Security by Default

Joseph Carson

Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

  1. Why Identity Is Becoming Every CISO's Biggest Challenge | Vlad Shapiro

    3d ago

    Why Identity Is Becoming Every CISO's Biggest Challenge | Vlad Shapiro

    Vlad Shapiro, a distinguished mathematician turned identity management expert, articulates his transformative journey in this episode, offering profound insights into the intersection of identity and business. He elucidates how the realm of identity has evolved into a critical pillar for organizational functionality, emphasizing that without effective identity management, business operations may falter. Our discussion delves into the implications of this evolution, particularly the necessity for board members to prioritize identity governance alongside traditional business strategies. Furthermore, we explore the pressing gaps within the current identity landscape, including the challenges posed by a lack of standardization and the imperative for innovative thinking to navigate an increasingly complex digital environment. Shapiro's reflections not only highlight the significance of identity management in contemporary business but also underscore the need for a collaborative approach that integrates technological advancements with ethical considerations for future generations. In this episode of the Security by Default podcast, host Joe Carson engages with Vladislav Shapiro, who shares his journey from a mathematician to an identity management expert. They discuss the evolution of identity management, its growing importance in business, and the innovations shaping the future of identity technology. The conversation emphasizes the need for a business-oriented approach to identity, the gaps in current practices, and the ethical considerations in technology development. In this conversation, Joseph Carson and Vladislav Shapiro explore the complexities of AI governance, drawing parallels with nuclear energy management. They discuss the importance of control mechanisms, the role of identity in AI, and the emerging threats related to computational workload theft. The conversation emphasizes the need for continuous learning in a rapidly evolving technological landscape and the significance of visibility in understanding both good and bad actors in the AI space. The dialogue between Joe Carson and Vlad Shapiro unfolds a captivating narrative that chronicles Vlad's evolution from an accomplished mathematician to a distinguished identity management expert. Vlad's journey is steeped in serendipity and introspection, illustrating the transformative power of career shifts propelled by the dynamics of professional landscapes and personal revelations. As he delves into his past, Vlad reflects on his academic pursuits in Ukraine and his subsequent migration to the United States, where he initially aspired to teach mathematics at a university level. However, as he navigated the academic landscape and its stark contrasts to European standards, he pivoted towards industry, seeking avenues to apply his analytical skills in a pragmatic context. The discussion transitions into a broader exploration of the identity management sector, a field that has burgeoned in significance over recent years. Vlad articulates the paradigm shift that identity management has undergone, now recognized as a critical business function rather than merely an IT concern. The conversation delves into the intricacies of identity governance, emphasizing the need for organizations to reconsider how they manage identity in a world increasingly reliant on digital interactions. Vlad's insights on the intersection of identity management and business strategy underscore the imperative for organizations to engage with this evolving landscape, reflecting on how identity impacts operational efficiency and risk management. As the episode progresses, Vlad shares his perspectives on contemporary challenges within the identity management domain, notably the importance of interoperability among diverse systems and the necessity for organizations to adapt to a rapidly evolving technological environment. His reflections on the ethical dimensions of identity management, particularly concerning data privacy and consumer trust, resonate deeply within the ongoing discourse surrounding digital identities. This episode serves as a profound reminder of the critical role that identity management plays in shaping secure and efficient organizational practices, and it encapsulates the wisdom gleaned from Vlad's unique journey through the realms of mathematics and identity management. Takeaways: Vlad Shapiro's transition from a trained mathematician to an identity management expert showcases the fluidity of career paths in the technology sector.The evolution of identity management has transformed it into a critical business function, emphasizing its integral role in organizational security and efficiency.Understanding identity as a business imperative rather than merely a technical challenge is essential for engaging stakeholders and achieving strategic alignment.The importance of fostering a culture of curiosity and continuous learning is paramount in the ever-evolving landscape of identity management and cybersecurity.Innovations in identity management must prioritize interoperability to ensure seamless integration across diverse systems and platforms.The conversation around identity management now encompasses ethical considerations, prompting a reevaluation of policies to mitigate risks associated with technological advancements.

