Skip to content
Artwork for Byte Sized Security
TechnologyBusinessEntrepreneurshipNewsBusiness News

Byte Sized Security

Marc David

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go.

Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more.

Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out.

Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.

Play
  • 20 episodes
  • Avg 8 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

  • S1 · E47
    Yesterday · 9 min

    Ep47: Why AI Risks Are Different

    Episode Summary: Someone told Marc that AI panic is nothing new — just the printing press or nuclear weapons all over again. He disagreed, and it turns out there was a report to back it up. In this episode he breaks down why AI collapses the cost of dangerous capability in a way the printing press, the internet, and even nuclear weapons never did, what Anthropic's brand-new September 2026 threat intelligence report documents, where his own "$200 expert" framing overstated the case, and the four guardrails that would close the gap. Key Topics Covered: The argument that started this episode — a debate about whether AI panic is history repeating, and the report Marc found three days later making his case for him Why the printing press comparison breaks down — institutions had a century (and decades, for the internet) to catch up; AI's capability curve moves in months What's actually different about nuclear weapons — nuclear risk lives behind physical choke points: materials, facilities, expertise. AI risk lives in a skill, and skills can't be fenced off Anthropic's report: the receipts — three disrupted operations, walked through case by case, that turn the argument from speculative to documented Does AI make anyone an expert? Not exactly — Marc's own "$200 subscription = expert" line, and the more defensible version of the claim Attackers, defenders, and who adapts faster — the same models cutting attacker costs are cutting defender costs too, and why that race matters What real AI guardrails would look like — four concrete guardrails: pre/post-release capability testing, enforceable standards, international coordination, and risk-scaled access Main Takeaways: AI doesn't need generations to reach scale like the printing press or the internet did — model capability jumps happen every few months, not every few decades Nuclear risk is contained by physical choke points (fissile material, facilities, expertise); AI risk lives in a skill, and skills don't have a border to fence Anthropic's September 2026 report documents real, disrupted operations — including a breach that went from one stolen developer token to full cloud admin control in roughly three hours "$200 subscription = expert" overstates it: AI doesn't manufacture expertise, it lowers the skill required to attempt tasks whose consequences the operator isn't trained to handle Defenders get the same acceleration attackers do — the organizations lagging on AI-assisted defense are the ones absorbing the most risk Closing the gap takes four things: pre/post-release capability testing, enforceable (not voluntary) standards, international coordination, and access that scales with risk instead of price Timestamps: [0:00] The argument behind this episode [1:03] Why the printing press comparison breaks down [1:53] What's different about nuclear weapons [2:55] Anthropic's report: the receipts [4:46] Does AI make anyone an expert? Not exactly [5:45] Attackers, defenders, and who adapts faster [6:16] What real AI guardrails would look like Tools & Resources Mentioned: Anthropic: Detecting and Countering Misuse of AI (September 2026) NIST AI Risk Management Framework EU AI Act (European Commission) Full written guide: Why AI Risks Are Different AI is fueling the cybersecurity career boom Why an AI agent shouldn't inherit your permissions Not legal advice. Figures reflect Anthropic's report as published on September 10, 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E46
    September 10 · 9 min

    Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

    Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview. In this episode: (00:00) The scan report that isn't as urgent as it looks (01:03) The 98.5% number and the mechanic analogy (02:01) Why the industry defaulted to patch everything (03:00) The 36-hour outage from a perfect-10 patch (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data (05:08) What it sounds like when someone understands this in an interview (06:15) Why the industry has no brakes, and the AI-hype myth (07:49) Your homework Links: Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing" CISA's Known Exploited Vulnerabilities (KEV) catalog FIRST.org, the CVSS specification Full written breakdown Our cybersecurity career guide Breaking into cybersecurity with no experience Third-party risk and the AI bug-report flood Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode. I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E45
    July 28 · 10 min

    Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

    Episode Summary: Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme. Key Topics Covered: What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who fails Can you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offense How corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%) "Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc lands Accountability without a blame culture — four principles for getting Binance's seriousness without the fear The boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns Main Takeaways: You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone owned Punishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incident The metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudly Humans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the person Fair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report Timestamps: [0:00] The gotcha that shows up on your performance review [1:03] What Binance's red team is actually doing [2:23] Can you really get fired? Three strikes and the Krebs debate [3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder [5:03] "Weakest link"? The industry split, and where we land [6:55] Accountability without a blame culture: four principles [8:19] The boring middle thing that actually works Tools & Resources Mentioned: Binance runs monthly phishing tests (crypto.news) Repeated failures may lead to dismissal (WEEX) Addressing the repeat phishing offender (IT Brew) "Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019) What to do (and not do) when employees click (Hook Security) What's a good phishing failure rate? (Hoxhunt benchmarks) KnowBe4 phishing security test Proofpoint phishing simulation Microsoft Defender attack simulation training Full written article: Fired for failing a phishing test? Why modern phishing beats smart people Why employee security awareness training matters General education, not legal or HR advice. Reporting reflects coverage as of July 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E44
    July 22 · 9 min

    Ep44: California's DROP Tool: Delete Yourself From Data Brokers in One Free Request

    Episode Summary: California just made deleting yourself from data brokers a single free request. In this episode Marc breaks down the state's new DROP tool: what it deletes, how to file it in a few minutes, why August 1, 2026 is the date that matters, and the three things it won't fix. If you're a California resident, this is a free privacy win you shouldn't skip. If you're not, he covers what to do instead. Key Topics Covered: What DROP is — California's Delete Request and Opt-out Platform, and where the 614 data broker number comes from How it works — one free request, and what it actually deletes across registered brokers Filing it step by step — a few minutes of work, plus the scam to watch out for The August 1, 2026 deadline — why that's the date brokers have to start honoring requests The honest limits — what DROP won't fix: Google, Meta, and brokers that re-collect your data Not in California? — the moves that get you similar protection without DROP Main Takeaways: DROP lets California residents delete themselves from every registered data broker (614 and counting) with a single free request — no per-broker opt-outs August 1, 2026 is the date that matters: that's when brokers must start honoring DROP deletion requests It's not a silver bullet — it won't remove you from Google or Meta, and brokers can re-collect your data over time, so treat it as maintenance, not a one-and-done Watch for the scam: the only official place to file is the state's own site — don't pay a third party to do what's free Not a California resident? Freeze your credit and use manual opt-outs or a removal service to get similar coverage Timestamps: [0:00] The 12-broker breaking point [1:10] What DROP is and where the 614 number comes from [2:05] How it works and what it actually deletes [3:40] Filing it step by step, plus the scam to avoid [4:46] Why August 1, 2026 is the deadline [5:19] The honest limits: Google, Meta, and recurring brokers [6:51] Not in California? Do this instead Tools & Resources Mentioned: File a DROP request (official) California Privacy Protection Agency California Delete Act (SB 362) EFF: What You Need to Know About California's DROP Tool Full written guide: California's DROP tool & data broker opt-out How consent laundering moves your data Remove your personal info from the internet Credit freezes & identity protection Not legal advice. Details reflect the tool as of July 2026; enforcement begins August 1, 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E43
    June 1 · 11 min

    Ep43: The Best Personality Traits for Working in Cybersecurity

    Episode Summary: A Reddit thread on r/cybersecurity asked a simple question: what's the best personality trait for working in cyber? The answers — with hundreds of upvotes — weren't about hacking or certifications. They were about curiosity, patience, humility, staying calm under pressure, and empathy. Marc walks through each trait with personal stories from 8+ years of building teams, hiring, and working incidents at 2 AM. Key Topics Covered: Curiosity — the #1 answer by a wide margin; the trait that makes you dig into a log line everyone else shrugs off Patience — explaining technical risk to non-technical people without making them feel stupid, because if you do, they stop reporting incidents Humility — saying "I don't know, but I'll figure it out" beats bluffing every time; ego is the worst trait in the field Calm under pressure — incident response at 2 AM, zero-days on Friday afternoons, breaches that keep growing; staying focused when everything is on fire matters more than any cert Empathy and kindness — cybersecurity is a people problem wrapped in a technology problem; being technically right doesn't matter if nobody wants to work with you The uncomfortable truth — ADHD, burnout, trauma-induced hypervigilance; the always-on mindset is a strength until it isn't Main Takeaways: Technical skills are trainable — tools, frameworks, scripting languages, detection logic are all learnable, especially with AI Soft traits like curiosity, patience, and empathy are harder to develop and are what separate people everyone wants on their team from people nobody wants to work with If you're thinking about getting into cybersecurity, don't ask "am I technical enough?" — ask "am I curious enough to keep learning?" The best cybersecurity professionals aren't the ones who sprint the hardest — they're the ones still there in five years Timestamps: [0:00] Introduction — the Reddit thread that started it all [0:58] Curiosity — the #1 answer and why it matters [2:41] Patience — the art of explaining things without condescension [3:58] Humility — why "I don't know" is a superpower [5:15] Calm under pressure — the difference between a skill and a warning sign [6:28] Empathy and kindness — the most surprising and important trait [7:49] The uncomfortable part — burnout, ADHD, and mental health in cyber [9:11] Final thoughts — what really separates the best from the rest Tools & Resources Mentioned: Reddit Thread: Best Personality Type/Traits for Working in Cyber --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E42
    Jul 5, 2025 · 6 min

    Ep42: Three Privacy Actions You Need Today

    # Byte Sized Security Show Notes ## Episode Title: 3 Immediate Actions to Protect Your Privacy Today ## Episode Summary: In this episode of Byte Sized Security, host Marc David outlines three practical, actionable steps to enhance your privacy protection immediately. With data breaches nearly doubling in 2024 and companies like AT&T and Ticketmaster experiencing massive exposures, these privacy protection measures aren't just theoretical—they're essential defenses against real threats. ## Key Discussion Points: * The alarming state of data breaches in 2024: 10,626 confirmed breaches, nearly double from previous year * Major breaches highlighted: AT&T (73M records), Ticketmaster (560M users), National Public Data (2.9B records) * The average breach costs $4.88 million, or $165 per stolen record * **Step 1**: Enable two-factor authentication everywhere * 2FA stops 99.9% of automated attacks * Use authentication apps instead of SMS * Save backup codes in a safe place * **Step 2**: Audit your privacy settings * Detailed walkthrough for Facebook, Instagram, Twitter/X, and LinkedIn * Phone settings review for both iOS and Android * Revoking unnecessary app permissions * **Step 3**: Protect your connection and digital footprint * Using a VPN to encrypt connections and mask browsing * Reviewing and cleaning your digital footprint * Opting out of data broker sites * Deleting old, unused accounts * The importance of ongoing privacy maintenance ## Tools and Resources Mentioned: * **Authentication Apps:** * [Google Authenticator](https://googleauthenticator.net/) * [Authy](https://authy.com/) * **Recommended VPN Services:** * [NordVPN](https://nordvpn.com/) * [ExpressVPN](https://www.expressvpn.com/) * [Surfshark](https://surfshark.com/) * **Data Broker Removal Services:** * [DeleteMe](https://joindeleteme.com/) * [Privacy Bee](https://privacybee.com/) * [Optery](https://optery.com/) * **Data Broker Sites to Opt Out From:** * [Whitepages](https://www.whitepages.com/) * [PeopleFinder](https://www.peoplefinder.com/) * [Spokeo](https://www.spokeo.com/)

  • S1 · E41
    Jul 3, 2025 · 3 min

    Ep:41 Beware: Your Top VPN App May Be a Chinese Government Spy

    Episode Summary: In this episode, we explore the alarming discovery that many of the top-rated VPN apps on the App Store and Google Play are secretly owned by Chinese companies. These VPNs pose a serious risk to user privacy and security, as Chinese law requires them to hand over all user data to the government without justification. Key Topics Covered: - Chinese-owned VPN apps masquerading as legitimate services - Lack of transparency and disclosure around company ownership - Risks of user data being accessed by the Chinese government - Failure of app stores to properly vet and regulate these VPN apps - Importance of researching VPN providers before using them Main Takeaways: - Many popular VPN apps are secretly owned by Chinese companies, creating a significant risk to user privacy and security. - App stores like the App Store and Google Play are not properly vetting and regulating these potentially compromised VPN apps. - Users must do their own research to ensure the VPN they are using is trustworthy and not owned by a company with ties to the Chinese government. Timestamps for Major Topics: - 0:00 - Introduction to the issue of Chinese-owned VPN apps - 1:30 - Examples of top-ranked VPN apps with hidden Chinese ownership - 3:00 - Explanation of the legal requirements for Chinese companies to hand over user data - 4:30 - Lack of action by app stores to remove or label these problematic VPN apps - 6:00 - Importance of user research and caution when selecting a VPN provider --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E40
    May 30, 2025 · 4 min

