Cybersecurity News & Analysis by Cyber Sidekicks - Your Weekly Update’ · Christina Richmond | Rory Duncan - Cybersecurity Experts | Richmond Advisory Group

Security: a multi-layered, programmatic approach - with Charles Henderson of Coalfire

·45 min·3 clips
Charles Henderson says there are “no takesies-backsies” once a breach happens.
1. Cyber Sidekicks’ episode centers on security as a “multilayered, programmatic approach” with Charles Henderson of Coalfire. 2. Christina Richmond and Rory Duncan host Henderson, who is EVP and head of Division Hex at Coalfire and is discussed as a veteran of IBM X-Force and Trustwave SpiderLabs. 3. The episode asks what CISOs should prioritize when budgets are tight, attackers are better funded, and no breach can be undone. 4. The hosts begin with October’s outages at Microsoft, Azure, and Google, and they note a Scottish Parliament voting failure tied to an Azure-based service. 5. They revisit the Nexperia story and discuss reported Chinese retaliation against the Netherlands after the Dutch government used a 74-year-old law to intervene. 6. Henderson says the core security pressure point is “budgets,” because CISOs are asked to do more with less while criminal groups earn higher ROIs. 7. Richmond adds that SEC regulation and breach accountability have concentrated pressure on individual CISOs, even when responsibility is shared across boards and executives. 8. Henderson says the result is “decision paralysis,” because CISOs face too many requirements, too much reporting, and too little clarity about what to fix first. 9. He says the right answer is a “programmatic” security approach rather than a “silver bullet,” with layered detection and response rather than only vulnerability management. 10. He specifically points to red teaming, add-sim exercises, and outside threat hunting as ways to expose gaps before a “cleanup on aisle five” moment. 11. Henderson says outside threat hunting can reveal that a team has strong visibility in one part of the environment and weak visibility elsewhere. 12. He says those visibility gaps are best found before an incident, not during incident response. 13. Richmond describes practicing the plan through cyber ranges and role-swapping people into PR, CEO, and HR responsibilities during breach exercises. 14. Henderson agrees that defense matters because it can determine whether a CISO is retained or fired. 15. The conversation shifts to risk management, and Henderson compares risk selection to a blackjack system where limited resources force hard choices. 16. He says the most successful risk-based programs rely on threat intelligence, not generic advice or gut feeling. 17. On cyber insurance, Henderson says carriers are not the organization’s “North Star for risk tolerance” and should be treated as a backstop, not a substitute for internal judgment. 18. The interview style is conversational and practical, with Richmond and Duncan pressing Henderson for examples and analogies throughout. 19. Listeners interested in CISO risk decisions, red teaming, and cyber insurance will get the most from this episode. 20. Listeners looking for a fast news roundup without a long security strategy discussion may skip it.

As heard by us

Security works better as layers and process than as a lone miracle product.

Cybersecurity is treated here less as a silver bullet and more as an ongoing discipline. Christina Richmond and Rory Duncan keep the focus on layered defense, with detection and response at the center and vulnerabilities folded into a broader operating process.

Read the full review in PlayNext →

Why you'd press play

Skip the silver-bullet pitch and hear how layered security gets argued in plain English.

Read the full recommendation in PlayNext →
Listen to the show on