Skip to content
Artwork for Cyber Threat Intelligence Podcast

Cyber Threat Intelligence Podcast

Pedro Kertzman

Welcome to the Cyber Threat Intelligence Podcast—your go-to source for staying ahead in the ever-evolving world of cybersecurity by harnessing the full potential of CTI.


In each episode, we dive into the latest cyber threats, emerging trends, best practices, and real-world experiences—all centered around how CTI can help us defend against cybercrime.


Whether you’re a seasoned CTI analyst, a CTI leader, or simply curious about the digital battlefield, our expert guests and host break down complex topics into actionable insights. From ransomware attacks and insider threats to geopolitical cyber risks and AI-driven security solutions, we cover all things CTI.


Join us for in-depth interviews with industry leaders and experienced professionals in the Cyber Threat Intelligence space. If, like me, you’re always in learning mode—seeking to understand today’s threats, anticipate tomorrow’s, and stay ahead of adversaries—this podcast is your essential companion.


Stay informed. Stay vigilant. Tune in to the Cyber Threat Intelligence Podcast.

Play
  • 22 episodes
  • fortnightly
  • Avg 33 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S2 · E12
    Yesterday · 37 min

    Mindset Deepens Technical CTI Skills (Cat Self & Pedro Kertzman)

    Imposter syndrome shows up in Cyber Threat Intelligence like clockwork, but we do not let it run the room. Cat Self, Senior Director of Adversary Research at Tidal Cyber, joins me to get practical about what actually helps CTI analysts perform: turning open source intelligence and vendor reporting into actionable intelligence your org can use, even if you do not have a massive telemetry stack or a dedicated reverse engineering team. We dig into the real problem with OSINT: noise that looks like signal. When six write-ups trace back to the same original report, repetition can feel like validation, and marketing content can drown out what matters. Cat shares how she filters for credibility by tracking specific authors and expertise areas, building a short list of sources she trusts, and keeping accountability front and center when publishing anything under her name. If you rely on MITRE ATT&CK mappings, threat actor reporting, or rapid intel notes for detection engineering, this part will sharpen your sourcing instincts. We also tackle AI in CTI without the hype. AI can help reduce the haystack, but it is still “rearview” and cannot replace judgment. Cat walks through lessons from building an intelligence pipeline with “vibe coding,” why debugging AI can be chaotic, and how guardrails and human agency keep automation useful instead of risky. Then we shift into analyst mindset: small role-play exercises, making intelligence fun, and creating psychological safety so teams learn faster and burn out less. References: Batman Effect: https://academic.oup.com/chidev/article/88/5/1563/82578 Lego Study: https://cms.learningthroughplay.com/media/wmtlmbe0/learning-through-play_web.pdf Problem solve improvement: https://tu-dresden.de/mn/psychologie/ifap/allgpsy/ressourcen/dateien/lehre/lehreveranstaltungen/bolte_lehre/ala/Isen_1987.pdf?lang=en Subscribe for more cyber threat intelligence conversations, share this with a teammate who lives in OSINT, and leave a review so more analysts can find the show. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E11
    August 18 · 38 min

    OT Risk Without The Guesswork - Episode 11 (Andrew Ginter & Pedro Kertzman)

    A lot of cybersecurity advice falls apart the moment the “asset” is a turbine, a boiler, a rail system, or a water plant. We sit down with Andrew Ginter, VP of Industrial Security at Waterfall Security Solutions and author of multiple OT cybersecurity books, to get practical about what actually matters in operational technology security: understanding how attacks work, where they enter, and what they can do in the physical world. We unpack why many OT programs struggle when they inherit IT-first language and assumptions. In critical infrastructure, the priorities are often safety, reliability, and efficiency not just protecting information. Andrew explains the shift from treating information as the asset to treating attack information as the threat, and why mapping “consequence boundaries” and information flows can reveal the most important attack vectors. We also talk about pivoting attacks, residual cyber risk, and how to think like an engineer when the worst credible consequence is simply unacceptable. For CTI teams and security leaders trying to brief executives, we explore a better way to communicate risk than likelihood times impact. High-end adversaries are not random, so Andrew advocates framing board conversations around credibility and reasonableness: what is reasonable to believe about intent, capability, and opportunity, and what defenses are reasonable given legal and business obligations. We close with a hard look at the next step change AI-driven zero-days and why cyber-informed engineering and resilience, including deterministic safeguards, will matter more than ever. Subscribe for more practical CTI and OT security conversations, share this with a teammate who briefs leadership, and leave a review to help others find the show. https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/engineering-grade-ot-security-a-managers-guide/ Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E10
    July 17 · 28 min

