The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Startups & Founders/The vCISO Chronicles
The vCISO Chronicles artwork

Episode 49: Greg Reitz with CISOciety

The vCISO Chronicles · 2024-04-22 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

36 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality6 / 20
Guest Caliber9 / 20
Specificity & Evidence8 / 20
Conversational Craft7 / 20

Greg Reitz brings three decades of IT leadership experience to a detailed conversation about the evolving role of virtual CISO services in modern businesses. After obtaining his CISO certification from Carnegie Mellon University in 2019 and CMMC certifications in 2021, Reitz launched R20 Consulting in 2020 and co-founded CISOciety in 2022 - a partnership of six VCISO providers targeting underserved markets. The episode explores his philosophy that virtual CISOs solve a critical capability-matching problem: companies need different expertise depending on their cybersecurity maturity stage, and fractional CISOs allow organizations to "hopscotch" through growth cycles without the risk of hiring a full-time CISO who may outgrow or be outgrown by the business. CISOciety focuses heavily on K-12 education districts navigating New York State's CSF compliance mandates, CMMC 2.0 manufacturing requirements, and emerging healthcare and financial services regulation. Reitz emphasizes responsible AI governance as an inevitable CISO domain and discusses the entrepreneurial discipline required to balance business growth with personal boundaries.

Key takeaways

  • →Virtual CISO services allow companies to match CISO expertise to their specific maturity stage, enabling faster adoption cycles rather than hiring permanent staff who may become overqualified or underqualified as the business evolves.
  • →K-12 school districts face regulatory pressure through state laws like New York's CSF framework, creating strong demand for fractional CISO services and maturity assessments that districts cannot resource internally.
  • →CISOciety's two-partner model with six co-founders and contract VCISOs enables deliberate, culture-focused growth rather than aggressive scaling, prioritizing client fit and delivery quality over revenue maximization.
  • →The transition from solo consulting to partnership ownership requires shifting from 80% client work to roughly 70% client and 30% administrative oversight, with particular attention to brand protection and engagement management.
  • →Password managers with breach-notification features (like 1Password) and credit-report freezes represent foundational personal security practices that even non-technical individuals should implement immediately.

In this episode

  1. 1Greg's Background in IT Leadership and Cybersecurity
  2. 2Certifications: CMU CISO Program and CMMC Training
  3. 3Launching R20 Consulting and the Pandemic Shift to Remote Work
  4. 4Founding CISOciety as a Collective of VCISOs
  5. 5Scaling from Solo Entrepreneur to Partnership Leadership
  6. 6The Growth of Virtual CISO Services and Business Maturity Cycles
  7. 7CISOciety's Focus on K-12 Education and CMMC Compliance
  8. 8Consulting Philosophy and Security Recommendations

Mentioned

ClearOpsR20 ConsultingCISOcietyCarnegie Mellon UniversityDepartment of DefenseCMMC1PasswordGreg ReitzCaroline McCaffrey

Guests

Greg Reitz

Topics in this episode

CMMC 2.0Responsible AI governanceCISOcietyR20 ConsultingCarnegie Mellon University CISO certificationNew York State Cybersecurity Framework mandateK-12 school districtsDepartment of Defense defense industrial baseVirtual CISO services1Password password manager

Questions this episode answers

What is CISOciety and who founded it?

CISOciety is a collective of virtual CISOs founded in 2022 by Greg Reitz and five other partners, structured as a partnership with contract relationships to additional VCISOs, designed to serve multiple industry segments with expertise matched to client maturity stages.

What certifications did Greg Reitz pursue and why?

Reitz obtained a CISO certification from Carnegie Mellon University in 2019 for foundational knowledge and professional networking, and CMMC certifications in 2021 to gain skills and access to Department of Defense defense industrial base opportunities.

What are the primary industries and regulatory drivers for CISOciety's business?

