This is Cyber Smokehouse. Join Ernie and Graeme as they grill the minds, dig into the experience, and serve up the stories of leaders in cybersecurity. Cyber Smokehouse is sponsored by TBDCyber, a cybersecurity strategy consulting firm.
All Episodes

Latest Episodes

All Episodes
#26

Protecting Delivery and Outcomes - Chris Logan - Cyber Smokehouse - Episode #26

Take your cybersecurity strategy to the next level with powerful insights on securing modern healthcare delivery, bridging the digital divide, and translating complex security tech into executive business language. It’s time to rethink patient care availability, move beyond legacy castle-and-moat models, and adopt platform-based zero trust architectures. Who better to guide you through it than U.S. Marine Corps veteran, published author, and Healthcare CISO at Zscaler, Chris Logan? You will learn how ambient AI is transforming clinical workflows, why health systems must consolidate point solutions into platform security to speed up M&A, and how servant leadership builds resilient, high-performing security teams. Get motivated to speak the language of business executives, protect critical patient care environments, and open career doors for the next generation of cyber leaders! Takeaways: Securing Care Everywhere: Healthcare has shifted from hospital-centric care to decentralized delivery across home, mobile, and wearable devices, making system availability vital to preventing negative patient outcomes. Leading with Business Outcomes Over Tech: Security leaders must frame investments in terms of clinical continuity, patient care, and revenue impact rather than technical jargon to win CFO and board support. The Rise of Ambient AI in Clinics: Ambient AI listening tools are relieving clinicians of manual EMR documentation during visits, restoring eye contact and the human relationship between doctor and patient. Platform Consolidation vs. Point Solution Noise: Health systems need platform-based security and the "80/20 rule" to reduce software sprawl, cut costs, and shorten clinic onboarding times from 18 months down to weeks. Servant Leadership & "Good Leaders Eat Last": True cyber leadership requires approachability, conducting skip-level check-ins, allowing teams room to fail forward, and opening doors for others to grow. Quote of the Show: "If you lead with technology when speaking to your board or CFO, you've already failed. They don't care about the technology, they care about the business outcome." - Chris Logan Links: LinkedIn: https://www.linkedin.com/in/logancm/ Website: https://www.zscaler.com Email: clogan@zscaler.com  christopherm.logan@gmail.com  Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#26

Retiring from Risk - Scott Barronton - Cyber Smokehouse - Episode #26

Take your understanding of cybersecurity risk, organizational alignment, and executive career pivots to the next level with powerful insights from a 30-year industry veteran! It’s time to rethink the evolving personal liability of CISOs, how to effectively communicate cyber risk to non-technical business leaders, and what it really takes to walk away and build a successful second-act venture. Who better to guide you through it than former CISO at Finastra and Diebold Nixdorf, and co-founder and Chief Travel Officer at Sunshine Travelers Experiences, Scott Berrington? In this episode, you will learn how the rapid influx of emerging tech like AI creates mounting operational risk, the pros and cons of different CISO reporting structures, and strategies for providing true security assurance to demanding global clients. Get motivated to build empowered, self-sufficient security teams, navigate executive burnout, and turn your lifelong passions into your next big career milestone! Takeaways: The Shifting Risk-Reward Matrix for CISOs: Increasing personal and criminal liability for CISOs, coupled with 24/7/365 operational burnout, is causing many seasoned security leaders to rethink the CISO role. Emerging Tech & AI Disruption: Business leaders often adopt fast-moving technologies like AI for efficiency without fully understanding the rapid, potent risks involved, leaving CISOs to clean up structural mistakes. Optimal Security Reporting Lines: Security functions operate best when reporting to a Chief Risk Officer or Chief Legal Officer due to shared risk frameworks, whereas reporting to a CIO or CFO often introduces budget and operational friction. Proactive Customer Assurance: Rather than waiting for demanding enterprise clients to audit your environment, presenting a comprehensive, tailored security program builds deep customer trust and streamlines compliance. Delegation with Accountability: Effective leadership means giving direct reports full authority to execute while keeping a "quick hook" offline to coach them gently without destroying their internal credibility. Quote of the Show: “I was proud when I got my first CISO role, but there’s no type of pride like being an entrepreneur and taking that role of trying to build something from scratch.” - Scott Barronton Links: LinkedIn: https://www.linkedin.com/in/scottbarronton/   https://www.linkedin.com/company/sunshine-travelers-experiences/home/ Website: https://www.sunshinetravelersexperiences.com/ Podcast Link: https://podcasts.apple.com/us/podcast/sunshine-travelers-podcast/id1683937797 Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#25

