This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Greg Schaffer. Greg founded vCISO Services in 2017 to help SMBs. He has over 33 years of experience in IT and security, including over 15 years at the CISO level. Greg is the host of the virtual CISO moment podcast and authored information security for small and mid-sized businesses.
Chapter Titles:
00:00 introduction
01:37 How did you get into Cyber?
04:40 What brought you to SMB?
07:00 Equifax Breach
10:30 Defense in Depth
13:05 Doing more than just checking the boxes
19:40 Cyber insurance
24:00 Some ways SMBs get breached
28:00 Ransomware
30:40 SMB: What to do if you don’t have the resources?
36:44 How much money should SMBs spend on cybersecurity?
38:24 Should the CISO work for the CIO?
42:17 Metrics for decision-makers
45:20 Russians and the Chinese
49:00 Meeting Greg
Audio:
Important Links:
Transcipt
Manoj Tandon:
Hello everyone, and welcome to another episode of Dark Rhino Security: Security Confidential. Today we have another great guest with us, and we’re honored to have Greg Schaffer joining us. Greg is the founder of vCISO Services, which he started in 2017 to help small and mid-sized businesses. He has over 30 years of experience in IT and security, with about 15 of those at the CISO level. He’s also the host of the Virtual CISO Moment podcast—definitely worth checking out—and the author of Information Security for Small and Mid-Sized Businesses. Greg, it’s great to have you on the show. Thank you so much for joining us.
Greg Schaffer:
Thank you for having me. It’s great to be on the other side for once and actually answering the questions.
Manoj Tandon:
I always enjoy having other podcast hosts on—it makes my job easier, and I know the audience will benefit from your perspective. Our audience is largely small and mid-sized businesses, and cybersecurity is a major concern for them, so we like bringing in experts who understand their challenges. Before we get into that, though, how did you get into cybersecurity in the first place?
Greg Schaffer:
It was kind of by accident—I just knew I didn’t want to work at Burger King. I was a student at the University at Buffalo back in 1989, before the internet was really a thing. The campus computing center had a part-time job opening for a network technician, and I figured I’d probably learn something. At the time, my only computer experience was programming in Fortran as an engineering student. I started in aerospace engineering, but when the Cold War ended, that job market dried up, so I switched to mechanical.
I was also in the Air Force Reserve, and the person interviewing me was a former Marine Corps drill sergeant—pretty intimidating. But he hired me and said something that stuck: if you can follow technical orders to fix airplanes, you can figure out networking. And here I am, 30-plus years later.
Manoj Tandon:
That’s an incredible story. And I love that point—back then, there wasn’t a defined “cyber path” like today. Did your Air Force experience translate into cybersecurity at all?
Greg Schaffer:
Not directly—I was an aircraft mechanic and spent time in Desert Storm—but the troubleshooting mindset absolutely carried over. Whether you’re diagnosing an aircraft issue or a network problem, it’s about following a process, understanding systems, and thinking logically. That foundation translates very well into cybersecurity.
Manoj Tandon:
That makes a lot of sense. So what led you specifically to focus on small and mid-sized businesses instead of staying in enterprise?
Greg Schaffer:
It really felt like a calling. I spent most of my career in larger organizations—higher education, government, even served as the first CISO for Nashville-Davidson County after a major breach, and later worked in banking. Over time, I realized SMBs didn’t have access to the kind of experience I had built over the years.
At the same time, the virtual CISO space was just starting to emerge. I felt like I could make a bigger impact helping smaller organizations that otherwise wouldn’t have access to that level of expertise. So I made the jump, and it’s been the best decision I’ve made. Everything I do now—my company, my podcast—is centered around helping SMBs and those who support them.
Manoj Tandon:
That’s fantastic. I actually listened to your “origins” episode, and one thing that stood out was your emphasis on the “why” behind cybersecurity. You mentioned there’s a gap in SMBs between technical controls and integrating security into the business. Can you expand on that?
Greg Schaffer:
Absolutely. A lot of organizations still view security as purely technical—firewalls, antivirus, logs—but that’s only part of the picture. I like to frame it using the “three lines of defense” model. The first line is technical controls, the second is risk management, and the third is audit.
The gap, especially in SMBs, is in that second line—risk management. They’re not thinking about how security ties into business processes, strategy, and decision-making. Cybersecurity is often seen as a cost center, but it’s really about avoiding loss and enabling the business.
Information security is broader than cybersecurity—it includes people, processes, business continuity, and risk management. SMBs often focus only on the technical side and miss the bigger picture.
