Security Mondays with Eva Benn

Eva Benn

Cybersecurity is evolving fast and it's hard to keep up amidst all the noise. Host Eva Benn sits down with some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the calls they're making right now. Every episode gives you practical things you can go do at your organization this week. New episodes every Monday.

  1. 4d ago

    The Cyber Mentor: What I Learned From Breaking Into Companies | Heath Adams | S2 E6

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week.This week is a hacker's perspective on defense. What actually reduces risk, what security teams waste money on, and how AI is changing the way we think about all of it.My guest is Heath Adams, The Cyber Mentor. He built TCM Security and the hands-on PNPT certification, and he now co-founds the security advisory firm Breach Point and works as a fractional vCISO. We get into why an offensive security guy moved to defense, where budgets get wasted, and how to look at your Active Directory the way an attacker would.We also take on the arguments everyone's having right now. Does upskilling and certifying still work when AI is changing the job? And what happens to vulnerability research and bug bounties when AI can flood a program with findings?I'm doing my part by bringing you some of the best global leaders in the security industry every Monday, with practical tools and resources you can go use this week.What you'll walk away with:- Why people who know offense often make better defenders.- How to spot security spend that isn't reducing real risk.- A practical way to look at your Active Directory.- A straight answer on whether certs and upskilling still work.- How AI is changing vulnerability research and bug bounties.Connect with Heath:LinkedIn: https://www.linkedin.com/in/heathadams/The Cyber Mentor (YouTube): https://www.youtube.com/c/thecybermentorBreach Point: https://breachpoint.comInsight Recon (AD tool): https://insightrecon.comTCM Security: https://tcm-sec.comReports and references:Practical Network Penetration Tester (PNPT): https://certifications.tcm-sec.com/pnpt/TCM Security, AI tools and certification exams: https://tcm-sec.com/ai-tools-and-certification-exams/curl ends its bug bounty over AI slop: https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/Coverage of the curl bug bounty shutdown: https://www.bleepingcomputer.com/news/security/curl-ending-bug-bounty-program-after-flood-of-ai-slop-reports/Infragistics IT talent survey (entry-level vs senior): https://techstrong.ai/articles/ai-cybersecurity-roles-top-2026-hiring-priorities-survey/Chapters:00:00 — What Security Leaders Get Wrong02:55 — The Attacker’s Perspective on Defense06:00 — What Actually Reduces Security Risk?08:33 — Where Security Budgets Go to Waste10:44 — Is Domain Admin Still the Ultimate Prize?12:17 — Inside Insight Recon27:16 — How AI Is Changing Vulnerability HuntingWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comAnd follow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  2. Aug 17

    Most AI Security Is Theater. Here’s What Actually Works | Joshua Copeland | Security Mondays | S2 E5

