Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)” inside PodZeus.
In this live episode of the CISO Series Podcast recorded in Clearwater, FL, host David Spark explores the growing frustration with security compliance theater—where organizations check boxes without meaningful impact. Featuring guests Pam Lindemann, CSO and VP of Strategy for Retail and Hospitality ISAC, and Jason Mayer, Deputy CISO at Raymond James Financial, the conversation dives into the limitations of traditional security awareness training and the shift toward human risk management (HRM). Both guests agree that while rebranding training as HRM is not a panacea, success lies in embedding security into daily workflows, using real-time behavioral data, and aligning security messaging with business outcomes. They emphasize the importance of moving beyond compliance to building a culture where employees understand the 'why' behind security practices. Real-world examples of security theater—like advance-announced phishing tests and ineffective third-party risk questionnaires—are critiqued, with solutions focused on coaching, continuous improvement, and leadership buy-in. The episode concludes with actionable insights on demonstrating ROI, engaging the C-suite, and transforming security from a cost center to a business enabler.
Security awareness training must evolve from compliance checkmarks to real behavioral change through personalized, AI-driven human risk management.
The most effective security programs align with business goals—framing security as an enabler, not a barrier.
Leadership buy-in starts with showing tangible, business-relevant metrics, not just fear-based narratives.
CISOs should foster a security culture by encouraging curiosity (e.g., the 'five whys' technique) and embedding security teams in business operations.
High-risk users (like 'always clickers') should be managed through coaching and support, not just punitive rules—especially when executives are involved.
…and 3 more takeaways available in PodZeus
The Biggest Security Mistake: Losing Business Understanding
“I stopped my pursuit of understanding the business. I thought I knew it well enough.”
The Security Awareness Training Paradox
“Despite regulatory compliance and significant investment, security awareness training seems to deliver marginal benefits.”
Debunking Security Theater
“If your only output of a risk assessment is a completed questionnaire, then it’s security theater.”
From Fear to Coaching: Changing the Security Culture
“Hey, you're in a safe place right now. Aren't you glad that you learned in a safe place?”
What's Worse? Mandatory Weekly Training vs. Three Strikes
“People will get numb to it. They'll just ignore you.”
“Despite regulatory compliance and significant investment, security awareness training seems to deliver marginal benefits.”
“The new attack surface is trust.”
“I stopped my pursuit of understanding the business. I thought I knew it well enough.”
Host
Guests
Pam Lindemann
person
Jason Mayer
person
CISO Series Podcast
media
David Spark
person
Raymond James Financial
organization
KnowBe4
brand
Retail and Hospitality ISAC
organization
Zippo
brand
Adaptive Security
brand
National Cybersecurity Alliance
organization
Remember, Every Underappreciated Risk Is Just a Crisis Waiting to Be Discovered
CISO Series Podcast • 42m • 4/7/2026
Our Theoretical Controls Work Great Against Hypothetical Attacks
CISO Series Podcast • 43m • 4/14/2026
Back in My Day, You Could Get a Cybersecurity Job at the Corner Store
CISO Series Podcast • 39m • 4/21/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
