This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Chad Weinman. Chad is the VP of Professional Services at Risk Lens. Risk Lens is a software company that has codified the FAIR-based approach to assessing cybersecurity risk. Chad has performed many consulting engagements, helping clients quantify cyber risk.
Chapter Titles:
00:00 Introduction
00:47 Is Cybersecurity Risk used in a cavalier way?
03:16 What are the ground rules for discussing cybersecurity risk?
05:53 Does the disaster recovery plan cover all the risks?
07:30 Are regulators considered threats?
09:03 Compliance does not correlate to cybersecurity
14:20 What is FAIR?
17:59Layman’s approach to risk
28:00 Is a single risk score of any relevance?
32:20 Companies that have direction with a FAIR analysis of risk
37:40Chad’s information for cybersecurity practitioners
Audio:
Important Links:
Transcript
Manoj Tandon: Hello everyone, welcome to another episode of Dark Rhino Security Confidential. Today, we are honored to have Chad Weinman join us. Chad is part of RiskLens, an organization that provides consultancy and technology to evaluate cyber risk. They have made an immense contribution, as has their founder, and we’re honored to have him here today. Thank you for joining us, Chad.
Chad Weinman: Appreciate it. Absolutely, happy to be here. Thanks.
Manoj Tandon: So Chad, we have to ask. Risk is a gigantic topic in cybersecurity. I don’t think you can visit a cybersecurity vendor or consultancy website where you don’t see the word “risk.” It comes up and is used so often, and I would dare to say that it’s actually abused in many ways. In our personal experience, we have found most organizations have a hard time actually quantifying it and really saying, “What is risk to them? What is acceptable? What is not?” How do we get there? What are your insights or thoughts on that? Is that what you folks observe in the industry, or are we an exception in that observation?
Chad Weinman: No, definitely not. It’s a magic word, “risk.” You put it in your job description, put it all over your resume, or in anything you’re sending to the business. Just put the word “risk” in there half a dozen times. It’s overused. It’s like a lot of other words, like “model” or “framework.” When in doubt, put the word “risk” in there and you’ll get somebody’s attention.
Unfortunately, because of that, it’s watered down or used blindly. An example I always point out when I talk to organizations is if they pull up their risk register, it’s a dumpster fire almost all the time. A dumpster fire of a whole bunch of stuff: findings, audits, assets, groups. It’s just a mess of everything. You want to pull your hair out when you go through it, and it’s just because it’s a word that’s thrown around very cavalierly and magically.
I think one of the first things I learned quickly was the benefit of actually understanding what risk is and being able to explain what risk is, instead of throwing it around very casually as well. That’s probably step one, understanding that. But it’s a huge problem in the industry and space.
Manoj Tandon: So how should companies look at it? Whether you’re a greenfield startup looking at risk, or you’re a company that’s been in business for a while, what are some ground rules for when you start talking risk? What should be some ground rules that are put in place?
Chad Weinman: I think it’s just having intention, because the crazy thing is most everybody rallies around the same definition of what it is, which is some form of likelihood or frequency and then impact. It’s like car insurance. Teenagers are going to pay more in car insurance. Why? Higher likelihood they’re going to get in an accident, and then obviously impact costs. Insuring a Honda Civic is not the same as insuring a Ferrari. There are various values of the asset.
It’s this idea of how likely some bad event is going to happen, and when it does, what’s the impact or loss associated with it? Everybody agrees that’s pretty common, standard, and used. But when people use the word “risk,” they use it not to discuss things that you can measure that definition on, but just around anything.
As an example, a malicious insider is not a risk. I can’t tell you the likelihood or impact of a malicious insider in and of themselves. What I could tell you is what a malicious insider may do. They may take your systems offline, they may steal information. Well, each of those has a different likelihood and impact. So the biggest thing is understanding that and having intention.
When you talk about risk, you can only assign a likelihood and impact to an event, some scenario, or what we refer to as a loss event, something that creates loss. Often what people do, and not just cybersecurity professionals but business people, is one of the first things I teach people on my team is you almost need to become a therapist. People will come to you and they’re going to tell you all their problems, issues, and concerns. They’re going to be like, “Oh, I’m worried about the cloud,” and “I’m worried about malicious insiders,” or “I’m worried about this and that.”
You have to translate. You have to say, “Sit on my sofa, let me ask you two or three more questions.” I’m going to find out what you’re really worried about, meaning I’m going to pull these threads to figure out what is the event or events that you’re worried about. That’s what I can measure. That’s what I can assign a likelihood and an impact to. So it’s really just having some intention behind it versus adding the word “risk” to whatever you want.
