LinkedIn used to have a decent reputation among cybersecurity professionals. But lately, it feels like our feeds are relitigating the same debates every day, just with different faces. Has the situation changed?
Check outthis postbyAllan AlfordofNTT Global Data Centersfor the discussion that is the basis of our conversation on this week’s episode co-hosted by me,David Spark, the producer of CISO Series, andGeoff Belknap. Joining us isSulohita Vaddadi, executive-threat operations,GE Aerospace. Thanks to our podcast sponsor,Teleskope.
The clichés that say nothing
Some phrases show up in security commentary so often they’ve stopped carrying any meaning at all.Nancy FreeofArmor Defensepointed to two of the worst offenders: “we take your security seriously,” which she noted is “found in every post-breach letter to impacted parties. Great… glad you’re serious NOW,” and “it’s not if you get breached, but when,” which she called “the security equivalent of ‘we all die eventually.’ Technically true. Operationally useless.” The market’s own commentary, others argued, is just as guilty of recycling empty lines.John T., global CISO atBMS Group, put it down to “the immaturity of some commentators and the market as a whole,” rattling off repeat offenders like “cyber is no longer just an IT issue,” as though it ever wasn’t, and “GRC is not just about policies,” when the name already says so, along with “boards don’t understand information/cyber security” and “cyber now threatens life,” which he noted isn’t new either given how much history already demonstrates it.
A discipline without shared answers
The repetition may point to something more structural than tired phrasing.Shawn P Rileyargued that security still operates on experience and opinion rather than shared models or measurable outcomes, which is why the same questions keep resurfacing, “not because they’re new, but because they’re never actually resolved.” In a more mature field, he said, these debates would converge into frameworks and evidence-based answers. “Instead, we keep re-litigating them from scratch, influenced by role, organization, or vendor narrative.” Until that changes, the pattern won’t either.Adrian G., CISO atSolenis, traced the same recycling back to the role itself, arguing it isn’t a LinkedIn problem but “a role-design problem.” Reporting lines, board communication, and business alignment keep resurfacing because the CISO role “was never structurally positioned to resolve them.”
Old topics, new lenses
Not everyone agreed that repetition is a flaw.Todd FitzgeraldofMcCormick School of Engineeringpushed back on the idea that recurring topics are stagnant, arguing that where they “seem the same,” different time periods and lenses are producing different solutions. He compared it to accounting. For example, an accountant today still has to talk about balance sheets, income statements, cash flow, and ROI. “This doesn’t make these concepts obsolete or solved,” he said. “We need to give our 30+ year CISO evolution a break.” That repetition, others said, is doing real work for a changing audience.Dale Werner PhD, PsyD-cofmindloftargued “advocacy and education requires repetition,” since what feels “tired and repetitive” to a veteran can be “interesting and insightful” to someone newer to the field, and consistent, knowledge-backed repetition “might nudge some to move in a consistent direction.”
A people problem, not a security problem
Timing may explain more of the repetition than anyone wants to admit.Mike RerickofDSG Supplysuggested that everyone sits at a different point in the same cycle, noting a topic like CISO reporting lines “may not be relevant to you until you are the CISO and feel some of the issues or constraints others have felt before,” and what feels tired to someone who’s already lived through the struggle can be “fresh and new” to someone still catching up. That gap, others said, has less to do with security than with people.Jonathan Waldrop, CISO atAcoustic, framed it as human nature rather than industry immaturity, since topics stay topics “because it’s complicated, and ‘your mileage may vary… We still have to tell people to eat healthy, exercise, get the vaccine, and wash your hands,” he said. “I don’t think it’s a security problem. I think it’s a people problem.”
Please listen to the full episode on your favorite podcast app, or over onour blog, where you can read the full transcript. If you’re not already subscribed to theDefense in Depthpodcast, please go ahead and subscribe now. Listen to the full episodehere.
Thanks to our podcast sponsor, Teleskope
Join us TOMORROW, Friday [10-02-26], for “Hacking Your Career Growth Mistakes”
Join us Friday, October 2, 2026, for “Hacking Your Career Growth Mistakes: An hour of critical thinking about learning from the past to build your cybersecurity future.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guestsJanet Heins, CISSP, former CISO, ChenMed and author ofGo Ahead… Ask For It!, andMathew Biby, director of cybersecurity,TixTrack. We’ll have fun conversation and games, plus be sure to stick around until the end of the hour for our always-popular post-show meetup, hosted on Zoom.
Register for this event on Crowdcast!
Orregister oncefor every upcomingSuper Cyber Fridayevent. No need to sign up week to week.
What’s a Red Flag When Evaluating a Security Vendor?
Red flag: A company nobody has heard of says it is the world’s leading something.
AtBlack Hat2026,David Sparkasked security practitioners a simple question: what’s a red flag when you’re evaluating a security vendor? Answers included salespeople who can’t explain their own technology, the “technical guy” who never follows up, reps who stick to a script instead of listening, and absolute promises like “we take care of everything.”
It’s a candid look at what earns trust from buyers, and what gets you shown the door.
Read more and watch the videohere. Big thanks to our sponsor,ThreatDown.
Thanks to our sponsor, ThreatDown
September AMA – I’m a CISO who’s built many security teams. I want to help you level up your career. Ask me anything.
CISO Series has assembled a panel of accomplished security leaders who have built and led many security teams over their careers. They are here to help you level up your own career and answer your questions about growing in your current role, moving into leadership, hiring and managing teams, and everything in between.
This AMA runs all week, from September 27 to October 2, 2026, onr/cybersecurity. Our participants will check in throughout the week to answer your questions.
Please ask questions for our participantshere.
This month’s participants are:
- Mathew Biby, (u/RelativeWolf), director of cybersecurity,TixTrack
- Joshua Scott, (u/threatrelic), CISO,Hydrolix
- Janet Heins, CISSP, (u/JBossOnTheLake), former CISO, ChenMed
- Jim Bowie, (u/IllustriousLadder211), healthcare CISO,Zscaler
- Tomás Maldonado, (u/tomas_mald), CISO,National Football League (NFL)
- Roland T., (u/AutoExec-exe), head of information security,ChenMed
Thanks to all of our participants for contributing!
Cybersecurity Headlines – Department of Know
Our LIVE stream ofThe Department of Knowhappens every Friday at 4 PM ET / 1 PM PT with CISO Series producerRichard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will featureBrett Conlon, CISO,American Century Investments, andDan Holden, CISO,Commerce.Join us on YouTubeand catch up on what shaped the week in security. Thanks to ourCybersecurity Headlinessponsor,Intezer.
Thanks to our sponsor, Intezer
Participate! Add our live shows to your calendar
Learn moreabout all of the fun ways you can participate, and add our events to your calendar.
Google Calendar,Outlook, or export an.ics file
Cybersecurity Headlines – Daily News Shorts
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming.Learn moreabout all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What’s Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.