Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)

CISO Series Podcast43mMarch 31, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)” inside PodZeus.

AI-Generated Summary

In this live episode of the CISO Series Podcast recorded in Clearwater, FL, host David Spark explores the growing frustration with security compliance theater—where organizations check boxes without meaningful impact. Featuring guests Pam Lindemann, CSO and VP of Strategy for Retail and Hospitality ISAC, and Jason Mayer, Deputy CISO at Raymond James Financial, the conversation dives into the limitations of traditional security awareness training and the shift toward human risk management (HRM). Both guests agree that while rebranding training as HRM is not a panacea, success lies in embedding security into daily workflows, using real-time behavioral data, and aligning security messaging with business outcomes. They emphasize the importance of moving beyond compliance to building a culture where employees understand the 'why' behind security practices. Real-world examples of security theater—like advance-announced phishing tests and ineffective third-party risk questionnaires—are critiqued, with solutions focused on coaching, continuous improvement, and leadership buy-in. The episode concludes with actionable insights on demonstrating ROI, engaging the C-suite, and transforming security from a cost center to a business enabler.

Key Takeaways
1

Security awareness training must evolve from compliance checkmarks to real behavioral change through personalized, AI-driven human risk management.

2

The most effective security programs align with business goals—framing security as an enabler, not a barrier.

3

Leadership buy-in starts with showing tangible, business-relevant metrics, not just fear-based narratives.

4

CISOs should foster a security culture by encouraging curiosity (e.g., the 'five whys' technique) and embedding security teams in business operations.

5

High-risk users (like 'always clickers') should be managed through coaching and support, not just punitive rules—especially when executives are involved.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

The Biggest Security Mistake: Losing Business Understanding

I stopped my pursuit of understanding the business. I thought I knew it well enough.

Highlight
2:00
3 min

The Security Awareness Training Paradox

Despite regulatory compliance and significant investment, security awareness training seems to deliver marginal benefits.

Highlight
5:00
5 min

Debunking Security Theater

If your only output of a risk assessment is a completed questionnaire, then it’s security theater.

Highlight
10:00
5 min

From Fear to Coaching: Changing the Security Culture

Hey, you're in a safe place right now. Aren't you glad that you learned in a safe place?

15:00
5 min

What's Worse? Mandatory Weekly Training vs. Three Strikes

People will get numb to it. They'll just ignore you.

High-Impact Quotes
Despite regulatory compliance and significant investment, security awareness training seems to deliver marginal benefits.
John Olsik2:28
Viral: 90.0
The new attack surface is trust.
Adaptive Security (sponsored segment)34:16
Viral: 90.0
I stopped my pursuit of understanding the business. I thought I knew it well enough.
David Spark0:00
Viral: 85.0
Speakers

Host

David Spark

Guests

Pam LindemannJason Mayer
Topics Discussed
security awareness training95%human risk management90%business alignment85%security theater85%security culture85%C-suite engagement80%proving security ROI80%AI-powered attacks75%
People & Brands

Pam Lindemann

person

25xPositive

Jason Mayer

person

20xPositive

CISO Series Podcast

media

15xPositive

David Spark

person

12xNeutral

Raymond James Financial

organization

8xPositive

KnowBe4

brand

7xNeutral

Retail and Hospitality ISAC

organization

6xPositive

Zippo

brand

5xPositive

Adaptive Security

brand

5xPositive

National Cybersecurity Alliance

organization

3xPositive

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Do You Think These Compliance Boxes Check Themselves? (LIVE in Clearwater, FL)” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime