
Hosted by Dejan Kosutic
Listed under Business › Management, Technology
“Secure & Simple” demystifies governance and compliance challenges faced by CISOs, consultants, and other cybersecurity professionals. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA.
41 episodes · publishes fortnightly · latest 2026-08-10 · ~48 min/episode
Rank
#211
Substance
77.4
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#211 of 1878
Substance
Top 11%
outscores 89% of the index
Secure & Simple ranks #211 on The B2B Podcast Index with a substance score of 77.4 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Bruno Lecoq is a credible practitioner: CEO and CISO of a CMMC-certified MSSP, has hands-on experience with multiple certifications (27K, SOC2, HIPAA, working on 42K), has led his company through mock and full audits, regularly advises clients, and attends Cyber AB monthly meetings. He speaks from operational trenches, not theory. His firm size focus (10-1000 users) limits scope, but he's clearly done the work at scale.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers solid, practical information about CMMC implementation with specific numbers (29 policies, 46 procedures, 700 evidence items, 110 controls, 320 AOs, $45-55K audit costs). However, insights are somewhat predictable for target audience (documentation requirements, phased audit process, leadership buy-in) - the core advice reiterates standard compliance wisdom. The specific operational examples (passkey/password discrepancy, onboarding workflows) add texture but don't challenge conventional thinking.
“29 policies. Uh-huh. We we have 46 procedure. Mhmm. We have 14 configuration document and more than 700 evidence.”
“C3PAO will charge today between 45,000 to $55,000 for an audit”
The framing around 'security rigor vs. technical controls' and the notion that CMMC is a 'company project, not an IT project' offer some fresh perspective. However, the broader narrative - compliance requires leadership buy-in, documentation discipline, ongoing maintenance - is standard in governance discourse. The comparison to ISO 27K and SOC2 is useful but not novel. No counterintuitive arguments or first-principles rethinking.
“CMMC is not an IT project, it's a company project and it's a way of life”
“I think the NIST, you know, the pure NIST will be the IT. And for me, what I see is on top of CMMC, they have added some, again, non IT controls”
Bruno Lecoq is a credible practitioner: CEO and CISO of a CMMC-certified MSSP, has hands-on experience with multiple certifications (27K, SOC2, HIPAA, working on 42K), has led his company through mock and full audits, regularly advises clients, and attends Cyber AB monthly meetings. He speaks from operational trenches, not theory. His firm size focus (10-1000 users) limits scope, but he's clearly done the work at scale.
“BEMO as a company is already CMMC certified together with other standards like 27,001, SOC two and HIPAA”
“we did a mock. So to explain for a mock is you your assessor is kind of they will assess you, but it doesn't count against your score”
The episode is concrete where it matters: audit costs ($45-55K + $10K mock), timeline ranges (3 months to 1 year, 9 months average), specific control/AO numbers (110 controls, 320 AOs, 66 monthly reviews), document counts (29 policies, 46 procedures, 700 evidence items), C3PAO numbers (93 registered), 87% phase-one failure rate. Lacks specifics on actual client transformations, ROI, or named customer examples (understandable due to NDAs). SSP page count cited (300 pages) but not comparative data.
“200,000 contractors in The US, and as of right now, only 3,000 are CMMC level two compliant”
“87% of the people don't pass phase one”
Host Dejan asks clarifying follow-ups ('Can you tell me about the basics?', 'What distinguishes level one and two?', 'Are all controls in NIST 171?') and gently probes contradictions ('But ISO 27K should also check records, right?'). However, questioning lacks sharpness - few pushbacks on vague claims, limited challenge to guest's framing. Host doesn't press on the cost/burden story or ask harder questions about why 87% fail or what 'security rigor' truly operationalizes. Conversation is friendly but surface-level, missing opportunities to stress-test Bruno's recommendations.
“But ISO 27,000 certification bodies should do the same. Right? They should also check the records. Yeah. But I I have I have felt like the the bar is lower”
“So what exactly do you mean by this? [on business velocity vs. security rigor]”
2 periods tracked.
11 scored on substance · 41 tracked in total.
CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq
2026-08-10 · 41 min
How CISOs Should Talk to Corporate Boards | Interview with Michelle Drolet
2026-06-30 · 42 min
Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo Huang
2026-06-16 · 43 min
ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange
2026-06-02 · 38 min
Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford
2026-05-19 · 41 min
What CISOs Must Do Now About Quantum? | Interview with Andrew Gault
2026-05-05 · 44 min
Continual Improvement, Nonconformities, and Corrective Actions | Interview with Carlos Cruz
2026-04-21 · 56 min
Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee Rossey
2026-04-07 · 47 min
AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy Merza
2026-03-24 · 49 min
Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew Gault
2026-03-10 · 46 min
Responding to Ransomware Attack [Case Study] | Interview with Yannick Hirt
2026-02-24 · 43 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/secure-simple-podcast-for-consultants-and-cisos-on-cybersecurity-governance-and-compliance" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/secure-simple-podcast-for-consultants-and-cisos-on-cybersecurity-governance-and-compliance/badge.svg" alt="Ranked #24 on The B2B Podcast Index" width="360" height="136" />
</a>Track Secure & Simple's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Ship It Weekly
Teller's Tech - DevOps, SRE and Cloud Podcast
Unsupervised Learning with Jacob Effron
by Redpoint Ventures
Podcast Archives
Podcast Archives - Software Engineering Daily
DevOps Daily with Fexingo
Fexingo
The Pragmatic Engineer
Gergely Orosz
The Engineering Leadership Podcast
The Engineering Leadership Community (ELC)
Podcasts that dig into the same topics.
Cyber Sentries: AI Insight to Cloud Security
TruStory FM
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
RunAs Radio
Richard Campbell
Threat Talks
Threat Talks
Security & GRC Decoded
Raj Krishnamurthy
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson