No Password Required: Recent Episodes

Cyber Florida

The No Password Required Podcast connects with the cybersecurity industry’s most interesting professionals and shares their stories. No Password Required covers a variety of tech topics, from the cyber-related challenges facing law enforcement to the advent of quantum computing, this podcast explores the people and topics at the forefront of the field.

View Details

No Password Required: Next Gen - Ep. 3 - Kieran Human

How Lead Cybersecurity Engineers Actually Think

In this episode of No Password Required: Next Gen, Yazzel interviews Kieran Human, Lead Cybersecurity Engineer at ThreatLocker. From research to working directly with ThreatLocker's CEO on new security initiatives, Kieran gives an inside look at what it's really like to work on the front lines of cybersecurity.

Kieran stands out as a cybersecurity professional by hares why curiosity, strong communication, and understanding the bigger picture are just as valuable as technical skills. He also reflects on one of his proudest career moments, writing a compliance white paper that earned praise from ThreatLocker's CEO Danny Jenkins, and explains how that experience reinforced the importance of research, writing, and always looking for ways to improve.

Kieran also explains why Zero Trust security is becoming essential, teaches viewers a few cybersecurity terms that are guaranteed to impress at dinner, and even reveals why the Terminator would be his ultimate cybersecurity teammate!

Whether you're exploring a career in cyber or looking for practical advice from someone working in the field every day, this episode is packed with insights for the next generation of cybersecurity professionals.

Presented by ThreatLocker

Supported by DerScanner

Follow Kieran on Linked in here: https://www.linkedin.com/in/kieran-human-5495ab170/

Chapter List:

00:00 Introduction to Cybersecurity and Career Path

02:54 Key Skills and Qualities for Success in Cybersecurity

06:07 Impact of AI and Zero Trust in Cybersecurity

06:56 Fun Insights and Closing Thoughts

View Details

Philipp Leo — Swiss cyber expert, diplomat, and military officer, always two steps ahead of the storm

No Password Required Season 7: Episode 7 - Philipp Leo

Philipp Leo co-founded Leo & Muhly Cyber Advisory, a strategic advisory firm specializing in cyber risk, resilience, and geopolitics. Now consulting with governments and private firms in Switzerland and abroad, Philipp has served as a UN observer on the Korean DMZ, trained the next generation of Swiss Armed Forces cyber specialists, and taught at the University of Glasgow. He is also part of Europol's network of experts in data protection and cybercrime and has published stateside in MIT Sloan Management Review.

In this episode, Philipp shares his journey from a Swiss bank he couldn't wait to leave to the Korean border, and eventually to the boardrooms of executives who still think cyber risk is someone else's problem. He breaks down the three most dangerous misconceptions executives have about cyber risk, why the CISO is too often a poster child rather than a decision-maker, and the challenges to cyber insurance in Europe.

Cyber attorney Jack Clabby and co-host Kayley Jerrell talk with Philipp about his live crisis simulation that nobody can win, how to train cyber warriors, and how nation-state cyber conflict is looking more and more like the age of Caribbean pirates.

In the Lifestyle Polygraph, Philipp reveals his favorite book, his eye-opening, go-to celebratory drink, and the weight of his luxury umbrella. He also shares his favorite escape when the complexity of modern life gets to be too much and introduces us to a Zurich commuting tradition that involves swimming home through a river.

In this episode:

  • Philipp's journey from a Swiss bank he couldn't wait to leave to the Korean DMZ and eventually the boardrooms of Fortune 500 executives (00:27 - 02:22)
  • The three most dangerous misconceptions executives have about cyber risk and why cyber risk is a corporate problem, not a technology problem (04:19 - 05:30)
  • How Philipp's live crisis simulation works, why nobody can win it, and why that's exactly the point (05:49 - 08:47)
  • Why cyber crisis teams have improved dramatically but leadership boards remain the weakest link (06:30 - 08:47)
  • The CISO poster child problem: why most CISOs have the accountability without the authority (09:54 - 11:00)
  • Why cyber insurance in Europe has largely failed to deliver and what happens when attackers find your policy before you do (11:17 - 13:44)
  • The OFAC twist: what happens mid-exercise when a Swiss bank decides to pay and then learns the attackers are on the sanctions list (18:38 - 19:31)
  • Training Swiss Armed Forces cyber specialists and why the first lesson is that the other side plays by no rules (19:47 - 21:37)
  • Whether nation states can ever beat the cyber threat and why the east side of Vienna tells you everything you need to know (21:54 - 23:25)
  • Why nation-state cyber conflict has become remarkably similar to the age of Caribbean pirates (23:46 - 24:23)
  • The Lifestyle Polygraph: Endurance, Campari Red Bull, a three-ounce umbrella, a cabin in the Alps, and swimming home through a Zurich river (00:04 - 12:03)

Timestamp Highlights:

  • (00:27) From Swiss banker to UN observer on the Korean DMZ
  • (04:19) The three misconceptions executives have about cyber risk
  • (05:49) The crisis simulation nobody can win and why that's the whole point
  • (09:54) Why the CISO is too often a poster child without real power
  • (11:17) Why cyber insurance in Europe has largely failed
  • (18:38) The OFAC twist that stopped a Swiss bank mid-exercise
  • (19:47) Training Swiss cyber warriors to understand the other side plays by no rules
  • (21:54) Nation states vs. cyber threats: are defenders always outpaced?
  • (23:46) How nation-state cyber conflict mirrors the age of Caribbean pirates
  • (07:25) Always prepared: the three-ounce umbrella that nobody sees

Resources & Links:

  • Leo & Muhly Cyber Advisory
  • Philipp Leo on LinkedIn
  • ThreatLocker — Presenting sponsor
  • DerScanner — Supporter of this podcast
  • Cyber Florida — The Mother Ship

View Details

In this episode:

  • Why Rob always asks for the team nobody wants and what the turnaround process actually looks like (00:31 - 02:10)
  • From sleeping in his car at 18 to Fortune 500 executive, and the kindness from strangers he still carries with him today (02:10 - 04:32)
  • What a successful team turnaround actually looks like, including eight leaders in ten years and what changed (04:32 - 07:00)
  • Servant leadership, why career leaders almost always fail, and the power of coming in with a partial idea instead of a completed thought (07:00 - 09:33)
  • The truth about the cybersecurity job shortage and why open jobs almost never mean what you think they mean (09:33 - 11:37)
  • Why communication skills matter more than technical ability and what happens when a technical score of 10 meets a communication score of two (11:37 - 13:22)
  • Cyber is a marathon, not a race, and why passion got Rob a job at Disney over people with far more experience (13:22 - 15:27)
  • Neurodiversity in the workplace, getting diagnosed with autism at 40, and why really smart doesn't get jobs anymore (15:27 - 17:51)
  • The colleague who told Rob everyone thought he was a jerk, the boss who explained why, and the apology tour that followed (17:51 - 21:31)
  • Getting laid off from Disney, becoming a ghost on the internet, and accidentally building the BowtieSecurityGuy brand (21:31 - 25:47)
  • Tying self-worth to career, crying before job interviews, and the four words his wife said that changed everything (25:47 - 27:40)
  • The 3am LinkedIn message from India that made Rob realize he was in this for life (27:40 - 29:40)
  • Zero expectations, zero conditions, and why Rob messaged Rex about a hat with absolutely nothing to gain (29:40 - 31:40)
  • Immersion therapy, D&D every Monday, and why a bad public speaker is more memorable than a good one (34:03 - 37:16)
  • Rejection sensitivity dysphoria, masking, and why setting the tone in a room changes everything (37:16 - 39:23)
  • The 3,000 manual LinkedIn messages, the algorithm daddy slap, and pricing yourself where you want to be (39:23 - 40:43)
  • Zero expectations as a life philosophy and why people don't quit jobs, they quit bosses (40:43 - 42:27)
  • Learning to walk three times, leg braces, and why cutting through grass almost brought Rob to tears (42:27 - 44:40)
  • What Rob tells job seekers who have been at it for two years: you are ten nos away from your dream job (44:40 - 47:09)
  • The cybersecurity salary reality check and why 3,500 to 4,500 people graduate with cyber degrees every single month (47:09 - 48:50)
  • Rob's thank you to the people who know who they are, his battle buddies, and why vulnerability is a strength (48:50 - 51:28)
  • Fail with style, the Walt Disney Haunted Mansion story, and why Rob never took no for an answer at Disney (51:28 - 56:39)

Timestamp Highlights:

  • (00:31) Give me the team nobody wants
  • (02:10) Homelessness at 18 and the kindness that stayed with him
  • (07:00) Servant leadership and the power of a partial idea
  • (09:33) The real reason there are so many open cybersecurity jobs that never get filled
  • (11:37) Stop applying. Start connecting.
  • (13:22) How passion got Rob hired at Disney over NSA agents
  • (17:51) Getting diagnosed with autism at 40
  • (21:31) Getting laid off from Disney and accidentally building a brand
  • (27:40) The 3am message that changed everything
  • (34:03) D&D, immersion therapy, and why bad public speakers are more memorable
  • (42:27) Learning to walk three times and why Rob doesn't take anything for granted
  • (51:28) Walt Disney, the Haunted Mansion, and failing with style

Resources & Links:

  • BowtieSecurityGuy — Rob's brand across all platforms
  • ThreatLocker — Presenter of No Password Required Breakout Room
  • Cyber Florida — The Mother Ship

View Details

Shane Tews — Non-Resident Senior Fellow at AEI and the person who explained the internet to Capitol Hill

No Password Required Season 7: Episode 7 – Shane Tews

Shane Tews is a Non-Resident Senior Fellow at the American Enterprise Institute, where she focuses on cybersecurity, privacy, artificial intelligence, and internet governance. She is also President of Logan Circle Strategies, a strategic advisory firm working at the intersection of technology and policy. Before her think tank work, Shane helped introduce modems to the George H.W. Bush White House, walked the halls of Capitol Hill explaining the internet to blank-staring legislators, and spent years at VeriSign helping shape the foundational frameworks of how the internet would be governed.

In this episode, Shane traces her unlikely path from the Bush administration to becoming one of Washington's most trusted voices on tech policy. She breaks down why regulating outcomes rather than inputs is the only sensible approach to technology governance, why the US and EU are operating from fundamentally different innovation philosophies, and why a national privacy bill is long overdue. She also explains why most organizations and individuals are far less protected than they think and why nobody knows who to call when something goes wrong.

Jack Clabby and co-host Kayley Melton talk with Shane about legacy system vulnerabilities, the cybersecurity implications of agentic AI, and what policymakers absolutely must get right over the next decade. She also reflects on what the CISA reauthorization limbo means for companies that don't even know they've lost liability protection.

In the Lifestyle Polygraph, Shane reveals she has 20,000 emails across eight accounts, admits she fakes laughs at bad jokes out of Midwestern politeness, shares her obsession with The Bear and Peaky Blinders, and tells us about her children's book project using Google Omni called "Shane on a Train."

Follow Shane on LinkedIn and on X at @ShaneTews. Find her work at AEI.org and TechPolicyDaily.com.

No Password Required is presented by ThreatLocker

In this episode:

  • Shane's path from the George H.W. Bush White House to becoming Capitol Hill's go-to internet explainer (00:34 - 02:22)
  • Why the Clinton-era multi-stakeholder model got internet governance right and what that means for policy today (04:40 - 06:13)
  • The case for a national privacy bill and why 50 state standards aren't working (07:24 - 09:27)
  • What AEI covers and how Shane thinks about riding the top of the wave across the entire tech policy stack (09:35 - 11:23)
  • Legacy systems, vendor debt, and why outdated software is the easiest entry point for bad actors (11:30 - 13:34)
  • The gap between how protected people think they are and how exposed they actually are, including a generational perspective on MFA (14:07 - 16:25)
  • The biggest disconnect between everyday cyber reality and the policy world (16:59 - 20:35)
  • Government readiness for a major cyber attack and why most people don't have a plan (20:54 - 22:32)
  • How the US and EU innovation philosophies differ and why Europe's banking system is the real tech problem (22:41 - 25:38)
  • The DeepSeek false narrative and where the US is leading vs. reacting on AI (25:45 - 29:21)
  • The shift from AI features to AI coordination and what agentic AI means for cybersecurity permissions (29:28 - 32:16)
  • What policymakers must get right on AI over the next 10 years (32:25 - 34:11)
  • The Lifestyle Polygraph: inbox chaos, fake laughs, The Bear, and Shane on a Train (00:04 - 12:48)

Timestamp Highlights:

  • (00:34) Shane's origin story: modems at the White House and blank stares on the Hill
  • (04:40) Why the internet got policy right early on and what we can learn from it
  • (07:24) The case for harmonizing breach standards with a national framework
  • (11:30) Legacy systems and vendor debt as the easiest attack vectors
  • (14:07) The real gap between how protected people think they are and how exposed they actually are
  • (20:54) Government cyber readiness: do you know who to call when something goes wrong?
  • (22:41) US vs. EU innovation: why Europe's banking system is the real tech problem
  • (29:28) Agentic AI and the cybersecurity risks of permissions you forgot you gave
  • (32:25) What policymakers must get right on AI over the next decade
  • (06:44) Shane on a Train: using Google Omni to write a children's book series

Resources & Links:

  • AEI.org — Shane's think tank home base
  • TechPolicyDaily.com — Daily tech policy coverage
  • ThreatLocker — Supporter of this podcast
  • Cyber Florida — The Mother Ship

View Details

Show Summary:

Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this”

No Password Required Season 7: Episode 6 - Mudita Khurana

Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team.

In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months.

Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to.

In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas.

Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/

In this episode:

  • Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37)
  • The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00)
  • Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23)
  • The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41)
  • Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29)
  • How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26)
  • The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47)
  • Mudita’s favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13)
  • Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36)
  • Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21)

Timestamp Highlights:

  • (00:25) Mudita's 10-year journey into cybersecurity starting from India
  • (02:26) Mentorship’s critical role in her growth and her admiration for Vandana Verma
  • (09:29) Transition from management back to technical roles and why staying close to the work matters
  • (15:31) How AI fosters layered, modular security systems for faster adaptation
  • (17:06) The importance of community and trusted information sources in security
  • (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days
  • (25:19) Leh, Ladakh: Mudita’s ideal remote work location nestled in Himalayan beauty

Resources & Links:

  • Vandana Verma - Influential mentor in cybersecurity
  • ThreatLocker - Supporter of this podcast
  • Cyber Florida – The Mother Ship

View Details

Madeline Sedgwick — Cyber Threat Analyst at Palo Alto Networks and a DUUUUVALLL lifer

No Password Required Season 7: Episode 5 – Madeline Sedgwick

Madeline Sedgwick is a Cyber threat Researcher and Threat Analyst at Palo Alto Networks Unit 42, specializing in nation-state cyber activity, covert infrastructure, and cyber intelligence analysis. Before entering the private sector, she spent six years in the U.S. Navy as an intelligence specialist, helping support some of the earliest cyber operations under United States Cyber Command.

In this episode, Madeline shares her journey from joining the Navy to becoming one of the first certified cyber targeteers supporting offensive cyber operations. She discusses the realities of tracking covert threat actor infrastructure, why defenders must understand adversary behavior beyond alerts and signatures, and how intelligence analysis helps uncover the bigger picture behind cyber campaigns.