CISOciety focuses on K-12 education districts (driven by New York State's CSF compliance mandates and similar laws in other states), CMMC 2.0 manufacturing compliance, and emerging opportunities in healthcare and financial services privacy regulation.

How does the virtual CISO model differ from hiring a full-time CISO?

Virtual CISOs allow companies to match expertise to their current maturity stage and swap providers as they grow, avoiding the risk of hiring someone who becomes overqualified or underqualified as organizational needs evolve.

What is the 'be brief, be bright, and be gone' consulting philosophy?

This approach, attributed to Reitz's former supervisor Gene Caceres, emphasizes short-term, high-impact consulting engagements where the consultant delivers value for a defined period and then moves on rather than creating indefinite dependencies.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is dominated by biographical backstory and generic entrepreneurship observations (work-life balance, delegating, trusting your team). The one genuinely interesting idea - matching vCISO seniority to a company's maturity stage like a 'hopscotch' progression - is fleeting and underdeveloped, with almost no actionable depth around it.

a business can basically hopscotch along the path, leveraging experience and guidance of the women and men that have done this job based on what their time in the seat has been for where the company is in their growth cycle
I've had to discipline myself as to the right times to work on my business so that I'm not so consumed with it that my family and everybody else that I should be paying attention to that they don't think that I'm just this person that spends all my waking hours working on a company

Originality

6 / 20

The maturity-matching framing for vCISO hiring is mildly novel, but the rest is standard vCISO sales logic, generic AI-as-hot-potato commentary, and borrowed phrases like 'be brief, be bright, and be gone.' No contrarian claims or first-principles reasoning appear.

it's challenging as a business if you have on staff a CISO who it's hard for them to grow as the business grows in their competencies without putting your business at risk
I'm going to steal your term, because I think it's a fantastic term, of responsible AI, especially from a CISO perspective

Guest Caliber

9 / 20

Greg Reitz is a genuine practitioner - 30+ years in IT leadership, a CMU CISO credential, CMMC assessor certification, and real founding experience - but C-Society has only six partners and is just beginning to scale, so his experience is at a modest level of organizational scale.

I became a certified professional as well as certified assessor So that gave me the skills I need to navigate through work in the defense industrial base
There's six partners in the business and we have relationships with individuals that come to us under contract to work as VC SOS

Specificity & Evidence

8 / 20

There are some concrete data points - Carnegie Mellon 2019, R20 launched 2020, CMMC work from 2021, NY State K-12 CSF mandate, CMMC 2.0 as a pipeline driver, and a named tool (1Password) - but claims about market size, client counts, revenue, and impact are entirely absent, keeping this in the vague-practitioner range.

New York State, where we're based out of, where we're founded from, has laws on the books that require school districts, K-12 school districts, to comply with this CSF framework
if it was 100% or when I was doing R20, if I was spending 80% of my time on clients and 20% on administrative, it's probably shifted to about a 70, 30 right now

Conversational Craft

7 / 20

The host does attempt structured follow-ups - probing the CMU-to-launch timeline and the R20-to-C-Society transition - but the questions remain biographical and never challenge a substantive claim. The 'give us a little bit more of the sales pitch' framing exemplifies the softball register throughout.

when you went to Carnegie Mellon, were you thinking to yourself that you were going to launch? Because you said it had always been a dream of yours
give us a little bit more of the sales pitch

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

started17ciso16society16cybersecurity15help9podcast8districts8practices7opportunity7first7security6spend6best6part6trying6based6

Episode notes

This week, meet Greg Reitz, an entrepreneurial vCISO and CMMC certified professional. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit securityexpertmarketplace.substack.com/subscribe

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

Hey there, this is Caroline McCaffrey, the host of the Virtual CISO Chronicles. This is a podcast about cybersecurity, entrepreneurship, and business. Every week, I interview an expert working in the field of security. So I am your host, as I mentioned before, and one of the co-founders of ClearOps.

ClearOps is an assessments platform, and basically we provide assessments for either assesses or assessors using Gen AI. For years, I was the general counsel for different kinds of companies, and I suffered from what I called the security questionnaire problem. So one day I figured if no one else was going to solve that problem, I would. I started this podcast much the same way.

I went running one day and I tried to find a podcast on cybersecurity, entrepreneurship, and business. I didn't find any. So just like how I started ClearOps, I thought, let's start my own podcast. Our host today is Greg Reitz.

Greg, thank you so much for joining me and welcome to the podcast. Thank you very much. It's a pleasure to be here. So to get us going, let's tell the audience about your background.

And if you can include where your passion for cybersecurity came from, that would be great. Okay. So my background, I've been a career IT leader for many years, 30-some years. Within the last, I'm going to say the last 10 years, I started getting a lot of my job as a CIO or VP of IT was really focused, starting to focus more and more on cybersecurity practices and issues that businesses face.

And I found myself gravitating more and more towards that as I found that to be, not only it was an emerging issue that was getting much more complicated month by month by month as time went on from 2014, it was not only getting more complicated, but it was getting to be a much larger risk for businesses and a significant financial impact if not handled correctly. So I started really picking up my interest in pursuing that, getting certifications in it, focusing on cybersecurity and practical ways that a business can roll cybersecurity into their processes and into their culture in a way that doesn't financially wreck them because you can spend a lot of money on these things if you're not careful, as well as being able to balance it so that you can focus on other initiatives that the business has underway.

So I was really looking for the best value-added moves that a company can take from a cyber perspective that will enable their business strategy overall. Interesting. So since you mentioned certifications and this industry loves to debate certifications, What was the drive for you to get certifications? Was it to just learn more and have that sort of learning quickly forced on you?

Or was it for some reputation benefits or industry professional benefits or both? It was more about my learning. I pursued the CISO certification at Carnegie Mellon University at CMU in Pittsburgh, and they have an outstanding program. I went through that program because and got certified in that simply because I thought them to be one of the best in the country to establish the foundation of cyber practices for an organization, as well as establishing a network of cybersecurity professionals that are part of the cohorts of the students that go through that process.

and so I great appreciation for that it has panned out very well um and so it mine was more about education I I really wasn't interested in in the letters that followed my name I've been in business for 35 years and um I'm more interested in practical experience than I am educational experience sure um but uh the opportunity to to neatly I guess kind of box these things up from a a skill perspective background. I brought everything I had in my career into that certification program.

It worked out very well. So that was my pursuit. I also pursued certifications around CMMC, which is part of the Department of Defense Cyber Strategy. There was programs that were beginning that were needed to be played out and needed to be pursued in order to participate fully in the defense industrial base and the work that's being done within Department of Defense.

So that certification was not only for my own learning and education, but it was also to help try to build access to some business opportunities for my company. Okay. Okay. Interesting.

So a couple of things. When did you go to Carnegie Mellon for the the CISO program? It was 2019. Yeah.

Okay. And then you started R20 Consulting when? In 2020. So in 2020, I stepped out of business formally and started my own consulting company.

It'd been kind of a dream of mine to be able to retire into a consultant role and kind of wind down through my late 60s to a full retirement age. But what I found is that because of the pandemic and things that were happening, the opportunity to work flexibly from anywhere, as long as you were servicing the customers and doing the very best that you could provide from a distance, people were more accepting of that. And as a result of that, I'm able to live in the places that I want to live and still provide services to my customers and try to help them out.

And so that opportunity launched my business. That's kind of how I started doing the consulting work and the VCSO work that I do. And then in 2022, started working with another group of people to launch a second company by the name of C Society. And it's kind of a tricky spelling.

It's capital CISO, so CISO, and then C-I-E-T-Y, so it's C-Society. But we envisioned a collective of VCISOs that could be brought to bear on a variety of different cybersecurity challenges and problems with multiple industry segments, and that's what we've been working on for the past year. So it's been going well with that as well. Okay, so much to unpack, but I'm going to take you back again for a second.

When did you do the CMMC training? I started that training in 2021. And since that time when we started, because the programs were young when they were building skill sets, because they were launching this framework and these skill sets and these tools So we started that in 2021 With CMMC I became a certified professional as well as certified assessor So that gave me the skills I need to navigate through work in the defense industrial base Okay. And so the reason I ask that question is because of this question, which is when you went to Carnegie Mellon, were you thinking to yourself that you were going to launch?

Because you said it had always been a dream of yours. Were you thinking about launching R20 already? Or was that, which came first? um the certification through cmu came first that kind of cemented my appreciation of what it means to be a cso and responsibly in our world and with our businesses so so that kind of lit the fuse of of what i was looking for and then the opportunity to actually launch a company that could service those needs in in the the clients in which we have So that's how that came about.

So it just kind of, it helped me appreciate the depth and the complications of the role and the services. And then 2020 gave me the opportunity to actually build something around that that is of value to the clients and serves people in the businesses that I serve. And so that's kind of how that, it was one two-step, so to speak. Okay.

Okay, great. I'm glad you just said one two-step because I'm going to take you on the third step. So how big did R20 get before you started focusing on C-Society? C-Society is, I think a good way to look at it, C-Society is really the vision of my company I had when I started five years into the future.

But we were able to pull it back to something that we could start in 2022. So I got full pretty quickly in terms of hours. I was one person in my company, was a one person company. It was really, it got filled pretty quickly.

And trying to balance the growth was difficult because of time. Like as an entrepreneur, as a one person shop, you just got so much capacity and that's it. So I had to figure out how to scale in a way that I was going to be satisfied with scaling. to protect my brand and be sure I got the right people involved and things like that.

And then with Sea Society, we started kind of constructing what this could look like. And it literally was a vision of my company years out in terms of how we would structure it. So I had the opportunity to kind of step into a time capsule and jump ahead five years and build something that I would have evolved into, you know, I believe on my own. So So it was really interesting to be able to take what I learned when I was by myself working just in R20 Consulting in terms of process and communication and background tools and ways to do business development, engage customers.

All those things I've learned how to do as an entrepreneur and individual business owner, I was able to use that as the foundation for how we built up C-Society. So it just naturally flowed together. It was really, really cool to see it. Yeah, that's why I'm so focused on this transition in your career, because I think the audience would love to hear.

So C-Society is approximately how big is, and do you work with virtual C-Society on like a contract basis based on how much workflow there is? There's six partners in the business and we have relationships with individuals that come to us under contract to work as VC SOS. So we're just now starting to really scale and grow the company. We spent about a year kind of putting things in place for it and getting the organization established and bylaws and all those things that we want to put in place and training and tools and things like that.

So we took our time. We built it right. Um, everybody had jobs, right? We all had other jobs.

And so we were kind of taking our time to be sure that we constructed this correctly. And, um, so when we, we started getting out there essentially in, um, late 2023, early 2024, we started building some capacity and building some customer. And, um, um, so, and that's where we find ourself today. So we're, we're scaling and we're growing and we're signing contracts and getting good business, but it's, it's very deliberate in terms of cultural fit and being sure we can serve the customer the way that we want to serve.

It's not growth at all costs. It's just very calculated steps that we want to take to responsibly grow the business. That makes sense. So how has your role changed from a solo entrepreneur to now being part of C Society?

And are you focusing, are you doing less maybe client work and focusing more on sort of like you just said, some of the operations of the business? Yeah, it's kind of shifted. So for the longest time in my career, when I was in corporate, I was in IT leadership roles. So I always had a team of people that I worked with.

So you learn as a young leader, how to delegate and trust. You're always verifying things, obviously, but you delegate and try to select the right people that can do the work to the expectations, that you have of the deliverable. And that's a bit of an art, right, of IT leadership when you're a young leader. So when I went on my own as R20, all of a sudden I was unshackled from all that, and I was feeling good because I trusted myself on what I could deliver.

