The TPRM PodcastThreats, Pitfalls & Risk Myths
Listen onYouTubeSpotifyApple PodcastsiHeartRadio
EP 9January 20, 2026

Security Without Waste

Ross Young

Former CISO: Capital One, Caterpillar Financial

Ross Young

In this episode of the TPRM Podcast, Nate Lee sits down with Ross Young, a former CISO and longtime security leader known for his pragmatic, outcome-driven approach to cybersecurity.

Ross brings experience from the intelligence community, including over a decade in government service, followed by senior security leadership roles at Capital One and Caterpillar Financial. He is also the co-host of the CISO Tradecraft podcast and the author of Cybersecurity’s Dirty Secret: Why Most Budgets Go to Waste.

The conversation focuses on why so much security spending fails to meaningfully reduce risk. Nate and Ross explore how budgeting based on status quo assumptions leads to bloated tool stacks, misaligned incentives, and defenses that no longer match today’s threat landscape. They discuss how CISOs can rethink prioritization, challenge legacy practices, and better align spend with real-world threats.

They also dig into how AI is accelerating both attack development and defensive capabilities — shrinking patching windows, changing risk dynamics, and forcing security teams to rethink how fast they operate.

What we cover

  • Why most cybersecurity budgets don’t reduce real risk
  • How legacy assumptions and inertia drive waste
  • Zero-based budgeting and rationalizing tool sprawl
  • Why third-party risk management is fundamentally broken
  • How incentives shape vendor and security outcomes
  • The impact of AI on patching speed and exploit development
  • Practical frameworks for spending smarter, not just spending more

This episode is a practical discussion for CISOs, security leaders, risk executives, and anyone responsible for building security programs that actually work.

About the guest

Ross Young is a former CISO with leadership experience at Capital One and Caterpillar Financial, following more than a decade in the intelligence community. He is the co-host of the CISO Tradecraft podcast and the author of Cybersecurity’s Dirty Secret: Why Most Budgets Go to Waste, where he focuses on helping security leaders reduce waste and align spend with real-world risk.