The New CISO cover art

The New CISO

The New CISO

Written by: Steve Moore
Listen for free

The New CISO is hosted by Exabeam Chief Security Strategist, Steve Moore. A former IT security leader himself, Steve sits down with Chief Information Security Officers to get their take on cybersecurity trends, what it takes to lead security teams and how things are changing in today’s world.517748 Economics
Episodes
  • The CISO Scarlet Letter: How a Breach Actually Builds Your Resume
    Oct 8 2026

    Zach Lewis has spent his career asking for things before anyone offered them. In this episode of The New CISO, he joins Steve Moore from Black Hat in Las Vegas to trace a path from fixing neighbors' laptops to running IT and security for a university — and to explain why he wrote a book about it.

    The origin story is a series of conversations most people never start. A few weeks into a new job at a college, with the CIO gone and his own supervisor out the door, Zach walked into the interim CIO's office and said he could carry more. He was promoted days later. When the director of technical support announced he was moving, Zach said he wanted the job before it was posted, then shadowed the man he hoped to replace. The theme holds: if you want something, say so, and make sure the deciders know it.

    One move breaks the pattern. A former boss invited him to a nearby college that needed its IT department rebuilt, five minutes from the house and weeks after his first child was born, and he said yes without asking why the rebuild was necessary. A team of twelve was down to two. Six months of interviews produced no hires. He worked overnights, burned out fast, and left for his old employer the first day back from winter break. His advice now: treat the interview as an advisory engagement — why is this role open, where did everyone go, what is the root cause.

    Back at the college he became director, then CIO, then built a security program from nothing — and when he pitched hiring a CISO, leadership said there was no budget for another chief officer and asked whether he could just do it himself. He said yes. In April 2023 the institution was hit by LockBit. Zach walks through the morning it surfaced: hours of ordinary troubleshooting, a recovery that collapsed hours later, and a readme file in the hypervisor he knew was bad before opening it. Three calls followed — cyber insurance, the FBI, and his wife, to tell her this might be a resume generating event.

    The conversation sharpens when Steve presses on the book's most contested line: would Zach trade everything the breach taught him for a guarantee he'd never face another one? He doesn't dodge it. That stigma is exactly why he wrote Locked Up — attackers trade notes about what works, defenders stay quiet, and the silence helps the wrong side. His closing advice: ask for things, remember it's reciprocal, and use the tool instead of being used by it.

    Key Topics

    • Asking for the role before it is posted, and what tends to happen next
    • The questions Zach wishes he had asked before a job that went wrong
    • Interviewing as an advisor rather than a candidate
    • Building a security program from scratch, then being handed the CISO title
    • The morning the LockBit ransom note turned up in the hypervisor
    • Three phone calls: cyber insurance, the FBI, and his wife
    • Holding the circle tight, and the debate over when to notify publicly
    • Why announcing too early can force you to restate the numbers
    • The stigma around breaches, and why attackers share more than defenders
    • Writing Locked Up on a chapter-every-ten-days deadline

    Guest Bio

    Zach Lewis is CIO and CISO at University of Health Sciences and Pharmacy, and the author of Locked Up, published by Wiley with a foreword by George Finney. He began in desktop and systems administration in St. Louis before moving into higher education, holds the CISM and CISA certifications through ISACA, and led his institution's response to a LockBit ransomware attack in April 2023.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    Show More Show Less
    1 hr and 8 mins
  • Complacency Kills: Why More Discomfort Might Fix Your Burnout
    Sep 17 2026

    Sean Murphy spent more than twenty years in the CISO chair and walked away from it while things were going well. In this episode of The New CISO, he returns to talk with Steve Moore about trading the operational seat for a field CISO role at F5 — and why getting too good at the job was the warning sign.

    Sean reintroduces himself: 21 years in Air Force medicine, multiple post-retirement CISO gigs in highly regulated industries, and now field CISO for North America at F5. What drew him was not the title but the teaching. He calls his hobby recreational learning, has been an adult student for decades, and still teaches at Central Washington and Columbia Southern. The new role makes education the job rather than something done off the side of the desk.

    The heart of the conversation is the exhaustion nobody names. Sean is blunt that his old role drained him less because it was hard than because it was the same — the same politics, the same pressures, the same day in and day out. Stability turned into autopilot, and autopilot is where complacency kills. Now he is drinking from the fire hose on post-quantum, AI security, and API security, admitting he has had to go learn the material before presenting it. His batteries are fuller than they were when the work was easier.

    Steve turns that into a theory of time. An hour of play feels infinite to a child because everything in it is new; as we get older and repeat ourselves, the days speed up and disappear. Discomfort, then, is not the enemy — it is the thing that slows relative time back down. Sean adds the other half: focus, being genuinely in the moment rather than running on muscle memory.

    Then Steve puts a hot one to him. He is often underwhelmed by people in field CISO roles, and he argues the position is overhead until it is not — frequently first on the chopping block. Sean does not flinch. If a company builds these roles without a strategic reason and hires people with no bench behind them, that is on the company. He walks through the questions he asked in his own interviews — what does success look like, what are the real pain points, how much selling is in the role — and how much the subtext tells you. The episode closes on narrative over geek speak, a Black Hat session, a possible third book, and his answer to the show's closing question: do not forget your roots.

    Key Topics

    • Leaving the operational CISO seat while the program was running well
    • Why F5 built a field CISO role around education rather than sales
    • Recreational learning: teaching, certifications, and staying a student
    • Complacency, autopilot, and the exhaustion of sameness
    • Actual versus perceived time, and how novelty slows the clock
    • The hot take: is field CISO the first position to get cut?
    • Interview questions for a vendor role, starting with what success looks like
    • Reading the subtext of an interview: politics, pain points, and red flags
    • Building the narrative that ties security work to the business
    • Staying comfortable being uncomfortable in a brand new role

    Guest Bio

    Sean Murphy is field CISO for North America at F5, which he joined after more than twenty years as an operational CISO in highly regulated industries and a 21-year career in Air Force medicine. He has authored two cybersecurity books published by McGraw-Hill, contributed to ISC2 study material, and still teaches at Central Washington and Columbia Southern. He was a panel guest on The New CISO in 2022.

    GET A DEMO:

    👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

    🔔 Subscribe for more product demos and cybersecurity insights!

    ABOUT EXABEAM:

    Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

    Exabeam: Stop Insider Threats. Human or AI.

    CONNECT WITH US:

    X: https://x.com/exabeam

    LinkedIn: https://www.linkedin.com/company/exabeam/

    Blog: https://www.exabeam.com/blog/

    Show More Show Less
    41 mins
  • The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools
    Aug 27 2026
    In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo🔔 Subscribe for more product demos and cybersecurity insights!ABOUT EXABEAM:Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.Exabeam: Stop Insider Threats. Human or AI.CONNECT WITH US:X: https://x.com/exabeamLinkedIn: https://www.linkedin.com/company/exabeam/Blog: https://www.exabeam.com/blog/
    Show More Show Less
    49 mins
adbl_web_anon_alc_button_suppression_t1
No reviews yet