Cyber Rants - A Miraculously Refreshing Cybersecurity Podcast: Recent Episodes

Silent Sector LLC

Join three longtime cybersecurity professionals and their guests as they rant, rave, and tell you the nitty-gritty of cybersecurity that nobody else talks about in their fancy marketing materials and trade show giveaways, all so you can protect your organization from cyber criminals. This cybersecurity podcast even pairs well with the international best-selling book "Cyber Rants: Forbidden Secrets and Slightly Embellished Truths About Corporate Cybersecurity Programs, Frameworks, and Best Practices." Zach Fuller, Mike Rotondo, and Lauro Chavez have fun, try not to take life too seriously, and definitely don't hold anything back when it comes to cybersecurity and compliance!

View Details

In this urgent episode, the Cyber Rants crew welcomes Silent Sector’s Principal Cybersecurity Architect, Brian Contario, to discuss his game-changing discovery of a critical vulnerability in the Two-Factor Authentication Enrollment Process. This vulnerability has the potential to impact hundreds of millions of accounts globally and poses a serious threat to IT infrastructures everywhere. Brian and the team break down why this finding is not just another CVE but a pivotal moment that will require swift action from software vendors to update their 2FA Enrollment Process. Tune in to learn what steps IT professionals must take now to protect their organizations from a new wave of attacks and where you can find additional resources, including the IETF Request For Comments Draft. This is a must-listen episode for anyone serious about safeguarding their systems!

More information: https://silentsector.com/2fa

IETF Request for Comments Draft: https://datatracker.ietf.org/doc/html/draft-contario-totp-secure-enrollment

View Details

In this episode of the Cyber Rants Podcast, Zach and Lauro are joined by Yasir Ali, CEO of Polymer, to dive deep into the critical issue of data leakage and shadow IT in today's SaaS-driven business environment. As companies rely on a multitude of software platforms, employees often create unauthorized accounts on new tools, posing significant security risks. Yasir shares his expert insights on identifying and mitigating these threats, offering actionable strategies to secure your operations against improper and unauthorized SaaS usage. Tune in to learn how to safeguard your organization's data in a complex, ever-evolving digital landscape.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Lauro and Zach welcome Denzil Wessels, Founder & CEO of Dymium, to explore groundbreaking innovations in database security. Denzil introduces Dymium's cutting-edge "Ghost layer" approach, which emphasizes securing data itself rather than just the network, offering granular control and preventing the need for data duplication. This episode highlights how Dymium's unique focus on protecting specific data sets them apart in the cybersecurity landscape. Additionally, Denzil shares insights into Dymium's other capabilities, designed to help organizations safely leverage AI platforms like ChatGPT and more. Tune in to discover a fresh perspective on safeguarding your one of your organization's most valuable assets—its data.

Denzil Wessels on LinkedIn
Learn more about Dymium

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In this episode of the Cyber Rants Podcast, we sit down with Chris Hadnagy, a prominent speaker at RSA, Black Hat, and DefCon's SE Capture the Flag events. Chris is the author of four influential books, including "Social Engineering: The Art of Human Hacking" and "Human Hacking: Win Friends, Influence People, and Leave Them Better Off for Having Met You." He is also the founder of the Innocent Lives Foundation, a nonprofit dedicated to fighting the sexual abuse of children, and the CEO of Social-Engineer, LLC.

Join us as we delve into Chris's extensive background in social engineering across corporate, government, and military sectors. Learn why social engineering is so effective and the kind of damage it can cause, along with the most common and sophisticated techniques used by cybercriminals today. Chris also shares the best strategies for protecting companies from malicious social engineering and discusses innovative personal security tips, such as human-based MFA and unique code words for family safety.

Chris's Company: https://www.social-engineer.com

Innocent Lives Foundation: https://www.innocentlivesfoundation.org/

The Human Behavior Conference 2024 (OCT 30 in Orlando): https://humanbehaviorcon.com/

View Details

Financial scams and cyber breaches are hitting more Americans than ever. This week, Zach and Lauro dive into common personal scams and cyber attacks, sharing essential prevention tips and steps to take if you're targeted. Tune in and share with non-tech-savvy friends to help them stay safe from online criminals.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, Zach and Lauro welcome pen tester, CISO, and entrepreneur, Dan DeCloss. From navigating organizational challenges to systemizing vulnerability management processes, Dan shares expert insight that applies to IT and security professionals in every organization. The guys also discuss Dan's solution to simplify penetration test reporting, vulnerability management, and monitor progress over time.

