The cyber weekly

Deogratius Okello, Josephine Olok and Angella Nabbanja

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!

  1. 3d ago

    Can You Trust Digital Forensics Tools? | Julian Derry on Digital Evidence

    Can you trust a digital forensics tool simply because it displays results on a dashboard? Not according to digital forensics professional Julian Derry. In this episode of The Cyber Weekly, Julian joins Deo Okello to explain why investigators must go beyond graphical interfaces and independently validate digital evidence. 🔍 In this episode, you'll discover: ✅ Why digital forensics tools can produce misleading results. ✅ How to validate evidence using raw data and multiple tools. ✅ How to investigate timestamp manipulation and anti-forensics. ✅ Why hands-on virtual labs are essential for learning. ✅ How to build a cybersecurity portfolio without expensive certifications. ✅ Why AI assistants and cloud platforms matter in future investigations. ✅ The practical tools, habits, and communities that help digital forensics professionals grow. Chapters 00:00 Welcome and guest introduction 02:02 Why digital forensics? The missing left shoe story 👟 04:23 From bank hardware support to security 06:45 Breaking into forensics beyond the textbooks 11:16 Why you can't trust the GUI 13:23 Case study: when the MFT tool misbehaved 17:17 Detecting time stomping (anti-forensics) 19:53 Android, iOS, macOS and Linux: same principles 21:08 Why forensics is reactive 21:42 Standing out without expensive certifications 25:59 Emerging evidence: AI assistants and the cloud ☁️ 28:08 Quick fire: 5 tools every analyst needs 33:07 Where to follow Julian's work (X, GitHub, Hive Consult) 38:02 Closing 💡 Julian's advice to aspiring professionals: Build your skills, document your findings, and show your work publicly. 🎙️ Whether you're a cybersecurity student, SOC analyst, digital forensics enthusiast, or experienced investigator, this conversation will challenge how you think about digital evidence. 👍 Like, comment, and subscribe to The Cyber Weekly for conversations that make cybersecurity careers and expertise easier to understand. 💬 QUESTION:Have you ever encountered a tool that produced unexpected results? What did you do? #TheCyberWeekly #DigitalForensics #CyberSecurity #DFIR #DigitalEvidence #CyberSecurityCareers

  2. Sep 24

    From Fixing Printers to CISO: Grant Hughes' Unlikely Cybersecurity Journey

    Ever feel stuck in a help desk role, wondering if cybersecurity is even reachable without a degree or years of "experience"? Grant Hughes was exactly there — until he sent one cold email that changed his career forever. In this episode of The Cyber Weekly Podcast, Grant Hughes (CISO at The Nascent Group, Founding President of the ISC2 Cape Town Chapter) breaks down: How he went from desktop support to CISO with zero security certs The exact conversation that got him his first break in security Why most security awareness training fails — and what actually works The real reason you don't need 5 years of experience to break in The one skill every newcomer needs right now 🔗 Connect with Grant Hughes: Portfolio: https://granthughes.co.za/ LinkedIn: https://www.linkedin.com/in/grant-hughes-52196569/ YouTube: https://www.youtube.com/@granthughes4989 🌍 African Tech Talent Support Project: https://isc2capetownchapter.com/africa-tech-talent-support-project/ 🏢 ISC2 Cape Town Chapter: https://www.linkedin.com/company/isc2-cape-town-chapter/ 💼 The Nascent Group: https://nascent.group/  LinkedIn: https://www.linkedin.com/company/nascent-group-global/ Chapters 00:53  Meet Grant Hughes: From help desk to CISO 02:05  The one takeaway Grant wants you to leave with 03:12  What pulled him from IT support into cybersecurity 04:56  The cold email that changed his life 08:39  What 6 years on the front lines taught him 10:40  Why the basics keep evolving 11:26  What security culture really means 16:44  Handling employee pushback and busy schedules 19:34  Why explaining "why" makes training stick (the password story) 20:15  No certs, no experience? Here's your path in 24:11  The power of networking (and why it beats applying blind) 26:14  AI, soft skills, and what's next for cybersecurity 30:00  Where to find Grant + the African Tech Talent Support Project

  3. Sep 16

    Why Most CISOs Don't Know What Their Business Actually Does

    🚨 Most CISOs can explain every control on their stack but ask them what the business actually sells, and they go quiet. In this episode of The Cyber Weekly, Deo sits down with Jake Bernardes CISO at Gambit Security, ex-pen tester, chartered accountant, and a guy who learned Chinese and German before ever touching cybersecurity. We get into: 💰 The "Minimum Viable Business" framework for justifying security spend 🧩 Why GRC is broken (and how to fix the forgotten "R") 🤖 Which security roles AI will kill and which ones it can't touch 📜 Why Jake thinks certifications are mostly pointless 🌐 Why your network matters more than your CISSP 🎙️ Building leadership on transparency, vulnerability, and authenticity   Here the links Random Access Memories: https://randomaccessmemories.io Jake Bernardes on LinkedIn: https://www.linkedin.com/in/jakeleobernardes/ Random Access Memories on YouTube: https://www.youtube.com/@RandomAccessMemoriesPod   If you're in GRC, trying to break into cybersecurity, or leading a security team through the AI shift this conversation will change how you think about your career. 00:00 Intro: The Intersection of Chinese & Cybersecurity 01:19 Who is Jake Bernardes? 03:18 How Accounting Creates Better CISOs 04:14 The "Minimum Viable Business" & Proving ROI 08:26 Why GRC is Broken (And How to Fix It) 13:02 The Future of GRC Engineering & Automation 17:32 Why Cyber Certifications Are "Pointless" 19:24 AI is Killing Tier 1 SOC Jobs: What to do next 22:43 The 3 Pillars of True Leadership #TheCyberWeekly #CISO #Cybersecurity #GRC #RiskManagement #CyberCareers #InfoSec #CyberLeadership 🔐🎙️📈

  4. Sep 2

    Heather Reed - She Turned 5 Volunteers Into 75 Cybersecurity Ambassadors 🔐

    Only 40% of her company completed the annual security awareness training. Human error was the #1 risk on the register. So she stopped writing policies and started recruiting people. 👥 In this episode of The Cyber Weekly Podcast, Deo Okello sits down with Heather Reed — cybersecurity leader, Cyber Security Woman of the Year finalist, competitive cookie designer 🍪 and former Cookie Wars contestant on the Food Network. Heather came into security from marketing, people leadership and compliance, and she says that non-traditional path became her biggest advantage. She never carried the "Department of No" reputation, because she'd spent years on the other side of it. We get into: 🔹 How she built a cybersecurity ambassador network from 5 departments to 75 ambassadors — and hit 100% training completion 🔹 Why she chose the friendliest people in the business, not the most technical 🔹 The 4 years it took to bring 23 factories and 8,000 employees into the ISMS — and how they scored their best audit ever 🔹 What a real "yes, if" conversation sounds like when the business wants speed 🔹 Tabletop exercises that actually work (hint: ask your execs what keeps them up at night) 🔹 Handling DLP and insider risk without turning security into the police 🚔 🔹 AI agents, guardrails, and why security leaders should be talking to startups 🔹 Her honest answer to "did you ever feel you didn't belong?" — and why that question is only ever asked of women 🔹 Three things any security leader can do in the next 90 days to shift culture

  5. Aug 20

    90 days from technical to IT risk professional

    ⚠️ One overlooked technical issue could become a major financial, operational or reputational crisis. But what exactly is IT risk, and why do organizations invest so much in managing it? In this episode of The Cyber Weekly Podcast, Deo Okello sits down with IT risk and security professional Peter Muhumuza to break down IT risk in practical, easy-to-understand language. You will learn: 🔍 How technical weaknesses become business risks 📊 How organizations classify and track risks ⚖️ Which risks can be accepted and which require immediate action 🚀 How risk professionals support innovation without becoming “Mr. No” 🤝 Why third-party and vendor risk assessments matter ☁️ The risks created by cloud concentration and AI adoption ✅ Why passing an audit does not mean risk management is complete 📈 How technical professionals can begin transitioning into IT risk within 90 days Peter also explains why effective IT risk management is about more than fixing technical problems. It requires understanding business priorities, regulatory obligations, operational downtime and financial exposure. If you work in cybersecurity, IT, banking, fintech, audit, governance or risk management, this conversation is for you. 👍 Like this episode 💬 Share your biggest IT risk lesson in the comments 🔔 Subscribe to The Cyber Weekly Podcast for more practical cybersecurity conversations 📤 Share this episode with someone interested in IT risk #TheCyberWeekly #ITRisk #RiskManagement #Cybersecurity #InformationSecurity #GRC #ThirdPartyRisk #CloudSecurity #CyberRisk #ITGovernance

About

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!