Inside Cyber Minds

Luciano Ferrari

Step inside the minds of cybersecurity leaders. Hosted by Luciano Ferrari, Inside Cyber Minds explores how professionals in security think, lead, and keep learning in an industry that never slows down. Each episode dives into honest conversations about growth, imposter syndrome, leadership, and the human side of cybersecurity — reminding us that even the experts are still figuring it out. 🎙️ Part of the Lufsec Podcast series. 🧠 Conversations that shape security.

  1. 4d ago

    Inside Cyber Minds S2E8 — Katie Moussouris: Bug Bounties, Vulnerability Disclosure, Hacker Economics

    🛡️ This episode is all about vulnerability disclosure, bug bounty programs, and working effectively with security researchers. To build practical offensive security skills, explore LufSec’s cybersecurity courses and hands-on training:👉 https://www.lufsec.com/courses/?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s2e8-course━━━━━━━━━━━━━━━━━━━━Season 2 of Inside Cyber Minds continues with Katie Moussouris — founder and CEO of Luta Security and one of the most influential leaders in vulnerability disclosure, bug bounty programs, and hacker economics.Katie has helped shape how major technology companies, governments, and global organizations work with security researchers. Her career includes launching vulnerability programs at Microsoft, contributing to the creation of Hack the Pentagon, and helping develop international standards for vulnerability disclosure and handling.Her core argument: launching a bug bounty program is not the same as building a mature vulnerability management capability. Organizations must first create the internal processes, resources, ownership, and remediation capacity required to receive and act on vulnerability reports.We discuss how organizations should work with hackers, why some bug bounty programs fail, and how leaders can determine whether their security teams are ready to engage with external researchers.Katie also explains the economics behind vulnerability research, how incentives influence researcher behavior, and why paying for vulnerabilities without fixing the underlying process can create more problems than value.We explore coordinated vulnerability disclosure, researcher relationships, government programs, liability protections, security maturity, and the difference between generating more vulnerability reports and actually reducing organizational risk.Katie also shares her perspective on the future of vulnerability research, how AI may affect bug discovery and exploitation, and what security leaders must understand before scaling a disclosure or bounty program.Topics CoveredKatie’s path into cybersecurity and vulnerability researchThe origins of modern bug bounty programsBuilding vulnerability disclosure programs at MicrosoftThe creation and impact of Hack the PentagonWhy bug bounty programs are not a shortcut to security maturityVulnerability disclosure versus vulnerability managementHow organizations should work with security researchersThe economics of vulnerabilities and hacker incentivesMeasuring the ROI of bug bounty programsCommon mistakes organizations make when launching programsCoordinated vulnerability disclosure and safe harborGovernment collaboration with ethical hackersPreparing internal teams to receive vulnerability reportsHow AI may change vulnerability discovery and exploitationThe future of bug bounties and security researchAbout Inside Cyber MindsA LufSec cybersecurity podcast featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders about mindset, decisions, emerging threats, and the human side of cybersecurity.LinkedIn: https://www.linkedin.com/company/lufsec/Katie Moussouris and Luta SecurityWebsite:https://www.lutasecurity.com/X:https://x.com/LutaSecurityhttps://x.com/k8em0Bluesky:https://bsky.app/profile/lutasecurity.bsky.socialhttps://bsky.app/profile/k8em0.bsky.social#Cybersecurity #BugBounty #VulnerabilityDisclosure #EthicalHacking #HackerEconomics #KatieMoussouris #LutaSecurity #InsideCyberMinds

  2. Jul 22

    Inside Cyber Minds S2E7 — David Girvin: AI Agent Security, Runtime Governance & Future Attacks