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. Walk into most organizations and you'll find security that photographs well. Clean dashboards, a passed audit, a binder of policies. Joshua Copeland calls a lot of this security theater, and he's been blunt about it for years. He co-wrote a piece called Cloud Security Theater arguing that vendor best practices are written to look good in a slide deck, not to stop the way attackers actually move. His line: compliance shows you followed the recipe; resilience shows you can improvise when the recipe stops working. Joshua now runs security at an AI company, so he sees the AI version of this up close. Teams are buying AI security tools fast, and a lot of that spend lands as a better-looking dashboard rather than lower risk. In this episode he gives security leaders the questions to ask before they sign off, the controls worth pulling out because they add risk, and the handful of numbers that tell you more than any audit score. I'm doing my part by bringing you some of the best global leaders in the security industry every Monday, with practical tools and resources you can go use this week. What you'll walk away with: • How to tell if an AI security purchase reduces risk or just produces a nicer dashboard • The questions to ask in the room before you approve a new AI security tool • What to measure instead of compliance scores and audit pass rates • A test you can run this week to see if your org is actually resilient • One thing to stop doing now, and one thing to double down on If you find this helpful, I'd appreciate a thumbs up, subscribe, and share. It helps more people find the show. Connect with Josh: • LinkedIn: https://www.linkedin.com/in/joshuacopeland/ • His book, Unpopular Opinion (Amazon): https://www.amazon.com/UNPOPULAR-OPINION-Burning-Rebuild-Cybersecurity/dp/B0FPZS6QX1 Resources we mention in the video: • Cloud Security Theater (essay he co-wrote): https://blog.jpsoftworks.com/cloud-security-theater-why-azure-best-practices-dont-actually-make-you-secure-with-guest-blogger-joshua-copeland/ • His five municipal security strategies, SmarterMSP: https://smartermsp.com/municipal-cyber-risk-unveiled-how-msps-can-stand-guard/ • Status: Secure podcast appearance: https://open.spotify.com/episode/1vwIYcAl4FfNW7xYoGTJC1 • dnsUNFILTERED, episode 38: https://www.dnsfilter.com/podcast/episode-38 • Tulane faculty profile: https://sopa.tulane.edu/about-sopa/advisors-faculty-staff/joshua-copeland Chapters: 00:00 — What Security Theater Looks Like in the AI Era 02:36 — Why So Much of Cybersecurity Is Just Performance 06:19 — 5 Questions to Ask Before Buying an AI Security Tool 08:32 — Why Compliance Doesn't Mean You're Actually Secure 12:32 — The Metrics That Actually Matter 15:21 — Why Security Transformations Keep Failing 18:37 — What a Boring but Effective Security Program Looks Like 22:05 — The AI Risk Most Security Leaders Are Missing Want to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.com And follow along for more free cybersecurity education. 🤗 LinkedIn: https://www.linkedin.com/in/evabenn/ Instagram: https://www.instagram.com/evabennofficial/ TikTok: https://www.tiktok.com/@evabennofficial Website: https://www.evabenn.com/

  3. Aug 10

    He Wrote the 27-Year-Old Bug Mythos Found. Then Proved Mythos Wasn’t Necessary | Neils Provos | S2E4

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. This week, I sat down with Niels Provos, founder of Security Blueprints and creator of IronCurtain, to discuss how AI is changing vulnerability discovery and what security teams should do about it.The big AI security story this year has been frontier models finding decades old bugs in core software. Niels Provos challenged the idea that this capability is limited to frontier models. Using his open source IronCurtain framework, he reproduced Anthropic’s marquee finding, a 27 year old OpenBSD TCP bug he committed in 1998, with commercial and open weight models.His conclusion: finding vulnerabilities is an orchestration problem, not a frontier model problem.We talked about the growing gap between defenders and attackers, model refusals and rate limits, why working proof of concepts matter for filtering false positives, and how AI could make routine code audits affordable.Niels also made the case for building security invariants, controls that eliminate entire attack classes without requiring human decisions every time. In his analysis of 70 real breaches, three controls would have stopped about 65%.What you’ll walk away with:- Why any model can find the bug should now be the planning assumption- The defender’s tax that attackers on open weight models don’t pay- How to filter AI surfaced findings before they overwhelm your SOC- The real cost of AI code audits- The three controls that could have stopped 65% of 70 analyzed breachesConnect with Niels: LinkedIn: https://www.linkedin.com/in/nielsprovos/ Website: https://www.provos.org/ GitHub: https://github.com/provos Mastodon: https://ioc.exchange/@nielsprovos Resources IronCurtain (open-source): https://github.com/provos/ironcurtain IronCurtain site: https://ironcurtain.dev Finding Zero-Days with Any Model: https://www.provos.org/p/finding-zero-days-with-any-model/ The Day After the Zero-Days: https://www.provos.org/p/day-after-the-zero-days/ "The Day After the Zero-Days" talk (Cloud Security Alliance AI Summit): https://www.youtube.com/watch?v=LKTYZehh_iw Security Blueprints (security invariants): https://securityblueprints.io/ Three invariants / 70-breach analysis: https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/ The Agent Perimeter Fallacy: https://securityblueprints.io/posts/agent-perimeter-fallacy/ Chapters:00:00 — The 27 Year Old Bug AI Found03:43 — Why Mythos Wasn't the Real Breakthrough06:47 — The Workflow That Made AI Vulnerability Discovery Work12:09 — Why AI Agents Can't Be Trusted With Everything25:00 — Why Finding a Vulnerability Isn't Enough29:13 — The Security Controls That Could Stop 65% of Breaches44:08 — The AI Dependency Risk Security Leaders Are MissingWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comAnd follow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  4. Aug 3

