<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/secure-simple-podcast-for-consultants-and-vcisos-on-cybersecurity-governance-and-compliance" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Secure &amp; Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/secure-simple-podcast-for-consultants-and-vcisos-on-cybersecurity-governance-and-compliance</itunes:new-feed-url>
    <description>“Secure &amp; Simple” demystifies governance and compliance challenges faced by consultants, as well as professionals acting as fractional CISOs in companies. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA. The episodes present topics in an easy-to-understand way and provide you with insight you won’t be able to find elsewhere.

To provide comments, suggest topics for the next episodes, or express your interest in participating in the show, contact us at podcast@advisera.com.

Learn more about ISO 27001, NIS2, and DORA at https://advisera.com.</description>
    <copyright>©2026 Advisera Expert Solutions</copyright>
    <podcast:guid>75075774-7b57-58c6-93ee-b843c536c03f</podcast:guid>
    <podcast:locked owner="dejan.kosutic@gmail.com">no</podcast:locked>
    <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
    <language>en</language>
    <pubDate>Tue, 07 Apr 2026 15:29:17 +0200</pubDate>
    <lastBuildDate>Tue, 07 Apr 2026 15:30:19 +0200</lastBuildDate>
    <link>https://advisera.com</link>
    <image>
      <url>https://img.transistorcdn.com/zSPzupvACzCP8XPTRgP5heMCWRsR1d8MP2cWhQNKBlQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YmI3/OGMyOGExNmRkNjEz/ZTI3MWJlMjUzZmFk/NzJmOC5wbmc.jpg</url>
      <title>Secure &amp; Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance</title>
      <link>https://advisera.com</link>
    </image>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <itunes:category text="Technology"/>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Dejan Kosutic</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/zSPzupvACzCP8XPTRgP5heMCWRsR1d8MP2cWhQNKBlQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YmI3/OGMyOGExNmRkNjEz/ZTI3MWJlMjUzZmFk/NzJmOC5wbmc.jpg"/>
    <itunes:summary>“Secure &amp; Simple” demystifies governance and compliance challenges faced by consultants, as well as professionals acting as fractional CISOs in companies. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA. The episodes present topics in an easy-to-understand way and provide you with insight you won’t be able to find elsewhere.

To provide comments, suggest topics for the next episodes, or express your interest in participating in the show, contact us at podcast@advisera.com.

Learn more about ISO 27001, NIS2, and DORA at https://advisera.com.</itunes:summary>
    <itunes:subtitle>“Secure &amp; Simple” demystifies governance and compliance challenges faced by consultants, as well as professionals acting as fractional CISOs in companies.</itunes:subtitle>
    <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
    <itunes:owner>
      <itunes:name>Dejan Kosutic</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Cyber Ranges, Attack Simulations &amp; AI: Proving Cyber Readiness | Interview with Lee Rossey</title>
      <itunes:episode>32</itunes:episode>
      <podcast:episode>32</podcast:episode>
      <itunes:title>Cyber Ranges, Attack Simulations &amp; AI: Proving Cyber Readiness | Interview with Lee Rossey</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1ee1d653-a0e8-4b37-9556-f44e01ab54e0</guid>
      <link>https://podcast.advisera.com/episodes/cyber-ranges-attack-simulations-ai-proving-cyber-readiness-interview-with-lee-rossey</link>
      <description>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) speaks with Lee Rossey, CTO and co-founder of SimSpace, about why much cybersecurity training is becoming outdated as AI accelerates both threats and defensive stacks. Rossey explains “train like you fight” through realistic, hands-on, team-based cyber range exercises that emulate an organization’s environment, tools, background traffic, and real attack scenarios such as ransomware and lateral movement. They discuss how cyber ranges complement tabletop exercises, what must be most realistic (security tools, attacks, and traffic), who should participate (SOC, IT, business owners, and leadership), and what typically breaks first under pressure. The conversation covers metrics like time to detect/respond/recover, ROI, and tool rationalization, evolving ranges for cloud/OT and AI, and the need to validate and govern AI-infused security tools with trust and oversight.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Lee Rossey</li>
<li>(01:18) - Why Training Is Outdated</li>
<li>(04:56) - What Is a Cyber Range</li>
<li>(07:53) - Building Realistic Attacks</li>
<li>(12:40) - Leadership Value and ROI</li>
<li>(15:49) - Who Should Participate</li>
<li>(19:53) - Senior Leaders in the Hot Seat</li>
<li>(23:41) - Lessons From Debriefs</li>
<li>(25:04) - Ranges Evolving With AI</li>
<li>(30:33) - Preparing For A Cyber Range</li>
<li>(32:15) - Measuring Exercise Results &amp; Reporting</li>
<li>(34:43) - Turning Findings Into Change</li>
<li>(38:33) - AI Governance And Trust</li>
<li>(41:39) - Regulations And Standards</li>
<li>(45:41) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) speaks with Lee Rossey, CTO and co-founder of SimSpace, about why much cybersecurity training is becoming outdated as AI accelerates both threats and defensive stacks. Rossey explains “train like you fight” through realistic, hands-on, team-based cyber range exercises that emulate an organization’s environment, tools, background traffic, and real attack scenarios such as ransomware and lateral movement. They discuss how cyber ranges complement tabletop exercises, what must be most realistic (security tools, attacks, and traffic), who should participate (SOC, IT, business owners, and leadership), and what typically breaks first under pressure. The conversation covers metrics like time to detect/respond/recover, ROI, and tool rationalization, evolving ranges for cloud/OT and AI, and the need to validate and govern AI-infused security tools with trust and oversight.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Lee Rossey</li>
<li>(01:18) - Why Training Is Outdated</li>
<li>(04:56) - What Is a Cyber Range</li>
<li>(07:53) - Building Realistic Attacks</li>
<li>(12:40) - Leadership Value and ROI</li>
<li>(15:49) - Who Should Participate</li>
<li>(19:53) - Senior Leaders in the Hot Seat</li>
<li>(23:41) - Lessons From Debriefs</li>
<li>(25:04) - Ranges Evolving With AI</li>
<li>(30:33) - Preparing For A Cyber Range</li>
<li>(32:15) - Measuring Exercise Results &amp; Reporting</li>
<li>(34:43) - Turning Findings Into Change</li>
<li>(38:33) - AI Governance And Trust</li>
<li>(41:39) - Regulations And Standards</li>
<li>(45:41) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 07 Apr 2026 15:29:17 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/1a06cb74/a897b8aa.mp3" length="45201845" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2823</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) speaks with Lee Rossey, CTO and co-founder of SimSpace, about why much cybersecurity training is becoming outdated as AI accelerates both threats and defensive stacks. Rossey explains “train like you fight” through realistic, hands-on, team-based cyber range exercises that emulate an organization’s environment, tools, background traffic, and real attack scenarios such as ransomware and lateral movement. They discuss how cyber ranges complement tabletop exercises, what must be most realistic (security tools, attacks, and traffic), who should participate (SOC, IT, business owners, and leadership), and what typically breaks first under pressure. The conversation covers metrics like time to detect/respond/recover, ROI, and tool rationalization, evolving ranges for cloud/OT and AI, and the need to validate and govern AI-infused security tools with trust and oversight.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Lee Rossey</li>
<li>(01:18) - Why Training Is Outdated</li>
<li>(04:56) - What Is a Cyber Range</li>
<li>(07:53) - Building Realistic Attacks</li>
<li>(12:40) - Leadership Value and ROI</li>
<li>(15:49) - Who Should Participate</li>
<li>(19:53) - Senior Leaders in the Hot Seat</li>
<li>(23:41) - Lessons From Debriefs</li>
<li>(25:04) - Ranges Evolving With AI</li>
<li>(30:33) - Preparing For A Cyber Range</li>
<li>(32:15) - Measuring Exercise Results &amp; Reporting</li>
<li>(34:43) - Turning Findings Into Change</li>
<li>(38:33) - AI Governance And Trust</li>
<li>(41:39) - Regulations And Standards</li>
<li>(45:41) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/1a06cb74/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1a06cb74/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1a06cb74/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1a06cb74/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/1a06cb74/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/1a06cb74/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy Merza</title>
      <itunes:episode>31</itunes:episode>
      <podcast:episode>31</podcast:episode>
      <itunes:title>AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy Merza</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8d44b563-5718-4409-b8a9-740156615569</guid>
      <link>https://podcast.advisera.com/episodes/ai-agents-vs-ai-agents-the-future-of-security-operations-interview-with-monzy-merza</link>
      <description>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Monzy Merza, co-founder and CEO of Crogl, about how cybersecurity is shifting to an “agent versus agent” world where attackers task AI agents to run fast, low-cost, sophisticated campaigns without human approvals. Merza outlines core security operations activities—preparation/tooling, alert investigation, and response—and explains how AI is changing each, including AI SOC agents that automatically connect to multiple data sources, enrich alerts, run MITRE kill chain analysis, and produce investigation reports, as well as AI-driven response actions and documentation. They discuss when humans must remain in the loop for high-impact decisions, how organizations build trust through phased adoption with measurable use cases, why roles may shift from analysts to more security engineers, and governance needs like flexible integrations, model choice, and transparency in AI security tools.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> <br>- <strong>Crogl company</strong> <a href="https://crogl.com/">https://crogl.com/</a><br>- <strong>2026 State of SecOps Report</strong> <a href="https://www.crogl.com/newsroom/state-of-secops-ai">https://www.crogl.com/newsroom/state-of-secops-ai</a></p>
<ul><li>(00:00) - Interview with Monzy Merza</li>
<li>(00:58) - Agent vs Agent Threats</li>
<li>(03:22) - Three Phases of SecOps</li>
<li>(05:53) - AI SOC Investigation Example</li>
<li>(08:41) - Autonomy vs Human in the Loop</li>
<li>(12:48) - Human Only Decisions</li>
<li>(16:43) - Building Trust and Maturity</li>
<li>(19:07) - Future Security Roles</li>
<li>(24:24) - AI Change Wave</li>
<li>(27:08) - Testing AI Maturity</li>
<li>(29:25) - Governance Framework Gap</li>
<li>(31:15) - Policy Meets Hallucinations</li>
<li>(34:50) - Business Alignment Example</li>
<li>(37:14) - Governance Requirements</li>
<li>(41:57) - SOC Roles Reshaped</li>
<li>(47:26) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Monzy Merza, co-founder and CEO of Crogl, about how cybersecurity is shifting to an “agent versus agent” world where attackers task AI agents to run fast, low-cost, sophisticated campaigns without human approvals. Merza outlines core security operations activities—preparation/tooling, alert investigation, and response—and explains how AI is changing each, including AI SOC agents that automatically connect to multiple data sources, enrich alerts, run MITRE kill chain analysis, and produce investigation reports, as well as AI-driven response actions and documentation. They discuss when humans must remain in the loop for high-impact decisions, how organizations build trust through phased adoption with measurable use cases, why roles may shift from analysts to more security engineers, and governance needs like flexible integrations, model choice, and transparency in AI security tools.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> <br>- <strong>Crogl company</strong> <a href="https://crogl.com/">https://crogl.com/</a><br>- <strong>2026 State of SecOps Report</strong> <a href="https://www.crogl.com/newsroom/state-of-secops-ai">https://www.crogl.com/newsroom/state-of-secops-ai</a></p>
<ul><li>(00:00) - Interview with Monzy Merza</li>
<li>(00:58) - Agent vs Agent Threats</li>
<li>(03:22) - Three Phases of SecOps</li>
<li>(05:53) - AI SOC Investigation Example</li>
<li>(08:41) - Autonomy vs Human in the Loop</li>
<li>(12:48) - Human Only Decisions</li>
<li>(16:43) - Building Trust and Maturity</li>
<li>(19:07) - Future Security Roles</li>
<li>(24:24) - AI Change Wave</li>
<li>(27:08) - Testing AI Maturity</li>
<li>(29:25) - Governance Framework Gap</li>
<li>(31:15) - Policy Meets Hallucinations</li>
<li>(34:50) - Business Alignment Example</li>
<li>(37:14) - Governance Requirements</li>
<li>(41:57) - SOC Roles Reshaped</li>
<li>(47:26) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 24 Mar 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/1d22d809/8f6c00d1.mp3" length="46860328" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2927</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Monzy Merza, co-founder and CEO of Crogl, about how cybersecurity is shifting to an “agent versus agent” world where attackers task AI agents to run fast, low-cost, sophisticated campaigns without human approvals. Merza outlines core security operations activities—preparation/tooling, alert investigation, and response—and explains how AI is changing each, including AI SOC agents that automatically connect to multiple data sources, enrich alerts, run MITRE kill chain analysis, and produce investigation reports, as well as AI-driven response actions and documentation. They discuss when humans must remain in the loop for high-impact decisions, how organizations build trust through phased adoption with measurable use cases, why roles may shift from analysts to more security engineers, and governance needs like flexible integrations, model choice, and transparency in AI security tools.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> <br>- <strong>Crogl company</strong> <a href="https://crogl.com/">https://crogl.com/</a><br>- <strong>2026 State of SecOps Report</strong> <a href="https://www.crogl.com/newsroom/state-of-secops-ai">https://www.crogl.com/newsroom/state-of-secops-ai</a></p>
<ul><li>(00:00) - Interview with Monzy Merza</li>
<li>(00:58) - Agent vs Agent Threats</li>
<li>(03:22) - Three Phases of SecOps</li>
<li>(05:53) - AI SOC Investigation Example</li>
<li>(08:41) - Autonomy vs Human in the Loop</li>
<li>(12:48) - Human Only Decisions</li>
<li>(16:43) - Building Trust and Maturity</li>
<li>(19:07) - Future Security Roles</li>
<li>(24:24) - AI Change Wave</li>
<li>(27:08) - Testing AI Maturity</li>
<li>(29:25) - Governance Framework Gap</li>
<li>(31:15) - Policy Meets Hallucinations</li>
<li>(34:50) - Business Alignment Example</li>
<li>(37:14) - Governance Requirements</li>
<li>(41:57) - SOC Roles Reshaped</li>
<li>(47:26) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/1d22d809/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d22d809/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d22d809/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d22d809/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d22d809/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/1d22d809/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew Gault</title>
      <itunes:episode>30</itunes:episode>
      <podcast:episode>30</podcast:episode>
      <itunes:title>Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew Gault</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">120e0680-5cf9-4fa5-a279-434edab982a7</guid>
      <link>https://podcast.advisera.com/episodes/zero-trust-as-a-mindset-identity-governance-and-access-interview-with-andrew-gault</link>
      <description>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about Zero Trust as a strategy and mindset rather than a single technology, shifting away from perimeter-based security to “default deny” with continuous verification. Gault outlines core layers such as identity for users and devices, policy-based scoring, encryption, and ongoing monitoring to reduce lateral movement when breaches occur. They discuss extending zero trust principles to suppliers by issuing vendor identities managed centrally, governance needs like documented access policies, change management, and least privilege, and challenges such as shared credentials and the ongoing effort to keep permissions current. The conversation also covers non-human identities for AI agents, service accounts, ownership and lifecycle management, audit expectations under SOC 2 and ISO 27001, vendor lock-in tradeoffs, and using inventories and exception reduction as practical KPIs.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Andrew Gault</li>
<li>(00:47) - Strategy Not Perimeter</li>
<li>(02:40) - Core Layers Explained</li>
<li>(03:53) - Vendors And Suppliers</li>
<li>(07:37) - Risks Reduced And Limits</li>
<li>(12:24) - Non-Human Identities</li>
<li>(16:04) - Managing Machine Accounts</li>
<li>(18:34) - Governance And Policies</li>
<li>(23:35) - Who Owns Zero Trust</li>
<li>(25:40) - Building Security Culture</li>
<li>(27:20) - Measuring Zero Trust Impact</li>
<li>(30:08) - Compliance vs Real Security</li>
<li>(34:35) - Avoiding Vendor Lock In</li>
<li>(38:33) - KPIs and Legacy Exceptions</li>
<li>(44:25) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about Zero Trust as a strategy and mindset rather than a single technology, shifting away from perimeter-based security to “default deny” with continuous verification. Gault outlines core layers such as identity for users and devices, policy-based scoring, encryption, and ongoing monitoring to reduce lateral movement when breaches occur. They discuss extending zero trust principles to suppliers by issuing vendor identities managed centrally, governance needs like documented access policies, change management, and least privilege, and challenges such as shared credentials and the ongoing effort to keep permissions current. The conversation also covers non-human identities for AI agents, service accounts, ownership and lifecycle management, audit expectations under SOC 2 and ISO 27001, vendor lock-in tradeoffs, and using inventories and exception reduction as practical KPIs.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Andrew Gault</li>
<li>(00:47) - Strategy Not Perimeter</li>
<li>(02:40) - Core Layers Explained</li>
<li>(03:53) - Vendors And Suppliers</li>
<li>(07:37) - Risks Reduced And Limits</li>
<li>(12:24) - Non-Human Identities</li>
<li>(16:04) - Managing Machine Accounts</li>
<li>(18:34) - Governance And Policies</li>
<li>(23:35) - Who Owns Zero Trust</li>
<li>(25:40) - Building Security Culture</li>
<li>(27:20) - Measuring Zero Trust Impact</li>
<li>(30:08) - Compliance vs Real Security</li>
<li>(34:35) - Avoiding Vendor Lock In</li>
<li>(38:33) - KPIs and Legacy Exceptions</li>
<li>(44:25) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 10 Mar 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/2e0fe42e/3bf7e8b4.mp3" length="43966287" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2746</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about Zero Trust as a strategy and mindset rather than a single technology, shifting away from perimeter-based security to “default deny” with continuous verification. Gault outlines core layers such as identity for users and devices, policy-based scoring, encryption, and ongoing monitoring to reduce lateral movement when breaches occur. They discuss extending zero trust principles to suppliers by issuing vendor identities managed centrally, governance needs like documented access policies, change management, and least privilege, and challenges such as shared credentials and the ongoing effort to keep permissions current. The conversation also covers non-human identities for AI agents, service accounts, ownership and lifecycle management, audit expectations under SOC 2 and ISO 27001, vendor lock-in tradeoffs, and using inventories and exception reduction as practical KPIs.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Andrew Gault</li>
<li>(00:47) - Strategy Not Perimeter</li>
<li>(02:40) - Core Layers Explained</li>
<li>(03:53) - Vendors And Suppliers</li>
<li>(07:37) - Risks Reduced And Limits</li>
<li>(12:24) - Non-Human Identities</li>
<li>(16:04) - Managing Machine Accounts</li>
<li>(18:34) - Governance And Policies</li>
<li>(23:35) - Who Owns Zero Trust</li>
<li>(25:40) - Building Security Culture</li>
<li>(27:20) - Measuring Zero Trust Impact</li>
<li>(30:08) - Compliance vs Real Security</li>
<li>(34:35) - Avoiding Vendor Lock In</li>
<li>(38:33) - KPIs and Legacy Exceptions</li>
<li>(44:25) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>Zero Trust</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/2e0fe42e/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/2e0fe42e/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/2e0fe42e/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/2e0fe42e/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/2e0fe42e/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/2e0fe42e/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt</title>
      <itunes:episode>29</itunes:episode>
      <podcast:episode>29</podcast:episode>
      <itunes:title>Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cc13005f-d476-432c-bdef-a1c91895d55f</guid>
      <link>https://podcast.advisera.com/episodes/responding-to-ransomware-attack-case-study-interview-with-yannick-hirt</link>
      <description>