    Season 2 of Inside Cyber Minds continues with David Girvin — offensive security expert, cybersecurity leader, and founder of Honey Badger, focused on securing AI agents at the execution layer.After an injury forced him to leave welding, David discovered hacking and bug bounty programs. That curiosity became a career spanning offensive security, threat modeling, detection engineering, MDR, startup leadership, and AI security.His core argument: AI governance cannot stop at policies, model evaluations, or prompt filtering. As agents gain access to tools, credentials, data, and business processes, organizations need controls that govern what they can actually execute.We discuss adaptive agent governance, runtime enforcement, deterministic controls, and why securing thousands of autonomous agents requires a different security architecture.David also shares lessons from BitDiscovery, 1Password, Red Canary, and Sumo Logic, and explains how offensive security, leadership, detection engineering, and threat modeling shaped his approach.We explore how attackers may target AI agents, why prompt injection is not going away, how attacks could evolve, and which AI security failures may emerge over the next two years.David also predicts that by 2028, AI will handle more repetitive SOC analysis while humans focus on judgment, investigation, and complex decisions.Topics CoveredDavid’s journey from welding to offensive cybersecurityBug bounty programs and early hacksThreat modeling for AI agentsWhy traditional AI governance is not enoughAdaptive agent governance at the execution layerRuntime governance and deterministic controlsSecuring agents with access to tools, systems, and dataPrompt injection and future AI attack techniquesManaging thousands of autonomous agentsHow AI may reshape SOC roles by 2028Expected AI security failures over the next two yearsChapters00:00 Introduction to David Girvin and his background01:14 Early security experiences and breaking into cars02:04 Transition from welding to cybersecurity03:32 Discovering hacking and bug bounty programs04:28 Offensive security work and early hacks06:38 Understanding the defender’s perspective08:42 The impact of AI on cybersecurity10:41 Startup GTM lessons from BitDiscovery12:32 Leadership challenges at 1Password14:00 Threat modeling inside a large organization15:42 Detection engineering and MDR operations18:25 Lessons from Red Canary and Sumo Logic20:00 Founding Honey Badger and focusing on AI security22:15 Hacking agents and securing agent environments25:43 Adaptive agent governance explained36:14 AI governance and deterministic controls40:37 Scaling security across thousands of AI agents45:53 Future agent attack techniques and AI risks51:29 Why prompt injection remains a major threat53:33 Runtime governance and platform integrations58:24 How SOC analyst roles may evolve by 202801:02:46 Expected AI security failures over the next two years01:04:23 Closing remarksAbout Inside Cyber MindsA LufSec cybersecurity podcast featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders about mindset, decisions, emerging threats, and the human side of cybersecurity.Watch & Listen🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🍎 Apple: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640🎤 Amazon: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1LinkedIn: https://www.linkedin.com/company/lufsec/David Girvin: https://assury.ai/#Cybersecurity #AISecurity #AgentSecurity #PromptInjection #AIGovernance #OffensiveSecurity #DavidGirvin #InsideCyberMinds

  3. Jul 17

    Inside Cyber Minds S2E6 — Marcio Cots: AI Overtrust, Digital Governance & the $1 Car a Chatbot Sold

    🎯 Free Cyber Security Career GuideBreak into cybersecurity without wasting years on the wrong path — the roles, skills, certs, and the shortest route in:👉 https://www.lufsec.com/products/digital_downloads/cyber-security-career-guide?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s2e6🎓 Bonus: download the guide and unlock a free lesson from the LufSec course library.🤖 In this episode, Marcio tells the story of a chatbot that sold a car for $1 through prompt injection. Want to learn how those attacks actually work — and how to defend against them? My new course, Introduction to Prompt Hacking for LLMs, has 2 free lessons — no card, no signup:👉 https://www.lufsec.com/enroll/3577077?et=free_trial&utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s2e6-course━━━━━━━━━━━━━━━━━━━━Season 2 of Inside Cyber Minds continues with Marcio Cots — international technology and privacy lawyer, digital governance consultant at GetGlobal International / ethosfy, and professor of AI ethics at Atlantis University. Marcio took Harvard Law School's cyber law program in 2005 — before "cyber law" was even a category — and has spent two decades building privacy and AI governance programs across the US, Europe, and Latin America.His core warning: the biggest AI risk most organizations are underestimating isn't poor performance — it's OVERTRUST. As AI gets more accurate, oversight gets quieter. His analogy: using AI is like riding a motorcycle — useful and reliable, until you get confident enough to skip the procedures.We discuss the three dimensions of AI governance every company must manage (how you use AI, how you buy it, how you develop it), why governance starts with assessment rather than policy, pentest-style testing for privacy programs, and the global regulatory chessboard — the EU AI Act, Brazil's LGPD, the US patchwork, and China's pragmatic approach.We also talk about the AI Risk Inspector — the AI risk assessment tool built as a joint venture between LufSec and ethosfy, running 1,400+ automated tests to catch AI risks before production. LufSec leads technical development; ethosfy leads sales and marketing.And near the end, the story that says it all: a company's chatbot sold a brand-new car for one dollar — because of a prompt injection attack.Topics CoveredWhy AI overtrust is the most underestimated riskThe three dimensions of AI governance: use, procurement, development"Privacy Proof" — pentest-style testing for privacy programsAI Risk Inspector — the LufSec × ethosfy tool (1,400+ tests)EU AI Act, LGPD, US patchwork, and China's approachThe one rule Marcio would mandate: human supervisionThe $1 car — prompt injection in the wildAbout Inside Cyber MindsA cybersecurity podcast by LufSec featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders — mindset, decision-making, emerging threats, and the human side of cybersecurity.Watch & Listen🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🍎 Apple: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640🎤 Amazon: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1LinkedIn: https://www.linkedin.com/company/lufsec/#Cybersecurity #AIGovernance #DataPrivacy #PromptInjection #ArtificialIntelligence #CyberLaw #MarcioCots #InsideCyberMinds

