Byte Sized Security

Marc David

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.

  1. Sep 19

    Ep47: Why AI Risks Are Different

    Episode Summary: Someone told Marc that AI panic is nothing new — just the printing press or nuclear weapons all over again. He disagreed, and it turns out there was a report to back it up. In this episode he breaks down why AI collapses the cost of dangerous capability in a way the printing press, the internet, and even nuclear weapons never did, what Anthropic's brand-new September 2026 threat intelligence report documents, where his own "$200 expert" framing overstated the case, and the four guardrails that would close the gap. Key Topics Covered: The argument that started this episode — a debate about whether AI panic is history repeating, and the report Marc found three days later making his case for himWhy the printing press comparison breaks down — institutions had a century (and decades, for the internet) to catch up; AI's capability curve moves in monthsWhat's actually different about nuclear weapons — nuclear risk lives behind physical choke points: materials, facilities, expertise. AI risk lives in a skill, and skills can't be fenced offAnthropic's report: the receipts — three disrupted operations, walked through case by case, that turn the argument from speculative to documentedDoes AI make anyone an expert? Not exactly — Marc's own "$200 subscription = expert" line, and the more defensible version of the claimAttackers, defenders, and who adapts faster — the same models cutting attacker costs are cutting defender costs too, and why that race mattersWhat real AI guardrails would look like — four concrete guardrails: pre/post-release capability testing, enforceable standards, international coordination, and risk-scaled access Main Takeaways: AI doesn't need generations to reach scale like the printing press or the internet did — model capability jumps happen every few months, not every few decadesNuclear risk is contained by physical choke points (fissile material, facilities, expertise); AI risk lives in a skill, and skills don't have a border to fenceAnthropic's September 2026 report documents real, disrupted operations — including a breach that went from one stolen developer token to full cloud admin control in roughly three hours"$200 subscription = expert" overstates it: AI doesn't manufacture expertise, it lowers the skill required to attempt tasks whose consequences the operator isn't trained to handleDefenders get the same acceleration attackers do — the organizations lagging on AI-assisted defense are the ones absorbing the most riskClosing the gap takes four things: pre/post-release capability testing, enforceable (not voluntary) standards, international coordination, and access that scales with risk instead of price Timestamps: [0:00] The argument behind this episode[1:03] Why the printing press comparison breaks down[1:53] What's different about nuclear weapons[2:55] Anthropic's report: the receipts[4:46] Does AI make anyone an expert? Not exactly[5:45] Attackers, defenders, and who adapts faster[6:16] What real AI guardrails would look like Tools & Resources Mentioned: Anthropic: Detecting and Countering Misuse of AI (September 2026)NIST AI Risk Management FrameworkEU AI Act (European Commission)Full written guide: Why AI Risks Are DifferentAI is fueling the cybersecurity career boomWhy an AI agent shouldn't inherit your permissions Not legal advice. Figures reflect Anthropic's report as published on September 10, 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  2. Sep 10

    Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

    Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview. In this episode: (00:00) The scan report that isn't as urgent as it looks(01:03) The 98.5% number and the mechanic analogy(02:01) Why the industry defaulted to patch everything(03:00) The 36-hour outage from a perfect-10 patch(03:48) CVSS score vs. exploitation evidence vs. insurance-claims data(05:08) What it sounds like when someone understands this in an interview(06:15) Why the industry has no brakes, and the AI-hype myth(07:49) Your homework Links: Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing"CISA's Known Exploited Vulnerabilities (KEV) catalogFIRST.org, the CVSS specificationFull written breakdownOur cybersecurity career guideBreaking into cybersecurity with no experienceThird-party risk and the AI bug-report flood Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode. I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  3. Jul 28

    Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

    Episode Summary: Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme. Key Topics Covered: What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who failsCan you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offenseHow corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)"Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc landsAccountability without a blame culture — four principles for getting Binance's seriousness without the fearThe boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns Main Takeaways: You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone ownedPunishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incidentThe metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudlyHumans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the personFair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report Timestamps: [0:00] The gotcha that shows up on your performance review[1:03] What Binance's red team is actually doing[2:23] Can you really get fired? Three strikes and the Krebs debate[3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder[5:03] "Weakest link"? The industry split, and where we land[6:55] Accountability without a blame culture: four principles[8:19] The boring middle thing that actually works Tools & Resources Mentioned: Binance runs monthly phishing tests (crypto.news)Repeated failures may lead to dismissal (WEEX)Addressing the repeat phishing offender (IT Brew)"Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)What to do (and not do) when employees click (Hook Security)What's a good phishing failure rate? (Hoxhunt benchmarks)KnowBe4 phishing security testProofpoint phishing simulationMicrosoft Defender attack simulation trainingFull written article: Fired for failing a phishing test?Why modern phishing beats smart peopleWhy employee security awareness training matters General education, not legal or HR advice. Reporting reflects coverage as of July 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  4. Jul 22