        <![CDATA[<p>Dejan Kosutic interviews Yannick Hirt from ODCUS about his experience with a real ransomware attack on an international industrial company. They discuss likely phishing entry via a privileged IT account, overnight encryption, and setting up a war room. The company restored critical systems from verified cloud backups without paying, while briefly negotiating via a Dutch specialist as the attacker threatened data release. Key lessons include tested backups, detection and provider SLAs, privileged access controls, BIA/process mapping, strong documentation and forensics, communications, insurance coordination, and regular training.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Yannick Hirt</li>
<li>(00:54) - How the Attack Started: Cloud Transformation, Gaps, and a Phishing Entry Point</li>
<li>(04:06) - Day Zero Response: Disconnecting Systems and Standing Up the War Room</li>
<li>(07:54) - Early Critical Decisions: Recovery Streams, Stakeholders, Police &amp; Insurance</li>
<li>(09:08) - Restore vs Rebuild: Mapping Critical Apps and Validating Backups</li>
<li>(11:11) - Talking to the Attackers: “Service Desk” Negotiations and Typical Ransom Size</li>
<li>(14:09) - To Pay or Not to Pay: Strategy, Data-Leak Risk, and Criminal “Reliability”</li>
<li>(16:12) - Recovery Timeline &amp; Aftermath: Dark Web Leak, Employee Calls, and Government Response</li>
<li>(21:20) - Who Decides the Recovery Order? IT + Business Alignment</li>
<li>(23:47) - PR in the War Room: Internal Updates, Guidelines &amp; External Liaison</li>
<li>(25:06) - Senior Management’s Real Job During Recovery</li>
<li>(27:38) - Working With Cyber Insurance: Support Now, Paperwork Later</li>
<li>(30:37) - Forensic Report Deep Dive: Entry Point, Lateral Movement, and Tradeoffs</li>
<li>(32:25) - Consultants in a Ransomware Crisis: Networks, Pragmatism, and Calm</li>
<li>(41:30) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dejan Kosutic interviews Yannick Hirt from ODCUS about his experience with a real ransomware attack on an international industrial company. They discuss likely phishing entry via a privileged IT account, overnight encryption, and setting up a war room. The company restored critical systems from verified cloud backups without paying, while briefly negotiating via a Dutch specialist as the attacker threatened data release. Key lessons include tested backups, detection and provider SLAs, privileged access controls, BIA/process mapping, strong documentation and forensics, communications, insurance coordination, and regular training.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Yannick Hirt</li>
<li>(00:54) - How the Attack Started: Cloud Transformation, Gaps, and a Phishing Entry Point</li>
<li>(04:06) - Day Zero Response: Disconnecting Systems and Standing Up the War Room</li>
<li>(07:54) - Early Critical Decisions: Recovery Streams, Stakeholders, Police &amp; Insurance</li>
<li>(09:08) - Restore vs Rebuild: Mapping Critical Apps and Validating Backups</li>
<li>(11:11) - Talking to the Attackers: “Service Desk” Negotiations and Typical Ransom Size</li>
<li>(14:09) - To Pay or Not to Pay: Strategy, Data-Leak Risk, and Criminal “Reliability”</li>
<li>(16:12) - Recovery Timeline &amp; Aftermath: Dark Web Leak, Employee Calls, and Government Response</li>
<li>(21:20) - Who Decides the Recovery Order? IT + Business Alignment</li>
<li>(23:47) - PR in the War Room: Internal Updates, Guidelines &amp; External Liaison</li>
<li>(25:06) - Senior Management’s Real Job During Recovery</li>
<li>(27:38) - Working With Cyber Insurance: Support Now, Paperwork Later</li>
<li>(30:37) - Forensic Report Deep Dive: Entry Point, Lateral Movement, and Tradeoffs</li>
<li>(32:25) - Consultants in a Ransomware Crisis: Networks, Pragmatism, and Calm</li>
<li>(41:30) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 24 Feb 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/f23bed3c/fa4ee6ea.mp3" length="41167107" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2571</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dejan Kosutic interviews Yannick Hirt from ODCUS about his experience with a real ransomware attack on an international industrial company. They discuss likely phishing entry via a privileged IT account, overnight encryption, and setting up a war room. The company restored critical systems from verified cloud backups without paying, while briefly negotiating via a Dutch specialist as the attacker threatened data release. Key lessons include tested backups, detection and provider SLAs, privileged access controls, BIA/process mapping, strong documentation and forensics, communications, insurance coordination, and regular training.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Yannick Hirt</li>
<li>(00:54) - How the Attack Started: Cloud Transformation, Gaps, and a Phishing Entry Point</li>
<li>(04:06) - Day Zero Response: Disconnecting Systems and Standing Up the War Room</li>
<li>(07:54) - Early Critical Decisions: Recovery Streams, Stakeholders, Police &amp; Insurance</li>
<li>(09:08) - Restore vs Rebuild: Mapping Critical Apps and Validating Backups</li>
<li>(11:11) - Talking to the Attackers: “Service Desk” Negotiations and Typical Ransom Size</li>
<li>(14:09) - To Pay or Not to Pay: Strategy, Data-Leak Risk, and Criminal “Reliability”</li>
<li>(16:12) - Recovery Timeline &amp; Aftermath: Dark Web Leak, Employee Calls, and Government Response</li>
<li>(21:20) - Who Decides the Recovery Order? IT + Business Alignment</li>
<li>(23:47) - PR in the War Room: Internal Updates, Guidelines &amp; External Liaison</li>
<li>(25:06) - Senior Management’s Real Job During Recovery</li>
<li>(27:38) - Working With Cyber Insurance: Support Now, Paperwork Later</li>
<li>(30:37) - Forensic Report Deep Dive: Entry Point, Lateral Movement, and Tradeoffs</li>
<li>(32:25) - Consultants in a Ransomware Crisis: Networks, Pragmatism, and Calm</li>
<li>(41:30) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/f23bed3c/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/f23bed3c/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/f23bed3c/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/f23bed3c/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/f23bed3c/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/f23bed3c/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>What Should the Board Ask the CISO? | Interview with Clar Rosso</title>
      <itunes:episode>28</itunes:episode>
      <podcast:episode>28</podcast:episode>
      <itunes:title>What Should the Board Ask the CISO? | Interview with Clar Rosso</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">32b989e4-8864-44fc-a69f-c0b8cb02e13d</guid>
      <link>https://podcast.advisera.com/episodes/what-should-the-board-ask-the-ciso-interview-with-clar-rosso</link>
      <description>
        <![CDATA[<p>In this episode, Dejan Kosutic talks with Clar Rosso, CEO of Rosso Strategic Advisors, board member of Excelsior University, and the former CEO of ISC2, about the evolving role of boards for cybersecurity. They discuss the increasing importance of cyber governance, the impact of AI, the concept of digital resilience, and the interaction between cybersecurity professionals and boards of directors. Claire shares her insights on how to better integrate cybersecurity into business operations and enhance board members' understanding. Tune in to learn how a strong cyber posture can help businesses achieve their strategic goals and mitigate risks.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Clar Rosso</li>
<li>(00:21) - Introducing Today's Guest: Clar Rosso</li>
<li>(01:18) - Cybersecurity as a Business Issue</li>
<li>(03:54) - Board Members' Role in Cybersecurity</li>
<li>(05:19) - Cyber Resilience vs. Cyber Defense</li>
<li>(07:59) - Cybersecurity's Role in Business Growth</li>
<li>(09:13) - Effective Communication with the Board</li>
<li>(19:56) - Compliance and Risk Management</li>
<li>(25:00) - The Future of Cybersecurity Audits</li>
<li>(31:19) - Board's Role During a Cyber Breach</li>
<li>(35:44) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, Dejan Kosutic talks with Clar Rosso, CEO of Rosso Strategic Advisors, board member of Excelsior University, and the former CEO of ISC2, about the evolving role of boards for cybersecurity. They discuss the increasing importance of cyber governance, the impact of AI, the concept of digital resilience, and the interaction between cybersecurity professionals and boards of directors. Claire shares her insights on how to better integrate cybersecurity into business operations and enhance board members' understanding. Tune in to learn how a strong cyber posture can help businesses achieve their strategic goals and mitigate risks.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Clar Rosso</li>
<li>(00:21) - Introducing Today's Guest: Clar Rosso</li>
<li>(01:18) - Cybersecurity as a Business Issue</li>
<li>(03:54) - Board Members' Role in Cybersecurity</li>
<li>(05:19) - Cyber Resilience vs. Cyber Defense</li>
<li>(07:59) - Cybersecurity's Role in Business Growth</li>
<li>(09:13) - Effective Communication with the Board</li>
<li>(19:56) - Compliance and Risk Management</li>
<li>(25:00) - The Future of Cybersecurity Audits</li>
<li>(31:19) - Board's Role During a Cyber Breach</li>
<li>(35:44) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 10 Feb 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/3cbd0770/ffcdd615.mp3" length="35629041" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2225</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, Dejan Kosutic talks with Clar Rosso, CEO of Rosso Strategic Advisors, board member of Excelsior University, and the former CEO of ISC2, about the evolving role of boards for cybersecurity. They discuss the increasing importance of cyber governance, the impact of AI, the concept of digital resilience, and the interaction between cybersecurity professionals and boards of directors. Claire shares her insights on how to better integrate cybersecurity into business operations and enhance board members' understanding. Tune in to learn how a strong cyber posture can help businesses achieve their strategic goals and mitigate risks.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Clar Rosso</li>
<li>(00:21) - Introducing Today's Guest: Clar Rosso</li>
<li>(01:18) - Cybersecurity as a Business Issue</li>
<li>(03:54) - Board Members' Role in Cybersecurity</li>
<li>(05:19) - Cyber Resilience vs. Cyber Defense</li>
<li>(07:59) - Cybersecurity's Role in Business Growth</li>
<li>(09:13) - Effective Communication with the Board</li>
<li>(19:56) - Compliance and Risk Management</li>
<li>(25:00) - The Future of Cybersecurity Audits</li>
<li>(31:19) - Board's Role During a Cyber Breach</li>
<li>(35:44) - Resources for Consultants and Cybersecurity Professionals</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/3cbd0770/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3cbd0770/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3cbd0770/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3cbd0770/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3cbd0770/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/3cbd0770/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>The Crucial Role of Management Review in Cybersecurity Governance | Interview with Carlos Cruz</title>
      <itunes:episode>27</itunes:episode>
      <podcast:episode>27</podcast:episode>
      <itunes:title>The Crucial Role of Management Review in Cybersecurity Governance | Interview with Carlos Cruz</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">066f86f9-b84b-412c-9dd5-bcdfae02b9bb</guid>
      <link>https://podcast.advisera.com/episodes/the-crucial-role-of-management-review-in-cybersecurity-governance-interview-with-carlos-cruz</link>
      <description>
        <![CDATA[<p>In this special first-year anniversary episode of the Secure and Simple Podcast, host Dejan Kosutic from Advisera welcomes back Carlos Cruz, founder of Metanoia Consulting and ISO expert. They deep-dive into best practices for conducting effective management reviews, covering not just ISO 9001 and ISO 14001 but also ISO 27001 and other cybersecurity frameworks. The discussion highlights the importance of top management’s involvement, the process of converting raw data into actionable insights, and setting future objectives. Ideal for consultants, CISOs, and cybersecurity professionals aiming to enhance their governance and compliance strategies.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on management review</li>
<li>(00:21) - Guest Introduction: Carlos Cruz</li>
<li>(01:46) - Understanding Management Reviews</li>
<li>(07:34) - Effective Management Review Practices</li>
<li>(12:34) - Management Review Process</li>
<li>(23:35) - Frequency and Importance of Management Reviews</li>
<li>(28:40) - Setting and Reviewing Objectives</li>
<li>(33:05) - Auditing and Performance</li>
<li>(37:50) - Common Pitfalls in Management Reviews</li>
<li>(41:25) - Consultant's Role in Management Reviews</li>
<li>(49:28) - Integrated Management Systems</li>
<li>(55:04) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this special first-year anniversary episode of the Secure and Simple Podcast, host Dejan Kosutic from Advisera welcomes back Carlos Cruz, founder of Metanoia Consulting and ISO expert. They deep-dive into best practices for conducting effective management reviews, covering not just ISO 9001 and ISO 14001 but also ISO 27001 and other cybersecurity frameworks. The discussion highlights the importance of top management’s involvement, the process of converting raw data into actionable insights, and setting future objectives. Ideal for consultants, CISOs, and cybersecurity professionals aiming to enhance their governance and compliance strategies.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on management review</li>
<li>(00:21) - Guest Introduction: Carlos Cruz</li>
<li>(01:46) - Understanding Management Reviews</li>
<li>(07:34) - Effective Management Review Practices</li>
<li>(12:34) - Management Review Process</li>
<li>(23:35) - Frequency and Importance of Management Reviews</li>
<li>(28:40) - Setting and Reviewing Objectives</li>
<li>(33:05) - Auditing and Performance</li>
<li>(37:50) - Common Pitfalls in Management Reviews</li>
<li>(41:25) - Consultant's Role in Management Reviews</li>
<li>(49:28) - Integrated Management Systems</li>
<li>(55:04) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 27 Jan 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/c16db0c3/5e73bda0.mp3" length="54189898" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3385</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this special first-year anniversary episode of the Secure and Simple Podcast, host Dejan Kosutic from Advisera welcomes back Carlos Cruz, founder of Metanoia Consulting and ISO expert. They deep-dive into best practices for conducting effective management reviews, covering not just ISO 9001 and ISO 14001 but also ISO 27001 and other cybersecurity frameworks. The discussion highlights the importance of top management’s involvement, the process of converting raw data into actionable insights, and setting future objectives. Ideal for consultants, CISOs, and cybersecurity professionals aiming to enhance their governance and compliance strategies.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on management review</li>
<li>(00:21) - Guest Introduction: Carlos Cruz</li>
<li>(01:46) - Understanding Management Reviews</li>
<li>(07:34) - Effective Management Review Practices</li>
<li>(12:34) - Management Review Process</li>
<li>(23:35) - Frequency and Importance of Management Reviews</li>
<li>(28:40) - Setting and Reviewing Objectives</li>
<li>(33:05) - Auditing and Performance</li>
<li>(37:50) - Common Pitfalls in Management Reviews</li>
<li>(41:25) - Consultant's Role in Management Reviews</li>
<li>(49:28) - Integrated Management Systems</li>
<li>(55:04) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/c16db0c3/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/c16db0c3/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/c16db0c3/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/c16db0c3/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/c16db0c3/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/c16db0c3/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Resolving a Conflict Between IT and Cybersecurity | Interview with Jared Leuschen</title>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <itunes:title>Resolving a Conflict Between IT and Cybersecurity | Interview with Jared Leuschen</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4043c0ea-bd6d-4d1b-80ed-f92384c48ac2</guid>
      <link>https://podcast.advisera.com/episodes/resolving-a-conflict-between-it-and-cybersecurity-interview-with-jared-leuschen</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, discusses the ongoing conflict between IT operations and cybersecurity governance with Jared Leuschen, CEO and Founder of Blue Tree. They delve into the human component behind security and compliance issues, misalignment and communication gaps within organizations, and practical solutions for aligning IT and cybersecurity efforts. The discussion also covers the importance of risk management, the role of consultants, and effective communication strategies between IT and cybersecurity teams. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jared Leuschen</li>
<li>(01:12) - The IT and Cybersecurity Conflict</li>
<li>(03:21) - Finding Alignment Through Communication</li>
<li>(06:05) - Proactive IT Involvement in Cybersecurity</li>
<li>(15:19) - Time Management and Leadership in IT</li>
<li>(17:38) - The Role of Consultants in Cybersecurity</li>
<li>(23:46) - Vendor Management and Supply Chain Security</li>
<li>(30:33) - Aligning IT and Security with Business Goals</li>
<li>(40:17) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, discusses the ongoing conflict between IT operations and cybersecurity governance with Jared Leuschen, CEO and Founder of Blue Tree. They delve into the human component behind security and compliance issues, misalignment and communication gaps within organizations, and practical solutions for aligning IT and cybersecurity efforts. The discussion also covers the importance of risk management, the role of consultants, and effective communication strategies between IT and cybersecurity teams. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jared Leuschen</li>
<li>(01:12) - The IT and Cybersecurity Conflict</li>
<li>(03:21) - Finding Alignment Through Communication</li>
<li>(06:05) - Proactive IT Involvement in Cybersecurity</li>
<li>(15:19) - Time Management and Leadership in IT</li>
<li>(17:38) - The Role of Consultants in Cybersecurity</li>
<li>(23:46) - Vendor Management and Supply Chain Security</li>
<li>(30:33) - Aligning IT and Security with Business Goals</li>
<li>(40:17) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 13 Jan 2026 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/13c6be56/6b3bdd2c.mp3" length="40004462" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2498</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, discusses the ongoing conflict between IT operations and cybersecurity governance with Jared Leuschen, CEO and Founder of Blue Tree. They delve into the human component behind security and compliance issues, misalignment and communication gaps within organizations, and practical solutions for aligning IT and cybersecurity efforts. The discussion also covers the importance of risk management, the role of consultants, and effective communication strategies between IT and cybersecurity teams. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jared Leuschen</li>
<li>(01:12) - The IT and Cybersecurity Conflict</li>
<li>(03:21) - Finding Alignment Through Communication</li>
<li>(06:05) - Proactive IT Involvement in Cybersecurity</li>
<li>(15:19) - Time Management and Leadership in IT</li>
<li>(17:38) - The Role of Consultants in Cybersecurity</li>
<li>(23:46) - Vendor Management and Supply Chain Security</li>
<li>(30:33) - Aligning IT and Security with Business Goals</li>
<li>(40:17) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/13c6be56/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13c6be56/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13c6be56/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13c6be56/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/13c6be56/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/13c6be56/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Penetration Testing &amp; Threat Intelligence: Enhancing Cybersecurity | Interview with Sasa Jusic</title>
      <itunes:episode>25</itunes:episode>
      <podcast:episode>25</podcast:episode>
      <itunes:title>Penetration Testing &amp; Threat Intelligence: Enhancing Cybersecurity | Interview with Sasa Jusic</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4aa290cd-1945-49b1-9bf9-dba350de23ea</guid>
      <link>https://podcast.advisera.com/episodes/penetration-testing-threat-intelligence-enhancing-cybersecurity-interview-with-sasa-jusic</link>
      <description>
        <![CDATA[<p>In this episode, host Dejan Kosutic interviews Sasa Jusic, a board member at Infigo IS and a cybersecurity expert. They delve deep into penetration testing and cyber threat intelligence, explaining their roles in enhancing cybersecurity. Learn about the differences between offensive and defensive security measures, the importance of DORA and ISO 27001 frameworks, the critical steps for preparing and executing successful penetration tests, and the elements of threat intelligence. Sasa also shares insights on the collaboration between IT and security teams, as well as the role of consultants in this evolving landscape.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Sasa Jusic</li>
<li>(01:41) - Penetration Testing and Threat Intelligence Relationship</li>
<li>(06:23) - DORA and Its Impact on Cybersecurity</li>
<li>(08:22) - Types of Penetration Testing</li>
<li>(10:33) - Preparing for a Successful Penetration Test</li>
<li>(13:07) - Reporting and Translating Technical Findings</li>
<li>(15:56) - Acting on Penetration Test Reports</li>
<li>(19:52) - Understanding Threat Intelligence</li>
<li>(22:11) - Tools for Threat Intelligence</li>
<li>(29:01) - Common Misconceptions About Threat Intelligence</li>
<li>(31:58) - Opportunities for Cybersecurity Consultants</li>
<li>(36:42) - Key Recommendations for Security Officers</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, host Dejan Kosutic interviews Sasa Jusic, a board member at Infigo IS and a cybersecurity expert. They delve deep into penetration testing and cyber threat intelligence, explaining their roles in enhancing cybersecurity. Learn about the differences between offensive and defensive security measures, the importance of DORA and ISO 27001 frameworks, the critical steps for preparing and executing successful penetration tests, and the elements of threat intelligence. Sasa also shares insights on the collaboration between IT and security teams, as well as the role of consultants in this evolving landscape.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Sasa Jusic</li>
<li>(01:41) - Penetration Testing and Threat Intelligence Relationship</li>
<li>(06:23) - DORA and Its Impact on Cybersecurity</li>
<li>(08:22) - Types of Penetration Testing</li>
<li>(10:33) - Preparing for a Successful Penetration Test</li>
<li>(13:07) - Reporting and Translating Technical Findings</li>
<li>(15:56) - Acting on Penetration Test Reports</li>
<li>(19:52) - Understanding Threat Intelligence</li>
<li>(22:11) - Tools for Threat Intelligence</li>
<li>(29:01) - Common Misconceptions About Threat Intelligence</li>
<li>(31:58) - Opportunities for Cybersecurity Consultants</li>
<li>(36:42) - Key Recommendations for Security Officers</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 30 Dec 2025 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/0e82ea4c/2f891a46.mp3" length="39940206" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2494</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, host Dejan Kosutic interviews Sasa Jusic, a board member at Infigo IS and a cybersecurity expert. They delve deep into penetration testing and cyber threat intelligence, explaining their roles in enhancing cybersecurity. Learn about the differences between offensive and defensive security measures, the importance of DORA and ISO 27001 frameworks, the critical steps for preparing and executing successful penetration tests, and the elements of threat intelligence. Sasa also shares insights on the collaboration between IT and security teams, as well as the role of consultants in this evolving landscape.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Sasa Jusic</li>
<li>(01:41) - Penetration Testing and Threat Intelligence Relationship</li>
<li>(06:23) - DORA and Its Impact on Cybersecurity</li>
<li>(08:22) - Types of Penetration Testing</li>
<li>(10:33) - Preparing for a Successful Penetration Test</li>
<li>(13:07) - Reporting and Translating Technical Findings</li>
<li>(15:56) - Acting on Penetration Test Reports</li>
<li>(19:52) - Understanding Threat Intelligence</li>
<li>(22:11) - Tools for Threat Intelligence</li>
<li>(29:01) - Common Misconceptions About Threat Intelligence</li>
<li>(31:58) - Opportunities for Cybersecurity Consultants</li>
<li>(36:42) - Key Recommendations for Security Officers</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/0e82ea4c/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/0e82ea4c/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/0e82ea4c/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/0e82ea4c/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/0e82ea4c/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/0e82ea4c/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Simplifying ISO Standards: Insights and Best Practices | Interview with Jim Moran</title>
      <itunes:episode>24</itunes:episode>
      <podcast:episode>24</podcast:episode>
      <itunes:title>Simplifying ISO Standards: Insights and Best Practices | Interview with Jim Moran</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1fb74311-c47c-49b7-a7f8-d0de17ebbe5a</guid>
      <link>https://podcast.advisera.com/episodes/simplifying-iso-standards-insights-and-best-practices-interview-with-jim-moran</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Jim Moran, founder of SimplifyISO, to discuss the importance and methods of simplifying ISO management systems. Jim, with over 30 years of consulting experience, shares valuable insights on how overly complex management systems can hinder employee understanding and implementation, leading to higher costs and minimal return on investment. Key topics covered include the benefits of simplification, principles for effective ISO implementation, and the use of visuals and flowcharts. The episode also explores how consultants can leverage simplification to build stronger relationships with clients and scale their consulting businesses efficiently.<br> <br>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:20) - The Importance of Simplifying ISO Implementation</li>
<li>(03:34) - Key Concepts in ISO Simplification</li>
<li>(08:47) - Using Visuals and Flowcharts for ISO Processes</li>
<li>(11:49) - Simplifying Documentation and Internal Audits</li>
<li>(24:18) - Visual Aids and Risk Assessment in ISO</li>
<li>(31:42) - Microlearning for Cybersecurity Awareness</li>
<li>(36:26) - Automating Document Control in ISO Standards</li>
<li>(38:51) - Balancing Complexity and Simplicity in Software Tools</li>
<li>(47:26) - Simplification Strategies for Consultants</li>
<li>(56:40) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Jim Moran, founder of SimplifyISO, to discuss the importance and methods of simplifying ISO management systems. Jim, with over 30 years of consulting experience, shares valuable insights on how overly complex management systems can hinder employee understanding and implementation, leading to higher costs and minimal return on investment. Key topics covered include the benefits of simplification, principles for effective ISO implementation, and the use of visuals and flowcharts. The episode also explores how consultants can leverage simplification to build stronger relationships with clients and scale their consulting businesses efficiently.<br> <br>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:20) - The Importance of Simplifying ISO Implementation</li>
<li>(03:34) - Key Concepts in ISO Simplification</li>
<li>(08:47) - Using Visuals and Flowcharts for ISO Processes</li>
<li>(11:49) - Simplifying Documentation and Internal Audits</li>
<li>(24:18) - Visual Aids and Risk Assessment in ISO</li>
<li>(31:42) - Microlearning for Cybersecurity Awareness</li>
<li>(36:26) - Automating Document Control in ISO Standards</li>
<li>(38:51) - Balancing Complexity and Simplicity in Software Tools</li>
<li>(47:26) - Simplification Strategies for Consultants</li>
<li>(56:40) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 16 Dec 2025 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/5c67ee45/825c6fe7.mp3" length="55728818" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3481</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Jim Moran, founder of SimplifyISO, to discuss the importance and methods of simplifying ISO management systems. Jim, with over 30 years of consulting experience, shares valuable insights on how overly complex management systems can hinder employee understanding and implementation, leading to higher costs and minimal return on investment. Key topics covered include the benefits of simplification, principles for effective ISO implementation, and the use of visuals and flowcharts. The episode also explores how consultants can leverage simplification to build stronger relationships with clients and scale their consulting businesses efficiently.<br> <br>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:20) - The Importance of Simplifying ISO Implementation</li>
<li>(03:34) - Key Concepts in ISO Simplification</li>
<li>(08:47) - Using Visuals and Flowcharts for ISO Processes</li>
<li>(11:49) - Simplifying Documentation and Internal Audits</li>
<li>(24:18) - Visual Aids and Risk Assessment in ISO</li>
<li>(31:42) - Microlearning for Cybersecurity Awareness</li>
<li>(36:26) - Automating Document Control in ISO Standards</li>
<li>(38:51) - Balancing Complexity and Simplicity in Software Tools</li>
<li>(47:26) - Simplification Strategies for Consultants</li>
<li>(56:40) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/5c67ee45/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/5c67ee45/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/5c67ee45/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/5c67ee45/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/5c67ee45/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/5c67ee45/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Mastering Internal Audits for ISO Standards | Interview with Carlos Cruz</title>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <itunes:title>Mastering Internal Audits for ISO Standards | Interview with Carlos Cruz</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8b76b1aa-0550-4fa5-927e-0614322b50ef</guid>
      <link>https://podcast.advisera.com/episodes/mastering-internal-audits-for-iso-standards-interview-with-carlos-cruz</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO at Advisera, welcomes Carlos Cruz, founder of Metanoia Consulting and a seasoned expert in ISO standards. Carlos and Dejan share best practices for performing internal audits across various ISO standards, including ISO 27001, and other cybersecurity frameworks such as NIS2 and DORA. Key topics discussed include the importance of internal audits, how to prepare effective audit checklists, and the role of AI in the future of auditing. The episode also explores the differences between internal audit programs and plans, the significance of audit objectives, and offers practical advice for consultants looking to expand their services into internal auditing. Carlos provides a deep dive into ensuring compliance and effectiveness while offering practical tips on maintaining independence and delivering valuable audit reports. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on internal audits</li>
<li>(01:38) - Importance and Best Practices for Internal Audits</li>
<li>(04:55) - Audit Objectives and Their Importance</li>
<li>(09:38) - Creating an Internal Audit Program</li>
<li>(13:31) - Audit Plans and Internal Audit Checklists</li>
<li>(27:06) - Conducting the Main Audit</li>
<li>(30:10) - The Importance of Evidence in Auditing</li>
<li>(36:43) - Preparing the Audit Report</li>
<li>(42:13) - Consultants and Internal Audits</li>
<li>(49:29) - Remote Auditing: Challenges and Opportunities</li>
<li>(57:17) - AI in Internal Auditing</li>
<li>(01:04:34) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO at Advisera, welcomes Carlos Cruz, founder of Metanoia Consulting and a seasoned expert in ISO standards. Carlos and Dejan share best practices for performing internal audits across various ISO standards, including ISO 27001, and other cybersecurity frameworks such as NIS2 and DORA. Key topics discussed include the importance of internal audits, how to prepare effective audit checklists, and the role of AI in the future of auditing. The episode also explores the differences between internal audit programs and plans, the significance of audit objectives, and offers practical advice for consultants looking to expand their services into internal auditing. Carlos provides a deep dive into ensuring compliance and effectiveness while offering practical tips on maintaining independence and delivering valuable audit reports. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on internal audits</li>
<li>(01:38) - Importance and Best Practices for Internal Audits</li>
<li>(04:55) - Audit Objectives and Their Importance</li>
<li>(09:38) - Creating an Internal Audit Program</li>
<li>(13:31) - Audit Plans and Internal Audit Checklists</li>
<li>(27:06) - Conducting the Main Audit</li>
<li>(30:10) - The Importance of Evidence in Auditing</li>
<li>(36:43) - Preparing the Audit Report</li>
<li>(42:13) - Consultants and Internal Audits</li>
<li>(49:29) - Remote Auditing: Challenges and Opportunities</li>
<li>(57:17) - AI in Internal Auditing</li>
<li>(01:04:34) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 02 Dec 2025 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/166ac2e0/41bbe0b5.mp3" length="63318948" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3955</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO at Advisera, welcomes Carlos Cruz, founder of Metanoia Consulting and a seasoned expert in ISO standards. Carlos and Dejan share best practices for performing internal audits across various ISO standards, including ISO 27001, and other cybersecurity frameworks such as NIS2 and DORA. Key topics discussed include the importance of internal audits, how to prepare effective audit checklists, and the role of AI in the future of auditing. The episode also explores the differences between internal audit programs and plans, the significance of audit objectives, and offers practical advice for consultants looking to expand their services into internal auditing. Carlos provides a deep dive into ensuring compliance and effectiveness while offering practical tips on maintaining independence and delivering valuable audit reports. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz on internal audits</li>
<li>(01:38) - Importance and Best Practices for Internal Audits</li>
<li>(04:55) - Audit Objectives and Their Importance</li>
<li>(09:38) - Creating an Internal Audit Program</li>
<li>(13:31) - Audit Plans and Internal Audit Checklists</li>
<li>(27:06) - Conducting the Main Audit</li>
<li>(30:10) - The Importance of Evidence in Auditing</li>
<li>(36:43) - Preparing the Audit Report</li>
<li>(42:13) - Consultants and Internal Audits</li>
<li>(49:29) - Remote Auditing: Challenges and Opportunities</li>
<li>(57:17) - AI in Internal Auditing</li>
<li>(01:04:34) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/166ac2e0/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/166ac2e0/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/166ac2e0/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/166ac2e0/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/166ac2e0/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/166ac2e0/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Exploring Cyber Warfare: Risks, Strategies, and Solutions | Interview with Steve Winterfeld</title>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <itunes:title>Exploring Cyber Warfare: Risks, Strategies, and Solutions | Interview with Steve Winterfeld</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fafdb135-b00e-4d7d-9243-3fb96889143f</guid>
      <link>https://podcast.advisera.com/episodes/exploring-cyber-warfare-risks-strategies-and-solutions-interview-with-steve-winterfeld</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Steve Winterfeld, a seasoned security consultant, fractional CISO, and author of the book 'Cyber Warfare Techniques, Tactics, and Tools for Security Practitioners.' The discussion revolves around the relevance of cyber warfare for companies, the different types of cyber threats, and strategic ways to address them. Steve shares insights on cyber warfare's impact on various sectors, from espionage and sabotage to operational tactics. He emphasizes the importance of risk assessment, the utility of frameworks like the MITRE ATT&amp;CK framework, and approaches to security hygiene. The conversation provides a comprehensive look at how businesses can enhance their cybersecurity measures to safeguard against advanced threats.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Steve Winterfeld</li>
<li>(01:10) - Understanding Cyber Warfare</li>
<li>(05:41) - Impact on Commercial Sector</li>
<li>(13:01) - Strategic, Operational, and Tactical Perspectives</li>
<li>(17:27) - Risk Management and Mitigation</li>
<li>(25:48) - Securing Supply Chains and Crisis Management</li>
<li>(30:36) - Validation Exercises and Technical Debt</li>
<li>(34:47) - Cybersecurity for Smaller Companies</li>
<li>(36:49) - Consulting Opportunities in Cybersecurity</li>
<li>(51:41) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Steve Winterfeld, a seasoned security consultant, fractional CISO, and author of the book 'Cyber Warfare Techniques, Tactics, and Tools for Security Practitioners.' The discussion revolves around the relevance of cyber warfare for companies, the different types of cyber threats, and strategic ways to address them. Steve shares insights on cyber warfare's impact on various sectors, from espionage and sabotage to operational tactics. He emphasizes the importance of risk assessment, the utility of frameworks like the MITRE ATT&amp;CK framework, and approaches to security hygiene. The conversation provides a comprehensive look at how businesses can enhance their cybersecurity measures to safeguard against advanced threats.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Steve Winterfeld</li>
<li>(01:10) - Understanding Cyber Warfare</li>
<li>(05:41) - Impact on Commercial Sector</li>
<li>(13:01) - Strategic, Operational, and Tactical Perspectives</li>
<li>(17:27) - Risk Management and Mitigation</li>
<li>(25:48) - Securing Supply Chains and Crisis Management</li>
<li>(30:36) - Validation Exercises and Technical Debt</li>
<li>(34:47) - Cybersecurity for Smaller Companies</li>
<li>(36:49) - Consulting Opportunities in Cybersecurity</li>
<li>(51:41) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 18 Nov 2025 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/6b77c06e/3606ffb3.mp3" length="50945483" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3182</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic, CEO of Advisera, welcomes Steve Winterfeld, a seasoned security consultant, fractional CISO, and author of the book 'Cyber Warfare Techniques, Tactics, and Tools for Security Practitioners.' The discussion revolves around the relevance of cyber warfare for companies, the different types of cyber threats, and strategic ways to address them. Steve shares insights on cyber warfare's impact on various sectors, from espionage and sabotage to operational tactics. He emphasizes the importance of risk assessment, the utility of frameworks like the MITRE ATT&amp;CK framework, and approaches to security hygiene. The conversation provides a comprehensive look at how businesses can enhance their cybersecurity measures to safeguard against advanced threats.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Steve Winterfeld</li>
<li>(01:10) - Understanding Cyber Warfare</li>
<li>(05:41) - Impact on Commercial Sector</li>
<li>(13:01) - Strategic, Operational, and Tactical Perspectives</li>
<li>(17:27) - Risk Management and Mitigation</li>
<li>(25:48) - Securing Supply Chains and Crisis Management</li>
<li>(30:36) - Validation Exercises and Technical Debt</li>
<li>(34:47) - Cybersecurity for Smaller Companies</li>
<li>(36:49) - Consulting Opportunities in Cybersecurity</li>
<li>(51:41) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/6b77c06e/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/6b77c06e/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/6b77c06e/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/6b77c06e/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/6b77c06e/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/6b77c06e/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Bridging the Cybersecurity Gap: From Tech Rooms to Boardrooms | Interview with Paul C Dwyer</title>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <itunes:title>Bridging the Cybersecurity Gap: From Tech Rooms to Boardrooms | Interview with Paul C Dwyer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">929ed03a-fb59-4af7-a847-c879758b1d87</guid>
      <link>https://podcast.advisera.com/episodes/bridging-the-cybersecurity-gap-from-tech-rooms-to-boardrooms-interview-with-paul-c-dwyer</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, Dejan Kosutic, CEO of Advisera, interviews Paul C Dwyer, founder and CEO of Cyber Risk International and president of the ICTTF. They discuss digital resilience from a business and strategic standpoint, the role of company boards in cybersecurity, and how to effectively bridge the communication gap between technical experts and business leaders. Paul shares insights from his extensive 30-year career across military, law enforcement, and business sectors, emphasizing the importance of aligning cybersecurity and business strategies, understanding the core business, and enhancing communication skills among cybersecurity professionals to engage effectively with board members. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Paul C Dwyer</li>
<li>(01:55) - Communication Gaps in Cybersecurity</li>
<li>(03:00) - Importance of Leadership in Cybersecurity</li>
<li>(07:17) - Building Trust and Rapport</li>
<li>(09:47) - Soft Skills and People Skills</li>
<li>(18:09) - Connecting Cybersecurity with Business Strategy</li>
<li>(23:58) - Understanding Resilience and Cybersecurity</li>
<li>(28:07) - Disaster Recovery and Business Continuity</li>
<li>(33:05) - Integrating Cyber Risk into Enterprise Risk Management</li>
<li>(39:21) - Supply Chain Security and Resilience</li>
<li>(44:58) - Effective Communication with the Board</li>
<li>(49:38) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, Dejan Kosutic, CEO of Advisera, interviews Paul C Dwyer, founder and CEO of Cyber Risk International and president of the ICTTF. They discuss digital resilience from a business and strategic standpoint, the role of company boards in cybersecurity, and how to effectively bridge the communication gap between technical experts and business leaders. Paul shares insights from his extensive 30-year career across military, law enforcement, and business sectors, emphasizing the importance of aligning cybersecurity and business strategies, understanding the core business, and enhancing communication skills among cybersecurity professionals to engage effectively with board members. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Paul C Dwyer</li>