And if I made mistakes, which I do, then I accepted that without a problem and fixed them and moved on. When C Society launched, and I became one of the people that does some responsible for growth and oversight and, and, and things like that. Um, I once again, had to start considering how to trust people to do the work that we sign up for, um, in a manner that protects our brand and that, uh, delivers for the client in to fulfill our commitments. And, um, so I've transitioned partially, not, not too far away from delivering to my clients.

I still do that still hands-on because that's what I enjoy. That's why I do this. But I do have an oversight responsibility of trying to figure out how to manage engagements or how to do bidding, how to handle some of the administrative responsibilities around insurance and things like that so that you can run your business effectively. So it's, if it was 100% or when I was doing R20, if I was spending 80% of my time on clients and 20% on administrative, it's probably shifted to about a 70, 30 right now.

So it more administrative work if we want to put it in those two buckets But it certainly is the right place to spend additional time So I happy to do it because it helps kind of as a catalyst to make sure our growth is controlled and focused Yeah, that makes sense. I guess keeping on this theme a little bit, what is the hardest part about owning and running your own business? Whether it's R20 or C Society, one is a partnership, one is your solo. I think the hardest part, when I was the VP of IT for a company, I felt in my mind I was on call all the time.

Because when you sign up for IT work and cybersecurity work, you're signing up for 24-7. That's just the way that job works and this career works. When I started with our 20RC Society, I don't think about being on call 24-7, but I think about our business at 24-7. So I spend my weeks working in the business, and I find myself on the evenings and early morning or on weekends working on my business.

So I've had to discipline myself as to the right times to work on my business so that I'm not so consumed with it that my family and everybody else that I should be paying attention to that they don't think that I'm just this person that spends all my waking hours working on a company. So I've had to find balance there because it's very tempting to jump in as an owner and work on your things whenever you get a moment. And I've had to find a way to manage that. And it was hard at first because you're just so dedicated to trying to get the thing launched.

And it takes a lot of effort and a lot of brainpower and work and planning. But you also need your personal time. And finding that boundary was tough for me at first, but I'm working better at that, I should say. yeah well i definitely a challenge for me i i find you're in the same boat right when you when you launched yeah so when you launch your company it's like you i i could spend we spend all our time on it if we wanted to yeah i just gotta be careful about it so yeah yeah when people start complaining i'm like oh okay um gotta adjust a little bit yeah that's about it um so i want to I want to focus a little bit on, on our industry specifically, what do you think about virtual CISO services where they're, you know, the, are they, is it becoming a more popular critical thing for businesses to, to have you know, a fractional CISO if they don't have a full-time CISO, or even if they do have a full-time CISO that they're hiring fractional CISOs.

And, and it's almost like not a, it's definitely not a nice to have anymore. It's a need to have. What do you think about that? First off, I think it's a need to have.

I think that if a CISO in some capacity is a need to have. If your board, if you have a board that you are accountable to as a business and your board is not asking you the right questions about security and risk, because that's really what this game is about is risk mitigation. If they're not asking the right questions, then if you have a CISO, they're not being challenged correctly, and the business is not hearing the right challenges from the board. So having a board that asks the right questions is one key to success for business, I believe.

The other is that the launch and maturity cycle to get up to speed on cybersecurity practices that truly benefit your business in a cost-effective manner that ties into your culture is a quick run in general terms. companies have had, I don't know, decades and decades to refine their financial practices. They've had decades and decades to refine their manufacturing processes or supply some of their supply chain processes or things that a business does to function. We've had a quick ramp of, I don't know, 10 years, six years that companies have really been looking at cybersecurity as a function and one that they need to come up to speed quickly on.

