UNSECURITY: Information Security Podcast: Recent Episodes

InfoSec Missionaries

Weekly information security podcast airing Monday mornings hosted by Evan Francen and Brad Nigh. In a unique focus on protecting personal information, Evan and Brad discuss information security as an issue that includes cyber security, physical security, as well as administrative controls. Evan is the CEO of FRSecure and the author of the book UNSECURITY (publish date December, 2018). Brad is the Principal Security Consultant at FRSecure and a 20+ year veteran of the industry. Hosting things like FRSecure's Certified Information Systems Security Professional (CISSP) Mentor Program, online hangouts, and other events together, the chemistry in their banter is sure to delight!

View Details

Welcome to Episode 260 of the Unsecurity Podcast!

Join hosts Brad Nigh and Megan Larkins as they sit down with special guest Mea Yang, an Information Security Consultant at FRSecure.

The conversation explores the pipeline problem from multiple angles — from early interest and industry perception to hiring bias, retention challenges, and the lack of women in leadership. They unpack how cybersecurity teams can move beyond the “cookie-cutter” hiring mindset and build stronger defenses through broader experience, better culture, and more intentional growth opportunities

Discover insightful discussions on:
* The current state of women in cybersecurity and the industry's talent shortage. * Cultural expectations and barriers affecting the progression of women in tech fields. * The importance of diversity in cybersecurity teams for enhanced problem-solving and defense. * Strategies for increasing female representation and retention in cybersecurity roles.

Whether you're in the industry or just interested in the topic, this episode is packed with valuable perspectives and actionable insights. Don't miss out on this important conversation about inclusiveness and growth in the tech world! Tune in to expand your understanding and join the conversation on creating a more inclusive cybersecurity industry.

Be sure to like, subscribe, and hit the notification bell for more insightful episodes.

UnsecurityPodcast #Cybersecurity #WomenInTech #DiversityInTech #Inclusion #FRSecure

We want to hear from you!
Reach out at unsecurity@frsecure.com and follow us for more:
LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, we unpack the Cyber Resilience Act and why it’s becoming a critical framework for anyone building or selling digital products in today’s connected world.

Megan talks with Madalin Neag and Christopher "CRob" Robinson about open source security, software supply chain risk, software bills of materials, and why passive consumption of open source is no longer enough.

The conversation also explores how AI is changing software development and cybersecurity—and why human judgment, upstream contribution, and responsible implementation still matter more than ever.

If you want a practical, thoughtful look at how regulation, open source, and AI intersect, this episode is for you.

Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!

We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins speak with Brian Kelley, information security consultant at FRSecure and one of the infamous CISSP Mentor Program's leads this year. Together, they talk about Brian's journey in information security and how it led him to helping support the FRSecure CISSP Mentor Program.

Hear the trio discuss:
* Working in IT and finding interest in information security * Security focuses at MSPs * Paying help forward * Studying tips and finding resources * Picking your exam date * The CISSP Mentor Program's format and evolution

While the program has already begun, you can still get all on-demand materials and join the rest of the live mentor sessions by signing up at https://learn.frsecure.com/courses/2026-cissp-mentor-program!

Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!

We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins speak with Samantha Floyd, an associate penetration tester and active member of Blacks in Cyber and Black Women in Cyber.

Together, they talk about Samantha's shift from marketing to the cyber industry, including:

  • The thrill and ethics of hacking and CTFs
  • The power of inclusive communities
  • Reducing barriers and amplifying diverse perspectives
  • Practical web app pen testing insights
  • Challenges pen testers face
  • The importance of support and mentorship in career transitions

Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!

We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:
* LinkedIn: https://www.linkedin.com/company/frsecure/ * Instagram: https://www.instagram.com/frsecureofficial/ * Facebook: https://www.facebook.com/frsecure/ * BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

The Unsecurity Podcast is back for our annual discussion with Pinky, FRSecure's Incident Response Manager, to discuss the "Breachmas" season.

Breachmas is a time of year or a phenomenon when attackers pull a few more levers available to them—more people on PTO, increased online spending, and general busyness contributing to less focus. The result is an uptick in cyber incidents nearing the end of each calendar year.

As the team lead of FRSecure's blue team, Pinky lives and breathes incident handling. Each year, we like to get his perspective on how Breachmas has changed or evolved to stay better informed on how to protect our clients (and ourselves). This is a reflection of what we saw at year-end 2025, along with suggestions moving forward!

In this episode, learn about:
* Resurgence of Ransomware * Importance of Conditional Access * Taking a Layered Approach to Security Tools * Logs, Baselining, and Anomaly Detection * EvilGinx and Token Theft Attacks * New This Year: Extortion and AI

Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!

We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

The Unsecurity Podcast returns with a truly joyful conversation with FRecure's own Jo Moldenhauer.

Jo, an Associate Information Security Consultant, is famous around the FRSecure office for her weekly security news reviews, where she meticulously compiles articles and talking points for a company-wide discussion around industry trends and snapshots.

And this couldn't have been easy to do. Jo's path to InfoSec is a recent and unique one—transitioning from dealing blackjack at casinos after most of them ceased operations during the COVID-19 pandemic. You can see how being tasked with leading a discussion to 75+ industry pros like this as a relative newcomer could be challenging—but Jo simply crushes it.

In this episode, learn about:
* Non-traditional information security career paths * What makes "good" InfoSec news * Why talking about industry news is important to FRSecure (and beyond) * How vCISO engagements and risk assessments guide talking points * The Gaming (casino) and InfoSec industry Venn Diagram (and what they can learn from each other) * User and security awareness training, culture, and incentive ideas

Like, subscribe, and share with your network to stay informed about the latest in cyber and information security!

We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

A slow-rolling holiday episode featuring CISO at DataSite, Ted Peterson! Transitioning from a Director Role, Ted shares his journey to the CISO title and how his unique background informs his work approach.

Tune in for insights on:
* Realities to navigating organizational leadership as a CISO * Importance of diverse perspectives and backgrounds in the security space * Establishing pathway to career goals

Like, subscribe, and share with your network to stay informed about the latest in cybersecurity! We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Kyle “caboose” Waters of Cyber Unicorns enlightens this extended episode! Having a combined passion for people and security, Kyle demonstrates how to effectively educate the masses. Steering away from typical training and using unique approaches, this talk explores how to break through the barriers that create vulnerabilities.

Like, subscribe, and share with your network to stay informed about the latest in cybersecurity! We want to hear from you!

Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

A live panel from Hacks & Hops featuring FRSecure's CFO, Vanae Pearson, Information Security Consultant, Greg Cloon, and Director of IT at Miner's Inc., Tyree Johnson.

Veterans in the field discuss consulting, translating security needs to executive teams, and advocating for the best budget practices.

Like, subscribe, and share with your network to stay informed about the latest in cybersecurity! We want to hear from you!

Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Coming off Cybersecurity Awareness Month and into the holidays, this season is the perfect time to reflect on personal cybersecurity practices. Information Security Consultant, Coral Morgan, and IR Case Manager, Cory Hanks, join this episode to provide tips and cybersecurity practices for all age groups.
Like, subscribe, and share with your network to stay informed about the latest in cybersecurity! We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Celebrating 250 episodes of Unsecurity, Megan and Brad go live at Hacks & Hops with former hosts and leaders of FRSecure, Evan Francen and Oscar Minks.

Stories of navigating the growing team and the evolution of Unsecurity weaves personal testimonies of leadership, trust in self, and growth. This is a milestone episode you won’t want to miss!

Thank you to our listeners for the support! Reach out at unsecurity@frsecure.com and follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosted by Megan Larkins and Brad Nigh from FRSecure, we are joined by Pinky from the IR team to dive deep into the pressing cybersecurity challenges as the holiday season approaches.

From early breaches to the increasing sophistication of AI in phishing attacks, discover how attackers are evolving their tactics. The trio discusses the impact of VPN vulnerabilities, the rise of AI-enabled chatbots in ransomware scenarios, and how businesses can prepare for the uptick in threats during this busy time of year.

Whether you're an IT professional or just curious about cybersecurity, this episode is packed with valuable insights.

Don't miss out!

--
Like, subscribe, and share with your network to stay informed about the latest in cybersecurity!

Looking to get in touch? Reach out at unsecurity@frsecure.com and follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Join us for another episode of the Unsecurity Podcast as Megan, Brad, and Seth Bowling, lead researcher and developer at FRSecure, dive into the evolving landscape of cybersecurity for city and county governments.

Seth shares how Mirrored Defense's innovative heat map visualizes the attack surface across the U.S. and presents surprising findings from their research. The trio discusses the challenges and vulnerabilities faced by local governments, the importance of proactive security measures, and how Project Broken Mirror aims to raise awareness by providing public service solutions.

The crew also discusses Seth's efforts to kick-start FRSecure's vulnerability management and conditional access policy initiatives.

Whether you're a cybersecurity professional or an interested citizen, this episode offers valuable insights into protecting our critical infrastructure.

Don't miss out on this engaging discussion and find out how you can get involved!

--
Like, subscribe, and share with your network to stay informed about the latest in cybersecurity!

Looking to get in touch? Reach out at unsecurity@frsecure.com and follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins are joined by special guest Jim Nelson from FRSecure to dive deep into the world of cloud security. Whether you're using AWS, Azure, or GCP, understanding the right security protocols is crucial. Jim, a subject matter expert in cloud assessments, CIS benchmarks, and cloud infrastructure, shares valuable insights on common security pitfalls and best practices to enhance your cloud security posture.

Topics Covered:
- Introduction to cloud security challenges and opportunities.
- Key areas often overlooked in cloud infrastructure security.
- The importance of proper configuration and ongoing monitoring.
- Best practices in identity and access management.
- Effective data protection and governance strategies.
- The significance of continuous vulnerability management.
- Real-world experiences and lessons from security assessments.
- Tips for leveraging CIS benchmarks and security frameworks.
- Insights into collaboration security and conditional access policies.

Join us for a comprehensive discussion that offers actionable advice to elevate your security efforts in the cloud. Perfect for InfoSec professionals and organizations looking to bolster their cloud security strategies.

Here are some resources to help get you started:
FRSecure's Cloud Security Checklist: https://frsecure.com/cloud-infrastructure-security-checklist/
The CIS Benchmarks: https://www.cisecurity.org/cis-benchmarks

Don't forget to like, subscribe, and share with your network to stay informed about the latest in cybersecurity!

--
Looking to get in touch? Reach out at unsecurity@frsecure.com and follow us for more!
LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this Friday edition of Unsecurity, Megan and Brad tackle Policy! They approach a topic commonly avoided with a consulting perspective, having real examples of policy benefits.

Hear the full coversation, covering:

  • Standardizing programs, documentation, and access
  • The relationship between technology and policy development
  • Legal considerations
  • Executive support and how to engage leadership

and the necessity of clear policies to guide organizational behavior and ensure security compliance and best practice.

Looking to get in touch? Reach out at unsecurity@frsecure.com and follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/ FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Returning from this year's DEF CON, hear from our Offensive Team Managers, Dowd and Findlay, and Pinky, IR Manager and co-host of The Hackle Box. Hear about new highlights, CTF's, and villages, and reflection from Brad as a Blue Team member navigating past challenges.

Have something to say? Contact us at unsecurity@frsecure.com and follow us for more!

LinkedIn: frsecure
Instagram: frsecureofficial
Facebook: frsecure
BlueSky: frsecure

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

We're back! Pen Tester and Team Ambush member Morgan Trust walks us through his journey into the cybersecurity field. With a can-do approach, Morgan discusses how he has developed professionally, expanding his expertise across public speaking and competitive hacking.

His presentation, "The New Era of Deception: AI, Deep Fakes, and The Dark Web" has hit many a stage with these essential points to keep in mind:

  • AI is increasingly being used in sophisticated phishing attacks.
  • Cybersecurity practices should be proactive; be prepared for a situation
  • Understanding the evolving nature of cyber threats is vital.

Enjoy this episode featuring a balance of hobby pursuits, shared experiences in security, and informative points.

We want to hear from you! Contact us at unsecurity@frsecure.com and follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Attorney Heidi Fessler is this week's guest! Practicing law for 35 years and specializing in cybersecurity, Heidi walks us through the right time to engage legal, navigating incident response, distinctions between general and cyber counsel, and cyber law.

Thoughts on Unsecurity? Contact us at unsecurity@frsecure.com and follow us for more!
LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

You hear it everywhere: the buzzing hot-topic, AI, lands on this week's episode with featured guest, Jim Wilt! Brad returns with Megan to hear from the AI Guy himself. With an introduction to AI in the 90s, Jim shares his expertise as a technologist and early adopter of the tool.

Whether you have a place in tech, executive space, or creative, get key takeaways on:
-AI impact & bias
-Advancing usage and tools
-Generative AI & LLMs

and its implication in the security realm.

We want your feedback - Be sure to reach out at unsecurity@frsecure.com and Follow us for more!

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

How can you approach your company's leadership to advocate for best security practices? Megan dives into a BIA (Business Impact Analysis) breakdown with triple guest features from FRSecure's Consulting Team. Mea Yang, Coral Morgan, and Kathryn Frickstad-Olson recall client trumphs and challenges they have witnessed with implementing BIAs.

Whether you need a 101 course in BIA Practices, want a little guidance with a company conversation, or simply want to learn more about a BIA's purpose and value, this episode is for you!

Access our free BIA Starter Kit by downloading today!
FRSecure BIA Starter Kit

--

As always, let us know what you'd like to see next! Send your thoughts to unsecurity@frsecure.com.

Follow for more!
LinkedIn: FRSecure
Instagram: FRSecureOfficial
Facebook: FRSecure
BlueSky: FRSecure

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Special guest & performance coach Dr. Cindra Kamphoff explores with Megan and Brad mental practices to thrive in demanding environments like IT and Cybersecurity fields.Through her work with companies like Verizon, the Minnesota Vikings, and Mayo Clinic, Cindra unpacks tools for resilience, confidence building, and facing setbacks.

From the "Learn, Burn, Return" method to understanding Imposter Syndrome, this conversation prompts action and provides strategies for thriving under pressure that can apply to anyone. Enjoy this episode of Unsecurity!

We want to hear from you! Send your suggestions, comments, and questions to unsecurity@frsecure.com.

LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/ FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

We're back! It's time for a "Meet The Mentor" session with our newest CISSP Program Instructor, John Kennedy.

From joining the Air Force to being an ISSM and a cybersecurity mentor, John transports us from his challenges in tech to now leading live sessions, the pressure of building slide decks, and why giving back is essential to him and the security field. Listen to hear John's success story and get a glimpse into to this year's CISSP Cohort!

For more information on FRSecure's CISSP Program, visit our webpage:
https://frsecure.com/cissp-mentor-program/

And register for this year's cohort through our event page!
CISSP Program 2025 Registration
--
Continue to stay connected with our happenings through our social platforms!
LinkedIn
Instagram
Facebook
BlueSky

About FRSecure: https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

This week on Unsecurity, Senior Offensive Security Engineer Sean Behan sits with Brad and Megan to dissect Air Gapping. Starting with the development of the Air Gap method, they discuss its evolution and the pros and cons of each type.

Tune in for an engaging discussion on understanding systems operations, strengths, and weaknesses of air gapped networks.

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins are joined by Melissa Kjendle, Assessor Manager at FRSecure, to recap our recent HERoic Hacks event. Melissa spoke at the event, highlighting the significance of inclusive and diverse perspectives in cybersecurity—particularly focusing on the growing role of women in the field.

Together, the three delve into the dynamics of security culture and education. The conversation covers the importance of fostering a security-conscious environment within organizations, the role of leadership in supporting this culture, and how storytelling can make security training more relatable and memorable.

Tune in for an engaging discussion on building a resilient security culture and empowering individuals with the knowledge to protect themselves and their organizations.

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, hosts Brad Nigh and Megan Larkins are joined by Melissa Kjendle, Assessor Manager at FRsecure, to recap our recent HERoic Hacks event. Melissa spoke at the event, highlighting the significance of inclusive and diverse perspectives in cybersecurity, particularly focusing on the growing role of women in the field.
Together, the three delve into the dynamics of security culture and education. The conversation covers the importance of fostering a security-conscious environment within organizations, the role of leadership in supporting this culture, and how storytelling can make security training more relatable and memorable.

Tune in for an engaging discussion on building a resilient security culture and empowering individuals with the knowledge to protect themselves and their organizations.

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

With two guest features, Scott Singer from CyberNINES and FRSecure's own Security Information Consultant, Ryan Abraham, this week's episode focuses on CMMC's recent changes, enforcement, and compliance requirements.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

April Meyer, Information Security Consultant, shines light on the recent initiative of HHS Cybersecurity Performance Goals.

*Note: This Unsecurity Episode was recorded in August 2024. CPGs are currently voluntary and it is expected that requirements be added through HIPAA in 2025.

Read more about the HHS CPG's in our blog:
HHS Cybersecurity Performance Goals: Context and 2 Comprehensive Checklists

About FRSecure
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we areready to serve.

View Details

In this special Edition of Unsecurity, Key Account Manager Tonya Barnes speaks on the creation of HERoic Hacks, the infosec conference that empowers women in the field.

About HERoic Hacks:
Envisioned by Tonya, and supported by FRSecure, HERoic Hacks addresses the gap in representation by providing networking opportunities, expert speakers, and award recognition with notable infosec organizations and leaders! This year's HERoic Hacks will feature keynote speaker Connie Hiber, Director of Technology Governance at GreatClips!

Interested in Sponsoring or Attending?
20% of sponsorship fees will support women-led organizations WiCys and MN Women in Tech! Visit the event page to register now and sign up to sponsor. Spots are limited!

https://www.eventbrite.com/e/heroic-hacks-tickets-1083192711559?aff=oddtdtcreator

About FRSecure https://frsecure.com/ FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Join us in the new year as FRSecure's Incident Response Manager, Pinky Thompson, joins to recap Breachmas 2024. The group discusses LDAP, recent cyberattack trends, Evil Jinx, and more.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Brad returns with Megan to talk 2025 predictions with former Unsecurity host Evan Francen and President of FRSecure, Oscar Minks. They discuss potential effects of new administration and AI.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this special holiday-themed episode, Gary Berger, Director of Information Security for Ogletree Deakins Law Firm, joins Megan to go over what a CISO wants for Christmas.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

This week, CEO, Nicole Salazar and Founder, Dr. Baljeet Malhotra of TeejLab join Megan and Brad to discuss all things Open Source and API Risk Management. Along with a brief review of Dr. Malhorta's background, the group discusses TeejLab's origins and discuss a new API workshop.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

This week, Unsecurity hosts are joined by CTO of Recon InfoSec, Andrew Cook. They discuss Andrew's journey into the InfoSec field and Recon InfoSec's approach and value.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, FRSecure's CFO, Vanae Pearson, and Illumifin's Chief Security Officer, Randy Kaedar are guests. The group discusses how to prompt key decision makers and executive teams to make the most effective security decisions.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure: https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Associate Penetration Tester Victoria Fogarty joins Megan and Brad to walk through how to buy in for InfoSec programs with an executive team.

Don't forget:The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/ FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Hosts of "Unsecurity" podcast, Megan Larkins and Brad Nigh, join Evan Francen and Michael Kennedy of "Sunsets and Snowdrifts" for a crossover panel.

Find the event slides here: https://info.frsecure.com/hubfs/FRSecure_Hacks%20and%20Hops_Master%20Deck-1.pdf

We look forward to seeing you next year! To stay updated about Hacks & Hops 2025, check our site. hacksandhops.com

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Brad and Megan recap Blackhat. They also discuss a zero-click exploit involving a Windows TCP IP flaw and backdoor Bitsloth exploits.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Brad and Oscar are joined by a new host, FRSecure's Megan Larkins!

Together, they discuss the recent CrowdStrike outage and its illustration of the importance of understanding your application inventory and dependencies—and the need for proper application allow listing and conditional access policies to prevent attacks.

00:00 Introduction and Weather Conversations
03:02 Introducing Megan as the New Co-host
04:00 Discussion on the CrowdStrike Outage
17:33 The Need for Application Inventory and Allow Listing
22:28 Starting with Critical Assets and Rolling Out Application Control
28:16 The Importance of Proactive Measures
31:22 Shoutouts to Spouses and the FRSecure SMT Team
32:48 Conclusion and Farewell

Don't forget: Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, the guys sit down with Michael Kennedy of Ostra to discuss burnout and share their personal experiences and strategies for preventing and managing work-related stress.

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Brad, and Oscar discuss the CISSP Mentorship Program with Brian Kelley now that this year's course has officially wrapped up, and touch on challenges and roadblocks for security professionals in the job market.

00:00 Intro
01:56 Ransomware and Security Best Practices
06:32 CISSP Mentorship Program and Learning Journey
25:32 Challenges of Information Security Professionals
27:31 The Journey to Becoming a Security Consultant
35:04 The Complexity of Job Postings and Hiring Challenges

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Brad, Oscar, and Pinky discuss recent news stories about IP and central manager flaws, as well as a vulnerability enrichment project by CISA.

They also share an interesting incident response story involving internal domains and proxy auto-configuration files.

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

In this episode of the Unsecurity Podcast, Brad interviews guest Ryan Cloutier as part of our Meet the Mentors series.

They discuss the importance of the CISSP Mentor Program and the value of different perspectives in teaching. They also discuss the release of an exploit code for the Palo Alto Networks Zero Day vulnerability and the ethics of publicly sharing vulnerabilities.

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 218 of the Unsecurity Podcast is now live!

This time, Brad is joined by Ron Woerner for another episode of our "Meet the Mentors" series introducing the 2024 CISSP Mentor Program instructors!

Links & information:

Find Ron on LinkedIn
https://www.linkedin.com/in/ronwoerner/

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 217 of the Unsecurity Podcast is now live!

This time, Brad is joined by Chris Foulon for the first episode in our "Meet the Mentors" series, introducing our 2024 CISSP Mentor Program instructors!

Links & information:

Chris's Podcast (Breaking Into Cybersecurity)
https://podcasts.apple.com/us/podcast/breaking-into-cybersecurity/id1463136698

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 216 of the Unsecurity Podcast is now live! This time, Oscar and Brad are joined by FRSecure's Matt Dowd to discuss the difference between vulnerability scanning and penetration testing.

Links & information

Cisco Critical Vulnerabilities
https://www.securityweek.com/cisco-patches-critical-vulnerabilities-in-enterprise-communication-devices/

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure

https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 215 of the Unsecurity Podcast is now live! This time, Brad is joined by FRSecure's Dave Tuckman to discuss an upcoming webinar series about securing home networks with ISACA and select FRSecure staff leading the sessions.

Links & information

ISACA home network webinar series:
* Session 1: 2/12 - Household Computer Safety, Using The Internet Safely https://isaca-sd.org/events/2024-02-12 * Session 2: 3/11 - Choosing and Protecting Your Account Login, Securing Mobile Devices https://isaca-sd.org/events/2024-03-11 * Session 3: 4/8 - Securing Wi-Fi, Securing the Wi-Fi/Network Router https://isaca-sd.org/events/2024-04-08 * Session 4: 5/13 - Backing up Data, Smart Devices and the Internet-of-Things https://isaca-sd.org/events/2024-05-13 * Session 5: 6/10 - Physical Security, Breach and Incident Response https://isaca-sd.org/events/2024-06-10

Avast spying on clicks
https://www.pcmag.com/news/the-cost-of-avasts-free-antivirus-companies-can-spy-on-your-clicks

Facebook users monitored by thousands of companies
https://www.consumerreports.org/electronics/privacy/each-facebook-user-is-monitored-by-thousands-of-companies-a5824207467/

Time to patch and threat-hunt
https://thehackernews.com/2024/01/critical-cisco-flaw-lets-hackers.html

Please send any questions, comments, or feedback to unsecurity@protonmail.com

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 214 of the Unsecurity Podcast is now live! This time, Brad and Oscar sit down with FRSecure's Mike (Pinky) Thompson for a Breachmas report and some news from around the industry.

News links

Mandiant's X (Twitter) Account Hacked
https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html

CISCO Patch
https://www.securityweek.com/cisco-patches-critical-vulnerability-in-unity-connection-product/

Two Ivanti Zero-Days Actively Exploited in the Wild
https://www.infosecurity-magazine.com/news/two-ivanti-zerodays-actively/

Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 213 of the Unsecurity Podcast is now live! This time, Brad and Oscar sit down with FRSecure's Amy MacElroy to discuss company culture and how she helps maintain it in her role as head of HR.

Vulnerabilities

Apache Struts
https://www.securityweek.com/recent-apache-struts-2-vulnerability-in-attacker-crosshairs/

Microsoft Patch Tuesday
https://securityaffairs.com/155719/security/microsoft-patch-tuesday-december-2023.html

Adobe Patches (207 Bugs)
https://www.securityweek.com/adobe-patches-207-security-bugs-in-mega-patch-tuesday-bundle/

Don't forget: The show is available in audio-only form wherever you listen to podcasts! Please send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 212 of the Unsecurity Podcast is now live!

This time, Brad and Oscar sit down with FRSecure's Shawn Pollard to discuss our new free BIA starter kit, CMMC, and more.

Water facilities report falling to hackers in separate breaches
https://arstechnica.com/security/2023/11/2-municipal-water-facilities-report-falling-to-hackers-in-separate-breaches/

Send any questions, comments, or feedback to unsecurity@protonmail.com.

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 211 of the Unsecurity Podcast is now live!

This time, Brad and Oscar sit down with FRSecure's Eric Hanson and Seth Bowling to discuss R&D and defensive evasion.

Blackcat report company they breached to SEC https://www.bleepingcomputer.com/news/security/ransomware-gang-files-sec-complaint-over-victims-undisclosed-breach/

About FRSecure: https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.

View Details

Episode 210 of the Unsecurity Podcast is now live!