To Connect with Dan, find him on LinkedIn: https://www.linkedin.com/in/ddecloss/

To learn more about Dan's company, PlexTrac, visit: https://plextrac.com/

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In this episode of Cyber Rants, Zach and Lauro sit down with Ty Smith, a former Navy SEAL turned successful tech entrepreneur, to uncover invaluable leadership and mindset lessons. Ty draws from his combat experience and entrepreneurial journey to offer crucial insights for technology leaders. Tune in to learn how to build resilient teams, lead with purpose, and elevate your organization to new heights. Whether you're a seasoned tech professional or aspiring leader, this episode is packed with actionable strategies to propel your team forward.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In this episode of Cyber Rants, Zach and Lauro are joined by Jeremy Snyder, CEO of Firetail, to explore the intricacies of safeguarding vital API connections. Jeremy shares invaluable expertise on identifying and fortifying the vulnerable points targeted by cyber adversaries. Tune in as he discusses a range of topics, from API authentication to threat detection, providing essential knowledge to shield your organization's API endpoints from malicious actors. Don't miss this deep dive into API security and learn how to protect your critical digital assets effectively.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In today's cyber landscape, breaches are often disclosed by criminals before victims are even aware, leaving companies scrambling to manage the fallout. Crafting a swift and effective response is essential to safeguarding trust and reputation. Join us this week with corporate communications expert Kevin Dinino, President of KCD PR, as he shares key strategies for post-breach messaging. From protecting customer relationships to addressing shareholder concerns, Kevin provides actionable insights to help organizations navigate the complexities of crisis communication. Whether you're a seasoned professional or new to incident response planning, this episode is a must-listen for mastering communication in the wake of a breach.

Learn more about Kevin Dinino and KCD PR at https://kcdpr.com
Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

It's not a matter of if an organization is going to be attacked, but when. This week, the guys dive into discussing what organizations should be doing more to ensure they are resilient and ready to recover after an attack.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

When the turn of the year comes, so do the projections of Zach, Mike, and Lauro. Sharing both obvious reminders and concepts that are not widely known, the guys break out the crystal ball and give their take on what's coming this year in cybersecurity.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

We are thrilled to welcome back Chris Rock, a cyber mercenary with the expertise to dismantle individuals, institutions, and even entire nations. Join us as Chris shares insights, captivating stories, and the harsh realities of the hacker's world, offering a unique perspective to help you comprehend the intricacies of safeguarding your organization. From explaining why hacks against certain CVEs are often just fluff and hype to the importance of specific technologies, Chris and the guys dive even deeper into the murky realm of cyber crime. If you were captivated by his previous appearance on our show, this is one you won't want to miss!

www.chrisrockhacker.com
www.siemonster.com
Follow Chris on Twitter @chrisrockhacker

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In a digital realm rife with misinformation, the guys dissect the reliability of cyber score sites like Security Scorecard that rate the security level of companies. They discuss the repercussions of false ratings and the pressures on organizations to pay for correcting misleading information. Breaking down real-world examples to a technical level, the guys explore the nuances of these scoring systems and give a concise yet insightful perspective on the pros and cons. Listen to this episode and decide for yourself whether cybersecurity scoring sites are providing real value or misinforming the public.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Let's face it, disasters are prone to strike anytime and almost always when least expected. Most businesses can't afford to stop operations for an extended period of time. Having a plan for disaster recovery and business continuity is central to your cybersecurity program and most compliance requirements. This week, the guys talk about developing effective plans that you hope you never have to use.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

The guys are asked regularly, "How can vendor risk management be quicker and easier?" After all, the process can be quite time-consuming. Others ask, "How do we answer these giant questionnaires from our clients without making ourselves look bad?" This week, the guys share tips to help organizations both manage vendor risk and present themselves in the best possible way when asked about their own cybersecurity. Regardless of whether you are the vendor under scrutiny or you are evaluating the security of your vendors, this episode is for you.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Let's face it, the end of the year is the busiest time in many areas of business - but fear not! Cybersecurity shouldn't be an end-of-year rush to catch up. This week the guys break down what you can do to make the 4th quarter easier for you so you can actually enjoy some time off during the holidays. They share their observations and insights so you can go into the new year ready and confident.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, Zach and Lauro are joined by Milton Chavez, as all three guests have one unique connection - they're all U.S. Army Veterans that have made the post-military transition to the Cybersecurity sector. They discuss what life is like making the jump from a military background to the cybersecurity industry, and tips for current soldiers to make the same transition when they hang up the uniform.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, Zach and Lauro talk about some critical but often overlooked topics including in-person social engineering attacks, the nuances of change management, and what it really means to hack wireless networks. They share why organizations need to do more in-person physical penetration testing and how to help employees react properly in the event of a face-to-face social engineering attack.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cyber criminals continue to increase their focus on executives and other high-profile individuals. Using well crafted and targeted attack methods, criminals are able to coerce people into sending money and information directly into the wrong hands. This week, the guys talk about whaling, spear phishing, and other tactics being used in successful attacks!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys talk about vCISO challenges from the perspectives of both the vCISOs and their clients. But wait - what does it really mean to be a vCISO? How do you know if a vCISO is right for your organization? Which vCISO is best? You’ll get answers from the guys as they share their vCISO stories and discuss cybersecurity expertise for rent in today's confusing marketplace!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome one of the most interesting figures in cybersecurity! Meet Chris Rock, the hacker and cyber mercenary who can overthrow a government, digitally birth and kill people, and leverage a lot more unique skills he doesn't share with everyone. In addition to founding SIEMonster and being a three time DefCon presenter, Chris has worked across the Middle East, the US, and Asia preventing cyber attacks for both governments and private organizations. This episode is as entertaining as it is eye-opening!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

It seems like there is a new cybersecurity regulation popping up every week and with so many changes, it can be hard to keep track. This week the guys explain the Securities and Exchange Commission Rule 10 and the Federal Trade Commission Safeguards Rule. They share who's affected and what these requirements could mean to your organization.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

