STATUS: SECURE – The Cyber Threat Briefing

WatchUr6 - Cybersecurity

You cannot be secure if you do not know the threat. On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy. Welcome to Status: Secure, the weekly cyber threat briefing for executives who refuse to operate in the blind. Hosted by the WatchUr6 collective, this show unites the battlefield with the boardroom. Featuring former Army Special Forces and Naval Special Warfare communications operators alongside an industry-leading CISO nominated for Cybersecurity Woman of the World. Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure. The enemy is listening. Is your status secure?

  1. 4d ago

    035 Coca-Cola's Fairlife Ransomware, Nike's 1.4TB Leak, and the Rise of Extortion Without Encryption

    One attack stopped milk production at four plants. The other took 1.4 terabytes out of Nike and never encrypted a single file. This week we break down two of the biggest cyber events of 2026, and they failed in completely opposite directions. Coca-Cola's fairlife subsidiary lost its production systems to the Anubis ransomware group and chose not to negotiate. Nike lost product designs, supplier lists, and pricing to WorldLeaks — a group that has largely abandoned encryption entirely, because there is nothing to restore when nothing was locked. What connects them is uncomfortable. In both cases, what got taken was not what the security program was pointed at. Intel Declassified in this Briefing: [01:03] The Bottling Line: Why compromising manufacturing control systems is a different kind of attack than a records breach.[04:12] Pay or Don't Pay: The calculation behind Coca-Cola's decision not to negotiate, and the eleven days to resumed production.[05:37] Why Canada Kept Running: Network isolation as the difference between a regional outage and a continental one.[07:31] What Did They Steal Then: Our CISO's unfiltered reaction to Nike's statement that no personal data was involved.[09:21] Nothing to Restore: Why your backup strategy is irrelevant against extortion without encryption.[12:23] 241 Days: The average dwell time, and why moving terabytes is months of quiet work through a third-party supplier.[14:28] Crown Jewels: Why most companies secure what the auditor asks about instead of what would actually hurt to lose.[17:14] Materiality: If you don't define it, the regulator will — and their definition will not be generous. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/035-fairlife-ransomware-nike-leak-extortion-without-encryption/Read the Associated Sitrep: Extortion Without Encryption - The Tabletop Your Ransomware Plan Is Missing: https://watchur6.com/sitrep/mission-resilience/extortion-without-encryption-tabletop/

  2. Sep 29

    034 Physical Security: Badge Cloning, USB Drop Attacks, and HIPAA Physical Safeguards

    A cloned badge gets somebody through the door. An unlocked laptop gets them onto the network. Not one cyber control has to be defeated for that to happen. This week we go the other direction from our usual briefing. Your security awareness training covers phishing and passwords and says nothing about the card hanging around your neck — and that gap is structural, because physical security and cyber security have always lived in different departments. We cover what a badge broadcasts when it leaves the building, how little it costs to clone one, what an attacker does in the twenty minutes after they walk in, and the section of the HIPAA Security Rule most healthcare organizations have never read. Intel Declassified in this Briefing: [01:06] The Training Gap: Why physical security belongs to facilities, and why that means nobody covers it.[03:32] Cloned in Seconds: The reader is on Amazon, MIFARE Classic has been broken since 2008, and one active badge per person is the control that catches it.[05:20] Walking In Beats Breaking In: Why a targeted attacker prefers the front door.[08:28] After Remote Work: How badly the screen-lock habit degraded, and what people leave sitting on their desks.[11:59] The Mailed USB: The FBI warning on FIN7 impersonating HHS and Amazon, and the 2026 pairing of planted devices with fake help desk calls.[16:15] The Parking Lot: A stranger didn't question a man breaking into a car. He offered to help.[20:04] HIPAA Physical Safeguards: Facility access controls, contingency operations, workstation use, and device disposal.[26:43] The Risk You Cannot Transfer: Encryption, badge reconciliation, and why outsourcing your guards does not outsource accountability.Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/034-physical-security-badge-cloning-usb-drop-attacks/Read the Associated Sitrep: Physical Security Awareness Training That Actually Changes Behavior: https://watchur6.com/sitrep/mission-resilience/physical-security-awareness-training/