    44 min
  2. How Hackers Attack AI: The New Battle to Secure Intelligent Machines | Harriet Farlow

    Jun 9

    How Hackers Attack AI: The New Battle to Secure Intelligent Machines | Harriet Farlow

    This podcast episode delves into the intricate nexus of artificial intelligence and security, featuring an enlightening conversation with Harriet, the author of a newly released book Practical AI Security. We explore her compelling journey from a background in physics and anthropology to becoming a pivotal figure in the realm of cybersecurity, particularly focusing on the challenges posed by adversarial machine learning. Harriet elucidates the pressing necessity for organizations to comprehend and mitigate the security vulnerabilities inherent in AI systems, as well as the broader implications for national security. Our discourse also addresses the critical need for collaboration between cybersecurity professionals and AI developers to ensure that security considerations are embedded within AI design from the outset. Ultimately, we aim to provide our audience with a profound understanding of the evolving landscape of AI security and the imperative of safeguarding these transformative technologies. 🎙️ Security by Default PodcastPractical AI Security: Attacking, Defending, and Securing the Future of AIWith Harriet Farlow — Founder of Mileva Security Labs & Author of Practical AI Security Artificial Intelligence is transforming the way we build technology, automate decisions, analyze data, and solve some of the world’s biggest challenges. But as AI becomes more powerful and more deeply embedded into our lives, one critical question becomes increasingly important: How do we secure AI itself? In this episode of Security by Default, host Joseph Carson is joined by Harriet Farlow, AI security researcher, founder of Mileva Security Labs, and author of “Practical AI Security: A Hands-On Guide to Attacking, Defending, and Securing Modern AI Systems.” Together they explore the rapidly evolving world of AI security, adversarial machine learning, and why understanding how AI works is essential before we can protect it. About This EpisodeAI is often described as the next technological revolution, but securing AI requires us to rethink many traditional cybersecurity approaches. Unlike conventional software, AI systems are built on data, probability, optimization, and learning models. They do not always fail in predictable ways, and vulnerabilities are not always solved with a simple patch. Harriet shares her fascinating journey from studying physics and anthropology to working in data science, national security, and artificial intelligence, eventually discovering the world of adversarial machine learning — where attackers attempt to manipulate and disrupt AI systems themselves. This conversation goes beyond the hype and explores what defenders, developers, and organizations need to understand as AI becomes a critical part of modern technology. What You Will Learn🤖 Why AI Security Matters More Than Ever AI is becoming part of software development, business operations, healthcare, finance, critical infrastructure, and cybersecurity itself. As adoption accelerates, organizations must move beyond simply asking: “How can we use AI?” and start asking: “How do we secure AI?” 🧠 Understanding How AI Really Works Harriet explains why machine learning systems are fundamentally different from traditional software. AI systems are: Probabilistic rather than deterministicDependent on training data qualityDesigned around optimizationContinuously influenced by changing environments Understanding these foundations is essential for anyone responsible for protecting AI. 🔓 The World of Adversarial Machine Learning What happens when attackers stop targeting only applications and infrastructure… …and start targeting the AI model itself? The episode explores: Model manipulationData poisoningAI weaknessesTraining challengesUnexpected behaviorsThe difficulty of understanding model decisions 🛠️ How Do You Patch AI? One of the biggest questions facing cybersecurity professionals today: If AI learns something wrong, how do we fix it? Traditional security follows a familiar process: Find vulnerability → Apply patch → Reduce risk AI changes that. Sometimes protecting AI is not about fixing code. It is about understanding and correcting behavior. ⚔️ AI for Security vs Security for AI For years, organizations have focused on using AI to improve cybersecurity. But now the challenge has expanded. Cybersecurity needs AI. But AI also needs cybersecurity. As AI becomes part of everyday systems, security teams must understand how to protect the models, data, and decisions that organizations rely on. 🌍 Why AI Security Requires Different Skills The future of AI security requires collaboration between: Cybersecurity professionalsAI engineersData scientistsResearchersRisk leadersPolicy experts Building trustworthy AI means bringing these worlds together. Security must be part of AI from the beginning. Key Topics Discussed🔹 Harriet’s journey from physics and anthropology into AI security 🔹 Working in data science and national security environments 🔹 Discovering adversarial machine learning 🔹 Founding Mileva Security Labs 🔹 Writing Practical AI Security with No Starch Press 🔹 Why AI vulnerabilities are different from software vulnerabilities 🔹 The importance of data quality and model training 🔹 Understanding probability and machine learning foundations 🔹 How attackers target AI systems 🔹 Why securing AI requires a new mindset 🔹 The future of AI safety and cybersecurity 🔹 Staying updated in a fast-moving industry 🔹 Building responsible and secure AI systems Memorable Quotes💬 “Before we can secure AI, we first need to understand how it works.” 💬 “AI security is not always about fixing a bug. Sometimes it is about correcting a behavior.” 💬 “Cybersecurity needs AI, but AI also needs cybersecurity.” 💬 “The future is not just about building smarter AI — it is about building safer AI.” Episode Chapters00:00 – Introduction to Security by Default 01:03 – Harriet Farlow’s origin story 04:28 – From data science to cybersecurity 08:48 – Creating Mileva Security Labs 10:51 – Conferences, community, and writing Practical AI Security 17:28 – How AI has evolved 19:43 – Understanding machine learning models 21:43 – The challenge of patching AI systems 23:37 – Training data, quality, and user impact 25:23 – Why AI models can be difficult to understand 27:36 – AI and cybersecurity coming together 30:18 – Why AI fundamentals matter 32:04 – Practical examples and real-world AI security 33:38 – Staying updated in AI security 36:27 – Learning from the AI security community 38:08 – Ethics and responsible AI development GuestHarriet Farlow Founder — Malevra Security Labs Author — Practical AI Security 🔗 LinkedIn: https://www.linkedin.com/in/harriet-farlow-654963b7/ 📘 Practical AI Security — No Starch Press https://nostarch.com 🎓 AI Fundamentals Course https://harriethacks.com/course/ Listen & Subscribe🎧 Security by Default Podcast Exploring the people, stories, and ideas helping make technology safer. Because security should not be an afterthought. Security should be by default. #SecurityByDefault #AISecurity #Cybersecurity #ArtificialIntelligence #MachineLearning #AdversarialML #AI #ResponsibleAI #SecurityResearch Takeaways: The podcast episode discusses the importance of understanding AI security in the context of national security and its implications.Harriet's journey from a background in physics and anthropology to her current role in AI security demonstrates the interdisciplinary nature of the field.The conversation highlights the necessity for collaboration between AI developers and cybersecurity professionals to ensure secure AI systems.Listeners are encouraged to engage with various resources to stay informed about the rapidly evolving landscape of AI and cybersecurity.The significance of addressing the ethical considerations in AI development is emphasized throughout the discussion, focusing on empowering rather than replacing human effort.The episode underscores the idea that AI security is not merely about using AI for cybersecurity but also about securing AI systems from external threats.

