Skip to content
Artwork for Security by Default
TechnologyEducationBusiness

Security by Default

Joseph Carson

Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

Play
  • 20 episodes
  • fortnightly
  • Avg 40 min
  • English
  • S1 · E37
    August 17 · 30 min

    Navigating the Convergence of Physical Security and Digital Access | Daniel

    Daniel Raines, a luminary in the realm of electronic security, shares his extensive journey through the intricate landscape of physical security and digital access. With three decades of experience, he has transitioned from hands-on installation of access control systems to software development, addressing vulnerabilities and enhancing security measures. Our discourse delves into the convergence of physical and digital security, exploring the nuances of vulnerability disclosure and the industry's response to emerging threats. Raines elucidates the complexities of hard-coded encryption keys and the imperative for robust security practices, particularly as the industry shifts towards mobile credentials and biometric solutions. This episode serves as a profound exploration of security's evolving nature, emphasizing the significance of adapting to technological advancements and fostering a culture of continuous learning and improvement. Daniel Raines' extensive career within the electronic security industry, spanning over three decades, serves as a testament to the evolving landscape of physical security and digital access. Initially immersed in the practical aspects of the field, Raines dedicated the first fifteen years to the installation of physical access control systems, including surveillance cameras and biometric solutions. However, he subsequently transitioned into software development, focusing on creating robust systems for access control and security research. This shift was catalyzed by his encounters with software vulnerabilities, which sparked a deep dive into ethical hacking and vulnerability disclosure. Raines' narrative illustrates not only his personal journey but also the critical intersection of physical and digital security, emphasizing the need for improved practices in vulnerability reporting and response within the industry. The discussion between Raines and the host, Joe Carson, delves into the intricacies of vulnerability disclosure in the realm of access control systems. Raines categorizes companies' responses to vulnerability reports into three distinct groups: those that are receptive and proactive, those that provide minimal feedback, and those that are entirely unresponsive. This classification underscores the varying maturity levels within the industry regarding security practices. Furthermore, Raines highlights the pressing issue of hard-coded credentials and encryption keys, which present significant security risks if not adequately addressed. The conversation also touches on the ongoing evolution towards mobile credentials and biometric systems, reflecting a broader trend towards enhancing security while minimizing user friction. Raines' insights serve as a clarion call for greater accountability and proactive measures in safeguarding both physical and digital access points. In a landscape increasingly characterized by the convergence of physical security and digital access, Daniel Raines' experiences and insights illuminate the paramount importance of vigilance and innovation in the electronic security industry. His journey from hands-on installation to software development exemplifies the dynamic nature of the field, where technological advancements continually reshape the strategies employed to secure environments. Raines articulates the necessity of adopting best practices in addressing vulnerabilities, particularly emphasizing the detrimental effects of hard-coded keys and unsecured systems. As the conversation progresses, it becomes evident that the industry is at a pivotal juncture, with a notable shift towards mobile credentials and cloud-based solutions. This transition not only enhances operational efficiency but also raises questions about data privacy and security in the cloud. Raines’ reflections serve as a vital reminder of the ongoing challenges and opportunities within the realm of electronic security, urging both practitioners and organizations to remain proactive in adapting to the evolving landscape. Takeaways: Daniel Raines has accumulated approximately three decades of experience in the electronic security industry, transitioning from hands-on installations to software development. The conversation highlights the critical intersection of physical security and digital access control, illustrating how these domains converge in today's security landscape. Raines emphasizes the importance of ethical vulnerability disclosure practices within the electronic security industry, advocating for responsible reporting of security flaws. As technology evolves, there is a notable shift from traditional physical access methods to more advanced mobile credentials and biometric solutions, enhancing security measures. The discussion reveals that hard-coded encryption keys and default passwords remain prevalent vulnerabilities, underscoring the need for improved security practices in software design. Raines advocates for a proactive learning approach, encouraging individuals interested in security to engage practically with hardware and software to deepen their understanding.

    • Transcript
    • Chapters
  • S1 · E36
    August 3 · 52 min

    L0pht Legend Chris Wysopal on the Evolution of Application Security

    Chris Wysopal, a distinguished figure in the realm of cybersecurity and a celebrated L0pht legend, engages in a profound dialogue with Joe Carson, delving into his remarkable journey from scavenging for Unix manuals to pioneering modern application security. Central to the discussion is the evolution of application security practices, particularly as they pertain to the emergence of artificial intelligence in coding. Wysopal recounts the storied ascent of the L0pht, traversing through pivotal roles at @stake and Symantec, ultimately culminating in the establishment of Veracode. The episode further explores the implications of AI-generated code on security, shedding light on the challenges and opportunities that this technological advancement presents for the cybersecurity landscape today. Listeners are invited to glean insights from Wysopal's extensive experience, which not only reflects on the past but also poses critical questions about the future of cybersecurity practices in an increasingly automated world. Chris Wysopal, a luminary in the realm of cybersecurity, recounts his remarkable journey from the nascent days of hacking to the forefront of application security. He shares anecdotes of his early experiences, such as dumpster diving for Unix manuals and the camaraderie fostered within the L0pht, a hacker collective that became a beacon of innovation and activism in the 1990s. Wysopal's narrative is interspersed with reflections on the evolution of cybersecurity and the societal implications of technology, particularly as he transitioned from the L0pht to @stake and subsequently co-founding Veracode. The conversation delves into the intricacies of application security, the challenges posed by AI-generated code, and the pressing need for a paradigm shift in how security is integrated into the software development lifecycle. This episode is a compelling exploration of Wysopal's contributions to the field and his insights into the future of cybersecurity in an increasingly complex digital landscape. Takeaways: Chris Wysopal's journey illustrates the evolution of cybersecurity from its nascent stages to its current complexity. The transition from the L0pht to Veracode highlights the necessity of adapting to modern security challenges. AI-generated code represents both an advancement and a significant challenge for application security today. Understanding the security landscape requires a holistic approach, integrating hardware, software, and human factors. The importance of early intervention in the software development life cycle for effective security cannot be overstated. Continuous learning and adaptation are essential in the fast-paced field of cybersecurity, especially with emerging technologies.

    • Transcript
    • Chapters
  • S1 · E35
    July 20 · 39 min

    Ransomware Unmasked: Inside the World's Biggest Cybercrime Gang | Geoff White

    The discourse surrounding ransomware takes center stage as we engage with investigative journalist Geoff White, whose extensive research delves into the notorious Conti Ransomware gang. This episode elucidates the profound implications of ransomware attacks, which have escalated beyond mere data encryption to encompass severe extortion tactics that threaten the integrity of personal and organizational data alike. White articulates the critical need for public awareness regarding the mechanisms and repercussions of ransomware, especially in light of recent high-profile attacks that have reverberated across various sectors in the United Kingdom. Furthermore, we explore the intricate dynamics of cybercrime, including the intersection of state-sponsored hacking and organized crime, revealing how these elements coexist and influence one another. In shedding light on the inner workings of the Conti gang, we aim to equip our listeners with the knowledge necessary to navigate this complex and evolving threat landscape effectively. The exploration of ransomware, particularly through the lens of the Conti Ransomware gang, presents a multifaceted narrative that delves into the complexities of modern cybercrime. Investigative journalist Geoff White, known for his extensive work in exposing organized crime and technology intersections, articulates the profound implications of ransomware on both corporate and individual levels. This episode sheds light on the alarming trend where ransomware has transitioned from mere data encryption to more sophisticated extortion tactics. The discussion is framed within the context of recent high-profile attacks on major UK entities, illustrating how these breaches have penetrated public awareness and sparked discourse on cybersecurity. White elucidates the significance of the unprecedented leak of 300,000 internal messages from the Conti gang, offering a rare insight into their operational mechanics and ethical considerations. This leak has unveiled not only their technical strategies but also the internal debates regarding the morality of targeting critical sectors such as healthcare. Such discussions prompt critical reflections on the broader ethical landscape of ransomware, as victims often grapple with the decision to pay ransoms to recover vital data, raising questions about the ramifications of empowering criminal enterprises. The conversation further enriches the understanding of ransomware's intertwining with traditional organized crime, showcasing how the financial flows from ransomware operations can fuel various illicit activities. White and host Joe Carson emphasize the necessity of enhancing public awareness and education on these issues, advocating for proactive measures that would empower individuals and organizations alike to recognize and combat ransomware threats. As ransomware evolves, the episode serves as a crucial reminder of the collective responsibility to foster a more informed society, one that is equipped to navigate the increasingly complex landscape of cyber threats. Takeaways: Geoff White elucidates the complexities of ransomware, particularly focusing on the notorious Conti gang, and its multifaceted impact on both businesses and individuals. The podcast reveals how ransomware attacks have evolved from mere data encryption to sophisticated extortion schemes that threaten to disclose sensitive information. Listeners gain insight into the significance of the Conti leaks, which provided unprecedented access to the inner workings of a leading ransomware organization. The narrative emphasizes the necessity for public awareness and education regarding ransomware, as its implications extend far beyond the realm of cybersecurity professionals. Geoff White discusses the intersection of financial crime and cybercrime, highlighting how ransomware profits are integrated into broader illicit financial networks. The episode underscores the importance of vigilance among employees and citizens alike in recognizing phishing attempts and other cyber threats that facilitate ransomware attacks. Links referenced in this episode: https://www.bbc.co.uk/programmes/p0ntv7bv https://geoffwhite.tech/ https://www.youtube.com/playlist?list=PLz_B0PFGIn4ccgXclIq9gdmf_nFNz-Og8

