What The Hack

Supported by Sysdig

Welcome to What The Hack Show (WTH), the podcast where cyber security gets real, raw, and a little bit rebellious. A unique series that dives deep into the untold, unfiltered stories from the world of cybersecurity. The What The Hack Show podcast is supported by Sysdig, GCP (Google Cloud Platform), and Predictiv. Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

  1. S2 E7: Cloud Misconfigurations at Scale

    12/09/2025

    S2 E7: Cloud Misconfigurations at Scale

    In S2 E7 of What The Hack, we hear about what can go wrong in the cloud. Our confession this week covers cloud misconfigurations and our guests - Petra Vukmirovic of Numan and cyber security journalist Danny Palmer - discuss how to improve cloud security processes and to support your team.  Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Petra Vukmirovic and Danny Palmer. Petra Vukmirovic is a technology enthusiast, leader, public speaker, ex-emergency medicine doctor, competitive athlete in volleyball and ex-sports scholar. In her career, she has led and directed teams around software and security, including roles at Job & Talent, Zava and now Numan, as well as contributing to OWASP on threat modelling. Prior to joining the cyber security industry, she worked as an emergency doctor providing frontline healthcare. Danny Palmer is an experienced, award-winning cybersecurity writer, reporter and editor. He has worked in journalism and editorial for over 15 years and spent over a decade covering cybersecurity and the impact it has on people, businesses and society. His goal is to make complex issues around cyber security, regulation and technology simpler to understand. Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources:CHECKLIST: Cloud Misconfigurations Audit - https://bit.ly/4oCG58z Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security - https://www.sysdig.com/learn-cloud-native

    42 min
  2. S2 E6: Alert fatigue

    11/25/2025

    S2 E6: Alert fatigue

    In S2 E6 of What The Hack, our confession goes into what happens when you get too tired to track your alerts properly. While they might be tiresome, they can still be the difference between a secure organisation and a breach. Hearing the confession this week are Goher Mohammad, Head of Information Security at L&Q, and renowned cyber security journalist Kate O’Flaherty, who never tire of discussing how to improve security planning and response. Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Goher Mohammad and Kate O’Flaherty. Goher Mohammad is the Head of Information Security for L&Q, where he leads a forward moving, agile and transformational Technology team aligning with new ways of working across the business. He has more than 17 years’ experience in the technology sector leading national and global teams, including risk and compliance at Photobox Group and heading up IT for Merrill Corporation in Europe. Kate is an experienced journalist, editor and copywriter that has appeared in titles including The Times, The Guardian, Forbes, SC UK, The Economist, Wired UK, IT Pro and CIO. She specialises in B2B technology, including cyber security, telecoms and public sector IT.  Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fuelled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources:CHECKLIST: Alert Fatigue Diagnostic Tool - https://bit.ly/4oekJ19 Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security - https://www.sysdig.com/learn-cloud-native

    50 min
  3. S2 E5: Deepfake Executive Fraud

    11/11/2025

    S2 E5: Deepfake Executive Fraud

    In S2 E5 of What The Hack we dive into the world of deepfakes, and hear a confession on how the IT security lead confronted an attack on the finance team. Our guests this week are Flick March of Accenture, one of the leading cyber security experts working around this topic, and security journalist Danny Palmer. Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Flick Marsh and Danny Palmer. Flick March is EMEA Cyber Strategy Lead & Global Cyber C-Suite and Board Lead at Accenture, providing Board Reporting, Executive Advisory, Protection and Education and Board Crisis Management to the company’s clients. With more than 30 years experience in cyber security, she plays a key role in leading EMEA Cyber Strategy covering Risk, Regulatory, Compliance, Controls, Human Risk, Organisation and Education. She is also the company’s global lead on Deepfake attacks and how these will affect cyber security and business risk planning. Danny Palmer is an experienced, award-winning cybersecurity writer, reporter and editor. He has worked in journalism and editorial for over 15 years and spent over a decade covering cybersecurity and the impact it has on people, businesses and society. His goal is to make complex issues around cyber security, regulation and technology simpler to understand. Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources: Checklist: Deepfakes and digital deception Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    49 min
  4. S2 E4: The Imposter Employee