    Ep44: California's DROP Tool: Delete Yourself From Data Brokers in One Free Request

    Episode Summary: California just made deleting yourself from data brokers a single free request. In this episode Marc breaks down the state's new DROP tool: what it deletes, how to file it in a few minutes, why August 1, 2026 is the date that matters, and the three things it won't fix. If you're a California resident, this is a free privacy win you shouldn't skip. If you're not, he covers what to do instead. Key Topics Covered: What DROP is — California's Delete Request and Opt-out Platform, and where the 614 data broker number comes fromHow it works — one free request, and what it actually deletes across registered brokersFiling it step by step — a few minutes of work, plus the scam to watch out forThe August 1, 2026 deadline — why that's the date brokers have to start honoring requestsThe honest limits — what DROP won't fix: Google, Meta, and brokers that re-collect your dataNot in California? — the moves that get you similar protection without DROP Main Takeaways: DROP lets California residents delete themselves from every registered data broker (614 and counting) with a single free request — no per-broker opt-outsAugust 1, 2026 is the date that matters: that's when brokers must start honoring DROP deletion requestsIt's not a silver bullet — it won't remove you from Google or Meta, and brokers can re-collect your data over time, so treat it as maintenance, not a one-and-doneWatch for the scam: the only official place to file is the state's own site — don't pay a third party to do what's freeNot a California resident? Freeze your credit and use manual opt-outs or a removal service to get similar coverage Timestamps: [0:00] The 12-broker breaking point[1:10] What DROP is and where the 614 number comes from[2:05] How it works and what it actually deletes[3:40] Filing it step by step, plus the scam to avoid[4:46] Why August 1, 2026 is the deadline[5:19] The honest limits: Google, Meta, and recurring brokers[6:51] Not in California? Do this instead Tools & Resources Mentioned: File a DROP request (official)California Privacy Protection AgencyCalifornia Delete Act (SB 362)EFF: What You Need to Know About California's DROP ToolFull written guide: California's DROP tool & data broker opt-outHow consent laundering moves your dataRemove your personal info from the internetCredit freezes & identity protection Not legal advice. Details reflect the tool as of July 2026; enforcement begins August 1, 2026. --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  5. Jun 1

    Ep43: The Best Personality Traits for Working in Cybersecurity

    Episode Summary: A Reddit thread on r/cybersecurity asked a simple question: what's the best personality trait for working in cyber? The answers — with hundreds of upvotes — weren't about hacking or certifications. They were about curiosity, patience, humility, staying calm under pressure, and empathy. Marc walks through each trait with personal stories from 8+ years of building teams, hiring, and working incidents at 2 AM. Key Topics Covered: Curiosity — the #1 answer by a wide margin; the trait that makes you dig into a log line everyone else shrugs offPatience — explaining technical risk to non-technical people without making them feel stupid, because if you do, they stop reporting incidentsHumility — saying "I don't know, but I'll figure it out" beats bluffing every time; ego is the worst trait in the fieldCalm under pressure — incident response at 2 AM, zero-days on Friday afternoons, breaches that keep growing; staying focused when everything is on fire matters more than any certEmpathy and kindness — cybersecurity is a people problem wrapped in a technology problem; being technically right doesn't matter if nobody wants to work with youThe uncomfortable truth — ADHD, burnout, trauma-induced hypervigilance; the always-on mindset is a strength until it isn't Main Takeaways: Technical skills are trainable — tools, frameworks, scripting languages, detection logic are all learnable, especially with AISoft traits like curiosity, patience, and empathy are harder to develop and are what separate people everyone wants on their team from people nobody wants to work withIf you're thinking about getting into cybersecurity, don't ask "am I technical enough?" — ask "am I curious enough to keep learning?"The best cybersecurity professionals aren't the ones who sprint the hardest — they're the ones still there in five years Timestamps: [0:00] Introduction — the Reddit thread that started it all[0:58] Curiosity — the #1 answer and why it matters[2:41] Patience — the art of explaining things without condescension[3:58] Humility — why "I don't know" is a superpower[5:15] Calm under pressure — the difference between a skill and a warning sign[6:28] Empathy and kindness — the most surprising and important trait[7:49] The uncomfortable part — burnout, ADHD, and mental health in cyber[9:11] Final thoughts — what really separates the best from the rest Tools & Resources Mentioned: Reddit Thread: Best Personality Type/Traits for Working in Cyber --- I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode. -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  6. 07/05/2025

    Three Privacy Actions You Need Today

    # Byte Sized Security Show Notes ## Episode Title: 3 Immediate Actions to Protect Your Privacy Today ## Episode Summary: In this episode of Byte Sized Security, host Marc David outlines three practical, actionable steps to enhance your privacy protection immediately. With data breaches nearly doubling in 2024 and companies like AT&T and Ticketmaster experiencing massive exposures, these privacy protection measures aren't just theoretical—they're essential defenses against real threats. ## Key Discussion Points: * The alarming state of data breaches in 2024: 10,626 confirmed breaches, nearly double from previous year * Major breaches highlighted: AT&T (73M records), Ticketmaster (560M users), National Public Data (2.9B records) * The average breach costs $4.88 million, or $165 per stolen record * **Step 1**: Enable two-factor authentication everywhere * 2FA stops 99.9% of automated attacks * Use authentication apps instead of SMS * Save backup codes in a safe place * **Step 2**: Audit your privacy settings * Detailed walkthrough for Facebook, Instagram, Twitter/X, and LinkedIn * Phone settings review for both iOS and Android * Revoking unnecessary app permissions * **Step 3**: Protect your connection and digital footprint * Using a VPN to encrypt connections and mask browsing * Reviewing and cleaning your digital footprint * Opting out of data broker sites * Deleting old, unused accounts * The importance of ongoing privacy maintenance ## Tools and Resources Mentioned: * **Authentication Apps:** * [Google Authenticator](https://googleauthenticator.net/) * [Authy](https://authy.com/) * **Recommended VPN Services:** * [NordVPN](https://nordvpn.com/) * [ExpressVPN](https://www.expressvpn.com/) * [Surfshark](https://surfshark.com/) * **Data Broker Removal Services:** * [DeleteMe](https://joindeleteme.com/) * [Privacy Bee](https://privacybee.com/) * [Optery](https://optery.com/) * **Data Broker Sites to Opt Out From:** * [Whitepages](https://www.whitepages.com/) * [PeopleFinder](https://www.peoplefinder.com/) * [Spokeo](https://www.spokeo.com/)

  7. 07/03/2025

    Ep:41 Beware: Your Top VPN App May Be a Chinese Government Spy

    Episode Summary: In this episode, we explore the alarming discovery that many of the top-rated VPN apps on the App Store and Google Play are secretly owned by Chinese companies. These VPNs pose a serious risk to user privacy and security, as Chinese law requires them to hand over all user data to the government without justification. Key Topics Covered: - Chinese-owned VPN apps masquerading as legitimate services - Lack of transparency and disclosure around company ownership - Risks of user data being accessed by the Chinese government - Failure of app stores to properly vet and regulate these VPN apps - Importance of researching VPN providers before using them Main Takeaways: - Many popular VPN apps are secretly owned by Chinese companies, creating a significant risk to user privacy and security. - App stores like the App Store and Google Play are not properly vetting and regulating these potentially compromised VPN apps. - Users must do their own research to ensure the VPN they are using is trustworthy and not owned by a company with ties to the Chinese government. Timestamps for Major Topics: - 0:00 - Introduction to the issue of Chinese-owned VPN apps - 1:30 - Examples of top-ranked VPN apps with hidden Chinese ownership - 3:00 - Explanation of the legal requirements for Chinese companies to hand over user data - 4:30 - Lack of action by app stores to remove or label these problematic VPN apps - 6:00 - Importance of user research and caution when selecting a VPN provider --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

  8. 05/30/2025

    Ep40: The AI Layoff Apocalypse Has Already Started — And You’re Next

    The Imminent AI Job Crisis: Are You Prepared? This episode highlights the alarming prediction by Dario Amodei, CEO of Anthropic, that AI could eliminate half of all entry-level white-collar jobs within the next one to five years, potentially raising U.S. unemployment to 20%. While major companies are quietly adopting advanced AI systems, the public and lawmakers remain largely unaware or in disbelief. The episode discusses the impacts of AI on various industries and jobs, stressing the need for urgent action such as an AI 'token tax,' real-time job replacement tracking, legislative briefings, and worker reskilling programs. The message is clear: the AI job crash is imminent, and proactive measures are essential to mitigate its effects. 00:00 The Impending Disappearance of White-Collar Jobs 00:37 Real-World Examples of AI-Induced Job Cuts 01:03 The Rise of AI Agents in the Workplace 01:30 The Alarming Capabilities of Advanced AI 01:48 Public Response and the Threat to Democracy 02:32 Proposed Solutions to the AI Job Crisis 02:57 The Urgency of Immediate Action 03:06 Conclusion: Preparing for the AI Job Crash --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Behind the Curtain: A white-collar bloodbath -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

About

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.