- CISO Series Newsletter
- Posts
- Join us tomorrow for "Hacking the SMB Security Gap"
Join us tomorrow for "Hacking the SMB Security Gap"
Join us TOMORROW, Friday [07-31-26], for "Hacking the SMB Security Gap"
Join us Friday, July 31, 2026, for “Hacking the SMB Security Gap: An hour of critical thinking about 24/7 protection for the businesses everyone forgets.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guests Shawn Dorsey, senior director, global managed services, ThreatDown and Tom Hollingsworth, networking technology advisor, The Futurum Group. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.
Or register once for every upcoming Super Cyber Friday event. No need to sign up week to week.
Thanks to our Super Cyber Friday sponsor, ThreatDown
Defense in Depth
Why is Preventative Security So Difficult?
Prevention in cybersecurity is a lot like flossing: everyone knows they should do it, but few do it enough. What's stopping us?
Check out this post by Ross Haleliuk of Venture in Security for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Deneen DeFiore, vice president & chief information security officer, United Airlines.
Listen to the full episode here.
The sponsorship gap
Prevention depends on business teams being on board with the idea and then funding it. But that rarely happens. "Most of these folks still think security is the security team's problem and don't have accountability for the security outcomes of their decisions," said Mark Simos of Microsoft. "They are used to just blaming security when an incident happens." The people who should sponsor prevention are the same ones with deep system expertise and admin rights, he noted, yet they have little incentive to act. "The lack of incentive to do it by the people who should sponsor it and execute on it makes it extra hard/unlikely to happen." Dakota Riley of Fluidstack identified the operational requirement on the other side of that gap. Prevention demands tight integration with and working knowledge of the platforms involved, whether Kubernetes, cloud, or endpoint, "as well as taking strong ownership if things break."
One strike and you're out
Prevention carries a political cost that compounds over time. "Don't forget about the burn of political capital when the control fails and triggers an outage due to yet another bad update, human mistake, unexpected traffic or bug," said Jamil Mneimneh of Brightmind Partners. It "can happen in nearly every part of the stack," he said, "and requires knowing that and keeping some capital in the piggy bank. Emptying the bank for a preventative control that will inevitably fail is essentially gambling on how long you can take to save back up for the failure." Bryson Bort of SCYTHE reduced the whole question to a single threshold. "Security prevention only gets one strike (stopping something legitimate) before it's circumvented or removed." Marios Kyriacou of Lumo Advisors framed the investment problem as an insurance question. "Prevention is a cost with unknown value," he said. "How much money do you pour into prevention and know it's working? It's an insurance policy without a known premium."
Policy without position
Friction in prevention often starts before change management even enters the picture. "Lack of context on what to prioritize and lack of resources to actually make a change are big enough friction that can be solved before change management friction can be addressed," said Ashish Popli of Defendermate. The opportunity, he said, is "directly proportional to the level of context and automation that can reduce some of the change management friction, especially on already deployed prevention controls." Daniel Hooper, CISO at Mesh, pointed to policy enforcement as a strong driver of prevention, but named the harder step that precedes it. "You need to define your position up front. That's the hardest part. Deciding on policies that are enforceable and defensible, aligned with both technical and compliance requirements, and then maintained as systems change." What that requires, he said, is not just set-and-forget-it policies but "robust change management processes too."
Prevention isn't static
Implementing prevention mechanisms doesn't reduce the volume of threats, but it does create an ongoing obligation to keep pace with the business. "You have to constantly adjust preventative measures because your business is not static but rather a living organism," said Nikoloz Kolozk of CybersecTools. Engineers need access, customers require data sharing, business processes change, and new products are regularly onboarded. "So you need to adjust to all of the above," he said, "plus do political wrestling and consider evolving attack mechanisms - especially in large organizations."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Huge thanks to our sponsor, CoreView
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
July Reddit AMA - "I came into cybersecurity with no degree and no traditional background. Ask Me Anything."

Our monthly AMA on r/cybersecurity on Reddit has begun! Our topic is "I came into cybersecurity with no degree and no traditional background. Ask Me Anything."
This month we're spotlighting the routes into cybersecurity that skip the expected computer science degree entirely. Our participants got here through help desk roles, the military, entrepreneurship, and a few other unconventional turns, and they're ready to talk about what actually got them hired and what they wish they'd known sooner.
Please ask questions for our participants here.
This month's participants are:
David Cross, (u/MrPKI), CISO, Atlassian
Adam Arellano, (u/AdamTalksTheCybers), field CTO, Traceable AI
Krista Arndt, (u/thedrivermod), associate CISO, St. Luke's University Health Network
Mathew Biby, (u/RelativeWolf), director of cybersecurity, TixTrack
Russell Spitler, (u/Extra-Grand-1543), CEO and co-founder, Nudge Security
Mary Carmichael, (u/TheCyberAuditor), field CISO, western Canada, Bell Cyber
Thanks to all of our participants for contributing!
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Derek Fisher, director of the cyber defense and information assurance program, Temple University, and Janet Heins, CISO, ChenMed. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, PinDrop
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"New AI attack can reconstruct typed text from keyboard sounds with 90-99% accuracy" (More here)
"Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts" (More here)
"Oracle drops 1,449 security patches like it's the new normal" (More here)
Coming up on Super Cyber Friday:
[07-31-2026] - “Hacking the SMB Security Gap”
[08-07-2026] - “Hacking AI in the Loop"
Register for and add all of these events to your calendar on our Events Page.
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.






