Skip to content
Artwork for And Security For All

And Security For All

Kim Hakim

Cyber security is not only important to everyone, it is critical to the future of every American. Each show details specific points in history and provides guidance and insights of both a technical and societal nature to help you understand and address cyber security issues more effectively. Our approach makes the often misunderstood and highly technical jargon of cyber security advisories, and popular media digestible for anyone that listens.brbr Anyone that leverages or uses internet and cyber related services, which in today’s world is basically everyone, stands to benefit from the show. You’ll gain insight into the reality of the space around cyber security and learn more details and truths on what is actually necessary to operate and be more secure at both the business and personal levels in an ever-changing technology space. We can help you truly understand a vast technology space and be better prepared in a dynamic technology ecosystem.

Play
  • 27 episodes
  • Avg 44 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • February 26 · 48 min

    LockBit Changed Everything and Locked Up Tells Why

    What really happens during a ransomware attack? In this powerful episode of And Security For All, host Kim Hakim sits down with Zach Lewis, CIO & CISO at the University of Health Sciences and Pharmacy in St. Louis, to break down the real-world story behind his new book Locked Up — a firsthand account of surviving a major ransomware incident. From negotiating with the notorious LockBit ransomware group to navigating board-level decisions about paying (or not paying) a ransom, Zach shares what most organizations never talk about publicly. 🔐 In this episode, we cover: What actually happens during a ransomware attack (pre, during & post-breach) How ransomware groups like LockBit operate as “ransomware-as-a-service” Why some organizations pay — and what happens after they do Double extortion & the evolving tactics of cybercriminals AI-powered phishing, deepfakes, and the new threat landscape How boards are responding to growing cyber risk Practical advice for small and mid-sized organizations with limited security budgets Lessons learned from real breach recovery With ransomware, AI-driven attacks, and data extortion on the rise in 2026, this conversation is essential listening for CISOs, IT leaders, board members, business owners, and anyone responsible for protecting sensitive data. 🎧 Whether you're in healthcare, education, finance, or enterprise security — this episode delivers actionable insight from someone who’s lived through it.

  • February 17 · 46 min

    Disrupt or Be Breached: The New Cyber Reality

    Cybersecurity isn’t slowing down — it’s accelerating. In this episode of And Security For All, host Kim Hakim is joined by Arun DeSouza, Managing Director at ProFortis Solutions and President of the ISSA Detroit Chapter, for a powerful conversation on emerging cyber trends, AI disruption, and the evolution of the modern CISO From supply chain risk and ransomware evolution to OT security, cloud vulnerabilities, regulatory accountability, and AI-powered threats, this episode explores the real-world challenges security leaders are navigating right now. Topics include: The rise of cyber resilience over pure prevention Why supply chain risk is now bigger than ransomware OT and critical infrastructure targeting The API economy and expanding attack surfaces AI as both attacker and defender Deepfakes, autonomous attacks, and data poisoning Observability vs visibility in modern security operations The revolutionary evolution of the CISO role Arun also shares practical strategies for embedding security into innovation lifecycles, building AI governance frameworks, and preparing organizations for the next wave of disruption. If you’re a CISO, security practitioner, board member, or technology leader, this episode delivers actionable insight on how to stay ahead in an era where innovation and risk move at warp speed.

  • February 10 · 48 min

    Welcome to the Runtime Era & the Rapid Shift in AppSec 📈

    In this episode of And Security For All, host Kim Hakim sits down with Jeff Williams, Founder and CTO of Contrast Security, for a deep dive into why application security is undergoing its most dramatic shift in decades. Jeff shares his journey from helping create the OWASP Top Ten to building one of the leading runtime application security platforms, and explains why traditional AppSec approaches are no longer keeping up with modern software development. 🎙️ In this episode, we cover: Why 2026 is shaping up to be the year of runtime security How traditional AppSec tools create noise instead of clarity What runtime security reveals that static and perimeter tools cannot Where AI truly helps in AppSec—and where the hype falls short How European regulatory changes are redefining software liability Why security teams must prioritize context over volume What developers, CISOs, and security leaders should focus on next This conversation breaks down complex topics like runtime protection, AI-driven remediation, regulatory pressure, and developer enablement into clear, practical insights for today’s security practitioners. Whether you’re a CISO, AppSec leader, developer, or security architect, this episode offers a forward-looking perspective on how application security is evolving—and what it takes to stay ahead.

  • January 28 · 44 min

    Securing Intelligence: AI’s Impact on Cyber Risk

    In this episode of And Security For All, host Kim Hakim is joined by Jessica Couto, VP of Channels & Alliances at Harmonic Security, for an in-depth conversation on Securing Intelligence: AI’s Impact on Cyber Risk. Together, they explore how generative AI has rapidly shifted from a productivity tool to a new source of organizational risk—and why blocking AI outright is no longer a viable strategy. Jessica shares real-world insights on how employees are using AI both inside and outside corporate environments, the growing risks of data exposure, phishing, deepfakes, and shadow AI usage, and what security leaders must do to regain visibility and control. The discussion also covers how organizations can safely enable AI without sacrificing productivity, the evolving role of the CISO, the rise of fractional CISOs, and how security teams can communicate AI risk in business terms that resonate with leadership. Topics include: How AI is changing the cyber threat landscape Why blocking generative AI puts organizations at risk of falling behind Data leakage, shadow AI, and employee behavior Deepfakes, phishing, and AI-driven social engineering AI governance, visibility, and policy challenges The future of the CISO role and cybersecurity careers This episode is a must-listen for CISOs, security leaders, IT professionals, and anyone navigating the fast-changing intersection of AI, cyber risk, governance, and workforce impact.

  • Nov 25, 2025 · 45 min

    Inside The Lion’s Den: Part 2

    In this follow-up episode, guest host Jonathan Kimmitt sits down again with Matthew Maynard, Security Operations Specialist at BJC HealthCare and Dark Web Researcher, to take an even deeper dive into the inner workings of ransomware crews and the people behind them. Matthew takes listeners deeper into the “lion’s den,” revealing what he has learned from directly engaging with threat actors on the dark web—how they think, how they operate, and why the human element inside these criminal ecosystems matters more than most organizations realize. In this episode, they break down: What motivated Matthew to enter ransomware intelligence and begin infiltrating criminal groups How ransomware crews recruit, organize, and operate like legitimate businesses Key differences between the clear web and dark web, and common misconceptions Essential OPSEC practices and how both researchers and criminals protect their identities How personas are created and maintained when engaging directly with threat actors Human drivers of cybercrime—from financial incentive to desperation and coercion Insider risks, layoffs, and how human vulnerability contributes to modern breaches Major intelligence wins and insights that help organizations make stronger security decisions This episode offers rare, firsthand insight into the techniques, mindset, and operational flow of active cybercriminals—paired with practical guidance for defenders. Whether you’re in security leadership, incident response, threat intel, or simply curious about the dark web, this conversation will challenge your assumptions and expand your understanding of today’s most dangerous threats. Listen now and hear why knowing your adversary is one of the most powerful defenses in cybersecurity.

  • Nov 18, 2025 · 43 min

    Inside The Lion’s Den: Infiltrating Ransomware Groups

    In this eye-opening episode of And Security For All, host Kim Hakim sits down with Matthew Maynard, Information Security Operations Specialist at BJC HealthCare and dark web researcher who has spent the last year doing the unthinkable—infiltrating active ransomware groups from the inside. Matthew shares how he entered closed cybercriminal communities, built trust, gathered intelligence, and passed critical findings to government agencies—all while maintaining a full-time role protecting one of the largest healthcare systems in the Midwest. His research provides a rare, real-time window into ransomware crews, their structure, their onboarding process, their business platforms, and the tactics they use to select, study, and strike their victims. What You’ll Learn in This Episode How ransomware groups actually operate behind closed doors What “initial access brokers” are and why they’re the real first step in most attacks How threat actors select targets, test stolen credentials, and prepare for exploitation Why holidays and long weekends remain prime attack windows What defenders consistently overlook—and the fixes that matter most How Matthew manages OPSEC, safety, and reporting while undercover Why MFA gaps, vendor access, phishing, and unpatched systems remain the top entry points The surprising internal rules, ethics, and boundaries some threat groups enforce How organizations should rethink backups, insurance, and negotiating ransom demands Matthew also discusses the psychological side of this work—the fear, the risk, and the personal motivation that keeps him in the fight. His insights provide actionable takeaways for CISOs, SOC teams, and anyone responsible for protecting an enterprise today. This is a rare interview with someone who has seen ransomware operations from the inside. It’s a conversation every cybersecurity leader should hear.

  • Nov 12, 2025 · 45 min

    SOTI Fraud & Abuse Report: Charting a Course Through AI’s Murky Waters

    In this episode of And Security For All, guest host Steve Winterfeld, Advisory CISO at Akamai Technologies, teams up with Tricia Howard, Security Evangelist and “Scrybe of Cybersecurity Magicks,” to unpack Akamai’s State of the Internet: Fraud & Abuse Report 2025. They explore how AI-driven bots are reshaping the landscape of digital fraud—surging over 300% in the past year—and what that means for businesses, defenders, and everyday users. From ad fraud and data scraping to compliance challenges and the ethics of AI, this conversation dives deep into the tension between innovation and exploitation in cybersecurity. Listen as Steve and Tricia discuss: The explosive growth of AI bots and their impact on digital operations Ad fraud, zero-click searches, and the dark economy of stolen data Why healthcare and commerce are prime targets for automated attacks The evolving balance between compliance, risk, and real security How organizations can defend against this new wave of AI-powered fraud With insights from Akamai’s global research team, this episode offers a grounded look at how to navigate the rise of generative AI, protect brand integrity, and build trust in a rapidly changing threat environment.

Showing 21–27 of 27 episodes