This time, Brad is joined by Megan Larkins to discuss her role as FRSecure's security consulting manager, as well as Proofpoint's 2023 Voice of the CISO report.

Proofpoint's 2023 Voice of the CISO
https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com

View Details

Episode 209 of the Unsecurity Podcast is now live! This time, Oscar and Brad welcome Evan back to the show to catch up on all his latest endeavors.

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 208 of the Unsecurity Podcast is now live!

This time, Oscar returns to the show and the guys get a chance to catch up on all the latest.

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com

View Details

Episode 207 of the Unsecurity Podcast is now live! This week, Brad and Pinky discuss Defcon 2023, Huntin' Ground, and the recent CloudNordic ransom case.

CloudNordic says it can't, and won't, pay the ransom demand (article): https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/

Send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week, Oscar and Brad sit down to discuss Adobe ColdFusion & Citrix NetScaler Vulnerabilities.

Give this episode a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

View Details

This month, we're doing a crossover episode with The Hackle Box!

For those who are not yet aware, The Hacklebox is another FRSecure podcast focused on the technical end of current events and happenings within the security industry. It's hosted several times a month by FRSecure's Technical Services Team.

Discussed this month:
* MOVEit Attacks * Microsoft Patch Tuesday: Six 0-Days * Fortinet Infinity

Please like, subscribe, and follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

View Details

Episode 205 of the Unsecurity Podcast is now live!

This week, Oscar and Brad sit down to discuss ChatGPT, mobile malware, and the recent Super Mario malware.

Don't forget: The show is available in audio or video form wherever you get your podcasts!

Give this episode a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 204 of the Unsecurity Podcast is now live!

This week, Oscar and Brad sit down to discuss the recent MOVEit, Fortinet, and Barracuda Vulnerabilities.

Links:
* Fortigate/Fortinet Vulnerability https://projecthyphae.com/threat/the-fortigate-to-mordor-has-been-left-open/ * Critical MOVEit Transfer Vulnerability https://projecthyphae.com/threat/hackers-like-to-moveit-moveit-critical-moveit-transfer-vulnerability/ * Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Applianceshttps://www.securityweek.com/zero-day-vulnerability-exploited-to-hack-barracuda-email-security-gateway-appliances/

Give this episode a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 203 of the Unsecurity Podcast is live!

This week, Oscar and Brad sit down to discuss 'malvertising' and 'malverposting'.

Links:

“Malverposting” — With Over 500K Estimated Infections...
https://labs.guard.io/malverposting-with-over-500k-estimated-infections-facebook-ads-fuel-this-evolving-stealer-54b03d24b349

Give this episode a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week, Oscar and Brad sit down to discuss passwordless tech, and the FBI's recent move to take down The Hive, one of the world's most notorious ransomware gangs.

FBI Takedown of The Hive
https://therecord.media/hive-ransomware-decryptors-fbi-bryan-smith-interview-click-here

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com

View Details

This week, Oscar and Brad sit down to discuss used network equipment resale, the risks posed to organizations, and how you can protect yourself.

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week, Oscar and Brad sit down with the creators of Hack Space Con to discuss the mission behind the conference, the unique venue, how the event came to be, and more!

Links:
https://www.hackspacecon.com/

Send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 198 of the Unsecurity Podcast is now live!

This week, Oscar and Brad discuss a new APT compromise strategy, a 3-year-old vulnerability exploited by multiple threat actors, and more.

Links:
3-Year-Old Vulnerability Exploited by Multiple Hacking Groups
https://thehackernews.com/2023/03/multiple-hacker-groups-exploit-3-year.html

Adobe ColdFusion Bug
https://gbhackers.com/adobe-coldfusion-bug/

Don't forget: The show is now available in audio form wherever you get your podcasts!

Send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 197 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss vendor risk management, incident response practices, and the recent Facebook vulnerability.

Links:

KillNet DDoS Blocklist
https://github.com/securityscorecard/SSC-Threat-Intel-IoCs/blob/master/KillNet-DDoS-Blocklist/proxylist.txt

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 196 of the Unsecurity Podcast is now live! This week, Oscar is joined by FRSecure's Eric Hanson and Seth Bowling to discuss red teaming and R&D.

Give this episode a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

This week, Oscar and Brad discuss some ideas for new year's resolutions you can apply to your security program.

Give this episode a listen and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 194 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss a CISA alert regarding Veeam backup and replication vulnerabilities being exploited, FBI seizing 48 domains linked to DDoS services, hackers using .svg files to install QBot malware on windows systems, and more.

Links:

CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html

FBI Seized 48 Domains Linked to World’s Leading DDoS-for-Hire Services https://gbhackers.com/fbi-seized-48-domains/

Citrix ADC and Citrix Gateway Security Bulletin for CVE-2022-27518 https://support.citrix.com/article/CTX474995/citrix-adc-and-citrix-gateway-security-bulletin-for-cve202227518

Hackers Use SVG Images to Install QBot Malware on Windows Systems https://gbhackers.com/hackers-use-svg-images/

Give episode 194 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com Don't forget to like and subscribe!

View Details

Episode 193 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss the new CISA reporting rule and what it means for organizations in the critical infrastructure sector.

Links:
Critical Infrastructure Sectors
https://www.cisa.gov/critical-infrastructure-sectors

CISA - Reporting Rule
https://thehackernews.com/2022/12/what-cisa-reporting-rule-means-for-your.html
https://www.congress.gov/bill/117th-congress/house-bill/5440/text?format=txt
https://www.federalregister.gov/documents/2022/09/12/2022-19551/request-for-information-on-the-cyber-incident-reporting-for-critical-infrastructure-act-of-2022
https://www.cisa.gov/report
https://www.cisa.gov/sites/default/files/publications/Sharing_Cyber_Event_Information_Fact_Sheet_FINAL_v4.pdf

Give episode 193 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 192 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss holiday precautions, vendor risk management, a few new vulnerabilities on the scene, and more.

Give episode 192 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 191 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss some recent vulnerabilities, cybersecurity awareness month, Hacks and Hops 2022, and more!

Links:

Fortinet Authentication Bypass
https://projecthyphae.com/threat/fortinet-authentication-bypass-critical/

ZeroDay: ProxyShell 2 (or 3?)
https://projecthyphae.com/threat/zeroday-proxyshell-2-or-3-even-proxier/

Cybersecurity Awareness Month
https://www.cisa.gov/cybersecurity-awareness-month

Give episode 191 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 190 of the Unsecurity Podcast is now live! This week, Oscar and Brad welcome Evan back to the show to discuss life in Mexico, next steps in the CvCISO program, and all the latest industry happenings.

Links:

Fancy Bear
https://projecthyphae.com/threat/fancy-bear-sinks-its-graphite-claws-into-powerpoint/

9/26/2022 Security News Roundup
https://projecthyphae.com/threat/information-security-news-9-26-2022/

Give episode 190 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 189 of the Unsecurity Podcast is now live! This week, Oscar and Brad are joined by Chris Furner and Jeremy Young with Blumira to discuss their perspectives on information security.

New EvilProxy Phishing Service Allowing Cybercriminals to Bypass 2-Factor Security
https://thehackernews.com/2022/09/new-evilproxy-phishing-service-allowing.html

TA505 Hackers Using TeslaGun Panel to Manage ServHelper Backdoor Attacks
https://thehackernews.com/2022/09/ta505-hackers-using-teslagun-panel-to.html

Give episode 189 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 188 of the Unsecurity Podcast is now live! This week, Oscar and Brad are joined by Michael Kennedy, Founder of Ostra Cybersecurity to discuss Ostra, working with FRSecure, industry news, and more.

LastPass Security Incident:
https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/

Okta one-time MFA passcodes exposed in Twilio cyberattack
https://www.bleepingcomputer.com/news/security/okta-one-time-mfa-passcodes-exposed-in-twilio-cyberattack/

Ostra Cybersecurity
https://www.ostra.net/

Give episode 188 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 187 of the Unsecurity Podcast is now live! This week, Oscar and Brad are joined by Eric Hanson and Mike Thompson of FRSecure's technical services team to discuss this year's DEFCON conference.

DEFCON site:
https://defcon.org/

Give episode 187 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 186 of the Unsecurity Podcast is now live! This week, Oscar and Brad review the recent updates to the FTC's Safeguards Rule concerning financial institutions. Here's what you need to know...

Need more detail? Check out FRSecure's blog post covering all the details of the recent updates:
https://frsecure.com/blog/ftc-safeguards-rule-what-you-need-to-know/

More resources:
https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know

https://arstechnica.com/information-technology/2022/08/sike-once-a-post-quantum-encryption-contender-is-koed-in-nist-smackdown/

https://www.infosecurity-magazine.com/blogs/compliance-security-passwords/

Give episode 186 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 185 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss securing a remote workforce in a post-COVID environment, industry news, and more!

Give episode 185 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 183 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss some of the simpler things you can do to bolster your security program. While there is no such thing as 'easy button' security, there are still some quick wins to be had!

News:

https://thehackernews.com/2022/07/5-key-things-we-learned-from-cisos-of.html

  • Remote work has accelerated the use of EDR Technology
  • 90% of CISO's surveyed used an MDR solution
  • Overlapping threat protection tools are the #1 pain point for small teams
  • Small security teams are ignoring more alerts
  • 96% of CISO's are planning to consolidate security platforms

https://www.helpnetsecurity.com/2022/07/14/conventional-cybersecurity-approaches/

Give episode 184 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 183 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss some training resources that you can use in your security program free of charge!

News:

Autopatch is now Available
https://thehackernews.com/2022/07/microsoft-windows-autopatch-is-now.html

'Callback' Phishing Campaign Impersonates Security Firms
https://threatpost.com/callback-phishing-security-firms/180182/

Resources Discussed:

Portswigger Web Security Academy
https://portswigger.net/training

XSS, Cross Site Request Forgery, SQL Injection, HTTP Request Smuggling
Burp Suite Training - All free & high quality

HacktheBox, TryHackMe, OverTheWire

Offensive Security - Metasploit Unleashed.
Also currently doing free OSCP classes via Twitch. Monday and Friday at 12:00 PM ET
https://www.offensive-security.com/metasploit-unleashed/

FRSecure CISSP mentorship
https://frsecure.com/cissp-mentor-program/

Federal Virtual training Environment
https://fedvte.usalearning.gov/
Free training for all Federa, State, Local, Tribal and Territorial government employees.

Using ATT&CK for CTI Training
https://attack.mitre.org/resources/training/cti/
Understand what ATT&CK is and how to use it to make defensive decisions.

SANS Cheat Sheets!
https://www.sans.org/blog/the-ultimate-list-of-sans-cheat-sheets/

PicoCTF
https://picoctf.org/resources.html
Learning Guides for General Skills, Crypto, Web Exploitation, Forensics, Binary Exploitation, Reversing

Infosecinstitute
https://resources.infosecinstitute.com/topic/13-cyber-security-training-courses-you-can-take-now-for-free/
$300 Annual

Cybrary
https://www.cybrary.it/
Some free courses or $60 a month

Give episode 183 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 182 of the Unsecurity Podcast is now live! This week, Oscar and Brad discuss some of the tools and strategies out there that you can implement in your security program free of charge!

Give episode 182 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 181 of the Unsecurity Podcast is now live! This week, Evan sits down to host the show one last time. Joined by Oscar Minks and Brad Nigh, who will be taking the reins, the trio looks back through almost 3 years of the podcast, security conferences, this year's DEFCON event, and more!

Give episode 181 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 180 of the Unsecurity Podcast is now live! This week, Evan and Oscar sit down with FRSecure's Mike 'Pinky' Thompson to talk incident response, and the recent uptick in incidents FRSecure's IR team is currently witnessing.

Give episode 180 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Episode 179 of the Unsecurity Podcast is now live! This week, Evan and Oscar sit down with FRSecure's Megan Larkins to discuss hiring practices in the information security industry. This episode is the second part of our 2 part discussion on hiring practices and ties into our larger series on the talent shortage and nature of working in the security field.

Give episode 179 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 178 of the Unsecurity Podcast is now live! This week, Evan is joined by Oscar Minks and Eric Hanson to talk mental health. We will resume our running series on hiring and the cybersecurity job market next week!

Mental health is an essential topic to us and in our industry, and we continue to talk regularly in hopes that our experiences can help others in our field.

Give episode 178 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 177 of the Unsecurity Podcast is now live! This week, Evan and Oscar sit down with FRSecure's Mike Nollan to discuss hiring practices in the information security industry. This episode is part of a 2 part discussion on hiring practices and is also part of our larger series on the talent shortage and nature of working in the security field.

Links mentioned in this episode:

https://www.hackthebox.com/
https://tryhackme.com/
https://sourceforge.net/projects/metasploitable/

Give episode 177 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 176 of the Unsecurity Podcast is now live! This week, Evan and FRSecure CTO, Oscar Minks sit down to discuss job descriptions in the information security field.