<li>(01:55) - Communication Gaps in Cybersecurity</li>
<li>(03:00) - Importance of Leadership in Cybersecurity</li>
<li>(07:17) - Building Trust and Rapport</li>
<li>(09:47) - Soft Skills and People Skills</li>
<li>(18:09) - Connecting Cybersecurity with Business Strategy</li>
<li>(23:58) - Understanding Resilience and Cybersecurity</li>
<li>(28:07) - Disaster Recovery and Business Continuity</li>
<li>(33:05) - Integrating Cyber Risk into Enterprise Risk Management</li>
<li>(39:21) - Supply Chain Security and Resilience</li>
<li>(44:58) - Effective Communication with the Board</li>
<li>(49:38) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 04 Nov 2025 13:30:00 +0100</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/734b8baa/d52703b0.mp3" length="48972153" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3059</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, Dejan Kosutic, CEO of Advisera, interviews Paul C Dwyer, founder and CEO of Cyber Risk International and president of the ICTTF. They discuss digital resilience from a business and strategic standpoint, the role of company boards in cybersecurity, and how to effectively bridge the communication gap between technical experts and business leaders. Paul shares insights from his extensive 30-year career across military, law enforcement, and business sectors, emphasizing the importance of aligning cybersecurity and business strategies, understanding the core business, and enhancing communication skills among cybersecurity professionals to engage effectively with board members. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview Paul C Dwyer</li>
<li>(01:55) - Communication Gaps in Cybersecurity</li>
<li>(03:00) - Importance of Leadership in Cybersecurity</li>
<li>(07:17) - Building Trust and Rapport</li>
<li>(09:47) - Soft Skills and People Skills</li>
<li>(18:09) - Connecting Cybersecurity with Business Strategy</li>
<li>(23:58) - Understanding Resilience and Cybersecurity</li>
<li>(28:07) - Disaster Recovery and Business Continuity</li>
<li>(33:05) - Integrating Cyber Risk into Enterprise Risk Management</li>
<li>(39:21) - Supply Chain Security and Resilience</li>
<li>(44:58) - Effective Communication with the Board</li>
<li>(49:38) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/734b8baa/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/734b8baa/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/734b8baa/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/734b8baa/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/734b8baa/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/734b8baa/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Mastering Integrated ISO Management Systems  | Interview with Jim Moran</title>
      <itunes:episode>20</itunes:episode>
      <podcast:episode>20</podcast:episode>
      <itunes:title>Mastering Integrated ISO Management Systems  | Interview with Jim Moran</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">06c60e4c-5329-446e-80ce-6a358a311d12</guid>
      <link>https://podcast.advisera.com/episodes/mastering-integrated-iso-management-systems-interview-with-jim-moran</link>
      <description>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, hosted by Dejan Kosutic, we are joined by Jim Moran, founder of Simplify ISO and member of the ISO Committee 280. With over 30 years of experience in consulting and various ISO standards, Jim shares his insights on the High-level Structure (HLS) of ISO management standards and the integration of various ISO standards into a cohesive management system. This episode covers strategies for merging ISO 9001, ISO 27001, and other standards, the benefits of HLS for integrated management systems, the importance of executive involvement, and recent updates to ISO 9001. Ideal for consultants, CISOs, and cybersecurity professionals, this episode provides practical tips and expertise on effectively implementing integrated management systems.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:49) - Understanding High-Level Structure (HLS)</li>
<li>(11:30) - The Role of Annexes in ISO Standards</li>
<li>(15:22) - Integrated Management Systems in Practice</li>
<li>(22:38) - Documenting Integrated Management Systems</li>
<li>(27:07) - Integrating Management Reviews</li>
<li>(35:42) - Starting with One Standard vs. Multiple Standards</li>
<li>(39:12) - Changes in ISO 9001 and Other Standards</li>
<li>(43:17) - Future Trends: AI and Cybersecurity</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, hosted by Dejan Kosutic, we are joined by Jim Moran, founder of Simplify ISO and member of the ISO Committee 280. With over 30 years of experience in consulting and various ISO standards, Jim shares his insights on the High-level Structure (HLS) of ISO management standards and the integration of various ISO standards into a cohesive management system. This episode covers strategies for merging ISO 9001, ISO 27001, and other standards, the benefits of HLS for integrated management systems, the importance of executive involvement, and recent updates to ISO 9001. Ideal for consultants, CISOs, and cybersecurity professionals, this episode provides practical tips and expertise on effectively implementing integrated management systems.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:49) - Understanding High-Level Structure (HLS)</li>
<li>(11:30) - The Role of Annexes in ISO Standards</li>
<li>(15:22) - Integrated Management Systems in Practice</li>
<li>(22:38) - Documenting Integrated Management Systems</li>
<li>(27:07) - Integrating Management Reviews</li>
<li>(35:42) - Starting with One Standard vs. Multiple Standards</li>
<li>(39:12) - Changes in ISO 9001 and Other Standards</li>
<li>(43:17) - Future Trends: AI and Cybersecurity</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 21 Oct 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/e1102ef7/2c874c55.mp3" length="46573099" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2909</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, hosted by Dejan Kosutic, we are joined by Jim Moran, founder of Simplify ISO and member of the ISO Committee 280. With over 30 years of experience in consulting and various ISO standards, Jim shares his insights on the High-level Structure (HLS) of ISO management standards and the integration of various ISO standards into a cohesive management system. This episode covers strategies for merging ISO 9001, ISO 27001, and other standards, the benefits of HLS for integrated management systems, the importance of executive involvement, and recent updates to ISO 9001. Ideal for consultants, CISOs, and cybersecurity professionals, this episode provides practical tips and expertise on effectively implementing integrated management systems.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Jim Moran</li>
<li>(01:49) - Understanding High-Level Structure (HLS)</li>
<li>(11:30) - The Role of Annexes in ISO Standards</li>
<li>(15:22) - Integrated Management Systems in Practice</li>
<li>(22:38) - Documenting Integrated Management Systems</li>
<li>(27:07) - Integrating Management Reviews</li>
<li>(35:42) - Starting with One Standard vs. Multiple Standards</li>
<li>(39:12) - Changes in ISO 9001 and Other Standards</li>
<li>(43:17) - Future Trends: AI and Cybersecurity</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/e1102ef7/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/e1102ef7/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/e1102ef7/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/e1102ef7/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/e1102ef7/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/e1102ef7/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Volunteer Work in Cybersecurity Nonprofits | Interview with Aruneesh Salhotra</title>
      <itunes:episode>19</itunes:episode>
      <podcast:episode>19</podcast:episode>
      <itunes:title>Volunteer Work in Cybersecurity Nonprofits | Interview with Aruneesh Salhotra</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">52eeb6a8-ae39-43c1-aa70-67332ad2ce1e</guid>
      <link>https://podcast.advisera.com/episodes/volunteer-work-in-cybersecurity-nonprofits-interview-with-aruneesh-salhotra</link>
      <description>
        <![CDATA[<p>Join Dejan Kosutic, CEO of Advisera, on the Secure and Simple Podcast as he delves into the importance of cybersecurity NGOs with expert guest Aruneesh Salhotra. Explore the impact of organizations like OWASP and the Eclipse Foundation on global cybersecurity standards, the benefits of volunteering in these NGOs, and the influence of these nonprofits on government policies. Learn about Aruneesh’s involvement with projects like OWASP AI Exchange and AI BOM, and gain insights on how consultants and CISOs can leverage these organizations for professional growth and thought leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Aruneesh Salhotra</li>
<li>(02:42) - Differences Between Cybersecurity NGOs</li>
<li>(04:55) - Governance-Oriented Cybersecurity NGOs</li>
<li>(06:19) - Educational Initiatives in Cybersecurity</li>
<li>(06:54) - OWASP AI Exchange and Its Impact</li>
<li>(13:51) - Volunteering in Cybersecurity NGOs</li>
<li>(25:45) - Aruneesh's Involvement in OWASP Projects</li>
<li>(34:43) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join Dejan Kosutic, CEO of Advisera, on the Secure and Simple Podcast as he delves into the importance of cybersecurity NGOs with expert guest Aruneesh Salhotra. Explore the impact of organizations like OWASP and the Eclipse Foundation on global cybersecurity standards, the benefits of volunteering in these NGOs, and the influence of these nonprofits on government policies. Learn about Aruneesh’s involvement with projects like OWASP AI Exchange and AI BOM, and gain insights on how consultants and CISOs can leverage these organizations for professional growth and thought leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Aruneesh Salhotra</li>
<li>(02:42) - Differences Between Cybersecurity NGOs</li>
<li>(04:55) - Governance-Oriented Cybersecurity NGOs</li>
<li>(06:19) - Educational Initiatives in Cybersecurity</li>
<li>(06:54) - OWASP AI Exchange and Its Impact</li>
<li>(13:51) - Volunteering in Cybersecurity NGOs</li>
<li>(25:45) - Aruneesh's Involvement in OWASP Projects</li>
<li>(34:43) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 07 Oct 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/1d00e3c5/db718adf.mp3" length="34653174" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2164</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Join Dejan Kosutic, CEO of Advisera, on the Secure and Simple Podcast as he delves into the importance of cybersecurity NGOs with expert guest Aruneesh Salhotra. Explore the impact of organizations like OWASP and the Eclipse Foundation on global cybersecurity standards, the benefits of volunteering in these NGOs, and the influence of these nonprofits on government policies. Learn about Aruneesh’s involvement with projects like OWASP AI Exchange and AI BOM, and gain insights on how consultants and CISOs can leverage these organizations for professional growth and thought leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Aruneesh Salhotra</li>
<li>(02:42) - Differences Between Cybersecurity NGOs</li>
<li>(04:55) - Governance-Oriented Cybersecurity NGOs</li>
<li>(06:19) - Educational Initiatives in Cybersecurity</li>
<li>(06:54) - OWASP AI Exchange and Its Impact</li>
<li>(13:51) - Volunteering in Cybersecurity NGOs</li>
<li>(25:45) - Aruneesh's Involvement in OWASP Projects</li>
<li>(34:43) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/1d00e3c5/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d00e3c5/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d00e3c5/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d00e3c5/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/1d00e3c5/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/1d00e3c5/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Building a Business-Aligned Cybersecurity Strategy | Interview with Thom Langford</title>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <itunes:title>Building a Business-Aligned Cybersecurity Strategy | Interview with Thom Langford</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">51d39d03-4d3c-4022-a437-8afedf0c02a6</guid>
      <link>https://podcast.advisera.com/episodes/building-a-business-aligned-cybersecurity-strategy-interview-with-thom-langford</link>
      <description>
        <![CDATA[<p>In this episode, Dejan Kosutic, CEO at Advisera, chats with Thom Langford, CTO of the EMEA region at Rapid7 and a director at (TL)2 Security. Thom shares invaluable insights from his 30-year career in cybersecurity, focusing on creating a business-aligned cybersecurity strategy and building a cybersecurity culture. Learn why understanding your business is crucial for effective cybersecurity, how to integrate security without hindering business operations, and ways to leverage cybersecurity as a competitive advantage. Thom also discusses the importance of risk management and how to effectively communicate cybersecurity needs to senior leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Thom Langford</li>
<li>(01:18) - Understanding Cybersecurity Strategy</li>
<li>(04:00) - Implementing Effective Cybersecurity Measures</li>
<li>(08:56) - Risk Management in Cybersecurity</li>
<li>(17:02) - Cybersecurity as a Competitive Advantage</li>
<li>(28:31) - Security Professionals' Role in Business</li>
<li>(30:13) - People-Centered Security</li>
<li>(33:58) - Effective Training Strategies</li>
<li>(37:49) - Creating a Security Culture</li>
<li>(42:01) - The Power of Storytelling and Humor</li>
<li>(51:53) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, Dejan Kosutic, CEO at Advisera, chats with Thom Langford, CTO of the EMEA region at Rapid7 and a director at (TL)2 Security. Thom shares invaluable insights from his 30-year career in cybersecurity, focusing on creating a business-aligned cybersecurity strategy and building a cybersecurity culture. Learn why understanding your business is crucial for effective cybersecurity, how to integrate security without hindering business operations, and ways to leverage cybersecurity as a competitive advantage. Thom also discusses the importance of risk management and how to effectively communicate cybersecurity needs to senior leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Thom Langford</li>
<li>(01:18) - Understanding Cybersecurity Strategy</li>
<li>(04:00) - Implementing Effective Cybersecurity Measures</li>
<li>(08:56) - Risk Management in Cybersecurity</li>
<li>(17:02) - Cybersecurity as a Competitive Advantage</li>
<li>(28:31) - Security Professionals' Role in Business</li>
<li>(30:13) - People-Centered Security</li>
<li>(33:58) - Effective Training Strategies</li>
<li>(37:49) - Creating a Security Culture</li>
<li>(42:01) - The Power of Storytelling and Humor</li>
<li>(51:53) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 23 Sep 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/d080e876/22af0819.mp3" length="51138217" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3194</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, Dejan Kosutic, CEO at Advisera, chats with Thom Langford, CTO of the EMEA region at Rapid7 and a director at (TL)2 Security. Thom shares invaluable insights from his 30-year career in cybersecurity, focusing on creating a business-aligned cybersecurity strategy and building a cybersecurity culture. Learn why understanding your business is crucial for effective cybersecurity, how to integrate security without hindering business operations, and ways to leverage cybersecurity as a competitive advantage. Thom also discusses the importance of risk management and how to effectively communicate cybersecurity needs to senior leadership. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Thom Langford</li>
<li>(01:18) - Understanding Cybersecurity Strategy</li>
<li>(04:00) - Implementing Effective Cybersecurity Measures</li>
<li>(08:56) - Risk Management in Cybersecurity</li>
<li>(17:02) - Cybersecurity as a Competitive Advantage</li>
<li>(28:31) - Security Professionals' Role in Business</li>
<li>(30:13) - People-Centered Security</li>
<li>(33:58) - Effective Training Strategies</li>
<li>(37:49) - Creating a Security Culture</li>
<li>(42:01) - The Power of Storytelling and Humor</li>
<li>(51:53) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/d080e876/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d080e876/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d080e876/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d080e876/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/d080e876/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/d080e876/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Demystifying Corporate Governance With ISO 37000 | Interview with George Kesteven</title>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <itunes:title>Demystifying Corporate Governance With ISO 37000 | Interview with George Kesteven</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2964571d-0938-4cf2-919b-fae56ad21a45</guid>
      <link>https://podcast.advisera.com/episodes/demystifying-corporate-governance-with-iso-37000-interview-with-george-kesteven</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple podcast, host Dejan Kosutic interviews George Kesteven, CEO of Frontex, who shares his experience in corporate governance. They discuss the critical importance of proper documentation and knowledge management in organizations for effective governance and compliance. The conversation covers the fundamentals of ISO 37000, how it helps organizations meet their governance objectives, and the distinctions between governance and management. They also explore how consultants can leverage ISO 37000 to assist organizations in achieving well-defined and structured governance systems. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with George Kesteven</li>
<li>(01:14) - The Importance of Governance and Compliance</li>
<li>(04:05) - Corporate Governance Management Systems Explained</li>
<li>(07:18) - ISO 37000: Principles and Applications</li>
<li>(14:26) - Governance vs. Management</li>
<li>(18:21) - Consultants' Role in Governance</li>
<li>(22:41) - The Value of Proper Documentation</li>
<li>(32:00) - ISO 37000: Starting Points for Consultants</li>
<li>(36:18) - Measuring Governance with ISO 37004</li>
<li>(38:44) - ESG and Corporate Governance</li>
<li>(42:13) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple podcast, host Dejan Kosutic interviews George Kesteven, CEO of Frontex, who shares his experience in corporate governance. They discuss the critical importance of proper documentation and knowledge management in organizations for effective governance and compliance. The conversation covers the fundamentals of ISO 37000, how it helps organizations meet their governance objectives, and the distinctions between governance and management. They also explore how consultants can leverage ISO 37000 to assist organizations in achieving well-defined and structured governance systems. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with George Kesteven</li>
<li>(01:14) - The Importance of Governance and Compliance</li>
<li>(04:05) - Corporate Governance Management Systems Explained</li>
<li>(07:18) - ISO 37000: Principles and Applications</li>
<li>(14:26) - Governance vs. Management</li>
<li>(18:21) - Consultants' Role in Governance</li>
<li>(22:41) - The Value of Proper Documentation</li>
<li>(32:00) - ISO 37000: Starting Points for Consultants</li>
<li>(36:18) - Measuring Governance with ISO 37004</li>
<li>(38:44) - ESG and Corporate Governance</li>
<li>(42:13) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 09 Sep 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/22d427ba/fd790fd3.mp3" length="41862067" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2614</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple podcast, host Dejan Kosutic interviews George Kesteven, CEO of Frontex, who shares his experience in corporate governance. They discuss the critical importance of proper documentation and knowledge management in organizations for effective governance and compliance. The conversation covers the fundamentals of ISO 37000, how it helps organizations meet their governance objectives, and the distinctions between governance and management. They also explore how consultants can leverage ISO 37000 to assist organizations in achieving well-defined and structured governance systems. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with George Kesteven</li>
<li>(01:14) - The Importance of Governance and Compliance</li>
<li>(04:05) - Corporate Governance Management Systems Explained</li>
<li>(07:18) - ISO 37000: Principles and Applications</li>
<li>(14:26) - Governance vs. Management</li>
<li>(18:21) - Consultants' Role in Governance</li>
<li>(22:41) - The Value of Proper Documentation</li>
<li>(32:00) - ISO 37000: Starting Points for Consultants</li>
<li>(36:18) - Measuring Governance with ISO 37004</li>
<li>(38:44) - ESG and Corporate Governance</li>
<li>(42:13) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/22d427ba/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/22d427ba/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/22d427ba/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/22d427ba/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/22d427ba/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/22d427ba/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>U.S. vs International and European Cybersecurity Standards | Interview with John Verry</title>
      <itunes:episode>16</itunes:episode>
      <podcast:episode>16</podcast:episode>
      <itunes:title>U.S. vs International and European Cybersecurity Standards | Interview with John Verry</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">48c2f415-fba2-4ee5-b6f6-38334f454e8f</guid>
