CISSP Cyber Training Podcast - CISSP Training Program

Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm. Tune in and take the reins of your cybersecurity journey—let’s ride into excellence together! 🚀

  1. 14h ago

    CCT 373: An AI Agent Was Told No and Got In Anyway (CISSP Domain 6.2)

    Send us Fan Mail An AI agent gets blocked by access controls, then calmly finds another way in anyway and that is the wake-up call. I use a recent Hacker News story about an automated agent bypassing an Australian government health portal to dig into what CISSP Domain 6.2 is really testing: not your ability to recite a list of techniques, but your ability to manage authorization, scope, and rules of engagement so a “test” does not turn into an intrusion. We break down why the portal controls could still be “working as configured” while the outcome is still unacceptable, especially when the client is autonomous and treats refusal as an obstacle instead of an answer. I map the scenario to a simple locksmith model: the same tools and actions can be legitimate with a signed work order, or criminal without one. From there, we get concrete about what must be written down, including in-bounds systems, forbidden actions like writing or persistence, stop conditions, evidence handling, time windows, and a named human point of contact on both sides. Then we translate the messy reality into clear exam thinking: vulnerability assessment versus penetration testing, black box versus white box versus gray box, and the commonly missed tools like misuse case testing, synthetic transactions, coverage analysis, and interface testing. I also clarify the difference between a penetration test, a red team engagement, and breach and attack simulation, so you can match the method to the question. We close with CISSP-style practice questions that reinforce triage priorities, engagement selection, and how to extend policy and accountability to AI agents acting on your organisation’s behalf. If you want more Domain 6.2 clarity and fewer distractor traps, subscribe, share this with a study partner, and leave a review so more CISSP candidates can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  2. Sep 28

    CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)

    Send us Fan Mail A stolen password is annoying. A stolen session token can be invisible, valid, and instantly profitable. Today we dig into a real warning sign from Okta threat intelligence: infostealer malware lifted live session tokens from browsers, and thousands of Google sessions were still working weeks later. No MFA prompt. No brute force. Just a legitimate session replayed by the wrong person, with real dollar damage through unauthorized usage and credits. We use that story to sharpen the CISSP Domain 5.6 mindset around implementing authentication systems and, more importantly, validating tokens after sign-in. I walk through why authentication and token validation are different security functions with different “owners,” why forcing password resets does not invalidate an attacker’s existing session, and what a token signature does and does not prove. Then we get practical: audience claim checks, expiration and token lifetime ceilings, scope validation, and why “skipping the audience check breaks nothing in testing” is exactly how breaches scale. We also cover the controls that shrink risk when you cannot reliably detect theft: short access token lifetimes, narrow scoping to limit blast radius, hardware-backed signing key storage, and automated key rotation with defined crypto periods. To lock it in, we run through four CISSP-style questions and explain the traps so you can answer like a risk-focused manager, not a spec reciter. Subscribe for more CISSP exam training, share this with a teammate who owns IAM, and leave a review so more candidates can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  3. Sep 21

    CCT 371: Secure Communication Channels and Who Is Really On Your Call (Domain 4.3)

    Send us Fan Mail One video hotline feels like a single, simple conversation until you trace the call path and realise there may be seven companies involved in making it work. That’s the spark for this training-focused breakdown of CISSP Domain 4.3 secure communication channels, using the viral AI “actress hotline” story to show how modern voice and video collaboration really behaves behind the curtain. We start with a practical analogy: you think you’re transacting with the waiter, but your meal passes through a hidden chain of people you never met. The same thing happens with telephony, video conferencing, contact centres, telehealth platforms, transcription tools, AI response generation, and cloud infrastructure. Even when every vendor is legitimate, contracted, and disclosed, your security model can fail if it only accounts for the one company you can see. From there, we get concrete about what CISSP candidates are tested on: who can join a call, what services are attached (recording, transcription, analytics), what survives after the call, and where trust boundaries actually sit. We also tackle a classic trap: encryption in transit can stop interception, but it does not prevent authorised intermediaries like transcription providers or model services from decrypting and processing content. Finally, we connect the dots to retention “clocks” and transborder data flows, including how Domain 4 channel design intersects with Domain 1 legal transfer mechanisms and accountability. If you’re studying for the CISSP exam or building a real-world secure communications programme, you’ll leave with a clearer mental model and a set of exam-style questions you can use right away. Subscribe, share this with a fellow CISSP candidate, and leave a review so more security pros can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  4. Sep 14

    CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

    Send us Fan Mail A compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to what’s happening with FIPS 140 validations: your VPN can keep encrypting, your database can keep protecting data, and yet an assessor can still mark you down because “working” is not the same as “validated.” We walk through the practical CISSP Domain 3 lesson behind the noise: the difference between an algorithm claim (we use AES-256), a configuration claim (we run in FIPS mode), and an evidence claim (we hold an active FIPS 140 validation on the CMVP list). With FIPS 140-2 certificates moving to historical status and FIPS 140-3 testing queues stretching beyond 500 days, the manager move is not wishful thinking. It’s documenting the gap, treating it as risk, and getting formal risk acceptance with executive sign-off plus a real remediation plan, especially if you’re facing CMMC or customer security assessments. From there we connect the dots across cryptographic life cycle management, cryptographic agility, and the real places crypto fails: key management and implementation. We cover HSM storage, rotation, dual control versus split knowledge, PKI revocation choices (CRL, OCSP, OCSP stapling), common cryptanalysis categories, and why side-channel and fault-injection attacks hit modules rather than “the math.” We then get clear on quantum risk, harvest now decrypt later, and what NIST’s post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) mean for your migration plan starting with a cryptographic inventory. Subscribe for more CISSP exam-ready training, share this with a teammate who owns compliance evidence, and leave a review if it helped. What would fail first in your environment: the crypto itself, or the proof you can show an auditor? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  5. Sep 7