    AI Supply Chain in Practice: Generate Your First AI Bill of Materials | Oakley & Raidman | S2 E3

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. In March, attackers pushed two poisoned versions of Axios to npm and used it to drop a remote access trojan across Mac, Windows, and Linux. Microsoft tied it to a North Korean actor and CISA put out an alert. The LiteLLM package on PyPI got hit the same spring. By June, the Miasma campaign had compromised 32 Red Hat npm packages. When this happens, the question that decides your week is simple: do you know what you're running, and where? That's what a bill of materials answers, and it's why AIBOMs matter for the AI models and tools your teams are pulling down every day. In this episode, the two people leading the OWASP AI SBOM Initiative show how to build one and what to do with it. I'm doing my part by bringing you some of the best global leaders in the security industry every Monday, with practical tools and resources you can go use this week. This week, I sat down with Helen Oakley, who leads software and AI security at SAP and built the first open-source AIBOM Generator, and Dmitry Raidman, CTO and co-founder of Cybeats and one of the authors of the original SBOM standard. We talked about how to generate an AI Bill of Materials this week, how to read it, and where it fits with the new June 2026 executive order. What you'll walk away with: - A plain-English definition of an AIBOM and how it differs from a software SBOM - What the 2026 npm attacks (Axios, Miasma, LiteLLM) teach about the exposure question - How to generate your first AIBOM from a Hugging Face model, by website or CLI - How to wire AIBOM generation into CI/CD using CycloneDX output - One Monday-morning action on AI supply chain you can verify by Friday If you find this helpful, I'd appreciate a thumbs up, subscribe, and share. It helps more people find the show. Connect with Helen: LinkedIn: linkedin.com/in/helen-oakley Connect with Dmitry: LinkedIn: linkedin.com/in/draidman Tools and references: OWASP AIBOM Generator (try it): owasp-genai-aibom.org AIBOM Generator on GitHub: github.com/GenAI-Security-Project/aibom-generator OWASP AI SBOM Initiative: genai.owasp.org/ai-sbom-initiative White House executive order, June 2, 2026: whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security CISA alert on the Axios compromise: cisa.gov/news-events/alerts/2026/04/20 Microsoft: mitigating the Axios npm compromise Wiz: Miasma supply chain attack on Red Hat npm packages Chapters:00:00 — Why AI supply chain risk is growing so fast03:50 — The AI security concept every team needs to understand10:05 — Why AI makes supply chain attacks even harder12:11 — Where every AI supply chain program should start14:46 — How to generate your first AI Bill of Materials23:13 — The AI risks your AI BOM won't reveal30:12 — How to operationalize AI supply chain securityWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comFollow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  5. Jul 27

    How to Detect, Investigate, and Hunt Attacks Across Your AI Ecosystem | Thomas Roccia | S2 E2

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. Thomas is an AI threat researcher, founder of SecurityBreak, former Senior Threat Researcher at Microsoft, author of Visual Threat Intelligence, creator of NOVA and PromptIntel, and one of the leading voices defining what AI threat intelligence looks like.We went deep on how attackers are abusing AI today, why AI systems have created an entirely new attack surface, and why traditional threat intelligence is no longer enough. We also explored indicators of prompt compromise, prompt injections, malicious MCP ecosystems, software supply chain attacks, autonomous AI agents, and how defenders can finally gain visibility into what their AI agents are actually doing.If you find this helpful, I'd appreciate a thumbs up, subscribe, and share. It helps more people find the show. Connect with Thomas:• LinkedIn: https://www.linkedin.com/in/thomas-roccia/ • SecurityBreak: https://securitybreak.io/ • Blog: https://blog.securitybreak.io/ • GitHub: https://github.com/fr0ggerTools and projects: • NOVA (prompt pattern matching, open source): https://novahunting.ai • NOVA documentation: https://docs.novahunting.ai/ • PromptIntel (free adversarial prompt database): https://promptintel.novahunting.ai/ • Unprotect Project (malware evasion database): https://unprotect.it/about/ • Visual Threat Intelligence (book): https://www.amazon.com/Visual-Threat-Intelligence-Illustrated-Researchers/dp/B0C7JCF8XDReports and research discussed:• "Malware Reverse Engineering is no longer a human problem" (Roccia, March 2026): https://blog.securitybreak.io/malware-reverse-engineering-is-no-longer-a-human-problem-5441e4a0564f• Introducing PromptIntel and Indicators of Prompt Compromise (Roccia): https://blog.securitybreak.io/introducing-promptintel-1624d03045a3 • CrowdStrike 2026 Global Threat Report: https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/• PwC on the AI-orchestrated GTG-1002 campaign: https://www.pwc.com/us/en/services/consulting/cybersecurity-risk-regulatory/library/ai-orchestrated-cyberattacks.html• Check Point threat intelligence report, June 29, 2026 (26,000 hijacked AI agents): https://research.checkpoint.com/2026/29th-june-threat-intelligence-report-2/Chapters:00:00 — Is AI replacing malware analysts?07:02 — Why AI threat intelligence changes everything09:34 — The new indicators security teams need to detect13:14 — Hunting malicious prompts with Nova20:40 — The biggest AI threats organizations face today28:30 — Where defenders can find adversarial prompts36:09 — The one thing every security leader should do nowWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comP.S. Going to BlackHat? Register here and use EVABENN for $200 Off a Briefings Pass or $100 off a Business Pass.And follow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  6. Jul 20

    How to Build a Mythos-Ready Security Program This Week | Rob T. Lee | Security Mondays Season 2 EP 1

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. Excited to kick off Season 2 of Security Mondays with the cybersecurity legend Rob T. Lee, the Chief AI Officer and Chief of Research at SANS Institute, a former Air Force officer, founding member of the Air Force's first information warfare unit, former director at Mandiant, and one of the pioneers of digital forensics and incident response.We went deep on what Mythos means for security teams, why AI is compressing the timeline between patch releases and exploitation, and how organizations should rethink vulnerability management in a world where attackers can operate at machine speed. We also explored why security leaders need to normalize uncertainty, invest in talent over tooling, and start preparing for an entirely new cybersecurity playbook.If you find this helpful, I'd appreciate a thumbs up, subscribe, and share. It helps more people find the show. Connect with Rob: YouTube: https://www.youtube.com/@Rob_T_LeeLinkedIn: https://www.linkedin.com/in/leerob/TikTok: https://www.tiktok.com/@cyber_robbyX: https://x.com/robtleeSubstack: https://robtlee73.substack.com/What you'll walk away with: - The first move from the AI Vulnerability Storm briefing: point agents at your own code, with tools you can run this week (Claude Code Security, Codex Security, OpenAnt, RAPTOR) - What 181 Firefox exploits versus 2 means for your patching SLAs, and why every patch is now an exploit blueprint - The line to use in your next board meeting: “the security program this board has funded is what makes the AI strategy viable” - What to put in front of your board before the EU AI Act takes effect in August 2026 - A minimum viable VulnOps function, plus one Monday action and the Friday check that proves it got done Resources we mention in the video The AI Vulnerability Storm: Building a Mythos-Ready Security Program: https://labs.cloudsecurityalliance.org/mythos-ciso/ Rob's write-up on the briefing: https://robtlee73.substack.com/p/the-mythos-ciso-briefing SANS AI Cybersecurity Summit 2026 (Protocol SIFT demo context): https://www.sans.org/cyber-security-training-events/ai-summit-2026 SANS BugBusters advisory (AI vulnerability discovery, hype vs. reality): https://www.sans.org/mlp/sans-critical-advisory-bugbusters-ai-vulnerability-discovery-hype-vs-reality OpenAnt (Knostic, open source): https://github.com/knostic/OpenAnt RAPTOR (Gadi Evron, open source): https://github.com/gadievron/raptor Find Evil! hackathon: findevil.devpost.com Chapters:Chapters:00:00 — Why Mythos changed the cybersecurity conversation03:30 — The question every CISO is asking right now08:53 — Why security leaders are starting with source code12:01 — The problem AI just made much worse16:08 — The mindset security teams need to abandon22:25 — Where security teams should actually start with AI28:40 — What happens to human analysts in an AI worldWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comP.S. Going to BlackHat? Register here and use EVABENN for $200 Off a Briefings Pass or $100 off a Business Pass.And follow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  7. Jun 29

