Category: Cybersecurity

How CMMC Drives Long-Term Security Maturity, Not One-Time Compliance ft. Rick Olivier (Ep. 13)

How CMMC Drives Long-Term Security Maturity, Not One-Time Compliance ft. Rick Olivier (Ep. 13)

How should defense contractors respond to the CMMC pause? Questions about assessment timing, preparation costs, and CMMC requirements are leaving many organizations unsure whether to continue.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, speak with Rick Olivier, Director of Cybersecurity Advisory at Eide Bailly, about how contractors can prepare without overhauling their entire technology environment. Rick explains how controlled unclassified information determines CMMC scope, when a focused enclave may reduce cost and disruption, and how MSP access can expand the assessment scope. They also cover C3PAO assessments, continuous monitoring, and readiness gaps that can waste time and money.

Key takeaways:

  • How the CMMC pause is affecting assessment timelines and contractor preparation
  • Why locating controlled unclassified information is the first step in defining CMMC scope
  • When a focused CMMC enclave may reduce licensing costs and operational disruption
  • How MSPs, MSSPs, and other third parties can expand the scope of a CMMC assessment
  • Why continuous logging, monitoring, documentation, and response support ongoing readiness
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Rick Olivier:

Cybersecurity Spending: How Saving Today Can Cost You Tomorrow ft. James Ganther (Ep. 12)

Cybersecurity Spending: How Saving Today Can Cost You Tomorrow ft. James Ganther (Ep. 12)

If the FTC reviewed your car dealership today, could you prove that your cybersecurity practices match your written policies and protect customer data?

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, speak with James S. Ganther, Owner and CEO of Mosaic Compliance Services, about FTC Safeguards Rule compliance for car dealerships. They explain why written policies and purchased technology aren’t enough without testing and verification. The conversation covers phishing, employee training, risk assessments, qualified individuals, and network vulnerability assessments. James also explains how dealerships can document that their cybersecurity controls work as intended.

Key takeaways:

  • What the FTC Safeguards Rule requires car dealerships to document, monitor, test, and verify in practice
  • Why a written information security program must reflect the dealership’s real cybersecurity controls and risks
  • How phishing and stolen credentials can expose customer records, dealership systems, and daily operations
  • What network vulnerability assessments can uncover about missing controls and customer data exposure
  • How qualified individuals, employee training, technology partners, and regular audits support compliance
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with James S. Ganther:

From Research to Reality: How Universities Are Driving Cybersecurity Forward (Ep. 11)

From Research to Reality: How Universities Are Driving Cybersecurity Forward (Ep. 11)

As organizations face growing cybersecurity hiring challenges, cybersecurity staffing shortages, and uncertainty around how AI will impact cybersecurity careers, security leaders are being forced to rethink how they recruit, develop, and retain talent.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, sit down with Julia Armstrong, Executive Director of the Institute for Cybersecurity and Digital Trust at The Ohio State University, to discuss the cybersecurity talent shortage, skills-based hiring, workforce development, and the future of cybersecurity careers. Their conversation explores how universities, industry, and government can work together to prepare the next generation of cyber professionals and build stronger, more resilient security teams.

Key takeaways:

  • Why the cybersecurity talent shortage continues to impact organizations.
  • How skills-based hiring is changing cybersecurity recruitment.
  • What role AI may play in future cybersecurity careers.
  • Why workforce development is critical to cyber resilience.
  • How collaboration between academia, industry, and government can help close the cybersecurity skills gap.
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Julia Armstrong:

What Cyber Psychology Teaches Us About Smarter Decision-Making ft. Rick Mishka (Ep. 10)

What Cyber Psychology Teaches Us About Smarter Decision-Making ft. Rick Mishka (Ep. 10)

Security incidents don’t usually start because someone is careless. They often start because someone is human, busy, tired, rushed, and trying to do the right thing.

In this conversation, Tony Pietrocola and Joe Marquette sit down with Rick Mischka, Head of Resilience and Senior Director of Education Enablement at AVANT Communications, to break down the psychology behind cybersecurity. They explore why people shouldn’t be dismissed as the “weakest link,” how attackers target attention and trust, and what leaders need to understand about building security programs around real human behavior.