    43 min
  3. AI Is Not Magic: The Truth Behind the Technology Changing Everything | Diana Kelley

    May 26

    AI Is Not Magic: The Truth Behind the Technology Changing Everything | Diana Kelley

    This podcast episode elucidates the evolution of artificial intelligence, particularly focusing on the transition from earlier models such as ELIZA and Watson to contemporary systems like ChatGPT and Claude. Our discussion emphasizes the importance of understanding the context and limitations of AI, as well as the implications of its rapid advancement on our professional landscape. We delve into the nuances of prompt engineering and the necessity of training AI models to interpret context effectively, which has become increasingly pivotal in their application. Furthermore, we address the societal concerns regarding job displacement in the wake of AI proliferation, positing that while certain roles may be rendered obsolete, new opportunities will arise, necessitating continuous adaptation and retraining. Ultimately, our dialogue aims to provide clarity amidst the complexities of AI technology, underscoring the imperative for informed engagement with these transformative tools. In this episode of the Security by Default podcast, host Joe Carson welcomes Diana Kelley, a prominent figure in the tech industry, to discuss her journey in technology, the evolution of AI, and its implications for cybersecurity and the job market. They explore the historical context of AI, from early systems like ELIZA to modern advancements like Watson and ChatGPT, and address common misconceptions about AI's capabilities. The conversation also delves into the future of jobs in an AI-driven world, emphasizing the need for training and understanding of AI technologies. In this conversation, Joseph Carson and Diana Kelley discuss the evolution of jobs in the context of technological advancements, particularly focusing on AI and its implications for the workforce. They explore the necessity of continuous retraining and the emergence of new roles, the importance of contextual understanding in AI, and the behavior of AI agents. Additionally, they emphasize the need for control mechanisms in AI development and the importance of empowering women in cybersecurity to address the growing challenges in the field. Takeaways The podcast aims to bring clarity and transparency to the chaos in the tech world.Diana Kelley has a rich history in technology, starting from the DARPAnet in the 1970s.ELIZA was one of the first AI systems, designed to emulate a therapist.Watson's success in Jeopardy was due to its speed, not intelligence.AI's interaction with humans can lead to misconceptions about its capabilities.Chain of thought prompting has improved AI's problem-solving abilities.AI is a probability machine, not a sentient being.Training is essential for effective AI usage.The evolution of AI has implications for job security and creation.Legacy systems still require human oversight and expertise. The jobs we have today are constantly evolving due to technology.Retraining is essential to stay relevant in the workforce.AI will create new job opportunities in various fields.Understanding context is crucial for effective AI interaction.Prompt engineering is a vital skill in working with AI models.Control mechanisms are necessary for managing AI behavior.Empowering women in cybersecurity is critical for the industry's future.Community support is essential for fostering diversity in tech.Continuous learning is key to adapting to technological changes.Networking and mentorship play a significant role in career development. Chapters 00:00 Introduction to the Podcast and Guest 01:01 Diana Kelley's Journey in Tech 04:56 The Evolution of AI: From ELIZA to Watson 10:14 AI in Cybersecurity: Training Watson for Cyber 14:03 Understanding AI: Human-like Interaction and Misconceptions 16:33 Advancements in AI: Chain of Thought Prompting 20:11 The Future of Jobs in the Age of AI 21:20 The Evolution of Jobs and Skills 23:51 AI and Human Interaction 27:06 Contextual Understanding in AI 29:56 Agent Behavior and Control 32:58 Staying Informed in a Rapidly Changing Field 36:07 Empowering Women in Cybersecurity Resources & Links: ELIZA - Joseph Weizenbaum's AI ProgramDiana Kelley - LinkedInOWASP GenAI ProjectWomen in Cybersecurity (WiCyS)IBM WatsonOpenAI GPT ModelsAnthropic's Claude Connect with Diana Kelley: LinkedIn Enjoy this insightful conversation on the past, present, and future of AI and cybersecurity, highlighting the balance between innovation and responsible deployment. The discourse conducted in the latest installment of the Security By Default podcast presents a profound exploration of the evolution of artificial intelligence (AI) and its consequential implications within the cybersecurity domain. The host, Joe Carson, alongside esteemed guest Diana Kelly, embarks on a reflective journey that traverses the historical underpinnings of AI, commencing with early innovations such as the DARPA Net and the pioneering chatbot Eliza, which simulated therapeutic conversation. As the conversation unfolds, they elucidate the transformative journey of AI from rudimentary systems to contemporary models like IBM's Watson and emergent generative AI technologies. The dialogue is rich with insights on how these advancements not only augment human capabilities but also necessitate a reevaluation of cybersecurity protocols, particularly in the context of AI's dual potential for both beneficial applications and nefarious exploits. Through this enlightening exchange, the episode instills a nuanced understanding of the need for responsible AI usage, emphasizing the importance of training and ethical considerations in the burgeoning field of AI-driven technologies. Takeaways: In this episode, we explore the evolution of AI technologies from early models like Eliza to modern systems such as Claude and ChatGPT, discussing their implications and societal impacts.The podcast emphasizes the importance of understanding the context in which AI operates, highlighting that these models do not possess true intelligence or decision-making capabilities.We address the urgency of educating users about responsible AI use, advocating for training requirements that ensure individuals comprehend the limitations and potential risks associated with these technologies.The discussion includes insights on the future of the workforce, particularly on how AI may transform job roles while also creating new opportunities for skilled professionals.We reflect on the historical significance of AI advancements, illustrating how past innovations inform our current understanding and utilization of machine learning algorithms.The episode concludes with a call to action for listeners to engage with AI thoughtfully, encouraging them to remain informed and proactive in adapting to the rapidly changing technological landscape.