Manoj Tandon: Would you say that a lot of companies already have a disaster recovery plan in place? Is that a good place to look for what those events could be?
Chad Weinman: Absolutely. It’s funny, though. I had a risk register I looked at for a customer that called their business continuity team a risk. I’m like, “Wait, business continuity is a risk? Isn’t that a group of people?” They’re like, “Well yeah, there’s a group that does that.” “So you’re calling them a risk? Do you not like them?” They’re like, “No.” “So they suck at their job?” They’re like, “No, I don’t mean that either.” “What do you mean?” They’re like, “Well, we can’t recover quickly.”
Okay. Well, that’s not the risk. Once again, the risk is when an outage occurs or something takes your systems offline, the impact is going to be longer than expected. It’s just asking intelligent questions to understand. What’s the probability you have an outage? If it’s once every hundred years, maybe it’s okay if you don’t have the fastest recovery timeframe. But if it’s something that happens every week or every month, maybe it matters a hell of a lot more.
So yes, disaster recovery, audit findings, current events happening in the industry, business continuity scenarios, all of those are valid. It’s just taking them the next step to define what are the specific events that cause those findings to create loss.
Manoj Tandon: Would you consider regulatory fines as a loss and thus a threat, or a risk?
Chad Weinman: Yes and no. In most cases I wouldn’t, because I care about my career. I don’t go around calling regulators threats. But in some ways they act in a manner like a threat because they create loss by fining or issuing judgments. Usually they’re doing it in response to some other event.
Usually there’s this idea of a bad thing happens and there’s an initial loss that happens with that, and then sometimes there’s fallout from that. That can include fines, lawsuits, settlements, and reputational harm. So often how we view it is there’s a catalyst event. Regulators are more the fallout or the response to that event, and they pile on additional loss or impact to the organization because they’re not happy.
Occasionally, though, there are circumstances where regulators can act in a manner that almost becomes a threat, as in they could be the source of loss in the first place, definitely in different geographies.
Manoj Tandon: If you’re in the defense business, the government can shut you down absolutely if you’re not in compliance with certain regulations. Which actually brings up another question. We often see that compliance does not correlate to great cybersecurity. Is that something that you have followed in your experience, because you see so many more companies?
Chad Weinman: That’s how I got into this. I started earlier in my career in the big four accounting and auditing firms and professional services. I was an IT auditor at the time when it was the thing. I went into it not knowing what it was, nobody could tell me what it was, and then it became a big thing.
I remember having a pretty strong technology background from programming and other experiences beforehand. I was auditing a large organization in their environment and coming up with a list of findings. I went to a meeting with this person who was very experienced and had been managing teams and thousands of systems for a decade. I went to him very naively and said, “Well, I’ve got a list of risks here for you.” I started going through all these findings and saying, “Well, this is wrong, and this is bad, and this is a risk.”
He was like, “I can tell you 1,299 reasons why those things do not matter and represent almost zero risk.” The reality is, because I had a technology background, I kind of knew he was right. I was like, “I can’t defend this.” These were the most minute little issues you have to deal with. But in my role, this is not the way it says it’s supposed to be, so I’m writing this up as a finding and this is a “risk.”
To me, that was something that bothered me. It bothered me that I felt like a principal grading people or a school teacher grading them. I knew what I was doing was lacking critical thinking or defensibility. That’s kind of where I learned that risk is that thing that takes the next step and really understands how much does that matter.
Then I found out how risk was done, and it was like, “Oh no, it’s not very good.” Then I kind of got into pushing the envelope there and trying to innovate. Compliance is necessary and it’s important, but it is definitely not risk. Not all findings are created equal.
Manoj Tandon: I’m so glad you’re saying this, because when we go in and talk to management teams, a lot of times they’re like, “Well, we don’t need these things; we’re already PCI compliant. We already have our SOC 2. We have sufficient controls.” But then we always like to point out, let’s look at JPMorgan Chase: they got breached. CNA: they got breached. Yahoo: three billion records, they got breached. Target, Home Depot, pick a company, they all got breached. Every one of those companies was compliant with all the compliances. All the things you can do and check all the boxes, and that doesn’t equate to good cybersecurity or understanding of the risk.
