Security by Default

Joseph Carson

Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

  1. The Analyst's Role in Cybersecurity: Bridging Gaps and Shaping Trends with Fernando

    -3 J

    The Analyst's Role in Cybersecurity: Bridging Gaps and Shaping Trends with Fernando

    In this episode, Fernando Montenegro shares his journey into the cybersecurity industry, insights on industry analysis, and the evolving trends shaping cybersecurity today. Discover how analysts bridge the gap between vendors, buyers, investors, and academia, and learn practical tips for engaging effectively with industry experts. key Takeaways Role of industry analysts in cybersecurityEmerging trends in cybersecurity including AI and attack surface expansionEffective engagement with analysts for decision supportStrategic cybersecurity budgeting and investmentInfluence of economics and incentives on security decisions sound bites "Understanding what's going on in the world" "Good enough security can be effective" "Workload AI versus workforce AI" Chapters 00:00 Introduction to Security by Default Podcast 00:53 Fernando Montenegro's Origin Story 05:16 The Role of an Industry Analyst 08:55 Maximizing Value from Analyst Interactions 13:16 Understanding AI in Conversations 15:44 Choosing the Right Solutions 16:40 Decision-Making in Technology and Business 17:13 Trends in Cybersecurity and AI 18:26 Understanding Workload vs. Workforce AI 19:40 The Evolving Role of Security Professionals 21:43 The Strategic Importance of Cybersecurity 23:58 Incentives and Decision-Making in Security 25:53 The Shift Left Approach in Development 27:16 Budgeting for Cybersecurity Investments 30:47 Navigating Cybersecurity Budgets 32:26 Engaging with Analysts and Staying Informed 34:33 Curating Information in a Data-Driven World 36:55 Balancing Operational and Strategic Insights 37:51 Connecting with Analysts and Final Thoughts Resources LinkedIn Profile of Fernando Montenegro - https://www.linkedin.com/in/fsmontenegro/ Futurum Group - https://futurumgroup.com/ Obsidian Knowledge Management System - https://obsidian.md/ Book: Why Most Security Budgets Go to Waste by Ross Young - https://a.co/d/02BZPwdO

    41 min
  2. Inside the Digital Battlefield: Cybersecurity in Geopolitical Conflicts with Chris Kubecka

    17 MARS

    Inside the Digital Battlefield: Cybersecurity in Geopolitical Conflicts with Chris Kubecka

    Join Joseph Carson in this insightful episode as he interviews cybersecurity expert Chris Kubecka. They discuss critical infrastructure security, cyber warfare, geopolitical risks, and the evolving landscape of digital threats, providing valuable lessons for cybersecurity professionals and policymakers. Key Topics Cybersecurity in critical infrastructure Geopolitical cyber threats and hybrid warfare Evolving landscape of digital threats and resilience Sound bites "GPS jamming has been a massive challenge." "Digital Empires: China, Europe, and the US." "Radio communications are a vital fallback." Chapters 00:00 Introduction and Background of Chris Kubecka01:37 Cybersecurity Challenges in Critical Infrastructure03:37 Evolving Nature of Cyber Threats05:45 The Role of Drones in Modern Warfare07:25 Hybrid Warfare and Global Diplomacy10:10 The Shift in Global Cybersecurity Dynamics12:18 The Importance of International Cooperation14:33 Privacy and Ethics in Cybersecurity16:50 Historical Context and Regional Cooperation18:55 Cyber Attacks on Civilian Infrastructure22:04 Personal Experiences in Estonia24:10 Geopolitical Tensions and Cybersecurity25:52 Challenges in Maritime Connectivity28:16 Critical Infrastructure Vulnerabilities30:22 The Role of Radio in Authoritarian Regimes33:43 International Maritime Law and Cybersecurity37:46 Recent Projects and Activism in Cybersecurity39:51 Staying Informed in a Rapidly Changing Landscape Resources Chris Kubecka's LinkedIn - https://www.linkedin.com/in/chriskubecka/ Field Tested: How to Hack a Modern Dictatorship with AI - https://www.amazon.com/dp/B0C7F4XYZ

    45 min
  3. How Gamification and Community Help Beginners Break Into Cloud and AI Security

