Skip to content
Artwork for Prabh Nair

Prabh Nair

Prabh Nair

Prabh Nair is a cybersecurity podcaster covering cyber risk, ransomware, incident response, SOC operations, GRC, AI security, threat intelligence, digital forensics, ISO 27001, CISSP, CISM, and security leadership. Built for SOC analysts, auditors, cybersecurity professionals, students, and business leaders, each episode delivers simple explanations, practical lessons, and real-world examples to help you stay ahead in the fast-changing cyber world.
#CyberSecurity #InformationSecurity #CyberRisk #GRC #SOC #IncidentResponse #Ransomware #ThreatIntelligence #AISecurity #DigitalForensics

Play
  • 24 episodes
  • a few times a week
  • Avg 55 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • July 27 · 1 hr 24 min

    CISSP 2026 AI Topics Questions Master Class

    Are you preparing for CISSP 2026 and wondering how AI security, AI governance, responsible AI, privacy, and model attacks can be tested in the exam?In this video, we break down important CISSP-style AI questions in a practical and exam-focused way. Instead of memorizing definitions, you will learn how to think like a CISSP candidate when facing scenario-based questions on AI systems, governance, risk management, security controls, privacy, and third-party AI platforms.AI is no longer just a technology topic. For CISSP candidates, AI connects directly with Security and Risk Management, Asset Security, Security Architecture, Security Operations, Identity and Access Management, Software Development Security, and Third-Party Risk Management.In this session, we cover AI governance, responsible AI, ethical AI, shadow AI, model poisoning, model inversion, membership inference, prompt injection, differential privacy, AI-SBOM, model cards, AI vendor risk, AI monitoring, risk appetite, risk tolerance, SOC, SIEM, SOAR, and AI security control selection. This video is useful for CISSP 2026 candidates, cybersecurity professionals, GRC professionals, SOC analysts, security managers, risk managers, and AI governance learners who want to understand how AI-related security topics may appear in scenario-based CISSP questions.Watch the full video and try answering each question before checking the explanation. That is how you build CISSP-level judgment.Subscribe for more CISSP exam preparation, cybersecurity concepts, AI security topics, and practical scenario-based questions.CISSP 2026 Coffee Shotshttps://www.youtube.com/watch?v=1krYtSQbMWc&list=PL0hT6hgexlYxKzBmiCD6SXW0qO5ucFO-J&pp=sAgCCISSP Spotify Podcast Domain 1 to Domain 7Domain 1 : https://open.spotify.com/episode/6fggB2lwYA5kzmdmz7BsCh?si=ff488838799b4baeDomain 2 = https://open.spotify.com/episode/4RkQIHgpTUC87TR3UqmkHd?si=ca4f12aea1dc473aDomain 3 = https://open.spotify.com/episode/1b59qRq9vk0hvfa0UiqRm1?si=5f9da0b4cf6545d6Domain 3 Part 2 = https://open.spotify.com/episode/4ncdZBhZEtPCZQYzbLi03m?si=041114030f904c21Domain 3 Part 3 = https://open.spotify.com/episode/3F1S1M8PzVdWMt4egBKFR2?si=dfcdb502cc8049afDomain 4 Part 1 = https://open.spotify.com/episode/6yRGRfpK51II7Od438imNA?si=f94c058f77854f5eDomain 4 Part 2 = https://open.spotify.com/episode/2b3Z8hFII1ypWcVMjqBQlC?si=a16dfb96da6a4addDomain 5 : https://open.spotify.com/episode/1ouhqFPycKwBqMYAF9v4rO?si=u-I7VHQ7Q0CjGmOPfelnSwDomain 6 https://open.spotify.com/episode/0SjIzz6eWO1YKvMg5MVpVK?si=b6980db1afce41a2Domain 7 : https://open.spotify.com/episode/2Ov3RXtw8XMq5R1jJL3o5X?si=2e1bb4ce50fa4516#cisspexam #cissp2026 #CISSP #CISSP2026 #AISecurity #Cybersecurity #aigovernance

