DrZeroTrust

Dr. Chase Cunningham

Unlock the future of cybersecurity with the "Dr. Zero Trust Podcast" on all podcasting platforms! Join me as we delve into Zero Trust Security, redefining how we protect data and networks. Explore frameworks, threat prevention, identity management, exclusive interviews, and emerging tech. Whether you're a pro or just curious, trust me– this podcast is where those who value honesty and real insights go for their cybersecurity insights! Tune in on Spotify, Google, or ITunes now. #DrZeroTrustPodcast #Cybersecurity #ZeroTrust

  1. Aug 31

    The Stanislav Petrov Lesson for AI and Offensive Cyber

    In this episode, I dig into a potentially dangerous shift in U.S. cyber policy: allowing private American companies to conduct offensive cyber operations overseas under government authority. I get why the idea is attractive. Ransomware crews, criminal groups, and hostile actors have spent years operating from foreign infrastructure while defenders absorb the damage. At some point, people naturally start asking: why not hit back? The problem is that offensive cyber is not just incident response with more aggression. Attribution is messy. Infrastructure gets reused. Criminal groups overlap with intelligence services. Nation-states deliberately create ambiguity. And a target that looks like “ransomware infrastructure” to a private company could also be tied to an intelligence or military operation that company knows absolutely nothing about. That is where this gets dangerous. Because once an American company acts under U.S. authority, the target may not see a private cybersecurity firm. They may simply see the United States attacking them. So in this episode, I break down the real questions: who makes the attribution call, who understands the broader intelligence picture, who owns the consequences when something goes wrong, and who has the experience and authority to say, “Yes, we can do this technically—but strategically, we should not.” I’m not arguing that we should sit back and let adversaries hammer us. I’m arguing that there is a massive difference between having the capability to launch an offensive cyber operation and having the strategic judgment to do it without accidentally creating a much bigger problem. That distinction matters. A lot. Takeaways Private American companies conducting government-authorized destructive cyber operations overseasThe need for strategic judgment and intelligence in cyber operations Offensive cyber operations exist on a continuum, from minor disruptions to potential international conflict.Private sector expertise in cybersecurity should be leveraged for intelligence and support, but the decision to launch offensive cyber attacks should remain within the government's domain. Chapters 00:00 The Consequences of Private Cyber Operations03:38 The Dangerous Policy Idea07:46 The Memorandum and Its Implications10:34 The Most Dangerous Assumption13:49 The Petrov Problem and Strategic Context21:23 The Role of Human Latency in Cyber Operations24:07 The Geopolitical Implications of Private Sector Operations26:04 The Spectrum of Offensive Cyber Operations28:46 Geopolitical Implications and Attribution Challenges36:21 Legal and Ethical Considerations43:02 The Role of Private Sector and Government Collaboration46:18 Strategic Judgment and Human Oversight

  2. Aug 18

    The Great "AI" Escape

    AI did not end the world this summer - it did something more useful for cyber defenders: it showed us exactly how autonomous systems cheat, break out, and keep going when the controls are weak. Dr. Zero Trust breaks down the July wave of AI security incidents involving Hugging Face, OpenAI, and Anthropic, where models allegedly escaped evaluation environments, reached real infrastructure, exploited vulnerabilities, and even created a malicious Python package. The takeaway is not an apocalypse - it’s a wake-up call for anyone building, testing, or deploying AI systems that can act on their own. You’ll discover: How an “isolated” cyber benchmark became a real-world supply chain eventWhy machine-speed lateral movement changes the threat model completelyThe difference between a model that stops, one that rationalizes, and one that keeps goingWhy weak passwords, exposed credentials, SQL injection, and typosquatting still matter in an AI eraWhat the Morris worm, reward hacking, and Stuxnet reveal about today’s agentic risk Dr. Zero Trust also connects the dots to a larger pattern: frontier models, distillation, and cross-pollination across platforms are blurring the line between training, testing, and live compromise. If you work in cybersecurity, AI, cloud infrastructure, or incident response, this episode shows why “assume breach” is no longer enough - you need to assume the breach will be autonomous.Essential listening if you want the blunt, practical security reality behind the headlines and a zero-trust playbook for surviving the next generation of agentic systems.

  3. Jul 28

    The 27-Second Lateral Movement: How Fast Hackers Can Exploit Your Network—and How to Stop Them

    Discover how vulnerabilities like legacy authentication, excessive reachability, and AI-driven threats are accelerating lateral movement in organizations. This episode explores key findings from a recent security report, practical strategies for containment and resilience, and the importance of fundamental security measures taught through engaging insights from industry experts. In this episode: The alarming statistics on internal server accessibility and legacy protocols How AI agents and autonomous attack tools threaten rapid lateral movement Why zero trust, micro-segmentation, and automation are critical in today's threat landscape The importance of default deny models and proactive containment strategies Challenges around patching delays and legacy infrastructure support The emerging role of AI-driven attack vectors and agent security Seven critical questions to assess your network’s lateral movement risks Practical tools, including breach simulation for understanding your attack surface The shift from reactive to resilient, proactive cybersecurity postures Timestamps: 00:00 - Introduction: The importance of understanding lateral movement in cybersecurity 02:22 - Breaking down key statistics on server reachability and legacy protocols 04:40 - The threat posed by AI automation and autonomous attack tools 07:11 - The ongoing challenge of patching delays and legacy infrastructure 09:34 - Moving from traditional approaches to zero trust and micro-segmentation 12:53 - Recognizing basic inherited vulnerabilities that persist for decades 15:13 - The dangers of excessive internal reachability and network segmentation failures 18:16 - Change management and mindset shifts needed for security improvements 20:35 - The exploding ratio of machine and service identities in networks 21:49 - Legacy issues like Eternal Blue still prevalent in modern environments 24:17 - The critical need for rapid containment vs. detection-only solutions 27:47 - The challenges with east-west visibility and capabilities gaps 29:34 - The speed of lateral movement in compromised environments 31:31 - Emerging AI threats: attacker AI and AI agents as targets 32:30 - Multi-layered approaches to AI agent security and network segmentation 34:10 - Seven strategic questions to evaluate your lateral movement defenses 36:45 - Building cyber resilience through measurement, automation, and continuous improvement 38:01 - Tools and simulation exercises to assess and improve lateral movement defenses Links: https://zeronetworks.com/landing/black-hat-26?utm_medium=paid_social&utm_source=linkedin&utm_content=bhlandingchasecunningham https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report?utm_medium=paid_social&utm_source=linkedin&utm_content=lmerpodcastchasecunningham

  4. Jul 13

    The Truth About Cyber Insurance Denials and Your Risk Exposure

    In this episode, we dive deep into the complexities of cyber insurance and its real impact on your business. Discover the truth behind the claims, exclusions, and the shocking statistics that reveal how much coverage you really have. Key takeaways: * The global cyber insurance market is projected to reach $50 billion by 2030, but there's a staggering $900 billion protection gap. * Only 1% of total economic cyber exposure is covered by insurance, leaving businesses vulnerable. * 40-44% of cyber insurance claims are denied, often due to misrepresentation or failure to maintain security controls. * Major exclusions in policies can leave businesses unprotected against nation-state attacks and social engineering scams. Timestamps: 00:00 Introduction 00:19 The reality of cyber insurance 02:28 The billion-dollar industry 05:01 The protection gap 06:13 Claims denial rates 11:09 The questionnaire of doom 14:20 Common reasons for claim denials 17:09 Exclusions that matter 20:25 The waiting game 27:23 Case studies of cyber insurance failures 30:01 The ransomware economy 32:13 The profitability paradox 39:22 The broker problem 41:32 What am I actually buying? 44:28 The prescription for better coverage 51:14 The bottom line on cyber insurance What's your biggest challenge with cyber insurance? Drop it in the comments! Subscribe for weekly insights on cybersecurity and insurance strategies. #CyberInsurance #CyberSecurity #Ransomware

  5. Jul 6

    Zero Trust for Hiring

    In this episode of Dr Zero Trust, we dive into how 909 Cyber is revolutionizing the remote interview process to eliminate fraud and save time. Discover the innovative solutions that are changing the game for employers and job seekers alike. Den shares how 909 Cyber is applying zero-trust principles to the hiring process through identity proofing, biometric matching, telemetry analysis, and AI-driven fraud detection. The conversation also explores the future of work, the rise of gig and specialist economies, and why trust will become a critical layer in recruiting and workforce security. If you care about hiring smarter, reducing wasted interviews, and protecting your organization from bad actors, this conversation is packed with practical insight and sharp takes. Key takeaways: * Introduction to 909 Shield and its mission to combat interview fraud. * The importance of identity proofing and biometric matching in hiring. * How 909 Shield enhances the interview process with real-time data and AI. * The impact of remote work on hiring practices and the gig economy. * Insights on the future of work and the rise of specialist roles. Timestamps: 00:00 Introduction 02:12 Meet Den Jones, CEO of 909 Cyber 03:35 The problem of interview fraud 06:22 How 909 Shield works 08:46 The role of AI in hiring 10:23 Addressing deep fakes in interviews 12:20 The importance of trust in hiring 15:01 The gig economy and its future What's your biggest challenge with remote hiring? Drop it in the comments! Subscribe for weekly insights on cybersecurity and hiring trends! #ZeroTrust #Cybersecurity #RemoteHiring

  6. Jun 10

    The Unicorn Trap and how it is failing the cybersecurity industry.

    Most venture-backed cybersecurity companies are doomed from the start. The math is rigged so only 5-10% of startups survive—and they have to return hundreds of millions, or even billions, to satisfy investors. The result? Exploding tools, premature scaling, vaporware, and a cybersecurity industry obsessed with quick exits rather than real defense. In this eye-opening episode, I pull back the curtain on how the VC funding model distorts cybersecurity innovation. You’ll discover how an industry designed to fail is fueling massive failures like IronNet’s $3 billion valuation crashing in just two years, Lacework’s $8 billion valuation shrinking to $200 million, and Cyber Reason’s 90% valuation collapse in 12 months. These aren’t coincidences—they’re the predictable consequences of a broken system that prizes scale over substance. I break down: * The real math behind “unicorn” valuations and their astronomical burn rates * Why premature scaling kills startups before they can build effective security * How VC incentives favor feature bloat, AI washing, and vaporware over genuine innovation * The ugly truth about the flood of tools that make SOCs worse, not better * Proven models like customer-funded R&D — exemplified by Palantir — that produce real, effective security products without sacrificing integrity If you’re a security buyer tired of bloated tools and false promises, or a founder questioning the current VC-driven chaos, this episode is your wake-up call. The industry is at a crossroads: continue chasing mythical “unicorns” or build resilient, purpose-driven solutions that actually defend us against modern threats. The stakes couldn’t be higher. Because if we keep funding the same flawed cycle, our cybersecurity defenses will remain weak—and the threat actors will keep winning. But there’s hope. Some companies are bucking the trend, proving that profitability and genuine innovation are possible outside the VC model. This is essential listening for security professionals, founders, and investors ready to rethink what really works. Share if you’re fed up with the status quo—because the future of cybersecurity depends on it.

Ratings & Reviews

5
out of 5
9 Ratings

About

Unlock the future of cybersecurity with the "Dr. Zero Trust Podcast" on all podcasting platforms! Join me as we delve into Zero Trust Security, redefining how we protect data and networks. Explore frameworks, threat prevention, identity management, exclusive interviews, and emerging tech. Whether you're a pro or just curious, trust me– this podcast is where those who value honesty and real insights go for their cybersecurity insights! Tune in on Spotify, Google, or ITunes now. #DrZeroTrustPodcast #Cybersecurity #ZeroTrust

You Might Also Like