To me, checking the boxes is foundational, baseline. We have to do it. But if you want to really get into adding value in the security field, it’s how are you going to minimize the impact, respond really efficiently, or understand how do you reduce the probability of things materializing? Checking the boxes is not going to prevent it from happening. It’s never going to make you perfectly secure.
Chad Weinman: It’s not going to help you recover quickly, respond, or identify it. It is something you need to do as a starting point, but by no means is it the finish line.
Manoj Tandon: So tell us a little bit about FAIR. What is the organization and what are its origins?
Chad Weinman: FAIR is a model for defining and measuring cybersecurity risk. It was created, I’m based in Columbus, Ohio, and it was actually created within the city of Columbus a long time ago with our founder and the gentleman who invented FAIR named Jack Jones.
He found himself, and this is a good story for all you salespeople or people talking about cybersecurity, as a new CISO of a very large insurance company in town, putting together a cybersecurity budget, a plan, and a strategy, and then going to beg for money to get this plan in place and execute. Remember, it’s an insurance company, so luckily they are very intelligent about what risk is.
They started asking some questions about security, such as, “How much risk do we have?” Like most people in security today, he would say, “Lots.” They were like, “That’s not a very good answer. If we give you these millions and millions of dollars, how much less risk will we have?” He shrugged his shoulders and, as he tells the story, he said, “Well, less.”
Now, if he wanted to rattle off the threats they face or the vulnerabilities they have, all these meaningless metrics that are very cyber-specific, to business executives and people that understand risk and insurance, those are very legitimate questions that he couldn’t answer. It goes back to this challenge we have in security of relying too much on FUD, fear, uncertainty, and doubt, to try to get what we want.
That was about 20 years ago. FAIR has been growing, and it was created as an international standard by a standards organization known as the Open Group. It’s got a community right now that has over 10,000 members globally and chapters around the world. It’s becoming this predominant model for cybersecurity about how you measure and assess risk quantitatively, predominantly in business terms. That means we actually measure it with data, not just a finger in the wind saying, “It feels medium to me.”
RiskLens, the company I’m part of, our co-founder was the gentleman who started this train, but we are really there to help scale that model into a large enterprise. That means a platform and strategies: people, process, and platform. Building it into something that can scale, because you can’t spend weeks quantifying risk; you need to do it in hours or a day depending on the decision. To do that means you’ve got to have the right processes in place, the right data, and the right platform. Underpinning everything we do is this standard model known as FAIR.
Manoj Tandon: Could you walk us through a simple layman’s exercise on how a company would quantify risk? What are the steps? I know there’s a lot of mathematics involved, but walk us through a sample example. Let’s say a company is concerned about ransomware. They’re going to get hit by WannaCry because they don’t know how many unpatched systems they have out there.
Chad Weinman: The first thing is what we talked about earlier: defining what it is we’re measuring, or scoping the assessment. What are we worried about? All right, we’re worried about the unavailability of critical systems from malware like ransomware. Who’s the actor? It’s not going to be an insider; it’s going to be some cybercriminal out there that’s holding you ransom, financially motivated.
So now we know the scenario we’re looking at. What are the assets or systems we’re worried about targeting? Usually it starts at a laptop or some endpoint and then propagates into a shared drive environment. What are the assets or systems we’re worried about, usually ones that we rely on to support our operations and our business?
Once we’ve scoped it out, then we move on to the next stage, which is starting the analysis where we start looking for data. What are the controls and the data points we have in place? How often are we seeing malware or phishing attacks coming into the system? What are the controls in place that we have to make us less susceptible to them?
We start analyzing and collecting data to measure the probability that ransomware may impact us. We also collect data on if it were to impact us, what does that loss look like? What are the teams we’re going to have responding? What are the recovery timeframes we think we’ll have in place? What are the impacts to our revenue, our reputation, and our contractual obligations? What does that look like from a loss perspective?
Once we’ve collected that data, we feed that into the RiskLens platform, as an example, to run the assessment. Then out come the results. Before we go presenting them, we obviously do a QA. The next step, which is important for the people running the assessment, is: all right, we’ve run it, and we see this result set in front of us. Here’s how much risk it represents to the organization. Before we go presenting it and getting tough questions, let’s try to poke holes in ourselves. Can we defend this likelihood? Can we defend this impact? Can we understand what’s driving it? If it’s high or if it’s surprisingly low, why?
We want to think ahead about the answers to the questions we’re likely to be asked, and then we put that together in a presentation and go communicate. That’s the standard identify, analyze, and communicate the results process of a general risk assessment or risk management process.
