
The Cyber Security Transformation Podcast
By Corix Partners


Series 6 - "Cybersecurity Transformation Cannot Be Reduced to a Mere Matter of Investments" - Episode 3
JC Gaillard revisits the importance trust and relationships for CISOs, looking beyond the mere justification of cybersecurity investments; read his original article on the theme here

Series 6 - "The CISO, the CSO and the Future of the Cybersecurity Organization" - Episode 2
In this second episode of Series 6, JC Gaillard revisits his views of the role of the CISO and the CSO and the real dynamics of cybersecurity transformation; read his original article on the theme here

Series 6 - "What Ever Happened with Cybersecurity Strategic Thinking?" - Episode 1
JC Gaillard introduces the first episode in Series 6 of the Cybersecurity Transformation Podcast and highlights the various themes that will be covered in the series; read his original article covering the theme here on the Corix Partners blog

Series 5 - Final Episode - "A Look Back at the CrowdStrike Incident and the Meaning of Cyber Resilience" - Episode 25
In this final episode of the series, JC Gaillard and guest Steve Lamb take another look at the CrowdStrike incident and analyze what cyber resilience needs to mean for businesses.

Series 5 - "A Round-up of Key Issues around Cybersecurity and Generative AI" - Episode 24
In this episodes, JC Gaillard focuses on the impact generative AI could be having on cybersecurity practices and goes back to number of key aspects he has been exploring in earlier episodes in this series.



Series 5 - "Three Questions and a Reality Check around the Role of the Board with Cybersecurity" - Episode 21
In this episode, JC Gaillard looks back at cybersecurity governance challenges in the light of a recent article from McKinsey and offers his views on the matter, echoing a number of topics already discussed in earlier episodes of the podcast; the McKinsey article can be found here; JC's original article on the theme can be found here

Series 5 - "Post-Quantum Cryptography: Why It Matters, and What to Do Now?" - Episode 20
In this episode, JC Gaillard and guest Steven O'Sullivan from Cystel look at the challenges of post-quantum cryptography in the light of the release by the U.S. NIST of new standards in that space


Series 5 - "Cyber Resilience: Real New Practice or Just a Coat of Paint on Some Old Concepts?" - Episode 18
In this episode, JC Gaillard looks back at cyber resilience in the light of previous podcast episodes and offers his views around a recent HBR article on the topic; read his original article on the theme here; the HBR article mentioned in the podcast can be found here

Series 5 - "Using AI to Talk to the Board about Cyber: Clever Ploy or False Good Idea?" - Episode 17
In this episode, JC Gaillard revisits the intersection between generative AI and cybersecurity, in a complement to the topics explored in episodes 6 and 12 in the first part of Series 5

Series 5 - "The CrowdStrike Outage Under the Spotlight: Cybersecurity Incident ? or Not?"" - Episode 16
In this episode, JC Gaillard and Chris Burtenshaw from Strata Security look back at the recent Crowdstrike outage and analyse the first implications from the incident

Series 5 - "Cybersecurity: The Key Ingredient is Trust, not Money" - Episode 15
In this episode, JC Gaillard analyses a recent article from Hacker News and highlights his take on the 5 key questions CISOs should ask about their cybersecurity strategy; read his original article on the theme here




Series 5 - "Large Enterprises Can’t Cope With More Cybersecurity Tools" - Episode 11
In this episode, JC Gaillard goes back to the topic of security tools proliferation discussed in previous series and highlights why it should be central to the role of the CISO to build a vision and a product strategy, and drive the decluttering of cybersecurity landscapes




Series 5 - "A Look Back at the Role of the Board around Cybersecurity Oversight" - Episode 7
In this episode, JC Gaillard looks back at a number of cybersecurity governance aspects he has written or spoken over the past few months, in the light of a recent report by Diligent and Bitsight; read his article on the theme here



Series 5 - "Looking Back at the Role of the Virtual CISO and the Reality of Small Firms" - Episode 4
In this episode, JC Gaillard looks back at the role of the virtual CISO and in particular why many small firms would often benefit from looking internally first, before jumping to externalised cybersecurity solutions; read his original article on the theme here

Series 5 - "Cybersecurity is Not Working: Time to Try Something Else" - Episode 3
In this episode, JC Gaillard continues his journey across cybersecurity governance matters, and in particular he goes back to the construction of the role of the CISO and why it is essential to put it back in its historical perspective; read his original article on the theme here

