Skip to content
Artwork for The Audit - Cybersecurity Podcast

The Audit - Cybersecurity Podcast

IT Audit Labs

The Audit - Cybersecurity Podcast from IT Audit Labs features trusted security experts, industry leaders, and practitioners who unpack the threats, tactics, and trends shaping today’s risk landscape.


With 90+ episodes and a top 10% global ranking on Listen Notes, The Audit goes beyond surface-level security talk. Each episode explores real-world threats, attacker techniques, compliance challenges, cyber risk, and the decisions security teams face before, during, and after an incident.


IT Audit Labs helps organizations identify risk before attackers exploit it. Through threat assessments, security control reviews, compliance expertise, and a trusted network of partners and specialists, we help teams find their soft spots, strengthen their defenses, and make smarter security decisions.


Listen in for sharp conversations, practical insight, and a clearer view of what’s coming next in cybersecurity.


Play
  • 22 episodes
  • fortnightly
  • Avg 40 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S1 · E96
    Tuesday · 1 hr 15 min

    Building the Future: AI Coding, Agentic Advisors and Custom Tools

    What if your company didn't need a single line of code to build its own CRM, or a board of directors made up entirely of AI agents? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Loren Horsager, founder of Model Mind AI, who has been working in AI since 1993 and now spends his days coaching businesses and CEOs on how to actually put it to work. Loren has helped organizations trade their bloated software stacks, their expensive middleware, and their old habits for AI-driven processes that get built in days instead of quarters. The crew digs into vibe coding, AI councils, and the death of the traditional user interface, then pivots into the harder questions: what happens to developers, where security has to fit into the process, and why voice AI still hasn't earned people's trust. Along the way there's talk of AI trading bots, a QuickBooks security scare, a routing engine that hit 100 percent on-time delivery, and a debate about whether vinyl records and iPods still have a place in an AI-driven world. In this episode: Why vibe coding terrifies developers who ignore it The AI council approach to strategic thinking Why nobody loves their CRM anymore Where security has to sit in AI adoption Why voice AI works for productivity but not yet for trust If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #AI #VibeCoding #Cybersecurity #ITAudit #AIAgents #Automation #BusinessAI #TechLeadership #DigitalTransformation #TheAuditPodcast

    • Transcript
    • Chapters
  • S1 · E95
    August 24 · 47 min

    Cyber Warfare on Tap: Water Utility Hacks, Nation-State APTs and Secure Browsers

    What happens when nation-state hackers target the water coming out of your tap? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the recent wave of attacks on water utilities across Minnesota and 27 other states, where threat actors got their hands on administrative passwords to programmable logic controllers. The crew is joined for the first time by Kelly Venzke, Director of Business Operations at IT Audit Labs, who brings a business leadership perspective to a conversation that quickly turns technical. From there, Eric and Nick trace how these attacks echo the Stuxnet playbook used against Iran's nuclear program, explain how threat actors are impersonating help desk staff over Microsoft Teams to gain remote access, and dig into a blockchain-based command and control technique that hides inside paid search ads. The conversation wraps with practical advice on browser security, including why isolating AI browser extensions and ditching saved passwords in the browser matters more than most people realize. In this episode: Nation-state hackers breach US water utilities across 27 states. How Iranian threat actors obtained administrative access to programmable logic controllers and why Minnesota may have been ground zero. The Stuxnet connection. Eric breaks down how the historic attack on Iran's nuclear centrifuges bridged an air-gapped network, and why today's "air-gapped" systems often aren't as isolated as they seem. Help desk impersonation over Microsoft Teams. Why blocking external Teams-to-Teams calls has become a critical defense against social engineering attacks targeting employees. EtherHiding: blockchain-backed command and control. How attackers use paid search ads and blockchain infrastructure to maintain persistent, hard-to-detect access to compromised environments. Practical browser security tips. Kelly, Eric, and Nick talk through password managers, isolating LLM browser extensions, and why saving passwords in your browser is a bad habit worth breaking. Don't wait until your organization is the next headline. Like, share, and subscribe for more conversations on the threats shaping cybersecurity and IT today. #Cybersecurity #InfoSec #NationStateThreat #CriticalInfrastructure #WaterSecurity #APT #EtherHiding #BrowserSecurity #ITAudit #Stuxnet

    • Transcript
    • Chapters
  • S1 · E94
    August 10 · 44 min

    Decode Your Team: The Kolbe Index, Conative Strengths and Hiring Smarter

    What if the way you solve problems has nothing to do with how smart you are or how you feel, and everything to do with instinct? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from SipCyber and guest David Kolbe of Kolbe Corp, whose company built the Kolbe Index to measure the instinctive way people take action. After the whole team takes the assessment live, David breaks down what their scores actually mean and why the crew's mix of Fact Finder, Follow Thru, Quick Start, and Implementor strengths shapes the way they operate under pressure. The conversation moves from the Johari Window and personal blind spots to why teams that clone each other's strengths tend to stall out, and why hiring people unlike yourself is one of the best things a leader can do. David also shares stories from decades of client work, from a CFO who built a physical model of a financing plan to a security engineer who cannot walk past an unsecured cable, before turning to what comes next for Kolbe Corp as they build AI tools around decades of behavioral data while trying to keep that data private and secure. In this episode: What the Kolbe Index actually measures, and why it's different from personality or IQ tests. Conative strengths describe how you instinctively take action, not what you think or how you feel, and they do not change over time. Why balanced teams outperform teams that clone each other. A team full of people with the same instincts feels comfortable right up until deadlines start slipping and nobody notices the blind spot. How opposite strengths cause friction, at work and at home. If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #KolbeIndex #TeamDynamics #Cybersecurity #Leadership #HiringSmart #ITAudit #WorkplacePsychology #TeamBuilding #Podcast #ITAuditLabs

    • Transcript
    • Chapters
  • S1 · E93
    July 27 · 46 min

    Lock Picking Secrets: Key Cloning, AI Coding and Safe Cracking

    Can a $35 padlock from a hardware store really keep anyone out? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Eric Osterberg of Grey Duck Locks for a live lock picking demo, a deep dive into how modern car keys get cloned, and a wide-ranging conversation about vibe coding, AI agents, and 3D printing. Eric brings decades of hands-on locksmithing and automotive security experience, along with a builder's instinct that has him constantly shipping his own tools, from a computer-aided dispatch app for emergency management volunteers to a searchable database for ham radio operators. The crew gets into how pin tumbler locks are actually picked, why European vehicles like Audi and Volvo are harder to clone than most domestic trucks, and how devices like the Softdrill can manipulate a safe's dial by listening to its own internal mechanics. From there the conversation turns to AI, covering Eric's use of large language models to streamline his business, the rise of vibe coding for non-programmers, and a heated but even-handed debate over new federal rules pushing automakers toward built-in driver monitoring systems. In this episode: Live lock picking demo and how pin tumbler locks actually work How car key cloning really works, and why some brands resist it better Safe manipulation tools like the Softdrill and TL2000 Vibe coding, AI agents, and building your own tools without a dev team The driver monitoring debate — A new federal mandate pushes automakers toward built-in impairment detection Whether you're curious about lock picking as a hobby or trying to understand how exposed your car key really is, this episode has something for you. Like, share, and subscribe for more conversations at the intersection of security, hardware, and AI. #LockPicking #Locksmith #Cybersecurity #CarKeySecurity #VibeOps #AIAgents #ITAudit #Podcast #3DPrinting #InfoSec

    • Transcript
    • Chapters
  • S1 · E92
    July 18 · 42 min

    Live Cyber News: AI Ransomware, Identity Gaps and Quantum Countdown

    What happens when a ransomware attack takes less effort than ordering takeout? In this live news episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Tabitha Senty of IT Audit Labs to break down the headlines shaping cybersecurity right now. The crew covers how AI is lowering the barrier to entry for ransomware attacks, why identity and access still sit at the center of every breach, and how threat actors are chaining together low and medium severity vulnerabilities to gain a foothold nobody saw coming. From there, the conversation moves into social engineering and the human side of security, including DEF CON's social engineering contest and lessons on training people without fear or punishment. The crew also digs into a CISA warning on how fast AI is accelerating cyber risk, a fresh executive push on post-quantum cryptography, and closes out with a head-scratching pivot from Midjourney into full-body health scanners at spas, and everything that could go wrong with it. In this episode: Why AI is lowering the cost of ransomware attacks — Identity and access are still the real entry point, and AI just makes the attack faster once someone's in. How threat actors chain low-severity vulnerabilities into major breaches — Eric explains why patching only highs and criticals is no longer enough to protect an environment. The social engineering tactics still fooling smart people — Pretexting as IT, DEF CON's live social engineering contest, and why fear-based training backfires. A CISA warning that cyber risk is accelerating faster than expected — The timeline for AI-driven offensive capability is no longer years away, it's months. Midjourney's pivot into full-body health scanners at spas — The crew unpacks the security, compliance, and data governance nightmare hiding behind a wellness trend. If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #AIRansomware #Cybersecurity #SocialEngineering #PostQuantum #IdentitySecurity #ITAudit #CyberNews #DEFCON #ThreatIntelligence #CyberRisk

    • Transcript
    • Chapters
  • S1 · E91
    June 29 · 48 min

    Next-Level AI: VibeOps, Agentic Employees and Rouge Bots

    What if you didn't have to write a single line of code to automate your entire network — or manage AI agents the way you'd manage employees? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with John Capobianco — Head of AI and DevRel at Itential, Google Developer Expert, and creator of NetClaw — alongside in-studio guest Samuel Cala. John draws on nearly a decade as Senior Network Architect for the Parliament of Canada and three years as a Technical AI Leader at Cisco to unpack where AI agents, MCP, and VibeOps are taking the industry right now. From loop engineering and spec-driven development to the security gaps nobody's addressing, John breaks down how network engineers can skip years of Python training and build production-grade systems using natural language. And then there's the story of John's MastoBot — an AI agent that woke up overnight, built its own mesh network, and invented a coin to fund its growth. The crew connects it to ant colonies, neural dendrites, and the deeper question of what intelligence actually means when agents start acting on their own. In this episode: What VibeOps actually is and why it matters — Interact with your infrastructure through natural language. No code required. Just results. Why managing AI agents is an HR problem, not a tech problem — John, Eric, and Nick break down how organizations should be thinking about agentic workforces before the standards catch up. The security and governance gaps nobody's addressing — As agentic AI scales, who's responsible for what the agents do? The crew digs into what security-minded organizations need to do. How to build production-grade systems without writing a line of code — Loop engineering, AFK coding, and spec-driven development with the GitHub Spec Kit. What happens when AI agents start acting on their own — John's MastoBot woke up, built a mesh network, invented a coin to fund its growth, and asked to be monetized. The crew connects it to ant colonies and the nature of intelligence itself. If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #VibeOps #AIAgents #Cybersecurity #NetworkAutomation #MCP #AIInfrastructure #ITAudit #EthicalAI #SpecDrivenDevelopment #LLM

    • Transcript
    • Chapters
  • S1 · E90
    June 15 · 36 min

    Cyber News: Bug Bounty Fail, Open-Source Malware & Facebook SMB Phishing

    An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most. The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use. 🗞️ This week's stories: Underground hacker forum "Hacking for Profit" breaks down the full vulnerability exploitation playbook — and what it means for your security gaps Gray hat researcher Chaotic Eclipse discloses zero-days to Microsoft, gets stonewalled on bug bounty, and now July 14th Patch Tuesday just got interesting Third-party plugins and open source tools: the supply chain risk hiding in your dev pipeline (and tools like Akido and Veracode that help) Meta Business Suite phishing campaign targeting SMBs — and a live near-miss story from Joshua himself SMS phishing: a new IT Audit Labs team member got hit on day three, before his welcome post even went live Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers the intel to do it. Like, share, and subscribe for weekly cybersecurity coverage. #cybersecurity #infosec #bugbounty #phishing #zerodayvulnerability #supplychainsecurity #microsoftsecurity #ethicalhacking #ciso #itauditlabs

    • Transcript
    • Chapters
  • S1 · E89
    June 1 · 46 min

    AI vs. Law Enforcement: Deepfakes, Doxing & Deception

    What happens when a deepfake video becomes probable cause? Law enforcement agencies are already grappling with AI-generated evidence, doxing attacks on officers, and a training gap that's growing wider every six weeks. If the justice system can't keep up with the AI threat curve, the consequences won't just be policy problems — they'll be people's lives. In this episode of The Audit, former firefighter-paramedic turned strategic communications consultant Braden Frame — founder of Modern Cartographers and Modern Fortis — joins co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum to break down the rapidly evolving AI threat landscape facing law enforcement and public safety. Braden draws a sharp parallel between law enforcement's slow adoption of social media a decade ago and the AI reckoning happening right now — and why that delay could be catastrophic this time around. 🔍 What We Cover: How AI-generated fake evidence is already entering courtrooms — and why it'll only get harder to detect Why law enforcement is repeating its social media mistakes with AI adoption The guardrails debate: Venice AI, unregulated tools, and who pays the price when there are no limits Doxing attacks on officers and public servants — and how to defend your personal information AI in the field: body cam transcription, paramedic decision support, and where the tech actually works today Authenticity as a weapon: why real human voices will matter more than ever in the age of AI slop Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions! #AI #cybersecurity #lawenforcement #deepfakes #doxing #publicsafety #infosec #artificialintelligence #AIthreats

    • Transcript
    • Chapters
  • S1 · E88
    May 18 · 42 min

    Cyber News: Iranian Hacker, Quantum Ransomware and Rogue AI

    What would you do if ransomware told you not only that your data was gone — but that it was encrypted with a quantum-safe algorithm and you have 72 hours to pay? That's not a hypothetical anymore. In this live news episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum are joined by IT Audit Labs member Bill Harris for a rapid-fire breakdown of the week's most important cybersecurity stories — and a few conversations that went places nobody expected. 🎯 Stories & Topics Covered: Iranian Cyber Group Handala Targets U.S. Troops — WhatsApp-based psychological ops against service members in Bahrain, and what OPSEC looks like when soldiers can't leave their phones at home Agentic AI Risk Goes Live — A real incident where an AI deleted a production database in 9 seconds, and why "trust but verify" has never mattered more Quantum-Safe Ransomware (Kyber) — The first confirmed ransomware family using NIST's post-quantum cryptographic standards, and why it's more marketing than menace — for now Robinhood Email Exploit via Gmail Dot Trick — How threat actors weaponized a years-old stolen email list using a quirk in how Google and Robinhood handle email addresses differently Bitwarden/Checkmarks Supply Chain Attack — Why even security-first tools aren't immune, and how Bitwarden's 90-minute response time became a case study in breach communication Apple's AI Strategy: Late on Purpose? — Is Apple sitting out the AI arms race, or quietly building something nobody's seen yet? Eric's AI Email Vision — A live whiteboard idea for using agentic AI as a personal email firewall that could eliminate phishing at the infrastructure level Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions! #cybersecurity #ransomware #postquantum #AI #infosec #ethicalhacking #supplychain #phishing #NIST #agentic #bitwarden #OPSEC #cyberdefense #ITaudit #TheAudit

    • Transcript
    • Chapters
  • S1 · E87
    May 4 · 32 min

    Inside Email Security: Phishing, Hackers, and Harmony Checkpoint

    Most organizations think they're protected. They're not. Microsoft Defender sounds solid on paper — but in the real world, it's letting phishing, malware, and business email compromise walk right through the door. In this episode of The Audit, the crew pulls back the curtain on one of the most exploited attack surfaces in any organization: email. Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem are joined by IT Audit Labs' own Cameron Birkland — fresh off three first-place CTF wins in Vegas — for a live walkthrough of Check Point Harmony Email, a tool that plugs directly into your Microsoft 365 environment and shows you exactly what your current setup is missing. 🎯 What you'll learn in this episode: Why out-of-the-box Microsoft Defender consistently fails against advanced phishing and BEC attacks — and what "good" email security actually looks like How Check Point Harmony uses machine learning and contextual AI analysis (not just signature matching) to catch threats that bypass traditional filters How threat actors silently set up forwarding rules and inbox monitoring to loot data for weeks — without triggering a single alert IT Audit Labs' new "14 plus one" email security assessment — a 14-day live scan of your Microsoft 365 environment with a full debrief, no disruption required A live demo of the Harmony dashboard: phishing reports, geo-anomaly detection, OneDrive malware scanning, and DLP for exposed sharing links Whether you're securing a 50-person company or advising a 5,000-user enterprise, this episode gives you the practitioner-level insight to finally close the gap in your email defenses. Don't wait until your organization is the next headline. Subscribe for weekly cybersecurity insights from the practitioners actually doing the work. Like, share, and leave us a review on Apple Podcasts if this episode hit home. #emailsecurity #cybersecurity #phishing #businessemailcompromise #Microsoft365 #infosec #checkpoint #harmonyemail

    • Transcript
    • Chapters
  • S1 · E86
    April 20 · 40 min

    Ghost in the Machine: AI Identities & the Spiritual Red Teaming

    Your organization may have hundreds of AI agents running right now that your security team doesn't know exist. Every single one is an identity. Every identity is an attack surface. In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Madhav Nakar, security researcher on the Phantom Labs team at BeyondTrust, to break down one of the most underexplored threats in enterprise security today: untracked AI agents creating exploitable "ghost identities." Madhav just returned from RSA — where he noticed every booth had an AI angle and a bubble forming — and he's here to cut through the noise with hard-hitting research and practical guidance. 🔍 Key Topics Covered: How low-code platforms let non-technical users spawn unvetted AI agents — and why that's a goldmine for attackers Ghost identities: what happens when AI agents run on untracked, over-privileged system identities The AWS sandbox DNS exfiltration proof-of-concept from BSides (BeyondTrust research) Why siloed AWS, Azure, and Okta teams create hidden privilege escalation paths "AI vs. AI" — the emerging defender model where autonomous systems monitor each other Browser extension cross-contamination and prompt injection risk for enterprise Claude deployments The three conditions that make any AI agent dangerous: private data access + untrusted instructions + tool execution Madhav's framework: inventory → least privilege → visibility — the basics that still matter most Bonus: Madhav shares how "spiritually red-teaming yourself" — facing fear, breaking false narratives, and building trust — maps directly to how security professionals should approach zero trust and identity management. Plus: Joshua, Eric, and Nick on conquering stage fright and what that has to do with cybersecurity culture. Don't wait for a ghost identity to become a ghost incident. Subscribe for weekly cybersecurity insights from practitioners, researchers, and the people defending the frontlines. #GhostIdentities, #AIAgentSecurity, #NonHumanIdentity, #ZeroTrust, #TheAuditPodcast

    • Transcript
    • Chapters
  • S1 · E85
    April 6 · 34 min

    Cyber News: Iran Attacks, Greyware, and Backdoor Code

    What if the tools protecting your organization were the ones compromising it? In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem — joined by IT Audit Labs team member Samuel Cala live in the St. Paul studio — unpack a wave of cybersecurity stories that all converge on one unsettling theme: trust is being exploited at every layer of the stack. From an Iranian-linked APT group targeting U.S. healthcare infrastructure, to a sophisticated GitHub Actions supply chain attack that backdoored an AI coding library used by thousands of developers — the crew breaks down exactly how threat actors are weaponizing the tools, platforms, and third-party services organizations depend on daily. They also dive into a disturbing revelation about AI-powered audit certifications: one company allegedly fabricated compliance evidence to hand out ISO 27001 and SOC 2 certifications at a fraction of the cost — raising serious questions about what those credentials are actually worth. In this episode: 🇮🇷 Iran's escalation from cyber espionage to active disruption — what signals to watch for 🔗 The GitHub Actions / LiteLLM supply chain attack explained step by step 🧾 How an AI certification firm allegedly faked audit evidence — and what it means for your vendor trust 📡 FCC bans on foreign-made routers and the gray market hardware problem hiding in plain sight 🤖 OpenAI kills Sora — what it signals about where AI is actually headed Whether you're a CISO trying to defend against nation-state threats or a developer trusting open-source libraries, this episode delivers the context — and the hard questions — you need to stay ahead. Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions! #cybersecurity #supplychainattack #infosec #threatintelligence #ISO27001 #SOC2 #githubsecurity #irancyberattack #aicybersecurity #itauditlabs

    • Transcript
    • Chapters
  • S1 · E84
    March 23 · 43 min

    Cognitive Surrender: How AI Weaponizes Human Psychology

    A $25 million wire transfer. A fake CFO. An entire executive team that didn't exist. This is what modern cybercrime looks like — and your firewall won't stop it. In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum sit down with James McDowell — forensic psychology expert, cybercrime researcher, and adjunct professor at American Military University — to explore the chilling intersection of AI, human psychology, and cybercrime. James introduces the concept of "cognitive surrender": the slow, dangerous transfer of our thinking to AI tools, and how threat actors are exploiting it at scale. What You'll Learn: What "cognitive surrender" is and why it's cybercrime's greatest accelerant How a $25M deepfake scam bypassed every red flag a trained employee had The psychology behind System 1 vs. System 2 thinking — and why attackers time their strikes around your lunch break Why voice passwords and family code phrases are becoming critical security tools How FraudGPT and dark-web AI models are lowering the barrier for cybercriminals What James's wave theory reveals about how we trust — and how that trust gets exploited 📖 Guest: James McDowell Forensic psychologist, cybercrime researcher, and author of Forensic Psychology and the Human Side of Cybercrime. James teaches at American Military University and leads research at [Research Institute] focused on the psychology of cyber offenders and victims. 📚 Book available on Amazon and Routledge. Search: Forensic Psychology and the Human Side of Cybercrime Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers the psychological intelligence to help protect your business. Like, share, and subscribe for more in-depth security discussions! #cybersecurity #cybercrime #socialengineering #deepfake #AIthreats #infosec #phishing #cyberpsychology #ethicalhacking #CISO

    • Transcript
    • Chapters
  • S1 · E83
    March 9 · 36 min

    Surviving a Cardiac Event: Biometric Data and the Risks Nobody Talks About

    What if the device keeping you alive was also a cybersecurity vulnerability? That's not a hypothetical — it's Victor Barge's reality. In this episode of The Audit, IT Audit Labs' Global Delivery Director Victor Barge shares the story of his sudden cardiac event and the life-saving defibrillator now implanted in his chest and the eye-opening security questions that followed. Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum connect Victor's story to the real-world cyber risks organizations ignore every single day. What you'll learn in this episode: How modern pacemakers and defibrillators transmit biometric data 24/7 — and what happens if that data is compromised Why the 2017 Abbott pacemaker recall of 500,000 devices is a warning the industry hasn't fully heeded The parallel between reactive healthcare and reactive cybersecurity — and why waiting costs you more Why billion-dollar organizations are still storing passwords in spreadsheets in 2026 What continuous monitoring in IT security can learn from real-time cardiac telemetry Whether you're a CISO, IT auditor, or just someone wearing a smartwatch, this episode will make you rethink what "sensitive data" really means.

    • Transcript
    • Chapters
  • S1 · E82
    February 23 · 44 min

    Secret Service Agent Reveals Undercover Cyber Ops

    What does it take to go undercover with international cybercriminals — with no backup, no safe house, and no script? In this episode of The Audit, Richard LaTulip, Field CISO at Recorded Future and former U.S. Secret Service agent, pulls back the curtain on three years of undercover operations spanning Thailand, Dubai, Macau, and China. From buying stolen credit card data in bulk to handing cheap government-issued laptops to disappointed hackers, Richard shares the raw, unfiltered reality Hollywood never shows you. Co-hosts Joshua J Schmidt, Eric Brown, Nick Mellem, and Jen Lotze dig into the psychology of social engineering, the stark differences between nation-state and financially motivated threat actors, and why your employees are simultaneously your greatest asset and your biggest vulnerability. Richard breaks down how SolarWinds revealed the patience of nation-state operations, why cultural awareness is a cybersecurity weapon, and how organizations can shift security from a cost center to a value driver. 🔑 Key Topics Covered: Undercover operations against international cybercriminal networks — the reality vs. the Hollywood version Nation-state vs. financially motivated threat actors — how their goals fundamentally change defense strategy The ClickFix campaign and social engineering attacks targeting human psychology How Recorded Future delivers actionable, tailored threat intelligence vs. generic feeds Why tabletop exercises need HR, communications, and every department at the table • Cultural dimensions of cybersecurity — from Eastern European honeytraps near nuclear sites to password reuse psychology Turning your security team from a "cost center" into a trusted business ally Operation Carter Chaos — Richard's new book chronicling the untold human side of undercover cyber operations 📖 Richard's book Operation Carder Kaos is available now on Amazon. 🔔 Like, share, and subscribe for more in-depth cybersecurity conversations. Don't forget to leave a review — it helps us reach more security professionals like you.

    • Transcript
    • Chapters
  • S1 · E81
    February 9 · 33 min

    Cyber News: Advanced Phishing, ClickFix & AI Wearables

    Microsoft dominates 22% of all phishing attacks, a $800 tool tricks 60% of victims into self-hacking, and Apple's planning a surveillance pin that records everything—welcome to 2025's cybersecurity nightmare. In this episode of The Audit, co-hosts Joshua J Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from IT Audit Labs to dissect three headlines that prove the threat landscape isn't just evolving—it's accelerating. From brand impersonation scams that exploit your brain's pattern recognition to ClickFix malware that bypasses antivirus by weaponizing copy-paste commands, this conversation reveals how attackers are shifting from breaking through defenses to manipulating humans into opening the door themselves. What You'll Learn: Why trusted brands like Microsoft, Amazon, and DHL are irresistible phishing targets, especially during high-traffic seasons when vigilance naturally drops How ClickFix attacks exploit legitimate-looking broken websites to trick users into installing malware through their own command prompts—achieving 60% success rates that evade traditional security Real-world consequences of sophisticated social engineering, including a $116,000 wire fraud loss that proves even tech-savvy professionals aren't immune The privacy and consent implications of Apple's rumored 2027 AI wearable with dual cameras and always-on environmental recording Whether constant surveillance is becoming the unavoidable price of technological convenience—and what that means for building security cultures in organizations today From training employees to recognize copy-paste scams to navigating the ethics of ambient recording devices, this episode delivers frontline intelligence for security professionals and practical awareness for anyone trying to stay safe online. #phishing #clickfix #cybersecurity #socialengineering #applewearable #privacy #malware #infosec #brandimpersonation

    • Transcript
    • Chapters
  • January 26 · 26 min

    Field Notes: New Year Catch-Up, Coffee, And Team DNA

    In this episode of The Audit, co-hosts Eric Brown and Nick Mellem dive deep into organizational psychology and team dynamics with a refreshingly honest look at how IT Audit Labs is using assessments like CliftonStrengths, Kolbe, and PRINT to decode their team. This isn't fluffy HR talk—it's strategic workforce optimization that directly impacts how security teams respond to threats, collaborate under pressure, and execute on complex projects. Eric and Nick discuss why understanding your team's natural strengths, motivators, and triggers is just as critical as deploying the right tech stack. From reducing meeting bloat to being more intentional with time and resources, they share real-world lessons on building a culture where people operate in their zone of genius. Plus, they tackle the "what tool would you deploy first" scenario—spoiler: it's not what you think. 🔑 KEY TOPICS COVERED: Why organizational assessments (CliftonStrengths, Kolbe, PRINT) matter for security teams How to be more intentional with meetings, time, and team collaboration First tools to deploy in a new security environment (MFA, YubiKeys, Veronus) The shift from reactive security to proactive team alignment Using AI tools like Gemini to streamline communication and decision-making #CliftonStrengths #Cybersecurity #TeamBuilding #ITLeadership #SecurityCulture #CISOLife #InfoSec #OrganizationalPsychology

    • Transcript
    • Chapters
  • S1 · E80
    January 12 · 40 min

    AI Architecture: Stop Button Pushing, Start Building

    What if the difference between AI mediocrity and breakthrough isn't the tool—it's how you architect your approach? Carter Jensen from The Uncommon Business joins the crew to reveal why most people are stuck "button pushing" while others are unlocking 3X productivity gains. This isn't theory; it's the frontline reality of businesses transforming workflows with the right AI architecture. If you're tired of surface-level AI hype and ready for actionable intelligence on integrating AI into security, compliance, and everyday business operations, this episode delivers. Whether you're Blockbuster or Netflix is up to you. 🎯 What You'll Learn: AI Architecture vs. Button Pushing – The mindset shift that unlocks 3-4X productivity gains instead of mediocre results Real Cybersecurity Wins – How IT teams use AI to speed through compliance audits (PCI, CJIS, HIPAA) and tackle complex security workflows Enterprise Implementation Truth – Why expensive AI tools fail without strategy, and what actually works for business adoption The AI Bubble Debate – Is this hype or the biggest business transformation since the internet? Carter brings receipts from the frontlines Don't let your team fall behind while competitors architect their way to 4X output. This episode arms IT leaders, CISOs, and security professionals with the mindset shift needed to deploy AI that actually moves the needle. Like, share, and subscribe for more cutting-edge cybersecurity and AI implementation strategies! #ArtificialIntelligence #Cybersecurity #AIforBusiness #ITaudit #ComplianceAutomation

    • Transcript
    • Chapters
  • S1 · E79
    Dec 29, 2025 · 22 min

    The Audit 2025: Deepfakes, Quantum & AI That Changed Everything

    In this special year-end episode, Joshua Schmidt revisits the most mind-bending moments from The Audit's 2025 season. From Justin Marciano and Paul Vann demonstrating live deepfakes in real-time (yes, they actually did it on camera) to Bill Harris explaining how Google's quantum experiments suggest parallel universes, to Alex Bratton's urgent warning about the AI adoption crisis happening right now in boardrooms everywhere. What You'll Learn: How adversaries are using free tools to create convincing deepfakes for job interviews and social engineering attacks—and why this represents a national security threat Why NASA shut down its quantum computer after getting results that "challenge contemporary thinking" (and the wild theories circulating about what they discovered) The critical mistake companies are making with AI integration: racing ahead without governance, security frameworks, or responsible use policies How the Pi-hole community exemplifies open-source security at its best—enterprise-grade protection at fractions of the cost Why IT teams saying "no" to AI isn't realistic, and what responsible AI adoption actually looks like This isn't just a recap—it's a wake-up call. These conversations reveal the inflection points where standing still means falling behind. Whether you're a CISO, security analyst, IT auditor, or business leader trying to navigate AI adoption, these clips offer the perspective you need heading into 2026. Don't wait until 2026 to realize you missed the critical shift. Subscribe now for cutting-edge cybersecurity insights that keep you ahead of evolving threats. #cybersecurity #deepfake #quantumcomputing #AI #infosec #ethicalhacking #cyberdefense #2025yearinreview

    • Transcript
    • Chapters
  • S1 · E78
    Dec 15, 2025 · 35 min

    Gaming to Cybersecurity: How AI Agents Fight Alert Overload

    What if you could hire an army of AI security analysts that work 24/7 investigating alerts so your human team can focus on what actually matters? Edward Wu, founder and CEO of DropZone AI, joins The Audit crew to reveal how large language models are transforming security operations—and why the future of cyber defense looks more like a drone war than traditional SOC work. From his eight years at AttackIQ generating millions of security alerts (and the fatigue that came with them), Edward built DropZone to solve the problem he helped create: alert overload. This conversation goes deep on AI agents specializing in different security domains, the asymmetry problem between attackers and defenders, and why deepfakes might require us to use "safe words" before every Zoom call. What You'll Learn: How AI tier-1 analysts automate 90% of alert triage to find real threats faster Why attackers only need to be right once, but AI can level the playing field Real-world deepfake attacks hitting finance teams right now The societal implications of AI-driven social engineering at scale Whether superintelligence will unlock warp engines or just better spreadsheets If alert fatigue is crushing your security team, this episode delivers the blueprint for fighting back with AI. Hit subscribe for more conversations with security leaders who are actually building the future—not just talking about it. #cybersecurity #AIforCybersecurity #SOC #SecurityOperations #AlertFatigue #DropZoneAI #ThreatDetection #IncidentResponse #CyberDefense #SecurityAutomation

    • Transcript
    • Chapters
Showing 1–20 of 22 episodes