      <link>https://podcast.advisera.com/episodes/u-s-vs-international-and-european-cybersecurity-standards-interview-with-john-verry</link>
      <description>
        <![CDATA[<p>In this episode, host Dejan Kosutic, CEO of Advisera, welcomes John Verry, Managing Director at CBIZ Pivot Point Security consulting company. With over 25 years of experience and managing more than a thousand clients, John shares his immense expertise in various cybersecurity frameworks, including ISO 27001, CMMC, HIPAA, and HITRUST. The discussion delves deep into the complexities and opportunities within cybersecurity governance, the nuances of different frameworks (especially ISO 27001 and HITRUST), and the impact of AI and privacy regulations. Whether you're a consultant, CISO, or cybersecurity professional, this episode has valuable insights to help you navigate the ever-evolving landscape of cybersecurity compliance. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with John Verry</li>
<li>(00:15) - Meet the Guest: John Verry</li>
<li>(01:10) - Comparing Cybersecurity Frameworks</li>
<li>(05:12) - The Impact of AI and Other Frameworks</li>
<li>(07:46) - HITRUST and Its Market</li>
<li>(12:00) - HIPAA vs. HITRUST</li>
<li>(14:45) - ISO 27001 vs. SOC 2 in the US Market</li>
<li>(17:27) - Working with European Clients</li>
<li>(24:35) - Navigating Privacy Laws in the US and Europe</li>
<li>(29:20) - The Role of AI in Consulting</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, host Dejan Kosutic, CEO of Advisera, welcomes John Verry, Managing Director at CBIZ Pivot Point Security consulting company. With over 25 years of experience and managing more than a thousand clients, John shares his immense expertise in various cybersecurity frameworks, including ISO 27001, CMMC, HIPAA, and HITRUST. The discussion delves deep into the complexities and opportunities within cybersecurity governance, the nuances of different frameworks (especially ISO 27001 and HITRUST), and the impact of AI and privacy regulations. Whether you're a consultant, CISO, or cybersecurity professional, this episode has valuable insights to help you navigate the ever-evolving landscape of cybersecurity compliance. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with John Verry</li>
<li>(00:15) - Meet the Guest: John Verry</li>
<li>(01:10) - Comparing Cybersecurity Frameworks</li>
<li>(05:12) - The Impact of AI and Other Frameworks</li>
<li>(07:46) - HITRUST and Its Market</li>
<li>(12:00) - HIPAA vs. HITRUST</li>
<li>(14:45) - ISO 27001 vs. SOC 2 in the US Market</li>
<li>(17:27) - Working with European Clients</li>
<li>(24:35) - Navigating Privacy Laws in the US and Europe</li>
<li>(29:20) - The Role of AI in Consulting</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 26 Aug 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/186ed6f0/4cfb6c40.mp3" length="39934337" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2494</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, host Dejan Kosutic, CEO of Advisera, welcomes John Verry, Managing Director at CBIZ Pivot Point Security consulting company. With over 25 years of experience and managing more than a thousand clients, John shares his immense expertise in various cybersecurity frameworks, including ISO 27001, CMMC, HIPAA, and HITRUST. The discussion delves deep into the complexities and opportunities within cybersecurity governance, the nuances of different frameworks (especially ISO 27001 and HITRUST), and the impact of AI and privacy regulations. Whether you're a consultant, CISO, or cybersecurity professional, this episode has valuable insights to help you navigate the ever-evolving landscape of cybersecurity compliance. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a><br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong><a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with John Verry</li>
<li>(00:15) - Meet the Guest: John Verry</li>
<li>(01:10) - Comparing Cybersecurity Frameworks</li>
<li>(05:12) - The Impact of AI and Other Frameworks</li>
<li>(07:46) - HITRUST and Its Market</li>
<li>(12:00) - HIPAA vs. HITRUST</li>
<li>(14:45) - ISO 27001 vs. SOC 2 in the US Market</li>
<li>(17:27) - Working with European Clients</li>
<li>(24:35) - Navigating Privacy Laws in the US and Europe</li>
<li>(29:20) - The Role of AI in Consulting</li>
<li>(40:13) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/186ed6f0/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/186ed6f0/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/186ed6f0/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/186ed6f0/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/186ed6f0/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/186ed6f0/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Best Practices for Writing Policies and Procedures | Interview with Carlos Cruz</title>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <itunes:title>Best Practices for Writing Policies and Procedures | Interview with Carlos Cruz</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">95c73871-c2c6-4078-a213-d1a0472312bb</guid>
      <link>https://podcast.advisera.com/episodes/best-practices-for-writing-policies-and-procedures-interview-with-carlos-cruz</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia Consulting in Portugal. They discuss essential best practices for creating and managing policies, procedures, plans, and other documents for compliance with ISO standards and cybersecurity regulations. Carlos shares insights on the distinction between procedures and work instructions, the importance of writing clear and concise documents, and the challenges of getting employees to adopt new procedures. They also cover the importance of templates, techniques for ensuring documents reflect current practices, and strategies for addressing resistance to new documents. This episode is a must-watch for consultants, CISOs, and other cybersecurity professionals looking to streamline their documentation process.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a> <br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong> <a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz</li>
<li>(01:55) - Types of Documents: Policies, Procedures, and Work Instructions</li>
<li>(11:51) - The Importance of Short and Focused Documents</li>
<li>(21:46) - Structuring Documents for Clarity and Compliance</li>
<li>(33:34) - Adapting Documents to Client Needs</li>
<li>(39:31) - The Importance of Templates for Writing Documents</li>
<li>(43:58) - Deciding What to Document</li>
<li>(45:50) - The Roles in Document Creation</li>
<li>(01:15:04) - Common Mistakes in Document Writing</li>
<li>(01:21:39) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia Consulting in Portugal. They discuss essential best practices for creating and managing policies, procedures, plans, and other documents for compliance with ISO standards and cybersecurity regulations. Carlos shares insights on the distinction between procedures and work instructions, the importance of writing clear and concise documents, and the challenges of getting employees to adopt new procedures. They also cover the importance of templates, techniques for ensuring documents reflect current practices, and strategies for addressing resistance to new documents. This episode is a must-watch for consultants, CISOs, and other cybersecurity professionals looking to streamline their documentation process.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a> <br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong> <a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz</li>
<li>(01:55) - Types of Documents: Policies, Procedures, and Work Instructions</li>
<li>(11:51) - The Importance of Short and Focused Documents</li>
<li>(21:46) - Structuring Documents for Clarity and Compliance</li>
<li>(33:34) - Adapting Documents to Client Needs</li>
<li>(39:31) - The Importance of Templates for Writing Documents</li>
<li>(43:58) - Deciding What to Document</li>
<li>(45:50) - The Roles in Document Creation</li>
<li>(01:15:04) - Common Mistakes in Document Writing</li>
<li>(01:21:39) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 12 Aug 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/77f96940/a56f0398.mp3" length="79714071" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>4980</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia Consulting in Portugal. They discuss essential best practices for creating and managing policies, procedures, plans, and other documents for compliance with ISO standards and cybersecurity regulations. Carlos shares insights on the distinction between procedures and work instructions, the importance of writing clear and concise documents, and the challenges of getting employees to adopt new procedures. They also cover the importance of templates, techniques for ensuring documents reflect current practices, and strategies for addressing resistance to new documents. This episode is a must-watch for consultants, CISOs, and other cybersecurity professionals looking to streamline their documentation process.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  <br>- <strong>Beginner's Course for ISO, Cybersecurity, and AI Consultants:</strong> <a href="https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t">https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t</a> <br>- <strong>How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:</strong> <a href="https://advisera.co/GrowYourConsultancyTraining">https://advisera.co/GrowYourConsultancyTraining</a> </p>
<ul><li>(00:00) - Interview with Carlos Cruz</li>
<li>(01:55) - Types of Documents: Policies, Procedures, and Work Instructions</li>
<li>(11:51) - The Importance of Short and Focused Documents</li>
<li>(21:46) - Structuring Documents for Clarity and Compliance</li>
<li>(33:34) - Adapting Documents to Client Needs</li>
<li>(39:31) - The Importance of Templates for Writing Documents</li>
<li>(43:58) - Deciding What to Document</li>
<li>(45:50) - The Roles in Document Creation</li>
<li>(01:15:04) - Common Mistakes in Document Writing</li>
<li>(01:21:39) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/77f96940/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77f96940/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77f96940/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77f96940/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/77f96940/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/77f96940/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>The Journey and Insights of a Successful Fractional CISO | Interview with Terry Ziemniak</title>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <itunes:title>The Journey and Insights of a Successful Fractional CISO | Interview with Terry Ziemniak</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">53d2c35b-99af-4e33-9799-c79d2e7a8174</guid>
      <link>https://podcast.advisera.com/episodes/the-journey-and-insights-of-a-successful-fractional-ciso-interview-with-terry-ziemniak</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we sit down with Terry Ziemniak, an experienced fractional CISO with over a decade in the field. Terry shares his unique career journey from traditional cybersecurity roles to becoming a trusted fractional CISO. We discuss the key differences between full-time and fractional CISOs, how to balance multiple clients, and the importance of aligning cybersecurity with business goals. Terry also provides valuable insights on the essentials of well-written security policies, the crossover between AI governance and cybersecurity, and tips for aspiring fractional CISOs. Join us for a deep dive into the world of fractional cybersecurity leadership and learn how to navigate and succeed in this growing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Terry Ziemniak</li>
<li>(02:28) - The Value of Business Alignment in Cybersecurity</li>
<li>(11:20) - Understanding the Role of a Fractional CISO</li>
<li>(18:29) - Educating Stakeholders on Cybersecurity</li>
<li>(23:13) - Finding Allies in the Organization</li>
<li>(25:42) - Importance of Well-Written Security Policies</li>
<li>(29:48) - Market Opportunities for Fractional CISOs</li>
<li>(31:26) - Challenges and Strategies for Fractional CISOs</li>
<li>(38:24) - AI Governance and Cybersecurity</li>
<li>(45:05) - Future of the CISO Role</li>
<li>(48:34) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we sit down with Terry Ziemniak, an experienced fractional CISO with over a decade in the field. Terry shares his unique career journey from traditional cybersecurity roles to becoming a trusted fractional CISO. We discuss the key differences between full-time and fractional CISOs, how to balance multiple clients, and the importance of aligning cybersecurity with business goals. Terry also provides valuable insights on the essentials of well-written security policies, the crossover between AI governance and cybersecurity, and tips for aspiring fractional CISOs. Join us for a deep dive into the world of fractional cybersecurity leadership and learn how to navigate and succeed in this growing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Terry Ziemniak</li>
<li>(02:28) - The Value of Business Alignment in Cybersecurity</li>
<li>(11:20) - Understanding the Role of a Fractional CISO</li>
<li>(18:29) - Educating Stakeholders on Cybersecurity</li>
<li>(23:13) - Finding Allies in the Organization</li>
<li>(25:42) - Importance of Well-Written Security Policies</li>
<li>(29:48) - Market Opportunities for Fractional CISOs</li>
<li>(31:26) - Challenges and Strategies for Fractional CISOs</li>
<li>(38:24) - AI Governance and Cybersecurity</li>
<li>(45:05) - Future of the CISO Role</li>
<li>(48:34) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 29 Jul 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/13907a29/86e165b8.mp3" length="47948868" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2995</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we sit down with Terry Ziemniak, an experienced fractional CISO with over a decade in the field. Terry shares his unique career journey from traditional cybersecurity roles to becoming a trusted fractional CISO. We discuss the key differences between full-time and fractional CISOs, how to balance multiple clients, and the importance of aligning cybersecurity with business goals. Terry also provides valuable insights on the essentials of well-written security policies, the crossover between AI governance and cybersecurity, and tips for aspiring fractional CISOs. Join us for a deep dive into the world of fractional cybersecurity leadership and learn how to navigate and succeed in this growing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Terry Ziemniak</li>
<li>(02:28) - The Value of Business Alignment in Cybersecurity</li>
<li>(11:20) - Understanding the Role of a Fractional CISO</li>
<li>(18:29) - Educating Stakeholders on Cybersecurity</li>
<li>(23:13) - Finding Allies in the Organization</li>
<li>(25:42) - Importance of Well-Written Security Policies</li>
<li>(29:48) - Market Opportunities for Fractional CISOs</li>
<li>(31:26) - Challenges and Strategies for Fractional CISOs</li>
<li>(38:24) - AI Governance and Cybersecurity</li>
<li>(45:05) - Future of the CISO Role</li>
<li>(48:34) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/13907a29/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13907a29/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13907a29/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/13907a29/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/13907a29/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/13907a29/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>ISO-as-a-Service and AI: Innovation in Consultancy  | Interview with Alexander Jaber</title>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:title>ISO-as-a-Service and AI: Innovation in Consultancy  | Interview with Alexander Jaber</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3391a7d4-674d-4e17-b173-3d77e8124af9</guid>
      <link>https://podcast.advisera.com/episodes/iso-as-a-service-and-ai-innovation-in-consultancy-interview-with-alexander-jaber</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Alexander Jaber, CEO of Compliant Business Solutions GmbH, a consulting company from Germany. They discuss ISO 27001 as a service, an innovative approach that combines consulting, policy writing, software, and certification into a cohesive package. Alexander shares insights on the consulting business, the importance of building client trust, the impact of AI on consultancy, and the future of compliance. Tune in to learn about the challenges and advantages of this unique service model and how AI could transform the industry.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Alexander Jaber</li>
<li>(05:01) - ISO 27001 as a Service Explained</li>
<li>(12:57) - Customer Collaboration and Trust</li>
<li>(19:26) - Importance of Using Software</li>
<li>(20:39) - Service Relevance for Different Company Sizes</li>
<li>(22:16) - Pricing Model</li>
<li>(25:51) - Impact of AI on Compliance</li>
<li>(29:23) - Future of Consultants in an AI-Driven World</li>
<li>(34:17) - AI Agents in Compliance</li>
<li>(39:39) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Alexander Jaber, CEO of Compliant Business Solutions GmbH, a consulting company from Germany. They discuss ISO 27001 as a service, an innovative approach that combines consulting, policy writing, software, and certification into a cohesive package. Alexander shares insights on the consulting business, the importance of building client trust, the impact of AI on consultancy, and the future of compliance. Tune in to learn about the challenges and advantages of this unique service model and how AI could transform the industry.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Alexander Jaber</li>
<li>(05:01) - ISO 27001 as a Service Explained</li>
<li>(12:57) - Customer Collaboration and Trust</li>
<li>(19:26) - Importance of Using Software</li>
<li>(20:39) - Service Relevance for Different Company Sizes</li>
<li>(22:16) - Pricing Model</li>
<li>(25:51) - Impact of AI on Compliance</li>
<li>(29:23) - Future of Consultants in an AI-Driven World</li>
<li>(34:17) - AI Agents in Compliance</li>
<li>(39:39) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 15 Jul 2025 13:30:00 +0200</pubDate>
      <author>ISO-as-a-Service and AI: Innovation in Consultancy  | Interview with Alexander Jaber</author>
      <enclosure url="https://media.transistor.fm/35d9f4aa/f025b107.mp3" length="39397990" type="audio/mpeg"/>
      <itunes:author>ISO-as-a-Service and AI: Innovation in Consultancy  | Interview with Alexander Jaber</itunes:author>
      <itunes:duration>2460</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Alexander Jaber, CEO of Compliant Business Solutions GmbH, a consulting company from Germany. They discuss ISO 27001 as a service, an innovative approach that combines consulting, policy writing, software, and certification into a cohesive package. Alexander shares insights on the consulting business, the importance of building client trust, the impact of AI on consultancy, and the future of compliance. Tune in to learn about the challenges and advantages of this unique service model and how AI could transform the industry.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Alexander Jaber</li>
<li>(05:01) - ISO 27001 as a Service Explained</li>
<li>(12:57) - Customer Collaboration and Trust</li>
<li>(19:26) - Importance of Using Software</li>
<li>(20:39) - Service Relevance for Different Company Sizes</li>
<li>(22:16) - Pricing Model</li>
<li>(25:51) - Impact of AI on Compliance</li>
<li>(29:23) - Future of Consultants in an AI-Driven World</li>
<li>(34:17) - AI Agents in Compliance</li>
<li>(39:39) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/35d9f4aa/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/35d9f4aa/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/35d9f4aa/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/35d9f4aa/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/35d9f4aa/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/35d9f4aa/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Role of EU Cybersecurity Bodies and How to Cooperate With Them | Interview with Brian Honan</title>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>Role of EU Cybersecurity Bodies and How to Cooperate With Them | Interview with Brian Honan</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">37a564e4-33fd-41ec-aec0-255ad0a25756</guid>
      <link>https://podcast.advisera.com/episodes/role-of-eu-cybersecurity-bodies-and-how-to-cooperate-with-them-interview-with-brian-honan</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Brian Honan, the CEO of BH Consulting, to discuss the evolving landscape of cybersecurity and its governance, particularly in the EU. Brian shares insights on the role of European cybersecurity bodies like ENISA and the importance of cybersecurity in business operations. The discussion covers how to effectively communicate cybersecurity concerns to non-technical stakeholders, tips for building a successful consultancy, and the potential impact of new regulations like NIS2 and DORA on the industry. Learn about the resources and tools available for consultants on the ENISA website and how collaboration with national and EU bodies can enhance cybersecurity efforts.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Brian Honan</li>
<li>(05:21) - European Cybersecurity Organizations and Their Roles</li>
<li>(12:49) - Consulting and EU Cybersecurity Resources</li>
<li>(18:11) - Engaging with National and EU Cybersecurity Bodies</li>
<li>(25:38) - The Role of Cyber Ireland</li>
<li>(27:54) - Government Grants and Support</li>
<li>(29:50) - Consultant's Role in Government Policy</li>
<li>(31:40) - Translating Cybersecurity for Businesses</li>
<li>(37:15) - Competitive Advantage Through Cybersecurity</li>