Give episode 176 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 175 of the Unsecurity Podcast is now live! This week, Evan is once again joined by FRSecure CTO, Oscar Minks, to discuss the talent shortage in cybersecurity, and what can be done to help fill these key roles with qualified professionals.

Give episode 175 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!

View Details

Episode 174 of the Unsecurity Podcast is now live! This week, Evan is joined by Oscar Minks, FRSecure's CTO to discuss the recent news on increasing concern around Russian cyber-threats in the United States.

Give episode 174 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

Episode 173 of the Unsecurity Podcast is now live! This week, Brad and Evan are joined by Eric Hanson, FRSecure's Offensive Services Manager to discuss the differences between attack simulation services like penetration testing and red teaming, and who they're for.

View Details

It's another episode with Evan running the show! This week he goes into detail about the antiquated technology still in use at some companies and even government agencies like the IRS.

Also discussed: FRSecure's annual CISSP mentor program, SecurityStudio's CvCISO program, and a recent breach involving GitHub which impacted dozens of organizations.

Contents:
00:00 - Intro
00:35 - Ensuring that MFA is effective
23:00 - News
28:00 - Closing thoughts & shout outs

Give episode 172 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

It's another episode with Evan running the show! This week he goes into detail about the antiquated technology still in use at some companies and even government agencies like the IRS.

Also discussed: FRSecure's annual CISSP mentor program, SecurityStudio's CvCISO program, and a recent breach involving GitHub which impacted dozens of organizations.

Give episode 171 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week Evan leads the podcast solo, discussing how the cybersecurity landscape has changed in the education sector after schools have returned to in-person learning. Evan also breaks down several things in the news including zero-click attacks, MailChimp, and more!

Contents:

How the K12 cybersecurity landscape has changed
Zero-click attacks
MailChimp breach
Brokenwire
Borat malware
Closing thoughts

Give episode 170 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week, Brad and Evan sit down to discuss the White House's recent cybersecurity briefing and break down the included advice, lending their perspective to each item on the list.

Give episode 169 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down again to discuss Russia's invasion of Ukraine and make some predictions as to what we can expect to see in the cybersecurity landscape as a result of the conflict.

Give episode 168 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to talk about the recent COVID-19 stimulus acts, and how the money available to schools can be used toward cybersecurity initiatives.

Register FRSecure's webinar on K-12 stimulus funds now!
https://www.eventbrite.com/e/maximizi...

Give episode 167 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to talk about Russia's invasion of Ukraine and the cybersecurity implications that may come of it and that we're already witnessing.

Give episode 166 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to talk about guiding conversations around IT budget and discussing cybersecurity as a necessity with your organizations' leadership. They also cover some recent news about a major phishing attack targeting job-seekers on LinkedIn.

Give episode 165 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

This week, Brad and Evan sit down to discuss this year's Hacks and Hops conference at the Nissan Stadium in Tennessee, FRSecure's CISSP mentor program, Security Studio's new CvCISO certification course, and predictions for the rest of the year.

Give episode 164 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to follow the show!

View Details

This week, Brad and Evan sit down with special guest Max of LimaCharlie to discuss the importance of transparency in cybersecurity products, and how LimaCharlie is doing things differently.

Give episode 163 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to talk about allowlisting and blocklisting, and why it's the most secure way to configure a network. They also discuss why it's so complicated to recommend one-size-fits-all best practices.

In the news: Europol Shuts Down Popular Cybercriminal VPN Service
https://www.darkreading.com/threat-intelligence/europol-shuts-down-popular-cybercriminal-vpn-service

Give episode 162 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to discuss the on-premise security landscape and how it’s changed now that we’re headed into another year of employers keeping staff home due to the pandemic.

Give episode 161 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

This week, Brad and Evan sit down to discuss some info security resolutions they hope to see come true in the new year, as well as some of the latest cybersecurity news!

Give episode 160 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to subscribe!

View Details

This week, Brad and Evan are joined by Mike (Pinky) Thompson, FRSecure's IR team lead, to discuss the recent log4j incident. They go into detail on what it is, how it happened, and some best practices to protect yourself.

Give episode 159 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan discuss some things your office can do to prepare for attackers who might be waiting until the holidays to attack.

Give episode 158 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan put their heads together to discuss some of the scams that are attempted around the holidays, and how to protect yourself against them.

Give episode 157 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan are joined by FRSecure's Lori Blair, a seasoned veteran of the cyber security industry! With Lori's help, they dive into some of the most important client relationships a CISO can build when working with a company to develop or mend existing security practices.

View Details

In this week's episode, Brad and Evan discuss the difference between IR service providers and cyber insurance policies, working with an IR provider to eliminate issues before falling back on insurance, and using the providers recommended by insurers.

Give episode 155 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan discuss the recent federal grant meant to aid in bolstering election security in the United States. Also covered, are some recent news stories from the information security industry.

View Details

In this week's episode, Brad and Evan are joined by the leader of FRSecure's Technical Services Team, and Team Ambush's very own Oscar Minks to recount some of the scariest stories they can remember from a career's worth of IR cases. ​

Give episode 153 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan discuss the first ever death via ransomware lawsuit, as well as the future of info security and the importance of it as more and more technology is relied upon to keep us alive.

They also touch on some industry news and more including GCAT- Google's Security Advisory Service.

First death via ransomware lawsuit
https://www.healthcareitnews.com/news/hospital-ransomware-attack-led-infants-death-lawsuit-alleges

GCAT
https://cloud.google.com/security/gcat

Give episode 152 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan discuss incident response retainers, the market, sizes, and categories of IR providers, and the difference between IR retainers and managed IR.

They also touch on Project Hyphae, a new goodwill threat hunting initiative powered by FRSecure, and FRSecure's annual Hacks and Hops event which took place last Thursday, October 14th.

Project Hyphae
https://projecthyphae.com/

Hacks and Hops
https://hacksandhops.com/

Give episode 151 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

View Details

In this week's episode, Brad and Evan talk Zero Trust (ZTA). They go into detail about what it is, how to do it, and how not to fall victim to the marketing BS that some people are selling.

Also discussed, is Zero Trust not being a new concept, but a more complex version of the same things we've been preaching since the beginning, and how complexity is the enemy of security.

Give episode 150 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

View Details

On this week's episode, Evan and Brad dive into cybersecurity awareness month, the free S2me security rating app, and discuss the already infamous Facebook outage.

Give episode 149 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

S2me
https://s2me.io/

View Details

In this episode, Brad and Evan discuss state government security issues and working with the Carolina Cyber Center, to provide higher education students with hands-on practical experience using SecurityStudio to deliver information security risk assessments to SMBs.

Also included in episode 148 is a conversation about PDEIS at the Cybersecurity Summit and updates about the future of the Unsecurity Podcast!

As always, they review some industry news, including a bug in Microsoft Exchange leaking 372,000 domain credentials, 100M IoT devices that were exposed by a zero-day bug, and a hacking group that used ProxyLogon exploits to breach hotels worldwide.

Give episode 148 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

A bug in Microsoft Exchange Autodiscover feature leaks +372K of domain credentials
https://securityaffairs.co/wordpress/122510/hacking/microsoft-exchange-autodiscover-feature-bug.html

100M IoT Devices Exposed By Zero-Day Bug
https://threatpost.com/100m-iot-devices-zero-day-bug/174963/

Hacking group used ProxyLogon exploits to breach hotels worldwide
https://www.bleepingcomputer.com/news/security/hacking-group-used-proxylogon-exploits-to-breach-hotels-worldwide/

View Details

In episode 147, Brad and Evan discuss the general busyness in their lives lately, as well as accountability and negligence in the security world.

As always, they review some news articles including recent patches from major companies like Microsoft, Apple, and Google, 3 former U.S. intelligence officers who admitted to hacking for a U.A.E. company, and the low levels of ransomware preparedness despite concerns at the executive level.

Give episode 147 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

Google patches Chrome zero-day exploited in the wild
https://www.securitymagazine.com/articles/96096-google-patches-chrome-zero-day-exploited-in-the-wild

3 Former U.S. Intelligence Officers Admit to Hacking for UAE Company https://thehackernews.com/2021/09/3-former-us-intelligence-officers-admit

Ransomware preparedness is low despite executives’ concerns
https://www.helpnetsecurity.com/2021/09/15/ransomware-preparedness/

View Details

In this episode, Evan and Brad discuss the Women's Society of Cyberjutsu (WSC) class on using your home network to learn attacks and defenses, plus a recap on the Wisconsin FBI Infragard SuperCon.

In the news this week, the FBI says surge in sextortion attacks cost targeted users $8M this year.

Give episode 146 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Don't forget to like and subscribe!

Surge in Sextortion Attacks Cost Targeted Users $8M This Year
https://www.ehackingnews.com/2021/09/surge-in-sextortion-attacks-cost.html

View Details

In this episode, Evan and Brad conduct a mental health check-in and have a candid discussion about their own struggles. They also discuss the first foundational steps in building a security program including less "what to do", and more "how to do".

In the news this week, a cryptocurrency hacker returns $260 million in stolen funds, and the State Department is hit by a cyberattack amid Afghan evacuation.

Give episode 145 a listen and send any questions, comments, or feedback to unsecurity@protonmail.com

Cryptocurrency hacker returns funds
https://www.bbc.com/news/business-58180692

State Department cyberattack
https://nypost.com/2021/08/21/state-department-hit-by-cyber-attack-amid-afghan-evacuation-report/

View Details

In this episode, Evan and Brad focus on the concept of PDEIS (Programmatic Distributed Empowerment of Information Security) and its ability to involve and empower others within the organization; not just CISOs, to make their own risk decisions.

They also debate the trend of information security leaders facing legal repercussions in the wake of the recent SolarWinds incident. As always, they close with some industry updates such as the T-Mobile breach, and more.

Give episode 144 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Please like and subscribe!

SolarWinds Breach
https://www.secureworld.io/industry-news/ciso-lawsuit-solarwinds

T-Mobile Investigating Claims of Massive Data Breach
https://krebsonsecurity.com/2021/08/t-mobile-investigating-claims-of-massive-data-breach/

T-Mobile confirms it was hacked again
https://siliconangle.com/2021/08/16/t-mobile-confirms-hacked/

US Govt’s secret terrorist watchlist with 2M records exposed online
https://www.hackread.com/us-secret-terrorist-watchlist-exposed-online

View Details

The boys are back with Team Ambush recapping their DEF CON 29 experience. This sparked a conversation about everyone's highs and lows at the event. Team Ambush brings insight about the hacking challenges and competitions they won, were involved in, and why it's important.

Evan & Brad continued to discuss how Team Ambush finished in 1st place in the biomedical hacking and dive deep into the medical devices that are the easiest to hack into.

They also touched on this year's annual Hacks & Hops event on October 14th, at the Nissan Stadium in Nashville, Tennessee.
https://hacksandhops.com/

Give episode 143 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com

Please like and subscribe!

View Details

It's finally here, the annual BlackHat and DefCon29 events are back again in Las Vegas, Nevada.

What are these events?

Evan & Brad unravel everything you need to know about these two events in this week's UNSECURITY episode.

They also touched on:

LockBit ransomware: recruiting insiders to breach corporate networks https://www.bleepingcomputer.com/news...

SolarWinds urges US judge to toss out crap info-sec sueball: We got pwned by actual Russia https://www.theregister.com/AMP/2021/...

Bipartisan Senate report finds federal agencies continue to suffer cybersecurity shortcomings https://siliconangle.com/2021/08/03/b...

Give episode 142 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Please like and subscribe!

View Details

Today, state and local government Chief Information Security Officers (CISO) are playing a game they can't win. CISOs are facing many obstacles and are losing focus of their roles and responsibilities.

So, how do we change the way we play the game?

Evan and Brad attempt to answer this question in this week's UNSECURITY episode.

They also touched on:

Apples recent IOS 14.7 and 14.7.1 and advisors listeners to get the update as soon as possible for their own good and safety.

Give episode 141 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

Please like and subscribe!

View Details

Recently, Amazon made changes to their terms of service. This sparked a conversation between Evan and Brad about terms and conditions, privacy, and what we tend to blindly agree to.

Together Evan and Brad discuss:

Amazon’s Conditions of Use https://www.amazon.com/gp/help/customer/display.html?nodeId=GLSBYFE9MGKKQXXM

Amazon.com Privacy Notice https://www.amazon.com/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ

Terms of Service Didn’t Read
https://tosdr.org (great resource!)

They also touched on:

Revealed: Leak Uncovers Global Abuse of Cyber-Surveillance Weapon https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus
and
https://securityaffairs.co/wordpress/120291/malware/pegasus-project-nso-pegasus-spywar.html

US Indicts Members of Chinese-Backed Hacking Group APT40
https://www.bleepingcomputer.com/news/security/us-indicts-members-of-chinese-backed-hacking-group-apt40/
and
https://thehackernews.com/2021/07/us-and-global-allies-accuse-china-of.html

Give episode 140 a listen or watch and send any questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Evan is down in Mexico and took Ryan Cloutier (Head of SecurityStudio) and John Harmon (President at FRSecure) down with him. The two replace Brad this week, and together, the three break down what the first half of 2021 looked like in the security industry.