Identity, Patching, and Zero-Downtime Security - Keith Lawson - Cyber Smokehouse - Episode #25

Take your cybersecurity operations to the next level with powerful insights on managing high-volume vulnerability patches, securing healthcare IT/OT environments, and applying deep reinforcement learning to autonomous defense. It’s time to move beyond reactive security measures and build resilient, zero-downtime systems in live, life-safety environments. Who better to guide you through it than healthcare CISO, critical infrastructure veteran, and University of Michigan-Dearborn researcher, Keith Lawson? You will learn how the surge in AI coding agents is driving a "tsunami" of software patches, strategies for managing identity as the modern perimeter, and how autonomous AI agents can adapt in real time to protect critical infrastructure. Get motivated to foster a zero-blame, collaborative culture that empowers your technical and non-technical teams to solve complex security challenges together. Takeaways: The Vulnerability Tsunami: The adoption of AI coding agents by software vendors is generating a massive wave of bug fixes and corresponding exploits, requiring organizations to automate testing and speed up patching cycles. Identity as the Modern Perimeter: As healthcare and enterprise data shift to cloud and SaaS environments, human vulnerabilities and weak identity controls, rather than traditional network perimeters, have become the primary target for social engineering and exploitation. Zero-Downtime Patching in Healthcare: Securing complex hospital networks (spanning medical IoT, legacy software, and life-critical devices) requires strict pre-planning, automated testing, and a zero-tolerance approach for service disruptions. Applied Reinforcement Learning: Unlike static large language models (LLMs), reinforcement learning enables real-time, continuous online learning for autonomous cyber defense against zero-day threats. Fostering a Zero-Blame Culture: Effective security leadership relies on open collaboration, empowering staff across all departments, and maintaining a transparent, zero-blame environment so teams can report mistakes and fix root causes fast. Quote of the Show: "In security, I think open honesty and sharing is the best thing that we can do... To me, security is a team sport." - Keith Lawson Links: LinkedIn: https://www.linkedin.com/in/j-keith-lawson/ Website: blog.9600baud.net http://www.lhsc.on.ca Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#24