For better or for worse, Artificial Intelligence has been dominating the news. Is it really what people say? What does easy access to AI tools mean for your cybersecurity program? The guys discuss pros, cons, and their opinions on how AI should be utilized in your cyber risk management program.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Enterprise customers want to work with vendors that are secure and reputable. This week, the guys discuss how smart companies leverage their cybersecurity efforts to increase revenue and gain a competitive edge. Zach, Mike, and Lauro share how they've helped clients gain millions of dollars in new contracts and tips so you can help your company thrive!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys celebrate the 100th episode of The Cyber Rants Podcast! They share Silent Sector’s origins as a company and how Cyber Rants was launched out of the desire to improve the cybersecurity industry. They also share a bit about their backgrounds and throw in quite a few rants for good measure. Help us look forward to another 100 episodes by rating and sharing!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

We’ve covered various forms of remote penetration testing, so in this episode we get up close and personal. On-site penetration testing has its own benefits, risks, and nuances. This week, the guys discuss activities such as Wireless Network Penetration Testing and Physical Security Assessments that are conducted on-site. This is “the fun stuff” and you don’t want to miss this episode!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss network penetration testing which is a critical aspect of cyber risk management. They share how internal and external network pen testing validates the effectiveness of the controls you have in place and helps you find exploitable vulnerabilities before the cyber criminals do. They discuss the differences between Black Box and Grey Box penetration testing, Red Team and Blue Team approaches, the intricacies of internal network pen testing, and compliance considerations.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys reach the epic conclusion of the SOC 2 audit preparation series. They finish the Security Trust Services Criteria, discussing Control Categories 7,8, & 9. They also share tips and tricks to succeed with your SOC 2 audit.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys return to helping you prepare for your SOC 2 audit. This time, they discuss Control Categories 5 and 6 in the Security Trust Services Criteria. They cover risk management controls and answer the question, "How does hosting in the cloud help with the audit?"

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

We all know that data breaches are nightmares and the legal ramifications can be far worse than the breach itself. So what can we do to protect ourselves? This week, Zach and Mike welcome attorney John Gray, Chair of Data Privacy and Cybersecurity of Lewis Roca, who specializes in Data Privacy law. He shares how companies can prepare in advance to reduce the legal ramifications often associated with cyber attacks. He also covers issues around nation-state threat actors and various malicious activities in today's environment.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Web applications are drastically different and like anything, are prone to vulnerabilities. Application penetration tests come in all shapes and sizes, some good, some bad, and some are not even penetration tests at all. This week, the guys share their insights about Web Application Penetration Testing and get what you need out of your next test! Do not miss this episode if you are planning a web application penetration test for the first time!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

As we get deeper into the SOC 2 Preparation series, the guys discuss the controls around monitoring activities, tracking deficiencies, and assessing results (CC 4). If a SOC 2 audit is in your future, be sure to catch all the SOC 2 audit readiness episodes!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys continue their series on how to prepare for your SOC 2 audit by discussing controls in Section 3 of the Security Trust Services Criteria. If your organization is about to undergo a SOC 2 audit or looking into it, be sure to catch all the SOC 2 audit readiness episodes!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Planning to go through your very first SOC 2 audit? If so, this series will be a binge worthy and enlightening adventure! This week, the guys walk you through the first few SOC 2 audit requirements with a step-by-step approach. They share what your auditor will be looking for, tips to prepare, and the pitfalls that might catch you off guard.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome IT leader Ken Wiley, who shares about cutting-edge work in the field of supercomputing, insights gained from a highly successful IT and cybersecurity career, plus some current tech trends to watch closely.

For more on Ken and Silverdraft, please see the links below.

https://www.linkedin.com/in/wileyken/

https://silverdraft.com/

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

The development of a cybersecurity committee will accelerate your company's alignment to a cybersecurity framework and compliance requirements.

This week, the guys discuss why you may need a committee for your cybersecurity framework adoption, instead of leaving one person to lead the job.

They also cover operational tempo with a 12-month calendar example to accelerate your progress and maintain compliance.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys talk about navigating the cybersecurity environment in 2023. From advancements and changes to cybersecurity practices, to economic conditions shifting budget priorities, to advancing your own career, this conversation is the primer for a great year! Start off strong and don't miss this episode!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome cybersecurity expert and entrepreneur, Ed Vasko. Ed shares his insights from decades of experience and reveals a much-needed cybersecurity education model that he has built at Boise State University. With the cybersecurity industry experiencing a severe talent shortage, Ed is answering the challenge by improving the education model with innovative programs that equip students with real-world, hands-on experience. Regardless of whether you're a student, educator, employer, or tech professional, don't miss this episode!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Sorry to say it, but nobody else can secure your organization from the outside. The reality is, every company has a significant amount of work that must be done internally (by real humans) to build an effective cybersecurity and compliance program. Be wise when looking at tools and services implying that they'll take care of your cybersecurity for you. This week, the guys discuss the hands-on internal requirements every company should consider when preparing to build a cybersecurity program for the first time.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

