CISO Series Podcast LIVE!

David Spark, Andy Ellis, Alexandra Landegger

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Recorded live at BSidesSF 2025 in a movie theater in San Francisco, the CISO Series Podcast tackled four substantive topics: the real barriers to entering cybersecurity, the contested value of the CVE program, AI's role in reshaping analyst work, and accountability as the underappreciated foundation of security programs. Co-host Andy Ellis (YL Ventures) and guest Alexandra Landegger (Global Head of Cyber Strategy and Transformation, RTX) brought a combination of practitioner depth and strategic perspective to a format that balanced entertainment with genuine insight. ---

Watch on YouTube

Visual summary for CISO Series Podcast LIVE! by David Spark, Andy Ellis, Alexandra Landegger
Visual summary for CISO Series Podcast LIVE! by David Spark, Andy Ellis, Alexandra Landegger

Key moments

  1. 3:29 Debate: can online courses alone fast-track a cybersecurity career?
  2. 6:29 Adjacent-role hiring: pre-K teacher becomes best security trainer
  3. 9:00 Red flag: Nicholas Kloster hacked health club to prove employability
  4. 14:00 AI in security operations: hype vs. actual practitioner reality
  5. 20:00 CISO accountability failure: same incident repeated a year later
  6. 26:59 Board communication: translating risk into business impact language
  7. 34:59 Hiring insight: "Do you like to break systems?" reveals security mindset
  8. 39:59 Key takeaway: crisis survival ability is best predictor of cyber success

CISO Series Podcast LIVE!

Speakers: David Spark, Andy Ellis, Alexandra Landegger

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch on YouTube

Reading time: ~7 minutes

TL;DR

Recorded live at BSidesSF 2025 in a movie theater in San Francisco, the CISO Series Podcast tackled four substantive topics: the real barriers to entering cybersecurity, the contested value of the CVE program, AI's role in reshaping analyst work, and accountability as the underappreciated foundation of security programs. Co-host Andy Ellis (YL Ventures) and guest Alexandra Landegger (Global Head of Cyber Strategy and Transformation, RTX) brought a combination of practitioner depth and strategic perspective to a format that balanced entertainment with genuine insight.

Introduction

Not many security podcasts are recorded in a movie theater where The Accountant 2 is scheduled to play the same evening, but that is exactly the setting for this live episode of the CISO Series Podcast at BSidesSF 2025. Host David Spark, co-host Andy Ellis of YL Ventures, and guest Alexandra Landegger of RTX took the stage for a forty-five-minute format mixing structured debate, audience participation, and recurring game segments.

The episode opened with a vignette from Landegger that set the tone for the rest of the show: she once worked on a post-incident after-action review (AAR), produced a thorough document — and then failed to follow up on accountability for the action items. A year later, the same incident happened again. "The lesson I learned: accountability is everything for cyber." That theme threaded through every topic the panel touched.

Can You Fast-Track a Career Into Cybersecurity?

▶ Watch: Fast-tracking cybersecurity careers (04:00)

The episode's first substantive segment opened with a question David Spark posed about the flood of online cybersecurity courses: can completing a bootcamp or certification actually land someone a job in security?

Andy Ellis offered a reframe that the audience found compelling. Rather than thinking of cybersecurity as an entry-level field, Ellis argued it should be viewed as an insertion-level field — a destination for professionals with adjacent skills who can move laterally. "Almost every career in cyber, there is a non-cyber career field that looks very similar to it," he said. The implication is that training should focus on helping journalists learn threat intelligence, helping lawyers learn compliance, helping network engineers learn defensive operations — rather than trying to manufacture security expertise from zero.

When Spark pressed on what questions would reveal whether a non-traditional candidate is genuinely suited for security, Ellis offered a memorable answer: "Do you like to break systems? Not just computer systems." He described a pre-K teacher who discovered and circumvented a mandatory tooth-brushing policy not by confronting it directly but by meeting with parents before the rule was enforced. That kind of systems-thinking instinct — finding the exploit in a process, not just a program — is what Ellis looks for.

Landegger added that the ability to survive and function under chaos is another strong predictor. "Whether it's running a stop sign or your kid getting sick — if you can survive chaos all around you, that's ultimately what makes a good cyber professional."

What's Worse? Security's Toughest Trade-Offs

▶ Watch: What's Worse game — security fundamentals (14:01)

The episode's "What's Worse?" segment, a recurring feature where panelists rank bad scenarios, produced one of the more interesting strategic debates of the show. The three scenarios — each representing the absence of a security fundamental — were:

  1. No asset management and no off-boarding process
  2. No incident response process and no asset management
  3. No off-boarding process and no incident response

Both Ellis and Landegger agreed that some form of incident response capability must come first. Ellis's reasoning: IR is the capability that lets you deal with everything else. "Give me incident response first because I'm going to have lots of problems I need to deal with." Landegger offered a sharper structural argument: "Asset management is the ERP of your environment for digital. It is the backbone of absolutely everything. You can't do incident response, you can't do off-boarding, you can't do anything without asset management."

The resolution was nuanced: IR first if asset management is imperfect, but good asset management is foundational to everything else working at all. The audience, polled by applause, leaned toward the IR-first camp — though the result was contested and generated a brief exchange about ranked-choice voting.