    37 min
  4. Why Cybersecurity Fails Without Trust: The Human Side of Defense | JC Vega

    May 12

    Why Cybersecurity Fails Without Trust: The Human Side of Defense | JC Vega

    This podcast episode elucidates the critical importance of effective communication and leadership within the realm of cybersecurity. We engage in a profound discussion with JC Vega, who shares his extensive background in both operational security and cybersecurity, emphasizing the necessity of translating complex technical concepts into relatable business language. We explore the pivotal role of leaders in fostering a secure organizational environment, underscoring that cybersecurity is not merely an IT concern, but an enterprise-wide imperative that encompasses every facet of an organization's operations. The conversation further delves into strategies for empowering champions within organizations to advocate for security practices, thus ensuring that everyone understands the significance of their roles in safeguarding the enterprise. Ultimately, we aspire to convey that a collaborative, informed approach is essential in navigating the complexities of today's security landscape, thereby enhancing both individual and organizational resilience. In this episode, cybersecurity expert JC Vega shares insights on effective communication, leadership, and risk management in cybersecurity. He emphasizes the importance of translating technical concepts for business leaders, building trust, and fostering community to enhance organizational resilience. keywords cybersecurity, leadership, risk management, communication, trust, community, organizational resilience, cybersecurity education keytopics Translating cybersecurity for non-technical audiencesBuilding champions within organizationsThe importance of trust and verification in securityCybersecurity as an enterprise survival issueLeveraging AI and technology responsibly sound bites "Validate and verify, don't just trust." "Train like it's a Super Bowl." "Leave a link, build a community." Chapters 00:00 Introduction to Cybersecurity Leadership 02:34 Translating Cybersecurity for Non-Technical Audiences 05:13 Building a Team of Champions 08:02 Understanding Business Impact and Risk 10:39 The Role of AI in Cybersecurity 12:58 Cybersecurity as an Enterprise Survival Problem 15:21 The Importance of Ecosystem Relationships 18:00 Trust and Zero Trust in Cybersecurity 20:28 Continuous Learning and Community Engagement resources Cyber Cannon Project - https://cybercannonproject.org/ B-Sides Conferences - https://www.bsidescon.org/ LinkedIn Profile of JC Vega - https://www.linkedin.com/in/jcvega/ Takeaways: The podcast emphasizes the necessity of translating complex cybersecurity concepts into practical business language for effective communication.I believe that strong relationships with champions within organizations are crucial for cybersecurity success and operational resilience.Our discussion highlights the importance of understanding the operational goals of various stakeholders to better address their cybersecurity needs.We advocate for the continuous evolution of skills and knowledge within the cybersecurity field through collaboration and community engagement.

    37 min
  5. Can AI Beat Hackers? The Future of Cyber Training Has Changed | Hack The Box

    Apr 28

    Can AI Beat Hackers? The Future of Cyber Training Has Changed | Hack The Box

    The eminent discourse of this podcast episode delves into the pivotal role of artificial intelligence in the contemporary cybersecurity landscape, underscoring the symbiotic relationship between AI and human expertise. I, Joseph Carson, engage in a compelling conversation with Gerasmus, a distinguished figure from Hack the Box, as we explore the transformative impact of AI on both offensive and defensive cybersecurity strategies. Our dialogue illuminates the necessity for practitioners to adapt and evolve their skill sets in tandem with rapid technological advancements, highlighting the significance of platforms such as Hack the Box in fostering a culture of continuous learning and practical application. We further examine the implications of AI governance and the emergence of agentic AI as a potential risk factor, urging a meticulous approach to data management and security protocols. Ultimately, this episode serves as a clarion call for cybersecurity professionals to embrace innovation while preserving the essential human element in safeguarding digital infrastructures. In this special edition recorded live at RSA Conference, Joseph Carson is joined by Gerasimos Marketos (gmar), Chief Product Officer at Hack The Box. They explore how AI is reshaping cybersecurity skills, why traditional education is struggling to keep up, and how hands-on platforms are redefining how defenders and ethical hackers are trained. From real-world fraud detection to AI-powered CTF competitions, this episode dives into the evolving relationship between humans and machines in cybersecurity. 🔑 Key Themes & Topics AI vs Humans in cybersecurity competitionsWhy AI is an accelerator, not a replacementThe evolution from traditional training → hands-on gamified learningClosing the cybersecurity skills gapRed, Blue, and Purple team upskillingAI governance, risk, and agentic threatsThe future of cybersecurity careers and hiring ⏱️ Chapters 00:00 – Introduction & RSA Conference insights02:00 – GMar’s journey: Data → Fraud → Cybersecurity06:30 – Who and What is Hack The Box?10:30 – AI vs Humans: CTF research findings13:00 – AI as a productivity multiplier15:30 – Real-world example: AI winning competitions16:00 – RSAC trends: AI everywhere17:00 – AI governance & emerging risks18:00 – AI for security vs security for AI19:00 – Staying relevant in cybersecurity 🚀 Hack The Box Explained Hack The Box is a cybersecurity upskilling platform offering: 🎓 Academy – Structured learning paths🧩 Challenges & Labs – Hands-on environments🏁 CTFs (Capture The Flag) – Competitive exercises🏢 Pro Labs – Enterprise-scale simulations🔎 Talent Search – Connecting skilled professionals with employers It supports: Red Teams (Offense)Blue Teams (Defense)Purple Teams (Collaboration) Resources: https://www.hackthebox.com/ https://www.linkedin.com/in/gmarketos/ https://www.hackthebox.com/ai-augmented-cyber-workforce-report Takeaways: In our latest episode, we explored the symbiotic relationship between artificial intelligence and cybersecurity, highlighting their mutual dependence.The insights gathered from the RCC conference emphasize the necessity of integrating AI to enhance cybersecurity measures effectively.We discussed the evolution of Hack the Box, illustrating its transition from a challenge-based platform to a comprehensive cybersecurity training ecosystem.The significance of continuous learning in cybersecurity was underscored, particularly in light of rapidly advancing AI technologies and their implications.We examined the results of our recent CTF events, showcasing how AI agents can enhance human capabilities in cybersecurity tasks and competitions.Lastly, we asserted the importance of maintaining foundational skills in cybersecurity, even as AI tools become increasingly prevalent in the industry. Links referenced in this episode: hackthebox.com Companies mentioned in this episode: SeguraHack the Box