The one thing that we do a lot in RiskLens with FAIR is, I find one of the biggest problems I have with risk is we almost stop halfway to adding value. Just telling the organization this is a lot of risk or a little risk tells them what’s important and what’s not, but what we can do when we quantify and apply data is we can also tell them, “By the way, if you implement this new control or this preventative technology, what does that do to our level of exposure and risk?”
If we say, “Hey, ransomware represents 1.5 million dollars of exposure to the organization each year,” by implementing this additional email filtering or malware protection service, we can reduce that exposure by forecasting it down to $300,000 a year. Now we’re actually helping do what risk management is supposed to do, which is help drive decisions or actions to manage risk.
Answering the “how much” question is half of the story that we like to tell at RiskLens. The other is, “What are we going to do about it?” When you present that to the business, you’re not just saying, “Do this, do this, do this,” but you’re saying, “Here’s how much it represents today, and here’s how much it will once we implement this process, control, or technology.” Now you’re enabling or encouraging them to make decisions, and that’s where we add value.
Manoj Tandon: As you were describing this, the word that came to my mind was that there’s a lot of guesstimation that might have to take place because of some of these things. If we got hit by ransomware, what does that mean? How much downtime is there? Who all could be impacted? This isn’t a black and white thing. It seems like you could have a continuum of values.
Chad Weinman: That is a hundred percent true, and it’s probably the first misconception people have when we say, “Oh, we quantify risk into dollars and cents.” They’re like, “BS, I don’t believe it.” It’s almost always not because that person wants to be a jerk; it’s because they have misconceptions about how we do it.
Listen, if I can predict the future with perfect data and perfect analysis to have a perfect outlook, I wouldn’t be in this business. I would be down at the casino, at the horse track, or retired right now.
Let me ask you a quick question. Because we’re remote and I’m on video right now, I want you to guess exactly how tall I am. You’ve seen this room and know the dimensions of that picture. How tall am I? Guesstimate.
Manoj Tandon: 5’10” to 6’1″.
Chad Weinman: All right, you have a nice wine collection there at Dark Rhino. Do you want to bet half your wine collection that I’m between 5’10” and 6’1″? Would you bet the entire collection? There are a lot of employees that might be upset if you’re wrong.
Manoj Tandon: I don’t drink wine, so I’m going to say the heck with them.
Chad Weinman: Normally, if you had a vested interest in this, no way. And by the way, you didn’t give me a precise guess, you gave me a range. That’s the thing. People assume that we come out with an exact number. “Oh, it’s going to be exactly 1.5 million.” I can’t give you that. I can estimate.
But there are definitely things in cyber where it’s an event that’s never happened or a place where we have really bad data. We have to be okay with the fact that there is no precise measurement and that there’s a wide range of possible outcomes. That’s something you can learn and train on, but there’s uncertainty in any form of risk.
Usually when we talk about quantification, people get very uncomfortable. But how else do they look at risk today? They say, “Ah, seems medium, seems high.” What does that mean? If I try to pin you down and put a definition on it, you’re going to start squirming. They conveniently use a qualitative, subjective word like “medium” so they don’t have to acknowledge the fact that they don’t actually know.
When you quantify, it just brings it out to where we say, “Listen, these are the places where we have good data and good understanding and good confidence, and here are places where we don’t.” The thing about applying risk in cybersecurity is how much data could we have? You can look at insurance for hurricanes where you have hundreds of years of data. By the way, when you project a hurricane, it doesn’t say, “Oh look, they put plywood up, let me change direction and wind speed to go around it.” But the kind of threats we face are humans. “Oh, I see what they put in place. Guess what? I’m going to change my tactics; I’m going to change my direction.”
We have a different threat landscape than other forms of insurance have. To me, it’s not to say it’s easier, it’s not, it’s harder, but it’s by all means possible. It’s just how you approach it.
Manoj Tandon: I’ll tell you, there are a lot of organizations out there providing their clients a risk score kind of like your credit score. That’s great, it’s wonderful, but aren’t they doing the industry a little bit of an injustice here?
Chad Weinman: It depends. It’s a sliding scale. Saying you’re low, medium, or high isn’t really all that valuable. You’re in one of three buckets. Saying, “Okay, out of a score of a thousand, you’re 462,” tells me a little more data, but what are you going to do about it?
