The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Startups & Founders/The vCISO Chronicles
The vCISO Chronicles artwork

Episode 48: Merleta Mohr of USA Cyber

The vCISO Chronicles · 2024-04-15 · 26 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber12 / 20
Specificity & Evidence7 / 20
Conversational Craft8 / 20

Merleta Mohr, a CISSP and CISM credential holder, shares her evolution from medical administration and MSP experience into fractional CISO consulting. Her background in compliance - starting with HIPAA in healthcare and progressing through strategic technology planning - shaped her philosophy that people, not checklists, represent both the greatest vulnerability and defense in security. She operates both through a transitional focus on DOD, CMMC, and NIST 800-171 compliance work, and through Security Squared, her private consultancy with a partner focused on building direct client relationships. Mohr advocates for approaching security through risk language that resonates with business leaders, developing a security-first culture embedded top-down through organizational governance, and creating a "critical services list" to uncover shadow IT and unauthorized tools. Her insight on the ineffectiveness of complete SaaS bans - given widespread ChatGPT and Google Gemini adoption - reflects the complexity modern organizations face. The fractional CISO model allows her independence and philosophical alignment that agency work often compromises, though she acknowledges the branding challenge of transitioning from agency visibility to personal recognition.

Key takeaways

  • →Security is fundamentally a people and culture problem requiring consistent training and top-down executive modeling, not merely technical controls and checklists.
  • →Risk is the universal language for engaging executives on security; framing security as a business differentiator and managed asset shifts conversations from compliance burden to competitive advantage.
  • →A critical services list exercise - documenting what staff actually use daily, not what leadership thinks they use - uncovers shadow IT and organizational vulnerabilities that formal asset inventories miss.
  • →CMMC's focus on protecting unclassified military data flow through organizations should be layered with the broader NIST 800-171 framework to secure the entire organization rather than a single data pathway.
  • →Building a strong personal brand and professional network earlier in a consultancy career - before leaving agency work - significantly eases the transition to fractional CISO independence.

In this episode

  1. 1Background in Medical Administration and MSP Experience
  2. 2Certifications: CISSP and CISM
  3. 3People as the Vulnerable Threat Surface
  4. 4Building a Security Culture from Top Down
  5. 5Risk as the Universal Language for Executive Engagement
  6. 6Fractional CISO vs MSP VCISO Services
  7. 7Starting Security Squared and the Importance of Personal Branding
  8. 8Focus on CMMC, DOD, and NIST 800-171 Compliance

Mentioned

Merletta MohrCaroline McCaffreyClearOpsSecurity SquaredISC 2ISACAKim JonesChatGPTGoogle Gemini

Guests

Merleta Mohr

Topics in this episode

NIST 800-171HIPAACMMC (Cybersecurity Maturity Model Certification)security cultureNIST 853 FedRampCISSP (Certified Information Systems Security Professional)CISM (Certified Information Systems Manager)Critical services listDOD complianceFractional CISO

Questions this episode answers

What's the difference between vCISO services through an MSP and fractional CISO consulting?

VCISO offerings through agencies like MSPs provide CISO services at scale, while fractional CISO work through private consultancy creates a more direct, independent relationship where the consultant focuses entirely on that single business's strategy and remains agnostic to organizational products or commitments.

How should organizations approach CMMC compliance relative to NIST 800-171?

CMMC specifically governs how unclassified military data flows through an organization, but should be layered on top of NIST 800-171, which provides broader security controls for the entire organization rather than just the protected data pathway.

What is a critical services list and why does it matter in security assessments?

A critical services list documents every tool, platform, and application employees actually use daily to do business; it typically reveals shadow IT and unauthorized tools that formal inventories miss, exposing previously unknown organizational vulnerabilities.

Why are complete bans on generative AI tools ineffective for organizations?

Complete bans are ineffective because employees are already using ChatGPT, Google Gemini, and similar tools regularly, so organizations must establish realistic policies and governance rather than attempting impossible restrictions.

What's the biggest challenge Merleta faced starting Security Squared as an independent consultancy?