When the calendar begins to turn, the infamous Cyber Rants crystal ball comes into view once more. This week, the guys discuss their predictions and cybersecurity trends in 2023. They share tips to stay ahead of the game while protecting your organization in the new year to come.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys (and "Skippy the Intern") are joined by special guest, Caren Shiozaki, to discuss cybersecurity considerations among executive teams and boards of directors. Caren shares her experience as a technology executive, insights at the leadership level, and emerging trends that are changing the thought process around cybersecurity and compliance.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cyber insurance is critical for risk management and the requirements are changing rapidly. With rate increases averaging 25-45% per year and many companies being declined for coverage altogether, this week the guys get the inside scoop with cyber insurance expert, Adam Guyton. Adam shares some important cyber insurance insights including how to get the most out of your policy, what to look for in your coverage, insurance carrier requirements, how to prepare for your renewal, and more.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome Founder and President of the Idaho Technology Council, Jay Larsen. They discuss his journey to building Idaho's premier tech organization, how technology councils help businesses thrive, the traits of a strong entrepreneurial ecosystem, and the benefits technology companies bring to their communities.

Visit www.idahotechcouncil.org for more about the Idaho Tech Council.
Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Unfortunately, there are some IT professionals who feel threatened when a 3rd party cybersecurity team is engaged. While it's the exception rather than the norm, there are both in-house and 3rd party IT professionals who become uncooperative, feeling as if security people are trying to poke holes in their work. While many IT professionals are very accepting of cybersecurity support, it should never be the case that anyone feels threatened. IT and cybersecurity are complementary disciplines. Good professionals not only strengthen the organization, they can even help each other grow in their own careers. This week, the guys share stories about walls going up and tensions growing, how to break down emotional barriers and eliminate the fear for better collaboration, the different personality types, valid sources of concern among IT professionals, and why nobody should ever feel threatened when their organization brings in quality cybersecurity support.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Thinking about a career in cybersecurity? This week, the guys share their thoughts about getting into the cybersecurity field. They share the pros and cons of the job, training and experience that helps along the way, how to find your first position or two, plus some reasons why cybersecurity is NOT a good career for some people. Chances are, you're probably closer than you realize to landing your first cybersecurity job.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

As technology's most widespread and trusted vendors are compromised, who can you really trust in today's environment? This week, the guys discuss attacks originating from compromised tech products, how the bad guys gain insider access, multi-factor authentication fatigue, and even a few hints at their love for Rick Astley.

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cloud services can offer tremendous benefits and cloud computing environments have become a standard across all industries. However, marketing hype leads consumers to believe that "the cloud is secure" by default and that someone else is taking responsibility for their protection. Too many people are quick to adopt cloud services without truly understanding the risks. This week, the guys discuss the risks and considerations around cloud services to help you ask the right questions and make wise decisions when moving to new technology environments.

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Ransomware can strike and infect your network at any given time, but we've noticed lately that ransomware attacks can spike during certain times of the year. This week, the guys talk about how Ransomware can be imployed on your devices, how to avoid these attacks, and even some horror stories from how ransomware has impacted major networks.

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

It's cyber risk assessment season! This is the time of year when many organizations seem to perform their annual cyber risk assessment. Unfortunately, the standard methods often result in limited visibility. This week, the guys discuss a more holistic risk assessment approach to make your cybersecurity program stronger than ever.

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss some cybersecurity trends, tips, and words to the wise that are timely and relevant in today's technology-centric world! They discuss:

  • Are attacks ramping up and if so, why?
  • The pros and cons of spending your cybersecurity budget on Black Hat and DefCon

Why you need specific objectives in your penetration testing, not just the numbers

  • The wrong and right way to establish vendor relationships
  • And more!

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Does your company recruit IT and cybersecurity staff with the same methods used to fill other positions? If so, don't miss this episode. This week, the guys welcome Cammas Freeman, an expert on finding and retaining the best technology professionals. Cammas shares a unique approach for recruiting the best talent, using a methodology that saves a tremendous amount of time and money. She also shares tips to build a strong culture for less turnover.

To Connect With Cammas:
Cammas Freeman
Founder & Executive Talent Strategist
stackrocktalent.com
cammas@stackrocktalent.com
208.412.6781

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cyber criminals are heavily focused on compromising backups so their attacks are as crushing and painful as possible for the victims. Good backups and the ability to quickly restore are a critical part of every infosec program but many organizations still treat backups as an afterthought. This week, the guys welcome the recognized authority on data backup W. Curtis Preston (aka. Mr. Backup) to reveal the backup and recovery trends he is noticing, tips organizations can implement to minimize risk, and what to look for in a backup solution.

