Episodios

  • CMMC Demystified Scoping Compliance and Avoiding Costly Mistakes
    Aug 29 2025

    In this episode, Cheri Hotman and Paula Biggs break down the realities of CMMC compliance, with a special focus on scoping and avoiding common missteps. They explain how CMMC builds on existing NIST 800-171 requirements and why scoping—deciding which systems, people, and vendors fall under compliance—is the first and most critical step. Paula emphasizes that smaller companies can often save significant cost and risk by narrowing their scope strategically, while Cheri highlights how poor scoping leads to inflated audits, unnecessary licensing fees, and added risk exposure. Together, they stress the importance of understanding vendor responsibilities, building accurate and detailed System Security Plans (SSPs), and treating audits as confidence-building exercises rather than checkbox events. The conversation reinforces that CMMC isn’t just about passing an audit—it’s about sustaining secure, risk-aware practices that protect sensitive data and long-term business trust.

    Más Menos
    44 m
  • Beyond the Audit: Making Continuous Compliance Work
    Aug 29 2025

    Cheri Hotman and Tanya Wade cut through the checkbox mentality of audits to show why real compliance is about building programs that protect your people, data, and reputation year-round. From SOC 2 readiness to the pitfalls of over-relying on GRC tools, they share practical steps for prioritizing controls, assigning ownership, and reducing audit stress. If you’ve ever thought “we passed the audit—now what?”, this episode gives you the roadmap to continuous compliance with less chaos and more confidence.

    Más Menos
    23 m
  • Episode 0: Why Cybersecurity Is as Much Art as Science
    Aug 20 2025

    In this kickoff episode of The Art of Cybersecurity, host Cheri Hotman shares why this podcast exists and what listeners can expect. Cyber isn’t just science or technology — it’s art. It’s messy, constrained, people-driven, and ultimately about mitigating risk to protect people and data.

    Cheri cuts through the noise of “easy button” tools, audit-passing mentalities, and checkbox compliance to talk about what security really is: designing programs that work, tackling people and process challenges, and aligning solutions to business goals.

    Expect honest, unfiltered conversations, real-world stories, and practical insights that go beyond buzzwords. If you’re ready to say what needs to be said and push for cybersecurity that truly matters, subscribe now and join the fight.

    Más Menos
    22 m
  • 5 Tactics to Protect the Cloud Pt. 2
    Jul 19 2022

    Take these 5 tactics given by Cheri Hotman to help better protect the cloud.

    Más Menos
    8 m
  • 5 Tactics to Protect the Cloud Pt. 1
    Jul 18 2022

    Take these 5 tactics given by Cheri Hotman to help better protect the cloud.

    Más Menos
    8 m
  • Cybersecurity is a Problem of People
    May 5 2022

    Cybersecurity is a Problem of People


    ➜ Hit the LIKE button

    ➜ SHARE the video with someone who might need it

    ➜ POST your questions in the comments for future video topics

    ➜ SUBSCRIBE for notifications of new episodes

    #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #phi #pii #pi #softwareindustry #dataprivacy #dataprotection #womenincybersecurity #womenincyber #womeninfintech #womenintech

    Más Menos
    11 m
  • Pen Test to Remove Security Blindness
    May 5 2022

    Pen Test to Remove Security Blindness


    ➜ Hit the LIKE button

    ➜ SHARE the video with someone who might need it

    ➜ POST your questions in the comments for future video topics

    ➜ SUBSCRIBE for notifications of new episodes

    #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #phi #pii #pi #softwareindustry #dataprivacy #dataprotection #womenincybersecurity #womenincyber #womeninfintech #womenintech

    Más Menos
    9 m
  • SaaS Tools Cover My Security, Right?
    May 5 2022

    SaaS Tools Cover My Security, Right?


    ➜ Hit the LIKE button

    ➜ SHARE the video with someone who might need it

    ➜ POST your questions in the comments for future video topics

    ➜ SUBSCRIBE for notifications of new episodes

    #cybersecurity #security #soc2 #vciso #compliance #risk #riskmanagement #grc #itrm #video #fintech #healthcare #healthcaretechnology #healthcaretech #software #saassecurity #ceo #ciso #phi #pii #pi #softwareindustry #dataprivacy #dataprotection #womenincybersecurity #womenincyber #womeninfintech #womenintech

    Más Menos
    8 m