
Hosted by G Mark Hardy & Ross Young
You are not years away from accomplishing your career goals, you are skills away. Learn the Tradecraft to Take Your Cybersecurity Skills to the Executive Level. © Copyright 2025, National Security Corporation. All Rights Reserved
290 episodes · publishes weekly · latest 2026-06-29 · ~42 min/episode
Rank
#1583
Substance
69.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#1583 of 6183
Substance
Top 26%
outscores 74% of the index
CISO Tradecraft® ranks #1583 on The B2B Podcast Index with a substance score of 69.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and specificity & evidence. Marcus Sachs has legitimate, senior, operational credentials: one of three people who stood up what became CISA post-9/11, White House cybersecurity policy work, CSO at NERC (the bulk power regulator), and VP/SVP roles at Verizon and CIS. He is a genuine practitioner who has done consequential work at scale, not a circuit-riding thought-leader. The transcript itself, however, does not fully exploit that depth.
Averaged across 1 recently scored episode, with cited evidence.
The episode surfaces a handful of genuinely useful concepts - harvest-now-decrypt-later, the asymmetric/symmetric distinction in quantum vulnerability, the cryptographic bill of materials - but long stretches are consumed by tangential anecdotes (the 1986 Risk Pack project, Italian postal strike, rack-depth war stories) and basic crypto 101 that adds little for any informed CISO. The ratio of insight-minutes to filler-minutes is poor.
“if I'm doing that, then what I have is an ability to capture a whole bunch of communications, store them up, and then at a future date, play them all back to my quantum computer”
“it's not replacing every encryption algorithm. For those who say we need to become post quantum ready, that's not RIP and replace everything. There's only a handful of things that need to be replaced”
The episode stays largely inside the standard post-quantum narrative (go to NIST, inventory your crypto, cryptographic agility), and the Y2K analogy is well-worn in this context. A few moments - the ransomware-without-encryption pivot and the Merkle-Hellman knapsack as a historical cautionary tale of an entire algorithm class collapsing overnight - are moderately fresh but not genuinely contrarian.
“PQC was real popular before AI came along a couple of years ago. That was like the big buzzword.”
“in 84 AD Shamir, he's the uh, SNRS came up with an attack that basically it didn't back really out of them. It was a general solution. What meant that everybody who'd built a product, everybody who'd implemented the product, everybody had used it, suddenly realized that... there you are with no cryptographic protection”
Marcus Sachs has legitimate, senior, operational credentials: one of three people who stood up what became CISA post-9/11, White House cybersecurity policy work, CSO at NERC (the bulk power regulator), and VP/SVP roles at Verizon and CIS. He is a genuine practitioner who has done consequential work at scale, not a circuit-riding thought-leader. The transcript itself, however, does not fully exploit that depth.
“Back in the summer of 03 it was three of us that were uh, kind of ones to make startup if you will.”
“I was the uh, CS at nerc, that's the regulator for the bulk power system”
The episode scores above average on algorithm-level specificity - naming FIPS 203/204/205, ML-KEM, CRYSTALS-Dilithium, Shor's algorithm relevance to RSA and Diffie-Hellman - but is nearly devoid of hard numbers on timelines, qubit thresholds, organisational cost, or breach impact. Practical recommendations stay at the level of 'do a crypto inventory' without named tools, vendors, or case studies.
“the NIST has a federal information processing standard or FIPS 203, 204 and 205”
“The first one uses a module, um, Lattice Key Encapsulation Mechanism. They call it MLChem”
The host has genuine domain knowledge - he can name Merkle-Hellman, Clifford Cocks, and FIPS standards - which lifts the conversation above a pure PR chat, but the questions are predominantly open and leading ('what else do we might want to think about?'), and there is no substantive pushback or productive disagreement at any point. The host frequently answers his own questions or hijacks the floor for extended personal anecdotes.
“Many CISOs hear the word quantum and they figure, yeah, that's a problem for 2035. Is, is that dangerous way of thinking?”
“How should CISOs go about evaluating vendor claims?”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/ciso-tradecraft" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/ciso-tradecraft/badge.svg" alt="Ranked #157 on The B2B Podcast Index" width="360" height="136" />
</a>Track CISO Tradecraft®'s rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.