    20 min
  6. Behind the Scenes: How Cybersecurity Decisions Really Get Made | Fernando Montenegro

    Apr 14

    Behind the Scenes: How Cybersecurity Decisions Really Get Made | Fernando Montenegro

    Fernando Montenegro, a distinguished industry analyst in cybersecurity, articulates the pivotal best practices that analysts should adopt to navigate the complexities of the cybersecurity landscape effectively. Throughout our discourse, he elucidates the necessity for analysts to function as intermediaries among various stakeholders, including buyers, sellers, and investors, thus facilitating informed decision-making processes. Montenegro emphasizes the importance of clarity in communication, advocating for an open-minded approach during analyst interactions to maximize the value derived from these engagements. He further discusses the strategic implications of cybersecurity decisions, urging organizations to appreciate the multifaceted influences that shape their security postures. Ultimately, this episode serves as an invaluable resource for professionals seeking to enhance their analytical practices within the rapidly evolving cybersecurity domain. In this episode, Fernando Montenegro shares his journey into the cybersecurity industry, insights on industry analysis, and the evolving trends shaping cybersecurity today. Discover how analysts bridge the gap between vendors, buyers, investors, and academia, and learn practical tips for engaging effectively with industry experts. key Takeaways Role of industry analysts in cybersecurityEmerging trends in cybersecurity including AI and attack surface expansionEffective engagement with analysts for decision supportStrategic cybersecurity budgeting and investmentInfluence of economics and incentives on security decisions sound bites "Understanding what's going on in the world" "Good enough security can be effective" "Workload AI versus workforce AI" Chapters 00:00 Introduction to Security by Default Podcast 00:53 Fernando Montenegro's Origin Story 05:16 The Role of an Industry Analyst 08:55 Maximizing Value from Analyst Interactions 13:16 Understanding AI in Conversations 15:44 Choosing the Right Solutions 16:40 Decision-Making in Technology and Business 17:13 Trends in Cybersecurity and AI 18:26 Understanding Workload vs. Workforce AI 19:40 The Evolving Role of Security Professionals 21:43 The Strategic Importance of Cybersecurity 23:58 Incentives and Decision-Making in Security 25:53 The Shift Left Approach in Development 27:16 Budgeting for Cybersecurity Investments 30:47 Navigating Cybersecurity Budgets 32:26 Engaging with Analysts and Staying Informed 34:33 Curating Information in a Data-Driven World 36:55 Balancing Operational and Strategic Insights 37:51 Connecting with Analysts and Final Thoughts Resources LinkedIn Profile of Fernando Montenegro - https://www.linkedin.com/in/fsmontenegro/ Futurum Group - https://futurumgroup.com/ Obsidian Knowledge Management System - https://obsidian.md/ Book: Why Most Security Budgets Go to Waste by Ross Young - https://a.co/d/02BZPwdO In this thought-provoking episode, Fernando Montenegro imparts his extensive expertise on the best practices for analysts within the cybersecurity industry. He begins by delineating the multifaceted role of an analyst, which encompasses serving as a conduit for communication between buyers, sellers, investors, and other relevant stakeholders. By elucidating the distinct motivations and concerns of each group, Fernando illustrates how analysts can effectively tailor their insights and recommendations, thereby enhancing the decision-making process for all parties involved. The dialogue further explores the significance of maintaining an open-minded approach during analyst interactions, as well as the necessity for analysts to remain well-informed about emerging trends and challenges in the cybersecurity landscape. Fernando identifies several pivotal trends, including the integration of artificial intelligence, the expansion of the attack surface, and the transition towards a more resilient approach to data protection. Each of these trends reflects the evolving priorities of organizations as they seek to mitigate risks and enhance their security postures. Through this episode, listeners are not only provided with actionable insights into the workings of an industry analyst but are also encouraged to consider the broader implications of their roles in shaping cybersecurity strategies. As Fernando articulates, the responsibility of analysts extends beyond mere data analysis; they must also facilitate meaningful dialogue among stakeholders to drive informed decisions that bolster organizational security in an increasingly complex digital landscape.