Series 5 - "Don’t Expect Cybersecurity to Work in Firms where Nothing Does" - Episode 2
In this episode, JC Gaillard continues to explore cybersecurity governance and in particular, why it is essential to place it in a broader corporate governance context; read his original article on the theme here

Series 5 - "Cybersecurity Governance, Compliance and Window-Dressing" - Episode 1
In this first episode of the series, JC Gaillard explores issues around cybersecurity governance and ownership and in particular, why cyber resilience needs clear accountability from the top; read his original article on the theme here
The UK Government "call for views" around a proposed "Cyber Governance Code of Practice" mentioned in the episode can be found here


Series 4 - "Cybersecurity, Cycles and Predictions" - Episode 23
As we reach that time in the journalistic calendar where predictions for the year to come start to appear, JC Gaillard reflects on what it means for the cybersecurity industry and the real cycles over which it has been evolving

Series 4 - "Everybody is talking about Cyber Resilience, but what do they really mean?" - Episode 22

Series 4 - "The Board needs to own cybersecurity in business terms, not in technology terms" - Episode 21
In this episode, JC Gaillard goes back to the discussions in Episode 14 and 16 and continues to analyse the comments received in response to his earlier article around the failed role of the CISO; in this episode, more on the role of the Board and why it needs to own cybersecurity in business terms, not in technology terms.

Series 4 - "The Relationship between the CISO and the Board: What's Really Going On?" - Episode 20
In this episode, JC Gaillard starts to explore the nature and the mechanics of the relationship between the CISO and the Board, in the light of two recent surveys and their conflicting headlines; References: The ComputerWeekly article mentioned in the episode can be found here; The InfoSecurityMag article can be found here; and the Proofpoint report "Cybersecurity: The 2023 Board Perspective" here


Series 4 - "A Recruitment Perspective on the Role of the CISO" - with guest Owanate Bestman - Episode 18
In this episode, JC Gaillard looks back at the role of the CISO in the light of discussions on the theme in the last few episodes, and takes a recruitment perspective on the role, its history and its evolution with guest and recruitmemnt specialist Owanate Bestman; some of JC's views on the topic can be found here; Owanate's profile can be found here

Series 4 - "Why are we still talking about the reporting line of the CISO?" - with guest Mark Segelov - Episode 17
In this episode, JC Gaillard and guest Mark Segelov look back at the reporting line of the CISO, and why it is still a hot topic of discussion amongst cybersecurity professionals; JC's views on the topic can be found in those 2 pieces from 2017 and 2018, which are revisited in the podcast; Mark's Linkedin profile can be found here

Series 4 - "Is it time to accept that the role of the CISO may be failing? - part 2" - Episode 16
In this episode, JC Gaillard goes back to the content of Episode 14 and explores a number of comments received on Linkedin around the associated article, and in particular, how the role of the CSO needs to be conceived and positioned, and the importance of a structured cybersecurity operating model



Series 4 - "From Vendor Risk to Supply Chain Risk - Part 2" - with guest Richard Preece - Episode 13
In this episode, JC Gaillard and Richard Preece continue their exchanges initiated in Episode 6 of this series around supply chain risk and comment on the outcome of the Security Transformation Research Foundation meeting in late June


Series 4 - "A Reality Check Around Cybersecurity Benchmarking" - Episode 11
In this episode, JC Gaillard looks at the challenges involved with cybersecurity benchmarking, and why the CISOs need to be careful when answering what could be a politically loaded question

Series 4 - "The Momentum Building Behind the Role of the CSO" - Episode 10
In this episode, JC Gaillard explores the momentum behind the role of the Chief Security Officer and why it starts to make sense in many firms to evolve the role of the CISO and return it to its native technical content

Series 4 - "Creating Transformational Dynamics around Cybersecurity" - Episode 9
In this episode, JC Gaillard explores the dynamics of change around cybersecurity in the light of this article from the Harvard Business Review, and highlights two essential steps for success; read his original article on the theme here



Series 4 - "From Vendor Risk to Supply Chain Risk" - with guest Richard Preece - Episode 6
In this episode, JC Gaillard and guest Richard Preece start exploring the various dimensions involved in managing supply chain risk, what it means for businesses, and how it differs from traditional vendor risk.