    CCT 369: Security Models Demystified - CISSP Domain 3.2 (Replay of CCT 278)

    Send us Fan Mail 🔁 REPLAY — this episode originally aired as CCT 278 in September 2025. I'm heads-down finishing a Domain 3 cryptography episode, so I'm re-running one of the strongest episodes in the archive rather than shipping something thin. If you're newer to the show, you haven't heard this one. And if you're studying Domain 3 right now the timing works in your favor — security models are the foundation the rest of the domain sits on, and next week's episode picks up in the same domain. New material next Monday. --- Security models represent some of the most difficult concepts for CISSP exam candidates to master, yet they form the foundation of implementing and understanding security controls. This episode breaks down Domain 3.2's security models using plain language and practical examples. The episode opens with analysis of the TransUnion data breach affecting 4.4 million individuals, demonstrating why proper security architecture matters. It then explores the Trusted Computing Base (TCB) — the foundation for secure code — covering key components like the Security Kernel, Reference Monitor, Trusted Path, and TCB Boundary. The core focus examines the eight major security models essential for exam preparation. These include Bell-LaPadula's confidentiality-focused "no read up, no write down" principle, Biba's integrity-centered approach, Clark-Wilson's business integrity enforcement through duty separation, and Brewer-Nash's conflict-of-interest prevention. Additional models addressing specific security concerns are also covered. The episode concludes with exam preparation guidance, highlighting which models deserve priority study attention. ⚠️ Since this is a replay: the TransUnion breach discussed at the top is from 2025. The Domain 3.2 material is unchanged and still current. Ready to stop guessing on Domain 3? Accelerator $19/mo · Pro $39/mo · Sprint Cohort https://www.cisspcybertraining.com Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  6. Aug 31

    CCT 368: CISSP Asset Security and Data Classification (Domain 2)

    Send us Fan Mail Nine million images. No password. No encryption. And the defence was basically: “It wasn’t public because you had to know the URL.” That single line opens up one of the most important CISSP Domain 2 conversations you can have: security through obscurity is not access control, and a hidden address is not a key. We take this real data exposure and translate it into the kind of manager-level reasoning the CISSP exam demands, not memorised trivia. We then zoom out into Asset Security fundamentals: identification and inventory, data classification based on impact, and the roles that make controls enforceable. We break down data owner versus custodian, plus controller and processor language you will see in privacy frameworks like GDPR. The core takeaway is simple and painful: without a named owner, nothing downstream is mandatory, so encryption, authentication, retention jobs, and evidence-producing logging keep losing to deadlines. Finally, we turn the incident into practice questions and “spot the trap” exam thinking: accountability does not transfer when you outsource, absent controls are not weak controls, and impact is not likelihood. We also hit retention and destruction across the data lifecycle, including NIST SP 800-88 clearing, purging, and destruction, and where degaussing and crypto erase really belong. Subscribe for more CISSP exam prep with real-world security stories, share this with a study partner, and leave a review if it helps you think more clearly under exam pressure. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  7. Aug 24

    CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10)

    Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions.  From there, we shift into training mode and get concrete about threat modeling concepts and methodologies. We define threat modeling the way the exam cares about it: proactive, iterative, and designed to produce security requirements and prioritised countermeasures that feed your SDLC and risk register. We break down the three starting perspectives (asset-centric, attack-centric, and system-centric), then anchor STRIDE to data flow diagrams and trust boundaries so you can identify what security property is actually being violated, not just recite acronyms.  We also cover the difference between identifying and ranking threats so you don’t fall into the classic traps: DREAD ranks threats you already found, while PASTA starts with business objectives and risk appetite and is built for risk-centric outputs leaders can fund. We talk attack trees, why MITRE ATT&CK is an input rather than a methodology, and why your threat actor catalog must include authorized non-human identities and vendor integrations that can operate outside intended scope. If this helps, subscribe, share it with a study buddy, and leave a quick review so more CISSP candidates can find it. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

  8. Aug 17

    CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)

    Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t be your finish line. From there, we tie the real-world scenario directly to CISSP Domain 8 Software Development Security and the secure SDLC. I lay out a clear, exam-friendly framework for assessing third-party and acquired software risk: Software Composition Analysis (SCA), Software Bill of Materials (SBOM), vendor and publisher risk assessment, and runtime plus pipeline controls. We talk about why SCA is necessary but incomplete, how a living SBOM enables fast exposure checks when a new campaign hits, and why Executive Order 14028 is pushing SBOM adoption into “expected” territory for many organisations. We also get practical about CI/CD pipeline security: dependency pinning, trusted publishing workflows, signed commits, OIDC, and package signing and verification approaches like Sigstore and Cosign. Finally, we run through scenario-based practice questions that highlight common CISSP traps and the manager mindset the exam rewards. If you want more episodes like this, subscribe, share it with a developer or security lead, and leave a quick review so more CISSP candidates can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

4.6
out of 5
35 Ratings

About

Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm. Tune in and take the reins of your cybersecurity journey—let’s ride into excellence together! 🚀

You Might Also Like