    10 AI Security Leaders Agree: Do These 5 Things Now | Security Mondays | Season 1 Recap

    If you watch one video on AI security, make it this one.I've summarized the biggest of themes of Season 1 in under 15 minutes for you, that's 10 episodes, 250+ years of combined security leadership experience in 15 mins, leaving you practical guidance you can implement this.After introducing the 10 episodes, add this: 250+ years of experience leaving you practical guidance you can implement this.I just wrapped up Season 1 of Security Mondays.Over the past 10 episodes, I had the privilege of sitting down with some of the brightest minds in AI security and cybersecurity. Different industries. Different experiences. Different perspectives.Yet the same five themes kept coming up again and again.In this episode, I'm bringing those lessons together into one practical recap, along with the actions you can take this week to better secure AI in your organization.A huge thank you to the incredible guests who made Season 1 possible:Chris Cochran – AI governance, Shadow AI, and building practical security programs.Edward Merrett – Visibility into AI adoption, governance, and enabling secure AI use across the business.Sergej Epp – Zero Day Clock, vulnerability management, and why defenders need to move at machine speed.John Sotiropoulos – AI governance, agentic security, and operationalizing AI security programs.Emil Binder Lassen – AIUC-1, AI governance, certification, and secure AI adoption.Rock Lambros – AI red teaming, agent security, and securing enterprise AI.Ken Huang – Threat modeling AI systems with the MAESTRO framework and practical AI security guidance.Ankur Shah – Agentic AI security, prompt injection, MCP risks, and runtime protection.Ross Young – Building resilient security programs and shifting from prevention to runtime security.Eric O'Neill – Counterintelligence lessons for the AI era and why least agency matters for AI agents.Every conversation reinforced one thing:AI is changing cybersecurity faster than anything we've seen before.The organizations that succeed won't be the ones trying to block AI. They'll be the ones learning how to adopt it resist, govern it effectively, and empower their teams to use it responsibly.If you take one thing away from this episode, let it be this:Don't try to do everything at once.Pick one lesson. Put it into practice this week.That's how we roll here.-Thank you for watching, commenting, sharing these episodes with your teams, and being part of the Security Mondays community. Your support has meant the world throughout Season 1.Season 2 is coming soon, and I can't wait to share what's next.Until then, I'll be here every Monday with practical AI security guidance you can turn into action.If you enjoyed this episode, I'd really appreciate it if you subscribed, gave the video a thumbs up, and left a comment below.Going to BlackHat? Register here and use EVABENN for $200 Off a Briefings Pass or $100 off a Business Pass: https://blackhat.com/us-26/registration.html?_mc=sm_social_evabennWant to hear from more voices in AI security? Security Mondays is a proud partner and supporter of the AI Cyber Magazine. Find it in any Lufthansa or Delta lounges. Not traveling soon? Get your copy here: https://aicybermagazine.comFollow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

