Prabh Nair

Prabh Nair

Prabh Nair is a cybersecurity podcaster covering cyber risk, ransomware, incident response, SOC operations, GRC, AI security, threat intelligence, digital forensics, ISO 27001, CISSP, CISM, and security leadership. Built for SOC analysts, auditors, cybersecurity professionals, students, and business leaders, each episode delivers simple explanations, practical lessons, and real-world examples to help you stay ahead in the fast-changing cyber world. #CyberSecurity #InformationSecurity #CyberRisk #GRC #SOC #IncidentResponse #Ransomware #ThreatIntelligence #AISecurity #DigitalForensics

  1. 6d ago

    How to Prepare for OffSec AI-300 AI Red Teaming

    Prepare for the Offsec OSAI+ certification with insights on interview strategies for 2026 cybersecurity roles.Ankit Bharathan joins Prabh Nair to discuss the path to mastering the Offsec OSAI+ (AI-300) certification. This conversation focuses on the practical skills required for professionals aiming to enter the specialized field of AI Security.Beyond the technical curriculum, we analyze effective interview strategies and the specific criteria used for candidate selection in 2026. Whether you are looking to pivot your career or sharpen your expertise, this session provides a roadmap to navigating the hiring landscape for off-sec positions.A practical learning path discussed in the episode:Web Security → AI Fundamentals → Build an LLM App → RAG → Embeddings → Agents → Threat Modeling → AI Security Labs → AI Red TeamingThis episode will be useful for:Pentesters • Red Teamers • AppSec Engineers • AI Security Professionals • OSCP holders • Security Researchers • AI Engineers • Cybersecurity StudentsSubscribe for weekly technology infrastructure breakdowns and comment below on what certification topics you want covered next.Prepare for the Offsec OSAI+ certification with insights on interview strategies for 2026 cybersecurity roles.Ankit Bharathan joins Prabh Nair to discuss the path to mastering the Offsec OSAI+ (AI-300) certification. This conversation focuses on the practical skills required for professionals aiming to enter the specialized field of AI Security.Linkedin Profilehttps://www.linkedin.com/in/ankitbharathan/https://github.com/microsoft/AI-Red-Teaming-Playground-Labshttps://owasp.org/projects/top-10-for-large-language-model-applicationshttps://atlas.mitre.org/AI red teaming is becoming a serious extension of offensive security.But preparing for AI security assessments requires more than learning prompt injection.You need to understand how modern AI applications are actually built — LLMs, RAG pipelines, vector databases, embeddings, agents, APIs, web applications and the traditional infrastructure underneath them. Beyond the technical curriculum, we analyze effective interview strategies and the specific criteria used for candidate selection in 2026. Whether you are looking to pivot your career or sharpen your expertise, this session provides a roadmap to navigating the hiring landscape for off-sec positions.Subscribe for weekly technology infrastructure breakdowns and comment below on what certification topics you want covered next.

  2. Oct 1

    Breaking Down Ransomware: Insights and Analysis

    Welcome to our deep dive into the world of ransomware. In this video, we'll unravel the intricacies of ransomware investigation , exploring their mechanisms, common vectors, and the tools used for analysis. From understanding the initial infection point to decrypting locked files, our comprehensive analysis will equip you with the knowledge to stay one step ahead of cyber threats.In this video, we'll be breaking down ransomware: what it is, how it works, and some tips on how to investigate ransomware . We'll also be discussing the different types of ransomware analysis, including static and dynamic analysis.If you're investigating ransomware symptoms or trying to determine if a system is infected, this is the video for you! We'll discuss the different types of ransomware, how to investigate them, and how to determine if a system is infected. After watching this video, you'll be able to break down ransomware and investigate it in a way that will help you protect your data!Ransomware Serieshttps://www.youtube.com/playlist?list=PL0hT6hgexlYy0PZMz9DejEZ2iDKBC-RTGSOC Interview Questionshttps://www.youtube.com/watch?v=UF_oLGoRL_c&list=PL0hT6hgexlYxd24Jb8OE7vZoas-iTcHAcPlaylist Network Securityhttps://www.youtube.com/playlist?list=PL0hT6hgexlYzX6AWwcyDbAZQUKYJL2MdtGRC Interview Questionshttps://youtu.be/4TyfNtFGAC4Internal Auditor Playlist https://www.youtube.com/playlist?list=PL0hT6hgexlYyNWBcGYfabwumCr0GKmLWvHow to make career progression post #isc2 and #isaca https://www.youtube.com/watch?v=PT0fnCWzAFA&pp=ygUJZ3JjIHByYWJoHow to make career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=102s&pp=ygUJZ3JjIHByYWJoHow to Build PIMShttps://www.youtube.com/watch?v=IwAseU4ZmuQHow to Implement 27001 in an organization https://www.youtube.com/watch?v=sQqJH2naU6IHow to conduct PIAhttps://www.youtube.com/watch?v=z1BD7exH2Ow&t=774sHow to Make a career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=7sTelegram Grouphttps://t.me/InfoseclearningStart your career in cybersecurity with free resources https://lnkd.in/g89gxkzc. Cybersecurity Career: How to Make a Career in Cybersecurity 2022 https://lnkd.in/gCGBnRM7Pentesting Career https://lnkd.in/gQYenKYdTelegram Group Linkhttps://t.me/InfoseclearningCybersecurity Guidehttps://www.youtube.com/playlist?list=PL0hT6hgexlYwdYBW6yqUQMuRqvABiQPXkFollow me on Instagramhttps://www.instagram.com/prabhnair/?...#soc #cybersecurity #infosec #ransomware , #Cybersecurity #malware Analysis, #RansomwareDecryption, Cyber Threats, #ransomwareattack #DigitalSecurity.

