When Cybersecurity Became a State Responsibility with James Saunders

Season 3 /
/Episode 8

When Cybersecurity Became a State Responsibility with James Saunders

Federal cybersecurity responsibility has shifted to the states. What happens next?

In this episode of The SafeHouse Podcast, Jeff Edwards welcomes James Saunders, Chief Information Security Officer for the State of Maryland, for a deep conversation on state-level cybersecurity, resilience, and leadership.

James walks through his path from early technical support roles to federal cybersecurity leadership and now to protecting Maryland’s digital ecosystem. He explains Maryland’s IT Master Plan, the state’s five-pillar cybersecurity strategy, and how partnerships, talent, and resilience come together in practice.

This episode offers a behind-the-scenes look at how cybersecurity decisions are made at scale, how states collaborate with one another, and why taking care of people matters as much as taking care of systems.

You’ll learn about:

• How cybersecurity policy and funding have shifted to the states

• Maryland’s approach to cyber resilience and zero trust

• Public-private partnerships and information sharing

• Cybersecurity workforce development

• Lessons from leading through COVID

• Practical advice for cybersecurity professionals

James closes with powerful advice: take care of yourself first—because burnout weakens even the strongest defenses.

Resources Mentioned in the Podcast: https://doit.maryland.gov https://doit.maryland.gov/About-DoIT/…

Subscribe for more conversations on resilience, cybersecurity, and risk.

#SafeHousePodcast #CyberRisk #CyberSecurity #StateCybersecurity #RiskManagement #CyberSecurityPodcast #Resilience #PublicSectorIT

Making Sense of Risk Management with Davis Hake

Cyber risk management is often discussed in technical language. But at its core, risk is financial.

In this episode of The SafeHouse Podcast, Jeff Edwards interviews Davis Hake of Venable to break down how cyber risk should be measured, communicated, and quantified inside organizations.

For CISOs, risk managers, brokers, underwriters, and resilience professionals, this episode provides a practical framework for thinking about cyber exposure beyond compliance checklists.

If you want to understand cyber risk in terms that boards and CFOs actually respond to, this conversation is essential listening.

Read More »

When Cybersecurity Became a State Responsibility with James Saunders

Federal cybersecurity responsibility has shifted to the states. What happens next?

In this episode of The SafeHouse Podcast, Jeff Edwards welcomes James Saunders, Chief Information Security Officer for the State of Maryland, for a deep conversation on state-level cybersecurity, resilience, and leadership.

James walks through his path from early technical support roles to federal cybersecurity leadership and now to protecting Maryland’s digital ecosystem. He explains Maryland’s IT Master Plan, the state’s five-pillar cybersecurity strategy, and how partnerships, talent, and resilience come together in practice.

This episode offers a behind-the-scenes look at how cybersecurity decisions are made at scale, how states collaborate with one another, and why taking care of people matters as much as taking care of systems.

Read More »

Why Cyber Warranties Are Not Insurance — and Why That Matters

Kirsten Bay, CEO and co-founder of Cysurance, explains why warranties are becoming a critical layer in cyber risk management. Bay explains how AI-driven cyber certification can help organizations predict where risk is most likely to surface, prevent disruption before it becomes a claim, and protect both insureds and carriers by creating clear, defensible signals of cyber maturity.

Read More »

Cybersecurity Frameworks Made Practical: From Confusion to Clarity

Ryan Ettridge, CEO of CyberCert, tackles a problem many organizations struggle with – cybersecurity frameworks that look good on paper but feel overwhelming or unusable in practice.
Ryan explains how AI-driven cyber certification can help organizations predict where risk is most likely to surface, prevent disruption before it becomes a claim, and protect both insureds and carriers by creating clear, defensible signals of cyber maturity.
Chart a clear path from path from compliance to real-world readiness with fundamentals covered in this episode.

Read More »

From Bootcamps to Battlefields: Keith Gologorsky on Modern Cyber Training

Keith Gologorsky, Head of Public Sector at Hack the Box, shares his personal journey from computer science graduate to government analyst, recounting pivotal moments in military operations, threat analysis, and international collaboration. The discussion explores the limitations of traditional certifications, the importance of hands-on training, and the need for regularly updated, gamified learning experiences. Keith also addresses the cybersecurity skills gap, the evolving role of AI, and offers actionable advice for organizations of all sizes: prioritize cross-training and real-world practice to build resilient teams.

Read More »