Jack Clabby and co-host Sarina Gandy talk with Madeline about fusion analysis, cyber warfare, leadership, and the challenges of translating highly technical investigations into actionable insights for government and industry leaders. She also reflects on the importance of humility in leadership, mentoring, and learning to navigate high-pressure situations with confidence and curiosity.

In the Lifestyle Polygraph, Madeline debates cybersecurity in the Star Wars universe, explains her Weird Al Yankovic Dragon Con costume, reflects on her time playing bass in a metal band, and proudly shares why Jacksonville, Florida, will always be home.

Follow Madeline on Linked in: https://www.linkedin.com/in/mesedgwick/

Chapters:

02:10 Intro-Madeline Sedgwick

09:00 The Role of Cybersecurity in National Security

12:08 Understanding Covert Networks and Threat Intelligence

14:52 Fusion Analysis in Cybersecurity

18:04 The Importance of Distinguishing Threats

20:52 Challenges in Cybersecurity Response

23:58 Briefing Decision Makers on Cyber Threats

27:52 Understanding Adversary Intent and Risk Communication

30:12 Leadership Lessons from the Navy

34:33 The Importance of Mentorship in Career Development

37:30 The Lifestyle Polygraph: A Fun Twist on Cybersecurity

41:04 Embracing Creativity and Personal Expression

45:50 Pride in Roots: The Jacksonville Connection

View Details

No Password Required: No Password Required: Next Gen - Ep. 2 - Tim Kircher

From Freshman Stress to Cyber Success: Formula 1, Pickleball, and hacking in Real life

In this episode of No Password Required: Next Gen, Yazzel Corona interviews Tim Kircher, a cybersecurity student at USF and member of the Security Operations Center Apprenticeship Program at Cyber Florida. Tim shares how his fascination with technology first sparked his interest in cybersecurity.

From networking advice and navigating the chaos of a cybersecurity education, Tim keeps it real, giving us all the tips about what it takes to get started successfully in the field. He talks about why communication skills matter just as much as technical ability in the age of AI and automation, and how taking things “one day at a time” helped shape his journey.

Outside of cyber mode, Tim is a huge pickleball and Formula 1 fan, leading to fun conversations about cyber pit crews, movie hacking scenes, and why Mercedes would absolutely be his dream team.

From defensive cyber operations to teamwork and leadership, Tim’s story is all about staying curious, building connections, and finding your path in cybersecurity.

Follow Tim on LinkedIn: https://www.linkedin.com/in/tim-kircher/

Chapters:

00:00 — Introduction

00:30 — Discovering Cybersecurity

00:54 — Advice for Freshman Cybersecurity Students

01:47 — Formula 1 & Cybersecurity

02:10 — Which F1 Team Would Be Vulnerable?

02:28 — Building the Ultimate Cybersecurity Pit Crew

03:01 — Hollywood Hacking vs. Real-Life Hacking

03:22 — Final Advice for Future Cybersecurity Professionals

04:01 — Toasting to the Future

Follow Tim on LinkedIn: https://www.linkedin.com/in/tim-kircher/

Presented by ThreatLocker

View Details

Fagan Afandiyev — Elite Cybersecurity Competitor and Legendary Whitehatter

No Password Required: Breakout Room: Episode 1 — Fagan Afandiyev

Fagan Afandiyev is a cybersecurity student at the University of South Florida and a member of the CyberHerd competition team, known for his strategic mindset and passion for solving complex challenges. From competing in international robotics competitions to discovering cybersecurity through hands-on platforms, Fagan has built his skills through curiosity, persistence, and a love for problem solving.

Fagan shares how competitions, community, and continuous learning shaped his journey into cybersecurity. He walks through his growth within USF’s cyber community, and how that led to a penetration testing internship at Microsoft.

He also offers insight into the mindset needed to succeed in cybersecurity, encouraging others to embrace challenges, learn through failure, and find enjoyment in the process.

Follow Fagan on Linked in here: https://www.linkedin.com/in/fagan-afandi/

Presented by ThreatLocker

Chapters:

00:00 Introduction to Cybersecurity Passion

3:02 Journey to Cyber Herd and University Life

06:12 Internship at Microsoft and Career Aspirations

08:59 Hackathon Experience and Community Engagement

12:39 Behind the Scenes of Cyber Competitions

14:30 Overcoming Challenges in Cyber Competitions

18:00 Gratitude and Mentorship in Cybersecurity

View Details

Cynthia Wyre —Project Manager at Rapid7 and the Queen of Cyber Media

No Password Required Season 7: Episode 4 - Cynthia Wyre

Cynthia Wyre is a Senior Strategic Engagement Project Manager at Rapid7, where she helps connect academic research and industry. Her path into cybersecurity innovation was untraditional, moving from healthcare and construction project management into vulnerability research and academic partnerships.

Cynthia reflects on how she applied for a role she did not think she was qualified for, why professionals of all backgrounds belong in cyber, and how project management skills can open unexpected doors.

Jack Clabby of Carlton Fields, P.A., and K. Melton of the Cognitive Security Institute welcome Cynthia live from CyberBay 2026 in Tampa for a conversation about research, resilience, and relationship-building in cybersecurity. Cynthia explains Rapid7’s partnership with USF and Cyber Florida, including her efforts to support research around SOC analyst training and burnout, and the future of cyber education.

Throughout the conversation, Cynthia highlights the importance of community, mentorship, and helping people see that cybersecurity is not limited to one path or one type of person.

The episode wraps with the Lifestyle Polygraph, where Cynthia reveals how she would work a room full of strangers and how she won a costume contest moments before meeting rapper Young Gravy. She also earns a crown of her own, officially joining the No Password Required fantasy cybersecurity squad as Queen of the Podcast.

Follow Cynthia on LinkedIn: https://www.linkedin.com/in/cynthiawyre/

Presented by ThreatLocker

Follow ThreatLocker on LinkedIn: https://www.linkedin.com/company/threatlockerinc/posts/

Chapters:

00:00 Introduction

02:15 From Aspiring Physical Therapist to Project Manager

03:50 Transitioning from Construction to Cybersecurity

05:12 Applying for the Rapid7 Role and Overcoming Self-Doubt

10:25 Academic Partnerships with USF and Cyber Florida

12:56 Leaning into Discomfort and Personal Growth

20:15 The Role of Marching Band and Education in Cynthia’s Life

24:25 A Memorable Encounter with a Music Industry Entertainer Yung Gravy

28:00 Lifestyle Polygraph and Fun Personal Questions

37:40 Crowning Cynthia as Queen of the Podcast

View Details

Madhav Nakar — AI Security Researcher and Documentarian of Spirituality and Play

No Password Required Season 7: Episode 3 - Madhav Nakar

Madhav Nakar is a Security Researcher at BeyondTrust specializing in identity threats, endpoint security, and cloud attack paths. With a background in theoretical mathematics, his current research focuses on analyzing attacker behavior to build practical systems of detection.

In this episode, Madhav shares the pivotal moments that shaped his career, including his first experience witnessing a nation-state attack unfold in real time from his seat in a SOC. He explains how mathematical thinking sharpens security strategy and why strong research is rooted in exploration, not predetermined outcomes.

Jack Clabby of Carlton Fields, joined by co-host Kayley Melton of the Cognitive Security Institute, welcomes Madhav for a conversation on modern cyber defense. From AI-driven attacks and agentic systems to privilege escalation risks in role-based access environments, Madhav breaks down what teams are getting wrong about AI and why defending against AI increasingly requires AI-powered tools.