  3. Sep 22

    033 The Race for an AI Governance Framework: ISO 42001, NIST AI RMF, and How to Choose

    The board wants AI controls. Procurement is writing AI clauses into contracts. And inside most organizations, nobody is sure which framework to commit to. This week we lay out what is actually on the table. ISO 42001, the NIST AI Risk Management Framework, COBIT and the ISACA credentials, and GRAICE — the Global Responsible AI Compliance and Ethics framework from the Global Council for Responsible AI, which our CISO has been working with directly. But the most useful answer in this episode is that the framework is not where you start. You cannot put a standard around something you have not found, and most organizations have no idea how much AI is already running inside software they already bought. Intel Declassified in this Briefing: [01:18] Pressure From Four Directions: The board, the customers, procurement, and the state AI disclosure rules now appearing in contract language.[04:38] ISO 42001: The first AI management system standard, why the ISO 27001 alignment makes it a building block, and why it is the one showing up in contracts.[07:03] NIST AI RMF: Govern, Map, Measure, Manage. Not a certification, and why that still matters for anyone who has never run a risk program.[08:52] COBIT and the ISACA Credentials: Why you cannot adopt COBIT for AI, and how AAISM, AAIA, and AAIR map onto the roles you already have.[11:11] GRAICE: The meta-framework that maps the others together and covers the one thing none of them do — ethics, and the human who has to hold that line.[13:05] Don't Start With the Framework: Inventory, accountable owner, risk register. In that order.[17:58] What Happens When You Just Turn Copilot On: A person can only see so much data. AI sees all of it at once.[23:02] The Marching Orders: Three moves, and why training comes before access. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/033-the-race-for-an-ai-governance-framework/Read the Associated Sitrep: AI Governance Frameworks You Can Implement Today: https://watchur6.com/sitrep/compliance-protocols/ai-governance-frameworks/

  4. Sep 15

    032 McKesson Breached: Voice Phishing, Social Engineering, and Vendor Liability

    No malware. No exploit. No vulnerability to patch. The attackers picked up a phone — and vishing, or voice phishing, walked them straight through single sign-on and into a terabyte of healthcare data. On August 28th, McKesson filed a Form 8-K with the SEC disclosing a cybersecurity incident discovered on August 25th. Then the extortion group ShinyHunters told BleepingComputer how they did it. They called the service desk, impersonated employees, and were given credentials. This week we go one subject all the way down. Because if McKesson is one of your vendors, the liability for that breach is now partly yours — and thousands of healthcare organizations that were never attacked at all will spend the next year notifying patients about it. Intel Declassified in this Briefing: [01:15] The Human Factor: Why our CISO wasn't surprised, and how every breach report has started to read identically.[03:28] One Login, Every System: What single sign-on actually opens, and why the attacker only had to find one account.[05:34] The Bank Comparison: Your bank asks five questions before discussing your account. Your help desk assumes you work there.[08:02] Records Are Not Patients: Why 284 million is being reported wrong, and how the 500-individual threshold decides what you owe.[11:06] The Clock You Inherit: What happens downstream when your Business Associate is breached, and whose name goes on the patient letter.[13:20] The Telephone Game: Health-ISAC warned about this exact playbook. Why the warning never reached the boardroom.[15:46] Pen Test Your Help Desk: The one test that would have caught this, and why organizations refuse to run it.[19:54] If You're Smaller Than McKesson: Why bots and AI mean small is no longer overlooked, and the one low-cost control to start with. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/032-mckesson-breached-voice-phishing-social-engineering-vendor-liability/Read the Associated Sitrep: Help Desk Social Engineering - How to Build a Verification Protocol That Holds: https://watchur6.com/sitrep/threat-intelligence/help-desk-social-engineering/

