Your Compliance Program Is Not a Security Program
A clean audit doesn’t tell you whether your company is secure. It tells you something much narrower, and the gap between what the audit answers and what executives read into
Security strategy for the business you’ve built.
Most security podcasts are built for practitioners. The Rook is built for the people who have to make decisions about security without being security experts.
Hosted by David Shaw — CISSP, fractional vCISO, and GRC consultant with 20 years in the seat — The Rook delivers board-ready intelligence for founders, PE operating partners, M&A attorneys, and executives who own security risk without a dedicated security function.
Every episode covers one topic in depth: a real incident, a regulatory development, a threat pattern, or a market shift. No vendor hype. No practitioner jargon. Just what it means for the business you’re running or the deal you’re working on — and what to do about it.
A clean audit doesn’t tell you whether your company is secure. It tells you something much narrower, and the gap between what the audit answers and what executives read into
David Shaw examines the most consistently overlooked risk in M&A transactions: inherited cyber exposure. From Yahoo-Verizon to Marriott-Starwood, the pattern is the same — cybersecurity due diligence gets a questionnaire while financial and legal diligence…
In chess, the rook controls the open file — a support piece that enables every other piece to win, operating at scale across the board rather than in the weeds of tactical skirmishes. That is the fractional vCISO role exactly.
The rook is also a corvid — part of the crow family, tied to the Corvus brand. The show is positioned squarely against the security podcast category, which overwhelmingly targets practitioners. The Rook targets the buyer: the PE partner evaluating portfolio risk, the founder-CEO facing an audit request, the M&A attorney whose deal team needs a cyber read. These people think in strategy, risk, and outcomes. The show speaks their language.
Hosted by David Shaw, CISSP, GLEG — Founder of Corvus Cybersecurity and a practicing vCISO with 20+ years in the seat. Read his analysis on The Corvus Brief.