  3. Sep 28

    Real ITGC Interview Questions from Big 4 Firms : Must-Know Questions

    Welcome to our channel! In this video, we dive deep into realistic ITGC interview questions frequently asked in Big 4 firms. If you're preparing for an ITGC (IT General Controls) interview with top consulting firms like Deloitte, PwC, EY, and KPMG, this video is a must-watch!What You'll Learn:The most common ITGC interview questions asked by Big 4 firms.Insider tips on how to answer these questions effectively.Real experiences from candidates who have successfully navigated ITGC interviews.Essential knowledge for ITGC consulting and audit roles.Why Watch This Video?Securing a job in ITGC consulting or ITGC audit at a Big 4 firm can be challenging. This video equips you with the insights and confidence you need to ace your interview. Whether you're a fresh graduate or an experienced professional, understanding these interview questions is crucial for your success.What You'll Learn:The most common ITGC interview questions asked by Big 4 firms.Scenario-based questions to help you prepare for real-life interview situations.Insider tips on how to answer these questions effectively.Real experiences from candidates who have successfully navigated ITGC interviews.Techniques to handle questions with confidence and make a great impression.Essential knowledge for ITGC consulting and audit roles.Internal Audithttps://www.youtube.com/playlist?list=PL0hT6hgexlYyNWBcGYfabwumCr0GKmLWvGRChttps://www.youtube.com/playlist?list=PL0hT6hgexlYz1Usn1Nrnur6OzVoz59zylAudit Serieshttps://www.youtube.com/watch?v=an15rFruIvo&list=PL0hT6hgexlYzvKY3AcOX2M7bkLRFVpQv4&pp=gAQBiAQB#ITGCInterviewPreparation#itaudit #audition #audition #itsecurity #itgc #sox

  4. Sep 21

    How to Build a Cybersecurity Program from Scratch | CISO Transformation Playbook

    Master Cybersecurity leadership with insights from Ilyas Kooliyankal, Cyber Security Leader of CyberShelter, on navigating modern industry challenges.Ilyas Kooliyankal joins Prabh Nair to discuss what it takes to succeed in the field today. With nearly three decades of experience across enterprise technology and financial services, Ilyas outlines the essential traits required for those looking to build a successful CISO career.We break down the core components of professional growth, emphasizing that knowledge, understanding, and common sense are just as critical as technical aptitude. The conversation also explores how to effectively prioritize security gaps when managing complex systems, providing a clear roadmap for GRC professionals aiming to advance their expertise.Building a cybersecurity program from scratch is not about buying more tools, copying policies, or implementing every security control available.https://www.linkedin.com/in/illyas/It starts with understanding what the business is trying to protect, how much risk it is willing to accept, and which security gaps create the greatest business impact.In this podcast, Prabh speaks with Illyas, a cybersecurity leader with nearly three decades of experience, about the practical process of building and transforming an enterprise cybersecurity program.The conversation covers:How to define information security risk appetiteWhy risk appetite should come before security strategyHow to perform a business-focused security gap assessmentHow to prioritize critical, high, medium, and low risksWhy externally exposed risks may need immediate actionHow to use existing controls before asking for new technologyHow to link cybersecurity investments to business objectivesHow to justify cybersecurity budgets to managementHow to communicate technical cyber risk in business languageHow to balance security with cloud, SaaS, AI, and digital transformationHow to build an executive cybersecurity dashboardHow to convert risk assessment into a strategic roadmapHow to establish the security operating model, roles, and responsibilitiesHow maturity targets should connect back to risk appetiteThe difference between KRIs and longer-term risk metricsSubscribe for weekly technology infrastructure breakdowns and comment below on what leadership topic you want covered next.#CISO #CyberSecurity #CyberRisk #RiskManagement #GRC #SecurityStrategy #CyberSecurityLeadership #SecurityArchitecture #RiskAppetite #CyberGovernance #CISOMindset #CoffeeWithPrabh

  5. Sep 17

    How to Investigate Akira Ransomware : Practical Insight

    Join cybersecurity experts Mr. Abhijeet and Mr. Chirayu in this enlightening podcast as they unravel the complexities of the Akira ransomware. Dive deep into their step-by-step investigation, uncovering the critical insights that led to the identification, mitigation, and protection strategies against this formidable cyber threat.https://www.linkedin.com/in/abhijit-tripathy-a84257a3/?originalSubdomain=inhttps://www.linkedin.com/in/chirayu-mahajan-bb1a974a/In this video, our speakers share exclusive documents and logs instrumental in dissecting the ransomware’s mechanisms. Gain practical knowledge on how these seasoned professionals navigated the challenges posed by Akira, developing robust defense tactics to safeguard organizational assets.🚀 In This Episode, You Will Discover:Dual Extortion Tactics: The double-edged threat posed by Akira ransomware and how it leverages victim data for ransom.Hybrid Encryption Techniques: Unpacking the encryption strategies that make Akira a formidable foe.Living Off The Land Attacks: Insights into how attackers use legitimate tools for malicious purposes.Reflective Injection Attacks: A deep dive into how Akira bypasses conventional detection methods.The Shadowy World of Initial Access Brokers: Understanding the brokers that provide gateways for ransomware attacks.PowerSploit's Role: Exploring how the PowerShell Mafia’s toolkit aids in the spread of Akira.Reconstructing RDP Bitmap Cache: A look at how investigators piece together user actions from remote desktop protocol data.Mr. Abhijeet and Mr. Chirayu not only share their riveting journey uncovering Akira but also arm you with the knowledge to identify, mitigate, and shield your organization against such sophisticated cyber threats.🌐 Stay Safe in the Cyber World: Whether you’re a cybersecurity rookie or a seasoned professional, this podcast is packed with invaluable insights that will elevate your understanding and preparedness against cyber threats.#CyberSecurity #AkiraRansomware #InfoSec #RansomwareInvestigation #DataProtection #ThreatIntelligence #CyberAttack #DigitalDefense #TechInsights #PowerSploit #InitialAccessBroker #DualExtortion #HybridEncryptionPart 2https://youtu.be/PUdvXHpKNjE✨ Don’t forget to subscribe for more exclusive content, and hit that bell icon so you never miss out on cybersecurity insights. Like, share, and comment below with your thoughts or questions for our experts!Playlist CISO Talkhttps://www.youtube.com/playlist?list=PL0hT6hgexlYz1LzzrLwTiSt5d_kO_0QsEPlaylist Network Securityhttps://www.youtube.com/playlist?list=PL0hT6hgexlYzX6AWwcyDbAZQUKYJL2MdtGRC Interview Questionshttps://youtu.be/4TyfNtFGAC4Internal Auditor Playlist https://www.youtube.com/playlist?list=PL0hT6hgexlYyNWBcGYfabwumCr0GKmLWvHow to make career progression post #isc2 and #isaca https://www.youtube.com/watch?v=PT0fnCWzAFA&pp=ygUJZ3JjIHByYWJoHow to make career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=102s&pp=ygUJZ3JjIHByYWJoHow to Build PIMShttps://www.youtube.com/watch?v=IwAseU4ZmuQHow to Implement 27001 in an organization https://www.youtube.com/watch?v=sQqJH2naU6IHow to conduct PIAhttps://www.youtube.com/watch?v=z1BD7exH2Ow&t=774sHow to Make an career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=7sTelegram Grouphttps://t.me/InfoseclearningStart your career in cybersecurity with free resources https://lnkd.in/g89gxkzc Cybersecurity Career: How to Make a Career in Cybersecurity 2022 https://lnkd.in/gCGBnRM7Pentesting Career https://lnkd.in/gQYenKYdTelegram Group Linkhttps://t.me/InfoseclearningCybersecurity Guidehttps://www.youtube.com/playlist?list=PL0hT6hgexlYwdYBW6yqUQMuRqvABiQPXk#ransomware #cybersecurity #infosec #hacking

  6. Sep 14

    How to Prepare for CGRC Certification in 2026

    Many professionals come from ISO 27001, audit, compliance, or traditional cybersecurity backgrounds. But CGRC is strongly aligned with NIST publications, system authorization, security and privacy control assessment, and the Risk Management Framework lifecycle.In this podcast episode, Prabh speaks with Aamir about his CGRC preparation journey, the difference between ISO-based GRC thinking and NIST-based GRC thinking, and why CGRC is useful for professionals working in governance, risk, compliance, security authorization, FedRAMP, control assessment, and AI governance. In this episode, we discuss:What CGRC certification isWhy CGRC requires NIST-based thinkingDifference between ISO-based GRC and NIST-based GRCWhy NIST RMF is central to CGRC preparationHow CGRC is different from CISSP, CCSP, CISA, CRISC and ISO 27001Why system authorization boundaries matterWhy control implementation and assessment are importantHow compliance becomes a lifecycle processWhy POA&M is important in risk assessment and remediationHow FISMA, FedRAMP, NIST, COBIT and ISO connect in GRC thinkingWhy CGRC is relevant for security and privacy integrationHow CGRC connects with AI governance and algorithmic riskKey NIST publications for CGRC preparationHow to prepare using the CBK and structured training materialsWhy candidates must think like a risk governance advisorAamir also explains that CGRC professionals should be able to support the full security lifecycle:Define authorization boundariesIdentify and categorize systemsSelect and implement controlsAssess control effectivenessSupport authorization decisionsMaintain continuous monitoringTrack remediation through POA&MAlign compliance with business and mission risk

  7. Sep 10

    Inside the Ransomware War Room | Human Side of Cybercrime with Jon DiMaggio

    Ransomware is not only a technical problem.Behind every ransomware attack, there are people — operators, affiliates, initial access brokers, negotiators, developers, money launderers, and criminal leaders making decisions under pressure.In this podcast episode, Prabh speaks with Jon DiMaggio, cybercrime investigator, founder and principal researcher at Arkham Cyber, and author of The Art of Cyber Warfare, about the human side of ransomware operations.Jon explains why organizations make a major mistake when they treat ransomware only as malware, encryption, indicators of compromise, backups, and recovery.The real adversary is human.To defend better, security teams must understand attacker motivation, fear, ego, trust, negotiation behavior, relationships, mistakes, and internal conflicts.In this episode, we discuss:Why ransomware is not only a technical problemWhy understanding the human adversary mattersHow ransomware groups operate behind the scenesThe role of initial access brokersHow affiliate teams work inside ransomware-as-a-service ecosystemsHow ransomware operators manage extortion and negotiation pressureWhy human intelligence matters in cybercrime investigationHow dark web research helps reveal attacker behaviorHow Jon investigated the LockBit ransomware groupWhy attacker psychology, ego, trust, and internal conflict matterHow technical intelligence and human intelligence work togetherHow MITRE ATT&CK, Cyber Kill Chain, and Diamond Model help defendersWhy technical indicators alone are not enoughHow ransomware negotiation patterns can manipulate victimsHow law enforcement and private-sector intelligence can support disruptionHow AI may increase the speed, scale, and automation of ransomware attacksWhy defenders must combine telemetry, threat intelligence, and human behavior analysisLinkedin Profilehttps://www.linkedin.com/in/jondimaggio/https://www.amazon.in/Art-Cyberwarfare-Investigators-Ransomware-Cybercrime-ebook/dp/B09BKLRH8P#Ransomware #ThreatIntelligence #CyberCrime #DarkWeb #LockBit #IncidentResponse #SOC #CISO #CyberSecurity #HumanIntelligence

Ratings & Reviews

5
out of 5
3 Ratings

About

Prabh Nair is a cybersecurity podcaster covering cyber risk, ransomware, incident response, SOC operations, GRC, AI security, threat intelligence, digital forensics, ISO 27001, CISSP, CISM, and security leadership. Built for SOC analysts, auditors, cybersecurity professionals, students, and business leaders, each episode delivers simple explanations, practical lessons, and real-world examples to help you stay ahead in the fast-changing cyber world. #CyberSecurity #InformationSecurity #CyberRisk #GRC #SOC #IncidentResponse #Ransomware #ThreatIntelligence #AISecurity #DigitalForensics

You Might Also Like