    How To Turn Stakeholder Needs Into Actionable Threat Intelligence (Marcelle Lee & Pedro Kertzman)

    Most threat intel programs don’t fail because analysts can’t research. They fail because the intelligence isn’t built for a real audience. We sit down with Marcelle Lee, CEO and founder of Fractal Security Group, to get brutally practical about stakeholder-driven cyber threat intelligence and how to turn priority intelligence requirements (PIRs) into outputs people actually use. We talk through what stakeholder interviews look like in the private sector, why a simple questionnaire beats guessing, and how “they know cyber” still doesn’t mean they understand what CTI can deliver. Marcelle shares how to explain CTI deliverables clearly, how to handle vague requests, and why embedding into team cadence meetings builds trust faster than one-off check-ins. We also dig into MSSP realities: serving many clients, curating emerging threats for broad relevance, and keeping reporting digestible without losing the technical substance that security teams need. We close with how to tailor threat intelligence products for very different audiences, from SOC and detection engineering to executives and boards, where business impact matters more than indicators of compromise. You’ll also hear concrete examples of CTI supporting red team and purple team exercises, security awareness training, risk calculations, PR and marketing monitoring, and phishing-focused guidance for HR and finance. Subscribe, share the episode with a CTI teammate, and leave a review. Then join our LinkedIn group, Cyber Threat Intelligence Podcast, and tell us which stakeholder group you struggle to serve most. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E9
    June 23 · 16 min

    Building Cyber Threat Intelligence In Government (Liam Ryan & Pedro Kertzman)

    Your CTI program can publish reports all day and still fail one basic test: does it change what anyone does next? That question drives our conversation with Liam, a cyber threat intelligence analyst supporting the Government of Alberta and the Cyber Alberta community, where “relevance” is not theoretical, it is local, proximate, and tied to real incidents across the province. We get specific about what it takes to build and mature a public sector cyber threat intelligence function from the early days: governance, executive support, a clear mandate, and intelligence requirements that stop CTI from becoming an overloaded side task. Liam shares the reality of serving both internal stakeholders and a community of more than a thousand organizations, including the hard part: creating two-way collaboration when most threat intelligence distribution methods are naturally one-way. We also dig into the maturity roadmap that makes progress repeatable: start with a strong foundation, earn targeted investment in tooling and training, then automate and improve iteratively. Along the way we talk hackathons as a way to protect deep work, KPIs that actually reflect value, and why “actionability” is the real definition of intelligence. Finally, we hit the OSINT tipping point and why intrusion analysis using your own telemetry often becomes the highest-relevance intelligence you can produce. Subscribe, share the episode with a CTI teammate, and leave a review so more analysts can find the show. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E8
    June 9 · 48 min

    Beyond CVSS With EPSS, SSVC, And Real Attack Signals (Brandon Parsons & Pedro Kertzman)

    CVSS can scream “critical” while the real risk in your environment is quietly sitting somewhere else and threat actors know it. We sit down with Brandon, a former United States Marine Corps intelligence specialist and longtime cyber threat intelligence practitioner, to get brutally practical about what actually drives smart vulnerability prioritization in 2025. We talk through why vulnerability management is so hard at scale, where EPSS and SSVC help (and where they can mislead), and why the CISA Known Exploited Vulnerabilities (KEV) catalog is a solid baseline but not the standard by itself. Brandon shares the products he screens for because attackers keep coming back to them: Citrix NetScaler, VMware ESXi and vCenter, Veeam Backup and Replication, Fortinet, Ivanti, file transfer tools, RMM software, and high-impact on-prem deployments. The throughline is adversary incentive: if taking out backups or gaining initial access raises the odds of a payout, expect fast “dogpiling” once research and proof of concept exploits hit the public. Then we pivot into the phishing and social engineering wave: device code phishing kits that steal refresh tokens and access tokens, Microsoft Teams phishing that abuses trust, callback phishing that hides the danger in a phone number, and the growing use of burnable infrastructure like workers.dev and pages.dev. We also dig into the dark web economy behind phishing as a service and why some groups are literally hiring English-speaking social engineers. Subscribe, share this with a teammate who owns patching or identity, and leave a review so more defenders can find the show. What’s the one vulnerability or phishing tactic you’re most worried about right now? Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E7
    May 26 · 25 min