    3 MARS

    How Gamification and Community Help Beginners Break Into Cloud and AI Security

    In this episode of the Security by Default podcast, host Joe Carson speaks with Ian Austin, co-founder of Pwned Labs, about his journey in cybersecurity, the evolution of learning in the field, and the challenges of Cloud and AI security. Ian shares insights on transitioning into cybersecurity roles, the importance of community engagement, and the need for continuous learning in an ever-evolving industry. They discuss the significance of gamification in training and the current trends in cloud security, emphasizing the importance of hands-on experience and collaboration. Key Takeaways Ian Austin is a co-founder of Pwned Labs, specializing in cloud and AI security training.His journey in cybersecurity began with help desk roles and evolved into penetration testing.Creating content is a great way to learn and contribute to the community.Cloud security presents unique challenges that require ongoing education and adaptation.Gamification in training enhances engagement but should not overshadow practical learning.Community involvement is crucial for personal and professional growth in cybersecurity.Transitioning into security roles can be done from various backgrounds, including sysadmin and help desk.Continuous learning is essential in the fast-paced cybersecurity landscape.Mentorship can significantly impact career development and confidence.Cloud security is a growing field with increasing demand for skilled professionals. sound bites "Learning is a great way to learn." "Community is a powerful thing." "Cloud is hard to secure." Chapters 00:00 Introduction to the Podcast and Guest 00:40 Ian Austin's Journey in Cybersecurity 06:40 Transitioning into Security Roles 10:54 Evolution of Learning in Cybersecurity 16:19 The Importance of Community in Learning 22:58 Challenges in Cloud Security 28:46 Staying Updated in the Cybersecurity Field Resources: https://pwnedlabs.io/ https://www.linkedin.com/in/ian-austin/

    33 min
  4. Cracking Passwords and the Future of Passwords with Evil Mog

    17 FÉVR.

    Cracking Passwords and the Future of Passwords with Evil Mog

    In this episode of the Security by Default podcast, host Joe Carson welcomes Evil Mog, an expert in password cracking and cybersecurity. They discuss the importance of Hacker Jeopardy in making cybersecurity fun, the ongoing challenges with passwords, and the evolving role of AI in password cracking. The conversation also touches on incident response, the significance of documentation, and the future trends in cybersecurity, including the shift towards passwordless authentication and the impact of AI on both attackers and defenders. Takeaways Hacker Jeopardy is a fun way to engage with cybersecurity.Teaching others helps reinforce your own knowledge.Passwords will remain a necessary evil in security.AI is enhancing password cracking methodologies.Documentation is crucial in incident response.The cost of hacking is increasing due to advanced techniques.Collaboration between red and blue teams is essential.Insider threats are on the rise in cybersecurity.Password management is fundamentally an asset management issue.Future trends indicate a shift towards passwordless authentication. Sound bites "Teaching helps you learn better." "Security is about enabling the business." "The cost of hacking is rising." Chapters 00:00 Introduction to Evil Mog and Hacker Jeopardy02:37 The Importance of Community and Teaching in Cybersecurity05:22 Password Security: The Louvre Incident07:59 The Evolution of Authentication Methods10:35 Challenges in Asset Management and Password Management13:15 Operational Technology (OT) Security Challenges15:53 The Role of Documentation in Cybersecurity18:42 AI in Cybersecurity: Automation and Password Recovery21:52 AI in Password Cracking24:56 Enhancing Human Capabilities with AI27:18 The Evolution of Cybercrime30:02 Trends and Predictions for Cybersecurity34:41 Collaboration in Cybersecurity37:24 The Future of Cybercrime and AI40:59 Connecting with Evil Mog

    42 min
  5. Exploring Identity Security Trends with Charles Chase

    3 FÉVR.

    Exploring Identity Security Trends with Charles Chase

    In this episode of the Security by Default podcast, host Joe Carson speaks with Charles Chase about his journey into the cybersecurity field, focusing on identity security and privilege access management. They discuss the evolving trends in identity security, the importance of maintaining identity hygiene, and the impact of regulations like NIST 2 and DORA on organizational practices. The conversation also covers the shift towards passwordless security, the role of AI in identity management, and resources for those looking to enter the field. The episode concludes with reflections on the importance of identities in business and society. Takeaways Charles Chase fell into cybersecurity from a military background.The importance of understanding what you don't know in identity security.Organizations often have dormant accounts that pose security risks.Regulatory bodies are pushing organizations to improve their identity security practices.The shift towards passwordless security is gaining momentum.AI is becoming a valuable tool in identity management.Identity hygiene is crucial for reducing risks in organizations.The commoditization of identity solutions allows smaller businesses to implement security measures.Engaging with customers is key to understanding their unique identity security needs.The future of identity management is focused on user experience and automation. Sound bites "What do I not know?" "It's a learning tool." "It's a fun industry." Chapters 00:00 Introduction to the Podcast and Guest00:47 Charles Chase's Journey into Cybersecurity02:22 Trends in Identity Security and Best Practices05:54 Understanding Dormant Accounts and Their Risks09:54 The Shift Towards Passwordless Security12:45 The Role of AI in Identity Management18:35 The Importance of Digital Identity in Society26:45 Resources for Entering the Identity Space30:49 Conclusion and Final Thoughts Keywords cybersecurity, identity security, privilege access management, trends, best practices, passwordless security, AI in identity management, regulatory impact, identity hygiene, resources for cybersecurity