  5. Sep 8

    031 The Talent Gap, Burnout Culture, and How to Build a High-Performing Security Team

    Tools don't stop attackers. The people running those tools do. Last week we covered how to get security funded. This week is the question that follows it — once you have the budget, how do you build the team that performs? Most companies are hiring for a résumé that doesn't exist. Ten years on every tool, a dozen certifications, all in one person. That posting doesn't produce a shallow candidate pool, it produces zero résumés, because whatever you write in the requirements becomes the filter HR actually runs. Meanwhile the person who could do the job may already be on your payroll. Intel Declassified in this Briefing: [01:00] The Unicorn Requisition: Why the posting you wrote is the reason the seat is still empty.[02:24] Signal vs. Guarantee: Certifications are a signal. What to screen for instead — curiosity, coachability, ownership, and common sense.[04:31] The Operations Advantage: Why upskilling someone who already knows your environment beats hiring a purist who has never carried the operating cost of a control.[06:09] The Tool You're Running at 25%: Buying the platform and skipping the people, and why security tools aren't exempt from the maintenance you demand of everyone else.[08:37] Why They Leave: Burnout and leadership disagreement, the fatigue signals leaders miss, and why blaming security for incidents produces teams that hide problems.[10:48] The Growth Path Trap: One manager, no seat above anyone, and what happens when nobody has the conversation.[16:38] The Honest Minimum: One named accountable security owner at 50 to 60 percent of their role. Small but mighty is not a consolation prize. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/031-how-to-build-a-high-performing-security-team/Read the Associated Sitrep: Your First Security Hire - How to Build a Security Team at a Startup: https://watchur6.com/sitrep/mission-resilience/first-security-hire-startup/

  6. Sep 1

    030 The Trust Deficit, Security Theater, and How to Pitch Security to Non-Technical Leaders

    The best security in the world protects nothing if it never gets funded. In this episode we are covering the one skill that determines whether a security program lives or dies, and it has nothing to do with technology. Most security programs are not killed by an adversary. They are killed in a budget meeting, by a technically flawless brief that nobody in the room could act on. Executives decide in revenue, risk, and reputation. A vulnerability count is denominated in none of them, and it is not their job to learn your language. Intel Declassified in this Briefing: [01:07] The Core Failure: Why a thousand vulnerabilities is true, accurate, and completely useless to a board.[03:13] Three Roles, Not Two: The engineer, the security leader, and the executive nobody remembered to include in the pitch.[07:26] The Translation, Worked: Turning a spend request into a revenue argument that happens to involve equipment.[12:04] Quantify or Lose: Why high, medium, and low are interpretations, and a dollar figure is not.[14:00] Know Where You Sit: The uncomfortable reality that security competes against the revenue-producing core for the same dollar.[17:52] Reconnaissance and the Crying Wolf Problem: Reading your own board, and the reputation that costs more than any rejected budget line.[21:36] Marching Orders: Never brief cold, right-size the ask, become the advisor and not the alarm.[24:03] For the Executives: What to demand from your security team, and why accepting a brief you did not understand is a failure on both sides. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/030-how-to-pitch-security-to-non-technical-leaders/Read the Associated Sitrep: How to Quantify Cyber Risk in Dollars - The Board-Ready Field Guide: https://watchur6.com/sitrep/mission-resilience/how-to-quantify-cyber-risk-in-dollars/