<li>(43:52) - Opportunities in Cybersecurity Regulations</li>
<li>(51:04) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Brian Honan, the CEO of BH Consulting, to discuss the evolving landscape of cybersecurity and its governance, particularly in the EU. Brian shares insights on the role of European cybersecurity bodies like ENISA and the importance of cybersecurity in business operations. The discussion covers how to effectively communicate cybersecurity concerns to non-technical stakeholders, tips for building a successful consultancy, and the potential impact of new regulations like NIS2 and DORA on the industry. Learn about the resources and tools available for consultants on the ENISA website and how collaboration with national and EU bodies can enhance cybersecurity efforts.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Brian Honan</li>
<li>(05:21) - European Cybersecurity Organizations and Their Roles</li>
<li>(12:49) - Consulting and EU Cybersecurity Resources</li>
<li>(18:11) - Engaging with National and EU Cybersecurity Bodies</li>
<li>(25:38) - The Role of Cyber Ireland</li>
<li>(27:54) - Government Grants and Support</li>
<li>(29:50) - Consultant's Role in Government Policy</li>
<li>(31:40) - Translating Cybersecurity for Businesses</li>
<li>(37:15) - Competitive Advantage Through Cybersecurity</li>
<li>(43:52) - Opportunities in Cybersecurity Regulations</li>
<li>(51:04) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 01 Jul 2025 11:11:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/991161f7/61b71659.mp3" length="50350066" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3145</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Brian Honan, the CEO of BH Consulting, to discuss the evolving landscape of cybersecurity and its governance, particularly in the EU. Brian shares insights on the role of European cybersecurity bodies like ENISA and the importance of cybersecurity in business operations. The discussion covers how to effectively communicate cybersecurity concerns to non-technical stakeholders, tips for building a successful consultancy, and the potential impact of new regulations like NIS2 and DORA on the industry. Learn about the resources and tools available for consultants on the ENISA website and how collaboration with national and EU bodies can enhance cybersecurity efforts.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Brian Honan</li>
<li>(05:21) - European Cybersecurity Organizations and Their Roles</li>
<li>(12:49) - Consulting and EU Cybersecurity Resources</li>
<li>(18:11) - Engaging with National and EU Cybersecurity Bodies</li>
<li>(25:38) - The Role of Cyber Ireland</li>
<li>(27:54) - Government Grants and Support</li>
<li>(29:50) - Consultant's Role in Government Policy</li>
<li>(31:40) - Translating Cybersecurity for Businesses</li>
<li>(37:15) - Competitive Advantage Through Cybersecurity</li>
<li>(43:52) - Opportunities in Cybersecurity Regulations</li>
<li>(51:04) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/991161f7/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/991161f7/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/991161f7/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/991161f7/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/991161f7/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/991161f7/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title> Coaching as a Service for Human-Centric Cybersecurity | Interview with Dominic Vogel</title>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:title> Coaching as a Service for Human-Centric Cybersecurity | Interview with Dominic Vogel</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">87f9f46c-92b6-4b36-b5c1-c116ea5c41b3</guid>
      <link>https://podcast.advisera.com/episodes/coaching-as-a-service-for-human-centric-cybersecurity-interview-with-dominic-vogel</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic sits down with Dominic "Dom" Vogel, president of Vogel Cyber Leadership and Coaching. Dom shares his unique journey from traditional cybersecurity consulting to a more human-focused coaching approach. He emphasizes the importance of building strong, empathetic relationships within tech teams and improving internal branding. Dom also discusses the value of integrating cybersecurity strategies with business goals and how a human-centric methodology can lead to more meaningful and sustainable change in organizations. With insights into his coaching methods and client success stories, this episode provides actionable advice for cybersecurity professionals, IT leaders, and consultants looking to enhance their leadership and coaching skills.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Dominic Vogel</li>
<li>(02:40) - Human-Centric Approach to Cybersecurity Coaching</li>
<li>(04:25) - Coaching Success Stories</li>
<li>(14:55) - The Importance of Internal Branding</li>
<li>(19:46) - Cybersecurity Leadership in Small Organizations</li>
<li>(24:08) - Aligning Cybersecurity with Business Goals</li>
<li>(29:33) - Building Sustainable Client Relationships</li>
<li>(31:26) - Value-Based Pricing in Consulting</li>
<li>(34:47) - The Importance of Saying No</li>
<li>(37:20) - Opportunities in Small and Mid-Sized Businesses</li>
<li>(40:13) - Leveraging Speaking Engagements for Leads</li>
<li>(43:23) - The Role of AI in Consulting</li>
<li>(47:31) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic sits down with Dominic "Dom" Vogel, president of Vogel Cyber Leadership and Coaching. Dom shares his unique journey from traditional cybersecurity consulting to a more human-focused coaching approach. He emphasizes the importance of building strong, empathetic relationships within tech teams and improving internal branding. Dom also discusses the value of integrating cybersecurity strategies with business goals and how a human-centric methodology can lead to more meaningful and sustainable change in organizations. With insights into his coaching methods and client success stories, this episode provides actionable advice for cybersecurity professionals, IT leaders, and consultants looking to enhance their leadership and coaching skills.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Dominic Vogel</li>
<li>(02:40) - Human-Centric Approach to Cybersecurity Coaching</li>
<li>(04:25) - Coaching Success Stories</li>
<li>(14:55) - The Importance of Internal Branding</li>
<li>(19:46) - Cybersecurity Leadership in Small Organizations</li>
<li>(24:08) - Aligning Cybersecurity with Business Goals</li>
<li>(29:33) - Building Sustainable Client Relationships</li>
<li>(31:26) - Value-Based Pricing in Consulting</li>
<li>(34:47) - The Importance of Saying No</li>
<li>(37:20) - Opportunities in Small and Mid-Sized Businesses</li>
<li>(40:13) - Leveraging Speaking Engagements for Leads</li>
<li>(43:23) - The Role of AI in Consulting</li>
<li>(47:31) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 17 Jun 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/77a068b5/c5a0ad44.mp3" length="46951000" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2932</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic sits down with Dominic "Dom" Vogel, president of Vogel Cyber Leadership and Coaching. Dom shares his unique journey from traditional cybersecurity consulting to a more human-focused coaching approach. He emphasizes the importance of building strong, empathetic relationships within tech teams and improving internal branding. Dom also discusses the value of integrating cybersecurity strategies with business goals and how a human-centric methodology can lead to more meaningful and sustainable change in organizations. With insights into his coaching methods and client success stories, this episode provides actionable advice for cybersecurity professionals, IT leaders, and consultants looking to enhance their leadership and coaching skills.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Dominic Vogel</li>
<li>(02:40) - Human-Centric Approach to Cybersecurity Coaching</li>
<li>(04:25) - Coaching Success Stories</li>
<li>(14:55) - The Importance of Internal Branding</li>
<li>(19:46) - Cybersecurity Leadership in Small Organizations</li>
<li>(24:08) - Aligning Cybersecurity with Business Goals</li>
<li>(29:33) - Building Sustainable Client Relationships</li>
<li>(31:26) - Value-Based Pricing in Consulting</li>
<li>(34:47) - The Importance of Saying No</li>
<li>(37:20) - Opportunities in Small and Mid-Sized Businesses</li>
<li>(40:13) - Leveraging Speaking Engagements for Leads</li>
<li>(43:23) - The Role of AI in Consulting</li>
<li>(47:31) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/77a068b5/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77a068b5/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77a068b5/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/77a068b5/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/77a068b5/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/77a068b5/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Next-level Consulting: Marketing &amp; AI Governance Opportunities | Interview with Tudor Galos</title>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>Next-level Consulting: Marketing &amp; AI Governance Opportunities | Interview with Tudor Galos</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">08d14443-438a-4293-8c5d-fafe7013363f</guid>
      <link>https://podcast.advisera.com/episodes/next-level-consulting-marketing-ai-governance-opportunities-interview-with-tudor-galos</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we delve into the secrets of becoming a subject matter expert and thriving as a consultant. Our special guest, Tudor Galos, shares his transition from a marketing role at Microsoft to establishing his AI and GDPR consultancy. We explore the power of providing valuable content, maintaining positive client experiences, and navigating the growing field of AI governance. Packed with insights on marketing strategies, building trust, and dominating your niche, this episode is a must-watch for cybersecurity (and other) consultants.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p>
<ul><li>(00:00) - Interview with Tudor Galos</li>
<li>(01:11) - Transition from Corporate to Entrepreneurship</li>
<li>(03:40) - Offering Free Consultations to Build a Brand</li>
<li>(07:48) - Focusing on Small and Medium-Sized Clients</li>
<li>(12:20) - Building Trust and Securing Clients</li>
<li>(20:45) - The Importance of Specialization</li>
<li>(24:37) - Expanding into AI Governance</li>
<li>(35:05) - Pricing Strategies for Consultants</li>
<li>(37:45) - The Future of Consulting in the AI Era</li>
<li>(42:23) - Advice for Aspiring Consultants</li>
<li>(44:42) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we delve into the secrets of becoming a subject matter expert and thriving as a consultant. Our special guest, Tudor Galos, shares his transition from a marketing role at Microsoft to establishing his AI and GDPR consultancy. We explore the power of providing valuable content, maintaining positive client experiences, and navigating the growing field of AI governance. Packed with insights on marketing strategies, building trust, and dominating your niche, this episode is a must-watch for cybersecurity (and other) consultants.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p>
<ul><li>(00:00) - Interview with Tudor Galos</li>
<li>(01:11) - Transition from Corporate to Entrepreneurship</li>
<li>(03:40) - Offering Free Consultations to Build a Brand</li>
<li>(07:48) - Focusing on Small and Medium-Sized Clients</li>
<li>(12:20) - Building Trust and Securing Clients</li>
<li>(20:45) - The Importance of Specialization</li>
<li>(24:37) - Expanding into AI Governance</li>
<li>(35:05) - Pricing Strategies for Consultants</li>
<li>(37:45) - The Future of Consulting in the AI Era</li>
<li>(42:23) - Advice for Aspiring Consultants</li>
<li>(44:42) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 03 Jun 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/d8ace4d8/8ce23691.mp3" length="44238605" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2763</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, we delve into the secrets of becoming a subject matter expert and thriving as a consultant. Our special guest, Tudor Galos, shares his transition from a marketing role at Microsoft to establishing his AI and GDPR consultancy. We explore the power of providing valuable content, maintaining positive client experiences, and navigating the growing field of AI governance. Packed with insights on marketing strategies, building trust, and dominating your niche, this episode is a must-watch for cybersecurity (and other) consultants.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p>
<ul><li>(00:00) - Interview with Tudor Galos</li>
<li>(01:11) - Transition from Corporate to Entrepreneurship</li>
<li>(03:40) - Offering Free Consultations to Build a Brand</li>
<li>(07:48) - Focusing on Small and Medium-Sized Clients</li>
<li>(12:20) - Building Trust and Securing Clients</li>
<li>(20:45) - The Importance of Specialization</li>
<li>(24:37) - Expanding into AI Governance</li>
<li>(35:05) - Pricing Strategies for Consultants</li>
<li>(37:45) - The Future of Consulting in the AI Era</li>
<li>(42:23) - Advice for Aspiring Consultants</li>
<li>(44:42) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/d8ace4d8/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d8ace4d8/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d8ace4d8/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d8ace4d8/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/d8ace4d8/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/d8ace4d8/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title> How to Scale Cybersecurity Consultancy | Interview with Bevan Lane</title>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title> How to Scale Cybersecurity Consultancy | Interview with Bevan Lane</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d6effadf-3c21-416f-be9a-03bed9cf153c</guid>
      <link>https://podcast.advisera.com/episodes/how-to-scale-cybersecurity-consultancy-interview-with-bevan-lane</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic speaks with Bevan Lane, CEO of InfoSec Advisory Group. Bevan shares his journey from starting as an independent contractor to building a successful cybersecurity consultancy with offices in South Africa and London, and clients across five continents. Learn about his approach to scaling the business, including hiring passionate young talent, leveraging automation, and adapting to industry changes. Bevan also discusses the importance of balancing work and family life and provides valuable advice for aspiring consultants. Stay tuned for insights on the future of cybersecurity consulting and more.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Bevan Lane</li>
<li>(03:11) - Hiring and Training the Right People</li>
<li>(06:26) - Mentorship and Structured Training</li>
<li>(09:34) - Challenges of Retaining Talent</li>
<li>(10:55) - CEO's Role and Company Growth Strategy</li>
<li>(14:22) - Impact of AI on Consulting and Auditing</li>
<li>(17:49) - Finding and Partnering with Clients</li>
<li>(22:45) - Leveraging LinkedIn for Business Growth</li>
<li>(27:02) - Challenges in Consultancy</li>
<li>(30:29) - Balancing Work and Personal Life</li>
<li>(35:23) - Future of Consulting and Auditing</li>
<li>(40:27) - Advice for Aspiring Consultants</li>
<li>(42:54) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic speaks with Bevan Lane, CEO of InfoSec Advisory Group. Bevan shares his journey from starting as an independent contractor to building a successful cybersecurity consultancy with offices in South Africa and London, and clients across five continents. Learn about his approach to scaling the business, including hiring passionate young talent, leveraging automation, and adapting to industry changes. Bevan also discusses the importance of balancing work and family life and provides valuable advice for aspiring consultants. Stay tuned for insights on the future of cybersecurity consulting and more.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Bevan Lane</li>
<li>(03:11) - Hiring and Training the Right People</li>
<li>(06:26) - Mentorship and Structured Training</li>
<li>(09:34) - Challenges of Retaining Talent</li>
<li>(10:55) - CEO's Role and Company Growth Strategy</li>
<li>(14:22) - Impact of AI on Consulting and Auditing</li>
<li>(17:49) - Finding and Partnering with Clients</li>
<li>(22:45) - Leveraging LinkedIn for Business Growth</li>
<li>(27:02) - Challenges in Consultancy</li>
<li>(30:29) - Balancing Work and Personal Life</li>
<li>(35:23) - Future of Consulting and Auditing</li>
<li>(40:27) - Advice for Aspiring Consultants</li>
<li>(42:54) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 20 May 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/bb02d9a0/f0b4ef3e.mp3" length="42519253" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2655</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic speaks with Bevan Lane, CEO of InfoSec Advisory Group. Bevan shares his journey from starting as an independent contractor to building a successful cybersecurity consultancy with offices in South Africa and London, and clients across five continents. Learn about his approach to scaling the business, including hiring passionate young talent, leveraging automation, and adapting to industry changes. Bevan also discusses the importance of balancing work and family life and provides valuable advice for aspiring consultants. Stay tuned for insights on the future of cybersecurity consulting and more.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertise to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Bevan Lane</li>
<li>(03:11) - Hiring and Training the Right People</li>
<li>(06:26) - Mentorship and Structured Training</li>
<li>(09:34) - Challenges of Retaining Talent</li>
<li>(10:55) - CEO's Role and Company Growth Strategy</li>
<li>(14:22) - Impact of AI on Consulting and Auditing</li>
<li>(17:49) - Finding and Partnering with Clients</li>
<li>(22:45) - Leveraging LinkedIn for Business Growth</li>
<li>(27:02) - Challenges in Consultancy</li>
<li>(30:29) - Balancing Work and Personal Life</li>
<li>(35:23) - Future of Consulting and Auditing</li>
<li>(40:27) - Advice for Aspiring Consultants</li>
<li>(42:54) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>cybersecurity, governance, consultants, CISOs, ISO 27001, NIS2, DORA</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/bb02d9a0/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/bb02d9a0/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/bb02d9a0/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/bb02d9a0/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/bb02d9a0/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/bb02d9a0/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Unlocking Business Value From NIS2: The Consultant’s Role | Interview with Philippe Cornette</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>Unlocking Business Value From NIS2: The Consultant’s Role | Interview with Philippe Cornette</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">29753a29-4a8d-4bbd-9327-6b81a31bec8b</guid>
      <link>https://podcast.advisera.com/episodes/unlocking-business-value-from-nis2-the-consultant-s-role-interview-with-philippe-cornette</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Philippe Cornette, an interim CISO and founding partner at DigiSôter consultancy, to discuss the challenges and opportunities in cybersecurity consulting. They delve into the importance of aligning cybersecurity projects with business value, the evolving nature of cybersecurity frameworks like NIS2, and the critical skills consultants need to succeed. Philippe shares his journey from working as an employee for over two decades to becoming a consultant and offers valuable insights into how consultants can make a significant impact in this ever-changing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Philippe Cornette</li>
<li>(03:33) - The Role of a Chief Troubleshoot Officer</li>
<li>(05:15) - Understanding NIS2 Directive</li>
<li>(09:35) - Aligning Business with Cybersecurity</li>
<li>(13:38) - The Importance of Business Risk Analysis</li>
<li>(15:44) - Challenges in IT and OT Convergence</li>
<li>(17:02) - Consultant's Role in Cybersecurity Projects</li>
<li>(26:41) - Expertise and Change Management in Cybersecurity</li>
<li>(29:22) - Navigating EU Regulations</li>
<li>(33:04) - Consulting Opportunities in Cybersecurity</li>
<li>(36:05) - The Future of Consulting with AI</li>
<li>(41:40) - CISO as a Service Explained</li>
<li>(47:35) - Competing in the Consulting Market</li>
<li>(56:23) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Philippe Cornette, an interim CISO and founding partner at DigiSôter consultancy, to discuss the challenges and opportunities in cybersecurity consulting. They delve into the importance of aligning cybersecurity projects with business value, the evolving nature of cybersecurity frameworks like NIS2, and the critical skills consultants need to succeed. Philippe shares his journey from working as an employee for over two decades to becoming a consultant and offers valuable insights into how consultants can make a significant impact in this ever-changing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Philippe Cornette</li>
<li>(03:33) - The Role of a Chief Troubleshoot Officer</li>
<li>(05:15) - Understanding NIS2 Directive</li>
<li>(09:35) - Aligning Business with Cybersecurity</li>
<li>(13:38) - The Importance of Business Risk Analysis</li>
<li>(15:44) - Challenges in IT and OT Convergence</li>
<li>(17:02) - Consultant's Role in Cybersecurity Projects</li>
<li>(26:41) - Expertise and Change Management in Cybersecurity</li>
<li>(29:22) - Navigating EU Regulations</li>
<li>(33:04) - Consulting Opportunities in Cybersecurity</li>
<li>(36:05) - The Future of Consulting with AI</li>
<li>(41:40) - CISO as a Service Explained</li>
<li>(47:35) - Competing in the Consulting Market</li>