    Ep40: The AI Layoff Apocalypse Has Already Started — And You’re Next

    The Imminent AI Job Crisis: Are You Prepared? This episode highlights the alarming prediction by Dario Amodei, CEO of Anthropic, that AI could eliminate half of all entry-level white-collar jobs within the next one to five years, potentially raising U.S. unemployment to 20%. While major companies are quietly adopting advanced AI systems, the public and lawmakers remain largely unaware or in disbelief. The episode discusses the impacts of AI on various industries and jobs, stressing the need for urgent action such as an AI 'token tax,' real-time job replacement tracking, legislative briefings, and worker reskilling programs. The message is clear: the AI job crash is imminent, and proactive measures are essential to mitigate its effects. 00:00 The Impending Disappearance of White-Collar Jobs 00:37 Real-World Examples of AI-Induced Job Cuts 01:03 The Rise of AI Agents in the Workplace 01:30 The Alarming Capabilities of Advanced AI 01:48 Public Response and the Threat to Democracy 02:32 Proposed Solutions to the AI Job Crisis 02:57 The Urgency of Immediate Action 03:06 Conclusion: Preparing for the AI Job Crash --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Behind the Curtain: A white-collar bloodbath -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E39
    May 27, 2025 · 2 min

    Ep39: AI in the Workplace: Adapt or Be Replaced

    Adapt or Replace: How AI is Changing Entry-Level Job Markets AI has already impacted the job market significantly, particularly affecting entry-level positions. The script highlights that entry-level hiring has decreased due to the integration of AI, which automates routine tasks. Companies are reconsidering traditional roles and opting for more efficient AI solutions. Job seekers are faced with two choices: compete against AI or learn to leverage it to improve productivity. The script emphasizes the importance of mastering AI tools to stay relevant in the workforce and outlines steps to integrate AI proficiency into daily routines and resumes. 00:00 AI Isn't Coming for Your Job 00:02 The Impact of AI on Entry-Level Jobs 00:18 Automation and Workflow Changes 00:39 Adapting to the AI Revolution 00:46 The Future of Work: Competing with AI 01:07 Embracing AI Tools for Success 01:15 The Consequences of Ignoring AI 01:31 Final Thoughts: Adapt or Be Replaced --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E37
    May 19, 2025 · 3 min

    Ep37: Deepfakes and Digital Deception: The 2025 Threat

    **Episode Summary:** Marc David dives into the rapidly evolving world of deepfakes and digital deception, projecting forward to 2025. The episode explores the alarming growth in deepfake use, driven by accessible AI technology and user-friendly tools. Mark discusses the severe consequences for businesses (e.g., fraudulent CEO announcements, financial scams like the Polish bank incident), politics (e.g., election manipulation), and personal lives. The discussion also covers emerging solutions, including AI-powered detection tools like those from MIT's DeepTrace Lab, the role of regulations like GDPR, and practical steps listeners can take, such as using verification software like Truepic. The core message is the importance of vigilance and questioning the authenticity of digital content. **Key Discussion Points:** * **The Explosion of Deepfake Use (00:21):** * A 900% increase in deepfake videos was found by Sensity researchers in 2021. * The problem is projected to have quadrupled by 2025. * **Drivers of the Deepfake Surge (00:35):** * Accessible and user-friendly AI technology. * Cheaper software accelerating spread. * **Impact on Businesses (00:48):** * Potential for CEO deepfakes to announce fraudulent mergers or layoffs. * Real-world example: A Polish bank lost millions in 2023 due to a deepfake scam involving an urgent fake call to redirect funds. * **Impact on Politics (01:10):** * Deepfakes manipulating elections (e.g., doctored videos of candidates). * Erosion of voter trust. * **Current Preparedness & Solutions (01:21):** * We are not yet fully equipped, but solutions are evolving. * **Detection Tools (01:25):** AI systems learning to recognize deepfakes by detecting minute digital artifacts. * MIT's DeepTrace Lab: Provides tools analyzing AI generation flaws. * **Policy and Regulations (01:42):** * Europe's GDPR now covers AI-generated media. * The US is considering similar steps. * **What You Can Do (01:52):** * Stay informed. * Report suspicious content. * Support legislative actions against deepfakes. * Use available verification tools. * **Today's Takeaway (02:04):** * Be vigilant. * Question authenticity until trust is verifiable. **Tools & Sites Mentioned:** * **Sensity:** (Research mentioned from 2021 regarding the 900% increase in deepfake videos). Sensity was an AI threat intelligence company, later acquired. The research highlighted the scale of the problem. * **MIT DeepTrace Lab:** A research initiative at MIT focusing on detecting deepfakes and manipulated media. * Website: [https://deeptrace.csail.mit.edu/](https://deeptrace.csail.mit.edu/) * **GDPR (General Data Protection Regulation):** Europe's privacy and data protection law, now addressing AI-generated media. * Official Information: [https://gdpr-info.eu/](https://gdpr-info.eu/) * **Truepic:** A company offering photo and video verification technology. * Website: [https://truepic.com/](https://truepic.com/) ------ I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  • S1 · E36
    Feb 3, 2025 · 21 min

    Ep36: DeepSeek AI – The Real Issue Isn't China, It’s AI Security

    AI Security and Competition: Unpacking the Debate Around DeepSeek This episode delves into the controversy surrounding DeepSeek, a Chinese AI considered by some as a national security threat. It questions whether this stance is legitimate or merely a tactic by big tech to stifle competition. The episode highlights multiple security breaches across the AI industry, including OpenAI and Google, arguing that the core issue lies in how AI handles security rather than its origin. The discussion also explores the suspicious uniformity in the anti-DeepSeek narrative, the potential motivations of big AI corporations to maintain monopolies, and the necessity of reading AI privacy policies. Additionally, the episode critiques the U.S. response to AI competition, drawing parallels to historical moments like the Sputnik era, and advocates for stronger AI security regulations and more open-source innovation. Listeners are encouraged to reflect on whether the fear of DeepSeek is justified or manipulated by big tech interests. 00:00 Introduction: The DeepSeek Controversy 00:08 Data Leaks: A Global Issue 00:39 The Suspicious Narrative Against DeepSeek 01:24 Big AI's Fear of Open Source 01:35 Smart AI Usage Tips 02:29 The Real Issue: AI Governance 03:15 The AI Moat Playbook 04:08 Big Tech's Control Over AI 05:49 The Global AI Competition 09:45 Security and Privacy Concerns 17:22 Conclusion: The Future of AI --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode DeepSeek Privacy Policy - The DeekSeek Privacy Policy -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E35
    Jan 14, 2025 · 3 min

    Ep35: So TikTok might manipulate Americans?

    The Double Standards of Social Media Manipulation: Facebook vs. TikTok This episode delves into the contrasting treatment of Facebook and TikTok concerning data manipulation and national security. It highlights the documented case of Facebook's data misuse with Cambridge Analytica, affecting 87 million Americans, and questions why similar scrutiny isn't applied to domestic companies. The script challenges the narrative around TikTok's possible threats, urging viewers to consider the double standards in regulatory actions against social media manipulation. 00:00 Introduction: The Manipulation Debate 00:02 The Facebook-Cambridge Analytica Scandal 00:43 The Double Standards in Social Media Manipulation 01:02 Questioning the Real Threat 01:30 Conclusion: Addressing Double Standards --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E34
    Jan 13, 2025 · 2 min

    Ep34: They say TikTok is dangerous... but look who's talking

    The Real Threat of TikTok: Manipulation by Any Owner The video discusses the controversy surrounding TikTok and the calls to ban it due to national security concerns. It questions the hypocrisy of other social media giants like Facebook and Twitter (now X) which have also manipulated users for profit. The script emphasizes that the issue isn't the country that owns TikTok, but rather the potential for manipulation by any corporation. The discussion highlights that banning social media isn't the solution and points out that corporate greed remains the true threat, affecting trust in these platforms. 00:00 Introduction: The TikTok Controversy 00:16 The Hypocrisy of Social Media Giants 00:44 The Real Question: Who Controls TikTok? 01:01 Conclusion: The True Threat of Manipulation --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Cambridge Analytica - Wikipedia -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E33
    Nov 6, 2024 · 4 min

    Ep33: Do you really need to know Python or coding to be a great cybersecurity engineer?

    Do You Need Coding Skills to Succeed as a Security Engineer? In this episode, we debunk the myth that coding expertise, particularly in Python, is essential for success in cybersecurity engineering. While many claim that coding skills are a gatekeeper in this field, the reality showcases a wide array of roles such as governance, risk and compliance (GRC), security awareness, and SOC analysis, which do not require deep coding knowledge. The ability to write simple, logical instructions can be helpful, especially in application security or cloud engineering roles. However, mastering core cybersecurity skills like threat modeling, vulnerability assessment, and incident response often has a greater impact. Additionally, AI tools are making coding tasks more accessible. We encourage you to focus on the skills that matter most for your desired cybersecurity role and not be deterred by the myth of mandatory coding expertise. 00:00 Introduction: Do You Need to Know Python for Cybersecurity? 00:06 Debunking the Coding Myth in Cybersecurity 00:26 The Role of Coding in Specific Security Roles 00:59 Core Skills Beyond Coding 01:07 Non-Coding Roles in Cybersecurity 01:34 The Impact of AI on Coding in Cybersecurity 02:12 Essential Skills for Cybersecurity Professionals 02:38 Encouragement for Aspiring Security Engineers --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E32
    Oct 30, 2024 · 7 min

    Ep32: Cybersecruity is more than learning how to code

    Dismantling Gatekeeping in Cybersecurity: Embracing Diverse Talents The episode discusses the need to move beyond gatekeeping in cybersecurity, which often prioritizes coding skills over diverse talents. It highlights the importance of embracing individuals who have strategic vision, risk management expertise, and effective communication abilities, even if they lack programming experience. The host argues that cybersecurity is a complex, multidisciplinary field that requires diverse teams to solve its challenges. The episode calls on hiring managers and leaders to recognize and nurture a variety of skills within their teams, aiming to dismantle barriers and create more inclusive opportunities in cybersecurity. 00:00 The Importance of Diverse Talents in Cybersecurity 00:06 The Problem with Gatekeeping Based on Coding Skills 00:24 A Story of Overlooked Talent 01:11 The Need for Visionaries and Strategists 01:38 The Human Aspect of Cybersecurity 02:35 The Power of Effective Communication 03:40 Encouraging Diverse Skillsets in Hiring 04:06 Broadening Skills Beyond Coding 04:31 A Message to Aspiring Cybersecurity Professionals 05:00 The Future of Cybersecurity 05:40 A Call to Action for the Cybersecurity Community --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E31
    Oct 29, 2024 · 7 min

    Ep31: How I turned Claude AI into a career coach and got 3 job offers in 2 weeks

    Tailoring Your Resume with AI: My Honest Experience with Claude We're diving into the often daunting task of tailoring resumes for specific jobs and how an AI tool, Claude, made this process significantly easier. The presenter shares a detailed, step-by-step account of their experience using Claude to enhance their resume, highlighting the tool's deep analysis, actionable feedback, and authentic improvement suggestions. They discuss the importance of presenting one's true skills and value in a competitive job market while emphasizing that quality and customization in job applications matter more than quantity. The episode wraps up by encouraging viewers to be genuine, strategic, and thoughtful in their job search efforts. 00:00 Introduction: The Dreaded Resume Tailoring 00:38 Discovering Claude AI: A Game Changer 01:22 How Claude AI Works: Step-by-Step Guide 02:15 Real-World Application: Matching Job Descriptions 03:04 Addressing the Experience Gap with Confidence 04:27 The Importance of Authenticity in Job Applications 05:20 Final Thoughts and Practical Advice --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Claude - Your Career Coach - My step by step experience using Claude Projects as a Career Coach -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E30
    Sep 19, 2024 · 15 min

    Ep:30 Practical Cybersecruity Advice You Can Use

    The source is an audio recording of a podcast episode focused on providing advice for those seeking to enter the cybersecurity field. The host, Marc, offers insights on acquiring practical experience, the importance of certifications, the significance of soft skills, strategies for successful job interviews, and effective networking methods. He emphasizes the importance of tailoring resumes to showcase relevant skills and using networking events to connect with industry professionals. He also shares his own personal experience with job hunting and rejection, encouraging listeners to persevere despite setbacks and to continuously improve their job application materials. --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E29
    Aug 29, 2024 · 22 min

    Ep29: Hack Your Career: Insider Tips for Cybersecurity Beginners

    Navigating Cybersecurity: Q&A Session with Marc In this special episode recorded outdoors, Marc answers listener questions about breaking into the cybersecurity field. Topics include gaining practical experience without an IT background, the importance of certifications, essential soft skills, networking strategies, handling job rejections, and making a career transition into cybersecurity. Marc provides practical advice on how to stand out in interviews, tailor your resume, and continuously improve your chances of landing a cybersecurity job. Resources and contact information are available in the show notes. 00:00 Introduction and Format Change 00:29 Question 1: Gaining Practical Experience in Cybersecurity 03:31 Question 2: Importance of Certifications 06:46 Question 3: Crucial Soft Skills 09:26 Question 4: Standing Out in Job Interviews 12:33 Question 5: Networking in Cybersecurity 15:59 Question 6: Handling Rejection and Improving Applications 22:35 Conclusion and Final Thoughts --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources, including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Cybersecurity Conferences - Our cybersecurity conference directory is meticulously updated and checked manually to prevent spam, ensuring it remains the community’s premier resource for discovering top cybersecurity conferences, events, meetings, and seminars for 2024, 2025, and beyond. The Hire Drive Podcast Series - Apple Podcasts Zero to Hired: Job Hunting in the AI Age - "Zero to Hired: Job Hunting in the AI Age" demystifies the complex world of job searching and hiring practices, providing job seekers with a comprehensive step-by-step guide to leverage artificial intelligence and modern digital tools to land their dream job. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E28
    Aug 27, 2024 · 17 min

    Ep28: How to Delete Your Data from the Internet

    Safeguarding Your Identity: Essential Tools and Techniques This episode focuses on the increasing dangers of data breaches and the various steps individuals can take to protect their personal information. Highlighting the threats posed by data breaches and data brokers, the discussion provides detailed reviews of free resources such as OperationPrivacy.com and Google’s 'Results About You' feature. These tools help users remove their data from major brokers and search engines. Additionally, the episode covers the importance and process of freezing your credit to prevent identity theft, emphasizing the use of password managers and two-factor authentication (2FA) for enhanced security. 00:00 Introduction: The Reality of Data Breaches 00:22 Understanding the Risks: How Your Data is Compromised 01:29 Adopting a Breach Mentality: Protecting Your Information 02:27 Operation Privacy: A Free Tool for Data Removal 06:41 Google Results About You: Managing Your Online Presence 10:15 Freezing Your Credit: An Essential Step 13:34 Conclusion: Taking Control of Your Data Security --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Google Take Controls of Results About You Operation Privacy -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    • Transcript
  • S1 · E27
    Aug 5, 2024 · 4 min

    Ep:27 The Great IT vs. Security Smackdown: A Comedy in Three Acts

    The Great IT vs. Security Smackdown: A Comedy in Three Acts In this hilarious and eye-opening episode of ByteSizedSecurity, we're flipping the script on the age-old IT vs. Security debate. Prepare for a rollercoaster ride through the corporate tech landscape as we challenge the notion that security is just IT's sidekick. From debunking myths to exposing organizational chart failures, this episode serves up hard truths with a side of laughter. Whether you're an IT pro, a security guru, or just someone who enjoys a good tech tussle, tune in for a fresh perspective on why security should be in the driver's seat. Warning: This episode may cause uncontrollable giggles and a sudden urge to redesign your company's org chart! Keywords: IT, Security, Cybersecurity, Corporate Structure, CIA Triad, CISO, CIO, Tech Humor

    • Transcript
Showing 1–20 of 20 episodes