  7. Aug 25

    029 AI-Accelerated Exploits, The KEV Catalog, and a Field Guide to Threat Intelligence Sources

    In this episode we're covering how AI is accelerating the speed at which attackers find and weaponize vulnerabilities — and where you actually go to get reliable threat intelligence without drowning in noise. The defensive problem has changed. It's no longer whether you're aware of your vulnerabilities. It's whether you can prioritize and act faster than an AI-accelerated attacker. The list of flaws is endless, so the real question every organization faces is where to start — and how to know what's genuinely being exploited right now versus what's just theoretical. We break down the CISA KEV catalog as the free anchor most organizations still aren't using, then build the full field guide to threat intelligence sources: the free government sources, the sector ISACs, the open-source platforms, and the commercial feeds — what each is good for, what each costs, and how to layer them on a budget. Then we get into the part nobody talks about: why good intelligence so often dies in the gap between the security team and the leadership that holds the budget. Intel Declassified in this Briefing: [00:32] Why AI is collapsing the window between a vulnerability going public and being weaponized — and why the CrowdStrike outage is a preview of the blast radius.[03:40] The CISA KEV catalog: how to turn an impossible patch backlog into a ranked priority, plus three moves to make this week.[06:54] The field guide — the four categories of threat intelligence sources and what each one actually delivers.[10:29] Signal vs. noise: why one sector-relevant ISAC feed beats ten generic global ones.[16:09] The gap in the perimeter: why security and leadership see the same risk completely differently.[21:34] The marching orders: building a real threat-intelligence capability on a budget. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/029-ai-accelerated-exploits-kev-catalog-threat-intelligence-sources/Read the Associated Sitrep: How to Sell Threat Intelligence to Your CEO — Turning Security Gaps Into Business Language: https://watchur6.com/sitrep/mission-resilience/how-to-sell-threat-intelligence-to-your-ceo/

  8. Aug 18

    028 The Meta Child-Safety Ruling, Ethical AI, and Insider Threats: A Briefing for Both Sides

    This week's briefing comes down to one word: trust. Three stories that look separate and turn out to be the same story. We open with the largest child-safety ruling against a social media company to date — a New Mexico judge ordering Meta to pay an additional $567 million, bringing the total to $942 million, for allowing bad actors to operate on its platform. The judge called Meta a "public nuisance," comparing the platform to a polluting factory. Meta disagrees and is appealing. But the security lesson stands: platform security isn't only about the hackers outside your walls — it's about who you allow to operate inside them. From there, our CISO takes us one layer down into the ethics of AI and the integrity problem — why the "I" in the CIA triad is the security pillar quietly breaking in the AI era, and the four rules that keep an AI system honest so it can't lie to you even by accident. Then the big one: what the historic wave of layoffs means for insider threat. Why most insider incidents involve people already on their way out, why disabling an email address is nowhere near enough, and how a forgotten account can get your cyber-insurance claim denied. And finally, the other side of the briefing — a direct word to anyone who's been laid off about why retaliation turns a grievance into a criminal act, and how to redirect that energy instead. Intel Declassified in this Briefing: [00:32] The Meta child-safety ruling — $567M more, $942M total, and why it's a security story about who operates inside your walls.[03:36] Ethical AI and the integrity problem — the CIA triad and the four rules of trustworthy AI.[08:13] Three moves to keep your platform and AI on the right side of trust — plus the customer-service AI asked how to build a bomb.[12:02] Insider threat and the layoff wave — the three categories of insider risk and the $19.5M price tag.[16:52] The departure window — 245,953 tech layoffs in 2025 and why the 30 days around an exit are the most dangerous.[19:42] Why offboarding fails — the 83% who keep access, and the denied insurance claim.[22:34] A word to the laid off — don't turn a grievance into a criminal act. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/028-meta-child-safety-ruling-ethical-ai-insider-threats/Read the Associated Sitrep: How Trustworthy Is Your AI? A Data Integrity Standard for Your Organization: https://watchur6.com/sitrep/compliance-protocols/how-trustworthy-is-your-ai-data-integrity-standard/

Ratings & Reviews

5
out of 5
2 Ratings

About

You cannot be secure if you do not know the threat. On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy. Welcome to Status: Secure, the weekly cyber threat briefing for executives who refuse to operate in the blind. Hosted by the WatchUr6 collective, this show unites the battlefield with the boardroom. Featuring former Army Special Forces and Naval Special Warfare communications operators alongside an industry-leading CISO nominated for Cybersecurity Woman of the World. Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure. The enemy is listening. Is your status secure?