Give this episode a listen and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Kaseya VSA, a remote management software, experienced a breach over the holiday weekend that is already impacting a number of clients. It appears that this attack is connected to the Russian hacker gang known as REvil—but it has not been determined whether or not it is the work of REvil itself or an affiliate in their Ransomware as a Service (RaaS) program (and yes, that's a thing).

Evan and Brad break down the attack on this week's UNSECURITY episode.

Additionally, and flying under the radar because of Kaseya, news broke on June 30th about an impressive and potentially very damaging vulnerability in the Microsoft Print Spooler service. This has actually impacted a larger number of customers than Kaseya (millions of servers) and likely would have been bigger news had it not been for Kaseya.

If you feel you've been impacted by the Kaseya attack directly, or would like more information, visit: https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689

Here is more information on the Microsoft bug: https://www.yahoo.com/entertainment/microsoft-sounds-urgent-warning-windows-022541397.html?

Additionally, Evan was on KARE 11 discussing Kaseya yesterday (July 5): https://www.kare11.com/video/news/local/breaking-the-news/ransomware-crime-wave-keeps-us-on-edge/89-44bed2c8-bbb1-4572-abc9-53551c6c74fa?jwsource=cl

Give episode 138 a watch/listen and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Between pirated games, customer support tools, SolarWinds group targeting customers, customer service systems being hacked, a malware supply chain fiasco, and a nasty Edge bug, Microsoft has a lot going on security-wise. Evan and Brad break down all the notable Microsoft security news surfacing recently on this episode of the UNSECURITY Podcast.

Give episode 137 a watch/listen and send questions, comments, and feedback to unsecurity@protonmail.com.

Microsoft
New malware in pirated games disables Windows Updates, Defender:
https://www.hackread.com/pirated-games-malware-disable-windows-defender

Nobelium hackers accessed Microsoft customer support tools:
https://www.bleepingcomputer.com/news/microsoft/nobelium-hackers-accessed-microsoft-customer-support-tools/amp/

Microsoft Warns of Continued Attacks by the Nobelium Hacking Group:
https://www.pcmag.com/news/microsoft-warns-of-continued-attacks-by-the-nobelium-hacking-group?amp=true

Group Behind SolarWinds Attack Targeted Microsoft Customers - https://www.bankinfosecurity.com/group-behind-solarwinds-attack-targeted-microsoft-customers-a-16945

Hackers hit Microsoft customer service system, make off with data:
https://www.cnet.com/google-amp/news/hackers-hit-microsoft-customer-service-system-make-off-with-data/

Microsoft admits to signing rootkit malware in supply-chain fiasco:
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/amp/

Microsoft approved a Windows driver booby-trapped with rootkit malware:
https://www.theregister.com/2021/06/28/microsoft_malware_signing/

Microsoft Edge Bug Could've Let Hackers Steal Your Secrets for Any Site: https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html

Other
One billion dollars lost by over-60s through online fraud in 2020, says FBI: https://hotforsecurity.bitdefender.com/blog/one-billion-dollars-lost-by-over-60s-through-online-fraud-in-2020-says-fbi-26049.html

John McAffee's Death

View Details

Ryan Cloutier joins this episode of the UNSECURITY Podcast. Ryan has taken a special interest and focus on cybersecurity in schools, so he and Evan talk all things K-12 security—including Ryan's "Awesome Top 5."

Give episode 136 a listen/watch and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Evan and Brad are back with episode 135 of the UNSECURITY Podcast. This week, they take a look at some of the issues stemming from the Colonial Pipeline attack—what the economic impact of cyber crime is, how attacks may begin to impact the power grid, and more.

Give this episode a listen or watch and send comments, questions, and feedback to unsecurity@protonmail.com.

US recovers most of Colonial Pipeline's $4.4M ransomware payment: https://www.bleepingcomputer.com/news/security/us-recovers-most-of-colonial-pipelines-44m-ransomware-payment/

'Broader economy' at risk if US doesn't act on cybercriminals soon, GOP lawmaker says:
https://www.foxnews.com/politics/broader-economy-at-risk-if-us-doesnt-act-soon-gop-lawmaker-says

Hackers Could Shut Down the U.S. Power Grid, Energy Secretary Granholm Says:
https://www.barrons.com/articles/hackers-could-shut-down-the-u-s-power-grid-energy-secretary-granholm-says-51623077337

Amazon Sidewalk starts sharing your WiFi tomorrow, thanks:
https://blog.malwarebytes.com/privacy-2/2021/06/amazon-sidewalk-will-share-your-wifi-unless-you-opt-out/

Username and password breaches increase by 450 percent:
https://betanews.com/2021/06/07/username-password-breaches-increase/

View Details

The UNSECURITY podcast is back with episode 134. There’s so much going on in the world around us, so Evan and Brad thought it would be good to focus on six news articles and discuss them. The topics of discussion include a CMMC review, the FBI sharing pwnd passwords, a Walmart phishing attack, JBS Foods cyberattack, a Nobelium attack on U.S government agencies, and the Army telling remote workers to switch off IoT devices.

Give this episode a listen and send comments, questions, and feedback to unsecurity@protonmail.com.

View Details

On this week's episode of the UNSECURITY Podcast, Evan and Brad are joined by Gabriel Friedlander. Gabriel was looking for a way to bring security and awareness training to the masses. He used a similar concept to how marketing teams express complex concepts and sell using 30-second- and minute-long videos to build a training video platform called Wizer. Today, Wizer has free and paid training options and relies heavily on social media to promote good security practices for consumers and businesses alike.

Give episode 133 a listen or watch and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

In an executive order announced on May 12, 2021, President Biden is aiming to improve the nation's cybersecurity practices. Naturally, as security professionals, Brad and Evan want to poke holes in the entire thing—find out what it gets right and where it misses the mark.

Section 1. Policy
Section 2. Removing Barriers to Sharing Threat Information
Section 3. Modernizing Federal Government Cybersecurity
Section 4. Enhancing Software Supply Chain Security
Section 5. Establishing a Cyber Safety Review Board
Section 6. Standardizing the Federal Government’s Playbook for Responding to Cybersecurity Vulnerabilities and Incidents
Section 7. Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Networks
Section 8. Improving the Federal Government’s Investigative and Remediation Capabilities
Section 9. National Security Systems
Section 10. Definitions
Section 11. General Provisions

Give episode 132 a listen to hear their initial reactions! Then, as always, send us your thoughts, questions, and feedback to unsecurity@protonmail.com.

View Details

For episode 131 of the UNSECURITY Podcast, Evan and Brad are joined by long-time friend, Chris Roberts. Chris's early life and trajectory in the information security industry both provide countless stories and lessons, so the three of them open the floor to whatever comes to mind!

Give this episode a listen or watch and send questions, comments, or feedback to unsecurity@protonmail.com!

View Details

The UNSECURITY Podcast is pleased to welcome John Strand from Black Hills Information Security as a guest on episode 130. Along with Brad and Evan, John chats candidly about his path in security, what Black Hills is working on, the different pockets of security people, why it's important to work together as information security vendors to improve the community, and so, so much more.

Give us a listen/watch and send your questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Evan and Brad are joined by Ron Woerner for episode 129 of the UNSECURITY Podcast. Ron and Evan first met at RSA, and they bonded over their shared passion to help people from all walks of life better protect themselves from cyber threats. Together, the three have an open discussion about current events, projects Ron is working on, and what's generally top of mind.

Give episode 129 a listen or watch and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

In the first of a number of guests appearances over the next few episodes, Brad and Evan are joined by Roger Grimes—a bona fide information security authority and renowned author of 12 books. Together, the three of them have an open dialogue on what's top of mind for them right now, some of the projects they are in the middle of, and current events that have drawn a ton of all of our attention lately.

Please note: we did experience some audio issues for the back half of this episode. While we considered re-recording, Roger's insight and conversation were phenomenal, and we did not want to rob you of that authenticity. We hope that you still gain something from this episode despite this, and thank you for your patience and understanding.

Give episode 128 a listen and send questions, comments, and feedback to unsecurity@protonmail.com.

View Details

In this epsiode of the UNSECURITY Podcast, Evan and Brad have a candid discussion about how important it is to understand world events and apply the understanding to our jobs as security professionals. Everyone’s perspective is valid, so all perspectives (especially ones differing from our own) should be considered in our view of both society and our jobs.

Give episode 127 a listen, and send comments, questions, or feedback to unsecurity@protonmail.com.

View Details

Evan ran across an article this week titled "15 Security Pitfalls and Fixes for SMBs." Small- and medium-sized businesses (SMBs) tend to be an underserved market, and with many businesses starting to regain their footing post-Covid, now is a great time to discuss SMB security. Brad and Evan analyze the "15 Security Pitfalls and Fixes for SMBs," provide their thoughts on the list, and give recommendations for those in smaller businesses to improve their security efforts.

Give episode 126 a listen and send any comments, questions, or feedback to unsecurity@protonmail.com.

View Details

We're just under two weeks away from FRSecure's annual CISSP Mentor Program—a free event that Evan and Brad host every year in the spring to help train industry professionals and get more people involved in the industry. In episode 125 of the UNSECURITY Podcast, Evan and Brad take a look back at why the program was started, how it's grown, and what to expect during this year's sessions.

Give it a listen and send your questions, comments, and feedback to unsecurity@protnmail.com.

View Details

After a two-episode hiatus, Brad is back this week to join Evan for episode 124 of the UNSECURITY Podcast. In this episode, the duo attempts to answer as many questions about passwords as they possibly can. Finally they touch on some company happenings like the CISSP Mentor Program and S2 updates.

Give this episode a watch/listen and then send us your questions, comments, or feedback to unsecurity@protonmail.com.

View Details

Have we lost our ability to reason? Evan is joined for the second week in a row for episode 123 of the UNSECURITY Podcast to discuss reason and how it applies to information security and life. The duo also dives into password hygiene—what the importance of passwords is and how they each tackle passwords.

Give this episode a watch or listen and let us know what you think or what questions you have at unsecurity@protonmail.com.

View Details

Evan has always been a strong proponent of weaving mental health transparency and help into the information security industry—one that tends to have long hours, stressful moments, and many other challenges that contribute to mental health struggles. With Brad out this week, Evan is joined by Ryan Cloutier for an honest and transparent discussion of mental health in infosec, their own personal mental health challenges, and the Mental Health First Aid certification.

Give episode 122 a listen and send your questions, comments, and feedback to unsecurity@protonmail.com.

View Details

In light of the SolarWinds attack (which you've more than likely heard of by now), the US Senate met about the events surrounding the attack and what can be done to prevent (or at least reduce the likelihood of) similar events in the future. There were some very interesting witness testimonials, but not all good. If policymakers draft policy based solely on what these witnesses said, we might be in some serious trouble!

Evan and Brad recount the hearing and discuss their thoughts on the attacks, the witnesses, the hearing itself, and more.

Give episode 121 a listen/watch and send us your questions, comments, and feedback to unsecurity@protonmail.com.

View Details

The UNSECURITY Podcast welcomes special guest Tony Alsleben this week. Tony is the head of security for CentraCare. With Brad and Evan, Tony discusses his career and current role, what being a CISO (and similar positions) in healthcare is like, some of the industry's biggest security challenges, and advice for healthcare security colleagues. The three of them also touch on the vCISO Handbook, the CISSP Mentor Program, and some industry news.

Give this episode a listen or watch, and send comments, questions, and feedback to unsecurity@protonmail.com.

View Details

Episode 119 of the UNSECURITY podcast is jam-packed with a number of current events topics Evan and Brad have been following. The discussion includes a super useful and free “Legal Guide to Privacy and Data Security” written by a friend, a novel attack vector used to target the supply chain of some big tech players, and more on the water facility attack from last week and what that might mean for our national infrastructure as a whole.

Give this episode a listen or watch, and as always, send us your questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Since the initial announcement of CMMC requirements and certification, the information security industry has abruptly shifted its focus towards preparing for it. While there are differences between "compliant" and "secure," CMMC seems to be one of the best compliance approaches to date—really taking important security fundamentals into account. In this episode, Brad and Evan discuss the differences between security and compliance, how to approach information security the right way, and how those relate to CMMC.

Give episode 118 a listen or watch and then send your comments, questions, and feedback to unsecurity@protonmail.com.

View Details

In episode 117 of the UNSECURITY Podcast, Evan and Brad listen to an impressive scam voicemail Evan received and talk about the novelty of it and how effective it might be. Then, they discuss privacy and whether it's truly the "right" people claim it to be. Finally, they talk about a well-known problem across the industry: burnout.

Give this episode a listen/watch, then send us your questions, comments, and feedback to unsecurity@protonmail.com!

View Details

Episode 116 of the UNSECURITY Podcast can really be broken into two parts. First. Evan and Brad discuss the CIS Controls Version 8 Public Call (running through 2/8/2021) and the changes that are expected made. Second, Evan posed a question about the root of all problems in the infosec industry on LinkedIn and has gotten an overwhelming response. Brad and Evan also chat about some of the responses. Finally, the guys provide an update on their free CISSP training course.