<li>(56:23) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 06 May 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/1e785e34/4687d22d.mp3" length="55366292" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3458</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Philippe Cornette, an interim CISO and founding partner at DigiSôter consultancy, to discuss the challenges and opportunities in cybersecurity consulting. They delve into the importance of aligning cybersecurity projects with business value, the evolving nature of cybersecurity frameworks like NIS2, and the critical skills consultants need to succeed. Philippe shares his journey from working as an employee for over two decades to becoming a consultant and offers valuable insights into how consultants can make a significant impact in this ever-changing field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Philippe Cornette</li>
<li>(03:33) - The Role of a Chief Troubleshoot Officer</li>
<li>(05:15) - Understanding NIS2 Directive</li>
<li>(09:35) - Aligning Business with Cybersecurity</li>
<li>(13:38) - The Importance of Business Risk Analysis</li>
<li>(15:44) - Challenges in IT and OT Convergence</li>
<li>(17:02) - Consultant's Role in Cybersecurity Projects</li>
<li>(26:41) - Expertise and Change Management in Cybersecurity</li>
<li>(29:22) - Navigating EU Regulations</li>
<li>(33:04) - Consulting Opportunities in Cybersecurity</li>
<li>(36:05) - The Future of Consulting with AI</li>
<li>(41:40) - CISO as a Service Explained</li>
<li>(47:35) - Competing in the Consulting Market</li>
<li>(56:23) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>consultancy, cybersecurity, CISO, NIS2</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/1e785e34/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1e785e34/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1e785e34/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/1e785e34/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/1e785e34/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/1e785e34/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Understanding the EU Electronic Evidence Package | Interview with Cristos Velasco</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Understanding the EU Electronic Evidence Package | Interview with Cristos Velasco</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ac726a21-d358-4e46-a492-d80fc3dc13c2</guid>
      <link>https://podcast.advisera.com/episodes/understanding-the-eu-electronic-evidence-package-interview-with-cristos-velasco</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes Cristos Velasco, an independent consultant and associate professor specializing in cyber law, cybercrime, cybersecurity, and AI. They discuss the new EU electronic evidence package published in August 2023 and its enforcement in 2026, diving into the regulation, the directive, and its implications for law enforcement and service providers. Cristos shares his journey into consultancy, the significance of electronic evidence and digital forensics, and the challenges presented by rapidly changing technologies and legislation. They also explore the benefits for companies preparing for these new regulations and offer advice for aspiring consultants in the cybersecurity field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Cristos Velasco</li>
<li>(01:05) - Cristos Velasco's Career Journey</li>
<li>(03:10) - Understanding Electronic Evidence</li>
<li>(06:11) - Challenges in Preserving Blockchain Evidence</li>
<li>(09:01) - Upcoming EU Electronic Evidence Package</li>
<li>(11:55) - Preparing for the New EU Package</li>
<li>(18:48) - Digital Forensics vs. Electronic Evidence</li>
<li>(20:57) - Freezing Digital Evidence: Importance and Challenges</li>
<li>(22:35) - Legal Complexities in Data Retention and Preservation</li>
<li>(24:35) - Technical and Organizational Aspects of Evidence Preservation</li>
<li>(31:51) - Chain of Custody in Digital Evidence</li>
<li>(38:40) - Consulting and Training in Cybersecurity</li>
<li>(45:02) - Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes Cristos Velasco, an independent consultant and associate professor specializing in cyber law, cybercrime, cybersecurity, and AI. They discuss the new EU electronic evidence package published in August 2023 and its enforcement in 2026, diving into the regulation, the directive, and its implications for law enforcement and service providers. Cristos shares his journey into consultancy, the significance of electronic evidence and digital forensics, and the challenges presented by rapidly changing technologies and legislation. They also explore the benefits for companies preparing for these new regulations and offer advice for aspiring consultants in the cybersecurity field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Cristos Velasco</li>
<li>(01:05) - Cristos Velasco's Career Journey</li>
<li>(03:10) - Understanding Electronic Evidence</li>
<li>(06:11) - Challenges in Preserving Blockchain Evidence</li>
<li>(09:01) - Upcoming EU Electronic Evidence Package</li>
<li>(11:55) - Preparing for the New EU Package</li>
<li>(18:48) - Digital Forensics vs. Electronic Evidence</li>
<li>(20:57) - Freezing Digital Evidence: Importance and Challenges</li>
<li>(22:35) - Legal Complexities in Data Retention and Preservation</li>
<li>(24:35) - Technical and Organizational Aspects of Evidence Preservation</li>
<li>(31:51) - Chain of Custody in Digital Evidence</li>
<li>(38:40) - Consulting and Training in Cybersecurity</li>
<li>(45:02) - Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 22 Apr 2025 13:30:00 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/eb1d801b/ad53af27.mp3" length="44562040" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2783</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes Cristos Velasco, an independent consultant and associate professor specializing in cyber law, cybercrime, cybersecurity, and AI. They discuss the new EU electronic evidence package published in August 2023 and its enforcement in 2026, diving into the regulation, the directive, and its implications for law enforcement and service providers. Cristos shares his journey into consultancy, the significance of electronic evidence and digital forensics, and the challenges presented by rapidly changing technologies and legislation. They also explore the benefits for companies preparing for these new regulations and offer advice for aspiring consultants in the cybersecurity field.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Cristos Velasco</li>
<li>(01:05) - Cristos Velasco's Career Journey</li>
<li>(03:10) - Understanding Electronic Evidence</li>
<li>(06:11) - Challenges in Preserving Blockchain Evidence</li>
<li>(09:01) - Upcoming EU Electronic Evidence Package</li>
<li>(11:55) - Preparing for the New EU Package</li>
<li>(18:48) - Digital Forensics vs. Electronic Evidence</li>
<li>(20:57) - Freezing Digital Evidence: Importance and Challenges</li>
<li>(22:35) - Legal Complexities in Data Retention and Preservation</li>
<li>(24:35) - Technical and Organizational Aspects of Evidence Preservation</li>
<li>(31:51) - Chain of Custody in Digital Evidence</li>
<li>(38:40) - Consulting and Training in Cybersecurity</li>
<li>(45:02) - Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>consultancy, electronic evidence, cybersecurity, euregulations</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/eb1d801b/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/eb1d801b/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/eb1d801b/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/eb1d801b/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/eb1d801b/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/eb1d801b/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Leveraging Online Courses for Consulting Success | Interview with Richea Perry</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Leveraging Online Courses for Consulting Success | Interview with Richea Perry</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4891d7a6-8629-4a2b-842b-05331328695e</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-richea-perry-leveraging-online-courses-for-consulting-success</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes independent cybersecurity consultant and Cyber JA podcast host, Richea Perry. Richea shares his journey from facing job loss during COVID-19 to becoming a successful consultant by leveraging online courses on platforms like Udemy. He discusses the importance of building a personal brand, creating valuable content, and how networking on LinkedIn and other platforms can lead to consulting opportunities. Richea also provides insights into the use of AI in course creation, effective communication skills, and the future of online education in cybersecurity. Tune in to learn best practices for building a portfolio of online courses and using them to support your consulting practice.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>   </p>
<ul><li>(00:00) - Interview with Richea Perry</li>
<li>(01:10) - Journey to Becoming a Consultant</li>
<li>(04:15) - Transition from Technical to Consulting</li>
<li>(06:25) - Starting with Udemy Courses</li>
<li>(10:43) - Developing Course Content</li>
<li>(20:18) - Using AI in Course Creation</li>
<li>(23:24) - Recording Courses Efficiently</li>
<li>(26:25) - Editing Tools</li>
<li>(28:13) - Promoting Your Courses</li>
<li>(31:50) - Monetizing and Business Model</li>
<li>(34:40) - Choosing the Right Platform</li>
<li>(36:35) - Future of Online Training and AI</li>
<li>(41:04) - Essential Skills for Consultants</li>
<li>(45:22) - Final Recommendations </li>
<li>(48:28) - Additional Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes independent cybersecurity consultant and Cyber JA podcast host, Richea Perry. Richea shares his journey from facing job loss during COVID-19 to becoming a successful consultant by leveraging online courses on platforms like Udemy. He discusses the importance of building a personal brand, creating valuable content, and how networking on LinkedIn and other platforms can lead to consulting opportunities. Richea also provides insights into the use of AI in course creation, effective communication skills, and the future of online education in cybersecurity. Tune in to learn best practices for building a portfolio of online courses and using them to support your consulting practice.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>   </p>
<ul><li>(00:00) - Interview with Richea Perry</li>
<li>(01:10) - Journey to Becoming a Consultant</li>
<li>(04:15) - Transition from Technical to Consulting</li>
<li>(06:25) - Starting with Udemy Courses</li>
<li>(10:43) - Developing Course Content</li>
<li>(20:18) - Using AI in Course Creation</li>
<li>(23:24) - Recording Courses Efficiently</li>
<li>(26:25) - Editing Tools</li>
<li>(28:13) - Promoting Your Courses</li>
<li>(31:50) - Monetizing and Business Model</li>
<li>(34:40) - Choosing the Right Platform</li>
<li>(36:35) - Future of Online Training and AI</li>
<li>(41:04) - Essential Skills for Consultants</li>
<li>(45:22) - Final Recommendations </li>
<li>(48:28) - Additional Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 22:23:33 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/93767ce1/24b7c466.mp3" length="47853781" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2989</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic welcomes independent cybersecurity consultant and Cyber JA podcast host, Richea Perry. Richea shares his journey from facing job loss during COVID-19 to becoming a successful consultant by leveraging online courses on platforms like Udemy. He discusses the importance of building a personal brand, creating valuable content, and how networking on LinkedIn and other platforms can lead to consulting opportunities. Richea also provides insights into the use of AI in course creation, effective communication skills, and the future of online education in cybersecurity. Tune in to learn best practices for building a portfolio of online courses and using them to support your consulting practice.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>   </p>
<ul><li>(00:00) - Interview with Richea Perry</li>
<li>(01:10) - Journey to Becoming a Consultant</li>
<li>(04:15) - Transition from Technical to Consulting</li>
<li>(06:25) - Starting with Udemy Courses</li>
<li>(10:43) - Developing Course Content</li>
<li>(20:18) - Using AI in Course Creation</li>
<li>(23:24) - Recording Courses Efficiently</li>
<li>(26:25) - Editing Tools</li>
<li>(28:13) - Promoting Your Courses</li>
<li>(31:50) - Monetizing and Business Model</li>
<li>(34:40) - Choosing the Right Platform</li>
<li>(36:35) - Future of Online Training and AI</li>
<li>(41:04) - Essential Skills for Consultants</li>
<li>(45:22) - Final Recommendations </li>
<li>(48:28) - Additional Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>consultancy, onlinecourses, Udemy, promotion, contentmarketing, ai</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/93767ce1/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/93767ce1/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/93767ce1/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/93767ce1/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/93767ce1/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/93767ce1/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Promoting Consulting Business Through Content Marketing | Interview with Punit Bhatia</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Promoting Consulting Business Through Content Marketing | Interview with Punit Bhatia</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">750a3c0a-f617-43a3-a2d5-45259d9db229</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-punit-bhatia-promoting-consulting-business-through-content-marketing</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Punit Bhatia, founder of FIT4Privacy Consulting Company, author of 4 books on GDPR, and host of the FIT4Privacy podcast. Punit shares his journey from working at a bank to becoming a leading consultant in privacy and AI governance. He discusses the importance of content marketing, personal branding, and consistency in building a consultancy business. Punit also provides insights into how creating expert materials, publishing books, speaking at events, and maintaining a presence on platforms like YouTube and LinkedIn have contributed to his success. Tune in to learn best practices for promoting your consultancy and establishing a strong professional network.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Punit Bhatia</li>
<li>(01:02) - Starting a Consulting Career: Punit's Journey</li>
<li>(03:47) - The Freedom of Being an Independent Consultant</li>
<li>(04:36) - Building an International Clientele</li>
<li>(07:33) - Visibility and Content Marketing Strategies</li>
<li>(13:02) - Effective Use of Social Media Channels</li>
<li>(18:14) - The Podcast Journey</li>
<li>(23:21) - Leveraging Content for Business</li>
<li>(25:49) - The Role of Books in Brand Building</li>
<li>(27:39) - The Importance of Consistency</li>
<li>(34:53) - Expanding Expertise to AI</li>
<li>(36:45) - Future of AI and Privacy Standards</li>
<li>(39:56) - Final Thoughts and Recommendations</li>
<li>(41:13) - Useful Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Punit Bhatia, founder of FIT4Privacy Consulting Company, author of 4 books on GDPR, and host of the FIT4Privacy podcast. Punit shares his journey from working at a bank to becoming a leading consultant in privacy and AI governance. He discusses the importance of content marketing, personal branding, and consistency in building a consultancy business. Punit also provides insights into how creating expert materials, publishing books, speaking at events, and maintaining a presence on platforms like YouTube and LinkedIn have contributed to his success. Tune in to learn best practices for promoting your consultancy and establishing a strong professional network.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Punit Bhatia</li>
<li>(01:02) - Starting a Consulting Career: Punit's Journey</li>
<li>(03:47) - The Freedom of Being an Independent Consultant</li>
<li>(04:36) - Building an International Clientele</li>
<li>(07:33) - Visibility and Content Marketing Strategies</li>
<li>(13:02) - Effective Use of Social Media Channels</li>
<li>(18:14) - The Podcast Journey</li>
<li>(23:21) - Leveraging Content for Business</li>
<li>(25:49) - The Role of Books in Brand Building</li>
<li>(27:39) - The Importance of Consistency</li>
<li>(34:53) - Expanding Expertise to AI</li>
<li>(36:45) - Future of AI and Privacy Standards</li>
<li>(39:56) - Final Thoughts and Recommendations</li>
<li>(41:13) - Useful Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 22:05:31 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/8804d1dc/41663bee.mp3" length="40892743" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2554</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic interviews Punit Bhatia, founder of FIT4Privacy Consulting Company, author of 4 books on GDPR, and host of the FIT4Privacy podcast. Punit shares his journey from working at a bank to becoming a leading consultant in privacy and AI governance. He discusses the importance of content marketing, personal branding, and consistency in building a consultancy business. Punit also provides insights into how creating expert materials, publishing books, speaking at events, and maintaining a presence on platforms like YouTube and LinkedIn have contributed to his success. Tune in to learn best practices for promoting your consultancy and establishing a strong professional network.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Punit Bhatia</li>
<li>(01:02) - Starting a Consulting Career: Punit's Journey</li>
<li>(03:47) - The Freedom of Being an Independent Consultant</li>
<li>(04:36) - Building an International Clientele</li>
<li>(07:33) - Visibility and Content Marketing Strategies</li>
<li>(13:02) - Effective Use of Social Media Channels</li>
<li>(18:14) - The Podcast Journey</li>
<li>(23:21) - Leveraging Content for Business</li>
<li>(25:49) - The Role of Books in Brand Building</li>
<li>(27:39) - The Importance of Consistency</li>
<li>(34:53) - Expanding Expertise to AI</li>
<li>(36:45) - Future of AI and Privacy Standards</li>
<li>(39:56) - Final Thoughts and Recommendations</li>
<li>(41:13) - Useful Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>podcast, consultancy, promotion, contentmarketing, privacy, ai</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/8804d1dc/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/8804d1dc/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/8804d1dc/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/8804d1dc/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/8804d1dc/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/8804d1dc/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Trends in ISO Standards: Certification Body Perspective | Interview with Tom Wheat</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Trends in ISO Standards: Certification Body Perspective | Interview with Tom Wheat</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2a19328c-33ba-4fdb-8616-c03893412d24</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-tom-wheat-trends-in-iso-standards-certification-body-perspective</link>
      <description>
        <![CDATA[<p>In this insightful episode of the Secure and Simple Podcast, host Dejan Kosutic discusses the evolving landscape of standards with Tom Wheat, UK Country Manager at PJR. They delve into the importance of ISO 27001 as the benchmark for global information security, the internal processes within certification bodies, and the value certification bodies can add beyond just issuing certificates. The discussion also covers the role of consultants, the competitive certification market, the impacts of AI, and key recommendations for consultants preparing clients for certification. Tune in for valuable insights on ensuring continuous improvement, compliance, and the future of cybersecurity certification.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Tom Wheat</li>
<li>(02:10) - Tom's Journey: From Consultant to Certification Manager</li>
<li>(05:36) - The Importance of ISO 27001</li>
<li>(07:51) - Trends in Certification and Compliance</li>
<li>(13:52) - Behind the Scenes of Certification Bodies</li>
<li>(22:18) - The Value of Certification Bodies</li>
<li>(24:55) - Auditors and Best Practices</li>
<li>(28:07) - Consultants in the Certification Process</li>
<li>(30:14) - Handling Non-Conformities and Appeals</li>
<li>(32:41) - Competing in the Certification Market</li>
<li>(36:42) - The Future of Certification Bodies</li>
<li>(39:13) - AI and the Future of Compliance</li>
<li>(43:13) - Top Recommendations for Consultants</li>
<li>(45:22) - Conclusion and Resources</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this insightful episode of the Secure and Simple Podcast, host Dejan Kosutic discusses the evolving landscape of standards with Tom Wheat, UK Country Manager at PJR. They delve into the importance of ISO 27001 as the benchmark for global information security, the internal processes within certification bodies, and the value certification bodies can add beyond just issuing certificates. The discussion also covers the role of consultants, the competitive certification market, the impacts of AI, and key recommendations for consultants preparing clients for certification. Tune in for valuable insights on ensuring continuous improvement, compliance, and the future of cybersecurity certification.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Tom Wheat</li>
<li>(02:10) - Tom's Journey: From Consultant to Certification Manager</li>
<li>(05:36) - The Importance of ISO 27001</li>
<li>(07:51) - Trends in Certification and Compliance</li>
<li>(13:52) - Behind the Scenes of Certification Bodies</li>
<li>(22:18) - The Value of Certification Bodies</li>
<li>(24:55) - Auditors and Best Practices</li>
