SecOops Cybersecurity Podcast

Ben, Moiz and Sneh

Join Ben, Moiz, and Sneh as they explore the ever-evolving world of cybersecurity. From phishing scams and hacking stories to emerging threats and defense strategies, they break down complex topics into relatable conversations. Whether you’re a tech pro or just cyber-curious, tune in to learn, laugh, and stay ahead of the latest in security—because in cybersecurity, there’s always an “oops” to uncover. Note: This podcast is powered by AI

  1. 4d ago

    Emerging Tech & Threat Trends Series – Episode 1 – AI and Cybersecurity – from AI-driven attacks to AI-powered defense

    🎙️ Episode: AI and Cybersecurity – From AI-Driven Attacks to AI-Powered Defense In this episode of the Emerging Tech & Threat Trends Series by Sec Oops, powered by Cyber View Point, we tackle the biggest double-edged sword in the history of cybersecurity: artificial intelligence. We open with an uncomfortable truth — the same technology helping defenders detect threats faster than ever is simultaneously helping attackers craft campaigns more convincing, more automated, and more devastating than anything seen before. Same tool. Same moment. Two very different trajectories. The team breaks down why this AI moment is fundamentally different from previous technology waves — and why the people who built these systems are the most vocal about how unprepared we are. From AI-generated phishing that renders traditional awareness training obsolete, to deepfakes enabling CEO fraud at scale, to attack timelines that collapsed from eight hours to 22 seconds, we walk through what the offensive landscape actually looks like right now. We then flip the lens — exploring how AI is transforming defense through anomaly detection, automated threat intelligence, and AI-powered SOC operations. We cover the emerging agentic frontier, where AI systems no longer just answer questions but take actions autonomously, and why that shifts the entire security model from access control to action control. From there we zoom out to the geopolitical dimension — the four battlegrounds where nations are competing for AI supremacy — and explore why active defense, not passive protection, is becoming the only viable strategy in a machine-speed threat environment. 👉 Tune in to learn why AI is not the future of cybersecurity — it's the present — and walk away understanding what your organisation needs to do right now before the gap between attacker capability and defender readiness becomes impossible to close.

    Emerging Tech & Threat Trends Series – Episode 1 – AI and Cybersecurity – from AI-driven attacks to AI-powered defense
  2. Sep 1

    Practical Cybersecurity Series – Episode 5 – Cyber Insurance 101 – what it is, what it isn’t

    🎙️ Episode: Cyber Insurance 101: What It Is, and What It Isn't In this episode of the Practical Cybersecurity Series by Sec Oops, powered by Cyber View Point, we tackle a topic that causes massive confusion in boardrooms everywhere: Cyber Insurance. We open with an uncomfortable truth: buying an insurance policy is not a magical get-out-of-jail-free card for security failures. The team breaks down the origins of the cyber insurance market—from its early days at the 1997 "Breach on the Beach" party to the explosion of state data breach notification laws that forced companies to publicly disclose incidents and face massive financial costs. We explain how the aftermath of massive early breaches, like the 2006 TJX incident, devolved into bitter legal battles over liability, driving organizations to seek out cyber insurance simply to transfer the blame onto a third party. We walk through the harsh limitations of these policies and what they don't cover. We examine why traditional Commercial General Liability (CGL) policies won't save you from a data breach, and highlight the chilling Mondelez vs. Zurich case, where insurers used a standard "Act of War" loophole to deny coverage for the devastating NotPetya attack. From there, we get practical: addressing the quantification problem actuaries face with interconnected "correlated losses", and exploring why shifting from a reactive compliance checklist to a proactive Enterprise Cyber Risk Management (ECRM) strategy is your best defense. We discuss why insurance might spread financial loss, but completely fails to duplicate the deterrence function needed to force better security practices. 👉 Tune in to learn why you can outsource your financial risk, but you can never outsource your reputation—and walk away with the insights you need to read the fine print, close the loopholes, and treat cyber threats as a core business risk today.

    Practical Cybersecurity Series – Episode 5 – Cyber Insurance 101 – what it is, what it isn’t
  3. Aug 1

    Practical Cybersecurity Series – Episode 4 – How to Secure Remote Work and Hybrid Offices

    🎙️ Episode: How to Secure Remote Work and Hybrid Offices In this episode of the Practical Cybersecurity Series by Sec Oops, powered by Cyber View Point, we confront the security reality that most organisations are still catching up to: the office perimeter is gone — and the attackers already know it. We open with an uncomfortable truth: every kitchen table, coffee shop, and hotel lobby where your employees work is a potential entry point for a breach. The traditional firewall protected everyone when everyone was in the same building. That model is dead. The team breaks down the full remote attack surface — unpatched home routers, personal devices mixing with corporate data, public Wi-Fi, and shadow IT — and explains why remote and hybrid workers have become the number one target for phishing and social engineering attacks. Isolation removes the instinct to "just ask a colleague," and attackers exploit that gap with precision. We walk through the evolution of remote access — from ageing VPNs that hand attackers the keys to the entire network, to Zero Trust Network Access, where every connection is verified, every device is checked, and no one gets more access than they actually need. From there, we get practical: securing the home office, managing personal devices, locking down cloud applications like Microsoft 365 and Google Workspace, and defending against MFA fatigue attacks that bypass even multi-factor authentication. 👉 Tune in to learn why in a distributed world every employee is the perimeter — and walk away with a concrete remote security starter pack your team can begin implementing today.