Building personal brand recognition proved hardest after transitioning from agency-branded work; having worked through an MSP meant the agency was branded rather than her individually, making the shift to independent visibility requires intentional personal brand strategy.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode covers competent practitioner advice on security culture, risk framing, and the importance of understanding business context. However, much of the substance is standard industry thinking (security as business enabler, people as the vulnerability, importance of executive buy-in) without novel frameworks or unexpected claims. The conversation lacks concrete methodologies, metrics, or counterintuitive findings that would elevate insight density.

your most vulnerable and most volatile threat surfaces people
security is not just an initiative, it is a part of doing business

Originality

8 / 20

The guest articulates a clear philosophy about direct client relationships versus agency work, but this distinction is well-established in consulting. The frameworks discussed - risk as universal language, security as business differentiator, security by design - are familiar industry concepts. The critical services list exercise is practical but not novel. No contrarian arguments or first-principles rethinking emerges from the conversation.

there's a philosophical position
you really have to enter the relationship with a complete focus on the business

Guest Caliber

12 / 20

Merletta Mohr is a credentialed practitioner (CISSP, CISM) with meaningful operational experience in MSP environments and DOD/CMMC work. She has founded her own consultancy and works directly with small-to-mid-market businesses. However, she is not a household name, has not scaled a major security operation, and the transcript does not establish her as exceptionally senior or broadly influential in the industry. She is a solid mid-level practitioner, not an exceptional caliber guest.

I have worked in the MSP space for years
I have one partner. And really we're just getting started

Specificity & Evidence

7 / 20

The episode is almost entirely devoid of concrete examples, metrics, or data. There are no named clients (anonymized or otherwise), no specific incident case studies, no numbers on compliance failure rates, no timelines on CMMC implementations, and no dollar figures. References to the aviation industry and software development verticals are generic. The 'critical services list' exercise is mentioned but never walked through with real examples from actual engagements.

I have a real interest in software development
there was a lot of demand for it because of the uh, prime and subcontractors in the aviation industry here

Conversational Craft

8 / 20

The host asks open-ended questions and shows genuine interest, but rarely probes deeply or challenges claims. When the guest makes assertions (e.g., 'security is a business asset'), the host agrees rather than pressing for evidence or counterexamples. There are few follow-ups that dig into methodology, failure cases, or concrete implementation details. The conversation flows naturally but remains at a surface level, with the host often pivoting to new topics rather than excavating substance.

Have you ever experienced the challenge where executives are not, um, sort of, I guess, eating their own dog food when it comes to security?
I completely agree with you and I love the framing of it

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B70%
  • Speaker A30%

Most-used words

security22part16organization13started12focus11podcast10cybersecurity9cmmc8ciso7compliance6technology6understand6first6love6agency6problem5

Episode notes

After taking a little break, we are back with our podcast on virtual CISOs. In this podcast, we interview a guest who is busy with entrepreneurship, cybersecurity and business. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit securityexpertmarketplace.substack.com/subscribe

Full transcript

26 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hey, welcome to the Virtual CISO Chronicles, a, uh, podcast about cybersecurity, entrepreneurship and business. Each week I interview an expert working in the field of security. I'm your host, Caroline McCaffrey, one of the co founders of ClearOps, a, ah, security program management platform for virtual CISOs and security experts and privacy experts. For years as the general counsel for various startups, I suffered from what I call the security questionnaire problem. So one day I figured that if no one else was solving that problem, I would. I started this podcast much the same way I went running one day and I tried to find a podcast on these topics, cybersecurity, entrepreneurship and business, and nothing came up. So just like how I started clearups, I thought I'll start my own podcast today. Our guest is Mhletta. Thank you so much for joining me and welcome to the podcast.

Speaker B: Hey, it's great to be here. Thanks for having me.

Speaker A: Let's get going with your background and specifically where your passion for cybersecurity came from.