    • Transcript
    • Chapters
  • S1 · E34
    July 7 · 33 min

    The Voice of the Customer: Why Listening Beats Selling with David Muniz

    The paramount focus of this podcast episode is the critical necessity of amplifying the voice of the customer in the contemporary business landscape. I engage in a profound dialogue with David Muniz from Segura, exploring the integral role that understanding customer pain points plays in the provision of effective solutions. We delve into the importance of listening attentively to customers, rather than hastily advancing towards solutions based on assumptions. This conversation elucidates the vital connection between customer feedback and organizational success, emphasizing that a true comprehension of customer needs fosters trust and enhances the overall customer experience. As we navigate this insightful discourse, we uncover best practices and strategies for harnessing customer feedback to drive meaningful engagement and ultimately, success in the marketplace. David Muniz, a seasoned professional from Segura, joins the Security by Default podcast to delve into the significance of the customer's voice in shaping business strategies and solutions. The discourse initiates with an exploration of the fundamental need for businesses to prioritize understanding the customer's unique challenges and pain points before hastily proposing solutions. Muniz articulates that an effective customer success strategy hinges upon the ability to listen actively and empathetically to clients, thereby enabling organizations to tailor their offerings to meet the specific needs of their clientele. Through a series of poignant examples and insights gained from his extensive experience in customer relations, Muniz emphasizes that fostering a genuine connection with customers not only enhances the overall experience but also cultivates loyalty and trust within the marketplace. As the conversation unfolds, Muniz elaborates on the necessity of balancing analytical frameworks with qualitative insights derived from direct customer interactions. He stresses that while market analysts provide valuable data, the true essence of customer satisfaction can only be gleaned through personal engagement and understanding of the client's narrative. The dialogue further emphasizes that the voice of the customer should not merely be an afterthought in product development but rather a cornerstone of the strategic planning process. This perspective is supported by statistical data indicating that customers who feel heard and valued are more likely to renew their contracts and engage more deeply with the brand. In conclusion, the episode encapsulates a compelling argument for integrating the voice of the customer into every facet of business operations, thereby ensuring that organizations remain not only relevant but also deeply connected to the communities they serve. Muniz's insights serve as a clarion call for businesses to adopt a customer-centric approach, which ultimately leads to enhanced satisfaction, long-term relationships, and sustainable success in an increasingly competitive landscape. Takeaways: The voice of the customer is paramount in understanding their unique challenges and needs. Effective customer success strategies require active listening to ensure customer voices are heard and valued. Building trust with customers is essential for fostering long-term relationships and achieving mutual success. Proactive engagement with customers allows organizations to anticipate their needs and provide tailored support effectively. Customer feedback should influence product development and service improvements to align better with user expectations. Utilizing peer insights can significantly enhance the decision-making process for prospective customers, validating their choices. Links referenced in this episode: Segura David Muniz Gartner Forrester Cosmos Choice Companies mentioned in this episode: Security Segura Gartner Forrester

    • Transcript
    • Chapters
  • S1 · E33
    June 23 · 43 min

    Why Identity Is Becoming Every CISO's Biggest Challenge | Vlad Shapiro

    Vlad Shapiro, a distinguished mathematician turned identity management expert, articulates his transformative journey in this episode, offering profound insights into the intersection of identity and business. He elucidates how the realm of identity has evolved into a critical pillar for organizational functionality, emphasizing that without effective identity management, business operations may falter. Our discussion delves into the implications of this evolution, particularly the necessity for board members to prioritize identity governance alongside traditional business strategies. Furthermore, we explore the pressing gaps within the current identity landscape, including the challenges posed by a lack of standardization and the imperative for innovative thinking to navigate an increasingly complex digital environment. Shapiro's reflections not only highlight the significance of identity management in contemporary business but also underscore the need for a collaborative approach that integrates technological advancements with ethical considerations for future generations. In this episode of the Security by Default podcast, host Joe Carson engages with Vladislav Shapiro, who shares his journey from a mathematician to an identity management expert. They discuss the evolution of identity management, its growing importance in business, and the innovations shaping the future of identity technology. The conversation emphasizes the need for a business-oriented approach to identity, the gaps in current practices, and the ethical considerations in technology development. In this conversation, Joseph Carson and Vladislav Shapiro explore the complexities of AI governance, drawing parallels with nuclear energy management. They discuss the importance of control mechanisms, the role of identity in AI, and the emerging threats related to computational workload theft. The conversation emphasizes the need for continuous learning in a rapidly evolving technological landscape and the significance of visibility in understanding both good and bad actors in the AI space. The dialogue between Joe Carson and Vlad Shapiro unfolds a captivating narrative that chronicles Vlad's evolution from an accomplished mathematician to a distinguished identity management expert. Vlad's journey is steeped in serendipity and introspection, illustrating the transformative power of career shifts propelled by the dynamics of professional landscapes and personal revelations. As he delves into his past, Vlad reflects on his academic pursuits in Ukraine and his subsequent migration to the United States, where he initially aspired to teach mathematics at a university level. However, as he navigated the academic landscape and its stark contrasts to European standards, he pivoted towards industry, seeking avenues to apply his analytical skills in a pragmatic context. The discussion transitions into a broader exploration of the identity management sector, a field that has burgeoned in significance over recent years. Vlad articulates the paradigm shift that identity management has undergone, now recognized as a critical business function rather than merely an IT concern. The conversation delves into the intricacies of identity governance, emphasizing the need for organizations to reconsider how they manage identity in a world increasingly reliant on digital interactions. Vlad's insights on the intersection of identity management and business strategy underscore the imperative for organizations to engage with this evolving landscape, reflecting on how identity impacts operational efficiency and risk management. As the episode progresses, Vlad shares his perspectives on contemporary challenges within the identity management domain, notably the importance of interoperability among diverse systems and the necessity for organizations to adapt to a rapidly evolving technological environment. His reflections on the ethical dimensions of identity management, particularly concerning data privacy and consumer trust, resonate deeply within the ongoing discourse surrounding digital identities. This episode serves as a profound reminder of the critical role that identity management plays in shaping secure and efficient organizational practices, and it encapsulates the wisdom gleaned from Vlad's unique journey through the realms of mathematics and identity management. Takeaways: Vlad Shapiro's transition from a trained mathematician to an identity management expert showcases the fluidity of career paths in the technology sector. The evolution of identity management has transformed it into a critical business function, emphasizing its integral role in organizational security and efficiency. Understanding identity as a business imperative rather than merely a technical challenge is essential for engaging stakeholders and achieving strategic alignment. The importance of fostering a culture of curiosity and continuous learning is paramount in the ever-evolving landscape of identity management and cybersecurity. Innovations in identity management must prioritize interoperability to ensure seamless integration across diverse systems and platforms. The conversation around identity management now encompasses ethical considerations, prompting a reevaluation of policies to mitigate risks associated with technological advancements.

    • Transcript
    • Chapters
  • S1 · E32
    June 9 · 42 min

    How Hackers Attack AI: The New Battle to Secure Intelligent Machines | Harriet Farlow

    This podcast episode delves into the intricate nexus of artificial intelligence and security, featuring an enlightening conversation with Harriet, the author of a newly released book Practical AI Security. We explore her compelling journey from a background in physics and anthropology to becoming a pivotal figure in the realm of cybersecurity, particularly focusing on the challenges posed by adversarial machine learning. Harriet elucidates the pressing necessity for organizations to comprehend and mitigate the security vulnerabilities inherent in AI systems, as well as the broader implications for national security. Our discourse also addresses the critical need for collaboration between cybersecurity professionals and AI developers to ensure that security considerations are embedded within AI design from the outset. Ultimately, we aim to provide our audience with a profound understanding of the evolving landscape of AI security and the imperative of safeguarding these transformative technologies. 🎙️ Security by Default Podcast Practical AI Security: Attacking, Defending, and Securing the Future of AI With Harriet Farlow — Founder of Mileva Security Labs & Author of Practical AI Security Artificial Intelligence is transforming the way we build technology, automate decisions, analyze data, and solve some of the world’s biggest challenges. But as AI becomes more powerful and more deeply embedded into our lives, one critical question becomes increasingly important: How do we secure AI itself? In this episode of Security by Default, host Joseph Carson is joined by Harriet Farlow, AI security researcher, founder of Mileva Security Labs, and author of “Practical AI Security: A Hands-On Guide to Attacking, Defending, and Securing Modern AI Systems.” Together they explore the rapidly evolving world of AI security, adversarial machine learning, and why understanding how AI works is essential before we can protect it. About This Episode AI is often described as the next technological revolution, but securing AI requires us to rethink many traditional cybersecurity approaches. Unlike conventional software, AI systems are built on data, probability, optimization, and learning models. They do not always fail in predictable ways, and vulnerabilities are not always solved with a simple patch. Harriet shares her fascinating journey from studying physics and anthropology to working in data science, national security, and artificial intelligence, eventually discovering the world of adversarial machine learning — where attackers attempt to manipulate and disrupt AI systems themselves. This conversation goes beyond the hype and explores what defenders, developers, and organizations need to understand as AI becomes a critical part of modern technology. What You Will Learn 🤖 Why AI Security Matters More Than Ever AI is becoming part of software development, business operations, healthcare, finance, critical infrastructure, and cybersecurity itself. As adoption accelerates, organizations must move beyond simply asking: “How can we use AI?” and start asking: “How do we secure AI?” 🧠 Understanding How AI Really Works Harriet explains why machine learning systems are fundamentally different from traditional software. AI systems are: Probabilistic rather than deterministic Dependent on training data quality Designed around optimization Continuously influenced by changing environments Understanding these foundations is essential for anyone responsible for protecting AI. 🔓 The World of Adversarial Machine Learning What happens when attackers stop targeting only applications and infrastructure… …and start targeting the AI model itself? The episode explores: Model manipulation Data poisoning AI weaknesses Training challenges Unexpected behaviors The difficulty of understanding model decisions 🛠️ How Do You Patch AI? One of the biggest questions facing cybersecurity professionals today: If AI learns something wrong, how do we fix it? Traditional security follows a familiar process: Find vulnerability → Apply patch → Reduce risk AI changes that. Sometimes protecting AI is not about fixing code. It is about understanding and correcting behavior. ⚔️ AI for Security vs Security for AI For years, organizations have focused on using AI to improve cybersecurity. But now the challenge has expanded. Cybersecurity needs AI. But AI also needs cybersecurity. As AI becomes part of everyday systems, security teams must understand how to protect the models, data, and decisions that organizations rely on. 🌍 Why AI Security Requires Different Skills The future of AI security requires collaboration between: Cybersecurity professionals AI engineers Data scientists Researchers Risk leaders Policy experts Building trustworthy AI means bringing these worlds together. Security must be part of AI from the beginning. Key Topics Discussed 🔹 Harriet’s journey from physics and anthropology into AI security 🔹 Working in data science and national security environments 🔹 Discovering adversarial machine learning 🔹 Founding Mileva Security Labs 🔹 Writing Practical AI Security with No Starch Press 🔹 Why AI vulnerabilities are different from software vulnerabilities 🔹 The importance of data quality and model training 🔹 Understanding probability and machine learning foundations 🔹 How attackers target AI systems 🔹 Why securing AI requires a new mindset 🔹 The future of AI safety and cybersecurity 🔹 Staying updated in a fast-moving industry 🔹 Building responsible and secure AI systems Memorable Quotes 💬 “Before we can secure AI, we first need to understand how it works.” 💬 “AI security is not always about fixing a bug. Sometimes it is about correcting a behavior.” 💬 “Cybersecurity needs AI, but AI also needs cybersecurity.” 💬 “The future is not just about building smarter AI — it is about building safer AI.” Episode Chapters 00:00 – Introduction to Security by Default 01:03 – Harriet Farlow’s origin story 04:28 – From data science to cybersecurity 08:48 – Creating Mileva Security Labs 10:51 – Conferences, community, and writing Practical AI Security 17:28 – How AI has evolved 19:43 – Understanding machine learning models 21:43 – The challenge of patching AI systems 23:37 – Training data, quality, and user impact 25:23 – Why AI models can be difficult to understand 27:36 – AI and cybersecurity coming together 30:18 – Why AI fundamentals matter 32:04 – Practical examples and real-world AI security 33:38 – Staying updated in AI security 36:27 – Learning from the AI security community 38:08 – Ethics and responsible AI development Guest Harriet Farlow Founder — Malevra Security Labs Author — Practical AI Security 🔗 LinkedIn: https://www.linkedin.com/in/harriet-farlow-654963b7/ 📘 Practical AI Security — No Starch Press https://nostarch.com 🎓 AI Fundamentals Course https://harriethacks.com/course/ Listen & Subscribe 🎧 Security by Default Podcast Exploring the people, stories, and ideas helping make technology safer. Because security should not be an afterthought. Security should be by default. #SecurityByDefault #AISecurity #Cybersecurity #ArtificialIntelligence #MachineLearning #AdversarialML #AI #ResponsibleAI #SecurityResearch Takeaways: The podcast episode discusses the importance of understanding AI security in the context of national security and its implications. Harriet's journey from a background in physics and anthropology to her current role in AI security demonstrates the interdisciplinary nature of the field. The conversation highlights the necessity for collaboration between AI developers and cybersecurity professionals to ensure secure AI systems. Listeners are encouraged to engage with various resources to stay informed about the rapidly evolving landscape of AI and cybersecurity. The significance of addressing the ethical considerations in AI development is emphasized throughout the discussion, focusing on empowering rather than replacing human effort. The episode underscores the idea that AI security is not merely about using AI for cybersecurity but also about securing AI systems from external threats.

    • Transcript
    • Chapters
  • S1 · E31
    May 26 · 36 min

    AI Is Not Magic: The Truth Behind the Technology Changing Everything | Diana Kelley

    This podcast episode elucidates the evolution of artificial intelligence, particularly focusing on the transition from earlier models such as ELIZA and Watson to contemporary systems like ChatGPT and Claude. Our discussion emphasizes the importance of understanding the context and limitations of AI, as well as the implications of its rapid advancement on our professional landscape. We delve into the nuances of prompt engineering and the necessity of training AI models to interpret context effectively, which has become increasingly pivotal in their application. Furthermore, we address the societal concerns regarding job displacement in the wake of AI proliferation, positing that while certain roles may be rendered obsolete, new opportunities will arise, necessitating continuous adaptation and retraining. Ultimately, our dialogue aims to provide clarity amidst the complexities of AI technology, underscoring the imperative for informed engagement with these transformative tools. In this episode of the Security by Default podcast, host Joe Carson welcomes Diana Kelley, a prominent figure in the tech industry, to discuss her journey in technology, the evolution of AI, and its implications for cybersecurity and the job market. They explore the historical context of AI, from early systems like ELIZA to modern advancements like Watson and ChatGPT, and address common misconceptions about AI's capabilities. The conversation also delves into the future of jobs in an AI-driven world, emphasizing the need for training and understanding of AI technologies. In this conversation, Joseph Carson and Diana Kelley discuss the evolution of jobs in the context of technological advancements, particularly focusing on AI and its implications for the workforce. They explore the necessity of continuous retraining and the emergence of new roles, the importance of contextual understanding in AI, and the behavior of AI agents. Additionally, they emphasize the need for control mechanisms in AI development and the importance of empowering women in cybersecurity to address the growing challenges in the field. Takeaways The podcast aims to bring clarity and transparency to the chaos in the tech world. Diana Kelley has a rich history in technology, starting from the DARPAnet in the 1970s. ELIZA was one of the first AI systems, designed to emulate a therapist. Watson's success in Jeopardy was due to its speed, not intelligence. AI's interaction with humans can lead to misconceptions about its capabilities. Chain of thought prompting has improved AI's problem-solving abilities. AI is a probability machine, not a sentient being. Training is essential for effective AI usage. The evolution of AI has implications for job security and creation. Legacy systems still require human oversight and expertise. The jobs we have today are constantly evolving due to technology. Retraining is essential to stay relevant in the workforce. AI will create new job opportunities in various fields. Understanding context is crucial for effective AI interaction. Prompt engineering is a vital skill in working with AI models. Control mechanisms are necessary for managing AI behavior. Empowering women in cybersecurity is critical for the industry's future. Community support is essential for fostering diversity in tech. Continuous learning is key to adapting to technological changes. Networking and mentorship play a significant role in career development. Chapters 00:00 Introduction to the Podcast and Guest 01:01 Diana Kelley's Journey in Tech 04:56 The Evolution of AI: From ELIZA to Watson 10:14 AI in Cybersecurity: Training Watson for Cyber 14:03 Understanding AI: Human-like Interaction and Misconceptions 16:33 Advancements in AI: Chain of Thought Prompting 20:11 The Future of Jobs in the Age of AI 21:20 The Evolution of Jobs and Skills 23:51 AI and Human Interaction 27:06 Contextual Understanding in AI 29:56 Agent Behavior and Control 32:58 Staying Informed in a Rapidly Changing Field 36:07 Empowering Women in Cybersecurity Resources & Links: ELIZA - Joseph Weizenbaum's AI Program Diana Kelley - LinkedIn OWASP GenAI Project Women in Cybersecurity (WiCyS) IBM Watson OpenAI GPT Models Anthropic's Claude Connect with Diana Kelley: LinkedIn Enjoy this insightful conversation on the past, present, and future of AI and cybersecurity, highlighting the balance between innovation and responsible deployment. The discourse conducted in the latest installment of the Security By Default podcast presents a profound exploration of the evolution of artificial intelligence (AI) and its consequential implications within the cybersecurity domain. The host, Joe Carson, alongside esteemed guest Diana Kelly, embarks on a reflective journey that traverses the historical underpinnings of AI, commencing with early innovations such as the DARPA Net and the pioneering chatbot Eliza, which simulated therapeutic conversation. As the conversation unfolds, they elucidate the transformative journey of AI from rudimentary systems to contemporary models like IBM's Watson and emergent generative AI technologies. The dialogue is rich with insights on how these advancements not only augment human capabilities but also necessitate a reevaluation of cybersecurity protocols, particularly in the context of AI's dual potential for both beneficial applications and nefarious exploits. Through this enlightening exchange, the episode instills a nuanced understanding of the need for responsible AI usage, emphasizing the importance of training and ethical considerations in the burgeoning field of AI-driven technologies. Takeaways: In this episode, we explore the evolution of AI technologies from early models like Eliza to modern systems such as Claude and ChatGPT, discussing their implications and societal impacts. The podcast emphasizes the importance of understanding the context in which AI operates, highlighting that these models do not possess true intelligence or decision-making capabilities. We address the urgency of educating users about responsible AI use, advocating for training requirements that ensure individuals comprehend the limitations and potential risks associated with these technologies. The discussion includes insights on the future of the workforce, particularly on how AI may transform job roles while also creating new opportunities for skilled professionals. We reflect on the historical significance of AI advancements, illustrating how past innovations inform our current understanding and utilization of machine learning algorithms. The episode concludes with a call to action for listeners to engage with AI thoughtfully, encouraging them to remain informed and proactive in adapting to the rapidly changing technological landscape.

    • Transcript
    • Chapters
  • S1 · E30
    May 12 · 37 min

    Why Cybersecurity Fails Without Trust: The Human Side of Defense | JC Vega

    This podcast episode elucidates the critical importance of effective communication and leadership within the realm of cybersecurity. We engage in a profound discussion with JC Vega, who shares his extensive background in both operational security and cybersecurity, emphasizing the necessity of translating complex technical concepts into relatable business language. We explore the pivotal role of leaders in fostering a secure organizational environment, underscoring that cybersecurity is not merely an IT concern, but an enterprise-wide imperative that encompasses every facet of an organization's operations. The conversation further delves into strategies for empowering champions within organizations to advocate for security practices, thus ensuring that everyone understands the significance of their roles in safeguarding the enterprise. Ultimately, we aspire to convey that a collaborative, informed approach is essential in navigating the complexities of today's security landscape, thereby enhancing both individual and organizational resilience. In this episode, cybersecurity expert JC Vega shares insights on effective communication, leadership, and risk management in cybersecurity. He emphasizes the importance of translating technical concepts for business leaders, building trust, and fostering community to enhance organizational resilience. keywords cybersecurity, leadership, risk management, communication, trust, community, organizational resilience, cybersecurity education keytopics Translating cybersecurity for non-technical audiences Building champions within organizations The importance of trust and verification in security Cybersecurity as an enterprise survival issue Leveraging AI and technology responsibly sound bites "Validate and verify, don't just trust." "Train like it's a Super Bowl." "Leave a link, build a community." Chapters 00:00 Introduction to Cybersecurity Leadership 02:34 Translating Cybersecurity for Non-Technical Audiences 05:13 Building a Team of Champions 08:02 Understanding Business Impact and Risk 10:39 The Role of AI in Cybersecurity 12:58 Cybersecurity as an Enterprise Survival Problem 15:21 The Importance of Ecosystem Relationships 18:00 Trust and Zero Trust in Cybersecurity 20:28 Continuous Learning and Community Engagement resources Cyber Cannon Project - https://cybercannonproject.org/ B-Sides Conferences - https://www.bsidescon.org/ LinkedIn Profile of JC Vega - https://www.linkedin.com/in/jcvega/ Takeaways: The podcast emphasizes the necessity of translating complex cybersecurity concepts into practical business language for effective communication. I believe that strong relationships with champions within organizations are crucial for cybersecurity success and operational resilience. Our discussion highlights the importance of understanding the operational goals of various stakeholders to better address their cybersecurity needs. We advocate for the continuous evolution of skills and knowledge within the cybersecurity field through collaboration and community engagement.

    • Transcript
    • Chapters
  • S1 · E29
    April 28 · 19 min

    Can AI Beat Hackers? The Future of Cyber Training Has Changed | Hack The Box

    The eminent discourse of this podcast episode delves into the pivotal role of artificial intelligence in the contemporary cybersecurity landscape, underscoring the symbiotic relationship between AI and human expertise. I, Joseph Carson, engage in a compelling conversation with Gerasmus, a distinguished figure from Hack the Box, as we explore the transformative impact of AI on both offensive and defensive cybersecurity strategies. Our dialogue illuminates the necessity for practitioners to adapt and evolve their skill sets in tandem with rapid technological advancements, highlighting the significance of platforms such as Hack the Box in fostering a culture of continuous learning and practical application. We further examine the implications of AI governance and the emergence of agentic AI as a potential risk factor, urging a meticulous approach to data management and security protocols. Ultimately, this episode serves as a clarion call for cybersecurity professionals to embrace innovation while preserving the essential human element in safeguarding digital infrastructures. In this special edition recorded live at RSA Conference, Joseph Carson is joined by Gerasimos Marketos (gmar), Chief Product Officer at Hack The Box. They explore how AI is reshaping cybersecurity skills, why traditional education is struggling to keep up, and how hands-on platforms are redefining how defenders and ethical hackers are trained. From real-world fraud detection to AI-powered CTF competitions, this episode dives into the evolving relationship between humans and machines in cybersecurity. 🔑 Key Themes & Topics AI vs Humans in cybersecurity competitions Why AI is an accelerator, not a replacement The evolution from traditional training → hands-on gamified learning Closing the cybersecurity skills gap Red, Blue, and Purple team upskilling AI governance, risk, and agentic threats The future of cybersecurity careers and hiring ⏱️ Chapters 00:00 – Introduction & RSA Conference insights 02:00 – GMar’s journey: Data → Fraud → Cybersecurity 06:30 – Who and What is Hack The Box? 10:30 – AI vs Humans: CTF research findings 13:00 – AI as a productivity multiplier 15:30 – Real-world example: AI winning competitions 16:00 – RSAC trends: AI everywhere 17:00 – AI governance & emerging risks 18:00 – AI for security vs security for AI 19:00 – Staying relevant in cybersecurity 🚀 Hack The Box Explained Hack The Box is a cybersecurity upskilling platform offering: 🎓 Academy – Structured learning paths 🧩 Challenges & Labs – Hands-on environments 🏁 CTFs (Capture The Flag) – Competitive exercises 🏢 Pro Labs – Enterprise-scale simulations 🔎 Talent Search – Connecting skilled professionals with employers It supports: Red Teams (Offense) Blue Teams (Defense) Purple Teams (Collaboration) Resources: https://www.hackthebox.com/ https://www.linkedin.com/in/gmarketos/ https://www.hackthebox.com/ai-augmented-cyber-workforce-report Takeaways: In our latest episode, we explored the symbiotic relationship between artificial intelligence and cybersecurity, highlighting their mutual dependence. The insights gathered from the RCC conference emphasize the necessity of integrating AI to enhance cybersecurity measures effectively. We discussed the evolution of Hack the Box, illustrating its transition from a challenge-based platform to a comprehensive cybersecurity training ecosystem. The significance of continuous learning in cybersecurity was underscored, particularly in light of rapidly advancing AI technologies and their implications. We examined the results of our recent CTF events, showcasing how AI agents can enhance human capabilities in cybersecurity tasks and competitions. Lastly, we asserted the importance of maintaining foundational skills in cybersecurity, even as AI tools become increasingly prevalent in the industry. Links referenced in this episode: hackthebox.com Companies mentioned in this episode: Segura Hack the Box

    • Transcript
    • Chapters
  • S1 · E28
    April 14 · 40 min

    Behind the Scenes: How Cybersecurity Decisions Really Get Made | Fernando Montenegro

    Fernando Montenegro, a distinguished industry analyst in cybersecurity, articulates the pivotal best practices that analysts should adopt to navigate the complexities of the cybersecurity landscape effectively. Throughout our discourse, he elucidates the necessity for analysts to function as intermediaries among various stakeholders, including buyers, sellers, and investors, thus facilitating informed decision-making processes. Montenegro emphasizes the importance of clarity in communication, advocating for an open-minded approach during analyst interactions to maximize the value derived from these engagements. He further discusses the strategic implications of cybersecurity decisions, urging organizations to appreciate the multifaceted influences that shape their security postures. Ultimately, this episode serves as an invaluable resource for professionals seeking to enhance their analytical practices within the rapidly evolving cybersecurity domain. In this episode, Fernando Montenegro shares his journey into the cybersecurity industry, insights on industry analysis, and the evolving trends shaping cybersecurity today. Discover how analysts bridge the gap between vendors, buyers, investors, and academia, and learn practical tips for engaging effectively with industry experts. key Takeaways Role of industry analysts in cybersecurity Emerging trends in cybersecurity including AI and attack surface expansion Effective engagement with analysts for decision support Strategic cybersecurity budgeting and investment Influence of economics and incentives on security decisions sound bites "Understanding what's going on in the world" "Good enough security can be effective" "Workload AI versus workforce AI" Chapters 00:00 Introduction to Security by Default Podcast 00:53 Fernando Montenegro's Origin Story 05:16 The Role of an Industry Analyst 08:55 Maximizing Value from Analyst Interactions 13:16 Understanding AI in Conversations 15:44 Choosing the Right Solutions 16:40 Decision-Making in Technology and Business 17:13 Trends in Cybersecurity and AI 18:26 Understanding Workload vs. Workforce AI 19:40 The Evolving Role of Security Professionals 21:43 The Strategic Importance of Cybersecurity 23:58 Incentives and Decision-Making in Security 25:53 The Shift Left Approach in Development 27:16 Budgeting for Cybersecurity Investments 30:47 Navigating Cybersecurity Budgets 32:26 Engaging with Analysts and Staying Informed 34:33 Curating Information in a Data-Driven World 36:55 Balancing Operational and Strategic Insights 37:51 Connecting with Analysts and Final Thoughts Resources LinkedIn Profile of Fernando Montenegro - https://www.linkedin.com/in/fsmontenegro/ Futurum Group - https://futurumgroup.com/ Obsidian Knowledge Management System - https://obsidian.md/ Book: Why Most Security Budgets Go to Waste by Ross Young - https://a.co/d/02BZPwdO In this thought-provoking episode, Fernando Montenegro imparts his extensive expertise on the best practices for analysts within the cybersecurity industry. He begins by delineating the multifaceted role of an analyst, which encompasses serving as a conduit for communication between buyers, sellers, investors, and other relevant stakeholders. By elucidating the distinct motivations and concerns of each group, Fernando illustrates how analysts can effectively tailor their insights and recommendations, thereby enhancing the decision-making process for all parties involved. The dialogue further explores the significance of maintaining an open-minded approach during analyst interactions, as well as the necessity for analysts to remain well-informed about emerging trends and challenges in the cybersecurity landscape. Fernando identifies several pivotal trends, including the integration of artificial intelligence, the expansion of the attack surface, and the transition towards a more resilient approach to data protection. Each of these trends reflects the evolving priorities of organizations as they seek to mitigate risks and enhance their security postures. Through this episode, listeners are not only provided with actionable insights into the workings of an industry analyst but are also encouraged to consider the broader implications of their roles in shaping cybersecurity strategies. As Fernando articulates, the responsibility of analysts extends beyond mere data analysis; they must also facilitate meaningful dialogue among stakeholders to drive informed decisions that bolster organizational security in an increasingly complex digital landscape.

    • Transcript
    • Chapters
  • S1 · E27
    March 31 · 46 min

    Can We Make Cybersecurity Fun Again? Turning Fear Into Action | Gary Berman

    This podcast episode delves into the imperative of transforming the often daunting landscape of cybersecurity into a realm of engagement and enjoyment. I, Joe Carson, alongside my esteemed guest Gary, explore how the prevailing culture of fear, uncertainty, and doubt (FUD) can be supplanted by a more vibrant and playful approach. We discuss the significance of fostering a sense of community and support within the cybersecurity field, emphasizing the need to celebrate successes and share positive narratives that can inspire both professionals and newcomers alike. The conversation further highlights innovative methods such as gamification and the incorporation of storytelling to make cybersecurity training more accessible and enjoyable. Ultimately, we aim to ignite a movement that not only safeguards our digital environments but also rekindles the joy and creativity that can be found within this vital industry. Join cybersecurity expert Joseph Carson and guest Gary as they explore innovative ways to make cybersecurity engaging, fun, and accessible. Discover how humor, storytelling, and community involvement can transform the industry and attract new talent. Chapters 00:00 Welcome to the Cybersecurity Chaos 02:32 From Fear to Fun in Cybersecurity 05:27 The Journey of a Cyber Advocate 08:09 The Importance of Community and Collaboration 10:45 Bringing Laughter Back to Cybersecurity 13:13 Rebranding Cybersecurity for New Talent 16:00 The Power of Words in Cybersecurity 18:43 Innovative Approaches to Cyber Awareness 21:29 Lessons from Kids: Simplifying Cybersecurity 24:39 The Inner Child and Cognitive Dissonance 26:40 Gamification and Learning Innovations 28:19 Storytelling in Cybersecurity 29:15 Cybersecurity Starts at Home 30:36 Community Engagement and Employee Connection 32:14 The Importance of Acknowledgment 34:13 Finding Joy in Everyday Life 35:11 Humor as a Coping Mechanism 40:04 The Power of Positive Thinking 45:02 Mission Accomplished: Fun and Safety Resources Cyber Heroes Comics - https://cyberheroescomics.com/ Gary's LinkedIn Profile - https://www.linkedin.com/in/gary-berman/ The discourse presented in this episode unveils the intricate relationship between cybersecurity and the often overwhelming sense of fear, uncertainty, and doubt (FUD) that pervades the industry. I, Joe Carson, alongside our distinguished guest Gary, delve into the necessity of transforming the cybersecurity narrative from one steeped in anxiety to a more palatable and enjoyable experience. Gary, who identifies himself as the 'Forrest Gump of cybersecurity,' shares his unique journey into this field, characterized by serendipitous encounters with influential figures and organizations. His advocacy for making cybersecurity engaging is pivotal; he emphasizes the importance of humor and creativity in addressing serious issues that often deter potential talent from entering the field. This conversation highlights the vital need to celebrate successes and communicate effectively, ensuring that cybersecurity is perceived not merely as a defensive measure but as an exciting and essential component of modern society. As our discussion unfolds, we explore the concept of gamification in cybersecurity training, an innovative approach aimed at enhancing engagement and retention of critical security practices. We reflect on the common tendency to focus predominantly on the negative aspects of cybersecurity incidents, neglecting the positive outcomes and triumphs that deserve recognition. By employing storytelling techniques and leveraging humor, we can reshape the perception of cybersecurity, making it accessible and relatable to a broader audience. The episode culminates in a call to action for industry professionals to foster a culture of positivity and collaboration, thereby transforming the cybersecurity landscape into one that is not only secure but also inviting and enjoyable for all. In conclusion, this episode serves as a clarion call for change within the cybersecurity domain. We advocate for the rebranding of cybersecurity from an intimidating realm to one that is engaging, fun, and inclusive. By embracing creativity and humor, we can attract new talent and invigorate the existing workforce, ensuring a robust defense against the ever-evolving landscape of cyber threats. Join us as we embark on this journey of transformation, aiming to illuminate the path ahead in the fascinating world of cybersecurity, where safety and enjoyment can coexist harmoniously. Takeaways: The podcast emphasizes the necessity of transforming the often fear-driven narrative surrounding cybersecurity into something more engaging and enjoyable for audiences. Through humor and storytelling, we can effectively communicate complex cybersecurity concepts, making them accessible to a broader audience, including children and families. The discussion highlights the importance of celebrating successes within cybersecurity, as these achievements often go unrecognized, leading to a narrative dominated by fear and negativity. The idea of rebranding cybersecurity as a fun and engaging field is critical for attracting new talent, especially in an era where other industries appear more appealing and entertaining.

    • Transcript
    • Chapters
  • S1 · E26
    March 17 · 45 min

    Inside Modern Cyber Warfare: The Invisible Battles Happening Every Day | Chris Kubecka

    This podcast episode delves into the intricate interplay between global politics, cybersecurity, and the evolving nature of threats faced by critical infrastructure. Our esteemed guest, Chris, shares his compelling journey from early experiences with technology to significant roles in safeguarding vital systems against sophisticated cyber threats. Notably, the discussion illuminates the transformation of cyber warfare, highlighting the emergence of physical attacks that disrupt both digital and physical infrastructures. We also examine collaborative efforts among nations to fortify defenses against such challenges, emphasizing the necessity of cooperation in the face of rising geopolitical tensions. As we navigate this complex digital landscape, it becomes increasingly apparent that a unified approach is paramount to ensuring our collective security and resilience in an interconnected world. Join Joseph Carson in this insightful episode as he interviews cybersecurity expert Chris Kubecka. They discuss critical infrastructure security, cyber warfare, geopolitical risks, and the evolving landscape of digital threats, providing valuable lessons for cybersecurity professionals and policymakers. Key Topics Cybersecurity in critical infrastructure Geopolitical cyber threats and hybrid warfare Evolving landscape of digital threats and resilience Sound bites "GPS jamming has been a massive challenge." "Digital Empires: China, Europe, and the US." "Radio communications are a vital fallback." Chapters 00:00 Introduction and Background of Chris Kubecka 01:37 Cybersecurity Challenges in Critical Infrastructure 03:37 Evolving Nature of Cyber Threats 05:45 The Role of Drones in Modern Warfare 07:25 Hybrid Warfare and Global Diplomacy 10:10 The Shift in Global Cybersecurity Dynamics 12:18 The Importance of International Cooperation 14:33 Privacy and Ethics in Cybersecurity 16:50 Historical Context and Regional Cooperation 18:55 Cyber Attacks on Civilian Infrastructure 22:04 Personal Experiences in Estonia 24:10 Geopolitical Tensions and Cybersecurity 25:52 Challenges in Maritime Connectivity 28:16 Critical Infrastructure Vulnerabilities 30:22 The Role of Radio in Authoritarian Regimes 33:43 International Maritime Law and Cybersecurity 37:46 Recent Projects and Activism in Cybersecurity 39:51 Staying Informed in a Rapidly Changing Landscape Resources Chris Kubecka's LinkedIn - https://www.linkedin.com/in/chriskubecka/ Field Tested: How to Hack a Modern Dictatorship with AI - https://www.amazon.com/dp/B0C7F4XYZ

    • Transcript
    • Chapters
  • S1 · E25
    March 3 · 33 min

    How Anyone Can Become a Hacker: Learning Cybersecurity the Right Way | Ian Austin

    This podcast episode delves into the evolving landscape of cybersecurity, particularly focusing on the intersection of cloud security and artificial intelligence. Ian Austin, co-founder of Pwned Labs, shares his extensive journey through the cybersecurity domain, highlighting the gradual transition from traditional IT roles to specialized security positions. A salient point discussed is the significance of fostering a community-oriented approach to learning, which enhances knowledge acquisition and practical skills in an increasingly complex environment. Ian emphasizes that current training methodologies must incorporate gamification and hands-on experiences to engage learners effectively, ensuring that knowledge is not only theoretical but also applicable. As we navigate these insights, listeners will uncover valuable strategies for enhancing their own cybersecurity practices and understanding the critical importance of cloud security in today's digital landscape. In this episode of the Security by Default podcast, host Joe Carson speaks with Ian Austin, co-founder of Pwned Labs, about his journey in cybersecurity, the evolution of learning in the field, and the challenges of Cloud and AI security. Ian shares insights on transitioning into cybersecurity roles, the importance of community engagement, and the need for continuous learning in an ever-evolving industry. They discuss the significance of gamification in training and the current trends in cloud security, emphasizing the importance of hands-on experience and collaboration. Key Takeaways Ian Austin is a co-founder of Pwned Labs, specializing in cloud and AI security training. His journey in cybersecurity began with help desk roles and evolved into penetration testing. Creating content is a great way to learn and contribute to the community. Cloud security presents unique challenges that require ongoing education and adaptation. Gamification in training enhances engagement but should not overshadow practical learning. Community involvement is crucial for personal and professional growth in cybersecurity. Transitioning into security roles can be done from various backgrounds, including sysadmin and help desk. Continuous learning is essential in the fast-paced cybersecurity landscape. Mentorship can significantly impact career development and confidence. Cloud security is a growing field with increasing demand for skilled professionals. Chapters 00:00 Introduction to the Podcast and Guest 00:40 Ian Austin's Journey in Cybersecurity 06:40 Transitioning into Security Roles 10:54 Evolution of Learning in Cybersecurity 16:19 The Importance of Community in Learning 22:58 Challenges in Cloud Security 28:46 Staying Updated in the Cybersecurity Field Resources: https://pwnedlabs.io/ https://www.linkedin.com/in/ian-austin/

    • Transcript
  • S1 · E24
    February 17 · 42 min

    Inside Password Cracking: How Hackers Really Break Your Secrets | Evil Mog

    This podcast episode delves into the intricate realm of password security and the evolving landscape of authentication methods, with particular emphasis on the implications of artificial intelligence within this domain. I am joined by the esteemed Evil Mog, an executive managing hacker at IBM, who shares his extensive expertise and insights derived from years of involvement in the password cracking community. Throughout our discussion, we explore the significance of enhancing cybersecurity measures while simultaneously acknowledging the pervasive challenges that continue to manifest, such as the recent incidents of compromised systems. We also reflect on the necessity of fostering a culture of collaboration and knowledge sharing within the cybersecurity community to fortify defenses against increasingly sophisticated threats. Ultimately, this episode serves as a poignant reminder of the delicate balance between security and usability in our ongoing pursuit of safeguarding digital assets. In this episode of the Security by Default podcast, host Joe Carson welcomes Evil Mog, an expert in password cracking and cybersecurity. They discuss the importance of Hacker Jeopardy in making cybersecurity fun, the ongoing challenges with passwords, and the evolving role of AI in password cracking. The conversation also touches on incident response, the significance of documentation, and the future trends in cybersecurity, including the shift towards passwordless authentication and the impact of AI on both attackers and defenders. Takeaways Hacker Jeopardy is a fun way to engage with cybersecurity. Teaching others helps reinforce your own knowledge. Passwords will remain a necessary evil in security. AI is enhancing password cracking methodologies. Documentation is crucial in incident response. The cost of hacking is increasing due to advanced techniques. Collaboration between red and blue teams is essential. Insider threats are on the rise in cybersecurity. Password management is fundamentally an asset management issue. Future trends indicate a shift towards passwordless authentication. Sound bites "Teaching helps you learn better." "Security is about enabling the business." "The cost of hacking is rising." Chapters 00:00 Introduction to Evil Mog and Hacker Jeopardy 02:37 The Importance of Community and Teaching in Cybersecurity 05:22 Password Security: The Louvre Incident 07:59 The Evolution of Authentication Methods 10:35 Challenges in Asset Management and Password Management 13:15 Operational Technology (OT) Security Challenges 15:53 The Role of Documentation in Cybersecurity 18:42 AI in Cybersecurity: Automation and Password Recovery 21:52 AI in Password Cracking 24:56 Enhancing Human Capabilities with AI 27:18 The Evolution of Cybercrime 30:02 Trends and Predictions for Cybersecurity 34:41 Collaboration in Cybersecurity 37:24 The Future of Cybercrime and AI 40:59 Connecting with Evil Mog In a thought-provoking dialogue, Joe Carson and Evil Mog engage in a profound examination of cybersecurity, particularly focusing on the critical role of password management in contemporary security practices. Evil Mog, a distinguished executive managing hacker at IBM and a key participant in various hacking competitions, brings invaluable insights to the discussion, blending his extensive expertise with anecdotes from the vibrant DEFCON community. The conversation underscores the often-overlooked aspect of humor in cybersecurity, showcasing how events like Hacker Jeopardy can serve as both a source of entertainment and a platform for learning and community building. The hosts delve deeply into the pressing issues surrounding password security, using real-world examples to illustrate the dire consequences of poor password practices. They analyze incidents, including the infamous Louvre heist, where a lack of foresight in password management led to significant breaches. This discussion highlights the critical need for organizations to adopt stronger authentication methods, such as passkeys and multi-factor authentication, while acknowledging the challenges that traditional passwords continue to pose in everyday scenarios. Carson and Mog emphasize the importance of balancing security with usability to prevent users from resorting to insecure workarounds. Looking ahead, the conversation shifts toward the future of cybersecurity, with the hosts expressing hope for continued advancements in password management technologies. They advocate for a proactive approach in adapting to new threats, underscoring the necessity of community collaboration and knowledge sharing among cybersecurity professionals. The episode concludes with a resounding reminder of the importance of staying informed and engaged in an ever-evolving landscape of cybersecurity risks. Takeaways: The podcast emphasizes the importance of community engagement in cybersecurity, advocating for teaching others to enhance personal understanding and benefiting the broader community. Evil Mogg discusses the evolution of password security, highlighting the ongoing necessity for shared secrets despite technological advancements in authentication methods. The conversation reveals a critical perspective on the complexities of cybersecurity, particularly how simplifying security for users can lead to better compliance and protection. Listeners are encouraged to actively participate in events like Hacker Jeopardy to foster a fun and interactive approach to cybersecurity education and awareness.

    • Transcript
    • Chapters
  • S1 · E23
    February 3 · 30 min

    Understanding the Critical Role of Identity in Modern Cybersecurity with Charles Chase

    The focal point of today’s discourse centers on the crucial importance of identity security and privileged access management in contemporary organizational frameworks. I am joined by the esteemed Charles Chase, who shares his extensive experience in the realm of identity security, elucidating the pressing trends and best practices that organizations must adopt to safeguard their digital assets. Our conversation delves into the regulatory pressures that compel businesses to enhance their security measures, particularly in light of evolving threats and compliance requirements. Furthermore, we explore the significance of understanding the unknowns within identity management systems and the necessity of maintaining rigorous hygiene practices to mitigate potential vulnerabilities. Through this dialogue, we aim to illuminate the transformative impact of effective identity management strategies on organizational security and operational efficiency. In this episode of the Security by Default podcast, host Joe Carson speaks with Charles Chase about his journey into the cybersecurity field, focusing on identity security and privilege access management. They discuss the evolving trends in identity security, the importance of maintaining identity hygiene, and the impact of regulations like NIST 2 and DORA on organizational practices. The conversation also covers the shift towards passwordless security, the role of AI in identity management, and resources for those looking to enter the field. The episode concludes with reflections on the importance of identities in business and society. Takeaways Charles Chase fell into cybersecurity from a military background. The importance of understanding what you don't know in identity security. Organizations often have dormant accounts that pose security risks. Regulatory bodies are pushing organizations to improve their identity security practices. The shift towards passwordless security is gaining momentum. AI is becoming a valuable tool in identity management. Identity hygiene is crucial for reducing risks in organizations. The commoditization of identity solutions allows smaller businesses to implement security measures. Engaging with customers is key to understanding their unique identity security needs. The future of identity management is focused on user experience and automation. Keywords cybersecurity, identity security, privilege access management, trends, best practices, passwordless security, AI in identity management, regulatory impact, identity hygiene, resources for cybersecurity The podcast commences with an engaging introduction by host Joe Carson, who expresses his enthusiasm for sharing insights and knowledge with the audience. He introduces his guest, Charles, who possesses an extensive background in identity security and privileged access management. Charles recounts his journey into the cybersecurity industry, highlighting his initial experiences in the U.S. Air Force as a network engineer and the serendipitous nature of his entry into the realm of privileged access management. The conversation swiftly transitions to the evolving landscape of identity security, where both speakers reflect on the advancements in tools and practices that have emerged over the years. They discuss the significance of understanding the regulatory landscape and the implications it has for organizations striving to enhance their security posture. Charles emphasizes the necessity for organizations to proactively address their security vulnerabilities and to adopt best practices that mitigate risks associated with identity and access management. He shares anecdotes from his experiences working with various clients, illustrating the startling discoveries often made when analyzing their systems, including the prevalence of dormant accounts and orphaned identities that pose significant security risks. As the dialogue progresses, the speakers delve into current trends in identity security, particularly the move towards passwordless authentication methods and the integration of multifactor authentication solutions. Charles elucidates how organizations are increasingly prioritizing the security of their identity frameworks to comply with regulatory demands while ensuring the integrity of their operations. He shares insights on the importance of continuous learning and adaptation in the field of cybersecurity, noting that each organization's journey is unique, and tailored approaches are essential to address specific challenges. The conversation culminates in a discussion on the future of identity management, where both speakers express optimism about the potential of emerging technologies and the need for organizations to remain vigilant in their security efforts. Ultimately, the episode underscores the critical role that effective identity management plays in safeguarding organizational assets and maintaining trust in today’s digital landscape. Takeaways: The conversation highlighted the significant evolution in identity security practices over the years, emphasizing the necessity of adopting modern tools and strategies. A recurring theme was the critical importance of addressing dormant and orphaned accounts to enhance overall security posture within organizations. Regulatory pressures have escalated, compelling organizations to prioritize identity management and security protocols to mitigate risks effectively. The speakers discussed the growing trend towards passwordless authentication and the integration of biometric solutions in identity security frameworks. The episode underscored the necessity of maintaining a proactive identity hygiene program to prevent security vulnerabilities. The importance of continuous education and awareness for professionals entering the identity and access management field was a key discussion point.

    • Transcript
    • Chapters
  • S1 · E22
    January 20 · 46 min

    A Deep Dive into Cyber Operations and OSINT with The Grugq

    The Grugq, a distinguished expert in the realm of open-source intelligence (OSINT) and cyber operations, elucidates the intricate interplay between information warfare and contemporary security challenges. He articulates the notion that during times of conflict, traditional rules governing cyber operations, such as deniability and stealth, become markedly less pertinent. Instead, the focus shifts towards achieving mission objectives without the necessity for concealment, as the stakes escalate in the context of warfare. Throughout our discourse, we explore the evolution of cyber tactics, emphasizing the shift from sophisticated methodologies to more rudimentary yet effective tools, reflecting a pragmatic approach to cyber engagements. Ultimately, our conversation serves as a profound examination of the current landscape of cyber warfare, underscoring the necessity for adaptability and a nuanced understanding of operational security in an era marked by rapid technological advancements and shifting geopolitical dynamics. In this episode of the Security by Default podcast, host Joseph Carson engages with the Grugq, a cybersecurity expert and PhD student, discussing his journey into the field, the evolution of cybersecurity practices, and the complexities of information warfare. The Grugq shares insights on anti-forensics, the importance of understanding human behavior in cybersecurity, and the current landscape of cyber warfare, particularly in the context of the ongoing conflict in Ukraine. The conversation highlights the challenges and changes in the cybersecurity field, emphasizing the need for clarity and understanding in a chaotic information environment. Takeaways The Grugq's journey into cybersecurity began with a Unix book. He transitioned from internships to freelancing in cybersecurity. Moving to Thailand helped reduce living costs while consulting. Understanding anti-forensics is crucial for effective cybersecurity. The rules of cyber warfare differ significantly from peacetime operations. Information warfare involves changing how people interpret information. The Grugq emphasizes the importance of human behavior in cybersecurity. Staying updated in cybersecurity requires monitoring current events and engaging with experts. The evolution of cybersecurity tools has made it easier for new actors to operate. The Grugq's PhD research focuses on the realities of cyber warfare. Additional Resources: https://x.com/thegrugq https://github.com/grugq Engaging with the multifaceted realm of Open Source Intelligence (OSINT) and Cyber Operations, this podcast episode presents an erudite dialogue featuring The Grugq, an esteemed expert in the field. The conversation is initiated by the host, who invites The Grugq to share his origin story, tracing his journey through the labyrinthine world of cybersecurity, beginning from his formative experiences with UNIX systems. The Grugq elucidates how he transitioned from being an independent security researcher to an academic, currently pursuing a PhD focused on cyber warfare. This episode delves into the complexities of operational security, the principles underpinning successful cyber operations, and the significance of understanding human behavior in the cybersecurity domain. The discourse further explores the dynamic interplay between OSINT and cyber operations, emphasizing the critical importance of meticulous analysis and strategic deception in contemporary cyber warfare. The Grugq articulates the evolving nature of threats in this space, and how adversaries utilize increasingly sophisticated techniques to obfuscate their activities. Throughout the episode, listeners are afforded a unique glimpse into the methodologies that underpin effective cyber operations, highlighting the necessity of adapting to the ever-shifting landscape of cybersecurity. Amidst the complexities of the cyber domain, The Grugq offers profound insights into the ethical implications of cyber operations, urging practitioners to consider the broader ramifications of their actions. This episode serves not only as a repository of knowledge but also as a call to action for cybersecurity professionals to reflect on the ethical dimensions of their work. By the conclusion, listeners are left with a rich understanding of the intersection of OSINT and cyber operations, equipped with the knowledge to navigate the tumultuous waters of the cybersecurity landscape with greater acumen and awareness. Takeaways: The Grugq emphasizes the importance of understanding the principles of operational security and their historical context in the realm of cyber warfare. In the discussion, we explore the evolution of cyber operations, highlighting how the dynamics of war have shifted the focus from stealth to achieving mission objectives. A key takeaway is the recognition that modern cyber actors often utilize pre-existing techniques rather than creating new ones, complicating attribution efforts in cyber incidents. The podcast delves into the significance of information warfare, stressing that the ability to manipulate perceptions is as crucial as the actual data being presented. The Grugq shares insights on how the principles of access, humanity, and economy underpin successful cyber operations, framing them within the context of both offense and defense. We discuss the blurred lines in modern cyber conflicts, where traditional rules of engagement may not apply, particularly in ongoing large-scale cyber warfare scenarios.

    • Transcript
    • Chapters
  • S1 · E21
    January 6 · 47 min

    Building Resilience in Cybersecurity: Lessons from Joe Sullivan

    The paramount theme of this podcast episode revolves around the critical necessity of preparing for crises within cybersecurity frameworks. As we navigate an increasingly chaotic landscape, it becomes evident that security must be accessible and comprehensible for all stakeholders involved. We engage in an enlightening dialogue with our esteemed guest, Joe Sullivan, who elucidates his remarkable journey from a federal prosecutor to a prominent figure in security leadership across major tech enterprises. Throughout our conversation, we emphasize the importance of cultivating resilience in the face of potential adversities, advocating for a paradigm shift from mere prevention to proactive crisis management. This episode serves not only as an exploration of individual experiences but also as a clarion call for organizations to invest in robust preparedness strategies to mitigate the impacts of inevitable security incidents. In this episode of the Security by Default podcast, host Joseph Carson interviews Joe Sullivan, a prominent figure in cybersecurity. They discuss Joe's journey from a federal prosecutor to the Chief Security Officer at Facebook, exploring the challenges and expectations in transitioning from government to private sector roles. The conversation delves into the evolving landscape of cybersecurity, the impact of ransomware, and the importance of crisis management and preparedness. Joe shares valuable lessons for aspiring security executives and highlights the significance of understanding technology in leadership roles. The episode concludes with Joe's current projects, including his nonprofit initiative, Ukraine Friends, which provides laptops to children affected by the war in Ukraine. Takeaways Security is possible for everyone. Joe Sullivan's journey reflects a unique path into cybersecurity. Transitioning from government to private sector presents challenges. Understanding corporate culture is crucial for success. Measuring success in cybersecurity requires clear metrics. Ransomware has fundamentally changed the cybersecurity landscape. Security leaders are increasingly reporting to CEOs. Crisis management is essential for organizational resilience. Aspiring security executives should focus on business understanding. Giving back to the community is a vital part of the cybersecurity profession. Sound bites "Security is possible for everyone." "I got an MBA through osmosis." "The expectations were so high." Chapters 00:00 Introduction to Security by Default Podcast 01:02 Joe Sullivan's Journey into Cybersecurity 05:10 Transition from Government to Private Sector 11:06 Navigating the Corporate Landscape 15:48 Measuring Success in Security 20:04 The Impact of Ransomware on Cybersecurity 28:01 The Evolving Role of Security Leaders 30:57 Understanding Business Strategy in Security 32:59 Risk Management and Business Partnership 33:52 Navigating Technology Risks 35:54 The Race for AI Innovation 38:03 Crisis Management and Preparedness 39:59 Building Resilience in Security Teams 42:16 The Importance of Response Training 44:10 Lessons from Emergency Services 47:41 Community Impact through Technology Additional Resources: https://www.joesullivansecurity.com/about https://ukrainefriends.org/ https://www.linkedin.com/in/joesu11ivan/ https://en.wikipedia.org/wiki/Joe_Sullivan_(cybersecurity) The discourse presented in this episode of the Security By Default podcast delves into the intricacies of cybersecurity through a rich narrative framed by the experiences of Joe Sullivan, a distinguished figure in the cybersecurity landscape. The conversation commences with a reflection on the current state of security in a world rife with chaos and challenges, emphasizing the necessity for clarity and preparedness in addressing security concerns. Sullivan recounts his unique journey into the realm of cybersecurity, marked by an initial aspiration to pursue law, which ultimately led him to blend his legal expertise with a burgeoning interest in technology. This intersection of law and technology is pivotal in understanding the evolution of cybersecurity practices, as Sullivan highlights the early days of his career at the Department of Justice, where he was thrust into the intricate dynamics of cybercrime prosecution. His narrative underscores the significant shifts in the cybersecurity landscape, illustrating how the role of cybersecurity professionals has evolved into one that requires not only technical prowess but also a profound understanding of business operations and risk management. As the discussion unfolds, listeners are introduced to the concept of operational resilience, a theme underscored by Sullivan's experiences at major corporations such as eBay, PayPal, and Facebook. He elucidates the necessity for security leaders to transition from a purely defensive posture to one that encompasses proactive crisis management and resilience building. Sullivan’s observations regarding the expectations placed upon security professionals in the private sector contrast sharply with his experiences in government service, where the pace and metrics of success differ markedly. This dichotomy serves to illuminate the complexities faced by modern security executives who must navigate not only the technical challenges of cybersecurity but also the imperative to align their strategies with broader business objectives. In conclusion, the episode encapsulates the essence of security as a multifaceted discipline that extends beyond mere technical solutions. Sullivan advocates for a paradigm shift in how organizations perceive and invest in security, urging a balanced allocation of resources towards both prevention and crisis preparedness. His insights serve as a clarion call for security professionals to engage more deeply with the business side of their organizations, fostering a culture where security is seen as an integral component of operational success rather than a mere compliance obligation. The conversation ultimately reinforces the notion that in the face of evolving threats, a proactive and well-prepared security posture is paramount for organizational resilience and success in an increasingly digital world.

    • Transcript
    • Chapters
  • S1 · E20
    Dec 23, 2025 · 56 min

    Laughing with Cyber - A Standup Comedy Special with Ian Murphy

    This podcast episode delves into the often-overlooked notion that the field of cybersecurity can be both enjoyable and engaging, rather than solely characterized by its daunting challenges and threats. We, Joe Carson and Ian Murphy, reflect on our shared experiences within the industry, emphasizing the importance of maintaining a sense of humor and joy amidst the chaos often associated with cybersecurity. Ian recounts his journey from the early days of the internet and his unconventional entry into the cybersecurity realm, highlighting how his background in mechanics and passion for storytelling have shaped his unique approach to security awareness. Our conversation touches on the significance of creativity in effectively communicating complex topics, as well as the necessity of fostering a more approachable and less fear-driven narrative within the cybersecurity space. Ultimately, we aspire to illuminate the path toward a more vibrant and connected community, where laughter and camaraderie thrive alongside security. In this episode of the Security by Default podcast, host Joseph Carson welcomes Ian Murphy, a cybersecurity expert and stand-up comedian. They discuss Ian's unconventional journey into cybersecurity, his experiences at the MOD and Symantec, and his transition to self-employment and comedy. Ian shares insights on the importance of storytelling in both cybersecurity awareness and comedy, as well as navigating online criticism and audience interactions. The conversation highlights the need for humor in serious industries and the value of real human connections. Takeaways Ian's journey into cybersecurity was unplanned and unconventional. The importance of storytelling in both cybersecurity and comedy. Self-employment offers freedom but comes with challenges. Humor can be a powerful tool in serious industries. Navigating online criticism requires thick skin and perspective. Comedy is subjective, and not everyone will appreciate it. Real human interactions are essential in today's digital age. Learning from experiences is crucial for growth in any field. Networking and peer relationships are vital for success. Life is better when you find joy and laughter in everyday situations. Sound bites "I wanted to be a footballer." "Comedy is subjective." "You need to grow the fuck up." Chapters 00:00 Introduction to the Podcast and Guest 00:56 Ian's Origin Story and Journey into Cybersecurity 06:29 Experiences at MOD and Symantec 10:44 Transitioning to Self-Employment and Freedom 14:27 The Switch to Stand-Up Comedy 22:05 The Impact of Humor in Cybersecurity Awareness 30:06 Audience Feedback and Social Media Interaction 31:54 The Power of Audience Engagement 34:49 Navigating Controversy in Comedy 37:43 The Art of Timing and Response 40:47 Comedy as a Reflection of Life 43:44 The Evolution of Comedy and Storytelling 49:53 Learning and Growth Through Comedy 53:50 Connecting with the Audience Takeaways: The podcast emphasizes the importance of maintaining joy and humor in the cybersecurity field despite its often serious nature. We explored how humor can be a powerful tool in security awareness, making the subject more engaging for audiences. Ian shared his remarkable journey from mechanic to cybersecurity expert, illustrating the value of diverse experiences in shaping one’s career. The discussion highlighted the challenges of transitioning from corporate environments to freelance work, emphasizing the freedom and responsibility it entails. Both speakers reflected on the necessity of fostering human connections in the tech world, counteracting the isolation often felt in digital spheres. The podcast concluded with a call to action for listeners to embrace humor and creativity in their professional lives, enhancing both workplace culture and personal fulfillment.

    • Transcript
    • Chapters
  • S1 · E19
    Dec 16, 2025 · 46 min

    From Teenage Hacker to Hollywood: A Cybersecurity Story You Won’t Believe | Alissa Knight

    This podcast episode features an enlightening conversation with Alissa Knight, a notable figure in the cybersecurity landscape, who shares her unique journey into the realm of hacking and cybersecurity. From her early days of curiosity and mischief, starting at the tender age of thirteen, to her transformative experiences following a pivotal arrest, Alissa reflects on the lessons learned and the paths forged in the aftermath. The discussion delves into the evolution of hacking practices and the current landscape of API security, which Alissa identifies as a critical area of concern due to its expanding attack surface in contemporary technology. As we navigate through the complexities of artificial intelligence's role in cybersecurity, Alissa emphasizes the necessity of integrating security practices into the development process. This episode serves not only to illuminate Alissa's personal narrative but also to provide valuable insights for aspiring cybersecurity professionals and organizations alike. In this episode of the Security by Default podcast, host Joe Carson engages with cybersecurity expert Alissa Knight, who shares her unique journey into the world of hacking and cybersecurity. They discuss the evolution of hacking, the challenges of API security, and the transformative impact of AI on the industry. Alissa emphasizes the importance of continuous learning and adapting to new technologies, while also reflecting on her career shifts and the significance of storytelling in cybersecurity marketing. The conversation highlights the need for organizations to invest in their employees' education and the future of cybersecurity innovation. Takeaways Alissa started hacking at the age of 13, driven by curiosity. The early days of hacking were like the wild west, with fewer resources. A significant turning point in Alissa's life was her arrest at 17. Cybersecurity offers lucrative career opportunities for skilled individuals. API security is a growing concern as more services rely on APIs. AI is reshaping the cybersecurity landscape, creating new challenges and opportunities. Continuous learning is essential in the fast-evolving field of cybersecurity. Organizations must invest in training their developers in secure coding practices. Storytelling can be a powerful tool in cybersecurity marketing. The future of cybersecurity will heavily involve AI and automation. Sound bites "It was the wild, wild west." "I was arrested on my school campus." "This industry pays very well." Chapters 00:00 Introduction to the Podcast and Guest 00:57 Alissa Knight's Unique Origin Story 05:30 The Evolution of Hacking and Cybersecurity 10:54 Turning Points and Career Shifts 16:10 The Impact of DDoS Attacks on Career Paths 20:57 The Importance of API Security 24:06 Hacking APIs and Security Vulnerabilities 27:52 The Evolution of AI in Coding 31:30 From Cybersecurity to Hollywood 36:32 Introducing ARIES: AI for Cybersecurity 39:03 The Importance of Continuous Learning in Cybersecurity Resources https://www.linkedin.com/in/alissaknight/ https://www.knightgroup.co/ https://microreels.com/ https://www.youtube.com/@AlissaKnightArchives The Security By Default podcast presents an engaging dialogue between Joe Carson and Alissa Knight, a seasoned cybersecurity expert with a rich and unique background in hacking and security. Alissa recounts her journey into the cyber realm, beginning at the tender age of thirteen when her curiosity led her to explore the inner workings of technology. Her early experiences with bulletin board systems (BBS) and the hacking community shaped her understanding of cybersecurity, illustrating the evolution from the rudimentary practices of the past to the sophisticated techniques employed today. Alissa reflects on her misadventures, including a pivotal incident that resulted in her arrest at seventeen, which ultimately redirected her path towards a career in cybersecurity. This incident, rather than being a mere setback, served as a catalyst for her transformation, providing her with insights into the resilience required in the face of adversity. Throughout the discussion, Alissa emphasizes the importance of continuous learning and adaptation in the ever-evolving field of cybersecurity. She highlights the shift in focus towards API security and the challenges posed by artificial intelligence in code development. The conversation delves into the significance of secure coding practices and the necessity for organizations to invest in the education of their developers. Alissa's insights illuminate the critical nature of understanding the vulnerabilities that arise in modern applications and the imperative for cybersecurity professionals to stay abreast of these developments. The episode encapsulates a narrative of growth, resilience, and the pursuit of knowledge, encouraging listeners to embrace their journeys and strive for continuous improvement in the cybersecurity domain.

    • Transcript
    • Chapters
  • S1 · E18
    Dec 9, 2025 · 41 min

    Understanding Customer Success: Beyond Support in Cybersecurity

    This podcast episode elucidates the essential nature of customer success within the realm of cybersecurity, positing that the discipline transcends mere technical proficiency to encompass a broader business perspective. I convey that security is no longer confined to IT; rather, it is a multifaceted issue that intertwines with various organizational domains such as finance, sales, and human resources. The dialogue with our esteemed guest, David Muniz, highlights the importance of understanding customer expectations and the role of trust in fostering meaningful relationships between organizations and their clients. We explore the distinction between customer support and customer success, emphasizing that the latter is a long-term endeavor focused on guiding clients toward their defined objectives. Ultimately, our conversation underscores the imperative of adopting a customer-centric approach to ensure that cybersecurity solutions not only protect but also enhance the overall business experience. In this episode of the Security by Default podcast, Joseph Carson engages with David Muniz to explore the evolving landscape of cybersecurity. They discuss the importance of diversity in the field, the distinction between customer success and support, and the critical role of trust in business relationships. The conversation also delves into the Zero Trust paradigm, emphasizing the need for a human-centric approach in cybersecurity. David shares insights on staying updated in a rapidly changing industry and the significance of happiness in the workplace, concluding with thoughts on the human element in cybersecurity. Keywords cybersecurity, customer success, zero trust, trust in business, diversity in tech, human relationships, customer support, industry insights, happiness in work, staying updated Takeaways · Customer success focuses on long-term relationships, not just immediate problem-solving. · Trust is a key component in building successful customer relationships. · Zero Trust is about managing trust dynamically, not eliminating it. · Customer success involves understanding what success means to the customer. · Building trust requires consistent and reliable service. · Human interactions are crucial in customer success, even in a digital world. · Customer success can lead to increased revenue through renewals and up-selling. · Trust in cybersecurity involves both technical and human elements. · Effective customer success strategies can differentiate a company in the market. · Balancing security with user experience is essential for customer satisfaction. Sound bites · "Customer success is about long-term relationships." · "Trust is not just assumed; it must be earned." · "Zero Trust is about managing trust, not eliminating it." · "Success is defined by the customer's perspective." · "Human interactions are crucial in a digital world." · "Trust leads to increased revenue and loyalty." · "Cybersecurity involves both technical and human elements." · "Balancing security with user experience is key." · "Customer success can differentiate a company." · "Trust is a business differentiator." Chapters 00:00 Introduction to Cybersecurity and Guest Background 04:10 The Importance of Diversity in Cybersecurity 08:41 Understanding Customer Success vs. Customer Support 12:52 Building Trust in Customer Relationships 17:15 The Role of Zero Trust in Cybersecurity 22:07 Understanding Zero Trust and Its Implications 27:33 The Dynamic Nature of Trust in Cybersecurity 32:01 The Human Element in Building Trust Additional Resources The Trust Paradox: A Cybersecurity Mindset for Human Relationships https://www.linkedin.com/pulse/trust-paradox-cybersecurity-mindset-human-david-muniz-f9fzf The Hidden ROI of Trust in Business and Cybersecurity https://www.linkedin.com/pulse/hidden-roi-trust-business-cybersecurity-david-muniz-7r3jc https://segura.security/ https://segura.security/blog https://en.wikipedia.org/wiki/The_Power_of_Now The podcast episode delves into the intricate subject of cybersecurity, emphasizing the necessity for clarity amidst the chaos that often accompanies it. The host, Joseph, expresses his enthusiasm for engaging with industry luminaries and cultivating thought-provoking discussions that aim to enhance the safety and security of organizations and individuals alike. Joseph is joined by David Muniz, a seasoned professional with a diverse background in computer science, project management, and cybersecurity. David recounts his unconventional journey into the field, highlighting how his academic pursuits led him to realize his passion for addressing issues related to fraud detection and risk management. The conversation gradually transitions to the importance of customer success within the realm of cybersecurity. David delineates the distinction between customer support and customer success, asserting that the latter is focused on understanding the customer's definition of success and facilitating their achievement of it. This involves a long-term commitment to building relationships and trust, as well as comprehending the various business objectives that drive customers to adopt cybersecurity solutions. The podcast underscores the need for a shift in perspective, viewing cybersecurity not merely as a technical challenge but as a fundamental business issue that necessitates the involvement of diverse stakeholders across an organization. Throughout the episode, a recurring theme emerges: the emphasis on trust as a cornerstone of effective cybersecurity practices. Both speakers advocate for a change in hiring practices, proposing that organizations should prioritize passion and willingness to learn over rigid certification requirements. As the discussion unfolds, the duo reflects on the evolving landscape of cybersecurity, addressing the concept of zero trust and the importance of a dynamic approach to risk management. They conclude by reiterating that the epitome of customer success is rooted in the cultivation of genuine relationships, where trust and open communication play pivotal roles, ultimately enabling organizations to navigate the complexities of cybersecurity with greater efficacy.

    • Transcript
    • Chapters
Showing 1–20 of 20 episodes