Key takeaways:

  • How AI is accelerating cyber threats and security capabilities
  • Why the human element remains critical in cybersecurity
  • The role Zero Trust plays in reducing organizational risk
  • What business leaders should focus on as AI adoption grows
  • Practical ways to strengthen cyber resilience
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Rick Mischka:

Mythos: The Emerging Threat Security Teams Can’t Ignore (Ep. 9)

Mythos: The Emerging Threat Security Teams Can’t Ignore (Ep. 9)

What happens when AI starts finding vulnerabilities faster than security teams can respond? As AI becomes a force multiplier for both defenders and attackers, organizations face a new reality where speed, scale, and decision-making matter more than ever.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, are joined by Andrew Desender, Senior Security Consultant at AgileBlue, and Dylan Marcoux, Founder and Principal Consultant at Aurora Cybersecurity. 

Together, they explore how emerging AI models are accelerating vulnerability discovery, changing how threat actors operate, and creating new leadership challenges for organizations trying to balance security, resilience, and operational continuity.

Key Takeaways:

  • AI is dramatically accelerating the discovery and exploitation of vulnerabilities, including weaknesses hidden in long-standing systems.
  • Threat actors are increasingly using AI for reconnaissance, social engineering, and exploit development, even when AI is not the primary attack driver.
  • Operational Technology (OT) environments face unique challenges because availability and safety often limit traditional patching approaches.
  • Organizations should focus on protecting their digital crown jewels through threat modeling and risk-based prioritization.
  • Security leaders must look beyond patching and build layered defenses through hardening, segmentation, governance, and human expertise.
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Andrew Desender:

Connect with Dylan Marcoux:

The Business of Cyber Partnerships: How MSPs & MSSPs Can Scale & Stand Out ft. Jason Collins (Ep. 8)

The Business of Cyber Partnerships: How MSPs & MSSPs Can Scale & Stand Out ft. Jason Collins (Ep. 8)

Cybersecurity isn’t just something the IT department handles anymore; it’s become a business issue that leaders across the organization must consider every day.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, sit down with Jason Collins, Chief Information Security Officer at Fit Technologies, a 100% employee-owned MSP based in Cleveland, Ohio.

They talk about how cybersecurity has changed over the years, from a behind-the-scenes IT function to a major part of business operations and decision-making. Jason shares why MSPs need to be more intentional about how they grow their security capabilities, how AI is accelerating both threats and innovation, and why people still play such a big role in successful phishing attacks. He also talks about the importance of understanding your environment before adopting new AI tools, and why real partnerships matter far more than simply stacking vendors.

Key takeaways:

  • Cybersecurity has shifted from an IT responsibility to a business-wide leadership priority
  • The difference between a vendor and a true partner can completely change security outcomes
  • MSPs must balance operational speed with thoughtful, risk-based security leadership
  • AI is accelerating both cybersecurity innovation and cyber threats at an unprecedented pace
  • Strong asset management and data visibility are foundational before adopting AI tools
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Jason Collins:

Women Who Secure the World: Breaking Barriers and Building the Future of Cyber Leadership (Ep. 7)

Women Who Secure the World: Breaking Barriers and Building the Future of Cyber Leadership (Ep. 7)

Most cybersecurity conversations focus on tools and threats. The better ones focus on people, trust, and how leaders actually show up when things go sideways.

In this episode, Tony Pietrocola, President and Co-founder of AgileBlue, and Joe Marquette, CEO and Co-founder, sit down with Becky Cross, Vice President of Client Partnerships at FIT Technologies.

They get into how cybersecurity leadership is shifting, what clients actually need in high-pressure moments, and why the way we communicate risk matters just as much as the technology behind it.

Becky brings a perspective that’s grounded in real client experience. Less noise, more clarity. Less fear, more trust. And a clear argument for why different perspectives lead to better decisions when it matters most.

Key takeaways:

  • What it looks like to lead with clarity when clients are under pressure
  • How asking better questions changes the outcome of client relationships
  • Where confidence and perception can get misaligned in leadership roles
  • Why diverse teams tend to make stronger, more balanced decisions
  • How representation continues to shape the future of cybersecurity
  • And more!