For More On W. Curtis Preston:
LinkedIn - https://www.linkedin.com/in/mrbackup/
Restore It All Podcast - https://www.backupcentral.com
Free Book by W. Curtis Preston: Modern Data Protection - https://www.druva.com/ebook

Get the show notes and articles at www.CyberRantsPodcast.com
Pick up your copy of Cyber Rants on Amazon.
Need cybersecurity expertise and support? Visit us at www.SilentSector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss one of their favorite topics, Payment Card Industry Data Security Standards (PCI DSS)! Companies that transmit, process, or store credit card data need to be compliant but PCI has its own nuances. What level of PCI compliance do you need? How do you determine what is in scope? How do you work with auditors? The guys answer these questions and more, plus share some wizard-like tactics to help you maneuver through the PCI requirements.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Inflation and other economic factors are affecting companies large and small. Some organizations are cutting budgets but still have security and compliance requirements to maintain. This week, the guys discuss what organizations can do if they need to reduce spending, how to get the most bang for your buck, plus mistakes you don't want to make during turbulent times.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Picture this: You are a large organization with several, small subsidiaries that have different types of Cybersecurity protocols. How do you get them all under one roof? This week, the guys talk about inspecting different aspects of a large organization and assessing risk for one unit at a time to gain a larger image of the organization as a whole, to normalize cybersecurity organizational-wide.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys reconvene after a mini-hiatus and talk about some topics and tips in the news today such as

  • Goodwill Ransomware Hacking
  • Safe Browsing - the hidden dangers people need to know
  • A word to the wise about Wordpress (even though they supposedly "don't talk about wordpress")

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Is there really such a thing as "offense" in cybersecurity? This week, the guys discuss how it's possible to proactively protect organizations against criminals and how to identify potential attacks so you can stop them before it's too late. They share the realities of offensive cybersecurity and "hacking back."

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Think that cybersecurity is all about protecting data and achieving compliance? Think again! This week the guys share real-world examples about companies using cybersecurity to grow revenue, create a competitive advantage, and become market leaders! Learn how to use your cybersecurity program to create an outstanding return on investment!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys continue to walk through the NIST Cybersecurity Framework, by discussing the Detect, Respond, and Recover control categories. They rant about logging, SIEMs, and incident response when you're facing a worst case scenario.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

A cybersecurity framework is the foundation of any good cyber risk management program but many people are not familiar with what a framework really is and what they include. This week the guys reveal the importance of following an industry-recognized cybersecurity framework and begin walking through the National Institute of Standards & Technology Cybersecurity Framework (NIST CSF) as an example. You'll understand why cyber risk management is not a mystical "make it up as you go" approach but a methodical process with easy to access, readily available guidance.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss cybersecurity for healthcare companies. From medical facilities and laboratories, to MedTech, benefits companies, and healthcare services firms, the medical world faces its own set of challenges. The guys share thoughts and strategies around HIPAA compliance, dealing with deprecated medical technologies, and assessment practices to protect your healthcare company.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys discuss physical security controls (and lasers) to ensure that your organization is both secure and compliant! Cybersecurity doesn't stop at technology implementation. If you follow NIST 800-171, CMMC, PCI-DSS, or a number of other compliance requirements, you'll need to physically secure your premises to protect systems and data. Hear what the guys have to say about implementing physical security controls.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys are joined by Eric Adams, experienced CISO and FedRAMP Strategist discuss what precisely is FedRAMP, why should organizations consider it for their structure, and the steps to make it happen.

Follow Eric on LinkedIn Here - https://www.linkedin.com/in/eadams2/
Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys deviate a little from the usual format and discuss some of the latest trends in Cybersecurity, and rant on what's on their minds, no matter how off-topic it may be!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

It's a wild market for cybersecurity services, often confusing buyers and selling companies less than ideal solutions. The question is, what cybersecurity services are the best fit for your organization's needs? This week, the guys discuss the pros and cons of the common services to help you understand the best fit. From Managed Security Services Providers (MSSP) and Virtual Chief Information Security Officers (vCISO), to remote security teams and tailored Cybersecurity Program Development solutions, this episode covers the critical considerations for selecting the right cybersecurity service partner.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe

View Details

It is important to know what you're getting into when you invest in a cybersecurity services firm to help with security and compliance! There are critical considerations and points you must know in order to get the most from your cybersecurity services company.

This week, the guys discuss how to properly engage your cybersecurity firm to make sure your initiatives are met. They also share insights about what a cybersecurity company cannot do for you, plus how much time you or your team should expect to spend.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

What do you think of when you hear "Red Team vs. Blue Team"? Board or video games, military exercises, or cybersecurity terms? This week the guys discuss Red Teaming as it relates to cybersecurity and penetration tests, when Red Team Testing is an appropriate method and when other colors are better, plus the critical considerations you need to think through before engaging a cybersecurity firm to perform a Red Team Penetration Test.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In today's Cybersecurity Gold Rush, we see so many new technology products claiming to solve the world's problems and companies promoting the newest trend of the week. However, are the new tools and products really measuring up? What can technologies really do for you and when do you need the human element? This week, the guys discuss where tools provide great benefits and where they come up short, requiring the hands-on work of a cyber professional.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

The transition to a remote workforce has left many companies wondering how they'll achieve compliance with various requirements like CMMC, ISO 27001, and SOC 2. Meanwhile, remote workers have made it easier than ever for cyber criminals to attack. This week, the guys discuss securing a remote workforce and meeting compliance requirements, sharing principles that work across companies of all sizes.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys discuss some of the bigger cybersecurity struggles for mid-market and emerging companies. Developing an effective incident response plan is a major challenge and when done incorrectly, can cause a lot of damage. The guys also share struggles SaaS companies face when they're inundated with cybersecurity questionnaires that are holding up the sales process.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys reunite for the first episode of 2022 by taking a look into the future. With their crystal ball of predictions, the guys look into the future of cybersecurity, ranting about potential trends, exploits, and tips for you to stay ahead in the new year! Plus, they share some housekeeping tips and how to "tidy up" your cyber risk management program in the new year.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cyber insurance is a critical part of any risk management program and something that every company must have. Finding the right policy with the proper coverage can be tricky and the major insurance companies are not always the best fit. This week the guys talk with cyber insurance expert, Tony Robbins, about the fundamentals you must know to properly protect your organization. They cover how to identify a good insurer, what questions to ask when getting your policy, and how cyber insurance must correspond with your incident response plan.