Give this episode a listen/watch, then send us your questions, comments, and feedback to unsecurity@protonmail.com!

View Details

Recurring guest and friend of the program, Amy McLaughlin, returns to the UNSECURITY Podcast this week to discuss her new book titled "Learning Continuity Planning: A Handbook for Schools, Colleges & Universities." With Evan and Brad in the process of co-authoring a book as well, the three of them discuss their new works in detail. They also touch on the 2021 CISSP Mentor Program (which registration just launched for) and news stories like DarkMarket Shutdown, Hackers Leak Stolen Pfizer-BioNTech COVID-19 Vaccine Data, and Serious Windows 10 Flaw Could Corrupt Your Hard Drive If You Open a Folder.

Give it a watch or listen and then send your comments, questions, and feedback to unsecurity@protonmail.com.

View Details

Thanks to Brad, FRSecure is now an official CMMC Registered Provider Organization (RPO). Given this, and the requirements beginning to trickle out to DoD service providers and supply chain, he and Evan chat about the upcoming requirements. Tune in to episode 114 to get an idea of what it looks like, what FRSecure is going to do for it, and what you can do to start preparing.

As always, feel free to send questions, comments, and feedback to us at unsecurity@protonmail.com.

View Details

If you're a loyal follower of the UNSECURITY Podcast, you know that from time to time Evan takes trips down to Mexico to get away from everything so he can write. Well, he's back. This time, he's co-authoring a vCISO Handbook with Brad. In this week's episode, the co-hosts (and soon to be co-authors) talk about what readers can expect in their upcoming piece—which hopes to be done before fall of this year.

Check it out anywhere you consume podcasts, and send us your questions, comments, and feedback to unsecurity@protonmail.com.

View Details

Episode 112 of the UNSECURITY Podcast marks the final episode of 2020. With that, Brad and Evan take a look back at some of the major security topics that surfaced this year—primarily breaches. The hope is that by dissecting some of these large-scale security events, businesses can continue to push forward in their efforts to protect data and people.

Happy New Year, everybody!

As always, please feel free to send comments, questions, or feedback to unsecurity@protonmail.com.

View Details

Evan and Brad continued their at-home security series with episode 111 of the UNSECURITY Podcast. Coincidentally, this one is guided by a recent conversation Evan had with his mom, who is a 73-year-old woman concerned with her accounts and financials in the wake of the SolarWinds attack. Evan's mom is a metaphor for a lot of people—concerned and confused about newsworthy breaches and what to do about them. The guys also continue their conversation about home network security, including changing passwords on a home router, running an Nmap scan on your home network, hunting down systems from the Nmap scan, and doing research on the systems to secure them. Give this one a listen/watch and send your comments, questions, and feedback to unsecurity@protonmail.com. And, most importantly, have a happy and safe holiday!

View Details

If you're at all in touch with information security news, you likely already know about the SolarWinds compromise that was announced yesterday. With the majority of Fortune 500 companies and a number of US government entities using their product, this compromise has the potential to do serious damage. And that was felt throughout the security industry yesterday. So, we pivot! Today, Brad and Evan are joined by Oscar Minks, FRSecure's Director of Technical Services (and head of our incident response team) to dive further into the breach and its potential ramifications. Give episode 110 a listen and send us any questions or concerns to unsecurity@protonmail.com.

View Details

The guys are continuing the Information Security at Home series on episode 109 of the podcast. As industry professionals, we often take our skills and knowledge for granted. There are a lot of things that are obvious to us that may not be to the non-industry professional. So, Evan and Brad do a deep dive into firewall and router security—taking a look at things like finding your router, logging into your router, changing the default password, and poking around at what might exist on your network you're unaware of. Give this one a listen and let us know what questions, comments, and feedback you may have at unsecurity@protonmail.com.

View Details

Brad is back after his recent bout with Labyrinthitis for episode 108 of the UNSECURITY Podcast. This week, Evan and Brad continue the conversation from episode 106. With many people working and schooling from home this year, in-home security is more important than ever. But why? Check out this episode to find out—and get some advice from the guys about the what you can do. As always, please feel free to send comments, questions, and feedback to us via email at unsecurity@protonmail.com.

View Details

It's nearly Thanksgiving, which means holiday shopping is already in full force. With more online shopping coupled with the fact that most of us are more distracted than ever, attackers could have a field day. It's important to know how to protect yourself and your family while holiday shopping, so Evan provides some tips in episode 107 of the UNSECURITY Podcast. Check it out and submit your comments, questions, and feedback to unsecurity@protonmail.com.

View Details

As information security professionals, we're responsible for protecting sensitive business information involving financials, customer info, employee data, and more. But, those protections don't always feel directly connected to us personally—more of our personal data lives in our home environment. So, from the perspective of security professionals, what should we do at home to protect ourselves and our family? Evan and Brad provide some tips in this week's episode of the UNSECURITY podcast. Give it a listen/watch, and send us your comments, questions, and feedback at unsecurity@protonmail.com.

View Details

The number of aggressive cyber attacks we've seen has been on the rise very recently—including a calculated Ryuk ransomware targeting healthcare organizations. Knowing attackers are taking extra advantage of the chaos of the pandemic, Oscar (who leads FRSecure's technical services team) gives some thoughts about what you should and shouldn't do when experiencing an incident or attack. Give episode 105 a listen/watch, and let us know what you think at unsecurity@protonmail.com.

View Details

At episode 104, the UNSECURITY Podcast has officially reached its second year anniversary of the show. First off, we'd like to thank all of our listeners for sticking with us during this journey. It's been fun, and we hope you've gained as much from the conversations as we have.

This week, we're continuing our unofficial series on the topics of mental health, wellness, and work-life balance in the information security industry. To do so, Brad and Evan are joined by Richie Breathe—who provides wellness education for professionals.

Go vote, then give this episode a listen/watch. As always, feel free to send comments, feedback, and questions to unsecurity@protonmail.com.

View Details

Things don't always go as planned. With Brad out last week and a riveting conversation with Neal O'Farrell about mental health in the information security industry, Neal joined the podcast again for an impromptu part two in episode 103. In part two of this discussion, Evan, Brad, and Neal review some very specific self-help measures they've tried—and what their experiences were with them. Give this episode a listen/watch and let us know what you think at unsecurity@protonmail.com.

View Details

With Brad out this week, Evan is joined by the founder of the PsyberReslience Project, Neal O’Farrell. The PsyberReslience Project is an "ongoing effort to address the prevalence and impact of stress, burnout, and mental health challenges in the cybersecurity workforce." Evan and Neal chat about what mental health is like in the information security industry, and what challenges need to be addressed. Give this episode a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Securing an election has never been more difficult. Especially with the current state of the pandemic and its impact on in-person events, there’s much more to election security than protecting voting machines. Things like voter intimidation, disinformation, and security after election night all tie back into election security as much as infrastructure. Brad and Evan break down securing the 2020 election on this week's episode. Check it out and let us know what your election security concerns are at unsecurity@protonmail.com or @unsecurityP on Twitter.

View Details

Brad and Evan pick up where they left off with episode 99 in talking about "The Social Dilemma" by Netflix. The documentary outlines the problems with the way society is moving and how social media and big tech companies are aiding in that. With security and online privacy and tech going hand-in-hand, this is an important topic to discuss. Let us know what you thought of the documentary at insecurity@protonmail.com.

View Details

In episode 99 of the UNSECURITY Podcast, Evan and Brad review "The Social Dilemma"—Netflix's new documentary which sheds light on some techniques tech companies use to get us hooked on social media and the information they're collecting on us. Hear what a couple of information security and privacy experts have to say about a topic that's not going away any time soon. And, as always, send us your feedback to unsecurity@protonmail.com.

View Details

Things aren't always as straightforward as they should be in information security. One thing it tends to be hard to determine is who is accountable for what. On this week's episode of the UNSECURITY podcast, Evan and Brad provide some tips and tricks for holding people accountable within our industry—but also life in general. Give episode 98 a listen, and don't hesitate to share your feedback at unsecurity@protonmail.com.

View Details

With the 2020 elections coming up quickly, it feels like the country is as divisive as it's ever been. What implications might that have on the information security industry? Brad and Evan unpack this in this week's episode of the UNSECURITY Podcast. As always, please send us your comments and feedback to unsecurity@protonmail.com.

View Details

Evan is flying solo on episode 96 of the UNSECURITY podcast. This week, he discusses the importance of context as it relates to making information security decisions. Without context, we often rely on emotion, bias, and assumptions to make decisions—which can be catastrophic. Give this episode a watch or listen and let us know what you think at unsecurity@protonmail.com.

View Details

As we all know, 2020 has been a wild ride. The culmination of events this year, including the pandemic, social justice events, economic issues, the election cycle, and more, have all made for a unique and changing information security landscape. In this episode, Evan and Brad discuss these changes and what they mean for the industry.

View Details

Evan is known for saying that the information security industry lacks a common language, making it hard for us to be on the same page. Using that line of thinking, Evan and Brad Google search "cybersecurity" on this episode and discuss their findings. Hopefully, this will shed some light on the challenges the industry faces in easing confusion. Give episode 94 a listen and let us know what you think at unsecurity@protonmail.com.

Link from discussion: https://apps.il-work-net.com/cis/clusters/OccupationDetails/100280?parentId=111100&section=glance&sectionTitle=At%20a%20Glance

View Details

Fresh off a really successful DEF CON with Team Ambush, Oscar Minks joins the UNSECURITY Podcast to reflect on the conference and its competitions. Oscar leads FRSecure’s technical services team—which many members of compete at events together as Team Ambush. Listen to get an inside look at one of the biggest hacking events in the world. Then, give us your feedback on this episode (or any) at unsecurity@protonmail.com.

View Details

The UNSECURITY Podcast is sticking with its Women in Security series for yet another week. This week, Brad and Evan are joined by Lee Ann Villella, who is the Senior Enterprise Security Sales Consultant at FRSecure, Program Director for the Minnesota Chapter of the Information Systems Security Association, and member of the Cyber Security Summit Advisory Board Committee (including the Women In Security Sub-Committee). We're lucky to have Lee Ann both at FRSecure and on the show. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

The Women in Security series of the UNSECURITY Podcast is back again this week for part 8. This week, Brad and Evan are joined by Theresa Semmens, who is the current CISO at the Nevada System of Higher Education. Having also served as the AVP/Chief Information Security Officer at the University of Miami and the CISO at North Dakota State University, Theresa brings an unmatched perspective on security programs and careers within colleges and universities. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

We've gotten great feedback on the Women in Security series thus far, so we're keeping the ball rolling. Part 7 of the series features Amy McLaughlin, who has an incredible background working in InfoSec in education—including the State of Oregon, the Consortium for School Network (CoSN), Chemeketa Community College, and Oregon State University. Get to know Amy and her experiences in the industry by giving episode 90 a listen. As always, feel free to submit feedback and/or questions to us at unsecurity@protonmail.com.

View Details

The quest to gain perspectives from women in the information security industry continues this week as Brad and Evan welcome their sixth guest, Judy Hatchett. Judy has experience operating in security departments across a number of industries including consulting, healthcare, manufacturing, and food. She's currently the CISO Surescripts, a health information network designed to increase patient safety, lower costs, and improve quality of care. Check out what Judy has to say about the information security industry, and let us know what you think at unsecurity@protonmail.com.

View Details

Episode 88 is part 5 of the UNSECURITY Podcast's Women in Security series. In this week's show, Evan and Brad interview Andrea Hatcher. Andrea is a senior majoring in Cybersecurity Analytics and Operations at Pennsylvania State University, and the guys chat with her about why she chose this path, her school's program, challenges, advice, and more. Give it a watch or listen and let us know what you think at unsecurity@protonmail.com.

View Details

Episode 87 marks part four of UNSECURITY's "Women in Security" series. This week, Evan and Brad chat with Kristin Judge, the current founder and CEO of the Cybercrime Support Network. With experience well beyond her current role, they talk about what the industry has been like from her perspective, advice for people starting out, and the claimed talent shortage that exists. Give it a listen or watch and let us know what you think at unsecurity@protonmail.com.