Humans Still Win at Security - Shannon Garcia - Cyber Smokehouse - Episode #24

Get ready to challenge everything you assume about AI's role in cybersecurity. Shannon Garcia, founder of Strategic Defense and a veteran red team leader with stops at Trustwave, SecureWorks, IBM, and Kudelski Security, joins the Cyber Smokehouse to break down why manual, human-led penetration testing still outperforms automated AI tools, and why that might not last forever. You'll learn how shadow IT quietly drains company budgets, why remote work has changed both testing methodology and phishing success rates, and how translating technical findings into business language can protect million-dollar contracts. Plus, Shannon shares her unlikely path from 11 years as an AMD engineer to building two cybersecurity companies from scratch. Takeaways: AI is reshaping conversations across cybersecurity, but Shannon's teams still rely on manual, human-led penetration testing. She notes that automated AI pen testing platforms can't yet handle certain test types, like wireless assessments, and that clients often value the real-time communication a human tester provides over an automated tool. Shadow IT remains a persistent and growing risk, not just from a security standpoint but from a business one. Shannon points out that when business units are given autonomy to buy and deploy their own tools, companies can end up bleeding money on redundant or unnecessary licensing without realizing it. Remote work has changed both how testing gets done and how social engineering performs. Without a traditional office network to test, engagements now lean heavily on VPN and SaaS-based access reviews, and Shannon has found that phishing and vishing success rates drop significantly when employees work from home and simply don't answer the phone. Shannon describes her leadership style as people-first and curiosity-driven. She asks her team detailed questions not to micromanage, but to genuinely understand their thought process and challenges, which she says helps her advocate for them with clients. Translating technical findings for non-technical executives has been one of Shannon's most valuable skills. She frames security findings in terms of business risk and cost avoidance rather than pure ROI, which has directly helped clients unblock stalled contracts tied to security requirements. Shannon transitioned into cybersecurity after being laid off from an 11-year engineering career at AMD in 2012. Her advice to newcomers is to recognize the transferable soft skills they already have, since communication and reliability matter as much as technical ability when building a career in the field. Looking ahead, Shannon is considering a potential acquisition to expand her pen testing company's capabilities, while continuing to grow her AppSec-focused company's response to AI-driven risk in the software development lifecycle. She also has a long-planned mentorship program for aspiring cybersecurity practice leads still in development. Quote of the Show: “The thing that I love the most about running my own business is I don't have to ask for permission.” - Shannon Garcia Links: LinkedIn: https://www.linkedin.com/in/shannongarcia/ Website: strategicdefense.co Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550 
#23

Building Better Security Leaders - Ward Balcerzak - Cyber Smokehouse - Episode #23

Strong cybersecurity programs aren't built through quick fixes, they're built through thoughtful leadership, patient execution, and investing in people. In this episode of Cyber Smokehouse, Ernie Anderson and Graeme Payne sit down with Ward Balcerzak, Field CISO at Sentra, to discuss what effective security leadership looks like in today's rapidly evolving landscape. Ward shares lessons from building security programs, mentoring future leaders, adopting AI responsibly, and helping organizations avoid reactive decision-making. From creating realistic AI roadmaps to developing cybersecurity talent and leading through change, this conversation offers practical guidance for security leaders focused on building resilient organizations for the long term. Takeaways: Successful AI adoption requires thoughtful planning rather than rushed implementation. Ward explains that many organizations are reacting to AI with unrealistic timelines and expectations. Leaders should slow down, identify their objectives, understand their gaps, and build a roadmap instead of treating AI as an overnight transformation. Effective security leaders know when to slow momentum without stopping progress. Rather than simply saying "no" to new initiatives, Ward advocates helping the business move forward responsibly by balancing innovation with practical execution and demonstrating measurable progress along the way. AI should eliminate repetitive work, not cybersecurity careers. Ward predicts entry-level analyst responsibilities will become increasingly automated, allowing security professionals to develop higher-value technical and strategic skills instead of spending time on repetitive manual tasks. Cybersecurity professionals should proactively develop new skills as technology evolves. Rather than fearing AI, Ward encourages practitioners to seek additional projects, expand their expertise, and have ongoing career conversations with leadership to remain valuable contributors. Networking has become one of the most valuable career investments in cybersecurity. Technical knowledge alone is no longer enough. Building relationships, participating in industry events, and maintaining an active professional network create opportunities that certifications alone often cannot provide. Leadership requires making difficult decisions with empathy. Ward reflects on both hiring and performance management, acknowledging that leaders often want to help people personally while still making decisions that are best for the organization. Quote of the Show: “Take a breath, zoom out, figure out what you're actually trying to accomplish.” -  Ward Balcerzak Links: LinkedIn: https://www.linkedin.com/in/ward-balcerzak/ Website: https://www.sentra.io/ Ways to Tune In: Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0  Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297  Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47  iHeart Radio: https://iheart.com/podcast/319629841/  Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550