The Rook
Most security podcasts are built for practitioners. The Rook is built for the people who have to make decisions about security without being security experts.
Hosted by David Shaw — CISSP, fractional vCISO, and GRC consultant with 20 years in the seat — The Rook delivers board-ready intelligence for founders, PE operating partners, M&A attorneys, and executives who own security risk when security isn’t their day job.
Every episode covers one topic in depth with examples from a real incident, a regulatory development, a threat pattern, or a market shift. No vendor hype. No practitioner jargon. Just what it means for the business you're running or the deal you're working on — and what to do about it.
New episodes every other Tuesday.
Episodes
2 episodes
The Rook Ep. 002: Your Compliance Program Is Not a Security Program
A clean audit doesn't tell you whether your company is secure. It tells you something much narrower, and the gap between what the audit answers and what executives read into it is where most companies are quietly carrying real risk.In th...
The Deal You Didn’t Know You Made: Cyber Risk in M&A
In this episode of The Rook, David Shaw, founder of Corvus Cybersecurity and principal vCISO, examines the most consistently overlooked risk in M&A transactions: inherited cyber exposure. From Yahoo's misrepresentation of its breach history...