Skip to content
Artwork for Caffeinated Risk
BusinessManagementTechnologyNewsTech News

Caffeinated Risk

McCreight & Leece

The monthly podcast for security professionals, by security professionals.Two self proclaimed grumpy security professionals talk security risk, how they’ve managed it in the past and forward looking discussions with guests working in information security and risk management.

Play
  • 20 episodes
  • monthly
  • Avg 28 min
  • English
  • S6 · E7
    September 22 · 25 min

    The Summer's Over Show

    Doug and Tim wrap up the summer with a look at both regulatory changes for critical infrastructure post Bill C8 and then jump across the ocean to dig into some European regulations. AI is top of mind for most and while the technology may be fascinating for some, the business consequences of bad decisions don't magically disappear. Critical thinking is potentially the best risk mitigation option there is in this turbulent time and the podcast hosts recommend one more book for the reading list, Winn Schwartau's MetaWar.

    • Transcript
  • S6 · E6
    August 20 · 11 min

    Inherent risk & business strategy with Patrick Hayes

    There are few business strategy conversations in 2026 that don't include the term AI, yet like the digital "game changers" before such as mobility, voice over IP, Cloud computing and of course the internet, after the hype fundamentals still matter in business. Patrick Hayes , a cyber security thought leader long before it was fashionable, recently released the second book in a series exploring assurance within digital business systems and services. Most organizations are now in a continuous state of digital transformation in one form or another, AI has increased the speed, scope and potential impacts almost overnight minus guard rails. Integrated Assurance introduced the framework, Relevant Impact is a field guide for both delivering an protecting value in this highly volatile time. While frameworks and strategic thinking tend to morph slowly, AI and it's impact on the digital aspects of all organizations is extremely fluid. Follow Patrick's current research in this space via his regular publications.

    • Transcript
  • S6 · E5
    August 6 · 7 min

    Designing AI Enabled Security Products with Rachelle Loyear

    Our inaugural podcast guest and friend of the show Rachelle Loyear has recently released her third book, "Enterprise Security Risk Management (ESRM) in the Real World". We are adding to the Caffeinated Risk summer reading list and marking the occasion with some additional content from the May 2023 episode . Despite being more than two years prior to the recent OpenAI Hugging Face incident, Rachelle's frank discussion about both the potential and the risks associated with AI agency are a cautionary tale for all risk professionals implementing or assessing AI security solutions.

    • Transcript
  • S6 · E4
    July 2 · 34 min

    Cybercrime, Intelligence and Impact with Richard LaTulip

    Richard LaTulip joins Caffeinated Risk for a candid conversation connecting cybercrime investigations, threat intelligence, and practical business risk. Richard is a Field CISO with Recorded Future, a former United States Secret Service special agent, and both the author and real-life main character behind the true crime story Operation Carder Kaos. The discussion starts with Richard’s experience investigating organized cybercrime and quickly moves beyond the “kid in a hoodie” myth toward the reality of structured criminal ecosystems, specialized roles, and professionalized operations. From there, the conversation turns to what threat intelligence should actually do for security teams: be timely, relevant, and actionable. Tim, Doug, and Richard explore how organizations can use actionable intelligence to assess vulnerabilities based on actual business impact, not just severity scores or compliance checkboxes. That risk-based approach is a core ESRM touchstone and is becoming even more important as AI-assisted cyber attacks increase the speed, scale, and adaptability of adversaries.

    • Transcript
  • S6 · E3
    May 7 · 32 min

    Risk Management - Enabling the pursuit of excellence with Joe Olivarez

    Visiting the Jacobs Engineering website you'll undoubtedly encounter the phrase "challenging today", an acknowledgement that the world is much more complex than ever before. While "it ain't like it used to be" can be said of any risk manager's portfolio, Joe Olivarez became the first global security leader in Jacobs history more than a dozen years ago. How much has changed in the last 3 years, let alone 13. Currently the Vice President, Operational Center of Excellence for Jacobs, Joe shares a candid discussion on how risk management has changed both wholistically as a profession and more specifically with large infrastructure projects. In addition to executive leadership for a world renowned organization, Mr. Olivarez is the most recent past president of ASIS , joining the show's own ASIS past president discussing ESRM roots.

    • Transcript
  • S6 · E2
    March 12 · 34 min

    Risk conversations; Awkward, Unpopular and Essential - with Joshua Copeland

    Joshua Copeland's cyber security moniker is "The Unpopular Opinion Guy", while most of us in security roles have been that person with an unpopular opinion at least a time or two, Copeland turned it into both a book and a bit of a movement through numerous posts on Linkedin about many of the challenges in our industry. That said, this is not a mud slinging episode, Joshua had numerous, pragmatic examples of both the problem space and ways to address them. There are a lot of misconceptions about cyber security but there are also a wide array of real world impacts in our daily lives making this a very difficult area to master. Mr. Copeland has some of the unlock codes, making for another compelling episode.