What Dave's Mom Is Describing: A Cybersecurity Vocabulary Interlude

▶ Watch: Dave's Mom guessing game (22:02)

A crowd-pleasing recurring segment challenged panelists to identify cybersecurity terms from David Spark's mother's colloquial descriptions — without any technical prompting. The results:

  • "No way are we going to give you internet service" → Distributed Denial of Service (correctly identified by Landegger almost immediately)
  • "Making your CV look awfully good" → Social engineering (Dave's mom's intended answer; nobody on the panel got it, and neither did the audience until Andy guessed "phishing" and the audience worked backward to the right answer)
  • A description involving something being "airtight, sealed" → Air gap (correctly identified by Ellis — his first correct answer by his own admission)
  • "Your boss wants something, your coworkers say something else, and you're stuck" → Man-in-the-middle attack (correctly identified by the audience)

The segment is designed to underscore one of the show's recurring themes: security practitioners communicate so poorly outside their own field that even laypeople's best-faith attempts to describe common concepts are almost unrecognizable.

The CVE Program: Worst System Except for All the Others?

▶ Watch: CVE program debate (26:02)

Recorded against the backdrop of the spring 2025 funding scare around the MITRE-managed CVE program — when the program's government contract briefly appeared at risk of lapsing — this segment asked whether the CVE system deserves the criticism it routinely receives on the show.

Ellis, who described himself as the first consumer of the CVSS scoring system, argued that the primary value of CVE is often undersold: "We no longer have to deal with the crazy, wacky names of trying to distinguish between last week's Active Directory vulnerability and this week's Active Directory vulnerability. We can just have numbers that are unique and specific — and that is an amazing amount of value." Just numbering them. Just the numbering system.

Landegger focused on CVE as critical infrastructure for supply chain communication. "Having a common taxonomy to be able to speak about vulnerabilities — so much of what we do as cyber professionals is working with our suppliers, with our customers, making sure we're passing on information through things like the ISACs. Being able to direct people to something that's always there and available for us — I think is huge."

Both acknowledged clear limitations. The CVSS score is not a risk score and was never designed to be one — a point Ellis made with the authority of someone who was in the room when the scoring methodology was designed. Landegger called for better ecosystem context in CVE data: what does a vulnerability mean in an OT environment versus an IT environment versus a product environment? The taxonomy exists, but the context does not.

AI in the SOC: Freeing Analysts or Eliminating Entry-Level Roles?

▶ Watch: AI and the future of analyst work (32:03)

The final substantive segment engaged with a question from Dragos analyst Leslie Carhart: modern analyst work looks completely different than it did ten or twenty years ago, and AI is accelerating that shift further. The panel debated both what AI enables and what it threatens.

Landegger identified the area where human judgment remains irreplaceable: "Computers have gotten very good at detecting a lot of types of threat behavior, but one that has not really been very well solved is when people use legitimate access credentials to traverse across and get to where they're going." Behavioral analysis of legitimate-but-anomalous activity requires knowing the business, the people, and the context — something AI systems trained on generic threat data cannot easily replicate.

Ellis offered a structural insight about how to deploy AI in detection workflows: rather than asking an AI to render a verdict, assign two AI agents to the same event — one tasked with building the case that the activity is malicious, one tasked with assuming it is normal. "Get the human to now think with the business context and to understand that sometimes the exact same action could be malicious, could also be legitimate. Let your AIs get stuck in a rut."

The panel also surfaced a structural concern about AI displacing entry-level roles: if AI handles the 101-level triage work that junior analysts traditionally performed, how do those analysts develop the judgment needed for senior roles? Ellis's position was unsparing: the corporate world has never been particularly good at developing junior talent, and the solution is not to preserve low-level tasks but to redesign how organizations are built. "Treat humans as AI herds — your job is managing a bunch of AIs that do work for you. What is the human going to do in that world?"

Notable Quotes

"Accountability is everything for cyber. I learned that lesson after the same incident happened again a year later." — Alexandra Landegger (00:00)

"Think of cyber as less of an entry-level role and more of an insertion-level role — almost every career in cyber, there is a non-cyber career field that looks very similar to it." — Andy Ellis (04:00)

"Asset management is the ERP of your environment for digital. It is the backbone of absolutely everything." — Alexandra Landegger (18:02)

Key Takeaways

  • Accountability, not just documentation, determines whether security programs improve. An after-action review that produces no follow-through produces no change.
  • Cybersecurity talent pipelines benefit from lateral insertion more than traditional entry-level hiring. Adjacent professionals — journalists, lawyers, network engineers, teachers — often have the instincts security teams need and just need domain context.
  • Incident response capability should be the first investment when a security program is starting from scratch, because it enables everything else.
  • CVE's primary value is the numbering system itself — a common taxonomy for cross-organizational communication. CVSS scores are not risk scores and were not designed to be; organizations must supply their own context.
  • AI excels at automating known threat patterns but struggles with legitimate-credential-based lateral movement. Human judgment — grounded in business context — remains essential for the hard cases.
  • Designing AI into the analyst workflow as a debate partner (one instance arguing malicious, one arguing benign) is more useful than asking AI to render a single verdict.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A podcast recorded in a movie theater. The debate format surfaces some genuinely sharp thinking — Ellis on CVE's numbering-system value, Landegger on legitimate-credential lateral movement — but this is content that belongs behind a podcast feed, not a conference slot. Entertainment-to-signal ratio is inverted.

Heather Calloway (CISO) — SOLID

The CISO Series format surfaces four real conversations — talent pipeline, CVE value, AI in the SOC, and accountability — with more candor than most panel formats allow. Ellis's 'insertion-level field' reframe on talent is the most durable idea in the session. Light on rigor but not on substance.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons