m not necessarily blaming SMBs on this, but.
Manoj Tandon (13:10.876)
That’s right. Hey, I love it. That’s three. Keep going. How many more jokes can be made on that?
Greg Schaffer (13:34.878)
they sometimes think that it is just technology. And that’s a big, in all seriousness, that’s a big disservice for when we have some folks that use cyber and InfoSec interchangeably, because you’re promoting that incorrect assumption that everything security -wise is just technology -related. And you’re gonna miss a lot if you don’t look at the people in the process, because ultimately they’re the ones
who are using the technology and how they’re using technology as opposed to just the technology itself.
Manoj Tandon (14:06.458)
Yeah. So let’s get into your book then. I mean, because I’m assuming that it’s for small medium businesses. So.
Greg Schaffer (14:14.79)
It’s self -description there. I found that sometimes if you just name something what it actually is, like VCSO services, it tends to get the message across. information sec…
Manoj Tandon (14:26.278)
And it’s not a super thick book, which means that someone can read this.
Greg Schaffer (14:31.014)
Well, yeah, it’s the current edition is about 140 pages and they’re they’re they’re easy reading pages. So how this started is back in twenty twenty one. I created a lead magnet for the website and it was just an e -book and it was very, very small. are only a few topics, but they were.
common questions that folks were asking, like, what’s the difference between InfoSec and cybersecurity, for example? What is risk management? What is a SOC 2? Those sorts of things. And businesses would get really confused because, again, they were conditioned to understand incorrectly that all of this was a technology thing. So I wrote the initial book, the first edition, just as like a little guide to download. And if you download this, then I get your email address. I can bug you. Hey, marketing. Lead magnet. That’s what it was.
Manoj Tandon (15:22.362)
Yeah, sure.
Greg Schaffer (15:24.366)
Well, I got some decent feedback about that and I did want to expand it and I expanded it to the second edition, which I thought I had a copy right here, but I don’t. But the second edition, I also did a print version of. Again, this was, it actually didn’t have my name on it. It just said a VC Social Services Guide. And so I would give that out at conferences if they came to the table, you you do the booth thing. It’s like, hey, well, that’s a little bit better than just like a little pamphlet. It’s like, you’ve got a little security book here. Well,
I started to get great feedback about that. I remember actually being at a conference in Houston a few years back, I think this was in 22, where one of the keynote speakers, unbeknownst to me, held up that version of it before or after their talk. I don’t remember which, but they said, this is one of the best books, if not the best book I’ve ever seen, I’ve ever read about information security for small and mid -sized businesses.
The only reason why I know that this happened is that apparently after his talk, a bunch of people started to come to my table. Hey, okay, it worked. But I didn’t know why, I didn’t know that he had promoted this. So between that and more great feedback about the book, I actually hunkered down and expanded the book by over 50 % for the third edition, covered a lot more things and AI, for example, being one of them.
Manoj Tandon (16:47.238)
Well, that’s obligatory anymore. You can’t call yourself a consultant unless you’re talking about AI, man.
Greg Schaffer (16:49.368)
Yeah, I had to get AI in here somehow. You have to do that. And the goal was actually, I actually released this early by accident, sort of. And the goal was to release this for cybersecurity awareness month this year, which of course starts in October. But I had solicited for review readers, hey,
I’ll send you a copy of the book if you promise to write a review. Not everybody ended up doing it, or it’s in the pipeline still that they’re doing it. when I did this, this was like in late June. Well, come to find out that you can’t write a review apparently on Amazon unless the book has actually been released. so the reviews started to go towards the second edition. And I’m thinking, this is a marketing fail. I’m not a marketer.
Manoj Tandon (17:37.572)
Okay.
Greg Schaffer (17:44.966)
So it was one of those decisions like at that hour decided we’re gonna release it right now. So we did and boom. And wouldn’t you know it, it’s like a couple of cool things that have happened with this thing. One is that it has reached the Amazon bestseller list for the technology books a few times. That only means top 100. So it’s not nearly as great as it sounds, but hey, marketing, right? But also I’ve gotten feedback
Manoj Tandon (17:56.646)
Please, yeah, tell us.
Manoj Tandon (18:13.328)
Jane was marketing, the way, but that’s okay.
Greg Schaffer (18:15.11)
But I’ve gotten feedback from folks saying, you know, this isn’t just good for small and mid -sized businesses. It’s good for folks that are early in their career to try to get a handle on complex information security topics. But I write it in a very conversational manner. And there’s even one university up in Minnesota that they’re using this as the textbook for one of their cybersecurity classes.
which I think is just amazing. So that’s gotten me thinking, well, maybe I got to do like a course for it or at least some sort of an outline or, but I’m just happy that it’s had some good positive effects on folks. And I’ve already started to take some suggestions towards working on a fourth edition, which will be out in 2026.