    41 min
  7. Can We Make Cybersecurity Fun Again? Turning Fear Into Action | Gary Berman

    Mar 31

    Can We Make Cybersecurity Fun Again? Turning Fear Into Action | Gary Berman

    This podcast episode delves into the imperative of transforming the often daunting landscape of cybersecurity into a realm of engagement and enjoyment. I, Joe Carson, alongside my esteemed guest Gary, explore how the prevailing culture of fear, uncertainty, and doubt (FUD) can be supplanted by a more vibrant and playful approach. We discuss the significance of fostering a sense of community and support within the cybersecurity field, emphasizing the need to celebrate successes and share positive narratives that can inspire both professionals and newcomers alike. The conversation further highlights innovative methods such as gamification and the incorporation of storytelling to make cybersecurity training more accessible and enjoyable. Ultimately, we aim to ignite a movement that not only safeguards our digital environments but also rekindles the joy and creativity that can be found within this vital industry. Join cybersecurity expert Joseph Carson and guest Gary as they explore innovative ways to make cybersecurity engaging, fun, and accessible. Discover how humor, storytelling, and community involvement can transform the industry and attract new talent. Chapters 00:00 Welcome to the Cybersecurity Chaos 02:32 From Fear to Fun in Cybersecurity 05:27 The Journey of a Cyber Advocate 08:09 The Importance of Community and Collaboration 10:45 Bringing Laughter Back to Cybersecurity 13:13 Rebranding Cybersecurity for New Talent 16:00 The Power of Words in Cybersecurity 18:43 Innovative Approaches to Cyber Awareness 21:29 Lessons from Kids: Simplifying Cybersecurity 24:39 The Inner Child and Cognitive Dissonance 26:40 Gamification and Learning Innovations 28:19 Storytelling in Cybersecurity 29:15 Cybersecurity Starts at Home 30:36 Community Engagement and Employee Connection 32:14 The Importance of Acknowledgment 34:13 Finding Joy in Everyday Life 35:11 Humor as a Coping Mechanism 40:04 The Power of Positive Thinking 45:02 Mission Accomplished: Fun and Safety Resources Cyber Heroes Comics - https://cyberheroescomics.com/ Gary's LinkedIn Profile - https://www.linkedin.com/in/gary-berman/ The discourse presented in this episode unveils the intricate relationship between cybersecurity and the often overwhelming sense of fear, uncertainty, and doubt (FUD) that pervades the industry. I, Joe Carson, alongside our distinguished guest Gary, delve into the necessity of transforming the cybersecurity narrative from one steeped in anxiety to a more palatable and enjoyable experience. Gary, who identifies himself as the 'Forrest Gump of cybersecurity,' shares his unique journey into this field, characterized by serendipitous encounters with influential figures and organizations. His advocacy for making cybersecurity engaging is pivotal; he emphasizes the importance of humor and creativity in addressing serious issues that often deter potential talent from entering the field. This conversation highlights the vital need to celebrate successes and communicate effectively, ensuring that cybersecurity is perceived not merely as a defensive measure but as an exciting and essential component of modern society. As our discussion unfolds, we explore the concept of gamification in cybersecurity training, an innovative approach aimed at enhancing engagement and retention of critical security practices. We reflect on the common tendency to focus predominantly on the negative aspects of cybersecurity incidents, neglecting the positive outcomes and triumphs that deserve recognition. By employing storytelling techniques and leveraging humor, we can reshape the perception of cybersecurity, making it accessible and relatable to a broader audience. The episode culminates in a call to action for industry professionals to foster a culture of positivity and collaboration, thereby transforming the cybersecurity landscape into one that is not only secure but also inviting and enjoyable for all. In conclusion, this episode serves as a clarion call for change within the cybersecurity domain. We advocate for the rebranding of cybersecurity from an intimidating realm to one that is engaging, fun, and inclusive. By embracing creativity and humor, we can attract new talent and invigorate the existing workforce, ensuring a robust defense against the ever-evolving landscape of cyber threats. Join us as we embark on this journey of transformation, aiming to illuminate the path ahead in the fascinating world of cybersecurity, where safety and enjoyment can coexist harmoniously. Takeaways: The podcast emphasizes the necessity of transforming the often fear-driven narrative surrounding cybersecurity into something more engaging and enjoyable for audiences.Through humor and storytelling, we can effectively communicate complex cybersecurity concepts, making them accessible to a broader audience, including children and families.The discussion highlights the importance of celebrating successes within cybersecurity, as these achievements often go unrecognized, leading to a narrative dominated by fear and negativity.The idea of rebranding cybersecurity as a fun and engaging field is critical for attracting new talent, especially in an era where other industries appear more appealing and entertaining.