  • July 23 · 49 min

    Kudankulam Data Leak Explained | Critical Infrastructure, Vendor Risk & Dark Web Intelligence

    Critical infrastructure may not always be directly attacked.Sometimes, the real risk comes from vendors, contractors, suppliers, hosting providers, exposed credentials, weak access controls, and data leaked through third-party ecosystems.In this podcast episode, Prabh speaks with Rakesh Krishnan, a threat intelligence researcher, about the Kudankulam Nuclear Power Plant-related data exposure discovered on a dark web data leak site operated by the ransomware group World Leaks.00:00 - 01:04 – Highlights01:04 - 02:54 - Introduction, Guest welcome, his credentials and Agenda02:54 – 04:29 - Discovery of the Breach04:29 – 11:16 - Research Motivation and Initial Investigation11:16 – 13:13 - Risk Assessment of Sensitive Data Leaks13:13 – 15:38 - Technical Analysis and Breach Patterns15:38 – 18:26 - Adversary Attack Life Cycles18:26 – 21:47 - Global Threat Landscape and APT Rankings21:47 – 23:10 - Identifying Nationally Sensitive Data23:10 – 28:06 - Geopolitical Data Logic and Intelligence28:06 – 30:35 - Vendor Security and Leadership Lessons30:35 – 35:45 - Offensive Perspective on Data Classification35:45 – 39:12 - Evolution of Ransomware Tactics39:12 – 44:42 - CISO Incident Response and Negotiation44:42 – 48:06 - Technical Rapid Fire48:06 – 49:40 - End of the conversation by thanking Rakesh Krishnan and looking forward to doing more Podcast.The discussion explains that this was not described as a direct attack on Kudankulam Nuclear Power Plant. Instead, sensitive KKNP-related documents were discovered inside a leaked dataset connected to One of the MNC infrastructure data hosted through a third-party data center.This case is important for every CISO, SOC analyst, threat intelligence team, GRC professional, vendor risk manager, and critical infrastructure stakeholder.Why?Because attackers do not always need to breach the main organization directly.They can study leaked vendor records, engineering drawings, supplier layouts, technical specifications, financial documents, and email records to understand the ecosystem around critical infrastructure.Twitter https://x.com/RakeshKrish12Linkedin Profilehttps://www.linkedin.com/in/rakesh-krishnan-6179a94b/Detailed Bloghttps://theravenfile.com/2026/07/17/kudankulam-nuclear-power-plant-leak-an-accidental-disclosure/In this episode, we discuss:- What was discovered in the Kudankulam-related data exposure- Why the incident points toward third-party and vendor ecosystem risk- How ransomware data leak sites operate- How double extortion works- Why exposed engineering drawings and technical records are dangerous- Why compliance does not always mean security- Why critical infrastructure defenders must monitor dark web leak sites- How attackers weaponize leaked supplier and vendor information- Why no data should be considered useless- How data classification must include business, regulated, and operational data- Why CISOs must investigate exposed VPN, RDP, credential, and access patterns- Why ransomware and data-extortion-only cases must be separated during investigation- How insider threat and credential compromise affect critical infrastructure security- What SOC teams should monitor after dark web exposure- Why vendor vetting must go beyond reputation and compliance certificates- What India’s critical infrastructure ecosystem can learn from this caseWhat should organizations improve first — dark web monitoring, vendor risk assessment, data classification, or SOC detection?#kudankulam #Kudankulamdatabreach #Kudankulamsec

  • July 23 · 1 hr 39 min

    How to Implement ISO 27701 in the Real World

    Want to understand how to implement ISO 27701 properly and turn privacy compliance into a working system? In this podcast, we break down the practical implementation of ISO 27701, explain how it relates to ISO 27001, and show how organizations can build a real Privacy Information Management System (PIMS) instead of treating privacy as a one-time compliance exercise.This session covers the structure of ISO 27701, the role of privacy principles, the difference between controllers and processors, and the real steps involved in operationalizing privacy controls across people, process, and technology. It also explores key implementation areas such as data processing assessments, records of processing activity, consent management, privacy impact assessments, vendor risk assessments, cross-border data transfers, training, privacy champions, and continuous monitoring.In this video, you’ll learn:What ISO 27701 is and why it mattersHow ISO 27701 extends ISO 27001 for privacy risk managementThe difference between data controllers and data processorsHow to start a practical PIMS implementationWhy records of processing activity are essentialHow to map privacy controls to regulations like GDPR and DPDPAHow to handle privacy impact assessments and vendor riskWhy privacy implementation takes months, not weeksHow privacy champions, training, and continuous monitoring support long-term complianceThis episode is useful for:privacy professionalsDPOsCISOscompliance leadersGRC teamsISO 27001 practitionersconsultants implementing privacy frameworksWhether you are starting an ISO 27701 implementation, improving your privacy governance model, or trying to align privacy operations with ISO 27001, this discussion gives you a practical roadmap.Data Privacy Professional Videohttps://www.youtube.com/watch?v=76fcelayw00&t=1734s&pp=ygUSZGF0YSBwcml2YWN5IHByYWJo0gcJCQQLAYcqIYzvInterview Serieshttps://www.youtube.com/watch?v=ugHmTNup-ys&list=PL0hT6hgexlYynj0FOvrGCPfiWZFRkMJx4&pp=sAgCGDPR Implementationhttps://www.youtube.com/watch?v=Pf_qQxeubIg&pp=ygUKZ2RwciBwcmFiaA%3D%3DPDPL Implementationhttps://www.youtube.com/watch?v=SgvOkRZgrd0&t=1338s&pp=ygUSZGF0YSBwcml2YWN5IHByYWJoSubscribe for more content on ISO 27701, privacy management, GDPR, data protection, information security governance, and compliance implementation#dataprivacy #iso27701 #cybersecurity #dataprivacyday

  • July 20 · 1 hr 43 min

    How to Pentest LLMs Like a Security Researcher Cybersecurity

    Are LLMs and AI apps really secure? In this podcast, we break down LLM security, prompt injection, LLM penetration testing, and the real vulnerabilities attackers look for when testing AI systems. From reconnaissance and enumeration to payload manipulation and lab-based exploitation, this session shows how traditional web application security testing differs from LLM security testing in real-world environments.Youtube : https://m.youtube.com/@darshanhackzInstagram : https://www.instagram.com/darshanhackzX : https://x.com/darshanhackzSecurity researcher Darshan Naik joins the discussion to explain common LLM vulnerabilities such as prompt injection, hallucinations, excessive agency, information disclosure, insecure integrations, and API misuse. The session also explores how weak validation, poor segmentation, and insecure AI workflows can expose sensitive data or create paths to unauthorized access. Practical examples and lab walkthroughs make the concepts easy to understand for both security professionals and learners.In this video, you’ll learn:How LLM penetration testing is different from traditional web app pentestingHow attackers identify whether a target is using a real LLM or static AIWhat prompt injection looks like in practiceWhy hallucinations, insecure permissions, and excessive agency create riskHow API integrations and AI agents can increase the attack surfaceWhy validation, segmentation, and secure implementation matterHow to use labs and practical exercises to improve AI security testing skillsWhat defenders should do to reduce LLM security vulnerabilitiesThis episode is useful for:penetration testersbug bounty huntersAI security researchersAppSec professionalsred teamersdevelopers building LLM applicationssecurity leaders exploring AI riskWhether you are testing AI chatbots, reviewing LLM security posture, or learning how modern attackers abuse AI systems, this conversation gives you a practical starting point.Subscribe for more content on AI security, LLM hacking, prompt injection, penetration testing, AppSec, and cybersecurity research.GEN AI Securityhttps://www.youtube.com/watch?v=aTJPKifa1VM&t=489s&pp=ygUPZ2VuIGFpIHNlY3VyaXR5#LLMSecurity #PromptInjection #AISecurity #Pentesting #CyberSecurity

Showing 21–24 of 24 episodes