The conversation turns to Madhav’s philosophy of “serious play,” where curiosity, experimentation, and failure fuel better research and resilience. He also shares insights from his spiritual and philosophy project, The Fire of Knowing, exploring consciousness and belief through a neutral lens.

In the Lifestyle Polygraph, Madhav pitches a cybersecurity documentary, debates growth versus comfort, and reflects public dancing experiments.

Follow Madhav Nakar here: https://www.linkedin.com/in/madhav-nakar/

Follow "The Fire of Knowing" on Instagram and Youtube!

CHAPTERS:

00:00 Introduction with Kayley and Jack

08:08 Transition from Theoretical Math to Cybersecurity

16:13 Exploring Spiritual Traditions and Madhav’s Documentary

19:48 The Intersection of Art and Science in Content Creation

25:20 The Lifestyle Polygraph: Challenging Perspectives on Security

View Details

No Password Required: Next Gen – Ep. 1 - Michelle McAveety

Michelle McAveety- Cyber Competitions, Crowd Surfing & Main-Character Energy

Welcome to our new spinoff series, No Password Required: Next Generation. Where we go behind the scenes and interview up-and-coming young professionals in cybersecurity!

Whether you’re trying to figure out your career path, looking for a little inspiration, or just want to have a laugh while learning about the industry, this show is for you.

Real stories. Real journeys. Next Gen Cyber.

About this episode:

Michelle McAveety is a Computer Engineering and Math student at USF and the Team Captain of the CyberHerd, the university’s cybersecurity competition team.

We get into the chaos and adrenaline of competition life, what it’s like leading in a high-pressure cyber environment, and how she balances it all without losing herself. Spoiler: the answer includes crocheting, blasting heavy metal, going to concerts, and possibly crowd surfing if the vibe is right.

Michelle also drops some real advice opening up about the pressure to compare yourself in competitive fields and why staying grounded and focused on your own path is the real win.

Follow Michelles journey on linked in! https://www.linkedin.com/in/mcaveety/

Chapters:

00:39 - Who is Michelle?

00:54- Being in Cyberherd

01:38- Hobbies that bring Michelle Joy!

02:51- Comparison and Growth

View Details

Sue Serna - Social Media Security and Governance Leader and Lover of All Beagles

No Password Required Season 7: Episode 2 - Sue Serna

Sue Serna is the CEO and Founder of Serna Social and the former head of global social media at Cargill. She brings more than two decades of experience at the intersection of storytelling, strategy, and security.

In this episode, she shares her journey from business reporter to leading her own consultancy serving companies around the world on social media strategy.

Jack Clabby of Carlton Fields, P.A, joined by guest co-host Rex Wilson of Cyber Florida, welcomes Sue for a candid discussion about the realities of enterprise social media. From managing more than 150 Facebook pages for a single company, to navigating internal politics, agency relationships, and regulatory pressure, Sue explains why social media is far from “free” and why most organizations still under-resource it.

Sue dives deep into the gap between social media teams and cybersecurity departments. She outlines how personal account compromises can escalate into enterprise-level incidents, why governance frameworks matter, and how large organizations can regain control of sprawling digital footprints. Drawing from real-world examples, she argues that social media must be treated like finance or HR, a core business function requiring structure, ownership, and accountability.

The episode wraps with the Lifestyle Polygraph, where Sue reveals her love of Apollo-era space history, debates iconic Philadelphia traditions, and imagines what magical talent her beagle would bring to Hogwarts.

Follow Sue at SernaSocial.com or connect with her on LinkedIn: https://www.linkedin.com/in/sueserna/

Chapters:

00:00 Introduction and First Impressions

02:45 The Evolving Role of Social Media in Corporations

04:58 Transitioning from Journalism to Social Media

11:11 Building Social Media from Scratch

13:00 Becoming a CEO and Founder

16:28 The Importance of Networking

16:54 Bridging the Gap Between Social Media and Cybersecurity

20:51 Real-World Social Media Security Incidents

28:35 Navigating Internal Conflicts in Social Media

30:32 The Lifestyle Polygraph Begins

31:17 Nerd Things That Expose Sue: Space and Harry Potter!

35:16 Sue’s Love For Beagles

37:50 Wreckless Intern or Overconfident Executive?

40:42 Hogwarts and Magical Beagles

View Details

Rob Hughes — CISO at RSA and Champion of a Passwordless Future

No Password Required Season 7: Episode 1 - Rob Hughes

Rob Hughes, the CISO at RSA, has more than 25 years of experience leading security and cloud infrastructure teams. In this episode, he reflects on his unconventional career path, from co-founding the original Geek.com and serving as its Chief Technologist during the early days of the internet, to leading security and systems design at Philips Home Monitoring.

Jack Clabby of Carlton Fields, P.A. and Kayley Melton welcome Rob for a wide-ranging conversation on identity, leadership, and the realities of modern cybersecurity. Rob currently leads RSA’s Security and Risk Office, overseeing cybersecurity, information security governance, and risk across both RSA’s products and corporate environment.

Rob explains his dream for a passwordless future. He unpacks why passwords remain one of the largest sources of cyber risk, how real-world incidents and password-spraying attacks have accelerated change, and why phishing-resistant technologies like passkeys may finally be reaching a tipping point.

The episode wraps with the Lifestyle Polygraph, where Rob lightens the conversation with stories about gaming with his kids, underrated horror films, and classic cars.

Follow Rob on LinkedIn: https://www.linkedin.com/in/robert-hughes-816067a4/

Chapters:

00:00 Introduction to No Password Required

01:43 Meet Rob Hughes, CISO at RSA

02:05 The Role of a CISO in a Security Company

05:09 Transitioning to the CISO Role

08:00 The Early Days of Geek.com

12:14 Launching a Startup During the Dot Com Boom

14:30 The Push for a Passwordless Future

18:21 Tipping Point for Passwordless Adoption

20:20 Ongoing Learning in Cybersecurity

26:09 Managing Stress in High-Pressure Environments

33:46 The Lifestyle Polygraph Begins

34:15 Career Insights in Cybersecurity

36:08 Dream Cars and Personal Preferences

39:58 Underrated Horror Films

41:19 Creating a Cybersecurity Monster

View Details

Gina Yacone — Virtual CISO at Trace3 and Roller Derby Penalty Box Visitor

Live from B-Sides Jacksonville, No Password Required welcomes Gina Yacone, Virtual CISO at Trace3. Jack Clabby of Carlton Fields, P.A. and Sarina Gandy, host and producer of the CyberBay Podcast, host a conversation on Gina’s unconventional career path, leadership under pressure, and the power of community in cybersecurity. With career stops in private investigation, digital forensics, and executive security, Gina brings a people-first, purpose-driven perspective to complex cyber risk.

Gina shares how her early work as a private investigator on high-profile criminal defense cases laid the foundation for her success in cybersecurity. She also reflects on raising her hand for big challenges, the rewards and risks of always saying yes, and how authenticity has guided her. She offers insight on why conference hallway conversations can be just as impactful as keynote sessions.

A visible advocate for the cybersecurity community, Gina speaks openly about setting healthy mentorship boundaries and building resilient professional networks.

The episode wraps with the Lifestyle Polygraph, where Gina lightens the mood with stories from her roller derby days, dream Amazing Race partners, and why John Wick might just be the ultimate executive assistant.