  • S6 · E1
    January 22 · 33 min

    Cyber Security, the legal perspective with Brent Arnold

    "Legal and Regulatory" is a common receptor category in most enterprise risk matrices but with any luck most organizations have limited direct experience with cyber litigation matters. This episode jumps right into the deep end with one of Canada's preeminent cyber lawyers, Brent Arnold. Business law has evolved over hundreds of years, cybersecurity precedents began to appear on the legal landscape in the late 1980s and AI is the new kid on the block, barely out of diapers. While this episode can not be considered legal advice the chance to listen in on the ideas and opinions of from someone on the frontlines of this emerging risk vector should not be missed.

  • S5 · E10
    Dec 4, 2025 · 30 min

    Cyber Resilience, a National Solution with Herbert Fensury

    Cyber crime is now a daily fact of life and a significant concern in both the private and public sectors but our response capabilities do not seem to be keeping up. This episode dives deep into one organization that is combatting this problem with a combination of academic research, industry expertise and hands-on training with the founder and CEO, Herbert Fensury. While cyber security is a global problem, economics and politics dictate different solution requirements. The Canadian Cyber Assessment, Training and Experimentation (CATE) Centre is both cutting edge and focused on Canadian cyber resilience at both a regional and national level.

  • S5 · E9
    Oct 23, 2025 · 34 min

    Integrated Assurance with Patrick Hayes

    20 years after their paths first crossed, three Canadian security professionals regroup to discuss a new risk management strategy book based on hard won field experience. Patrick Hayes was a security strategist before organizations knew this was success differentiator. For decades he has been guiding organizations large and small, public, private and government on balancing business objectives with security. Mr. Haye's new book "Integrated Assurance: Unified Risk Strategy" is destined to become a reference for others tasked with supporting enterprise security and he has recently added a Substack series on the emerging threats of AI, again from the focus of an adversary intent on mission interruption.

  • S5 · E8
    Sep 11, 2025 · 27 min

    The Summer Show - 2025, (pt 2)

    Part 2 of this summer break episode takes a bit of a light hearted look at the cyber security industry predictions that become the norm in late December and early January. Eight or nine months later, how accurate where they? Take a listen, there are a couple surprises. The conversation uncovers a few ongoing challenges with the cyber security industry, from the digital divide associated with aging to organizational shifts away from engineering principles. A book by security pioneer Bruce Schneier is mentioned late in the show and Doug managed to mangle the title twice, but did read, and does recommend the book.

    • Transcript
  • S5 · E7
    Aug 28, 2025 · 26 min

    The Summer Show - 2025, (pt 1)

    The summer show started with the light hearted goal of evaluating the top security predictions that fill the internet in late December each year. Forever unscripted, Tim and Doug wind up reflecting on the growing gap between physical and virtual information systems. While it is easy to lament, from a cognitive perspective there is little hope, the BSides movement, alive and well in Western Canada, is helping address that. It is almost inevitable that security and risk conversations involving society veer into AI, but get back on track with ESRM. Stay tuned for the predictions portion in part 2.

  • S5 · E6
    Jul 31, 2025 · 35 min

    ESRM roots, revelations & resilience with John Petruzzi

    Enterprise Security Risk Management (ESRM) principles appear in almost every episode and this one is a bit more overt because it features two of the three people responsible for promoting ESRM in the early days of it's reintroduction through ASIS. John Petruzzi is now the CEO of Unlimited Technology and leading them toward an expanded influence in the enterprise security industry, sharing insights for what works with fortune 250 organizations, government and even local school boards. As the title implies, resilience is the discipline most organizations need to improve upon, and Mr. Petruzzi's personal and professional opinions on this gap may surprise some. The threat landscape is changing at a pace and breadth few could have predicted, those that navigate it well will prosper.

  • S5 · E5
    Jun 19, 2025 · 35 min

    Global Risk Management as Strategic Advantage with Dominic Bowen

    The Caffeinated Risk hosts navigate time zones and catch up with Dominic Bowen traveling between meetings to discuss risk management with an international expert on the subject. Mr. Bowen is a partner and Head of Strategic Advisory at 2Secure, one of Europe's leading risk management consulting firms, as well as the host of the International Risk Podcast. Political tensions are higher than they have been for years and there is seldom a month that goes by without a technical disruption that affects numerous businesses and services due to the interconnected nature of our modern world. Despite the serious topics covered, Dominic Bowen offers some practical solutions based on experience in the business world , the higher stakes of military service and humanitarian relief offering an unexpected, potentially positive outcome. I.E., accepting the tempo of constant crisis and becoming and effective manager of those risks can actually accelerate success.

  • S5 · E4
    Apr 24, 2025 · 8 min

    Simplifying risk analysis using FAIR and Wiley Coyote with Jack Freund

    A while back we were fortunate enough to spend time with Jack Freund, coauthor and thought leader responsible for bring the FAIR methodology and practice into the main stream. A bonus from that original recording is now an espresso shot discussing how to fast track an assessment when the threat vectors are numerous. While the metaphor Jack used is somewhat unexpected it's both memorable and an excellent approach to dealing with an entire class of attacks in a single assessment. A pro tip from one of the original practitioners of the FAIR methodology well worth a listen.