    Practical Cybersecurity Series – Episode 4 – How to Secure Remote Work and Hybrid Offices
  4. Jul 1

    Practical Cybersecurity Series – Episode 3 – Incident Response on a Budget

    🎙️ Episode: Incident Response on a Budget In this episode of the Practical Cybersecurity Series by Sec Oops, powered by Cyber View Point, we tackle the security discipline most small and mid-sized teams know they need — but assume they can't afford: Incident Response. We open with an uncomfortable scenario — a ransomware attack at a business with no IR plan, no defined roles, and no tested backups. Not because they lacked good intentions, but because they assumed IR was an enterprise problem. It isn't. The team walks through how a real attack unfolds — from a single phishing email or exposed remote desktop port, through silent lateral movement and privilege escalation, all the way to the ransom note. By the time most teams react, the attacker has already been inside for days. We break down the six phases of incident response and explain why Preparation is the only one you can control before an incident hits. From there, we get practical — covering how to build an IR plan, assemble a jump kit, write scenario-specific playbooks, and run tabletop exercises, all without a dedicated security team or enterprise budget. We also cover what detection looks like without a SIEM, why the "5% of data tells most of the story" principle changes how you think about logging, and why the Lessons Learned phase — the one most teams skip — is the most valuable of all. 👉 Tune in to learn why incidents are inevitable but chaos is optional — and walk away with a concrete IR starter pack your team can begin building today.

    Practical Cybersecurity Series – Episode 3 – Incident Response on a Budget
  5. Jun 1

    Practical Cybersecurity Series – Episode 2 – Top 10 Policies Every Business Needs

    🎙️ Episode: Top 10 Policies Every Business Needs In this episode of the Practical Cybersecurity Series by Sec Oops, powered by Cyber View Point, we move beyond the tools and technologies to tackle the most overlooked foundation of any security program: policies. We open with an uncomfortable truth — that some of the most damaging breaches in history weren't caused by sophisticated exploits, but simply because nobody wrote down the rules. No policy. No enforcement. No accountability. The team starts by clearing up a confusion that plagues most organizations: the difference between a policy, a standard, a procedure, and a guideline — and why getting this wrong produces documents that are either too vague to enforce or too rigid to follow. From there, we walk through the Top 10 policies every business needs, covering why the CEO's signature on an Information Security Policy changes the entire organizational conversation, why the Acceptable Use Policy is simultaneously the most violated and most legally protective document in any company, and why an Incident Response Policy is only worth the paper it's printed on if you've actually rehearsed it. We also tackle the policies most businesses forget until it's too late — Vendor and Third-Party Risk, Remote Access and BYOD, and Business Continuity — and explain exactly what good looks like for each one, regardless of your company's size or budget. 👉 Tune in to learn why writing the policy is actually the easy part — and walk away with a clear, practical starting point for building a security program that holds up when it matters most.

    Practical Cybersecurity Series – Episode 2 – Top 10 Policies Every Business Needs
  6. Apr 1

    Deep Dive Series – Episode 7 – Identity Governance and Privileged Access Management: Taking IAM further

    🎙️ Episode: Identity Governance and PAM – From Access to Oversight In this episode of the Deep Dive Series by Sec Oops, powered by Cyber View Point, we move beyond the basic "username and password" to explore Identity as the New Perimeter. We dissect the "Identity Explosion"—the shift from managing a few hundred employees to governing thousands of human and machine identities, from API keys to RPA bots. The team breaks down the IGA Lifecycle (Joiner, Mover, Leaver), explaining how to automate the "digital census" and stop "permission creep" before it turns an internal account into an attacker’s playground. The conversation then shifts to the high-stakes world of Privileged Access Management (PAM). We challenge the dangerous status quo of "Always-On" administrative rights and introduce the "Gold Standard" of modern defense: Zero Standing Privilege (ZSP) and Just-in-Time (JIT) access. Learn why the most secure administrative account is the one that doesn't actually exist until the moment it's needed. Finally, we look at the Identity Attack Surface, discussing the rise of Identity Threat Detection and Response (ITDR). We explore why it is now officially easier for an adversary to "log in" than to "hack in," and how to build a resilient, identity-centric architecture that assumes breach at the credential level. 👉 Tune in to learn how to bridge the gap between "Active Directory" and "Zero Trust," ensuring your organization’s most powerful accounts are never left out in the cold.

    Deep Dive Series – Episode 7 – Identity Governance and Privileged Access Management: Taking IAM further

About

Join Ben, Moiz, and Sneh as they explore the ever-evolving world of cybersecurity. From phishing scams and hacking stories to emerging threats and defense strategies, they break down complex topics into relatable conversations. Whether you’re a tech pro or just cyber-curious, tune in to learn, laugh, and stay ahead of the latest in security—because in cybersecurity, there’s always an “oops” to uncover. Note: This podcast is powered by AI