Skip to content
Artwork for Plaintext with Rich

Plaintext with Rich

Rich Greene

Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people?


Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!

Play
  • 23 episodes
  • weekly
  • Avg 9 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S1 · E40
    Friday · 9 min

    Google Selfie Account Recovery: Convenience vs. Privacy

    Would you hand Google a video of your face for one more way back into your account? That question gets harder when you are locked out, holding a new phone, and missing every recovery route you thought would save you. In this episode of Plaintext with Rich, we look at Google's selfie video sign-in option and what eligible users should know before opting in. You will hear how Google described comparing a saved recording with a new video, why prompted head movements support a liveness check, and how suspicious sign-in checks add another layer. We also unpack encryption at rest, biometric data, optional use of recordings to improve verification services, and Google's deletion terms. The episode explains the eligibility limits Google documented in July 2026. Most importantly, it puts selfie recovery alongside passkeys, recovery contacts, phone numbers, and recovery email as one part of a stronger account recovery plan. This is for anyone whose Google Account holds important email, photos, documents, or access to other services, and for leaders helping people make informed security choices. Convenience and privacy both matter, so make the choice on purpose. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E39
    August 21 · 10 min

    AI Security Test Escape: Why Agent Containment Failed

    An AI security test was supposed to stay inside a controlled environment. Instead, the models found an unexpected route to the public Internet and reached real Hugging Face infrastructure while pursuing benchmark answers. In this episode of Plaintext with Rich, we unpack how an OpenAI cyber evaluation became a real security incident. You will hear how the models exploited a package service, increased their permissions, used stolen credentials, and pursued ExploitGym solutions beyond the intended test boundary. Rich explains zero-day vulnerabilities, remote code execution, vulnerability chaining, and why a sandbox depends on far more than one isolation control. The episode also examines Hugging Face's response and the practical management lesson behind the incident: when an agent is rewarded for reaching a goal, leaders must understand every system it can touch along the way. This episode is for business leaders, security teams, technology buyers, and anyone evaluating AI agents with access to websites, codebases, or internal tools. You will leave with a five-part starter kit for mapping exits, limiting credentials, layering containment, monitoring agent behavior, and writing a stop plan before testing begins. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E38
    August 14 · 10 min

    PTC Windchill Vulnerability: Why Your Product Blueprints Are at Risk

    A company can lose its most valuable product plans without a broken lock, an encrypted laptop, or an obvious warning on the screen. The first clear sign may be an extortion email claiming the files are already gone. This episode of Plaintext with Rich explains the attacks disclosed against PTC Windchill and FlexPLM, two product lifecycle management platforms that can hold designs, bills of materials, manufacturing instructions, supplier details, and launch plans. Rich breaks down CVE-2026-12569, remote code execution, unsafe deserialization, and web shells in language built for people who do not spend their days reading security advisories. You will also hear why CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, why reporting in July 2026 compared the campaign tactics to Clop, and why attribution was unconfirmed when the episode was prepared. Most importantly, the episode explains why applying the PTC patch is only half the job when attackers may already have copied sensitive data. This is for business leaders, technology teams, product owners, manufacturers, retailers, and anyone responsible for a central platform that holds concentrated company value. It offers a practical way to think about patching, compromise hunting, incident response, and the business decisions that follow possible data theft. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E37
    August 7 · 9 min

    CVE-2026-50522: Why SharePoint Patching Is Only Step One

    A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work? In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. You will hear why CISA's Known Exploited Vulnerabilities catalog matters, how SharePoint machine keys can extend risk beyond the vulnerable code, and why a clean vulnerability scan cannot prove that nobody arrived earlier. Rich breaks the response into three separate jobs: patch the affected farm, hunt for signs of compromise and persistence, and rotate machine keys, credentials, or tokens that may have been exposed. He also explains why rotation must be coordinated to avoid session, authentication, and integration problems. This episode is for leaders, business owners, IT teams, and anyone responsible for asking whether a SharePoint incident is truly contained. It gives you better questions for the status meeting without turning a serious risk into panic. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E36
    July 31 · 8 min