What are the options for a CISO? “We need to do what?” Well, that doesn’t seem great. We want to improve that. How are you going to improve that? People, process, and technology. All right, what do all of those three things take? They’re all resources. We’re going to put resources to it: new controls, new technologies, or new team members. What does all that take? Money.
So what are we really talking about? Money. Imagine I came to you and I said I work for Titleist. In my basement last night, I created the greatest new driver, the best driver you’ve ever hit. As the CEO, the entire company has to put all our efforts behind this new driver. You’re a golfer and a CEO. What are you going to ask me about this driver I’m raving about?
Manoj Tandon: You’re going to want to know how much of an improvement in yardage you’re likely to get, and then what have you done to it.
Chad Weinman: Exactly. If I tell you I’ve done a lot, and I’ve got a medium-high feeling you’re going to hit the ball farther, and I’ve got a moderate-to-low amount of confidence we’re going to sell more drivers, are you going to take that seriously? You’re going to laugh me out of the room.
But that’s literally the conversation, if we’re honest about ourselves, that we have in security. “I need another $400,000.” “Why?” “I have to implement a control.” “What’s it going to do?” “Well, we’ve got this high risk and I hope I’m going to make it medium.”
It’s not that we’re quantifying in dollars just to do it. We’re doing it because that is the unit of measure by which we’re evaluating cost-benefit. Every investment we’re making is really going to take money, people, and time. We have a responsibility to the organization to say, before we spend money on those resources, what is that going to do, and is that a smart business decision?
The only way to do that, I would argue, is quantification, talking about it in business terms, in dollars and cents or euros. Something that’s monetary and valuable to them, apples to apples. If I give you a score and I say, “Okay, we’re at 642, and if you do these things and you spend a million dollars, you’ll get it down to a 486,” if you’re a CFO, is that a good answer? No. I want to know if that is worth a million dollars.
I’m willing to accept anything that’s adding more data and more rigor, but I feel like any time you’re still talking about scores or ratings, you’re falling short of trying to answer the question, “Is this a good business decision?” If you can take that more rigorous approach but talk about it in the same unit of measure as the investment you’re looking for, then you can help the business make a well-informed decision. That to me is the key differentiation that we do and that FAIR, as a model, is looking to do beyond just scores.
Manoj Tandon: Can you give any examples or stories where companies have gone through a FAIR-based approach and materially changed their direction?
Chad Weinman: There are a lot. I’ll cherry-pick a few. A smaller hospital system recently told us that they were able to make a better case to their board to get additional funding for a security investment that wasn’t budgeted, which they’re pretty confident they would have never done before they were able to quantify risk.
The reason is not just because they were throwing around dollars and cents. It’s because they felt they could talk to the business in a language they understood and explain why that investment was going to reduce risk.
We have another organization that’s able to present to their board of directors and explain cyber in a way that business people understand, because that board is not stacked with cyber people. Coming out of the last year, there isn’t this endless pot of gold for cyber spending that there once was. The business is going to ask and expect more questions to justify that spending.
Everyone is trying to more closely guard their cybersecurity budget. A big use case for us is taking their big initiatives and their cyber investments and being able to explain how those are going to present value to the business, meaning how they’re going to reduce risk and why they’re valuable uses of resources.
CIOs and technology leaders are going to talk about gaining efficiency, faster delivery, and more value. Our security value proposition is protecting customers, protecting the organization, and preventing bad things from happening. If we can tell that same story but say, “We saved the organization this amount of fraud loss or lost revenue from outages because we’re better protecting the organization,” that’s the discussion we need to have.
Manoj Tandon: The small health system story is very powerful. Twenty percent of Dark Rhino’s revenue is from healthcare companies, and we often find that those CISOs are competing against life-saving equipment. Do we spend $4 million on a new MRI unit, or do we put $500,000 into a new EDR platform? Somewhere, that reconciliation happens and that question comes up. If one can explain in dollars and cents what this truly means to the operational effectiveness of the hospital, management might be more apt to listen.
Chad Weinman: It won’t be precise, but it gives a range of outcomes that helps them be more informed and come to a well-informed decision. That’s all we’re trying to do.
Manoj Tandon: Chad, I know we’re coming up on the hour. Time went by so fast. Give us some things you’d like to plug: any events, books, or presentations you guys are doing? Anything new and notable coming out that you’d like everybody to know?
Chad Weinman: Obviously, from a platform standpoint, I’ve been with the company for over 10 years from the very start, and some things that have come out recently in the platform are some of the biggest advancements we’ve done in the last decade by far. What we have coming out, I’ve never been more excited about what we’re seeing happen. The momentum in the market right now is truly exciting.