Follow Gina on LinkedIn: https://www.linkedin.com/in/ginayacone/

Chapters:

00:00 Introduction to Cybersecurity and B-Sides Jacksonville

01:16 Gina Yacone's Unique Journey to Cybersecurity

06:22 Navigating Burnout in Cybersecurity

08:06 The Importance of Raising Your Hand

10:04 Adapting Leadership Styles in Different Roles

14:03 Being a Role Model for Women in Cybersecurity

16:34 How to Establish a Good Mentee and Mentor Relationship

18:50 Feedback and Constructive Criticism

22:55 The Value of Hallway Conversations

26:19 The Lifestyle Polygraph: Fun and Insights

38:54 Conclusion and Future Connections

View Details

Danny Jenkins — Founder of ThreatLocker and the Zero-Trust Revolution

Danny Jenkins is the CEO of ThreatLocker, the leading cybersecurity company that he built alongside his wife. Hosts Jack Clabby of Carlton Fields, P.A., and Kayley Melton of the Cognitive Security Institute follow Danny’s journey from a scrappy IT consultant to leading one of the fastest-growing cybersecurity companies in the world.

Danny shares the moment everything changed: watching a small business nearly collapse after a catastrophic ransomware attack. That experience reshaped his mission and ultimately sparked the creation of ThreatLocker. He also reflects on the gritty early days—cold-calling from his living room, coding through the night, and taking on debt before finally landing their first $5,000 customer.

Danny explains the origins of Zero Trust World, his passion for educating IT teams, and why adopting a hacker mindset is essential for modern defenders.

In the Lifestyle Polygraph, Danny relates his early “revenge tech” against school bullies, the place he escapes to when celebrating big wins, and the movie franchise he insists is absolutely a Christmas classic.

Follow Danny on LinkedIn: https://www.linkedin.com/in/dannyjenkins/

00:00 Introduction to Cybersecurity and ThreatLocker

02:26 The Birth of ThreatLocker: A Personal Journey

05:42 The Evolution of Zero Trust Security

08:35 Real-World Impact of Cyber Attacks

11:25 The Importance of a Hacker Mindset

14:46 The Role of SOC Teams in Cybersecurity

17:34 Building a Culture of Security

20:23 Hiring for Passion and Skill in Cybersecurity

23:44 Understanding Zero Trust: Trust No One

26:32 Lifestyle Polygraph: Personal Insights and Fun

29:41 Conclusion and Future of ThreatLocker

View Details

Summary

In this episode of No Password Required, host Jack Clabby and Kayley Melton engage with Steve Orrin, the federal CTO at Intel, discussing the evolving landscape of cybersecurity, the importance of diverse teams, and the intersection of technology and security. Steve shares insights from his extensive career, including his experiences in the startup scene, the significance of AI and IoT, and the critical blind spots in cybersecurity practices. The conversation also touches on nurturing talent in technology and offers valuable advice for young professionals entering the field.

Chapters

00:00 Introduction to Cybersecurity and the Edge

01:48 Steve Orrin's Role at Intel

04:51 The Evolution of Security Technology

09:07 The Startup Scene in the 90s

13:00 The Intersection of Biology and Technology

15:52 The Importance of AI and IoT

20:30 Blind Spots in Cybersecurity

25:38 Nurturing Talent in Technology

28:57 Advice for Young Cybersecurity Professionals

32:10 Lifestyle Polygraph: Fun Questions with Steve

View Details

In this episode of No Password Required, host Jack Clabby and guest host Sarina Gandy discuss the insights gained from their conversation with Demarcus Williams, a senior security engineer at Starbucks. They explore Demarcus's journey into cybersecurity, the importance of competitions like CCDC in career development, and the role of gut instinct in cybersecurity. The discussion also touches on the differences between corporate cultures, the significance of mentorship, and the fun aspects of the cybersecurity community, including a light-hearted lifestyle polygraph segment.

Takeaways

Demarcus' curiosity about video games sparked his interest in cybersecurity.

The transition from defense contracting to corporate roles offers broader access to tools.

Gut feelings play a significant role in cybersecurity decision-making.

Competitions like CCDC are crucial for career development in cybersecurity.

Networking at competitions can lead to job opportunities.

Corporate culture varies significantly between government contracting and tech companies.

A people-first approach is essential in mentorship and cybersecurity.

The red team experience enhances skills applicable to day-to-day work.

Work-life balance is crucial in maintaining a sustainable career in cybersecurity.

Engaging with the community is vital for personal and professional growth.

Chapters

00:00 Introduction to Cybersecurity and Curiosity

02:47 Day-to-Day Life of a Senior Security Engineer

05:30 The Role of Gut Instinct in Cybersecurity

08:31 Early Inspirations and the Journey into Cybersecurity

11:35 The Importance of Competitions in Career Development

14:33 Transitioning from Student to Professional

17:34 The Red Team Experience and Its Impact

20:25 Recruitment Opportunities in Cybersecurity Competitions

23:33 Navigating Corporate Culture in Cybersecurity

26:31 Mentorship and People-First Approach

29:11 Lifestyle Polygraph and Fun Insights

View Details

Keywords

cybersecurity, product management, career development, market strategy, customer insights, hacking, music, team building, startup life, risk management

Summary

In this episode of No Password Required, host Jack Clabby and co-host Kayleigh Melton engage in a lively conversation with John Shipp, a product strategist at Rapid7. They explore John's unique journey from a metalhead to a cybersecurity expert, discussing the importance of passion in career development, the intricacies of product management, and the significance of customer insights in shaping cybersecurity solutions. John shares his early experiences in hacking, the influence of music on his life, and the value of building strong teams and company culture. The episode concludes with a fun segment called the Lifestyle Polygraph, where John answers quirky questions about his ideal cyber team and his dream day with Ric Flair.

Takeaways

Being a metalhead prepares you for the boardroom.

You can follow your passion and thrive in your career.

Product management involves understanding customer needs and market dynamics.

Curiosity is a key driver in the tech field.

Great teams are built on strong leadership and culture.

Startup life requires a willingness to take risks.

Networking and building relationships are crucial in cybersecurity.

Understanding your risk appetite is important when considering career moves.

Music can be a significant influence on personal and professional life.

Mentorship and sharing knowledge are vital for growth in the industry.

Titles

From Metal to Management: A Cybersecurity Journey

Passion and Profession: Finding Your Path in Cybersecurity

Sound bites

"You can follow your passion and thrive."

"I learned security at scale."

"Curiosity drives my passion for tech."

Chapters

00:00 Introduction to Cybersecurity and Personal Journeys

02:49 The Role of Passion in Career Development

05:21 Navigating Product Management and Market Strategy

08:23 The Evolution of Cybersecurity Skills

11:37 The Importance of Customer Insights in Product Development

14:35 Early Experiences in Hacking and Cybersecurity

17:24 The Influence of Music on Personal and Professional Life

20:19 Building Teams and Company Culture

23:10 Startup Life and Risk Management

26:08 Lifestyle Polygraph: Fun Questions and Insights

29:13 Final Thoughts and Connections

View Details

Keywords

cybersecurity, military transition, Tampa cybersecurity, mentorship, cyber law, incident response, private sector, cybersecurity misconceptions, legal perspectives, cybersecurity growth

Summary

In this episode of No Password Required, hosts Jack Clabby and Kayley Melton sit down with Kurt Sanger — former Deputy General Counsel at U.S. Cyber Command — to talk about the evolving world of cyber law, the wild ride from government service to private sector strategy, and what keeps him grounded in a field that’s constantly shifting. Kurt dives into the fast-growing cybersecurity scene in Tampa, the power of mentorship, and why people still get cyber law so wrong. Plus: insights on responding to incidents under pressure and what role the government should (and shouldn’t) play in the digital fight.

Takeaways

Kurt emphasizes that newcomers to cybersecurity are not as far behind as they think.

The transition from military to private sector can be challenging but rewarding.

Tampa is becoming a significant hub for cybersecurity talent and companies.

Understanding cybersecurity misconceptions is crucial for decision-makers.

Mentorship plays a vital role in navigating career challenges in cybersecurity.

Military and civilian cyber law have distinct differences in enforcement and flexibility.

The stakes in private sector cybersecurity can be incredibly high for clients.

Kurt's experience highlights the need for collaboration between government and private sectors.

Cybersecurity is an ever-evolving field that requires continuous learning.

Kurt finds excitement in helping clients during their most challenging times.

Sound bites

"You're only six months behind."

"We're all in the same boat."

"The government needs to step back."

Chapters

00:00 NPR S6E7 Kurt Sanger

52:53 NPR S6E7 Kurt Sanger

01:45:47 Introduction to Cybersecurity Conversations

01:48:22 Transitioning from Military to Private Sector Cybersecurity

01:51:11 The Growth of Tampa as a Cybersecurity Hub

01:54:05 Understanding Cybersecurity Misconceptions

01:57:15 The Role of Mentorship in Cybersecurity Careers

02:00:24 Military vs. Civilian Cybersecurity Law

02:03:07 The Excitement of Cyber Command vs. Private Sector

02:13:52 High Stakes in Cybersecurity for Small Organizations

02:15:44 The Role of Legal Experts in Cybersecurity

02:17:21 Translating Technical Jargon for Clients

02:18:57 Challenges of Explaining Cyber Operations to Commanders

02:22:43 Lifestyle Polygraph: Fun Questions and Insights

02:23:30 The 10,000 Hour Rule in Cybersecurity

02:29:34 Creative Freedom with LEGO Bricks

02:31:27 Tampa's Culinary Delights and Local Favorites

View Details

keywords

cybersecurity, culinary arts, penetration testing, career transition, high-pressure situations, horror films, IT, social engineering, cooking, cybersecurity horror, dark web, pen testing, B-Sides community, cybersecurity, lifestyle polygraph, music, childhood memories, culinary skills, competition

takeaways

Kathy Collins transitioned from IT to culinary arts and back to cybersecurity.

Her journey highlights the transferable skills between cooking and cybersecurity.

Physical penetration testing involves unpredictable human elements.

High-pressure situations in cooking can prepare one for cybersecurity challenges.

Unexpected challenges can arise in both culinary events and cybersecurity tests.

The importance of communication in cybersecurity engagements is crucial.

Kathy's experience in cooking for large groups parallels the complexities of cybersecurity.

The need for proper notification in penetration testing to avoid misunderstandings.

Kathy's culinary background influences her approach to problem-solving in cybersecurity.

There is a lack of big-budget horror films focused on cybersecurity. Going with the correct skeptical mindset is crucial.

Using tools like Flare helps in dark web monitoring.

B-Sides events are affordable and beneficial for newcomers.

Engaging with the community fosters excitement and learning.

Hannibal Lecter would be an interesting pen test partner.

The Jaws soundtrack sets a perfect mood for stealth.

Bonding over music can strengthen family relationships.

Childhood toys can reveal early hacker tendencies.

Culinary skills can be approached with a hacker mindset.

Competition in cooking shows often emphasizes drama over skill.

summary

In this episode of the No Password Required podcast, host Jack Clabby and co-host Kaylee Melton welcome Kathy Collins, a security consultant at Secure Ideas. Kathy shares her unique journey from working in IT to pursuing a culinary career, and then back to cybersecurity. The conversation explores the transferable skills between cooking and cybersecurity, the unpredictability of physical penetration testing, and the high-pressure situations faced in both fields. Kathy also recounts memorable experiences from her culinary career and discusses the lack of horror films centered around cybersecurity. In this engaging conversation, the speakers delve into various aspects of cybersecurity, including the use of the dark web in penetration testing, the importance of community events like B-Sides, and the fun of the Lifestyle Polygraph segment. They also share personal anecdotes about music, childhood memories, and culinary skills, creating a rich tapestry of insights and experiences in the cybersecurity field.

titles

From Chef to Cybersecurity: A Unique Journey

The Culinary Path to Cybersecurity

High Stakes: Cooking and Cybersecurity Under Pressure

Penetration Testing: The Culinary Connection

Sound Bites

"I had to do some soul searching."

"I was like, what if I have to do..."

"It's disturbingly easy."

"There are so many opportunities there."

"Going with the correct skeptical mindset."

"We have a tool that we use called Flare."

"They should attend them, first of all."

"I had an Easy Bake Oven and took it apart."

Chapters

00:00 Introduction to Cybersecurity and Culinary Journeys

02:46 From IT to Culinary Arts: A Unique Transition

06:02 The Shift Back to Cybersecurity

09:00 Experiences in Physical Penetration Testing

11:48 High-Pressure Situations: Cooking vs. Cybersecurity

15:02 Unexpected Challenges in Culinary Events

17:54 The Intersection of Horror and Cybersecurity

23:32 Exploring the Dark Web in Pen Testing

25:34 Engaging with the B-Sides Community

27:09 The Lifestyle Polygraph: Fun and Games

31:09 Bonding Over Music and Childhood Memories

34:17 Culinary Skills and Competition Insights

View Details

Summary

In this episode, Jack Clabby and Kayley Melton discuss their conversation with Reginald Andre, a cybersecurity expert and CEO of ARK Solvers. They explore themes of mentorship, the evolution of cybersecurity businesses, the impact of AI, team culture, and community engagement. Andre shares his journey from aspiring English teacher to successful entrepreneur, emphasizing the importance of mentorship and personal growth in the cybersecurity field. In this engaging conversation, the speakers delve into the importance of mentorship, innovative teaching methods, and the role of AI in personal and professional development. They share personal anecdotes about mentoring students and children, emphasizing hands-on learning and real-world applications. The discussion also touches on the fun and insightful lifestyle polygraph segment, where the guest answers quirky questions that reveal his personality and approach to challenges.

Takeaways

  • Andre is a natural mentor who emphasizes actionable advice.
  • The importance of building a fantasy board of directors.
  • Reginald's journey from CompUSA to CEO of ARK Solvers.
  • The shift from IT to cybersecurity in business.
  • AI's growing role in cybersecurity and business efficiency.
  • Hiring based on personality and cultural fit over technical skills.
  • Encouraging a culture of learning from mistakes.
  • The impact of community engagement on personal growth.
  • The significance of mentorship in shaping careers.
  • Raising awareness on critical social issues like human trafficking. Mentorship can significantly impact a student's career trajectory.
  • Hands-on learning is more effective than traditional lectures.
  • Building a resume starts with taking initiative in school activities.
  • AI can serve as a valuable tool for decision-making and mentorship.
  • Creating a community around learning can enhance educational experiences.
  • Students should actively seek internships and opportunities before graduation.
  • Innovative teaching methods can fill gaps in traditional education systems.
  • Personal anecdotes can illustrate the effectiveness of mentorship.
  • Engaging with technology early can lead to better career prospects.
  • Networking and building relationships are crucial for professional growth.

Titles

  • Mentorship in Cybersecurity: Lessons from Reginald Andre
  • The Evolution of Cybersecurity: From IT to AI
  • Building a Strong Team Culture in Cybersecurity
  • Community Engagement: Making a Difference Beyond Business

Sound Bites

  • "Andre is such a natural mentor."
  • "I built my fantasy board of directors."
  • "I had to pivot my business."
  • "AI is not going to take your job."
  • "I always leave him with something."
  • "He was actually building his resume."
  • "Everything has to be hands-on."
  • "I would do Too Fast Too Furious."
  • "You'd be tasked with AI education."