Contact Tony Robbins at robbinsinsurancegrp@gmail.com

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cyber criminals can learn more about you than you ever realized. Open Source Intelligence (OSINT) often exposes information that you didn't realize was available to the public. Cyber criminals use OSINT to find weak spots in cybersecurity and exploit employees through social engineering. This week, the guys unwrap the fact that while Open Source Intelligence can be detrimental in the wrong hands, there are tools and methodologies that can be used to better protect your organization.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

If your organization is growing and is getting ready to build its own InfoSec team, this week's episode is for you. The guys discuss the "Who's Who" of cybersecurity, explaining the key players that growing organizations need when maturing their cybersecurity programs. From Chief Information Security Officers to Architects, Engineers, and Project Managers, the guys share who's who in each position, plus the required skill sets, responsibilities, and proper staffing models.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Is being compliant the same as being secure? If you're meeting all the requirements, are you adequately protected? This week, the guys discuss the differences, nuances and overlaps between cybersecurity and compliance, plus how you can simplify alignment to multiple compliance requirements.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Are your executives and board members struggling to understand cyber risk? This week, the guys are joined by David Moon of Arx Nimbus, a company that turns cyber risk into the language that all business leaders understand. David shares how they translate cybersecurity into financial metrics that allow organizations to make better risk management decisions. The guys discuss how companies can create tremendous clarity around cyber risk, resulting in better support and resource allocation.

For more information on Arx Nimbus, visit https://www.arxnimbus.com

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys discuss the good steps forward that are making the cybersecurity industry strong, from awareness to technologies, education to growing the workforce. They share the silver linings in the turmoil, plus some areas for improvement in the industry.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome a new member to the team, longtime technology professional, David Baker! They discuss his experience in helping small businesses with IT and security, plus the challenges SMBs are facing with new cybersecurity and compliance requirements. This episode is perfect for any businesses struggling with stepping into today's IT and cybersecurity standards.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss wireless penetration testing and explain many of the common findings that are revealed through the testing process. They provide an indepth look at how wireless penetration testing works and why certain organizations should make it a part of their annual cyber risk assessment process. If you're wondering about the risks associated with your wireless environment, this is not an episode to miss!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

There is a lot of news about cyber attacks but the big question is, "Do people actually care?" This week the guys rant about cyber crime and how it affects people and companies who often don't care until it's too late. Through real-life examples, horror stories, and tips to help you stay protected, this episode is not one to miss!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys share what Silent Sector is all about, from the origins of the company to what makes the services and methodologies stand apart. The guys share their "why" behind what they do and what they are working to change in the world of cybersecurity. This episode is perfect for anyone wanting to know about Silent Sector at a deeper level.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys share simple tips that individuals and very small businesses can use to protect themselves and their data from cyber criminals, even without any technical background or experience! These are the basic cybersecurity measures that everyone should follow.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys share what they saw in the cybersecurity and IT industries from the start of COVID to the current day. They share what went poorly as well as lessons learned and why our Nation's cybersecurity will come out stronger than pre-COVID.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

For some organizations, vendor vetting for cyber risk management is a process that runs like a well-oiled machine. For most, it's a tedious and challenging nightmare. This week, the guys discuss the vendor vetting process from both sides, vetting your vendors and navigating the vetting process of your prospects. They share how organizations of all sizes can use the vetting process to their advantage.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss technical controls to protect your employees and protect your company from its own employees. From honest mistakes to gross negligence and malicious activity, proper protections minimize employee related cyber risk. The guys also share tips for configuring and issuing devices to your team members, which is especially critical for those working from home.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome Heather Monthie, PhD, who's illustrious career has blended her passions for cybersecurity, aviation, and education. She has been an integral part of K-12 and university education systems, developing STEM programs that build a stronger technology workforce.

Heather shares her insight about the world of cybersecurity education, plus valuable advice and resources for anyone looking to work toward a career in technology.

Learn more about Heather: www.heathermonthie.com.

Find her podcast: www.CyberCoffeeTalk.com

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Nobody loves cybersecurity governance documentation like we do! This week, the guys discuss cybersecurity policies and why the proper policies make all the difference for security, compliance, and audits. Plus, learn what documents are most important, why the "one size fits all" cybersecurity policy templates don't work, and how to build documentation to your exact needs.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

From PII and PHI to intellectual property and sensitive business information, the guys talk about how to keep your sensitive data from leaking to the outside world.
While there is no single answer, they cover both technology and governance tips to keep your data where it belongs. Plus they rant to everyone, "Don't be a data hoarder!"