Speaker B: Sure. I, uh, am a cissp, uh, and cism. I have worked in the MSP space for years. Um, I am transitioning, um, to a more focused, um, organization that has a, a primary focus right now on DOD and CMMC and um, NIST 853 FedRamp. But I also have my own business, Security Squared, where I do, um, private cybersecurity consulting. I kind of, I kind of came to this organically, Carolyn. I, I started my career in medical administration and so I was introduced early to compliance with hipa, um, other regulation. And that just kind of seemed like an area that made sense to me. Uh, and then I started working, uh, in the MSP space and um, you know, spent most of my time working on strategic planning and um, uh, business initiatives and making technology work for business owners. And that kind of led organically into compliance and regulation. As that became a more pervasive issue, um, I just found that I had a passion for that, that I liked being in it. Um, I appreciated the structure of it and so I went ahead and started credentialing myself and decided this was the space I wanted to be in.

Speaker A: Oh, uh, let's, let's focus on the credentialing for a second. Um, and just for purposes of the audience, in case they are not aware, can you just do like a cissp? Cism? What do those stand for?

Speaker B: Certified, um, Information Security, um, System Professional which is through ISC 2, and then certified, um, Information System Manager which is through isaca. And so both of those are really more management, business focused, um, certifications. And again my background is business, it's strategy. Um, you don't want me turning a wrench on your server, I'm here to tell you. And so my role is really more strategic in that. Planning, vision, making uh, technology work for your business, uh, making sure that you're managing risk. Um, that's, that's more where my focus is and governance and, and I think really Carolyn, that's what kind of got me. You know, my evangelism in this space is your most vulnerable and most volatile threat surfaces people. And so you know, everybody wants to reduce cyber security to technical controls and a checklist. And it's, it's so much more than that. It, it's people that really need um, consistent interaction, consistent training, um, top of mind awareness. And, and it's, it's really the people part that really drew me in.

Speaker A: Interesting. So this morning I was scrolling uh, through LinkedIn, which I do periodically and someone was saying uh, specifically on the topic of people in cybersecurity, um, how they don't like how people are called the weakest link in security. But more that people can be your biggest defense in cybersecurity. Which I thought was an interesting um, way to sort of flip the, the, the way it's, it's um, presented. How do you approach the people process and technologies both focusing on the people part in terms of strategy and how you're talking to business leaders?

Speaker B: You know, when I engage with a client, um, my focus is to help them develop a culture of security and to help them understand that security is not just an initiative, it is a part of doing business. And so as we adopt security both with people and with technology and build it into our systems, our processes, our training, then it just becomes part of doing business every day. And so when I engage, the first thing I start talking about is who is your team and, and who are your subject matter experts and what governance do you already have in place. And I really want to identify the people that are involved and I want to identify how the organization communicates, how they um, you know, flow information through the organization. So there's adoption all the way from top to bottom. And then the other thing I'm really looking for is a top down governance based organization. I think a lot of times. And I, and I spend most of my time in the small and midsize business market. So there's you know, a lot of businesses that they're just taking their first crack at compliance. And you know, I think there has to be an understanding that this is a modeled behavior, you know, this is a top down, it has to be adopted, supported, um, influenced, um, reinforced by executive management in order for it, the initiatives to really go through the organization be effective.

Speaker A: Have you ever experienced the challenge where executives are not, um, sort of, I guess, eating their own dog food when it comes to security?

Speaker B: I use that phrase all the time.

Speaker A: Absolutely. I do too. And how do you, uh, if you can think of an example, how do you help change that mindset?

Speaker B: You know, I think that risk is the universal language. And you often have organizations that think that cybersecurity is a technology problem. And you know, uh, there's a famous quote out there about if you think cybersecurity is a technical problem, you need a better understanding of the technology and a better understanding of the problem. And, and it's a good one. So, um, you know, part of what I've found is there's not a business leader in the world that's not concerned about, doesn't want to mitigate and reduce and doesn't want to talk about risk. And so if I can use that universal language and, and use that exercise of risk to engage the executive team and show them not only not only how to build a security platform, but how to make it a differentiator. I mean in this day and age, if you can show that you have an intentional security platform that you maintenance, that you take care of, that you keep current, that's a, that's a business asset. It's not just a checklist.