    From Law Enforcement To Adversary Intelligence In Modern Banking (Eric Huber & Pedro Kertzman)

    Telegram isn’t just where fraud gets discussed, it’s where entire criminal markets operate in the open. I sit down with Eric Huber, who leads adversary intelligence and disruption work at TD Bank Group, to map how cyber-enabled financial crime really works today: the blend of fraud, payments, cybersecurity, cryptocurrency, and now AI. If you’ve ever wondered why CTI in banking feels different than “classic” threat intel, this conversation makes the overlap tangible and practical. We get into what Eric is seeing in Southeast Asia focused fraud ecosystems, including why the scale on Telegram can be overwhelming and how to find signal without drowning in noise. We talk about the reality of doing OSINT in a regulated financial services environment, where legal, privacy, vendor reviews, and governance controls are not red tape but part of doing investigations safely. Along the way, Eric shares a simple approach that works: start with a few sources, iterate, validate with peers, and keep your assumptions testable. From there, we connect the dots between telecom and banking with SIM swap attacks, insider risk, and why phone number takeover is still a fast path to account takeover and crypto theft. We also explore cryptocurrency fraud and blockchain analysis, including how public ledger data can help you evaluate criminal tooling and payment flows. Finally, we dig into AI in cybersecurity: where it accelerates analysis, where hallucinations can mislead teams, and why human QA and strong data handling matter more than ever. Subscribe, share this with a teammate, and leave a review if it helps. What part of the fraud and cyber threat landscape do you want us to unpack next? Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E6
    May 12 · 29 min

    From Ransomware Matrices To Actionable Threat Actor Profiles (Will Thomas & Pedro Kertzman)

    The fastest way to fall behind in cybersecurity is to stay reactive while attackers iterate in real time. We sit down with Will Thomas, known across the CTI community as “BushidoToken” to get practical about what actually helps defenders: threat actor profiling that is repeatable, actionable, and built for change. We start with how Will builds community-ready resources like the ransomware tool matrix and his threat actor profiling guide, then zoom into the Conti leaks and what hundreds of thousands of internal ransomware messages can teach us. From “salary day” breakdowns to operator behavior during major incidents, we talk about why these datasets are a gold mine and how to avoid getting lost in the volume. Will shares a concrete workflow for large-scale analysis using JSON exports, regex searches, CyberChef, and Elasticsearch so you can extract IOCs, wallets, infrastructure clues, and the higher-level “so what” that drives detections and threat hunting. From there, we shift into emerging threats and modern intrusion tradecraft: hacktivism that ranges from empty noise to destructive campaigns, EDR bypass techniques like bring-your-own vulnerable drivers and “EDR-on-EDR” tactics, and the steady rise of legitimate tools abused for access. We also dig into identity-led attacks where stolen credentials, social engineering, and SSO platforms like Okta can make endpoint controls less decisive. Finally, we unpack threat intelligence exchange beyond IOC feeds, including why STIX/TAXII still matters, how data quality and freshness drive results, and why a bidirectional TIP and SIEM relationship enables better correlation and “sightings.” Subscribe, share the episode with your team, and leave a review, then tell us: what part of your threat intelligence program needs the biggest upgrade right now? Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E5
    April 28 · 30 min

    From Shiny PDFs To Decisions In CTI - Season 2 - Episode 5 (Joshua Copeland & Pedro Kertzman)

    Most organizations say they “do CTI,” but what they really have is a pile of threat feeds, glossy reports, and alerts nobody trusts. We sit down with Joshua Copeland, cybersecurity executive, board advisor, and creator of the Unpopular Opinion series, to get brutally practical about what cyber threat intelligence should be: decision support that changes behavior inside a real security program. We talk through what it looks like to operationalize threat intelligence in security operations and threat hunting, including a trap that catches even mature teams: tuning everything around a baseline that might include attacker behavior. If a threat actor moves low and slow, “normal” network traffic can quietly become the attack. Joshua shares how strong CTI teams use frameworks like MITRE ATT&CK to turn a single piece of intel into targeted hunts, better detections, and smarter prioritization instead of endless IOC matching that breaks the moment infrastructure changes. The conversation also goes upstream into hiring and leadership. We dig into why certifications and degrees can’t substitute for critical thinking, how to interview with open ended scenarios that reveal real judgment, and how state level fusion centers can help public sector teams share actionable guidance. We also unpack why ransomware hits schools and why student data can be the real prize, then shift to the business case: translating CTI into risk reduction, downtime avoidance, insurance impact, and clear ROI. We close with a grounded take on AI in cybersecurity: it can add speed, but only with tight guardrails, source checking, and humans staying accountable. If you found this valuable, subscribe, share the episode with your team, and leave a review so more practitioners can find it. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E4
    April 14 · 20 min

    Precision Over Volume: Rethinking Threat Feeds For Real-World Impact (Sergio Albea & Pedro Kertzman)

    Ever wonder why your TI platform ingests thousands of new indicators a day and still finds almost nothing useful? We dig into the gap between volume and relevance with Sergio Albea of SWITCH, who built a simple, powerful framework to make IOCs matter for real users in real environments. The idea is direct: score every indicator by system, language, location, and sector so your detections match the way attackers actually operate. We walk through practical examples that flip the match rate from near-zero to meaningful hits. A URL mentioning Zurich or SBB scores higher for Swiss campuses. German or French lures outrank Spanish in that context. Mac fleets discount Windows-themed bait. Subject lines about research grants and student loans rise to the top. With that context, Sergio operationalizes Match4 using Azure Logic Apps to run KQL collectors, aggregates indicators in MISP, and pushes high-confidence URLs into Microsoft Defender TI Indicators to stop access at the endpoint—vital for students traveling worldwide. The impact grows as signals are shared. When one university sees a malicious domain, neighbors with similar language and services often see it next, revealing how threat actors campaign by sector. By centralizing across European NRENs, the team builds a living, education-focused threat feed you can’t buy off the shelf. Bonus: the data now surfaces cross-org targeting patterns, extends IOC lifetimes for “golden tickets,” and preserves history for threat hunting long after default telemetry ages out. If you’re tired of bloated, generic feeds and want precise detections that block real attacks, this conversation lays out the roadmap: prioritize relevance, automate collection, enforce at endpoints, and collaborate across your sector. Grab Sergio’s open-source templates on GitHub, start with a few collectors, and score for your environment—education, healthcare, finance, or beyond. Subscribe for more CTI strategies, share this with your team, and leave a review to help others find the show. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E3
    March 31 · 37 min

    Why Ransomware Attribution Keeps Getting Harder (Katya Kandratovich & Pedro Kertzman)

    Attribution is getting weird. The same ransomware ecosystem that used to leave clear fingerprints is now full of affiliate “job hopping,” shared tooling, rapid rebrands, and deep web noise that can trick even experienced cyber threat intelligence teams. Pedro Kurtzman sits down with Katya Kandratovich to map what’s changing and what’s stubbornly staying the same. We talk about why ransomware remains a dominant cyber threat, how law enforcement takedowns disrupt infrastructure without ending the business, and why ransomware-as-a-service programs keep professionalizing. Katya explains how affiliates move between groups for better payouts and support, and why that movement blurs profiling, negotiation patterns, and incident expectations. We also get practical about defense. Katya shares how she treats attribution as a decision-support tool, not a badge you follow blindly, and how to separate credible reporting from rumor when doing deep web monitoring. Then we dig into the intrusion basics that still work at scale: phishing and vishing boosted by AI, stealer logs that include portal context, and zero-days and internet-facing app exposure that won’t go away. We explore “living off the land” tradecraft where attackers abuse legitimate admin and device management tools, plus pressure tactics that target employees directly through calls and emails, sometimes even via personal addresses. Finally, we zoom out to supply chain attacks, MSP risk, third-party integrations, and developer package threats, and we confront a troubling trend: some groups now openly allow healthcare targeting. Subscribe for more cyber threat intelligence conversations, share this with your security team, and leave a review so more defenders can find the show. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E2
    March 17 · 21 min

