
Hosted by Dejan Kosutic
“Secure & Simple” demystifies governance and compliance challenges faced by CISOs, consultants, and other cybersecurity professionals. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA.
38 episodes · publishes fortnightly · latest 2026-06-30 · ~49 min/episode
Rank
#523
Substance
76.2
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#523 of 6183
Substance
Top 8%
outscores 92% of the index
Secure & Simple ranks #523 on The B2B Podcast Index with a substance score of 76.2 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Aron Lange is a relevant practitioner with substantial hands-on experience: founder of GRC Lab, certified auditor with multiple dozen ISO 27001 certification audits completed, trainer, and recently expanded to ISO 27007 audits. He brings real audit-floor perspective rather than pure theory. However, he is not a C-level operator, major enterprise CISO, or someone who has built security programs at scale, which limits the depth of strategic insight.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers practical, actionable insights about what certification auditors actually look for during ISO 27001 audits, with specific examples like risk treatment plan approval and scope documentation failures. However, it relies heavily on well-known findings (missing approvals, undocumented policies, scope issues) that experienced practitioners likely encounter in standard guidance, and contains notable filler including podcast boilerplate at the end and some repetitive questioning that doesn't advance substantive understanding.
“something that's very common in a stage one to observe...you need to get two acceptances or two approvals. You need to get an approval for your risk treatment plan, which is often omitted. You need acceptance for the residual risks”
“the most important part of an audit is the proof or the evidence that what you write in your policy is actually carried out in practice”
While the guest offers some genuinely useful reframes - notably distinguishing between auditing for conformity versus hunting for non-conformities, and explaining the inherent gap between an ISO 27001 certificate and actual security posture - most of the core content recycles standard audit frameworks and well-documented compliance patterns. The insight about SOC2 tools being poorly adapted to ISO management systems is valuable but niche. Overall, the thinking is sound but not particularly fresh or contrarian.
“I don't enter the audit with the mindset of I have to find something today...I'm tasked to assess the conformity”
“we are technically on the wall, 2,000,000,000 corporation has the same ISIS certificate hanging on the wall than the five person startup from around the corner”
Aron Lange is a relevant practitioner with substantial hands-on experience: founder of GRC Lab, certified auditor with multiple dozen ISO 27001 certification audits completed, trainer, and recently expanded to ISO 27007 audits. He brings real audit-floor perspective rather than pure theory. However, he is not a C-level operator, major enterprise CISO, or someone who has built security programs at scale, which limits the depth of strategic insight.
“he works as a certification auditor for TUV or TÜV SÜD certification body and has already performed couple of dozen certification audits for 27,001”
“I mean, I know you are very well known for your expertise in the ISO management system world”
The episode provides several concrete examples: specific policy approval failures, risk treatment plan findings, recovery point objective mismatches with backup frequency (one week vs. 24-hour RPO), and password complexity rules (8 vs. 12 characters). However, these examples are somewhat generic illustrations rather than named case studies with actual numbers, dollar figures, or timeline data. The guest avoids naming specific companies or sharing quantified metrics on audit failure rates or costs, limiting evidence density.
“Let's say you have a system that is backed up once a week, but the system belongs to a process that has a recovery point objective of twenty four hours”
“you realize the password minimum length is eight characters. And you feel like, well, practice, 12 characters at least would be better”
The host asks solid foundational questions that draw out actionable insights (e.g., how auditors collect evidence, the difference between non-conformities and opportunities for improvement, where the line between auditing and consulting lies). Some follow-ups are sharp and probe assumptions, such as the question about whether verbal confirmation alone is sufficient or whether written evidence is always needed. However, the host occasionally allows repetitive circling (e.g., multiple restatements of the same point about written vs. verbal evidence) and misses opportunities to push the guest on harder contrarian claims, such as deeper exploration of the 'absurdity' of certifying management systems rather than security posture.
“So what can actually a company do in this kind of a situation if the auditor is pushing something that is really not required?”
“Where is this line between auditing and consulting? So how far can you go with these suggestions as an auditor without doing the consulting work?”
First period on the Index - history builds from here.
10 scored on substance · 38 tracked in total.
How CISOs Should Talk to Corporate Boards | Interview with Michelle Drolet
2026-06-30 · 42 min
Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo Huang
2026-06-16 · 43 min
ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange
2026-06-02 · 38 min
Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford
2026-05-19 · 41 min
What CISOs Must Do Now About Quantum? | Interview with Andrew Gault
2026-05-05 · 44 min
Continual Improvement, Nonconformities, and Corrective Actions | Interview with Carlos Cruz
2026-04-21 · 56 min
Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee Rossey
2026-04-07 · 47 min
AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy Merza
2026-03-24 · 49 min
Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew Gault
2026-03-10 · 46 min
Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt
2026-02-24 · 43 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/secure-simple-podcast-for-consultants-and-cisos-on-cybersecurity-governance-and-compliance" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/secure-simple-podcast-for-consultants-and-cisos-on-cybersecurity-governance-and-compliance/badge.svg" alt="Ranked #53 on The B2B Podcast Index" width="360" height="136" />
</a>Track Secure & Simple's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
Cyber Sentries: AI Insight to Cloud Security
TruStory FM
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson
CISSP Cyber Training Podcast
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
Cyber Go-To-Market Talk
Andrew Monaghan
The Backup Wrap-Up
W. Curtis Preston (Mr. Backup)