  4. Jul 10

    Inside Cyber Minds S2E5 — Roger Grimes: AI, Quantum & the Future of Cybersecurity

    Season 2 of Inside Cyber Minds continues with Roger Grimes — cybersecurity author, researcher, speaker, and one of the industry’s most experienced voices on malware, social engineering, identity, artificial intelligence, and emerging security threats. In this episode, Roger shares lessons from decades on the front lines of cybersecurity and explains why organizations continue to be compromised despite investing heavily in security tools. We discuss the two problems behind most successful cyberattacks, why identity and social engineering remain so effective, and how defenders can focus on the risks that actually cause the majority of real-world breaches. The conversation also explores the growing impact of artificial intelligence and quantum computing on cyber threats and defenses. Roger explains what security leaders should take seriously today, what is still being exaggerated, and how organizations should prepare for a rapidly changing threat landscape. This is a practical and strategic discussion about security fundamentals, emerging technology, risk prioritization, and why cybersecurity teams must become more data-driven. If you care about AI security, quantum computing, identity attacks, social engineering, ransomware, and building more effective security programs, this episode is essential listening. Topics Covered The two root causes behind most successful cyberattacksWhy social engineering remains one of the biggest security risksIdentity, credentials, and authentication attacksWhy organizations often focus on the wrong security problemsArtificial intelligence as an offensive and defensive security toolHow quantum computing could affect cybersecurityPost-quantum cryptography and organizational readinessMalware, ransomware, and modern attacker techniquesData-driven defense and risk prioritizationLessons from Roger’s decades in cybersecurityHow security leaders should prepare for emerging threatsThe future of cybersecurity education and awarenessRoger Grimes’ New Book Roger recently released his 16th book: How AI and Quantum Impact Cyber Threats and Defenses Amazon:https://www.amazon.com/dp/B0GGB7Y855/ Get a Free PDF Copy Roger is offering podcast viewers a free PDF copy of the book: https://www.knowbe4.com/hubfs/AI-Quantum-Book-Roger-Grimes.pdf About Inside Cyber Minds Inside Cyber Minds is a cybersecurity podcast by Lufsec, featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders. The show focuses on mindset, decision-making, leadership pressure, emerging threats, and the human side of cybersecurity. Watch & Listen ▶️ YouTube: https://youtube.com/@Lufsec 🔗 Listen on your favorite platform🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🎤 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640 LinkedIn: https://www.linkedin.com/company/lufsec/ #Cybersecurity #ArtificialIntelligence #QuantumComputing #RogerGrimes #InsideCyberMinds

  5. Jul 2

    Inside Cyber Minds S2E4 — Hector Monsegur: From Sabu to Cybersecurity

    Season 2 of Inside Cyber Minds continues with Hector Monsegur, also known as Sabu — the former Anonymous and LulzSec hacker whose story became one of the most controversial and widely discussed chapters in modern hacking history.In this episode, Hector shares his journey from the underground hacking world to the realities of consequences, accountability, transformation, and cybersecurity today.We discuss the rise of Anonymous and LulzSec, the culture of hacking during that era, what motivated many of those operations, and how the line between activism, cybercrime, ego, and chaos can become dangerously blurred.This conversation goes beyond the headlines.It is about identity, pressure, loyalty, mistakes, consequences, reinvention, and what the cybersecurity community can learn from people who have lived on both sides of the keyboard.If you care about hacking culture, Anonymous, LulzSec, cybercrime, redemption, and the human side of cybersecurity, this episode is essential listening.Topics Covered* Hector Monsegur’s journey as Sabu* The rise of Anonymous and LulzSec* Hacking culture and online movements* Hacktivism, cybercrime, and blurred lines* The psychology of hacking communities* Mistakes, consequences, and accountability* What the media often gets wrong about hackers* Life after the underground hacking world* Redemption, reinvention, and second chances* Lessons for young hackers and cybersecurity professionals* Why the human side of cybersecurity mattersAbout Inside Cyber MindsInside Cyber Minds is a cybersecurity podcast by Lufsec, featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, and industry leaders. The show focuses on mindset, decision-making, leadership pressure, and the human side of cybersecurity.Watch & Listen▶️ YouTube: https://youtube.com/@Lufsec🔗 Listen on your favorite platform🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🎤 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640LinkedIn → https://www.linkedin.com/company/lufsec/Hector MonsegurSafehill: https://safehill.comLinkedIn: https://www.linkedin.com/in/hxmonsegur/

  6. Jun 25

    Inside Cyber Minds S2E3 — JP Calabio: CISO Leadership, Risk & Real-World Security

    Season 2 of Inside Cyber Minds continues with JP Calabio — cybersecurity executive, CISO, and security leader at Grainger.In this episode, JP shares a practical look at modern cybersecurity leadership from the perspective of someone responsible for protecting a large, complex enterprise environment.We discuss what it really means to lead security inside a business, how CISOs balance risk, operations, communication, and executive expectations, and why cybersecurity leadership is no longer just about technology.This conversation goes beyond tools and frameworks.It is about decision-making, business alignment, security culture, leadership pressure, vendor noise, resilience, and the reality of defending organizations where security must enable the business without slowing it down.If you care about CISO leadership, enterprise security, cyber risk, executive communication, and the human side of cybersecurity, this episode is essential listening.Topics CoveredThe role of the modern CISOCybersecurity leadership inside a large enterpriseRisk management and business alignmentCommunicating security to executives and the boardBuilding security programs that support the businessThe difference between technical security and leadershipSecurity culture and organizational influenceVendor noise and how security leaders evaluate solutionsResilience, incident readiness, and operational pressureLessons for the next generation of cybersecurity professionalsHow CISOs think about trust, accountability, and executionAbout Inside Cyber MindsInside Cyber Minds is a cybersecurity podcast by Lufsec, featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, and industry leaders. The show focuses on mindset, decision-making, leadership pressure, and the human side of cybersecurity.Watch & Listen▶️ YouTube: https://youtube.com/@Lufsec🔗 Listen on your favorite platform🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🎤 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640LinkedIn → https://www.linkedin.com/company/lufsec/JP Calabio / LinksCISOXC Chicago 2026: https://www.cisoxc.com/chicago-2026Grainger: https://www.grainger.com/

  7. Jun 17

    Inside Cyber Minds S2E2 — Toni de la Fuente: Open Cloud Security & Prowler

    Season 2 of Inside Cyber Minds continues with Toni de la Fuente — founder and CEO of Prowler, creator of the open-source Prowler project, and a cloud security leader focused on helping organizations secure cloud environments with transparency, automation, and practical security engineering. In this episode, Toni shares the story behind Prowler, how an open-source cloud security tool became a widely used platform for security and compliance, and why cloud security needs to be practical, continuous, and accessible. We discuss the evolution of cloud security, the challenges of securing AWS, Azure, Google Cloud, Kubernetes, GitHub, Microsoft 365, Infrastructure as Code, and other modern environments, and why visibility remains one of the hardest problems for security teams. This conversation is about more than one tool. It is about open source, cloud security posture management, compliance automation, engineering culture, startup building, community, and the future of securing complex cloud environments. If you care about cloud security, open source, compliance, automation, and how security tools are built from real-world engineering problems, this episode is essential listening. Topics Covered The story behind ProwlerOpen-source cloud securityCloud security posture managementSecurity and compliance automationAWS, Azure, Google Cloud, Kubernetes, GitHub, Microsoft 365, and multi-cloud visibilityWhy cloud security needs to be continuousThe role of open source in cybersecurityBuilding a security product from a community projectThe challenge of making cloud security simple, scalable, and usefulWhat security teams often get wrong about cloud securityToni’s journey as a founder and security engineerThe future of cloud security and AI-driven security workflowsAbout Inside Cyber Minds Inside Cyber Minds is a cybersecurity podcast by Lufsec, featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, and industry leaders. The show focuses on mindset, decision-making, leadership pressure, and the human side of cybersecurity. Watch & Listen ▶️ YouTube: https://youtube.com/@Lufsec 🔗 Listen on your favorite platform🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🎤 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640 LinkedIn → https://www.linkedin.com/company/lufsec/ Toni de la Fuente / Prowler Prowler: https://prowler.com/Prowler GitHub: https://github.com/prowler-cloud/prowlerProwler Docs: https://docs.prowler.com/Toni’s website: https://blyx.com/

  8. Jun 10

    Inside Cyber Minds S2E1 — Dmitri Alperovitch: Cyber War & Global Security

    The Season 2 premiere of Inside Cyber Minds features a conversation with Dmitri Alperovitch — co-founder and former CTO of CrowdStrike, co-founder and chairman of Silverado Policy Accelerator, founder of the Alperovitch Institute for Cybersecurity Studies at Johns Hopkins SAIS, and author of World on the Brink: How America Can Beat China in the Race for the 21st Century.In this episode, Dmitri goes beyond traditional cybersecurity conversations to explore how cyber conflict now fits into a much larger global picture: nation-state competition, geopolitical power, deterrence, intelligence, China, Russia, Taiwan, Ukraine, and the future of American leadership.We discuss how cyber operations have changed over the years, why the line between cybersecurity and national security has almost disappeared, and what security leaders need to understand about the new era of global conflict.This is not a tactical “how-to” episode. It’s a strategic conversation about power, cyber statecraft, geopolitical risk, and where cybersecurity is heading next.If you care about cyber war, national security, threat intelligence, and the people shaping the future of global cybersecurity, this episode is essential listening.Topics Covered- Cybersecurity as a national security issue- Cyber war, cyber espionage, and state-sponsored operations- China, Taiwan, and the race for the 21st century- Russia, Ukraine, and lessons from modern conflict- The evolution of threat intelligence- What cyber leaders often misunderstand about geopolitics- Deterrence, power, and strategic competition- Dmitri’s journey from CrowdStrike to Silverado Policy Accelerator- The role of cybersecurity professionals in a world of great-power competition- How the next generation should think about cyber, policy, and global riskAbout Inside Cyber MindsInside Cyber Minds is a cybersecurity podcast by Lufsec, featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, and industry leaders. The show focuses on mindset, decision-making, leadership pressure, and the human side of cybersecurity.Watch & Listen▶️ YouTube: https://youtube.com/@Lufsec🔗 Listen on your favorite platform🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🎤 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640LinkedIn → https://www.linkedin.com/company/lufsec/Dmitri:Book: https://www.amazon.com/World-Brink-America-Twenty-First-Century/dp/1541704096/Podcast: https://podcast.silverado.org/Social: @DAlperovitch

About

Step inside the minds of cybersecurity leaders. Hosted by Luciano Ferrari, Inside Cyber Minds explores how professionals in security think, lead, and keep learning in an industry that never slows down. Each episode dives into honest conversations about growth, imposter syndrome, leadership, and the human side of cybersecurity — reminding us that even the experts are still figuring it out. 🎙️ Part of the Lufsec Podcast series. 🧠 Conversations that shape security.