So we don't have the luxury of time to do this for decades and decades to settle into a really nice cybersecurity practice in a business. You really need to move quick. And that's why I like virtual CISOs because based on where you are in this adoption cycle and this maturity cycle as a business, you need somebody that has the experience of a startup if you're just starting this up. You need somebody who has the background experience as a middle manager or middle leader around cybersecurity if you're hit that point of your maturity.

If you are moving along faster, you may need somebody who has the wisdom of 20 years of doing, you know, focused on security as opposed to someone who has four. So you almost, it's challenging as a business if you have on staff a CISO who it's hard for them to grow as the business grows in their competencies without putting your business at risk. So be CISOs, you can plug and play. I'm going to get this person for two years because this is the cycle that I'm in with my business, but I need somebody with these experiences in about two years.

So I'm going to go get those guys to replace who I have today. So a business can basically hopscotch along the path, leveraging experience and guidance of the women and men that have done this job based on what their time in the seat has been for where the company is in their growth cycle. So I look at it as a way to match capability with the reality of where a business is, And therein, I believe, is where speed comes from. So that's kind of how I view that.

I really like the way that you just framed that. I have actually not heard someone frame it that way, but it makes a lot of sense that you're hiring someone based on their expertise level, but also where your business is level. So tell me a little bit, I know we did this in the promo, and you said at the very beginning, but C-Society, what type of customers, what is your focus when you work with customers? I know obviously do CMC, so I assume a little bit of Department of Defense, but yeah, give us a little bit more of the sales pitch.

I guess the best way to look at it right now, C Society is we're focused a lot on K through 12 education space So we have a lot of business that we signing and business that we pursuing that is handling cybersecurity practices maturity assessments training those types of things for school districts not only in New York State where we based but we also have business in other states And we have states we're pursuing because of state law associated with cybersecurity practices. So New York State, where we're based out of, where we're founded from, has laws on the books that require school districts, K-12 school districts, to comply with this CSF framework.

Well, that's a great law. It's fantastic. It's the right thing to do. The execution of it was kind of left up to the districts on how you want to become competent with those practices and that framework.

And districts needed help. A lot of districts didn't know anything about that. So we offer our services and my colleagues and other companies offered theirs. And kind of together, we're trying to help get in place the things that districts need to manage this data safely because the data they have is just so sensitive that everybody's trying to pitch in and do the best that they can.

There's other states in the United States that have some laws that are driving the way that New York State's law did. And those are targets for us because we know that they're going to go through the same thing that the districts in New York State went through. So we're paying attention to state law. We're trying to focus on those things.

And that's how we're growing that business. We're also with CMMC. They're just going through review periods and CMMC 2.0 is coming out.

And so we're now starting to target manufacturing companies in the supply chain that will need assistance. And we're having some good luck there as well. So it's really the two things that we're focusing on most intensely right now. So we do have in our back pocket that we're looking at financial services and we're looking at medical and healthcare companies as well around some of the privacy laws that are on the books for them.

So that's where we spend our time. Yeah, it makes sense. And I was just at a conference where AI regulation is coming down the pike. So whole new thing.

The interesting thing was I was sitting at a table full of CISOs and one CISO said, I don't think this belongs in the privacy office. And I said, no, if anything, it probably goes in the CISO office. And she was like, I don't want it in my office either. So it's going to be a little bit of a hot potato game.

Anyway. It's going to be a hot potato game. But there's, you know, the whole concept around your company, ClearOps, is well-founded with, and you've used this term, responsible AI, because I don't think any of us in the CISO space, we cannot avoid, it's already in play. So, you know, it's kind of the genie is out of the bottle.

So we have to figure out how to deal with this in a way, and I'm going to steal your term, because I think it's a fantastic term, of responsible AI, especially from a CISO perspective. At some point, you know, we can't just sit there and go, none of it's allowed. Like, we can't say that. We have to say, here's how you use it.