    47 min
  8. Inside Modern Cyber Warfare: The Invisible Battles Happening Every Day | Chris Kubecka

    Mar 17

    Inside Modern Cyber Warfare: The Invisible Battles Happening Every Day | Chris Kubecka

    This podcast episode delves into the intricate interplay between global politics, cybersecurity, and the evolving nature of threats faced by critical infrastructure. Our esteemed guest, Chris, shares his compelling journey from early experiences with technology to significant roles in safeguarding vital systems against sophisticated cyber threats. Notably, the discussion illuminates the transformation of cyber warfare, highlighting the emergence of physical attacks that disrupt both digital and physical infrastructures. We also examine collaborative efforts among nations to fortify defenses against such challenges, emphasizing the necessity of cooperation in the face of rising geopolitical tensions. As we navigate this complex digital landscape, it becomes increasingly apparent that a unified approach is paramount to ensuring our collective security and resilience in an interconnected world. Join Joseph Carson in this insightful episode as he interviews cybersecurity expert Chris Kubecka. They discuss critical infrastructure security, cyber warfare, geopolitical risks, and the evolving landscape of digital threats, providing valuable lessons for cybersecurity professionals and policymakers. Key Topics Cybersecurity in critical infrastructure Geopolitical cyber threats and hybrid warfare Evolving landscape of digital threats and resilience Sound bites "GPS jamming has been a massive challenge." "Digital Empires: China, Europe, and the US." "Radio communications are a vital fallback." Chapters 00:00 Introduction and Background of Chris Kubecka01:37 Cybersecurity Challenges in Critical Infrastructure03:37 Evolving Nature of Cyber Threats05:45 The Role of Drones in Modern Warfare07:25 Hybrid Warfare and Global Diplomacy10:10 The Shift in Global Cybersecurity Dynamics12:18 The Importance of International Cooperation14:33 Privacy and Ethics in Cybersecurity16:50 Historical Context and Regional Cooperation18:55 Cyber Attacks on Civilian Infrastructure22:04 Personal Experiences in Estonia24:10 Geopolitical Tensions and Cybersecurity25:52 Challenges in Maritime Connectivity28:16 Critical Infrastructure Vulnerabilities30:22 The Role of Radio in Authoritarian Regimes33:43 International Maritime Law and Cybersecurity37:46 Recent Projects and Activism in Cybersecurity39:51 Staying Informed in a Rapidly Changing Landscape Resources Chris Kubecka's LinkedIn - https://www.linkedin.com/in/chriskubecka/ Field Tested: How to Hack a Modern Dictatorship with AI - https://www.amazon.com/dp/B0C7F4XYZ

    45 min

About

Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.