Security Bros

Security Bros

John and Rocky Giglio, brothers from the same mother share insights from their combined 50+ years of experience in the trenches of cyber, infrastructure, and consulting.

Episodes

  1. 16 JAN

    CrowdStrike Proved Patch Management is Broken

    In this episode the Security Brothers, Rocky and John Giglio delve into the complexities of patch management and vulnerability management in the tech industry. They discuss the ongoing challenges faced by security practitioners, the implications of recent incidents like the CrowdStrike outage, and the evolving role of AI in enhancing security measures. The conversation emphasizes the need for comprehensive testing, strategic planning, and prioritization in managing vulnerabilities, while also exploring the importance of adapting to new technologies and methodologies in cybersecurity.TakeawaysHandling old tech and patch management is a significant issue.Vulnerability management is overwhelming but necessary.Prioritization is key in dealing with numerous vulnerabilities.Automated systems can help reduce the burden of patch management.Testing is crucial before rolling out updates.AI can assist in writing tests and improving deployment processes.A comprehensive security strategy includes monitoring and logging.Continuous learning from incidents is essential for improvement.Collaboration with business leaders is vital for effective security management.The landscape of vulnerabilities is constantly evolving, requiring adaptive strategies.Chapters00:00 Introduction to Security Challenges02:49 The Importance of Patch Management06:03 Navigating Vulnerabilities in Modern Tech08:53 Lessons from the CrowdStrike Incident11:45 Testing and Deployment Strategies14:49 The Role of AI in Security Management17:43 Building a Comprehensive Security Strategy20:53 Final Thoughts and Future Directions

    28 min
  2. 16/12/2025

    Security Bros - Episode 1 - The Misconfiguration Crisis in Cloud Security

    John and Rocky Giglio kick of the Security Bros podcast with a special guest, Justin O'Connor founder of Onward Platforms. Want to see it live with your own eyes? Jump into the webinar Dec 19th, 12pm EST: https://bit.ly/sb-infracode Subscribe to catch every episode and stay up-to-date with security trends and the latest security tech. Summary In this inaugural episode of the Security Bros podcast, hosts Rocky and John Giglio welcome Justin O'Connor, an industry leader in cloud and AI, to discuss the current state of cloud security, the challenges posed by misconfiguration, and the impact of AI on coding practices. Justin introduces Infracodebase, a tool designed to enhance security in infrastructure as code, and demonstrates its features by building a secure API management landing zone. The conversation highlights the importance of integrating security from the outset and the need for organizations to adapt to the evolving landscape of cloud technology. Takeaways Cloud adoption is primarily hybrid or multi-cloud.85-90% of organizations report an increase in cloud security incidents.Misconfiguration is a leading cause of cloud security failures.AI can generate code quickly, but often lacks context.Security posture varies significantly between startups and enterprises.InfraCodebase helps enforce security standards across teams.The tool allows for easy integration with existing security tools.Automated security checks can improve compliance and reduce risks.Creating a secure infrastructure requires ongoing monitoring and adjustments.The future of cloud engineering lies in simplifying infrastructure management. Sound bites "AI slop is a real problem." "This is the future of cloud engineering." "We need to layer in security from day zero." Chapters 00:00 Introduction to Security Bros Podcast 02:42 Current State of Cloud Security 04:39 The Impact of AI on Security 07:43 Understanding Security Posture 09:32 Infracodebase Product Overview 12:33 Creating Secure API Management 17:21 Governance and Control in Security 19:13 Terraform Configuration and Security Best Practices 24:19 Understanding Infrastructure Architecture and Security Checks 28:48 MCP Server Integration and Security Considerations 34:33 The Future of Cloud Engineering and Security 37:55 Enterprise Scale Infrastructure as Code Check out Infracodebase at https://bit.ly/4iZM2LH This is not sponsored, we just like Justin and his team.

    39 min

About

John and Rocky Giglio, brothers from the same mother share insights from their combined 50+ years of experience in the trenches of cyber, infrastructure, and consulting.