Speaker A: I completely agree with you and I love the framing of it in terms of do you care about business risks? Well, guess what? So security is one of them. Um, and that, that is how you talk, uh, to the leaders about it. I also want to focus a little bit on what you said from the. Because you, because you have such an interest in strategy, your ability to think about business, um, is, is uh, really interesting to me. And specifically what you said is, uh, you worked at an msp, you're building VCISO services right now, right, As a, as a offering. But then you also said you have another company, um, also.

Speaker B: Right. Security squared.

Speaker A: Right, Security squared. Right. Talk about that.

Speaker B: You know, I think that when you are providing CISO services through like an MSP through an agency like that, you know, that's kind of the VCSO offering. Uh, but for me, through my own company, it's more of a fractional CISO offering because I think there's a more direct relationship there. And I, and really I think that at the end of the day, you have to have that very direct relationship with a business because you are a strategist on their behalf. Hm. And also a CISO has to be somewhat agnostic. Um, you know, you can't be married to an organization or a product or you, you really have to enter the relationship with a complete focus on the business. You have to understand what their process is. You have to understand how they make money, you have to understand, uh, how they engage the marketplace. And I just got done putting a little video out on LinkedIn and just talking about how the world used to stop at the firewall and it doesn't anymore. You know, the tentacles of business are everywhere. And one of the first, first things that I do as a fractional CSO is I work with a company to do a, uh, critical services list. Like what's, what do you and your staff use every day to, to do business and uh, trust and believe they're going to find stuff on that that they didn't know they were using. You know, and I, I really try to push that down all the way through the organization. And that's one of the first exercises that I kind of start to loosen up executive management because they want everything to be clean and tight. And I get it, I've been a business owner and here's the stuff that we use. No, that's the stuff you use. You don't know what Bobby sue at the front reception desk is using. And that's what I want to know. And so that's a, that's an exercise that has to be pushed through the whole organization.

Speaker A: Yeah, yeah. I, I, another thing I was reading this morning was, uh, something about how complete bans on the use of AR are completely ineffective because company employees are using Chat GPT on a regular basis. So, or Google Gemini or whatever. Um, but so saying on Security Squared for a second, is it just you? Do you have partners?

Speaker B: I have one partner. And really we're just getting started and really our focus is just. I, I, I have had the experience of really. And uh, in the industry we talk about this all the time, but I've had the experience of really having a seat at the table. And I've seen the difference between being a vendor and truly having a seat at the table and being a part of that team. And that's what I want.

Speaker A: Okay.

Speaker B: I really want that seat at the table because I've seen how profound, when you're working with an engaged, um, business, I've seen how profound that change can be. And that's really what I'm after. That's what I'm in this for.

Speaker A: And, and so that's, that's the impetus behind Security Squared is what I'm picking up from you. So how did you, is that, I mean, I usually ask how did you start your own, your own business? Ah, is that why? Because you, you wanted that seat at the table.

Speaker B: That, that really is why. I, I think there's a lot of great MSPs out there that are delivering good services. Um, I just wanted to be a little more independent. I just wanted, I just wanted to really be able to walk into an organization and say, my focus is completely on you. My, you know, that's, that's really what I wanted. And um, and that's just part of who I am. You know, that's just, that's just part of how I express, um, the way that I engage in this business. And so that's, that's what brought me to just looking at a private consultancy.

Speaker A: And then you and your partner started it together, or did you bring your partner on after you started it?

Speaker B: Started together.

Speaker A: Um, and how did that, uh, how did that partnership come about?

Speaker B: You know, it was a conversation. It was, it, it was um, really just talking about philosophy. And that's really the difference here. It's, there's nothing wrong with the services that are out there. There's lots of good ones out there, but there's just a, uh, philosophical position. And you know, Carolyn, I've been at this game a long time and I really am to the point in my career that I want to work and express my philosophy the way that seems right to me. And through opening a private consultancy, I just don't have to make some of the compromises that I feel like in an agency you, you are required to make. Um, and again, nothing wrong with that. This is just a personal choice.