And here's the controls you have to have in place to use it. And I think that's a pretty exciting space for CISOs is to figure out what that balance point looks like. Yeah, I think CISOs have the skill set that is completely applicable to this area. But I'm cognizant we're starting to run out of time.

And I have a few more questions I want to ask you. So what is something that you have really enjoyed about running your own business? I have enjoyed the opportunities to work with people who I truly admire and who I truly, truly like. I have found, and I don't know if this is bad or good, I don't know what it is, but I found that there are certain groups that I just really, really enjoy helping them and working with them.

And I think the best part of the job is being able to pick those groups and be selective about the folks you want to work with. And my philosophy around consulting is I had an old supervisor when I was working in another job whose phrase was be brief, be bright, and be gone. And I really feel like that is the type of consultant that I want to be, that I strive to be, because I don't want to be somebody's consultant for 20 years. I want to go in and help for some period of time.

And if it's two years, whatever it is, go in and help and then go help someone else. Like that's my mission. So, so yeah, so I think that the opportunity to be able to work selectively with people that, you know, you can get good progress on things and everybody feels good about the right thing. And that's why I like doing this.

I really like this. Be brief, be bright, and be gone. I like that, yeah. Yeah, that was, yeah, Gene Caceres was the one who told me that.

I loved it. That is great. Okay, last quick fire question for you. The number one security tip that you tell people these days, thinking about maybe friends at a social event or something along those lines.

Well, I always start with freezing their credit reports, right? That was, it's always the first thing I tell them, but I, but really one of the things that I tell people is that if they can get a password manager tool, I use one password, you can get a password manager tool that will alert you if their, if passwords are found out in the wild. Number one, I think that that is invaluable information for people that they cannot get any other way because they don't know how to go find and see if what's out there.

So this, those tools do that on a regular basis. They tell you what's out there. Number two, they also tell you, they show you dead accounts that you should have gotten rid of long ago that you might have forgotten about. So they help you prune the tree a bit and they help you keep things managed with proper levels of complexity, but also awareness.

And they're not that difficult to use. They are probably my number one tip is to get a password manager. Awesome. Well, Greg, awesome to talk to you.

Really enjoyed this podcast recording. Can you please tell our listeners how and where they can find you? Yeah. Yeah.

They can email me. My email address is my first initial G, my last name, R-E-I-T-Z at C-I-S-O-C-I-E-T-Y.com. So csociety.

com. So gwrites at csociety.com. Great.

Well, thanks again. And if you are listening to this podcast, you can find all of our blogs and this podcast on Substack and Apple Podcasts at the Security Expert Marketplace. So thanks again, Greg. Greg Writes from C Society.

And we'll talk to you next time. Bye-bye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • #292: AI Without Adult Supervision with Aubrey BlancheThe Analytics Power Hour · on Responsible AI governance86 / 100
  • Top CMMC Compliance Mistakes and How to Avoid ThemCMMC Compliance Guide · on CMMC 2.080 / 100
  • Bold, Fast, Responsible Workflows with KPMG US Vice Chair, AI & Digital Innovation Steve ChaseEnterprise AI Innovators · on Responsible AI governance79 / 100
  • The Evolution and Enforcement of CMMC with Jacob AndersonTrust Issues · on CMMC 2.076 / 100
  • AI Trust Architect: Building Responsible AI with Jill HeinzeFutureProof · on Responsible AI governance51 / 100
  • What Leaders Are Getting Wrong About AI ROI and What Needs to Change ft. Kavita GanesanBringing Data and AI to Life · on Responsible AI governance

More from The vCISO Chronicles

All episodes →
  • Episode 48: Merleta Mohr of USA Cyber
  • Episode 47: Ferry Haris of FeHa International Consulting
  • Episode 46: Nick Mullen
  • Episode 20: Jacob Ideji from E-Panzer
  • Episode 18: Sam Bourgeois from Make It Secure
Explore the best B2B Startups & Founders podcasts →
All The vCISO Chronicles episodes →