We have an active blog and a lot of case studies at risklens.com, so I’ll shill that as expected. But I will tell you, assuming your audience has a lot of practitioners and salespeople, as a cybersecurity professional, one of the strongest things I got from this is a better understanding of how to communicate and understand security and risk, because they’re synonymous.
Instead of just saying technical things, be able to communicate more effectively, especially with business people, and talk about the value of security that comes from understanding risk. One of the things I would point those people to is the FAIR Institute, which is that community of over 10,000 people learning about the FAIR model. There are communities, interest groups, a blog, tons of write-ups, and more at fairinstitute.org.
Then on top of it, training and education. Usually people have funds and resources and wonder what they’re going to learn and how they’ll grow professionally in the next year. I can’t think of something better. The feedback we get from people in security, whether they’re risk professionals or not, is that they get better at understanding and communicating risk. It’s so foundational.
We train thousands of people a year, online, hybrid, and in person, in many different formats. Spend a few days and learn about this. Even if you’re in sales, learn about risk. It will help you communicate better with your prospects and help you communicate the value of what you’re trying to accomplish or bring to the market. So I definitely would highly encourage training as a first step for anybody.
Manoj Tandon: Well, maybe at some point we can do a little mini-series with you guys and take people through it. Next week you do Wine Wednesdays and Risk.
Chad Weinman: That is a really good concept.
Manoj Tandon: When the new studio is up and running and some of these COVID restrictions come to an end, I think it’ll be a great concept. We used to do Whiteboard and Whiskey Friday.
Chad Weinman: There you go. I love it.
Manoj Tandon: Well, that was a thing, and then COVID came along and pretty much killed that, which is why we have all that booze in the office. People come into the office and ask, “Are you guys a bunch of alcoholics?” It’s like, “No, no, it was a Whiskey and Whiteboards thing.” The whole idea was to get our customers together every Friday late afternoon and give them a chance to talk to each other, get us out of the way so we’re not selling anything. We were trying to foster a cybersecurity community in Dublin and Columbus, get them to talk to each other, and perhaps have a glass or two of an allocated bourbon they wouldn’t be able to buy on the open market.
Chad Weinman: It’s great. Every city I go to, there’s always a great opportunity to have a good community of people that can share ideas, thoughts, and news updates. It’s always good to stay close in your communities. Whenever it’s whiskey or wine, sign me up. I’ll be there.
Manoj Tandon: We’re going to take you up on that, believe me. So with that, everyone, we’re going to sign off. Thanks again, Chad, for joining us. It’s been a real pleasure.
Chad Weinman: Absolutely. If anybody found it interesting or wants to talk more about it, I’m on LinkedIn, so feel free to hit me up.
Manoj Tandon: We will put your LinkedIn profile in the show notes with a direct link to it. And if you can send me your blog link, I’ll put that in the show notes.
To learn more about Chad Weinman
To learn more about Risk Lens
To learn more about FAIR
Check out the other episodes in Season 4:
Ep. 0 Dark Rhino Security – Cyber Basics: The Rundown on Ransomware
Ep. 1 Rob Duhart Jr – In Cybersecurity There are Builders and Breakers, You Need Both!
Ep. 2 Rob Oden – Is a Traditional Computer Science path necessary for Cybersecurity?
Ep. 3 Chad Weinman – Compliance does not correlate to Cybersecurity
Ep. 4 Rob Oden (part 2) – Should the office of the CISO be separate from IT?
Ep. 5 Ross Young – Foreign Cyber Espionage Capabilities
Ep. 6 Ilya Bodner – How to land your first customer
Ep. 7 Samara Williams – Why is there a lack of people going into STEM?
Ep. 8 Amelia Jarboe – A passion for protecting people with Cybersecurity
Ep. 9 Hans Vargas-Silva – Compliance is a low bar for Cybersecurity
Ep. 10 Fredrik Oedegaardstuen – Cautionary advice on Automation
About Chad Weinman

Chad Weinman is a cybersecurity risk expert and leader at RiskLens, where he helps organizations quantify cyber risk in clear business terms.
With a background spanning IT audit, compliance, and risk analysis, he is known for translating complex security issues into practical, defensible decisions executives can act on.
Chad is a strong advocate for moving beyond check-the-box compliance and toward measurable, data-driven risk management, with a focus on helping security teams communicate value to the business.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