    10/28/2025

    S2 E4: The Imposter Employee

    In S2 E4 of What The Hack Show, we hear a confession around a fake IT employee that led to a very real security issue. This week’s guests are Kate O’Flaherty, a journalist that writes on cyber security for the likes of Forbes, SC Media and IT Pro, and cyber security expert Roger Grimes of KnowBe4, who discovered their own organisation had been targeted by fake IT workers and shared the investigation publicly. Connect with our speakers: What The Hack Show is hosted by Rayna Stamboliyska and this episode's special guests are Roger Grimes and Kate O’Flaherty. Roger A. Grimes has 35 years of experience in computer security and has authored 13 previous books on the topic. He is the Data-Driven Defense Evangelist at KnowBe4, a security awareness education company, and a senior computer security consultant and cybersecurity architect. Kate is an experienced journalist, editor and copywriter that has appeared in titles including The Times, The Guardian, Forbes, SC UK, The Economist, Wired UK, IT Pro and CIO. She specialises in B2B technology, including cyber security, telecoms and public sector IT.  Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources: Guide: North Korean Fake IT Workers: Detection Guide for EMEA Businesses Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    49 min
  5. S2 E3: Security Team Social Engineering

    10/14/2025

    S2 E3: Security Team Social Engineering

    In S2 E3 of What The Hack we look into social engineering, and how security teams have to protect themselves as well as their organisations. Our guests, CISO and security leader Didar Gelici and editorial director of Dolphin Publishing Sander Almekinders, hear a confession around social attacks, knowing your tools, and how to keep your operations protected against ransomware.  Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Didar Gelici and Sander Almekinders. Didar Gelici is an award winning tech and security leader that has led teams at the likes of Just Eat, Travelex and Commonwealth Bank. Alongside her roles, Didar has led communities including the Ladies of London Hacking Society and She CISO, and she has volunteered to develop standards as part of the Open Worldwide Application Security Project (OWASP) Foundation. Her experience is in technology risk and controls, third party risk, and security strategy. Sander Almekinders is an experienced IT editor in chief, moderator, panelist, and writer for the C-suite and IT professional communities. He has a thorough knowledge of what's happening in the IT industry in the broadest sense of the word, and is the owner of Dolphin Publishing.  Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources: Checklist: Executive Targeting Tactics (With & Without AI) Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    45 min
  6. S2 E2: Communication Breakdowns Between Teams

    09/30/2025

    S2 E2: Communication Breakdowns Between Teams

    In S2 E2 of What The Hack we hear about how communication within teams can help security … or hinder it! Our guests, cyber security expert Glenn Wilson and journalist Joe Fay, hear a confession this week that goes into the world of DevOps, security, and how a conversation or two with the right people can make a huge difference.  Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Glenn Wilson and Joe Fay.  Glenn is a leadership coach specialising in DevOps, Agile, and security. He is founder of Dynaminet and the best-selling author of the book DevSecOps: A leader’s guide to producing secure software without compromising flow, feedback and continuous improvement. He is an experienced security professional who has worked for over 20 years in the IT industry across multiple sectors. Glenn focuses on strategy and employs systems thinking in practice to enable organisations to apply secure processes and principles across their operations. Glenn also works in the DevSecOps London Gathering and DSO Overflow Podcast. Joe Fay has been covering the technology industry for 30 years and has edited publications in London and San Francisco. His work has appeared in a range of publications from TechInformed, The Stack and The Register through to the BBC. His coverage includes a range of technology topics, from the impact of data centres and recruiting military veterans to work in cyber security through to software development and security. Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources Checklist: Lost In Translation Diagnostic Tool Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    49 min
  7. S2 E1: Container Security Nightmares

    09/16/2025

    S2 E1: Container Security Nightmares

    In this episode of What The Hack we dive into the world of container security, and how teams can harden their applications running in containers against attack. Our guests, Conor Sherman, CISO in Residence at Sysdig, and freelance journalist Joe Fay, hear from someone who suffered a container security issue, and discuss the costs and problems that teams can face if they don’t get their approach right from the start. They also share their thoughts on how to spot problems before they lead to expensive cloud bills or a dangerous data breach. Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Conor Sherman and Joe Fay. Conor Sherman is the CISO in Residence at Sysdig, bringing over 15 years of experience leading security programs across fintech, Saas, GovTech, and private equity environments. At Sysdig, he works closely with the Sysdig Threat Research Team and CISOs to understand emerging cloud and Al security challenges, translating their needs into product and community impact. Before joining Sysdig, Conor was CISO at Updater, where he built and scaled enterprise security and threat intelligence programs.  Joe Fay has been covering the technology industry for 30 years and has edited publications in London and San Francisco. His work has appeared in a range of publications from TechInformed, The Stack and The Register through to the BBC. His coverage includes a range of technology topics, from the impact of data centres and recruiting military veterans to work in cyber security through to software development and security. Learn more about our supporters - Sysdig, Google Cloud and Predictiv:Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. Sysdig Sage™ - the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry, providing the context, speed, and precision that modern teams need to build and defend innovation in real time. Google Cloud is the new way to the cloud, providing AI, infrastructure, developer, data, security, and collaboration tools built for today and tomorrow. Customers in more than 200 countries and territories turn to Google Cloud as their trusted technology partner. Predictiv helps B2B revenue teams uncover, prioritize, and activate their complete revenue landscape with unified intelligence and first-party marketing campaign execution. Resources Policy vs. Practice Quick Audit - Container Security Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    46 min
  8. S1 E9: AI Is Going To Solve Everything

    01/28/2025

    S1 E9: AI Is Going To Solve Everything

    In episode 9 of What The Hack we travel to the future with Sergej Epp (technology leader and CISO at Sysdig) and Ed Targett, Founder and Editor in Chief at The Stack. We challenge these cyber security experts on how they see leadership evolving as we approach 2030 and investigate how leaders can prepare for multiple possible futures while maintaining effective security operations today. After all, there are no surprises, just lack of foresight. Connect with our speakers: What The Hack is hosted by Rayna Stamboliyska and this episode's special guests are Sergej Epp and Ed Targett. Sergej Epp is the CISO at Sysdig and is a tech-savvy cybersecurity and technology leader, with extensive international tech and financial services industry experience. Trusted advisor to customers and partners. Advocate for collaboration and threat intelligence sharing among public and private sectors. Successful track record in cybersecurity architecture, cyber defense operations / SOC, security risk management, cloud security, DevSecOps, global cyber and digital forensics investigations (DFIR). Ed Targett is the Founder and “Editor-in-Chief” at The Stack, a B2B technology website aimed at CIOs and other C-level technology leaders. Prior to founding The Stack, Ed was the editor at Computer Business Review and has held editorial lead roles in sustainability and business publications. Learn more about our supporters, Sysdig and AWS: The podcast is proudly supported by Sysdig and AWS - together, Sysdig and AWS help enterprises strengthen cyber resilience and accelerate secure cloud innovation. Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.

    42 min

Ratings & Reviews

5
out of 5
2 Ratings

About

Welcome to What The Hack Show (WTH), the podcast where cyber security gets real, raw, and a little bit rebellious. A unique series that dives deep into the untold, unfiltered stories from the world of cybersecurity. The What The Hack Show podcast is supported by Sysdig, GCP (Google Cloud Platform), and Predictiv. Visit the Learn Cloud Native Hub for articles that provide a foundational understanding for the core pillars of cloud and container security.