    AutoJack Attack: How Malicious Pages Hijack AI Browsing Agents

    You told your AI assistant to book a flight and compare hotels. You come back, and it did all of that. It also ran commands on your machine that you never approved. What just happened? This episode unpacks AutoJack, a demonstrated attack pattern where malicious web pages hijack AI browsing agents through prompt injection. We cover how untrusted web content can steer autonomous agents into unsafe actions, the critical risk of localhost access in agent frameworks like AutoGen, and the chain from reading a bad page to remote code execution on your host machine. You'll learn why giving an agent a browser is fundamentally different from giving it information access, and how ambient authority plus autonomous actions creates a blast radius most teams haven't planned for. This is for security teams adopting AI agents, engineering leads building agentic tools, and anyone who needs to understand the new attack surface before deploying browsing automation at work. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E35
    July 24 · 10 min

    North Korea Mastra NPM Supply Chain Attack: How It Works

    You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code. This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attack surface, the difference between package takedown and forensic cleanup, and why lockfiles are history snapshots not security verdicts. We walk through the controls that protect teams most: deterministic builds with pinned versions and provenance attestations for verified package origins. The episode includes timeline thinking for exposure windows, hunting for execution artifacts beyond package names, and the specific steps for rotating secrets and rebuilding compromised environments. This is for developers, security teams, and engineering leaders managing open source dependencies in fast moving stacks. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E34
    July 17 · 9 min

    Patch Tuesday 206 Vulnerabilities: AI Discovery vs Remediation Speed

    Your update dashboard keeps climbing. Not ten fixes, not fifty. Two hundred and six security patches waiting for approval, and everyone is asking if work stops now. That was June 2026, the largest Patch Tuesday on record. This episode covers why record patch volumes are becoming normal, what AI-assisted vulnerability discovery has to do with the bug pipeline, how to prioritize under pressure with a four-lens triage framework (exploitability, exposure, impact, compensating controls), and why the real problem is not volume but the speed mismatch between finding bugs and fixing them. We walk through CVE-2026-45657, the wormable kernel issue rated CVSS 9.8, and what that severity score actually means for your risk timeline. You will also get a practical approach to building a 24-hour critical patch lane, classifying assets before the next wave, and using temporary containment when patching must wait. This is for IT leaders managing emergency change windows, security teams ranking exploit paths, and business leaders deciding when downtime is justified. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E33
    July 10 · 8 min

    Instagram AI Takeover: How Attackers Exploited Meta Support Bots

    Your profile photo vanishes. Your email is changed. A password reset you never requested lands in someone else's inbox. You're locked out of your own Instagram account, and you didn't click a single suspicious link. In early 2026, attackers manipulated Meta's AI support chatbot to approve password resets on roughly 20,225 Instagram accounts over seven weeks. This episode breaks down how social engineering evolved from targeting human support reps to exploiting AI-powered customer service systems. We cover identity verification failures, how chatbots became part of the security boundary, the policy response led by California Attorney General Rob Bonta and 40 state attorneys general, and the difference between traditional phishing and trust-layer manipulation. You'll hear why separating chat from authority matters, what phishing-resistant multi-factor authentication means, and how to apply throttling, anomaly detection, and tabletop exercises for bot abuse. This is for anyone managing Instagram accounts, security teams integrating AI support tools, and developers building customer service automation who need to understand where convenience meets risk. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E32
    July 3 · 9 min

    FortiBleed: When Your Firewall Becomes the Front Door

    Your firewall is supposed to be the thing that keeps attackers out. FortiBleed is the story of what happens when it becomes the way in. In June 2026, roughly 86,644 sets of working Fortinet credentials turned up circulating among attackers across 194 countries. On June 18th, CISA issued an emergency advisory telling anyone running internet-facing Fortinet gear to terminate active sessions, rotate every credential, and turn on phishing-resistant multi-factor authentication immediately. This episode of Plaintext with Rich explains what FortiBleed actually is, why patching alone does not solve a credential-exposure incident, and what the difference between "patch" and "rotate" means for the people responsible for keeping a network safe. It also covers why a firewall breach lands differently than almost any other kind of breach, and what to check if you are worried someone already walked through the door before you changed the locks. If you manage a team, own a business, or sit anywhere near a decision about network security gear, this one is directly relevant to your week. If you have no idea what a firewall does, that is fine too; the episode starts from the beginning. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E31
    June 26 · 10 min

    Post-Quantum Cryptography: Start the Inventory Before Q-Day

    You don't inventory your house the morning of the move. You start months before. So why are most organizations still treating post-quantum cryptography as a 2035 problem? Episode 31 of Plaintext with Rich treats the post-quantum crypto migration as what it actually is. A logistics problem, not a science one. We walk through the news peg that moved the timeline. Google's March 2026 announcement of a 2029 internal deadline, years ahead of federal targets, anchored by Craig Gidney's research at Google Quantum AI showing that one million noisy qubits could break a 2,048-bit RSA key in under a week. We explain harvest-now-decrypt-later in plain language, the threat that doesn't wait for Q-Day. We cover the three new NIST standards (FIPS 203, FIPS 204, FIPS 205), the NSA's January 2027 CNSA 2.0 procurement gate, and the design principle that matters more than any single algorithm. Crypto-agility. The episode closes with a Plaintext Starter Kit for the leader who needs to know what to ask the security team this quarter. If you've ever wondered what "quantum breaks encryption" actually means for your environment, or whether you should be doing anything about it before 2030, this one is for you. Ten minutes. One topic. No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E30
    June 19 · 10 min

    Cybersecurity Careers and AI: The Squeeze and the Opening

    Someone pulled Rich aside at a conference recently. Six years in IT, ready to break into security, and asking the question more people ask every week. Should I even bother right now? Here's what the data actually shows. Episode 30 of Plaintext with Rich unpacks the cybersecurity career paradox of 2026. The bottom rung is getting squeezed as AI automates SOC analyst, threat intelligence, and incident response work. At the same time, demand for AI security engineers, prompt injection specialists, and model risk leads is climbing fast. The episode walks through what prompt injection actually looks like in plain language, why the 2025 ISC2 Cybersecurity Workforce Study calls AI the field's top critical skill for the second year running, what BLS projects through 2034, and how the Pentagon's new Cyber Registered Apprenticeship Program is becoming a skills-based hiring blueprint other employers will copy. If you're trying to break into cybersecurity right now, or you're already in the field and watching AI requirements sprout on every posting, this one is for you. It addresses the anxiety honestly. No doom. No false comfort. Ten minutes. One topic. No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E29
    June 12 · 8 min

    Supply Chain Attacks: How One Update Hit OpenAI

    A routine software update. No phishing. No sketchy download. Then a security team finds the unthinkable: trusted code has been hijacked, and the breach rode in through the exact channels engineers rely on every day. I walk through the supply chain attacks that piled up across April and May 2026, including poisoned open source packages tied to TanStack and trojanized Daemon Tools installers, plus the rapid-fire abuse of major software registries like NPM, PyPI, and Docker Hub. The most important twist is what the malware is hunting. These campaigns aren’t primarily chasing customer data. They’re after the assets sitting on developer laptops and flowing through build servers: developer credentials, API keys, cloud tokens, SSH keys, and the permissions that turn “one compromised machine” into “access everywhere.” I explain why this shift is happening now through two lenses: trust (software is assembled, not written from scratch) and leverage (compromise one popular dependency and you reach everyone who installs it). Then we get practical about software supply chain security and CI/CD security. I break down how a poisoned pipeline can still output packages that look legitimate, complete with valid signatures, and why that makes detection so hard. Finally, I lay out five moves you can take right now: build an SBOM, treat CI/CD like production, watch for suspicious dependency changes and too-fresh releases, rotate to short-lived scoped secrets, and patch known-bad tool versions quickly. Subscribe, share this with a developer or leader who approves tooling, and leave a review so more teams stop trusting updates on autopilot. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E28
    June 5 · 9 min

    Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA

    It's Monday morning. You open the third email of the day. Nothing visible happens, but in the background, an attacker just borrowed the proof you were logged in. Episode 28 of Plaintext with Rich is a hot take on CVE-2026-42897, the Microsoft Exchange Server zero-day under active exploitation right now. We break down what cross-site scripting actually does inside Outlook Web Access, why session hijacking is more dangerous than the underlying bug, and how a single crafted email becomes business email compromise. We look at the on-premises versus Exchange Online divide, why ProxyLogon and ProxyShell aren't ancient history yet, and what CISA's Known Exploited Vulnerabilities catalog listing and the May 29 federal deadline mean for everyone else. The episode closes with a Plaintext Starter Kit of four moves any on-prem Exchange team should make this week. If you run on-prem Exchange, support someone who does, or you've been putting off the migration conversation, this one is for you. Ten minutes. One topic. No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E27
    May 29 · 8 min

    Work-Life Balance in Cybersecurity: The Structural Fix

    You finish at 6:00pm. At 6:47 you reopen the laptop, 'just to check something.' By 9:00 the evening is gone. The boundary didn't fail tonight. It was never there. Episode 27 of Plaintext with Rich closes the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about work-life balance, but not as willpower or time management. As protective infrastructure. We pull the arc together, mental, spiritual, physical, and burnout, and land on the idea that balance is what keeps the first three from collapsing into the fourth. We borrow briefly from Cal Newport's concept of deep work and Jocko Willink's framing of discipline as freedom, neither as sermon, both as shorthand. The episode closes with a Plaintext Starter Kit of structural defaults, not resolutions, designed to protect a sustainable career in a job that otherwise won't let you have one. If you've made it to the end of this series and you're asking 'okay, but how do I actually live this on a Tuesday,' this one is for you. Ten minutes or less. One topic. No panic. Cal Newports "Deep Work: Rules for Focused Success in a Distracted World" Jocko Willink Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E26
    May 22 · 8 min

    Cybersecurity Burnout: Not a Character Flaw, a System Problem

    You're reading a breach report. Third one this month. Last year a story like this would have lit something in you. Today you scroll past it. That's not you. That's the bill. Episode 26 of Plaintext with Rich is the fourth installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about burnout, what it actually is and why the cybersecurity industry produces it reliably. We use the World Health Organization's classification of burnout as an occupational phenomenon and Christina Maslach's three dimensions (exhaustion, cynicism, reduced efficacy) to name what most of us feel but can't label. We get into the systemic causes specific to our field: always-on culture, headcount lag, and job designs that treat recovery as a perk instead of infrastructure. The episode lands with a Plaintext Starter Kit split between what the individual can do and what only leadership can fix. If you've ever caught yourself scrolling past a breach report that used to light a fire and realized you don't feel anything, this one is for you. Whether you're the one carrying the load or the one supposed to be protecting the people who are. Ten minutes or less. One topic. No panic. Christina Maslach -> https://www.linkedin.com/in/christinamaslach/ World Health Organization -> https://www.linkedin.com/company/world-health-organization/ Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E25
    May 15 · 7 min

    Physical Health in Cybersecurity: The Body Keeps the Receipts

    It's Friday morning. You stand up to refill your water and your back doesn’t move the way it used to. The systems are up and running smoothly. Your body hasn’t gotten the same memo. Episode 25 of Plaintext with Rich is the third installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we’re talking about physical health, the silent receipt your body keeps for the cumulative load of this job. We get into the specific body costs of security work: long incident response shifts, screen time, the cortisol of on-call, sleep disruption from pages, and the war-room conditions that turn your spine into a slow-motion lawsuit. The episode lands with a Plaintext Starter Kit of habits you can start this week, no programs to join and no protocols to memorize. If you’ve ever come off a long incident and felt every hour you spent at the keyboard in your shoulders, this one is for you. Whether you’re an analyst, an engineer, or the one person doing security at a 40-person company, the body keeps the bill. For community around this conversation, find Rich’s LinkedIn group, Desk to Deadlifts. The name is catchy, but it’s not a powerlifting group. It’s a space for professionals trying to fit physical health into busy lives. Ten minutes or less. One topic. No panic. Desk to Deadlift (LinkedIn Group) https://www.linkedin.com/groups/13248033/ Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E24
    May 8 · 8 min

    Spiritual Health in Cybersecurity: The Why Behind the Work

    Spiritual health on a cybersecurity podcast sounds like a stretch. Stay with us. Because somewhere between the vendor pitches, the patch cycles, and the 3 a.m. page, a lot of us stopped working for the why and started working for the number. Episode 24 of Plaintext with Rich is the second installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we define spiritual health as the values that make up who you are, the things you won’t trade even for a raise. We get into mission drift, the quiet trap of lifestyle creep in a high-paying field, and the 3 a.m. test for whether your values are still alive when the paycheck isn’t watching. We acknowledge that for some listeners these values come from a faith tradition and for others they don’t, and both are valid. The episode lands with a Plaintext Starter Kit, including the simple act of writing your values down, asking yourself what ‘enough’ actually looks like, and finding people (including communities like Shield that are built for grounded, sustainable careers in tech and cyber) who remind you who you are before the title does. If you’ve ever wondered why the bigger paycheck stopped making the work feel better, this one is for you. Whether you’re a SOC analyst, an engineer, a CISO, or the one person doing security at a 40-person company, your values have to outrun your comp. Ten minutes or less. One topic. No panic. Shield Community, a wellness program built specifically for technology and cybersecurity professionals. https://www.shield.community/ Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E23
    May 1 · 7 min

    Mental Health in Cybersecurity: The Weight of Vigilance

    It's 6:47 a.m. The incident was contained hours ago. The systems are fine. You're the one still running hot. This episode opens the Month of Mindfulness, a five-week Plaintext with Rich series on mental health, spiritual health, physical health, burnout, and work-life balance for people working in cybersecurity and tech. May 1 happens to fall during Mental Health Awareness Month, which makes it the right time to start. We're talking about the mental load that comes with vigilance work: on-call rotations, alert fatigue, incident response, and the cost of being the person who carries worst-case scenarios in your head all day. Plus a Plaintext Starter Kit with five practical moves, including how to actually use your Employee Assistance Program (EAP) and where to find Mental Health Hackers at the next conference you attend. And three programs worth bookmarking: Pacific Mindful's CyberReset, The Zensory, and Shield Community, each built for the nervous system demands of technology and cybersecurity work. If you've ever come off an incident and wondered why your body is still running an alert two days later, this is for you. Whether you're an analyst, an engineer, a CISO, or the one person doing security at a 40-person company, the load is real and so is the recovery. Ten minutes or less. One topic. No panic. Pacific Mindful's CyberReset, a precision nervous system training tool built for high-exposure roles. https://www.pacificmndfl.com/reset The Zensory, a science-backed wellbeing platform with a dedicated Cyber Mindfulness Campaign. https://thezensory.com Shield Community, a wellness program built specifically for technology and cybersecurity professionals. https://www.shield.community/ Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E22
    April 24 · 9 min

    Threat Intelligence: Why Most Organizations Get It Backwards

    A dashboard lights up with indicators of compromise. The analyst copies the top five into a ticket, tags it "actionable," and sends it to the SOC. Nobody reads it not because they don't care, but because it didn't tell them what to do or why it mattered. That's not an intelligence failure. That's a confusion about what intelligence actually is. This episode breaks down threat intelligence from the ground up, drawing on Rich's military experience as a case officer in special operations. It separates data, information, and intelligence into three distinct layers, explains why most CTI programs skip the step that actually matters. Connecting analysis to a specific decision and introduces the concept of Priority Intelligence Requirements as the questions that should drive everything a security team collects and analyzes. The episode covers the intelligence cycle, why feeds alone aren't intelligence, and why organizations that never close the loop are publishing, not protecting. It closes with a five-step starter kit for building a threat intelligence function that actually changes decisions. Whether you're standing up a CTI program, evaluating one that isn't delivering, or just trying to understand what threat intelligence should look like, Plaintext with Rich cuts through the noise. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
  • S1 · E21
    April 17 · 10 min

    Roll for Security: What D&D Teaches About Cyber Defense

    The fighter absorbs hits up front. The rogue finds traps before the party walks into them. The cleric keeps everyone alive when things go wrong. And the bard convinces the people with resources to actually fund the quest. Nobody does everything. Everybody has a role. Now replace the dungeon with your company's network. This episode maps cybersecurity roles to D&D character classes, SOC analysts as fighters, pen testers as rogues, incident response as clerics, security architects as wizards, CISOs as bards, and threat intelligence analysts as rangers. It translates the six core ability scores into an organization's security posture: Strength as technical controls, Dexterity as speed of response, Constitution as resilience, Intelligence as threat knowledge, Wisdom as judgment, and Charisma as communication. Then it breaks down why parties wipe, siloed teams, no incident response plan, main character syndrome, and ignoring the logs before closing with a five-step starter kit for building your party and running the campaign. Whether you're a tabletop gamer who works in security or a leader trying to understand why your team needs every role filled, Plaintext with Rich has the quest briefing. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene

    • Transcript
    • Chapters
Showing 1–20 of 23 episodes