
Hosted by John Verry
The Virtual CISO Podcast is a frank discussion that provides the very best information security advice and insights for Security, IT and Business leaders. If you’re looking for the latest strategies, tips, and trends from seasoned information security practitioners, want no-B.S.
160 episodes · publishes fortnightly · latest 2026-06-10 · ~43 min/episode
Rank
#3142
Substance
61.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#3142 of 6186
Substance
Top 51%
outscores 49% of the index
The Virtual CISO Podcast ranks #3142 on The B2B Podcast Index with a substance score of 61.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and insight density. Friedman is a genuine 20-year practitioner who built visitor management infrastructure for the World Trade Center campus and now works on military physical security programs - real operational credibility, not a thought-leader circuit rider. However, his domain is narrow (visitor management), he struggles to move beyond high-level speculation on AI and IoT, and his answers frequently stay vague when pressed for specifics.
Averaged across 1 recently scored episode, with cited evidence.
The episode surfaces some genuinely interesting ideas - cross-correlating physical badge data with cyber identity to flag impossible authentications, and the risk of AI-to-AI trust enabling unauthorized physical access - but these are buried under extended drink chat, Long Island reminiscing, and a lot of high-altitude hand-waving about convergence. The idea-to-filler ratio is low for a 41-minute runtime.
“I would say a very, very, very low percentage of organizations are actually putting A plus B equals C together”
“the information that you can get out of physical access control reveals that truth. And that you would compare it to the other side of it, which is your cybersecurity element of this person through this IP address at this network is definitely in this country”
Applying zero trust concepts to physical visitor management is mildly interesting but has been discussed in the industry for years. The speculative AI-bollard scenario and the drug-theft-via-cyber-reconnaissance angle have some novelty, but most of the framing - physical-cyber convergence, siloed security teams, public-private partnerships - is standard industry discourse without contrarian or first-principles development.
“we really just modeled it after zero trust, we really just took the considerations that cybersecurity people were taking and saying, look, you know, if I don't know who you are, you shouldn't have access to this”
“part of it is also, like, how do I know where the drugs are stored, right? Is that on the network? Like, is there a map on the network that I can access”
Friedman is a genuine 20-year practitioner who built visitor management infrastructure for the World Trade Center campus and now works on military physical security programs - real operational credibility, not a thought-leader circuit rider. However, his domain is narrow (visitor management), he struggles to move beyond high-level speculation on AI and IoT, and his answers frequently stay vague when pressed for specifics.
“I became a big part of supplying the solution and also the framework for managing access to the secure facilities within the campus”
“I've been doing it for about 20 years. I've seen a lot of different places and I've applied the same concepts and techniques. And now I'm actually in a project working on it with the military”
The episode name-drops real reference points - the Target/HVAC breach, CMMC, FedRAMP IL-5, NIST 800, ISACs, InfraGard, UnitedHealthcare CEO assassination - but nearly all of these are well-known examples requiring no insider knowledge. There are no proprietary metrics, no client case studies, no dollar figures beyond a passing mention of 'a billion dollars' for a transformer, and no timelines or outcome data from Friedman's own deployments.
“The POS systems that are at every single target are what got hacked by the HVAC guy that got into the cybersecurity because he got into the POS system through the local HVAC system network”
“CMMC is real. And other FedRAM, IL-5, these are things that are part of my journey”
The host occasionally asks sharp, specific questions - pushing on the percentage of organizations actually correlating physical and cyber signals, introducing CMMC and TISAX regulatory angles unprompted - but spends material time on drinks and Long Island small talk, frequently summarizes rather than challenges, and lets vague claims like 'very, very, very low percentage' pass without any follow-up for data or named examples.
“What percentage of organizations would actually be able to detect that?”
“I spent a lot of time pondering AI and AI governance and the risks associated with AI and the new threat vectors that will exist. And I hadn't really thought through very well, shame on me”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-virtual-ciso-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-virtual-ciso-podcast/badge.svg" alt="Ranked #288 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Virtual CISO Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.