HANDS-ON LAB: SECURE AI AT RUNTIME WITH GHS & CROWDSTRIKE | Oct 13

REGISTER HERE

IBM i CURRENCY DEBT WEBINAR | OCT 8

REGISTER HERE

INTRODUCE AI WITHOUT REBUILDING YOUR IT ENVIRONMENT WEBINAR

GET THE RECORDING

ON-DEMAND GOOGLE'S AGENTIC SECOPS WEBINAR

Watch Recording

WIZ CLOUD SECURITY BLUEPRINT WEBINAR

REGISTER HERE

iTL:DR

GHS PODCASTS

Episode 07: Only 11% of Cyber Managers Get Risk Right.

generated-image (11)

 

Guest:
Jeff Gardiner, PhD., vCISO, GlassHouse Systems

 
Episode Overview

 

Cybersecurity is failing because most teams are managing threats, not risk. Jeff Gardiner breaks down the dangerous gap between what CISOs think they’re measuring and what boards actually need to make decisions—and why that mistake keeps showing up in major breaches.


Shawn Gershman and Jeff Gardiner dig into Jeff’s doctoral research on risk and cybersecurity, exposing how training frameworks like NIST NICE and certification courses teach threat awareness while barely touching true risk management. Jeff explains why his research found only about 11% of cybersecurity professionals demonstrate real risk management skill, why that number matters, and how companies can start fixing the disconnect without hiring an actuary or rebuilding everything from scratch.

 

You’ll discover:

  • * Why threat and risk are not the same thing, and why that distinction changes everything

  • * How to use a simple 2x2 risk matrix to translate technical judgment into business decisions

  • * Why boards manage financial, reputational, and compliance risk—but often hand technical risk to the wrong people

  • * How the Morris Worm shifted cybersecurity away from risk and toward incident response and controls

  • * What Jeff’s research says about the training gap, the 5.8% stat, and why formal education is not enough

 

Jeff also shows how to make assessments actually useful: mapping NIST results to maturity, comparing policy to practice, and turning security conversations into language the board understands. Then the episode gets practical with a tier list of security controls—from S-tier essentials like MFA, centralized identity, patch management, and security awareness training, to lower-value bets like pen testing when the fundamentals are missing.

 

If you’re a CISO, security leader, or executive trying to cut through tool noise and prove ROI, this episode gives you a sharper way to think about budget, prioritization, and risk. Essential listening if you want your security program to reduce real business exposure—not just generate reports.

  •  

 

 

Latest from the podcast

Conversations with the people building and securing enterprise IT.

How can we help?

Feel free to ask a question or simply leave a comment