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

What's the difference between having an Incident Response Plan and just "winging it"? This week the guys talk about their real world cybersecurity incidents and share their knowledge about proper planning and preparation. Learn what goes into incident response planning, who should be involved, and how to ensure everyone is on the same page for quick response and minimizing damage during a cyber attack.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys take a deep dive into the intricate world of Cyber Risk Assessments. They cover best practices from choosing an industry recognized cybersecurity framework, to scoping and preparing for your cyber risk assessment, plus how to make cybersecurity standards like NIST, CSF, and CIS Controls work for your company.

They discuss how these assessments work for different purposes and what to expect when you're planning for your first Cyber Risk Assessment.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Cybersecurity is critical for financial services organizations but many mid-market and emerging companies struggle tremendously with their cyber risk management programs.

This week, the guys talk about cybersecurity programs for financial institutions, sharing specific considerations for the industry including staffing, risk assessment, penetration testing, and compliance. Financial services companies are an attractive and highly targeted sector for cyber criminals. It is also an industry where Zach, Mike, and Lauro have a deep history

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys talk about a topic that everyone loves, PCI (Payment Card Industry) Compliance! They rant about PCI-DSS compliance levels and standards, plus what first timers need to consider when preparing for a PCI audit. They share tips about how to make your PCI compliance process simpler throughout the year and how to deal with the QSA (auditor), especially when the auditor doesn't understand your environment.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss cybersecurity for healthcare organizations. They dispel the myth that healthcare cybersecurity is completely unique while also sharing the healthcare nuances that don't apply as frequently in other industries. From healthcare risk assessment to policies, HIPAA compliance, and even physical intrusion testing, the guys share their experience and points of view on healthcare cyber risk management.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

There's no "right way" to get started in cybersecurity but there are a lot of different paths. This week, the guys talk about their career paths starting from the ancient IT world and moving into modern day cybersecurity disciplines. They share some of the most important skill sets that you rarely hear about, plus tips and tricks to succeed.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Zach and Lauro discuss 10 common cybersecurity myths that are causing business leaders to make poor decisions and making companies an easy target for cyber criminals. They clear up these myths and share how you can be better informed if you hear something that doesn't sound quite right.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss Social Engineering - the most common way cyber criminals get access to their targets. They discuss the controls smart companies are implementing to prevent their staff from falling for cyber criminal scams and how to minimize exposure resulting from human error.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys welcome back Ed Escobedo, former Head of Technology Risk Management for PayPal, CIO of Apollo Education Group, VP for DHL and Charles Schwab, and currently Silent Sector's Chief Strategy Officer. They share how to bust through the growth roadblocks that CISOs hit when improving their organizations' cybersecurity programs. They also share the unique Organizational Adoption Framework and Methodology(TM) that Silent Sector uses to bring established cybersecurity programs to the next level.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys dive into the rapidly growing topic of SOC 2 Audits. The SOC 2 Audit is widely becoming a requirement for B2B technology companies serving large enterprise clients. As both SOC 2 auditors and the guys who help companies prepare for audits, they cover common misconceptions such as the SOC 2 being all about IT security. They talk about the important factors to consider when undergoing the audit for the first time such as scope, timeline, and even auditor selection.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys dive into all the "fun" requirements that U.S. Government defense contractors are facing when working with Controlled Unclassified Information (CUI), including the NIST 800-171 Self-Assessment and getting CMMC certificatied. They share their insights and experience about how organizations align to these requirements and what's involved.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Companies are turning to Virtual CISO and CISO as a Service providers for help as cybersecurity requirements continue to grow. Is hiring a vCISO always the right option?
What are the pros and cons? How do you find a good one? This week the guys answer these common vCISO questions and more.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

The "cloud" is arguably one of the most common topics of discussion in technology today, primarily for its cost savings and accessibility benefits. However, it's also a hot topic for cybersecurity professionals and not always for the best reasons. This week, the guys discuss cloud considerations for organizations of all sizes, providing recommendations for transitioning to the cloud, safely storing information, and avoiding data loss nightmares.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week in the final part of our Penetration Test Mini-Series, the guys discuss the realities of automated vs. manual penetration tests and what those terms actually mean. They also talk about timeframes, approaches, and situations that seem to cause some confusion for companies undergoing their first penetration test.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys continue their penetration testing discussion, covering the following common questions:

How often should your organization conduct a penetration test?
What's the right approach, red team or purple team?
What should you see in your penetration test reports?