Manoj Tandon (19:04.486)
Give us some, walk us through the synopsis of it. What, without giving away everything, because of course you want people to buy the book, but.
Greg Schaffer (19:13.626)
The butler did it. I mean, so just like reading from the table of contents and talk about the start out with governance. And I think that that’s important to start out with governance because often it’s again, assigned to IT. But every section has a discussion about what it is that we’re talking about. So everything from policies.
to information classification, to risk management, to your different types of risk assessments, qualitative and quantitative, and why they’re different. Because sometimes you get folks that they do a risk assessment. I do this too. What’s the traditional way to do a risk assessment? You say, OK, let’s think about the likelihood and impact that something bad might happen. All right, we’ll assign it three.
Manoj Tandon (20:06.864)
Sure.
Greg Schaffer (20:09.734)
levels, low, medium, and high. And we’ll assign a number to that. OK, one, two, three. And then we’ll multiply those numbers together. We get a nine for really high risk. And then we have some controls. And the controls have some sort of an effect. And so you can then incorporate that as a fraction. We would call that a mitigation effectiveness. So you have a nine, but your controls are pretty darn effective. So you say that that’s a 0 .05. Multiply that again.
your risk that was a nine now is a 4 .5, which on your scale is a moderate. But you’ve got all this multiplication going around, but what are you multiplying? The numbers, don’t really represent anything. It’s fake math. it’s just, right, it’s just a numerical representation of some subjective opinion, which is fine. But people got to understand that that’s not a quantitative risk assessment. A quantitative risk assessment actually takes into account
Manoj Tandon (20:53.414)
Sure, it’s arbitrary. It’s relative.
Greg Schaffer (21:09.338)
some actual qualities, some quantitative qualities, if you will, like cost of breaches and all of that. How much revenue would you lose if you were down for seven hours? So revenue, dollars, time, hours, those are actual numbers that you can actually do math on, not these little flaky things. anyway, back to the book. At the end of each section, I always have two final
two final bullets, so the bottom line and then SMB considerations because for folks that want to like, okay, Greg, you just wrote a chapter about this. Why did you write it? Well, that’s the bottom line. And then how does it apply to me as an SMB, SMB considerations? So, and finally, the book, it’s not sequential. It’s not like a novel. And if you want to look up something on frameworks, for example, I don’t talk about every single framework in here, but I do talk about a few.
that SMBs should be interested in. so NIST Cybersecurity Framework and CIS 18, and probably one more in there that I’m not remembering right now. But if you want, if you never heard about these frameworks and you’re like, okay, let me go over there and check this out. It explains why, why they’re for.
Manoj Tandon (22:29.697)
So it’s a, would it be a good read prior to hiring a firm or a virtual CISO or a fractional CISO or during the course of engagement?
Greg Schaffer (22:45.39)
I think both. think that for some businesses, and I’m not trying to kick any of us out of getting a client, but for some businesses, they might be fine just having a guide like this as opposed to engaging with a virtual CISO. It depends upon what they have, the experience that they have on staff and the bandwidth that they have. More often than not though, this can help.
those that are already engaged with a virtual or fractional CISO understand a little bit more about where their consultant is coming from. So why are they going through this? Why is this important to the program? And that was more so, again, remember this started out as a lead magnet. it’s like, these are some things you should know and by the way, work with us. So I think it is a good companion for clients.
Manoj Tandon (23:32.447)
Sure.
Manoj Tandon (23:36.549)
Yeah.
Manoj Tandon (23:43.992)
In the last couple of minutes here, we still have a few things to get to, but I wanted like, know, in terms of what you have seen in the seven years that you’ve been doing this virtual CISO work, what are still some of the problems that continue to be sore points for you when you’re looking at the SMB market? What, is there a top two, top three that come to mind for you?
Greg Schaffer (24:08.622)
Well, yeah, mean, one we’ve already discussed that’s bad advice. In fact, I think you use those words. On the virtual CSO moment, I always ask what’s one of the big threats to cybersecurity for an InfoSec, I should say, for SMBs, and bad advice is one of them. then the corollary of that is having unqualified virtual CSOs. There’s a whole bunch of like,
Manoj Tandon (24:13.814)
Yeah.
Greg Schaffer (24:38.814)
more pressure for SMBs to need to engage in this sort of a service, at least they think so, because they’re getting pressure from their prospects and their customers saying, hey, we need to know more about your security program. And certainly some official actions like everything, CMMC, for example, has prompted a lot of this. And that’s a good thing in that compliance, it’s good to be compliant, but from a security
Manoj Tandon (24:57.645)
sure.
Greg Schaffer (25:07.686)
program standpoint, it often is the gateway into building a program. I don’t think that there’s going to be a drawdown in need for such. I do think that there’s going to be that split between real effective consultants and those that just really focused more on first line.
Manoj Tandon (25:32.908)
I would tend to agree with you. So, well, hey, listen, we’ve reached the end of this tiny little episode. I want to give you a minute. What are you here to plug other than your book? Or you can plug that some more if you’d like. This is your opportunity for a shameless marketing.
Greg Schaffer (25:50.66)
Well, I’ll plug the fact that I will be at the National Cyber Summit in late September. Unsure when this is going to air, understanding that. So maybe I was there. And have a few other projects involved. In fact, I’ve been doing work with those who follow me on LinkedIn know that I’ve been doing work as a contributor to a couple of TV shows with Now Media. Got a project involved there.
that I’m not ready to really talk about yet, but I’m really excited about it. You can already see me on Roku. it’s a, because now media, 31 million is their audience. But this is going to be something focused hopefully on technology. We’re working on what this might look like. So more to come later.
Manoj Tandon (26:23.856)
That’s really cool. So we’re going to see you on Netflix.
Manoj Tandon (26:45.569)
Greg, you know, keep up the good work and we wish you continued success and come back maybe not two years from now, you know.
Greg Schaffer (26:54.106)
Hey, I’m always happy to come back. I really appreciate being invited back on. And I just can’t believe it’s been two years. I know I’ve gotten a little bit grayer here, it looks like.
Manoj Tandon (27:03.416)
No, I don’t know. I, well, well, no, I think you’ve gotten a little younger, actually. When I look at the picture from the last time, maybe you got a snazzy new studio with lighting and everything. Last time you didn’t have that, so.
Greg Schaffer (27:10.8)
Yeah.
Greg Schaffer (27:20.663)
It’s the place, but it’s things that I enhance for the TV thing. So, more to come on that.
Manoj Tandon (27:27.824)
Well, it’s all great. Well, hey, Greg, you have a great day. Appreciate you stopping by and giving us a little bit of knowledge here.
Greg Schaffer (27:36.614)
Appreciate the invite and we will talk later, not two years from now, but sooner.
Manoj Tandon (27:41.014)
Sounds good. Take care. Bye bye.
Click here to get $5 Greg’s new book Information Security for Small and Midsized Businesses exclusively for Security Confidential. Offer expires September 30, 2024.
Learn more about Greg on his LinkedIn
Watch our first episode with Greg
Listen to Greg share his Cyber Horror Story
Kiteworks enables organizations to effectively manage risk in every send, share, receive, and save of sensitive content. To this end, they have created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content moving within, into, and out of their organization, significantly improving risk management while ensuring regulatory compliance on all sensitive content communications.
Check out the other episodes in Season 15:
Ep.0 Robert Kerbeck – Fame, Fortune, and Corporate Espionage
Ep. 1 Stephen Kowski – Inside the mind of a Field CTO
Ep. 2 Vivek Ramachandran – Inside Email Security: Breaking Through Gmail and Outlook’s Defenses
Ep. 3 Dr. Eric Daimler – AI’s Future: More Than Just Machine Learning
Ep. 4 Purandar Das – Data is the New Oil
Ep. 5 Aaron Painter – Understanding Deepfakes
Ep. 6 Jake Moshenko – Navigating Open Source and Distributed Systems
Ep. 7 Nick Espinosa – Why CISOs Must Master Nerd to English Translation
Ep. 8 Dan Lohrmann – AI, Fraud, and the Future of Cybersecurity
Ep. 9 Greg Schaffer – How the Role of a vCISO is changing
Ep. 10 Sanjay Chopra – AI Innovations and the Future of Automation
About Greg Schaffer

Greg Schaffer is a Christian, husband, father (to rescue dogs), veteran, and information security executive consultant. His most recent work is Information Security for Small and Midsized Businesses, third edition (2024), a guide for organizations without a Chief Information Security Officer to help them understand basic information security risk management concepts. Greg is also a novelist, with works that include Forgiveness (2014), Leaving Darkness (2018), and Fatherhood (in development). In addition, he has published Summer’s Drowning (2013), a collection of poems, and From the Loft (2017), a collection of horse-humor articles.
In January 2017, Greg felt a spiritual nudge to resume writing. He outlined a three-act story inspired by his involvement in small group ministries, which had deeply impacted his life and the lives of others. This led to the publication of Leaving Darkness in the fall of 2018, a story centered around healing through these ministries.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