Connect with Tony Pietrocola:

Connect with Becky Cross:

Keeping the Lights On: How Critical Infrastructure Leaders Defend the Systems We All Rely On (Ep. 6)

Keeping the Lights On: How Critical Infrastructure Leaders Defend the Systems We All Rely On (Ep. 6)

What happens when the systems we rely on every day stop working? A former Army officer shares how real-world failures reveal the hidden connections inside critical infrastructure.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, sit down with Chelsea Treboniak, U.S. Army veteran, West Point graduate, and owner of Critical Ops. Drawing from her experience deploying with the 82nd Airborne Division and working across critical infrastructure sectors, Chelsea explains why financial systems, energy, identity access, and supply chains are deeply interconnected.

The conversation explores why modern cybersecurity challenges go far beyond traditional IT environments. Chelsea shares how disruptions in one system can ripple across entire sectors, why disaster recovery plans often fail when they are not tested, and how leaders must rethink risk in a world of tightly coupled digital and physical systems. The discussion also tackles the growing role of automation and AI in security operations. While these tools can improve efficiency, Chelsea emphasizes that human judgment, accountability, and leadership remain essential when systems face unexpected failures.

Key takeaways:

  • Critical infrastructure failures rarely happen in isolation; disruptions in one system often cascade across others.
  • Financial services play a larger role in infrastructure resilience than many leaders realize.
  • Business continuity and disaster recovery plans only work when they are tested under real conditions.
  • Automation and AI can improve efficiency, but human decision-making remains essential in high-pressure situations.
  • Leaders must embrace humility and curiosity to identify hidden risks across interconnected systems.
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Chelsea Treboniak:

AI Beyond the SOC: Preparing People and Businesses for a Long-Term Shift (Ep. 5)

AI Beyond the SOC: Preparing People and Businesses for a Long-Term Shift (Ep. 5)

AI can detect disease from your voice.

It can write code, replace junior roles, and potentially reshape global power structures.

So the real question is not whether AI is advancing. It’s whether we can control what we don’t fully understand.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, sit down with AI strategist, advisor, and educator Jason Lowe to explore how rapidly expanding AI capability is outpacing control mechanisms across industries. From healthcare breakthroughs to workforce disruption and global AI competition, the conversation moves beyond hype into practical leadership realities.

Key takeaways:

  • AI is expanding faster than governance and control frameworks can keep up.
  • Continuous learning models could fundamentally change how AI systems behave and evolve.
  • The global AI race is not just commercial; it carries geopolitical implications.
  • AI-driven productivity gains are reshaping entry-level and junior workforce roles.
  • The five human skills that will matter most in an AI-driven world: collaboration, communication, curiosity, creativity, and critical thinking.
  • And more!

Connect with Tony Pietrocola:

Connect with Jason Lowe:

AI Sidekicks: How Artificial Intelligence is Changing Security Ops (Ep. 4)

AI Sidekicks: How Artificial Intelligence is Changing Security Ops (Ep. 4)

AI is moving faster than most organizations are ready for, and the real risk is not the technology itself, but how leaders choose to adopt it. From boardrooms to security operations centers, the balance between innovation and control has never mattered more.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, are joined by Ken Stasiak, veteran cybersecurity leader and founder of NegotiatorIQ, to unpack what AI adoption really means for security teams, executives, and boards. Together, they explore how AI mirrors the early days of the internet boom, why cultural readiness matters just as much as technical capability, and how organizations can avoid overtrusting or underutilizing AI. Ken shares insights on governance, cognitive bias, SOC transformation, and the human responsibility that must remain firmly in place as automation accelerates.

Key takeaways:

  • Why AI adoption today feels similar to the internet boom of the late 1990s
  • The difference between AI as a tool and AI as a decision-maker
  • How overtrusting AI can create long-term regulatory and operational risk
  • Why culture and leadership mindset determine successful AI integration
  • What a healthy human + AI workflow looks like inside a modern SOC
  • And more!

Connect with Tony Pietrocola:

Connect with Ken Stasiak: