Skip to content
Artwork for The Cyber Kitchen: TrustNet Cybersecurity Podcast
TechnologyBusiness

The Cyber Kitchen: TrustNet Cybersecurity Podcast

TrustNet

Welcome to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Led by TrustNet's CISO and founder, Trevor Horwitz, each episode breaks down the real recipe for success for CISOs and industry professionals navigating today’s threat landscape, one ingredient at a time.

trustnetinc.substack.com
Play
  • 10 episodes
  • monthly
  • Avg 36 min
  • English
  • Tuesday · 38 min

    The Cyber Kitchen Episode 010: A New Recipe for Penetration Testing: AI, Continuous Testing, and Attack Paths

    Welcome back to The Cyber Kitchen, where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet’s Jamie Kerem with CISO and founder, Trevor Horwitz. “A penetration test doesn’t reduce risk when the tester finds the vulnerability. Risk changes when that vulnerability can no longer be used against you.” In this episode, Jamie and Trevor explore how penetration testing is being reinvented as modern environments change faster than traditional annual testing cycles can keep up with. The conversation breaks down what organizations are actually buying when they invest in a penetration test, from internal and external testing to web applications, APIs, cloud environments, and identity. They examine why scope matters, why automated vulnerability scanning isn’t the same as human-led penetration testing, and why an annual pentest should be viewed as a snapshot rather than a year-round picture of security. Jamie and Trevor also explore how AI, Penetration Testing as a Service (PTaaS), continuous testing, and attack-path analysis are changing offensive security. As technology makes it possible to discover vulnerabilities faster and across a much larger attack surface, they discuss why finding more issues doesn’t necessarily mean reducing more risk—and why remediation may ultimately be the bigger bottleneck. Along the way, they look at why security teams should focus less on individual findings and more on the attack paths connecting them, how identity, APIs, cloud infrastructure, and AI systems are reshaping what penetration testers need to assess, and what CISOs should demand from modern penetration testing. Ultimately, the conversation asks organizations to rethink the metric that matters most: how quickly can you move from “this can be exploited” to “it can’t be exploited anymore”? Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E9
    August 13 · 33 min

    The Cyber Kitchen Episode 009 - The Kitchen Never Closes: Why Managed Security Runs 24/7

    Welcome back to The Cyber Kitchen, where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet’s Jamie Kerem with CISO and founder, Trevor Horwitz. “Technology creates visibility. People create security.” In this episode, Jamie and Trevor tackle a deceptively simple cybersecurity question: when something suspicious happens in your environment at two in the morning, who is actually watching? The conversation explores why strong security tools alone don’t guarantee protection, how attackers often start with opportunity rather than a specific target, and why generating an alert is very different from investigating it and determining whether something actually requires action. Jamie and Trevor also break down what security monitoring looks like behind the scenes, from sorting through enormous volumes of security events and connecting seemingly normal activity to using AI to help analysts summarize logs, correlate alerts, review evidence, and investigate faster. They examine why human judgment remains critical and what organizations should look for when evaluating a managed security provider. Along the way, they share practical questions business and security leaders can ask about 24/7 monitoring, alert investigation, incident response, internal versus outsourced security operations, and why the strongest organizations make security part of how they operate rather than something they think about once a year during an audit. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E8
    July 29 · 52 min

    The Cyber Kitchen EP 008: Searing the C-Suite: How California’s New Rules Put Cybersecurity on the Executive Menu (CPPA)

    Welcome back to The Cyber Kitchen, where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet’s Jamie Kerem with CISO and founder, Trevor Horwitz. “Cybersecurity is no longer an IT responsibility. It’s a business leadership responsibility.” In this episode, Jamie and Trevor examine California’s new cybersecurity audit regulations and why they’re redefining the relationship between privacy, security, and executive leadership. The conversation explores what the regulations actually require, which organizations are most likely to be affected, and what independent cybersecurity audits will evaluate beyond technical controls. Jamie and Trevor also discuss why governance has become the foundation of cybersecurity maturity, how existing investments like SOC 2, ISO 27001, PCI DSS, and the NIST Cybersecurity Framework can accelerate readiness, and what organizations should realistically budget for preparation, remediation, automation, and ongoing compliance. Along the way, they share practical guidance on executive accountability, board oversight, continuous compliance, and why building a mature cybersecurity program ultimately delivers far more value than simply passing an audit. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E7
    June 29 · 46 min

    The Cyber Kitchen Episode 007 - From Prep to Plate: The Real Cost of SOC 2

    Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet’s Jamie Kerem with CISO and founder, Trevor Horwitz. “The audit is the finish line. What you’re really building is an operating model for trust.” In this episode, From Prep to Plate: The Real Cost of SOC 2, Jamie and Trevor unpack one of the most misunderstood topics in compliance: what SOC 2 actually costs. While many organizations focus on auditor fees, the conversation reveals a much broader picture that includes readiness assessments, remediation, engineering effort, compliance operations, automation platforms, and ongoing program maintenance. From hidden labor costs and operational debt to compliance fatigue and the growing role of AI, the discussion explores why the audit itself is often only a small part of the overall investment. Trevor breaks down the major cost drivers that influence SOC 2 programs, including Trust Services Criteria selection, organizational maturity, infrastructure complexity, and the difference between Type 1 and Type 2 reporting. The episode also examines how compliance automation platforms are changing the economics of compliance, why continuous compliance is often more cost-effective than annual audit preparation, and how organizations can avoid expensive scoping mistakes that add complexity without reducing risk. Finally, Jamie and Trevor provide realistic budget expectations for startups, growth-stage companies, and enterprise organizations, while exploring the often-overlooked cost of not having SOC 2 in today’s competitive B2B environment. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E6
    May 15 · 37 min

    The Cyber Kitchen Episode 006 - Penetration Testing: What’s Really Cooking Behind The Scenes

    Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by Jamie Kerem with CISO and founder, Trevor Horwitz. “A vulnerability without exploitation is just a hypothesis.” In this episode, Penetration Testing: What’s Really Cooking Behind the Scenes, Jamie and Trevor break down penetration testing from the inside out, moving beyond checkbox compliance and into the realities of adversarial security validation. The conversation walks through the full lifecycle of a penetration test, from scoping and reconnaissance to exploitation, lateral movement, post-exploitation, remediation, and continuous testing. Along the way, they unpack how attackers actually think, move through environments, chain vulnerabilities together, and exploit the gaps between security controls. They also explore: * Vulnerability scanning vs penetration testing * Black box, gray box, and white box testing * Cloud, API, network, and application security testing * Phishing, MFA fatigue, and human-layer attacks * Business logic abuse and identity-based attack paths * AI-assisted remediation and continuous security validation * Why modern organizations are shifting from annual testing to continuous testing integrated into CI/CD and DevSecOps workflows Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E5
    April 17 · 18 min

    The Cyber Kitchen Episode 005 - Inside the ISO 27001 Kitchen: Engineering Security Beyond the Recipe (Part 2)

    Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet‘s Jamie Kerem with CISO and founder, Trevor Horwitz. “Controls aren’t mandatory by default. Justification is.” In this episode, Inside the ISO 27001 Kitchen: Engineering Security Beyond the Recipe (Part 2), Jamie and Trevor build on the foundations introduced in Part 1 and go deeper into how ISO 27001 controls are engineered in modern cloud-first environments. The focus shifts to operational maturity, covering SaaS governance through defined exit strategies, secure CI/CD pipelines with shift-left practices, and continuous validation through dynamic testing and API discovery. From data masking in non-production environments and immutable logging to anomaly-based monitoring, secrets orchestration, and automated key rotation, the conversation highlights how controls must be continuously validated, not just implemented. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • March 30 · 29 min

    The Cyber Kitchen Episode 004 - RSAC 2026: The Real GRC Conversations Happening Behind the Booths

    Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet‘s Jamie Kerem with CISO and founder, Trevor Horwitz. “RSA Conference is always fascinating because you get the marketing on the main stage, but the real insights come from conversations between CISOs trying to solve the same problems.” In this episode, RSAC 2026: The Real GRC Conversations Happening Behind the Booths, Jamie and Trevor unpack the key Governance, Risk, and Compliance themes emerging from RSA beyond the vendor headlines. Drawing from real conversations happening in hallways and side meetings, the discussion highlights how security leaders are shifting their focus from tools to governance, accountability, and enterprise-wide risk. From AI governance and third-party risk to accelerating regulations and identity as the new control layer, the episode explores how organizations are being pushed to rethink how they manage and communicate risk. It also reflects the broader shift of cybersecurity into enterprise risk governance, where decisions are increasingly tied to business impact and board-level visibility. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • S1 · E3
    March 20 · 37 min

    The Cyber Kitchen Episode 003 - Inside the ISO 27001 Kitchen: Engineering Security Beyond the Recipe (Part 1)

    Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet‘s Jamie Kerem with CISO and founder, Trevor Horwitz. “ISO 27001 controls will never make you secure. It’s the discipline behind selecting and operating those controls that will.” In this episode, Inside the ISO 27001 Kitchen: Engineering Security Beyond the Recipe (Part 1), Jamie and Trevor move from theory into the operational reality of ISO 27001 controls. They break down the four control domains and explain how modern security programs translate risk decisions into operational safeguards. From attribute-driven control design and dynamic asset inventories to identity lifecycle management, privileged access, endpoint posture validation, physical access monitoring, vulnerability orchestration, and network segregation, the conversation explores how mature environments actually engineer controls in cloud-first systems. Watch the full PART 1 episode now and keep an eye out for PART 2. Take the conversation further: * TrustNetInc.com * https://www.linkedin.com/company/trustnet-inc * https://www.linkedin.com/in/trevorhorwitz/ * https://www.linkedin.com/in/jamie-kerem * info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

  • #1
    January 9 · 31 min

    The Cyber Kitchen Episode 001 - SOC 2 Cookbook: Recipes for Success

    Welcome to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by TrustNet's Jamie Kerem with CISO and founder, Trevor Horwitz. In this episode, SOC 2 Cookbook: Recipes for Success, Jamie and Trevor serve up a practical SOC 2 guide for business leaders, covering what SOC reports mean, how Type 1 differs from Type 2, what belongs in your scope, and how to avoid the biggest compliance pitfalls. Packed with clear explanations and real-world insights, this episode turns SOC 2 into a strategic ingredient for trust, growth, and smoother enterprise deals. Take the conversation further: TrustNetInc.com https://www.linkedin.com/company/trustnet-inc https://www.linkedin.com/in/trevorhorwitz/ https://www.linkedin.com/in/jamie-kerem info@TrustNetInc.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit trustnetinc.substack.com

Showing 1–10 of 10 episodes