Kansikuva näyttelystä The Rook

The Rook

Podcast by David Shaw

englanti

Talous & ura

Rajoitettu tarjous

3 kuukautta hintaan 3,99 €

Sitten 7,99 € / kuukausiPeru milloin tahansa.

  • Podimon podcastit
  • Lataa offline-käyttöön
Aloita nyt

Lisää The Rook

Most security podcasts are built for practitioners. The Rook is built for the people who have to make decisions about security without being security experts.Hosted by David Shaw — CISSP, fractional vCISO, and GRC consultant with 20 years in the seat — The Rook delivers board-ready intelligence for founders, PE operating partners, M&A attorneys, and executives who own security risk when security isn’t their day job.Every episode covers one topic in depth with examples from a real incident, a regulatory development, a threat pattern, or a market shift. No vendor hype. No practitioner jargon. Just what it means for the business you're running or the deal you're working on — and what to do about it.New episodes every other Tuesday.

Kaikki jaksot

2 jaksot

jakson The Rook Ep. 002: Your Compliance Program Is Not a Security Program kansikuva

The Rook Ep. 002: Your Compliance Program Is Not a Security Program

Send us Fan Mail [https://www.buzzsprout.com/2611183/fan_mail/new] A clean audit doesn't tell you whether your company is secure. It tells you something much narrower, and the gap between what the audit answers and what executives read into it is where most companies are quietly carrying real risk. In this episode, David Shaw walks through what compliance audits actually evaluate, the three places where compliance and real security pull apart inside companies (access management, detection, out-of-scope creep), what someone running a real security practice will tell the board, and the two questions every board should be putting on the agenda at the meeting after the next audit closes. In this episode: * What an audit actually answers, and what it doesn't * Why the gap between the report and reality isn't a failure of the audit * The three places compliance and real security pull apart: access, detection, scope * What a real security practice looks like, versus a compliance program * What someone running a real program will tell the board * The two questions to put on the agenda after the next audit closes Resources mentioned: * SOC 2, ISO 27001, PCI, NIST, HIPAA frameworks Connect with David Shaw: * Website: corvus-cyber.com * LinkedIn: linkedin.com/in/djshaw * Email: david@corvus-cyber.com [david@corvus-cyber.com] The Rook · Corvus Cybersecurity · corvus-cyber.com · David Shaw, CISSP, GLEG

19. touko 2026 - 18 min
jakson The Deal You Didn’t Know You Made: Cyber Risk in M&A kansikuva

The Deal You Didn’t Know You Made: Cyber Risk in M&A

Send us Fan Mail [https://www.buzzsprout.com/2611183/fan_mail/new] In this episode of The Rook, David Shaw, founder of Corvus Cybersecurity and principal vCISO, examines the most consistently overlooked risk in M&A transactions: inherited cyber exposure. From Yahoo's misrepresentation of its breach history during the Verizon acquisition to the Marriott-Starwood breach that went undetected for four years, the pattern is the same. Cybersecurity due diligence gets a questionnaire, while financial and legal diligence get exhaustive scrutiny. The result is that acquirers close deals and inherit compromised environments, undisclosed incidents, and compliance gaps that carry real remediation costs. In this episode: * How Yahoo's misrepresentations to Verizon held through signing, and what saved Verizon wasn't diligence * How Marriott bought a four-year-old, undetected breach when it acquired Starwood * Why the standard M&A cybersecurity questionnaire fails to catch material risk * How R&W insurance carve-outs and cyber insurance pre-existing condition exclusions are changing the stakes for deal teams * The four-stage cyber due diligence process used on the buy side, and the three-bucket model for translating findings into deal team decisions * What sellers should be doing now to protect deal value * Three artifacts every buyer should require, not just three questions to ask The Rook · Corvus Cybersecurity · corvus-cyber.com · David Shaw, CISSP, GLEG

27. huhti 2026 - 20 min
Kuuntele rekisteröitymällä
Loistava design ja vihdoin on helppo löytää podcasteja, joista oikeasti tykkää
Loistava design ja vihdoin on helppo löytää podcasteja, joista oikeasti tykkää
Kiva sovellus podcastien kuunteluun, ja sisältö on monipuolista ja kiinnostavaa
Todella kiva äppi, helppo käyttää ja paljon podcasteja, joita en tiennyt ennestään.

Valitse tilauksesi

Suosituimmat

Rajoitettu tarjous

Premium

  • Podimon podcastit

  • Ei mainoksia Podimon podcasteissa

  • Peru milloin tahansa

3 kuukautta hintaan 3,99 €
Sitten 7,99 € / kuukausi

Aloita nyt

Premium

20 tuntia äänikirjoja

  • Podimon podcastit

  • Ei mainoksia Podimon podcasteissa

  • Peru milloin tahansa

30 vrk ilmainen kokeilu
Sitten 9,99 € / kuukausi

Aloita maksutta

Premium

100 tuntia äänikirjoja

  • Podimon podcastit

  • Ei mainoksia Podimon podcasteissa

  • Peru milloin tahansa

30 vrk ilmainen kokeilu
Sitten 19,99 € / kuukausi

Aloita maksutta

Vain Podimossa

Suosittuja äänikirjoja

Aloita nyt

3 kuukautta hintaan 3,99 €. Sitten 7,99 € / kuukausi. Peru milloin tahansa.