The cyber weekly

Deogratius Okello, Josephine Olok and Angella Nabbanja

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!

  1. 6d ago

    90 days from technical to IT risk professional

    ⚠️ One overlooked technical issue could become a major financial, operational or reputational crisis. But what exactly is IT risk, and why do organizations invest so much in managing it? In this episode of The Cyber Weekly Podcast, Deo Okello sits down with IT risk and security professional Peter Muhumuza to break down IT risk in practical, easy-to-understand language. You will learn: 🔍 How technical weaknesses become business risks 📊 How organizations classify and track risks ⚖️ Which risks can be accepted and which require immediate action 🚀 How risk professionals support innovation without becoming “Mr. No” 🤝 Why third-party and vendor risk assessments matter ☁️ The risks created by cloud concentration and AI adoption ✅ Why passing an audit does not mean risk management is complete 📈 How technical professionals can begin transitioning into IT risk within 90 days Peter also explains why effective IT risk management is about more than fixing technical problems. It requires understanding business priorities, regulatory obligations, operational downtime and financial exposure. If you work in cybersecurity, IT, banking, fintech, audit, governance or risk management, this conversation is for you. 👍 Like this episode 💬 Share your biggest IT risk lesson in the comments 🔔 Subscribe to The Cyber Weekly Podcast for more practical cybersecurity conversations 📤 Share this episode with someone interested in IT risk #TheCyberWeekly #ITRisk #RiskManagement #Cybersecurity #InformationSecurity #GRC #ThirdPartyRisk #CloudSecurity #CyberRisk #ITGovernance

  2. Jul 29

    The Unexpected Risks of Cloud Security That Experts Are Overlooking

    Cybersecurity in the Cloud: The Hidden Threats and Future of Digital Defense If you’re managing cloud infrastructure or responsible for cybersecurity in a hybrid environment, overlooking emerging threats can leave your organization exposed before you even notice the gap. In this episode, Muhiire Bill, a seasoned IT security professional with nearly a decade in financial institutions, reveals the cloud security blind spots most teams miss. From misconfigured cloud resources and weak access controls to API vulnerabilities and social media reconnaissance, this conversation uncovers the real risks hiding behind “secure” systems. Bill also breaks down how organizations can balance usability, compliance, and protection without slowing the business down.  You’ll learn: Why misconfigured cloud settings create massive breach risks How multi-factor authentication and role-based access can strengthen defenses Why API security is becoming one of the biggest threats in cloud environments How continuous compliance helps teams stay ahead of attackers Practical ways to align security with real-world operations If you work in IT, security, cloud operations, or leadership, this episode gives you the insight you need to avoid common mistakes and build a stronger security culture. Bill’s experience across financial and manufacturing sectors brings a practical, real-world perspective to one of today’s most important tech conversations. Stay ahead of the curve hit play now.

  3. Jul 22

    🔐 From Floppy Disk Viruses to the SOC — 15 Years in Cybersecurity | Brett @ Cyber Weekly

