CISO Tradecraft
Hosted by G Mark Hardy & Ross Young
A weekly career course for security people who want to lead, structured like lessons rather than banter.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Independent, National Security Corporation sourceSponsor-supported; feed copyright held by National Security Corporation.
- Last verified
Listed underCISO and leadership
Editorial take
The most deliberately educational of the CISO shows. G Mark Hardy, a long-time security educator and conference speaker, hosts most episodes, with co-host Ross Young joining for the solo teaching episodes on budgets, templates and leadership culture. The rest are 40 to 45 minute interviews with practitioners and authors: Cassie Crossley on software supply chain security, Anton Chuvakin on SIEM, Nishant Kaushik on passwordless, and SolarWinds CISO Tim Brown on the breach and the SEC case. The episodes are structured like lessons, which makes them good for anyone preparing for a first management role or a CISSP-style exam. The trade-off is polish over edge: guests are rarely challenged hard, and the 2026 run leans heavily on AI topics.
Last hand-checked 2026-09-30.
Listen if you …
- are a senior engineer or manager working toward a security leadership role
- want structured, lesson-style episodes rather than banter
- are studying for CISSP or a similar management-level certification
Skip if you …
- you want hard-edged debate, interviews are friendly
- you are early in a hands-on career, much of it assumes budget and team ownership
Start with these 3 episodes
- 01
#288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)
· 39 min · Beginner
The friendliest entry point: how to enter security through GRC, from someone who came from accounting.
- 02
#265 - 12 CISO Templates (with Ross Young)
· 45 min · Practitioner
The two hosts in teaching mode, walking through a dozen practical CISO templates you can reuse.
- 03
#285 - Passwordless Authentication (with Nishant Kaushik)
· 42 min · Practitioner
A clear passwordless explainer for leaders: why passwords fail and how FIDO passkeys change the threat.
About the show
CISO Tradecraft is a weekly podcast hosted by G Mark Hardy and Ross Young about the skills needed to move into and succeed in security leadership. Episodes alternate between host-led teaching episodes and interviews with CISOs, authors and researchers, and the website offers free CISO templates that tie into some episodes.
The show began in October 2020 and has passed 300 numbered episodes. Most episodes run 40 to 48 minutes and are also published on YouTube. The feed copyright is held by National Security Corporation.
Notable guests
- Chris Inglis
- Anton Chuvakin
- John Strand
- Tim Brown
- Cassie Crossley
- Gadi Evron
- Richard Stiennon
- Gary Hayslip
- George Finney
- Nishant Kaushik
Pairs with
If CISO Tradecraft works for you, these likely will too.
CISO Series Podcast
David Spark · Andy Ellis · Mike Johnson
Weekly CISO roundtable built on community posts, quick verdicts and a running joke in every title.
Listen if you are a security leader or aspire to be one and want to hear peers disagree.
panelweekly30–60mDefense in Depth
David Spark · Steve Zalewski · Geoff Belknap · Edward Contreras
One contested security question per week, argued by a CISO co-host and a guest in about 30 minutes.
Listen if you want one security leadership question argued properly in 30 minutes.
panelweekly30–60mResilient Cyber
Chris Hughes
Supply chain, vulnerability management and AI agent security, from a practitioner who writes the books on them.
Listen if you work in AppSec, product security or vulnerability management and want the current debates.
interviewweekly30–60mCISSP Cyber Training Podcast
Shon Gerber
Weekly CISSP domain lessons and practice questions, each tied to a real incident from the news.
Listen if you are studying for the CISSP and want domain-by-domain audio review.
soloweekly30–60m