  • S5 · E3
    Mar 27, 2025 · 30 min

    SMB Resilience and lessons for larger organizations with Rochelle Clarke

    At 45-50%, depending on your statistical source, there is no denying that small to medium sized businesses are a significant economic engine from both an employment and innovation perspective. In 1978 Microsoft numbered 11 people. Unfortunately small businesses are also the least likely to survive a major disruption, an experience that changed Rochelle Clarke's corporate leadership trajectory to a business founder. The Continuity Strength founder shares insights on the needs of small to medium businesses and how to develop resilience plans while simultaneously addressing the two biggest concerns of most SMB owners, time and money. Prior to founding Continuity Strength, Ms. Clarke was the Country Manager, Global Strategy for Heineken, a management consultant and is on multiple board and academic committees.

  • S5 · E2
    Feb 20, 2025 · 36 min

    Addressing Risk and Cyber Resilience, the Alberta Approach - with Rachel Hayward

    A surprising number of digital innovations began in Alberta, be it the world's first public digital cellular network in 1985, the DNP3 industrial controls protocol and becoming the first Google international research lab in 2017. CyberAlberta is another innovative collaboration focused on strengthening the cyber resilience of Alberta organizations. At almost 330 billion annually, protecting the Alberta economy and it's citizens from digital attacks is an important mission. In a very candid conversation, Rachel Hayward, Executive Director of CyberAlberta shares both successes and challenges observed with cyber workforces and organizational readiness. Her previous tenure with the Alberta Privacy commissioner adds some additional nuance in these times of ever greater tests of personal rights.

  • S5 · E1
    Jan 9, 2025 · 36 min

    Security Risk Management in an Open Data Environment with Michael Spaling

    Ever wondered how top universities protect their cutting-edge research from prying eyes while ensuring seamless access for their scholars? Join us as Michael Spaling, Principal Security Architect at the University of Alberta, takes us behind the scenes of this high-stakes balancing act. Just like any other large organization, research universities have many different stakeholder, operational and regulatory requirements, thousands of employees and tens of thousands of customers. In a strange twist, both Mr. Spaling and podcast cohost Tim McCreight are also recent recipients of industry awards, prompting a few questions that reveals some darker elements of social media while continuing to offer security leadership.

  • S4 · E9
    Nov 30, 2024 · 29 min

    Engineering, Risk Management for Cyber-Physical Systems with Andrew Ginter

    The practice of engineering dates back thousands of years, incorporating science and mathematics to solve problems in the ancient world, and remains a key requirement for developing the complex digital systems controlling the physical systems core to our modern way of life. Unfortunately connectivity and complexity have created a vulnerability we must now engineer our way out of, and just like risk management, engineering is about balancing constraints. Andrew Ginter is a recognized thought leader within the industrial security space with decades of real world experience and the willingness to distill that knowledge into a series of book on operational technology cybersecurity. Mr. Ginter's latest book "Engineering-Grade OT Security, a manager's guide" explores risk elements over multiple chapters and provided a great intersection with ESRM principles. A self professed collector of industry wisdom, Andrew was quick to highlight Cyber Informed Engineering principles for security engineering within OT and call out calculation issues when risk assessing black swans yet also offering an elegant approach to resolution. Due to a technical glitch, this episode joins Andrew, Tim and Doug in mid-conversation about Cyber Informed Engineering instead of the typical introduction banter of most episodes.

  • S4 · E8
    Oct 24, 2024 · 34 min

    Deviance Normalization & Risk Management with Marco Ayala

    Technological change is inevitable and often one of the aspects that attracts people toward careers in information and operational technology. Although risk management is a part of navigating advancement in any area, the fundamental flaw in any management system is our human tendencies. This episode explores how organizations can make slow, steady migration from first principles to risky undertakings without noticing. Marco Ayala, an operational technology cybersecurity expert and current Houston InfraGard president, joins this episode to further explore the reasons behind this normalization of deviance, a concept first introduced to OT cyber specialists at S4 in 2024. Mr. Ayala is also CCE proponent and facilitator leading to a discussion on possible options for course correction back off the normalization path. Although solutions must always be tailored to work within organizational constraints, the early contributors to catastrophic outcomes associated with the Challenger space shuttle and Boeing 737 Max warrant exploration or we will inevitably repeat.

  • S4 · E7
    Sep 26, 2024 · 32 min

    Managing Supply Chain Risk Management - with Darren Gallop

    Whether it's the NIST CSF, 8276 or the new European Cyber Resilience Act there is no denying the expectation that supply chain management (SCM) is a risk management area no organization can ignore. While SolarWinds is recent common reference in many SCM discussions, this episode's guest takes us back to Target's major data breach that resulted in significant changes to the PCI-DSS standard. Darren Gallop, a serially successful Canadian tech entrepreneur, recounts the early journey into the software as a service business up to his current role as CEO of Carbide. The episode talks frankly about the current challenges with supply chain management, but Mr. Gallop also shares where he sees bright lights on the horizon and a path forward for organizations willing to consider the shift.

Showing 1–20 of 20 episodes