Speaker A: Yeah, I really resonates with me quite a bit. And um, as an attorney working with, with companies, that's one of the things that was thrilling for me to start my own business was, was the fact that it gave me an opportunity to run it the way my philosophy and my, my morals. Um, anyway, so, you know, at the

Speaker B: end of the day, we spend so much time working. It's really part of an expression of who we are.

Speaker A: Mhm.

Speaker B: You know, and, and as a business person, I'm to the point in my career that I just really want to have a little bit more influence on that expression. I. Yeah. And that's really all this is Yeah,

Speaker A: I. I love that. So what's. This is my favorite question. And. Ah. So I have to ask everybody, what's been the hardest part of starting your own consultancy firm?

Speaker B: Um, getting our name out there. You, um, know, just. Just, um, creating a brand. Um, you know, getting to know people. Um, you know, when your brand has been through an agency, it's that agency that's branded, not specifically you. So just making that transition between, you know, being a part of an. An agency versus being out on your own, that's been the hardest part.

Speaker A: Oh, interesting.

Speaker B: But. But it's a challenge worth. Worth accepting.

Speaker A: Yeah, of course. Yes. Um, and then what has been the most. I kind of feel like we talked about a little bit, but what has been the most fun or rewarding or best part of starting your own business?

Speaker B: You know, uh, when I was younger, I used to run. Okay. And you know, when. When you're a runner, that first five or 10 or 15 minutes can be awful. And then your body, like, relaxes into it and you just feel like you're the wind, you know? Uh-huh. And oftentimes when. When you truly have a, uh, shared engagement with a business and with an executive team and you really have that flow and that seat at the table, it's like running. You're like, in the wind. And, And. And you know that there is a mutual contribution happening there. It's not just me as a CISO trying to drive something up a hill.

Speaker A: Yeah, it.

Speaker B: It is. It is being a part of a team, being a part of that strategy, being a part of that looking forward and, and consulting on how to, you know, mold processes, systems, um, governance, uh, technology around those business initiatives. So we have security by design instead of trying to retrofit into something that we built without it.

Speaker A: Yeah, you mentioned that you focus on the small medium businesses. Do you focus on a particular sector, given your experience, your initial job experience in healthcare?

Speaker B: You know, I live in the Midwest, and where I live, we do a lot of aircraft. So, uh, when I worked for my previous agency, the managing director of the location where I was at, I think he coined the phrase the best. But that before I became a vcso, I was a hobbyist. I had a real interest in CMMC and nist, and. And there was a lot of demand for it because of the, uh, prime and subcontractors in the aviation industry here. And so that's kind of where I started, and that's what I'm most familiar with. And I was a hobbyist for a couple of years before I got credentialed, um, so through my CISO career, um, I've really found myself in that space. And I've also found myself. I have a real interest in software development. And you know, software development, um, is kind of an industry that's kind of skated out of, uh, compliance a little bit. And now that compliance is recognizing, um, the relationship between second, third, fourth party vendors, they're starting to get some compliance pressure they haven't seen before. And so I have a real interest in secure development, you know, and, and that, um, so I work with a couple of those and um, I do work in medicine, um, but, but I, I really haven't specialized in any vertical. Um.

Speaker A: Yeah, but you did. Sorry, go ahead.

Speaker B: I, um, I have probably had the most experience in CMMC and dod.

Speaker A: That's exactly what I was going to say.

Speaker B: Yeah.

Speaker A: Because you, you started a bit with

Speaker B: that, so m. Yeah, But I'm not afraid of other verticals at all.

Speaker A: I am sure you are not. Especially since I think if I, if I remember looking, when I looked at the cmmc, um, different security, uh, recommendations, it trails very closely to nist, so.