    30 min
  6. Cyber Ops and OSINT with the Grugq

    20 JANV.

    Cyber Ops and OSINT with the Grugq

    In this episode of the Security by Default podcast, host Joseph Carson engages with the Grugq, a cybersecurity expert and PhD student, discussing his journey into the field, the evolution of cybersecurity practices, and the complexities of information warfare. The Grugq shares insights on anti-forensics, the importance of understanding human behavior in cybersecurity, and the current landscape of cyber warfare, particularly in the context of the ongoing conflict in Ukraine. The conversation highlights the challenges and changes in the cybersecurity field, emphasizing the need for clarity and understanding in a chaotic information environment. Takeaways The Grugq's journey into cybersecurity began with a Unix book.He transitioned from internships to freelancing in cybersecurity.Moving to Thailand helped reduce living costs while consulting.Understanding anti-forensics is crucial for effective cybersecurity.The rules of cyber warfare differ significantly from peacetime operations.Information warfare involves changing how people interpret information.The Grugq emphasizes the importance of human behavior in cybersecurity.Staying updated in cybersecurity requires monitoring current events and engaging with experts.The evolution of cybersecurity tools has made it easier for new actors to operate.The Grugq's PhD research focuses on the realities of cyber warfare. Additional Resources: https://x.com/thegrugq https://github.com/grugq

    46 min
  7. From Prosecutor to CSO: Joe Sullivan on Cybersecurity Leadership, Crisis, and Resilience

    6 JANV.

    From Prosecutor to CSO: Joe Sullivan on Cybersecurity Leadership, Crisis, and Resilience

    In this episode of the Security by Default podcast, host Joseph Carson interviews Joe Sullivan, a prominent figure in cybersecurity. They discuss Joe's journey from a federal prosecutor to the Chief Security Officer at Facebook, exploring the challenges and expectations in transitioning from government to private sector roles. The conversation delves into the evolving landscape of cybersecurity, the impact of ransomware, and the importance of crisis management and preparedness. Joe shares valuable lessons for aspiring security executives and highlights the significance of understanding technology in leadership roles. The episode concludes with Joe's current projects, including his nonprofit initiative, Ukraine Friends, which provides laptops to children affected by the war in Ukraine. Takeaways Security is possible for everyone.Joe Sullivan's journey reflects a unique path into cybersecurity.Transitioning from government to private sector presents challenges.Understanding corporate culture is crucial for success.Measuring success in cybersecurity requires clear metrics.Ransomware has fundamentally changed the cybersecurity landscape.Security leaders are increasingly reporting to CEOs.Crisis management is essential for organizational resilience.Aspiring security executives should focus on business understanding.Giving back to the community is a vital part of the cybersecurity profession. Sound bites "Security is possible for everyone.""I got an MBA through osmosis.""The expectations were so high." Chapters 00:00 Introduction to Security by Default Podcast01:02 Joe Sullivan's Journey into Cybersecurity05:10 Transition from Government to Private Sector11:06 Navigating the Corporate Landscape15:48 Measuring Success in Security20:04 The Impact of Ransomware on Cybersecurity28:01 The Evolving Role of Security Leaders30:57 Understanding Business Strategy in Security32:59 Risk Management and Business Partnership33:52 Navigating Technology Risks35:54 The Race for AI Innovation38:03 Crisis Management and Preparedness39:59 Building Resilience in Security Teams42:16 The Importance of Response Training44:10 Lessons from Emergency Services47:41 Community Impact through Technology Additional Resources: https://www.joesullivansecurity.com/about https://ukrainefriends.org/ https://www.linkedin.com/in/joesu11ivan/ https://en.wikipedia.org/wiki/Joe_Sullivan_(cybersecurity)

    48 min

À propos

Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

Vous aimeriez peut‑être aussi