View Details

Part three of the UNSECURITY Women in Security series features Victoria Fogarty—a security analyst and member of the vCISO team at FRSecure. You’ll get to meet her and hear her perspective on all sorts of things, including the information security industry, her journey, and what it’s like to do her job. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

In the second episode of the UNSECURITY Podcast's Women in Security series, Evan and Brad chat with Lori Blair. Lori is a Senior Security Analyst with FRSecure and has done fantastic work over a 35-year career in IT and security. Together, the three discuss her path and some of her thoughts on the industry. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Brad and Evan start their new "Women in Security Series" this week. This will be a four-part series where they connect with women in the information security industry around their experiences. First is Renay Rutter, the Chief Operating Officer for FRSecure. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

In the hustle and bustle of today's society, taking a step back to look at the "why" sometimes gets lost. When it comes to information security, we do what we do not just to protect data, but the people behind it. In this week's UNSECURITY episode, Brad and Evan take a deep dive into what it means to serve people in this industry—not only from a customer side, but an employee one too. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

It's hard to talk about anything other than current events with the events that have transpired over the last few months, really. As always, Brad and Evan take what's happening across the country and look at it from a business and information security lens. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

On Monday, May 25, CSO Online published an article outlining the "six hard truths that security pros must learn to live with." Evan and Brad take episode 81 to break down their list and provide their reactions to each. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

After getting a ton of questions about it, and realizing just what kinds of search volume it's getting online, Evan and Brad decided to take episode 80 and clear the air on Zero Trust. What is Zero Trust? Is it really new? Is Zero Trust even possible? If I want Zero Trust, what do I need to do? What common mistakes should I look out for? Dive into this week's episode to get these questions answered, then let us know what you think at unsecurity@protonmail.com.

View Details

In this week's episode of the UNSECURITY Podcast, Evan and Brad take a deep dive into a recent report from the Consortium for School Networking (CoSN) titled “The State of Edtech Leadership in 2020." Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad add to last week's discussion about working from home in episode 78 of the UNSECURITY podcast. Together, they discuss the past, present, and future of work from home in relation to COVID-19, tips for information security while working remotely, and some tools that can help. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

The challenges of working from home extend far beyond our kids bugging us, the dog needing to be let out every five minutes, and a constant urge to go to the fridge. Working from home poses security challenges and risks as well. In this week's episode of the UNSECURITY podcast, Brad and Evan discuss some of those challenges. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad are joined this week Serge Suponitskiy from Flight Centre. Together, the three guys will catch up on what's been going on in Serge's world, and then break down a petty war between Rapid7 and Qualys from last week. You're not going to want to miss this one! Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Brad and Evan are back for the 75th installment of the UNSECURITY podcast. This week, they take a positive spin on the COVID-19 outbreak—discussing hope and how FRSecure is trying to instill it. They'll also dive a little deeper into the security-related issues we've seen around Zoom. Give this one a listen and let us know what you think at unsecurity@protonmail.com.

View Details

In this week's episode of the UNSECURITY podcast, the guys are joined by Jim Nash who serves as both a state representative for Minnesota, as well as FRSecure's Information Security Evangelist. Together, the three talk primarily about what's going on in Minnesota, other state governments, what Jim's doing in the community, as well as information security impacts—all relating to COVID-19. Give episode 74 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

In this week's episode of the UNSECURITY podcast, Brad and Evan are joined by Oscar Minks. Oscar is the director of technical services at FRSecure and heads both the pen testing operations, as well as the incident response team. The three of them discuss incident response, scams, and physical security considerations in the wake of the COVID-19 outbreak. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

It's hard not to talk about what's going on with the COVID-19 pandemic right now. It's impacting all of our daily lives on a monumental level. Information security is no different. Evan and Brad break down the current state of information security amidst the COVID-19 pandemic in this week's episode. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad discuss the impact of the novel coronavirus COVID-19 on the world, Evan's experience last week on a cruise and returning home, new information security concerns as a result of the changes during the pandemic situation, and the importance of remaining calm and avoiding the panic during these turbulent times.

View Details

With Evan on vacation, Brad is joined by Ryan for another episode. This week, Brad and Ryan discuss voting machine and election device security given the Super Tuesday elections held last week—as well as the 2016 debacle. Give episode 70 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan is back in the saddle after a week at RSA, and wraps up the conversation with Brad bout infosec roles and responsibilities—this time in the home. Give episode 69 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Brad hosts episode 68 as Evan and Ryan "Cola" Cloutier call in from RSA. They pick up where last week left off about information security roles and responsibilities. This time they look a little more granularly at each component of the business and the role that department plays in infosec. Part 3 next week! Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Welcome to episode 67 of the UNSECURITY podcast. This week, Evan and Brad discuss roles and responsibilities. One of the foundational components of information security is understanding and implementing roles and responsibilities. Part one of a two-part episode, this week talks about information security roles and responsibilities at a macro level. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Brad and Evan are back with another episode of the UNSECUIRTY podcast. Episode 66 features a conversation about how to speak with your board of directors or executive leadership about information security. They also touch on the new and upcoming CMMC requirements and, as always, some relevant news stories. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad are not shy about calling it like they see it in this episode of the UNSECURITY podcast. There are a lot of companies and people in the information security space that want your money and only your money. They're more than willing to sell you things you don't need and that won't help improve your security posture, just so they can make a buck. Listen in to see how the money grab impacts our industry. Let us know what you think at unsecurity@protonmail.com.

View Details

Episode 64 features an in-depth conversation from Brad and Evan about vendor risk management. Together, they discuss audit-style certifications, security risk assessments, and the differences between the two. Hopefully, this will help both vendors and those in charge of managing vendor security navigate better. Check it out, and let us know what you think at unsecurity@protonmail.com.

View Details

Evan is back in the U.S. and joins Brad and Ryan in-studio for a discussion about his recent writing getaway, an update to the US/Iran conflict, and FRSecure's CISSP Mentor Program as an extension of its mission. Give episode 63 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

You'd probably have to be living under a rock to not know what's going on between the United States and Iran. What you may not know is that there are imminent cyber threats as a result of the tension. Episode 62 outlines some of the incidents we've already seen as a result, what we can expect to see moving forward, and how what you can do to protect yourself. Listen in with Brad, Evan, and Ryan, and let us know what you think at unsecurityu@protonmail.com.

View Details

Episode 61 welcomes recurring guest, Ryan Cloutier, as he begins his new venture with SecurityStudio. Together, Ryan, Brad, and Evan (calling in from sunny Cancun) recap 2019 and look ahead to 2020. Give it listen and let us know what you think!

View Details

Brad and Evan wrap up 2019 on a not-so-positive note, dismayed at the state of the information security industry. They take a realistic look at the increase in breaches and corresponding increase in breach fatigue, the challenges local governments and schools are facing with infosec, and individual security. It's not all doom and gloom, but we must face facts in order to fix the industry.

View Details

In episode 59, Brad and Evan are joined by FRSecure President John Harmon. They discuss the upcoming holiday break, recap the SecurityStudio Roadshow so far, and talk about the latest news in the industry.

View Details

In episode 58 of the UNSECURITY Podcast, Evan and Brad are joined by Mike Dronen. The three of them chat about cybersecurity threats within K-12 schools that pose a problem for their CIOs, and some tips administrators, educators, and parents can use to keep student and staff data safe. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Justin Webb is back for part 2 of the conversations in episode 56, centered around the California Consumer Privacy Act, primarily. Brad and Evan briefly provide an update on the new show format and some information security news as well. Give it a listen and let us know what you think at unsecurity@protonmail.com

View Details

In episode 56 of the UNSECURITY podcast, Evan and Brad are joined by Justin Webb. Stories have been circulating about Target suing their former insurance provider from the infamous breach of 2013—a breach Evan served on a special litigation committee for. Justin is a data privacy attorney from Milwaukee and provides some insight into the this story from a legal perspective. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Brad and Evan are joined by Zoe Bundy for episode 55. Zoe is the founder of Brainy Ladies, an organization that helps introduce science, technology, engineering, and mathematics (STEM) as career paths for girls and women. Together, the three discuss Zoe's path, her organization, and advice she has for girls and women looking to get into STEM. Give it a listen and let us know what you think at unsecurity@protonmail.com.

You can learn more about Brainy Ladies and get a hold of Zoe here:
@STEMBrainyLadies on Instagram
hello@girlsinstemmagazine.com
girlsinstemmagazine.com

View Details

Evan and Brad are back for episode 54 of the UNSECURITY podcast. They're joined by Kenneth Bechtel and discuss this interesting phenomenon we're experiencing where we're short on information security talent, but somehow good security professionals are struggling to find jobs. Check it out and let us know what you think at unsecurity@protonmail.com!

View Details

The 53rd episode of the UNSECURITY podcast is a special one. The episode is hosted by Brandon Matis from the FRSecure marketing team as he takes a look back at the first year of the UNSECURITY podcast—recapping some of the most interesting topics and conversations from episodes 1-52. Check it out and let us know what you think at unsecurity@protonmail.com.

View Details

Happy one-year anniversary to the UNSECURITY podcast! In episode 52, Brad and Evan are joined by David Kruse to discuss cyber insurance, the Fitbit/Google news, and (of course) the first year of the UNSECURITY podcast. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

This week's episode includes an look at penetration testing, featuring special guest @vimk1ng (Eric Hanson), FRSecure's Penetration Testing Lead, joining Evan and Brad from Reno, NV. You'll also get an update on the #S2Roadshow, with Evan and John in Virginia and San Diego last week. Check it out and let us know what you think at unsecurity@protonmail.com

View Details

In the 50th episode of the UNSECURITY Podcast, Evan and Brad give a recap of week 3 of the #S2Roadshow, discuss what it's like to be a security person learning how to take on business objectives like strategic planning, and review some interesting news stories from the week. Check it out and let us know what you think at unsecurity@protonmail.com

View Details

Brad and Evan are reunited in-studio for episode 49 of the UNSECURITY podcast. With Evan still touring the country for the #S2Roadshow, the conversation starts with a recap. The duo adds a discussion about IT Security, Information Security, Cyber Security, and Physical Security. They field a listener request about the Cybersecurity Maturity Model Certification for the third segment and wrap up with a Twitter exchange about what it takes to do InfoSec as a job. There's a lot to listen to this week, so get after it and let us know what you think at unsecurity@protonmail.com.

View Details

With Brad traveling, Evan is joined by John Harmon for episode 48. With the two of them touring the country together for the #s2roadshow, the episode centers around the goings-on behind their travels. They'll also add to the recent ongoing vCISO discussion with John's perspective—as he's hired many vCISOs over his career. Give episode 48 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

In episode 47, we catch up with Evan as he still returns to "normal" after his visit to Bulgaria, learn about the launch of S2Org and Evan and John's upcoming #S2Roadshow, and get the scoop on the SecurityStudio partner jumpstart. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Episode 46 features jam-packed discussions on the most recent installment of FRSecure's Hacks & Hops event series, the upcoming speaking engagements Evan and Brad are preparing for (including the big SecurityStudio roadshow), the importance of mental health in the security industry, and some recent infosec news stories. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan's back state-side for episode 45 of the UNSECURITY podcast. He and Brad add to last week's conversation about vCISOs by discussing what someone would have to do to become one. The guys also chat about Evan's recent trip to Bulgaria and make an exciting announcement. You won't want to miss this one! Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

With Evan in Bulgaria, Brad is joined in-studio by recurring guest Ryan Cloutier. Together, the three guys discuss the correlation between security and liability. After, they dive into Ryan's mission—helping "humans" (non-security people) secure themselves better. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Welcome to the Labor Day special of the UNSECURITY podcast. Evan and Brad give an inside look at virtual chief information security officers—what they are, what makes a good one, who needs one, and more. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Returning guest Christophe Foulon is back for another great discussion on this week's episode of the UNSECURITY podcast. Evan and Brad pick Christophe's brain about the projects he's working on, his passion and drive as a security pro, and why security boils down to helping people. Don't miss this one! As always, questions, comments, and feedback are welcome at unsecurity@protonmail.com.

View Details

Evan and Brad are joined this week by Oscar Minks, who runs the technical team at FRSecure. The three of them recap DEFCON from Oscar's perspective, and they introduce S2Me—a new platform for people to measure their own personal security. Give episode 41 a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Episode 40 of the UNSCURITY podcast features another lengthy discussion on incident response. Brad was quickly immersed in responses after returning from time off, so Evan and Brad discuss the projects he's working on. The discussion also ties in two events FRSecure is a part of: Hacks & Hops and DEFCON. The guys give an update on the exciting FRSecure-run event on incident response in September and recount how the FRSecure team did at DEFCON warl0ck gam3z.

If you'd like to attend Hacks & Hops on September 19th at U.S. Bank Stadium, please feel free to use the promo code UNSECURITY for 50% off the price of regular admission.

View Details

In the latest installment of the UNSECURITY podcast, "Ben" joins Evan once again to give us the lowdown on what he has been up to lately. His latest project has been enlightening, to say the least. Episode 39 is a real treat! Check it out, and let us know what you think at unsecurity@protonmail.com.

View Details

With Brad on vacation, Evan is joined by president John Harmon for episode 38 of the UNSECURITY podcast. Together, the two chat about Project Bacon—a project they'll be taking on before the end of the year. Check it out, and let us know what you think at unsecurity@protonmail.com.

View Details

In a jam-packed episode 37, Evan and Brad are joined by state representative Jim Nash to circle back on the civic ransomware discussion, recap Evan's #100DaysofTruth, and call BS on some startling allegations that have been seen in the information security industry recently. Dig in and let us know what you think at unsecurity@protonmail.com.

Also, join us for our next Hacks & Hops event—BREACHED! What to Do When Your Defenses Fail— on Sept. 19 at U.S. Bank Stadium in Minneapolis. Use the code UNSECURITY for 50% off.

https://www.eventbrite.com/e/breached-what-to-do-when-your-defenses-fail-tickets-62585025496?aff=podcast

View Details

There's a lot of money changing hands in the information security world. Unfortunately, a lot of what's being sold is just blinky lights—things that are flashy, but don't actually make anyone's security better. Organizations look for quick fixes and easy buttons out of fear of a breach, despite the fact that it takes legitimate, consistent work and buy-in to make their security better. Evan and Brad break down the money grab in episode 36. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad are refreshed and raring to go after an enjoyable Fourth of July weekend. This week for episode 35, they provide a refresher on the recent city government ransomware attacks and also talk about the transfer of wealth that happens when attackers steal from our businesses and organizations. Some reports suggest that the global cost of breaches by 2021 will cause the greatest transfer of wealth in world history. Are these reports true, or are they just more scare tactics? Listen in and see what Brad and Evan think. Let us know what you think at unsecurity@protonmail.com.

View Details

Less than one short week after Evan and Brad discussed the Riviera Beach, FL ransomware attack, another Florida city has paid off attackers in a ransomware scheme. In episode 34, Evan and Brad take a look at what we can do about civic ransomware, and how what we've learned about these cities applies to schools as well. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

The city of Riveria Beach, Florida experienced a ransomware attack last week. This is the third major city affected by ransomware in the last 12 months or so, following Atlanta and Baltimore (who was hit twice). Episode 33 of the UNSECURITY podcast features an in-depth breakdown from Brad and Evan about the Riveria Beach attack, and municipality security in general. GIve it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan fills in leading for this episode of the UNSECURITY podcast with Brad wrapped up in numerous incident response engagements. Together, the two of them chat about the numerous security standards the information security world has the ability to adhere to. What do we use standards for, why are there so many, and which ones are best? After that, the guys discuss the ASCO ransomware and what they know about it. Give episode 32 a listen and let us know what you think at unsecurity@protonmail.com

View Details

Epsidode 31 boils the blood of Evan and Brad a little bit. The topic of discussion stems around a recent meeting Evan sat in on where the salespeople pushed a solution before even getting a real understanding of what the problem actually was. Join the guys for a discussion on "sales vs. solutions," and let us know what you think at unsecurity@protonmail.com.

View Details

Incident response has become one of the most pertinent conversation pieces in the information security world. Many organizations are starting to realize that it's important to be prepared for what to do when a breach occurs— because we can't prevent all incidents from happening. Episode 30 centers around this.

View Details

In the spirit of Memorial Day and remembrance, Evan and Brad decided to do something a bit different for episode 29. The guys share audio of L0pht Heavy Industries testifying before the United States Senate Committee on Governmental Affairs (live feed from CSPAN) on May 19, 1998. You'll notice that a lot of the issues discussed in the trial still translate today, despite it being over 20 years ago. Give it a listen, and let us know what you think at unsecurity@protonmail.com

View Details

Evan's been gone a lot lately. Back in the office for episode 28, him and Brad take a look back at some of the recent presentations and conferences the two have made appearances and presented at. After, they break down some of the recent information security news stories like Microsoft updates, WannaCry, Cyptography, and more. Give it a listen and let us know what you think at unsecurity@protonmail.com

View Details

Epsidode 27 is packed with meaningful discussion around how we can do a better job of teaching our children the importance of information security and internet safety starting at a young age. To do so, Brad and Evan are joined by Ryan Cloutier— a decorated security architect and security education advocate. Check out episode 27 and give us feedback at unsecurity@protonmail.com.

View Details

Evan recently wrote an article detailing why he thinks there is a lot of ego an arrogance among people who work in the information security industry. This topic has drawn some interesting conversations and debate on social media since it's been posted, so Evan and Brad made this their primary focus for Episode 26's discussion. They also chat a bit about Evan's recent 'normal people" research, and break down the latest infosec news as always. Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad are back with episode 25 of the UNSECURITY podcast. This week, they're joined by special guest, Christophe Foulon, a senior cyber risk management consultant for ConQuest Federal. Together, the three of them chat a bit about Christophe's path in security, give some password guidance to the listeners, and end with information security news story discussion (per usual). Check out episode 25 and, as always, let us know what you think at unsecurity@protonmail.com

View Details

Episode 24 of the UNSECURITY podcast takes a deep dive into the differences between what it means to be "secure" vs. what it means to be "compliant." Give it a listen and let us know what you think at unsecurity@protonmail.com

View Details

Evan leads the discussion in a jam-packed episode 23 of the UNSECURITY podcast. This week, the guys chat about the FRSecure CISSP Mentor Program, Evan's new #100DaysOfTruth concept, what it's like to podcast about security, and the recent stories in InfoSec. Give it a listen and let us know what you think at unsecurity@protonmail.com

View Details

Brad and Evan are back at FRSecure HQ for episode 22. They discuss their recent travels, the CISSP Mentor Program starting this evening, industry news, and how to deal with toxic coworkers (as requested by a listener). Give it a listen and let us know what you think at unsecurity@protonmail.com.

View Details

Evan and Brad are back together for episode 21, but are recording from Rochester, NY. Other than talking about what the heck they're doing out there, they took a look back at our recent Hacks & Hops event and summarized its discussion surrounding vendor risk management. In addition, the guys chatted about how you can deal with customers that treat you poorly and finished up with ways that you can stay current on InfoSec news and trends without bogging yourself down. Check it out and let us know what you think at unsecurity@protonmail.com!

View Details

With Brad on vacation, Evan was joined this week by Shawn Pollard, an analyst at FRSecure. The two of them discuss ways in which a person can stay healthy while working in a security job— part five of Evan's five-part series on starting a security career.

As always, please give us your feedback on how the episodes are going, and don't be afraid to send in questions or topic suggestions to unsecurity@protonmail.com. We welcome them!

View Details

Evan leads the discussion this week from Louisiana as some of his travel plans were foiled. Him and Brad chat about cruise ship internet, RSA, the importance of mental health as a security professional, even more incident response topics, and the big Boening news. Give it a listen and (as always) let us know what you think at unsecurity@protonmail.com!

View Details

Episode 18 is a little bit different than weeks prior. We forced Evan to take a vacation and promised his wife we wouldn't give him a dial-in number. So instead of Evan, Brad cohosted this week with our VP of Ops, Renay Rutter. The two of them will take a deep dive into the world of incident responses— since we've seen so many of them lately. Tune in to learn more about how to properly prepare for an incident and how to handle one once it does occur.

As a reminder, FRSecure is hosting our spring Hacks & Hops event at Dayblock Event Center in Minneapolis on March 28. Join us to learn about the growing topic of third-party vendor risk management. Use the code UNSECURITY for half-off admission. https://hhdefend.eventbrite.com/?aff=podcast

View Details

Evan leads this week as he and Brad walk through the security principles FRSecure has in place for the organization. Principles are vital parts of every information security program as they serve as guidelines and reminders. The two of them will give an inside look at the FRSecure principles (and why they exist) so that you can get a better understanding of how you can apply similar principles to your business.

View Details

Brad and Evan are joined by very special guests this week in a unique episode of the UNSECURITY Podcast. Brad and Evan's wives joined the show to give an inside look at how working in the information security industry can have an impact on your life outside of work (for better or worse). After the interview, the guys break down some of the week's top news pieces, as usual. Give episode 16 a listen and let us know what you think!

View Details

Episode 15 starts out with a bang as Evan and Brad break down two incidents that they recently worked on, and another one that's on the way. They'll also go into detail about a Breach civil lawsuit OSINT, a visit with Lockton, keynoting a manufacturing event and— as always— break down some current events/news topics sweeping the industry.

View Details

Brad leads episode 14 with the help of Evan and M1ndFl4y, aka "Ben." M1ndFl4y is a social engineer at FRSecure, and brings with him fascinating stories about his ability to gain access to facilities and information that he's not permitted to. Brad and Evan discuss some of those with him, and then chat about how someone could get into social engineering or learn more about the field.

View Details

Evan and Brad are joined in episode 13 by Jim Nash, who is the assistant minority leader for the Minnesota House of Representatives and also a member of the FRSecure family. Naturally, the state of security in local government and in the state of Minnesota were major talking points this week. In addition, the guys chatted about incident response planning and current events like Apple's FaceTime bug. Give it a listen and let us know what you think!

View Details

In episode 12 of the UNSECURITY podcast, Brad and Evan take an in-depth look at the state of employment in the information security industry, including some ways people who are interested in the industry can break through. One example is FRSecure's CISSP Mentor Program, which they also discuss in this episode. Finally, Brad and Evan chat about the news circulating this week surrounding the cost of a cyber-attack, Google's GDPR fine, and hijacked Nests. As always, if you have questions, comments, or suggestions, please pass them along!

unsecurity@protonmail.com
frsecure.com/cissp-mentor-program

View Details

With Evan back from his trip to Cancun writing his second book, it was a perfect time for the first face-to-face recording of the UNSECURITY Podcast. In our 11th episode, Brad and Evan discuss Evan's writing trip, the next release of the FISASCORE® risk assessment, and current news topics like the American military, a flaw in Cisco routers, and Apple's privacy evangelism. Thanks for following along each week. The feedback and listenership have been exciting! Remember, feel free to send questions or comments to unsecurity@protonmail.com.

View Details

Brad hosts another great UNSECURITY Podcast episode with Evan. This week, they discussed information security book writing, day-to-day security challenges, the new Modlishka 2FA proxy tool (hacking 2FA), El Chapo’s chats, Zurich claiming “act of war” while refusing to payout for NotPetya, and another third-party data breach. While Brad’s back home, Evan tries to make this podcast work from a Starbuck’s in Cancun. Everything goes fine for a while until a bunch of kids show up to play Fortnite. Entertaining as usual. Be sure to tune in next week, after Brad and Evan tackle the audio issues!

View Details

In this episode, Brad and Evan discuss “Tom” (the "normal people" who are the reason behind what we do at FRSecure), the very soon-to-be-released UNSECURITY book, the next UNSECURITY book being written now, the next book later this year that Brad and I will be writing together, cool vendor risk management and NIST CSF stuff that Brad’s working on, and some current news:

2019’s First Data Breach: It Took Less than 24 Hours - https://www.cbronline.com/news/2019s-first-data-breach and https://www.abc.net.au/news/2019-01-01/victorian-government-employee-directory-data-breach/10676932

2019 security forecast: Cloudy and unsettled, with a chance of gloom - https://siliconangle.com/2019/01/01/2019-security-forecast-cloudy-unsettled-chance-gloom/

The 21 scariest data breaches of 2018 - https://www.businessinsider.com/data-hacks-breaches-biggest-of-2018-2018-12

Join us next week!

View Details

In the last episode of the year, Brad and Evan reflect on what made an impact in 2018 and what we can look forward to in the upcoming year. In episode 8, find out if Evan's 2018 security predictions came to fruition, learn about how many of the top organizations in the world are missing the memo when it comes to security executives, and listen to how GDPR almost ruined Christmas.

View Details

In this pre-holiday episode of the UNSECURITY podcast, Evan and Brad begin wrapping up 2018. They took a look back at the biggest vulnerabilities that impacted the information security industry this year, and broke down some of the current events that have presented themselves in the last few weeks of the year.

View Details

Brad Nigh hosts episode six of the Unsecurity podcast, where the guys are joined by Wade, a K-12 Director of Technology at a mid-sized public school district. They discuss their innovative Compass Cybersecurity and Applied Mathematics course and how they’re preparing the next generation of information security pros. They also discuss the current skills shortage in the industry, Australia’s new encryption law, a 12-state lawsuit against a medical records company, and the Equifax breach according to the newly released House report.

View Details

In this week's episode, Evan and Brad are joined by Minnesota State Representative Jim Nash to discuss the state of cyber security and information security in state government. They also break down the recent NRCC hack, more about Google and Marriott, the Quora breach, and sextortion in the U.S. military.

View Details

In episode 4 of the Unsecurity Podcast, Evan and Brad break down the massive Marriott breach that happened this week. They also take some time to discuss Microsoft's multi-factor authentication, GDPR issues, third-party risk management, and more.

View Details

FRSecure's Evan Francen and Brad Nigh wrap up Thanksgiving week with episode 3 of UNSECURITY. In this episode, Evan and Brad break down connected devices and IOT, the healthcare industry, and incident/breach response.

View Details

In Episode 2 of the UNSECURITY podcast, Brad and Evan discuss current information security events and industry news. Brad led this podcast, and he chose the following topics for discussion:

• Secret Service Warns about ID Theft through USPS "Informed Delivery" Service
• Google’s G Suite, Search and Analytics Taken Down in Hijacking
• Internet con men ripped off Pathe NL for €19m in sophisticated fraud
• Botnet pwns 100,000 routers using ancient security flaw
• Employees’ Poor Security Habits Getting Worse, Survey Finds

View Details

In this episode, the first UNSECURITY podcast, Evan and Brad discuss current information security events, including what they're both working on, and industry news.