<li>(28:07) - Consultants in the Certification Process</li>
<li>(30:14) - Handling Non-Conformities and Appeals</li>
<li>(32:41) - Competing in the Certification Market</li>
<li>(36:42) - The Future of Certification Bodies</li>
<li>(39:13) - AI and the Future of Compliance</li>
<li>(43:13) - Top Recommendations for Consultants</li>
<li>(45:22) - Conclusion and Resources</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 17:38:26 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/25bb90ef/1d6531ca.mp3" length="44884686" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2803</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this insightful episode of the Secure and Simple Podcast, host Dejan Kosutic discusses the evolving landscape of standards with Tom Wheat, UK Country Manager at PJR. They delve into the importance of ISO 27001 as the benchmark for global information security, the internal processes within certification bodies, and the value certification bodies can add beyond just issuing certificates. The discussion also covers the role of consultants, the competitive certification market, the impacts of AI, and key recommendations for consultants preparing clients for certification. Tune in for valuable insights on ensuring continuous improvement, compliance, and the future of cybersecurity certification.</p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a><br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a>  </p>
<ul><li>(00:00) - Interview with Tom Wheat</li>
<li>(02:10) - Tom's Journey: From Consultant to Certification Manager</li>
<li>(05:36) - The Importance of ISO 27001</li>
<li>(07:51) - Trends in Certification and Compliance</li>
<li>(13:52) - Behind the Scenes of Certification Bodies</li>
<li>(22:18) - The Value of Certification Bodies</li>
<li>(24:55) - Auditors and Best Practices</li>
<li>(28:07) - Consultants in the Certification Process</li>
<li>(30:14) - Handling Non-Conformities and Appeals</li>
<li>(32:41) - Competing in the Certification Market</li>
<li>(36:42) - The Future of Certification Bodies</li>
<li>(39:13) - AI and the Future of Compliance</li>
<li>(43:13) - Top Recommendations for Consultants</li>
<li>(45:22) - Conclusion and Resources</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>podcast, certification, trends, iso27001, cybersecurity, isostandards</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/25bb90ef/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/25bb90ef/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/25bb90ef/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/25bb90ef/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/25bb90ef/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/25bb90ef/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>How to Combine ISO 27001 and GDPR | Interview with Luigi Viscione</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>How to Combine ISO 27001 and GDPR | Interview with Luigi Viscione</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ce7fa416-cae6-4f70-996d-27d1d3de4751</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-luigi-viscione-how-to-combine-iso-27001-and-gdpr</link>
      <description>
        <![CDATA[<p>This episode features Luigi Viscione, CEO and Founder of Micsar, a seasoned consultant with a decade of experience in IT security and data protection. Luigi discusses the intersection of privacy and cybersecurity, the challenges and benefits of being a consultant, as well as the importance of integrating multiple security frameworks like GDPR and ISO 27001. Gain insights on how to streamline processes, secure client buy-in, and manage large-scale implementations effectively. Don't miss Luigi's experiences on the future of AI in consultancy and how it can influence the cybersecurity landscape.</p><p>Links from the episode:<br>- Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software<br>- White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits<br>- Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertize to potential clients: https://advisera.co/Consultant-Courses<br>- Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account </p><p></p><ul><li>(00:00) - Interview with Luigi Viscione</li>
<li>(01:27) - Starting a Consulting Business</li>
<li>(03:10) - Combining Cybersecurity and Privacy</li>
<li>(05:16) - Implementing ISO 27001 and GDPR</li>
<li>(07:07) - Integrated Risk Management</li>
<li>(10:47) - Handling Security Incidents</li>
<li>(12:27) - Client Reactions to Integrated Approaches</li>
<li>(16:23) - Gaining Senior Management Support</li>
<li>(28:41) - Balancing Implementation and Maintenance</li>
<li>(33:31) - Managing Multiple Frameworks</li>
<li>(40:28) - Future of AI in Consulting</li>
<li>(47:14) - Consultancy Evolution and Key Takeaways</li>
<li>(50:24) - Conclusion and Resources</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode features Luigi Viscione, CEO and Founder of Micsar, a seasoned consultant with a decade of experience in IT security and data protection. Luigi discusses the intersection of privacy and cybersecurity, the challenges and benefits of being a consultant, as well as the importance of integrating multiple security frameworks like GDPR and ISO 27001. Gain insights on how to streamline processes, secure client buy-in, and manage large-scale implementations effectively. Don't miss Luigi's experiences on the future of AI in consultancy and how it can influence the cybersecurity landscape.</p><p>Links from the episode:<br>- Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software<br>- White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits<br>- Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertize to potential clients: https://advisera.co/Consultant-Courses<br>- Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account </p><p></p><ul><li>(00:00) - Interview with Luigi Viscione</li>
<li>(01:27) - Starting a Consulting Business</li>
<li>(03:10) - Combining Cybersecurity and Privacy</li>
<li>(05:16) - Implementing ISO 27001 and GDPR</li>
<li>(07:07) - Integrated Risk Management</li>
<li>(10:47) - Handling Security Incidents</li>
<li>(12:27) - Client Reactions to Integrated Approaches</li>
<li>(16:23) - Gaining Senior Management Support</li>
<li>(28:41) - Balancing Implementation and Maintenance</li>
<li>(33:31) - Managing Multiple Frameworks</li>
<li>(40:28) - Future of AI in Consulting</li>
<li>(47:14) - Consultancy Evolution and Key Takeaways</li>
<li>(50:24) - Conclusion and Resources</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 17:22:14 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/31745848/3dfe1726.mp3" length="49710629" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3105</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode features Luigi Viscione, CEO and Founder of Micsar, a seasoned consultant with a decade of experience in IT security and data protection. Luigi discusses the intersection of privacy and cybersecurity, the challenges and benefits of being a consultant, as well as the importance of integrating multiple security frameworks like GDPR and ISO 27001. Gain insights on how to streamline processes, secure client buy-in, and manage large-scale implementations effectively. Don't miss Luigi's experiences on the future of AI in consultancy and how it can influence the cybersecurity landscape.</p><p>Links from the episode:<br>- Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software<br>- White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits<br>- Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertize to potential clients: https://advisera.co/Consultant-Courses<br>- Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account </p><p></p><ul><li>(00:00) - Interview with Luigi Viscione</li>
<li>(01:27) - Starting a Consulting Business</li>
<li>(03:10) - Combining Cybersecurity and Privacy</li>
<li>(05:16) - Implementing ISO 27001 and GDPR</li>
<li>(07:07) - Integrated Risk Management</li>
<li>(10:47) - Handling Security Incidents</li>
<li>(12:27) - Client Reactions to Integrated Approaches</li>
<li>(16:23) - Gaining Senior Management Support</li>
<li>(28:41) - Balancing Implementation and Maintenance</li>
<li>(33:31) - Managing Multiple Frameworks</li>
<li>(40:28) - Future of AI in Consulting</li>
<li>(47:14) - Consultancy Evolution and Key Takeaways</li>
<li>(50:24) - Conclusion and Resources</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>podcast, consultancy, iso27001, gdpr, cybersecurity, privacy, integration</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/31745848/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/31745848/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/31745848/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/31745848/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/31745848/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/31745848/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>Trends with ISO 27001, NIS2, and Supplier Security | Interview with René Matthiassen</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Trends with ISO 27001, NIS2, and Supplier Security | Interview with René Matthiassen</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1634fe53-4aa4-42cd-a8fe-3d0243c067c0</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-rene-matthiassen-trends-with-iso-27001-nis2-and-supplier-security</link>
      <description>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic is joined by Rene Matthiassen, a senior security consultant and partner at Front Door Security. With 30 years of experience in cybersecurity frameworks, Rene discusses the importance of tailored security frameworks, particularly ISO 27001, and how they benefit companies and suppliers under NIS2 scope. They delve into Rene’s journey from network engineering to consulting, the process behind developing security standards, and practical steps for managing cybersecurity among suppliers. The conversation also touches on the increasing importance of operational technology security frameworks like IEC 62443 and provides a forecast for the evolution of cybersecurity compliance in the digital decade. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Interview with René Matthiassen</li>
<li>(00:19) - Meet Our Guest: Rene Matthiassen</li>
<li>(02:35) - Transitioning from Technical to Governance</li>
<li>(04:38) - Developing ISO 27001 Standards</li>
<li>(06:15) - The Democratic Process of Standardization</li>
<li>(07:53) - Transposing NIS2 in Denmark</li>
<li>(11:10) - ISO 27001 and NIS2: A Symbiotic Relationship</li>
<li>(18:07) - Supply Chain Security and Compliance</li>
<li>(24:25) - Handling Supplier Disruptions</li>
<li>(26:56) - Creating Effective Security Contracts</li>
<li>(30:10) - Supplier's Perspective on Compliance</li>
<li>(36:40) - Navigating the Competitive Consulting Market</li>
<li>(39:39) - Operational Technology Security Standards</li>
<li>(42:26) - Future of Cybersecurity Compliance</li>
<li>(46:34) - Conclusion and Resources for Consultants</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic is joined by Rene Matthiassen, a senior security consultant and partner at Front Door Security. With 30 years of experience in cybersecurity frameworks, Rene discusses the importance of tailored security frameworks, particularly ISO 27001, and how they benefit companies and suppliers under NIS2 scope. They delve into Rene’s journey from network engineering to consulting, the process behind developing security standards, and practical steps for managing cybersecurity among suppliers. The conversation also touches on the increasing importance of operational technology security frameworks like IEC 62443 and provides a forecast for the evolution of cybersecurity compliance in the digital decade. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Interview with René Matthiassen</li>
<li>(00:19) - Meet Our Guest: Rene Matthiassen</li>
<li>(02:35) - Transitioning from Technical to Governance</li>
<li>(04:38) - Developing ISO 27001 Standards</li>
<li>(06:15) - The Democratic Process of Standardization</li>
<li>(07:53) - Transposing NIS2 in Denmark</li>
<li>(11:10) - ISO 27001 and NIS2: A Symbiotic Relationship</li>
<li>(18:07) - Supply Chain Security and Compliance</li>
<li>(24:25) - Handling Supplier Disruptions</li>
<li>(26:56) - Creating Effective Security Contracts</li>
<li>(30:10) - Supplier's Perspective on Compliance</li>
<li>(36:40) - Navigating the Competitive Consulting Market</li>
<li>(39:39) - Operational Technology Security Standards</li>
<li>(42:26) - Future of Cybersecurity Compliance</li>
<li>(46:34) - Conclusion and Resources for Consultants</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 16:54:51 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/38aeffac/0cc87a2f.mp3" length="46032994" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>2875</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Secure and Simple Podcast, host Dejan Kosutic is joined by Rene Matthiassen, a senior security consultant and partner at Front Door Security. With 30 years of experience in cybersecurity frameworks, Rene discusses the importance of tailored security frameworks, particularly ISO 27001, and how they benefit companies and suppliers under NIS2 scope. They delve into Rene’s journey from network engineering to consulting, the process behind developing security standards, and practical steps for managing cybersecurity among suppliers. The conversation also touches on the increasing importance of operational technology security frameworks like IEC 62443 and provides a forecast for the evolution of cybersecurity compliance in the digital decade. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Interview with René Matthiassen</li>
<li>(00:19) - Meet Our Guest: Rene Matthiassen</li>
<li>(02:35) - Transitioning from Technical to Governance</li>
<li>(04:38) - Developing ISO 27001 Standards</li>
<li>(06:15) - The Democratic Process of Standardization</li>
<li>(07:53) - Transposing NIS2 in Denmark</li>
<li>(11:10) - ISO 27001 and NIS2: A Symbiotic Relationship</li>
<li>(18:07) - Supply Chain Security and Compliance</li>
<li>(24:25) - Handling Supplier Disruptions</li>
<li>(26:56) - Creating Effective Security Contracts</li>
<li>(30:10) - Supplier's Perspective on Compliance</li>
<li>(36:40) - Navigating the Competitive Consulting Market</li>
<li>(39:39) - Operational Technology Security Standards</li>
<li>(42:26) - Future of Cybersecurity Compliance</li>
<li>(46:34) - Conclusion and Resources for Consultants</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>podcast, consultancy, cybersecurity, iso27001, nis2</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/38aeffac/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/38aeffac/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/38aeffac/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/38aeffac/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/38aeffac/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/38aeffac/chapters.json" type="application/json+chapters"/>
    </item>
    <item>
      <title>How to Become a Successful Consultant | Interview with Carlos Cruz</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>How to Become a Successful Consultant | Interview with Carlos Cruz</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a4466ec3-bf69-4a8f-902d-00ce4c24e028</guid>
      <link>https://podcast.advisera.com/episodes/interview-with-carlos-cruz-how-to-become-a-successful-consultant</link>
      <description>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia and ISO 9001 &amp; ISO 14001 expert at Advisera. Carlos shares his journey in the consulting business, starting from the 1990s, and provides valuable insights on the do's and don'ts of building a successful consulting career. Learn how Carlos used writing, training, and strategic connections to grow his business, and how the consulting landscape has changed over the decades. The discussion also touches on the role of AI in consulting and offers practical advice for new consultants. Don't miss this opportunity to learn from Carlos's extensive experience in the consulting field. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Audio 1001 Interview Carlos Cruz</li>
<li>(00:19) - Meet Carlos Cruz: A Veteran Consultant</li>
<li>(01:42) - Starting a Consulting Business in the 1990s</li>
<li>(03:20) - The Importance of Writing and Blogging</li>
<li>(06:07) - Connecting Quality Management with Strategy</li>
<li>(12:01) - Differentiation and Client Satisfaction</li>
<li>(28:12) - Promoting Imperfect Competition</li>
<li>(29:59) - Understanding Customer Perception</li>
<li>(31:41) - Finding Your Niche as a Consultant</li>
<li>(33:43) - Working with Japanese Companies</li>
<li>(37:44) - Lessons from Bad Consultants</li>
<li>(44:23) - The Role of Training and Auditing</li>
<li>(48:25) - The Evolution of Consulting</li>
<li>(51:15) - Future of Consulting with AI</li>
<li>(54:34) - Top Tips for Consultants</li>
<li>(58:34) - Conclusion and Resources</li>
</ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia and ISO 9001 &amp; ISO 14001 expert at Advisera. Carlos shares his journey in the consulting business, starting from the 1990s, and provides valuable insights on the do's and don'ts of building a successful consulting career. Learn how Carlos used writing, training, and strategic connections to grow his business, and how the consulting landscape has changed over the decades. The discussion also touches on the role of AI in consulting and offers practical advice for new consultants. Don't miss this opportunity to learn from Carlos's extensive experience in the consulting field. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Audio 1001 Interview Carlos Cruz</li>
<li>(00:19) - Meet Carlos Cruz: A Veteran Consultant</li>
<li>(01:42) - Starting a Consulting Business in the 1990s</li>
<li>(03:20) - The Importance of Writing and Blogging</li>
<li>(06:07) - Connecting Quality Management with Strategy</li>
<li>(12:01) - Differentiation and Client Satisfaction</li>
<li>(28:12) - Promoting Imperfect Competition</li>
<li>(29:59) - Understanding Customer Perception</li>
<li>(31:41) - Finding Your Niche as a Consultant</li>
<li>(33:43) - Working with Japanese Companies</li>
<li>(37:44) - Lessons from Bad Consultants</li>
<li>(44:23) - The Role of Training and Auditing</li>
<li>(48:25) - The Evolution of Consulting</li>
<li>(51:15) - Future of Consulting with AI</li>
<li>(54:34) - Top Tips for Consultants</li>
<li>(58:34) - Conclusion and Resources</li>
</ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Apr 2025 16:10:41 +0200</pubDate>
      <author>Dejan Kosutic</author>
      <enclosure url="https://media.transistor.fm/50432054/d18c9f08.mp3" length="57559058" type="audio/mpeg"/>
      <itunes:author>Dejan Kosutic</itunes:author>
      <itunes:duration>3595</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of Secure and Simple Podcast, host Dejan Kosutic interviews Carlos Cruz, founder of Metanoia and ISO 9001 &amp; ISO 14001 expert at Advisera. Carlos shares his journey in the consulting business, starting from the 1990s, and provides valuable insights on the do's and don'ts of building a successful consulting career. Learn how Carlos used writing, training, and strategic connections to grow his business, and how the consulting landscape has changed over the decades. The discussion also touches on the role of AI in consulting and offers practical advice for new consultants. Don't miss this opportunity to learn from Carlos's extensive experience in the consulting field. </p><p>Links from the episode: <br>- <strong>Conformio software</strong> to streamline and scale ISO 27001 implementation and maintenance for your clients: <a href="https://advisera.co/Conformio-software">https://advisera.co/Conformio-software</a><br>- <strong>White label documentation toolkits</strong> for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: <a href="https://advisera.co/page-all-toolkits">https://advisera.co/page-all-toolkits </a><br>- <strong>Accredited Lead Auditor and Lead Implementer courses</strong> for various standards and frameworks to show your expertize to potential clients: <a href="https://advisera.co/Consultant-Courses">https://advisera.co/Consultant-Courses</a> <br>- <strong>Company Training Academy</strong> with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: <a href="https://advisera.co/page-Company-Training-Account">https://advisera.co/page-Company-Training-Account</a> </p><p></p><ul><li>(00:00) - Audio 1001 Interview Carlos Cruz</li>
<li>(00:19) - Meet Carlos Cruz: A Veteran Consultant</li>
<li>(01:42) - Starting a Consulting Business in the 1990s</li>
<li>(03:20) - The Importance of Writing and Blogging</li>
<li>(06:07) - Connecting Quality Management with Strategy</li>
<li>(12:01) - Differentiation and Client Satisfaction</li>
<li>(28:12) - Promoting Imperfect Competition</li>
<li>(29:59) - Understanding Customer Perception</li>
<li>(31:41) - Finding Your Niche as a Consultant</li>
<li>(33:43) - Working with Japanese Companies</li>
<li>(37:44) - Lessons from Bad Consultants</li>
<li>(44:23) - The Role of Training and Auditing</li>
<li>(48:25) - The Evolution of Consulting</li>
<li>(51:15) - Future of Consulting with AI</li>
<li>(54:34) - Top Tips for Consultants</li>
<li>(58:34) - Conclusion and Resources</li>
</ul>]]>
      </itunes:summary>
      <itunes:keywords>podcast, consultancy, cybersecurity, success</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:person role="Host" href="https://podcast.advisera.com/people/dejan-kosutic">Dejan Kosutic</podcast:person>
      <podcast:transcript url="https://share.transistor.fm/s/50432054/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/50432054/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/50432054/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/50432054/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/50432054/transcription" type="text/html"/>
      <podcast:chapters url="https://share.transistor.fm/s/50432054/chapters.json" type="application/json+chapters"/>
    </item>
  </channel>
</rss>