  8. Jun 22

    Former FBI Spy on How Spies and Hackers Use AI in 2026 | Eric O'Neill | Season 1 EP 10

    Hi, I'm Eva Benn. Every Monday morning I bring you some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the decisions they're making right now. Every episode is designed to give you practical things you can go and implement in your organization this week. This week I sat down with Eric O'Neill, the FBI counterintelligence operative who brought down Robert Hanssen, founder of The Georgetown Group and NeXasure AI, and the USA Today bestselling author of Spies, Lies, and Cybercrime. They go deep on what the old counterintelligence playbook teaches security leaders about today's AI-driven attacks, why the hiring pipeline is the new front door, and the boardroom conversation CISOs aren't having yet. Eric founded The Georgetown Group and NeXasure AI. His new book Spies, Lies, and Cybercrime came out from HarperCollins in October 2025 and hit USA Today's bestseller list. We talked about what counterintelligence teaches us about today's threats, including the espionage tradecraft now running at machine speed: AI-generated identities, deepfake interviews, North Korean operators inside U.S. companies, and the surveillance stack that can read a heartbeat through a wall. If you find this helpful, I'd appreciate a thumbs up, subscribe, and share. It helps more people find the show. Connect with Eric: • LinkedIn: https://www.linkedin.com/in/eric-m-oneill • Website: https://ericoneill.net/ • Newsletter (Spies, Lies & Cybercrime): https://spies-lies-cybercrime.ericoneill.net • X / Twitter: https://twitter.com/eoneill • YouTube: https://www.youtube.com/channel/UCPLsW0-H8dfsx_oQXnTVLJg • Instagram: https://www.instagram.com/ericoneill.official/• NeXasure AI leadership page: https://nexasure.ai/about/leaders/eric-oneill/ Resources we mention in the video The Georgetown Group: https://www.georgetowngroup.com/ Books: Spies, Lies, and Cybercrime (HarperCollins, October 2025): https://ericoneill.net/books/spies_and_lies/ Gray Day (Penguin Random House, 2019): https://ericoneill.net/books/gray-day/ Nisos investigation into DPRK remote worker fraud: https://nisos.com/blog/dprk-remote-worker-fraud-interview/ FBI advisory on North Korean IT worker threats (Jan 2026 update): https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses FBI IC3 2025 Internet Crime Report ($21B in losses): https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf Palo Alto Networks on AI agents as insider threats 2026: https://www.theregister.com/2026/01/04/ai_agents_insider_threats_panw/ MICE counterintelligence framework: https://thecyberwire.com/glossary/mice Heart rate detection through walls research (Frontiers in Physiology): https://www.frontiersin.org/journals/physiology/articles/10.3389/fphys.2024.1344221/full Chapters:00:00 — The cyber threat most people still underestimate03:29 — What a spy actually looks like in 202605:38 — The dangerous assumption making companies easy targets07:40 — The espionage playbook every cybercriminal now uses11:08 — A simple framework to stay ahead of attackers12:15 — When one attacker can do the work of an entire team16:30 — Why your employees are the new attack surface20:05 — The spy tactics hiding inside modern cybercrime23:28 — The AI agent mistake that can expose your entire company27:24 — The interview scam fooling companies worldwide37:05 — The hidden industry collecting your personal data39:35 — The conversation every board should be having right nowFollow along for more free cybersecurity education. 🤗LinkedIn: https://www.linkedin.com/in/evabenn/Instagram: https://www.instagram.com/evabennofficial/TikTok: https://www.tiktok.com/@evabennofficialWebsite: https://www.evabenn.com/

About

Cybersecurity is evolving fast and it's hard to keep up amidst all the noise. Host Eva Benn sits down with some of the best global security leaders to talk through what's actually top of mind, the threats they're seeing, the tools they're using, and the calls they're making right now. Every episode gives you practical things you can go do at your organization this week. New episodes every Monday.