Speaker B: Oh, yeah, yeah. You know, the interesting thing about cmmc, the actual cmmc, what it really cares about is how, uh, military or unclassified data flows through your organization. So CMMC is all about protecting the flow of that information through your organization. But I always lay CMMC on top of NIST 800 171. Because 800171 is broader and it encompasses the whole organization. And so I would prefer, let's not just focus on this one trail of data. Let's secure the whole organization. And that's always been my approach.

Speaker A: It makes sense. Um, a couple, uh. Well, I do want to ask, just for our audience's benefit, any advice if someone's listening to this and thinking about starting their own cybersecurity consulting business that you would give to that person,

Speaker B: um, Have a strategy to build your brand.

Speaker A: Okay.

Speaker B: And I kind of came to that a little bit late, but I ran into a magnificent. I, um, have a professional coach and her name is Kim Jones. And Kim is really helping me strategize about how to do that and how to build my brand. And so I probably would have started building my personal brand a lot earlier, um, in order to help with the transition. So I, I would say that.

Speaker A: Okay. I love it. And I am, um, unfortunately noticing that we're running close to time. And in the promo video for this podcast, you talked about the fact that you're also passionate about rescuing dogs. Love to just hear maybe a few seconds on how, uh, where that came from.

Speaker B: I am, and I really just don't understand why I can't just have all the dogs. But I just really have been a dog lover all my life. And um. Can you hear that?

Speaker A: Oh, yeah.

Speaker B: Uh, can you hear? I've been a dog lover all my life. And um.

Speaker A: Hold on. Dogs in the background.

Speaker B: Yeah, and, um, I rescued. I, uh, up in southeast Nebraska, there was a no kill shelter that I was familiar with and I'd rescued a couple of dogs from there and I rescued a Shiba Inu from there and he had some fear behaviors and stuff that I, I had not run into before. And I met a trainer who helped me work through that and building those tools to understand how to really effectively communicate with canines. It's really opened up a whole new world for me. Um, I, I really, um, feel a sense of responsibility for animals out there that don't have a home. And so I work with rescues. I, I would be a crazy dog lady if it weren't for my husband. But, uh, you know, I also help friends find, um, homes as well. So. Yeah, I, I love it when a good dog finds a, a good family. I love it.

Speaker A: Well, I mean, I could talk to you about that forever because I, I am a dog lover, um, for sure. But unfortunately we have run out of time. Um, and so I need to ask you for purposes of the podcast, where can people reach out to you? How can they find you?

Speaker B: Probably the easiest way to find me is on LinkedIn. Um, you know, on LinkedIn you can message me and I have some videos out there and some, uh, work that I've done and um, I'd be more than happy to answer any questions and if, if you have a need for a ciso, I'm your girl.

Speaker A: Great. Well, Merletta, it is a been a pleasure speaking to you today and thank you so much for joining me me on the podcast. And if you are listening to this podcast, then you know where to find it. But just as a reminder, all of our podcasts are located on substack at the Security Expert Marketplace as well as on Apple Podcast Me, it's been a pleasure. And um, to the rest of you, talk to you next time. Thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why CMMC became necessary in the first place.Trust Issues · on NIST 800-17188 / 100
  • How Consumers Are Defining Healthcare's Future w/ Dr. Daniel Kraft, Founder, NextMed HealthCareTalk: Healthcare. Unfiltered. · on HIPAA81 / 100
  • July 2026 CMMC ConnectCyberspin · on NIST 800-17180 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on NIST 800-17180 / 100
  • CMMC Readiness Can’t Pause Just Because Phase 2 of the Program DidThe Government Technology Insider Podcast · on NIST 800-17178 / 100
  • The Evolving World of Cybersecurity Compliance, with Nathanael DickIT Matters · on NIST 800-17176 / 100

More from The vCISO Chronicles

All episodes →
  • Episode 49: Greg Reitz with CISOciety56 / 100
  • Episode 47: Ferry Haris of FeHa International Consulting
  • Episode 46: Nick Mullen
  • Episode 20: Jacob Ideji from E-Panzer
  • Episode 18: Sam Bourgeois from Make It Secure
Explore the best B2B Startups & Founders podcasts →
All The vCISO Chronicles episodes →