    Inside macOS Security: Blind Spots, LOLBins, And Supply Chain Risks (Olivia Gallucci & Pedro Kertzman)

    Think your Mac is the safe corner of the network? Olivia Gallucci joins Pedro Kertzman to dismantle the myth of “secure by default” and show how modern attackers slip past comfort-zone defenses. We dig into the real blind spots on macOS, why unified logging and strict entitlements complicate endpoint visibility, and how Apple’s Endpoint Security API helps—while still leaving gaps clever adversaries can exploit. Olivia walks us through the rise of living-off-the-land tactics on Mac, often called LOLBins, where trusted tools like osascript, curl, launchctl, bash, and dscl become covert malware helpers. Instead of fixating on blocklists, we explore behavior-based detections that catch suspicious parent-child process chains, stealthy downloads, and persistence via launch agents. We also trace the expanding attack surface created by enterprise adoption of Macs among developers, admins, and executives—users with access, keys, and data worth chasing. On the supply chain front, we unpack how developers get targeted through poisoned dependencies and compromised package ecosystems, with examples tied to CocoaPods issues and malicious packages pulling command-and-control frameworks. For end users, trojanized apps, shady installers, and macro-laced documents still work, and notarization alone isn’t a silver bullet. Olivia shares pragmatic safeguards: dependency pinning, signed builds, stricter MDM policies, and layered monitoring that blends Apple-native frameworks with network telemetry. To help users help themselves, she highlights Objective-See’s open source tools that flag camera, microphone, and persistence changes in plain language. If you care about macOS security beyond the brochure, this conversation maps the terrain—what’s visible, what isn’t, and how to build defenses that hold up when trust fails. Subscribe, share with a teammate who uses a Mac at work, and leave a review with the one Mac detection you wish you had today. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S2 · E1
    March 3 · 45 min

    How Militarization, Language, And Policy Shape Modern Hacktivism (Anastasia Sentsova & Pedro Kertzman)

    The moment a “hacktivist” group starts speaking with a state’s voice, the puzzle of attribution changes. We explore how Russian-speaking cybercrime transformed after 2022, why so many crews began to move in sync with national narratives, and what language, targeting, and coordination can reveal about influence without leaning on weak assumptions. Our guest, analyst Anastasia Sentsova, brings deep regional fluency and years of fieldwork to explain how militarization, culture, and policy shape a pipeline that normalizes digital action and pulls volunteers toward more aggressive operations. We walk through the rise of coordinated Telegram ecosystems, including bot-driven “cyber squads” that gamify propaganda with ranks, points, and real-world rewards. That may sound harmless, but it builds habits, grows networks, and legitimizes escalation. From there, it’s a short step to DDoS—and increasingly—intrusions that touch critical infrastructure. We also examine the ransomware world’s political boundaries: no-go lists that evolved from domestic targets to BRICS countries, selective law enforcement pressure following diplomatic milestones, and the unspoken bargain that keeps operators productive so long as they toe the line. Rather than force-fit labels like sponsored or tolerated, we talk about influence as a measurable spectrum. Indicators include state rhetoric in native-language posts, synchronized activity with kinetic events, target selection aligned with policy goals, and public signaling when named individuals “celebrate” sanctions without consequence. For practitioners, we offer concrete ways to avoid Western bias, validate translations, and build multi-source cases with explicit confidence levels. And we look ahead: the proxy model travels, youth pipelines deepen skills, and hybrid operations blur the boundary between hacktivists and APTs. If this kind of clear-eyed CTI resonates, follow the show, share it with your team, and leave a review so others can find it. Join our LinkedIn group, Cyber Threat Intelligence Podcast, to keep the conversation going and tell us what signals you’re tracking next. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • February 17 · 40 sec

    Cyber Threat Intelligence Podcast - Season 2 Premiere

    🎙 Season 2 Starts March 3rd Season 1 was about building foundations. Season 2 is about raising the bar. We’re diving deeper into the Cyber, Threats, and Intelligence, with practitioners who live it every day. FULL Video: https://youtu.be/oa2t9GQl6EU 📅 Premiere: March 3rd 🔔 Subscribe now so you don’t miss it. The threat landscape evolves. So should we. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

  • S1 · E24
    January 20 · 23 min

    Season 1 Finale

    Want fewer fire drills and smarter security moves? This season finale brings together the strongest lessons from our guests on how cyber threat intelligence turns uncertainty into clarity—and clarity into action. We share what actually works when the data is partial, the stakes are high, and leadership wants proof that CTI moves the needle on risk and cost. We start with the core: prioritization under uncertainty. You’ll hear how teams use intelligence to decide what to patch first, where controls matter most, and how to focus limited resources without missing the threats that can take a business offline or put customer data at risk. We dig into the language of value—money saved, revenue protected, efficiency gained—and why BLUF, clear implications, and stakeholder interviews beat jargon every time. If you’ve wrestled with KPIs, KRIs, or ROI, we unpack practical metrics that reflect real outcomes, not vanity numbers. From there, we look ahead. Forecasting adversary capabilities, mapping susceptibility, and choosing proactive mitigations can shift a security program from reactive to resilient. You’ll get candid perspectives on building CTI the right way—starting tactically and growing into operational and strategic impact, or choosing a build-vs-buy path aligned to budget and goals. We also talk careers and team shape: why diverse backgrounds thrive in CTI, how small teams can deliver outsized results, and the discipline of deciding what you will not do so you can excel at what matters. If you want CTI to influence decisions at every level—SOC, IR, red and purple teams, and the board—this wrap-up offers the playbook: stakeholder-first communication, focused scope, useful metrics, and a relentless push toward proactive defense. Follow, share, and leave a review to help more practitioners find these insights—and tell us: what CTI metric best proves your impact? Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E23
    January 6 · 33 min

    Season 1 - Episode 23 (Pedro Kertzman & Alex Keedy)

    Want a front-row seat to how cyber threat intelligence turns noise into decisions that save real money and protect trust? Pedro Kertzman sits down with Alex Keedy, a seasoned CTI leader with experience at Flashpoint, ZeroFox, Intel 471, Deloitte, and Booz Allen Hamilton, to unpack the craft of translating technical signal into business impact. From a political science beginning to profiling actors and advising executives, Alex shows why great intelligence starts with curiosity and ends with clarity: here’s what’s happening, what it means for us, and what we should do next. We dig into the tough question every leader asks: how do you prove ROI for attacks that never landed? Alex breaks down practical models that map blocked activity to benchmark costs, balance tangible savings with brand and trust impacts, and prioritize the few actions that reduce the most risk. For mid-sized organizations, she lays out a pragmatic roadmap: start small, tap managed services, automate the obvious, and use early wins to earn budget. You’ll hear how a$10 stolen credential becomes a$50M outage, why ransomware-as-a-service thrives, and how to disrupt that supply chain before it reaches your environment. Alex also opens the curtains on dark web tradecraft. Reputation-driven marketplaces demand embedded personas to validate threats, verify leaks, and ask the questions victims can’t. That access helps teams confirm exposure, guide response, and even support law enforcement—with examples spanning financial fraud, takedowns, and human trafficking investigations. Along the way, we share actionable learning paths: SANS webcasts, vendor blogs, Security+ or Network+ for baseline fluency, and community routes like B‑Sides and scholarships that lower barriers for new talent. If you care about cybersecurity strategy, budget impact, and real-world outcomes, this conversation delivers the playbook: align intelligence to business risk, measure what matters, and communicate in plain language. Subscribe, share with a teammate who needs stronger CTI outcomes, and leave a review telling us the one question you want answered next. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E22
    Dec 23, 2025 · 28 min

    Season 1 - Episode 22 (Pedro Kertzman & Valerii Soloninka)

    Curiosity can rewrite a career—and change how an investigation ends. We sit down with Valeri Soloninka, a Russian-speaking cybersecurity professional now protecting government entities in the UAE, to trace a path from hands-on engineering to enterprise SOC work and into the high-impact world of operational and tactical cyber threat intelligence. Along the way, we unpack how fundamentals like networking, DNS, and OS internals still power great CTI, even as LLMs speed up drafting and research. Valeri takes us inside Russia’s cybersecurity market—large, regulated, and comparatively closed—where public reporting is scarce and partnerships carry the weight of intelligence sharing. That perspective meets a striking case from the Middle East: identifying Lazarus Group activity tied to Russian-language lures, a reminder that geopolitics and targeting rarely align neatly. Allies still spy, strategic programs demand data, and defenders must follow evidence over assumptions. We break down how to translate adversary tactics into detections, drive incident response with attribution-aware guidance, and help vulnerability teams prioritize what matters. Thinking about moving from SOC to CTI? Valeri’s playbook emphasizes relentless curiosity, a bias for action, and the technical backbone to make sense of infrastructure, indicators, and behavior at speed. We also talk candidly about the Gulf market—its boom years, current hiring realities, and why safety, services, and zero income tax continue to draw talent. For learners at every stage, you’ll hear practical recommendations on podcasts, YouTube channels, Reddit communities, and books that build lasting baselines. Join us for a candid, story-driven look at building a meaningful CTI career, spotting threats where others aren’t looking, and becoming the teammate IR and SOC leaders seek out when stakes are high. If this conversation helps you think differently, subscribe, share the show with a colleague, and leave a quick review to help others find it. What topic should we dig into next? Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E21
    Dec 9, 2025 · 26 min

    Season 1 - Episode 21 (Pedro Kertzman & Charlotte Guiney)

    What if your best career move starts where you least expect it? Charlotte joins us to share how a love for global history and policy, a bout of academic burnout, and a train-to-hire detour into agile software set the stage for a thriving path in cyber threat intelligence. Her story shows how curiosity, timing, and a willingness to say yes can turn scattered experiences into a focused CTI career. We dig into the practical differences between enterprise and vendor CTI: why enterprise teams learn fast by wearing many hats, how vendor roles sharpen deep specialties, and where each path provides leverage. Charlotte breaks down what she learned reporting into a red team—turning intel into action through adversary emulation, purple teaming, and proactive threat hunting that leads directly to better detections. The theme that ties it together is collaboration: fusion teams that share goals move faster and reduce risk in measurable ways. Charlotte also opens up about management and maturity. Translating technical wins into business language builds trust with leadership and secures long-term investment. We talk through a simple framework for proof: define the problem, show the intervention, quantify the outcome. On the personal side, we cover sustainable learning—curated news feeds, role-aligned priorities, and thoughtful use of LLMs—to stay sharp without burning out. And the mindset that makes it all work? Embrace the gray, follow the side quests, and keep building toward the bigger picture. If this conversation sparks an idea, share it with a teammate, subscribe for more, and leave a quick review to help others find the show. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E20
    Nov 25, 2025 · 37 min

    Season 1 - Episode 20 (Pedro Kertzman & Sarah Freeman)

    Remember when critical infrastructure defenders had to convince people that cyber attacks were even possible? Those days are gone. Today's challenge is prioritizing defenses in a landscape where threats are multiplying faster than resources. Sarah Freeman, Chief Engineer for Intelligence Modeling and Simulation at MITRE's Cyber Infrastructure Protection Innovation Center, takes us on a journey through the evolution of industrial security. With over a decade of experience protecting the systems that power our world, she offers a refreshing perspective that cuts through both complacency and fear. The conversation explores how industrial security has matured from basic awareness to strategic defense. Sarah reveals how threat actors have shifted tactics, increasingly targeting third-party providers as a way to compromise multiple critical infrastructure customers simultaneously. "More and more of the actors target those companies deliberately," she explains. "By compromising this one entity, they have theoretical access to all of these customers." We dive into the practical challenges of security in operational technology environments, where the sheer volume of vulnerabilities has become overwhelming. Rather than attempting to patch everything, Sarah advocates for a more targeted approach based on anticipating adversary capabilities—a "cyber forecast" that helps organizations focus limited resources where they matter most. The discussion also tackles the integration of artificial intelligence into traditionally isolated control systems, offering insights on balancing innovation with security. For threat intelligence professionals looking to specialize in industrial security, Sarah provides guidance on essential resources and community connections. Whether you're responsible for critical infrastructure protection or simply interested in understanding the unique challenges of securing systems where digital meets physical, this episode offers valuable perspective from someone who's been on the front lines since before most people recognized the threat existed. Listen now to gain insights that will help you think more strategically about protecting the systems that power our modern world. Want to connect with other CTI professionals? Join our LinkedIn group "Cyber Threat Intelligence Podcast" to continue the conversation. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E19
    Nov 11, 2025 · 40 min

    Season 1 - Episode 19 (Pedro Kertzman & Tammy Harper)

    Imagine a criminal enterprise so sophisticated it employs lawyers, creates flashy recruitment videos, and operates its own university. Welcome to the modern ransomware ecosystem, expertly decoded by threat intelligence researcher Tammy Harper in this eye-opening episode. Harper pulls back the curtain on the surprisingly corporate structure of ransomware operations, revealing a three-tiered hierarchy ranging from invite-only "syndicates" managing millions in cryptocurrency to small "operators" struggling to recruit talent, down to inexperienced "script kiddies" with minimal operational security. The business models are equally fascinating – Ransomware-as-a-Service providers take a 20% cut while offering everything from malware payloads to secure communication channels and victim-shaming blogs. What's truly alarming is how these criminal groups continue to innovate their extortion techniques. As fewer victims pay ransoms (just one in twenty pay significant amounts), gangs are escalating pressure tactics. Some offer affiliates legal counsel to identify regulatory pressure points, others implement AI-assisted negotiations to counter traditional stalling tactics, and some are even calling victims' clients directly to orchestrate supply chain attacks. Harper dispels common misconceptions about attack vectors too. Modern ransomware rarely arrives as an email attachment – instead, attacks begin with phishing emails containing Trojans, followed by extensive reconnaissance lasting weeks or even months. "When you see your systems encrypted," she warns, "it's too late." The longest compromise she witnessed lasted a full year from initial infection to ransomware deployment, despite law enforcement warnings to the victim. Whether you're a cybersecurity professional or simply curious about digital threats, this episode provides rare insights into a criminal ecosystem that continues to evolve despite increasing law enforcement pressure. Listen now to understand the tactics that make modern ransomware so persistent and how organizations can better protect themselves. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
  • S1 · E18
    Oct 28, 2025 · 1 hr 6 min

    Season 1 - Episode 18 (Pedro Kertzman & Freddy Murre)

    "Basically, everyone just do whatever they feel like and then call it intelligence." With these provocative words, Freddy Murre cuts straight to the heart of what's wrong with most cyber threat intelligence practices today. Drawing from 13 years of intelligence experience spanning military operations and private sector work, Freddy exposes the critical disconnect between intelligence methodology and what many CTI teams actually deliver. Most security teams, he argues, are producing cyber threat information, not intelligence—pushing technical indicators without context, relevance, or the crucial "so what" that decision-makers need. The conversation explores how CTI professionals often fall back on their technical comfort zones rather than embracing true intelligence tradecraft. Freddy walks us through the intelligence cycle, explaining how requirements drive collection and analysis to produce actionable insights. He challenges the industry norm of one-directional "data dumps" from vendors to customers, advocating instead for a more tailored approach that considers each organization's specific technologies, vulnerabilities, and business needs. Perhaps most valuable is Freddy's practical guidance on stakeholder engagement—identifying who your intelligence serves, understanding their decision-making needs, and continually validating that your work delivers measurable value. "If they can't articulate the decisions they made based on your intelligence," he warns, "you're in a dark space." His Ferrari analogy brilliantly illustrates how CTI teams must find the right fit between capabilities and stakeholder requirements. The episode also tackles AI's impact on intelligence work, with Freddy offering a sobering assessment of large language models' limitations while acknowledging their potential benefits when properly understood as tools rather than solutions. Whether you're a seasoned CTI professional or just building your program, this conversation provides an essential framework for elevating your practice from information sharing to true intelligence production. Send us Fan Mail Support the show Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

    • Transcript
    • Chapters
Showing 1–20 of 22 episodes