Manoj Tandon:
That aligns with what we see all the time. Many businesses think, “We have a firewall, we’re good.” But they’re missing the human and process elements.
Greg Schaffer:
Exactly. And even large organizations fall into that trap. I’ve seen cases where highly mature companies with multiple CISOs and strong controls still fail because of process gaps. Security isn’t just about tools—it’s about how everything works together.
Manoj Tandon:
Let’s talk about compliance. A lot of SMBs say, “We’re compliant, so we’re secure.” What’s your take on that?
Greg Schaffer:
Compliance is not security—it’s just a baseline. It can be a good starting point, but if your only goal is to check boxes, you’re not building a real security program. In fact, my firm won’t work with organizations that only care about compliance.
You have to live and breathe security as part of the business. Compliance might get you in the door, but it’s not the end goal. Without executive buy-in and a real commitment to integrating security into the business, the program won’t be effective.
Manoj Tandon:
That leads into another common mindset: “We’ll just rely on cyber insurance.” What do you say to that?
Greg Schaffer:
That’s a dangerous approach. Cyber insurance is part of a broader strategy, but it’s not a substitute for controls. You still own the risk—you’re just transferring part of the financial impact.
Insurance companies are also getting stricter. They’re evaluating controls more closely before underwriting policies. And even then, insurance should be the last line of defense—not the first.
Relying on minimal controls and insurance won’t put you in the winner’s circle.
Manoj Tandon:
What about common attack vectors? What are you seeing most often in SMBs?
Greg Schaffer:
The number one is still people clicking on things—phishing. It’s the easiest entry point. There’s always debate about whether to focus on user training or technical controls, but the reality is you need both.
You also need to assume something will get through. That’s why incident response planning is critical. We run ransomware tabletop exercises with clients because many organizations haven’t thought through what they’d actually do in that scenario.
Ransomware today isn’t just encryption—it’s data exfiltration and extortion. If you don’t have a plan, you’re making decisions under pressure, and that’s the worst time to do it.
Manoj Tandon:
Let’s touch on that—should companies pay the ransom?
Greg Schaffer:
I don’t like paying ransom because it fuels the ecosystem. But it’s not a black-and-white decision. If the choice is paying or going out of business, you may have no choice.
Ultimately, it’s a business decision, not a security decision. My role is to provide risk-based guidance. The board and executives have to decide.
The best strategy is to never be in that position in the first place.
Manoj Tandon:
That’s a great way to put it. Now, for SMBs trying to cut through all the noise—tools, vendors, frameworks—where should they start?
Greg Schaffer:
Honestly, they should consider bringing in outside expertise, like a virtual CISO. Most SMBs don’t have the internal resources to build and manage a full security program.
One of the biggest risks I see is bad advice. There are a lot of people selling solutions, but not all of them understand risk management. A good advisor helps translate business risk into actionable strategy—not just recommend tools.
It’s no different than hiring a CPA or a lawyer. You need a specialist.
Manoj Tandon:
That’s a great analogy. Before we wrap up, one last question—should SMBs care about geopolitical threats like Russia or China?
Greg Schaffer:
Absolutely. The threat landscape is heavily influenced by global events. Even if you’re a small business, you can be impacted—directly or indirectly—through supply chains, phishing campaigns, or broader cyber activity.
Understanding the “why” behind threats helps you understand the “so what” for your business. That awareness should inform your risk decisions and security investments.
Manoj Tandon:
That’s a great note to end on. Greg, thank you so much for joining us—this was an incredibly insightful conversation.
Greg Schaffer:
Thank you, Manoj. I really enjoyed it.
Manoj Tandon:
And thanks to everyone listening—we’ll see you next time.
CU Intersect conference is July 18-20.
Greg’s podcast
Gregs Book
To learn more about Greg visit LinkedIn
Check out the other episodes in Season 6:
Ep. 0 Bonus: Why do People Get Hacked?
Ep. 1 Brian Stoner – VP of StellarCyber
Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity
Ep. 3 Tim Chase – Ethical Hacker, CISO
Ep. 4 Brian Haugli – CEO of SideChannel
Ep. 5 Nat Schere – Cybersecurity as a revenue
Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity
Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive
Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur
Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host
Ep. 10 Jake Belcher – Sr. Director of Security Strategy
About Greg Schaffer

Greg founded vCISO Services in 2017 to help SMBs.
He has over 33 years of experience in IT and security, including over 15 years at the CISO level.
Greg is the host of the virtual CISO moment podcast and authored information security for small and mid-sized businesses.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
Share and spread the word!