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week we take a deeper dive into penetration testing. The guys discuss why it's important to consider the reason behind a penetration test and some different methods of testing to consider. In addition, they cover options that companies can take in their testing initiatives, along with providing best practices for companies getting their first pen test.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Penetration tests are vital for nearly every organization to see how secure they really can be. While the demand for them is higher than ever, it can be a bit tricky on deciding what test which penetration test provider is best for you, along with figuring out if a penetration test is right for you. This week, the guys answer these questions and give their own advice on how to guide yourself through the world of Penetration Tests.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week the guys discuss why it's vital for an organization to have Network Architecture Diagrams, discuss best practices for building them (scotch can help), and explain why a little effort now will make your work life so much better.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

There is a lot of talk about "proactive cybersecurity" but what does that really mean and is it better than reactive security? On this week's show, the guys discuss proactive versus reactive cybersecurity considerations and where to focus.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

The guys talk with Haidon Storro, who brings a different point of view to the conversation. Haidon is an exceptionally motivated cybersecurity professional who recently graduated college and started her career. She shares her journey from finding a passion in technology, to getting educated and finding her first full time role in the industry. It's a highly competitive market for finding talent and Haidon insights are critical for employers to understand when trying to recruit junior team members.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Compliance. It's not the most attractive topic to discuss but for most organizations, it's a necessity. This week, the guys discuss compliance obstacles and pitfalls, how to overcome them, plus the investment that provides the biggest returns when it comes to cybersecurity compliance. Whether you're faced with PCI, CMMC, SOC 2 audits, GDPR, CCPA, or any other set of requirements, the fundamentals are the same and this episode is for you.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Are we losing the war against cyber crime? What does winning look like? Where does the U.S. stand on a global spectrum of cyber protection? This week the guys discuss these alarming yet valid concerns.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

How do you find the right people when other companies can pay them more? How do you make your rock stars want to stay? Does it make sense to hire a Senior VP of IT when they will also be handling the help desk function? What about entry-level staff running critical functions?

This week, the guys discuss the importance of finding and hiring the best talent for your company's cybersecurity program, along with sharing best practices to make your team the best in the industry!

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss one of their favorite topics the comes up frequently in the CyberSecurity World: The difference between companies reaching out to meet compliance, rather than aligning to a secure Cybersecurity Framework, and how being compliant does not always mean being secure.
They give tips and tricks on which framework would be best for your company, along with their own experience on the struggles in this topic.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, the guys discuss a disconnect between employees working remotely and their corporate IT departments hindering productivity for both parties, along with how the debate between IT providers leaning towards a self-service model for IT help.

In addition, the guys discuss the recent shutdown of Parler and the issue of companies relying on a cloud-based server, instead of relying on its own hardware.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Zach, Lauro, and Mike welcome 2021 by diving into one of their favorite topics, Cybersecurity Implementation Models. They discuss the different ways companies build cybersecurity programs and considerations to find right method for your organization. Whether you're considering a DIY approach, hiring a cybersecurity firm, or getting a vCISO, this episode rants about the pros and cons of each.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

In the last episode of the year, Zach, Mike, and Lauro discuss the benefits of performing certain cybersecurity tasks earlier in the year rather than waiting for the last quarter. They also discuss tips and tricks to avoid cyber criminals around the holiday season, along with what they liked and loathed in the year of cybersecurity news and blunders, plus their holiday wish lists.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week Zach, Mike, and Lauro rant about the pitfalls of the "arms race" of new cybersecurity tools. In addition, they propose strategies for evaluating and implementing cybersecurity tools with a holistic approach instead of chasing the shiny new products that promise to answer all problems.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week, Zach, Mike, and Lauro discuss the misperception of the critical points on what can happen if companies choose to not take Cybersecurity seriously, how it can affect more than a bottom line for a businesses, and what steps businesses can take to thwart initial attacks and protect themselves from Cyber Criminals.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Zach, Mike, and Lauro discuss using cybersecurity as an asset and competitive advantage to drive revenue, rather than just a necessary cost. They cover the ins and outs of cybersecurity questionnaires that all B2B tech companies get when they're trying to land enterprise clients. The team discusses the proper precautions and steps needed to align your company with the best cybersecurity framework, plus navigating potential audits and avoiding security pitfalls.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This Week: Zach, Lauro, and Mike discuss how Cybersecurity professionals can be active with organizations in their cybersecurity approach, along with encouraging continuing education and participation by other employees in the workforce.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This Week, Zach, Lauro, and Mike discuss the steps needed to create a proactive security posture, especially when creating a cybersecurity program for the first time. In addition, we also provide tips on how to create a plan of action when implementing your cybersecurity program to make it the right fit for your company.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week - The guys discuss how to build a Security-Conscious Culture in your organization, along with some of the successes and failures that occur in the process. In addition, they talk steps to implement your your security program, beginning with leadership support.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

This week - Ed Escobedo joins the podcast to discuss his journey to joining the Silent Sector team as Chief Strategy Officer and what lesson’s he’s learned while implementing programs for companies like PayPal and Apollo Education Group, plus the importance of translating the value of cybersecurity to CFO’s and other organizational leaders.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Episode 2: Lauro, Mike, and Zach reveal the biggest failure that companies make when it comes to cybersecurity. We discuss what steps leaders can take to implement a program within their organization. The team also provides ideas for companies to use additional incentives with staff in order to help minimize cyber risk related to the human element.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!

View Details

Episode 1: In our introduction episode, we discuss our book “Cyber Rants: Forbidden Secrets and Slightly Embellished Truths About Corporate Cybersecurity Programs, Frameworks, and Best Practices.” We discuss reasons why corporate cybersecurity programs fail and how some organizations do not receive the right guidance or education to get the best cybersecurity protection for their needs.

Pick up your copy of Cyber Rants on Amazon.
Looking to take your Cyber Security to the next level? Visit us at www.silentsector.com.
Be sure to rate the podcast, leave us a review, and subscribe!