    🎙️ Cyber Weekly | Episode with Brett (@infosecbret) What turns a kid whose family PC got wrecked by a boot sector virus into a security professional with 15+ years in IT and a Master's in Information Assurance? In this episode, host Deo Okello sits down with Brett to trace that path — and to talk honestly about what the job actually looks like once the "unicorns and rainbows" phase wears off. We get into why information assurance is really just cybersecurity with the spotlight on data, why AI is now the threat he worries about most, and what "doing the basics well" looks like in practice. 🔐 ⏱️ In this episode: - The Windows 95 floppy virus that started it all 💾 - IT → SOC analyst: how the transition actually happened - Information assurance explained (and why the CIA triad still matters) - Why phishing is still the risk that never goes away 🎣 - AI in the hands of ransomware gangs — and the well-meaning employee pasting production code into an LLM 🤖 - What Patch Tuesday teaches us about vulnerability management - Defenders have to be right 100% of the time. Attackers only need once. ⚔️ - Brett's top 3: go back to basics, patch all the things, invest in your people 📈 - The one takeaway: never stop learning 🧠 💬 Favourite line from the episode? Drop it in the comments. 👍 Like, subscribe, and hit the bell for weekly conversations on security, threats, and the people defending against them. 🔗 CONNECT WITH BRET X (Twitter): https://x.com/infosec_bret YouTube: https://www.youtube.com/c/BretWitt 📌 REFERENCED IN THIS EPISODE The "Mythos" story Bret mentions at ~10:00 — Anthropic's Claude Mythos 5 and Fable 5 launched June 9, 2026. On June 12 the US Commerce Department imposed export controls after researchers found a way to prompt the model into identifying software vulnerabilities and, in one case, producing working exploit code. Anthropic pulled both models globally. Controls were lifted June 30 and access restored July 1. - Anthropic's statement (June 12): https://www.anthropic.com/news/fable-mythos-access - Anthropic on restoring access: https://www.anthropic.com/news/redeploying-fable-5 - Forbes breakdown: https://www.forbes.com/sites/anishasircar/2026/06/16/anthropic-disabled-fable-5-and-mythos-5-after-a-us-export-control-order-heres-what-happened/ - CNBC on controls being lifted: https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html #CyberSecurity 🔐 #InfoSec 🛡️ #InformationAssurance 📊 #CyberWeekly 🎙️ #SecurityPodcast 🎧 #SOCAnalyst 👨‍💻 #Ransomware 🚨 #Phishing 🎣 #AISecurity 🤖 #PatchTuesday 🩹 #VulnerabilityManagement ⚠️ #ThreatIntelligence 🕵️ #ITCareers 📈 #CyberCareers 🚀 #BlueTeam 🔵 #SupplyChainAttack ⛓️ #TechPodcast 🎬 #NeverStopLearning 🧠 #CyberAwareness 👁️

  4. Jun 25

    TCW Episode 106: Compliance Is Not a Checkbox

    Ever felt like your compliance checks are just a checkbox exercise? 📝 It's time to rethink the way we approach governance!   Tag someone who needs to hear this! 👇   Today, I sat down with Pierre Paul, a GRC expert who believes governance should live *inside the code*, not just above it. He's challenging the status quo, building AI compliance tools that could revolutionize how we manage risk.   Why does this matter? Because relying solely on templates and frameworks can lead to missed opportunities for real improvement. Let's break free from the cycle of checkbox compliance!   Still figuring this out myself, but it’s a conversation we all need to have.   Show Notes  Follow Pierre-Paul Ferland https://www.linkedin.com/in/ppferland   Like and Follow our LinkedIn page https://www.linkedin.com/company/thecyberweekly   Like and Follow our X page https://twitter.com/thecyberweekly   Follow Deogratius Okello  https://www.linkedin.com/in/deo-okello/ https://twitter.com/deookello51   Follow Josephine Olok  https://www.linkedin.com/in/josephine-olok/ https://twitter.com/josephine_olok   Follow Angella Nabbanja https://www.linkedin.com/in/angella-nabbanja-4b6361178/ https://x.com/angellamukasa_   Follow Magala our Social Media Content Writer  https://www.linkedin.com/in/magala-rogers/                                     Follow Aine our Graphics Designers https://www.linkedin.com/in/aine-allan-60987916a

  5. May 20

    Cyberpsychology & AI with Lisa Ventura

    Welcome to The Cyber Weekly! In this episode, we sit down with Lisa Ventura MBE FCIIS MBCS, a trailblazer in cybersecurity awareness, cyberpsychology, and neurodiversity advocacy. Lisa’s unconventional journey from broadcasting into cybersecurity has shaped her unique perspective on the human side of security. She explains how attackers exploit psychology, why AI is both a blessing and a curse, and how neurodiversity can transform SOC teams into powerhouses of resilience and innovation. We discuss: How attackers exploit urgency and fear in social engineering Why cyber psychology is critical in today’s AI-driven threat landscape The role of AI in both enabling attackers and empowering defenders How neurodiversity can be leveraged as a competitive advantage Building communities and associations that strengthen cybersecurity culture Her message is clear: “Security is a human problem before it’s a technical one.”   📑 Show Notes & Links 🔗 Follow Lisa Ventura LinkedIn: https://www.linkedin.com/in/lisasventura/ Unity Group Solutions: https://unitysolutions.org.uk/ AI and Cyber Security Association: https://aisec.org.uk/ 📢 Follow The Cyber Weekly LinkedIn: https://www.linkedin.com/company/thecyberweekly X (Twitter): https://twitter.com/thecyberweekly 👥 Connect with the Hosts & Team Deogratius Okello LinkedIn: https://www.linkedin.com/in/deo-okello/ X: https://twitter.com/deookello51 Josephine Olok LinkedIn: https://www.linkedin.com/in/josephine-olok/ X: https://twitter.com/josephine_olok Angella Nabbanja LinkedIn: https://www.linkedin.com/in/angella-nabbanja-4b6361178/ X: https://x.com/angellamukasa_ Magala (Social Media Content Writer) LinkedIn: https://www.linkedin.com/in/magala-rogers/ Aine (Graphics Designer) LinkedIn: https://www.linkedin.com/in/aine-allan-60987916a

  6. Apr 29

    From Big Tech to Private Eye, Building a Career in Digital Forensics

    You think deleting a message means it's GONE. It's not. But here's what nobody's telling you—law enforcement doesn't have access to everything either. And that gap? It's where justice lives or dies. In this episode of The Cyber Weekly, I sit down with Kenneth Hartman—digital forensics expert, CISO, SANS instructor, and the guy defense attorneys call when they need the truth about digital evidence. Here's what hit me hardest: 🔹 Deleted texts might still be sitting in a database on your phone. 🔹 AI agents are walking around with YOUR credentials right now—and you don't even know it. 🔹 License plate readers are building a map of your life without a warrant. 🔹 The law is NOT keeping up with technology—and that affects ALL of us. Kenneth has worked inside Google, SAP, and Illumina. He's taught cybersecurity on five continents. And now, he's breaking it ALL down in plain language. This isn't just for tech people. This is for anyone who owns a phone, uses the cloud, or believes in the right to a fair trial. #DigitalForensics #CyberSecurity #TechTruths #PrivacyMatters #TheCyberWeekly #DataPrivacy #FutureOfTech #SmartPhoneHacks #tcw  Show Notes  Follow Kenneth G. Hartman https://www.linkedin.com/in/kennethghartman/ https://x.com/KennethGHartman Check out Ken’s whitepaper https://www.sans.org/white-papers/when-security-scanner-became-weapon Check out the Algorithm Gavel paper  https://lucidtruthtechnologies.com/images/pages/The-Algorithmic-Gavel.pdf Check out the Team PCP webcast https://www.sans.org/webcasts/when-security-scanner-became-weapon Like and Follow our LinkedIn page https://www.linkedin.com/company/thecyberweekly Like and Follow our X page https://twitter.com/thecyberweekly Follow Deogratius Okello our Producer and Editor https://www.linkedin.com/in/deo-okello/ https://twitter.com/deookello51 Follow Josephine Olok  https://www.linkedin.com/in/josephine-olok/ https://twitter.com/josephine_olok Follow Angella Nabbanja https://www.linkedin.com/in/angella-nabbanja-4b6361178/ https://x.com/angellamukasa_ Follow Magala our Social Media Content Writer  https://www.linkedin.com/in/magala-rogers/                                     Follow Aine our Graphics Designers https://www.linkedin.com/in/aine-allan-60987916a

About

Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!