CISO Series Podcast CISO Series Podcast

Why Don't You Tell Me Which Metrics Sound Most Impressive?

Jul 28, 2026 · 48m

Summary

Hosts David Spark and Andy Ellis join guest Pavi Ramamurthy to critique vanity metrics, SIM failures, and the Delve audit scandal. They discuss the pitfalls of checkbox compliance, the futility of "I told you so" risk logs, and the need to redesign systems rather than blame human error. The episode concludes with a debate on when AI agents will gain trust for autonomous purchasing.

Topics discussed

Introduction and guest welcome Andy's story about destroying minimalist art The problem with vanity metrics in security Reporting meaningful metrics to the board Critique of phishing simulation campaigns Flaws in SOC 2 audits and TPRM questionnaires Vendor risk management and incident response Debate: Compliance vs. effective security training The futility of checkbox security awareness Risk registers and CISO job protection AI governance and prompt injection risks Reducing friction and eliminating passwords Book plug and closing remarks
Listen ad-free on Castria