Chapters

00:00 Introduction to Cybersecurity Mentorship

01:56 The Journey of Reginald Andre

05:58 From IT to Cybersecurity: A Business Evolution

11:55 The Impact of AI on Cybersecurity

17:52 Building a Strong Team Culture

22:05 Community Engagement and Personal Growth

27:39 Mentorship and Impact

30:21 Innovative Teaching Approaches

34:04 Lifestyle Polygraph: Fun and Insightful Questions

View Details

keywords

cybersecurity, leadership, startups, failure, vendor trust, HACKERverse, communication, investment, innovation, beginner's mindset, job search, LinkedIn, networking, AI, personal branding, cybersecurity, lifestyle polygraph, superheroes, career advice, mentorship

summary

In this episode of No Password Required, host Jack Clabby and co-host Kaylee Melton engage in a thought-provoking conversation with Mariana Padilla, co-founder and CEO of HACKERverse.AI. The discussion revolves around the importance of embracing failure as a learning opportunity, the role of leadership in fostering a positive work environment, and the challenges faced in the cybersecurity vendor landscape. Mariana shares her insights on the need for better communication in the industry and the importance of a beginner's mindset in driving innovation. The conversation also touches on the future of investment in cybersecurity and the necessity of rebuilding trust within the industry. In this engaging conversation, Mariana discusses the challenges of job searching in the current landscape dominated by AI and the importance of networking and personal branding. She emphasizes that building trust and connections is crucial in the cybersecurity field. The discussion transitions into a fun segment called the lifestyle polygraph, where Mariana shares her thoughts on superheroes and their relevance to personal and professional growth. The episode concludes with Mariana providing insights on how to connect with her and her work.

takeaways

Embracing failure is crucial for personal and professional growth.

Leadership should focus on transparency and learning from mistakes.

A beginner's mindset can lead to innovative solutions in cybersecurity.

The cybersecurity industry struggles with communication and trust.

Venture capital influences the direction of cybersecurity startups.

Sustainable business practices are essential for long-term success.

The sales process in cybersecurity needs to be more efficient.

Understanding vendor interoperability is critical for security.

Cybersecurity vendors must demonstrate product viability effectively.

The industry must evolve to meet the rapid pace of technological change. You're competing against AI for some of these jobs.

Networking is so, so, so important.

The online application system has been dying for quite some time.

Your personal brand matters and you have to have one.

Conferences are a prime opportunity to peacock a little bit.

Batman has real feelings and real demons.

The correct answer is Star Trek.

Margot Robbie, I really like her.

You're on the fantasy cybersecurity squad.

Come follow me on LinkedIn for lots of shenanigans.

titles

Embracing Failure in Cybersecurity

The Importance of Leadership in Startups

Innovating with a Beginner's Mindset

HACKERverse: Revolutionizing Cybersecurity

Sound Bites

"It's all about leadership and leading by example."

"I think we have a gap here."

"We should focus on sustainably built businesses."

"It's just a bunch of nonsense."

"Networking is so, so, so important."

"Batman has real feelings and real demons."

"The correct answer is Star Trek."

"Margot Robbie, I really like her."

"You're on the fantasy cybersecurity squad."

Chapters

00:00 Introduction to Cybersecurity Conversations

02:00 Embracing Failure as a Learning Opportunity

06:02 The Role of Leadership in Startups

09:00 The Value of a Beginner's Mindset

11:58 Understanding HACKERverse's Mission

13:59 Challenges in the Cybersecurity Vendor Landscape

17:08 Shaking Up the Status Quo in Cybersecurity

21:52 The Future of Investment in Cybersecurity

24:36 Navigating Job Searches in the Age of AI

29:35 The Importance of Personal Branding

30:23 Lifestyle Polygraph: Fun and Games

39:05 Superheroes and Their Lessons

43:45 Connecting with Mariana: Final Thoughts

View Details

summary

In this episode of No Password Required, host Jack Clabby and guest Trevor Hilligoss discuss various aspects of cybersecurity, including the transition from military service to the private sector, the importance of leadership in tech, and the misconceptions surrounding cyber threats. Trevor shares insights from his career, emphasizing the need for a proactive approach to cybersecurity and the value of empowering teams to innovate and learn from failures. In this engaging conversation, the speakers delve into memorable experiences in cybersecurity, including impactful interactions and the importance of sharing knowledge. They explore personal preferences through a fun lifestyle polygraph segment, discussing walk-up songs, breakfast favorites, and nerd culture. The conversation also touches on the lighter side of cybersecurity with prank calls and the dynamics of building an escape room team. The episode concludes with contact information and an invitation to connect further.

takeaways

  • Trevor emphasizes the importance of metaphors in understanding cybersecurity.
  • The public often fears sophisticated threats while ignoring more common dangers.
  • Leadership in cybersecurity should focus on empowering teams rather than micromanaging.
  • A proactive approach in cybersecurity can prevent victimization before it occurs.
  • Technical leaders should understand core concepts to effectively guide their teams.
  • Misconceptions about cyber criminals often stem from Hollywood portrayals.
  • The military experience can significantly shape leadership styles in tech.
  • Daily life in cybersecurity involves constant learning and adaptation.
  • Sophistication in cyber threats does not always correlate with success.
  • Cybersecurity is about both fighting threats and fortifying defenses. Memorable interactions can lead to impactful collaborations in cybersecurity.
  • Sharing knowledge can help mitigate cyber threats effectively.
  • Personal preferences can reveal a lot about an individual's character.
  • Walk-up songs can reflect one's personality and professional identity.
  • Breakfast choices can be a blend of cultural influences and personal tastes.
  • Building a team for an escape room requires diverse skills and personalities.
  • Nerd culture can foster connections and shared interests among individuals.
  • Prank calls can be a humorous way to engage with public figures.
  • Culinary competitions highlight the absurdity of turning survival into entertainment.
  • Networking in cybersecurity can lead to unexpected opportunities.

titles

  • Cybersecurity Connections: Memorable Moments
  • The Lifestyle Polygraph: Fun and Insights
  • Walk-Up Songs: A Reflection of Identity
  • Breakfast Favorites: A Culinary Journey

Sound Bites

  • "Tell them what needs to get done."
  • "Empower your people to fail."
  • "We can stop that identity theft."
  • "I was in Europe giving a talk."
  • "I sent him everything that we had."
  • "I would get Jack Sparrow."
  • "I love Star Wars."
  • "I would call Gordon Ramsey."

Chapters

00:00 Introduction to Cybersecurity Insights

02:54 Career Path and Unexpected Experiences

05:55 Transitioning from Military to Cybersecurity

09:07 Daily Life at Spy Cloud

12:12 Leadership Philosophy and Management Style

14:53 The Nature of Cyber Threats

17:50 Technical Skills in Leadership

20:52 Misconceptions About Cyber Criminals

25:32 Memorable Cybersecurity Interactions

28:12 Lifestyle Polygraph Introduction

28:35 Walk-Up Songs and Personal Preferences

32:07 Breakfast Favorites and Culinary Influences

34:40 Building the Ultimate Escape Room Team

37:36 Nerd Culture and Personal Interests

39:02 Prank Calls and Culinary Competitions

41:20 Closing Thoughts and Contact Information

View Details

keywords

cybersecurity, zero trust, public speaking, ThreatLocker, AI threats, layered security, Rob Allen, cybersecurity insights, personal growth, industry challenges, technology, wearables, Buc-ee's, sports, DIY, tech addiction, Vision Pro, personal achievements, American culture, cybersecurity

summary

In this episode of the No Password Required podcast, host Jack Klabby engages with cybersecurity experts Kaylee Melton and Rob Allen, discussing Rob's journey to ThreatLocker, the importance of overcoming public speaking fears, and the principles of Zero Trust security. They explore common mistakes organizations make when implementing Zero Trust, the future of cybersecurity in relation to AI threats, and the public's perception of cybersecurity incidents. The conversation also touches on the significance of layered security approaches and personal experiences in the industry, culminating in a fun lifestyle polygraph segment. In this engaging conversation, the speakers delve into their personal tech addictions, particularly focusing on extravagant purchases like the Vision Pro. They explore the future of wearable technology and its integration into daily life. The discussion shifts to the uniquely American experience of visiting Buc-ee's, a gas station that offers much more than fuel. They also debate the joy derived from sports victories versus personal achievements like hitting a hole in one. Finally, the conversation wraps up with a humorous take on the challenges of mastering DIY skills.

takeaways

  • Rob Allen's journey from engineer to Chief Product Officer at ThreatLocker showcases career growth in cybersecurity.
  • Public speaking can be daunting, but practice and experience help overcome fears.
  • Zero Trust is a mindset focused on security, not just a product to buy.
  • Organizations often hesitate to adopt Zero Trust due to misconceptions about efficiency.
  • Inertia is a major obstacle for companies considering Zero Trust implementation.
  • AI can be a double-edged sword in cybersecurity, used for both protection and attacks.
  • Many smaller cybersecurity incidents go unreported compared to major breaches.
  • Layered security should involve diverse approaches, not just similar detection tools.
  • Stress in the workplace can be managed by adopting a laid-back mindset.
  • Mentorship plays a crucial role in personal and professional development. Some people have good addictions and some have bad ones.
  • The Vision Pro is an expensive but amazing piece of tech.
  • Wearable technology is becoming increasingly common.
  • Buc-ee's is a unique and quintessentially American experience.
  • Experiencing a sports win can be as joyful as personal achievements.
  • DIY skills can be both challenging and rewarding.
  • Tech purchases often lead to guilt and reflection.
  • The future of wearables may include more practical and stylish designs.
  • Personal experiences shape our views on technology and culture.
  • Mastering DIY can lead to greater independence and satisfaction.

titles

  • Tech Addictions: The Price of Innovation
  • The Future of Wearables: Are We Ready?
  • Buc-ee's: A Journey into American Culture
  • Sports Wins vs. Personal Achievements: What Brings More Joy?

Sound Bites

  • "It's a process, you know, start somewhere."
  • "Deny by default, permit by exception."
  • "Zero Trust is not a product. It's a mindset."
  • "The beauty of Zero Trust is it's not reactive."
  • "AI is just as likely to be used against you."
  • "I am never going to be that guy."
  • "Buc-ee's is the most American thing ever."
  • "I would very much like to have a hole in one."
  • "I would like to be good at DIY."

Chapters

00:00 Introduction to Cybersecurity Insights

03:05 Rob Allen's Journey to ThreatLocker

05:49 Overcoming Public Speaking Fears

08:55 Understanding Zero Trust Security

12:12 Common Mistakes in Zero Trust Implementation

15:02 The Future of Zero Trust and AI Threats

18:05 Public Perception of Cybersecurity

21:08 Layered Security Approaches

24:02 Personal Experiences and Lessons Learned

26:58 Lifestyle Polygraph and Fun Questions

27:11 Tech Addictions and Unnecessary Purchases

32:05 The Future of Wearable Technology

34:08 Experiencing Buc-ee's: The Most American Gas Station

36:44 Joyful Moments: Sports Wins vs. Personal Achievements

39:03 Mastering DIY Skills: A Personal Journey

View Details

keywords

cybersecurity, 5G, 6G, AI, quantum computing, global collaboration, career advice, creativity, technology, Dr. Anmol Agarwal

summary

In this episode of No Password Required, host Jack Clabby and cybersecurity expert Dr. Anmol Agarwal discuss the evolving landscape of cybersecurity, focusing on the challenges and innovations surrounding 5G and 6G networks, the integration of AI and quantum computing, and the importance of global collaboration in addressing cybersecurity threats. Dr. Agarwal shares her insights on the significance of creativity in the field, offers advice for those entering the cybersecurity space, and engages in a fun lifestyle polygraph segment that highlights her personal interests and professional aspirations.

takeaways

  • Start posting about what you're learning immediately to gain exposure.
  • The transition from 5G to 6G involves long-term security thinking.
  • AI and quantum computing are complementary technologies in cybersecurity.
  • Global collaboration is essential for effective cybersecurity solutions.
  • Creativity is crucial in addressing emerging cybersecurity challenges.
  • Focus on personal interests rather than peer pressure in career choices.
  • Healthcare is a sector particularly vulnerable to AI-driven attacks.
  • Continuous learning and sharing knowledge is vital for career growth.
  • Security standardization is a key aspect of developing new technologies.
  • Engagement and interaction are important in educational and professional settings.

titles

  • Navigating the Future of Cybersecurity
  • The 6G Security Landscape
  • AI and Quantum: The New Frontier
  • Collaborative Cybersecurity: A Global Perspective

Sound Bites

  • "Start posting about what you're learning immediately."
  • "We're going to be thinking in a serious way."
  • "My role specifically on this team is security standardization."
  • "I want to work on AI security."
  • "Security is a team effort."
  • "AI can make mistakes as well."
  • "Focus on what you like instead of worrying about others."
  • "Creativity is probably the most important thing."
  • "I would add a journalist to my cybersecurity dream team."

Chapters

00:00 Introduction to Cybersecurity Insights

02:30 Exploring 5G and 6G Security Challenges

11:10 The Intersection of AI, Quantum Computing, and Cybersecurity

18:00 Global Collaboration in Cybersecurity

24:57 Advice for Aspiring Cybersecurity Professionals

26:48 The Role of Creativity in Cybersecurity

31:27 Lifestyle Polygraph: Fun and Insightful Questions

View Details

In this conversation, Tanya Janca discusses the importance of secure coding in the cybersecurity landscape, sharing her journey and experiences as both a developer and educator. She emphasizes the need for software developers to understand security principles, the role of OWASP in providing resources, and the challenges of balancing user experience with security measures. Tanya also highlights the significance of validation in development and the implications of implied trust in cybersecurity practices.

View Details

Summary

This conversation explores the U.S. Army's investment in cybersecurity compliance for small businesses, the importance of mentorship in the defense industry, and the unique career path of Sabrina McIntyre at KPMG. Sabrina discusses her transition from art to cybersecurity, the challenges of navigating compliance standards, and her advocacy for women in the field. The episode also touches on the intersection of art and cybersecurity, the vision for a cybersecurity museum, and fun personal insights from Zabrina's life.

Takeaways

  • The U.S. Army is investing in small business cybersecurity compliance.
  • Certification programs can help defense contractors meet compliance.
  • Creating a secure environment for small businesses is essential.
  • Mentorship programs are crucial for small business growth.
  • Zabrina's career path showcases the value of diverse experiences.
  • Understanding compliance standards like PCI DSS is challenging but necessary.
  • Being open to new opportunities can lead to fulfilling career paths.
  • Women in Cybersecurity is making strides in community building.
  • Creativity is important in the cybersecurity field.
  • Cybersecurity education should be accessible to all.

titles

  • Investing in Cybersecurity for Small Businesses
  • Navigating Compliance in the Cybersecurity Landscape
  • Zabrina McIntyre: A Unique Career Journey
  • Empowering Women in Cybersecurity

Sound Bites

  • "Certification program for defense contractors"
  • "Largest federal government mentor-protege program"
  • "Cybersecurity maturity model is crucial"
  • "Be your own best advocate in your career"
  • "If you can see it, you can be it"
  • "We need more creative people in cybersecurity"
  • "Cybersecurity should be accessible to everyone"
  • "Umbrellas don't work in Seattle"

Chapters

00:00 Introduction to the Next Generation Commercial Operations Program

02:51 The Importance of Cybersecurity Compliance for Small Businesses

05:45 Zabrina McIntyre's Role at KPMG

08:54 Zabrina's Unique Career Path

11:51 Navigating Cybersecurity Standards

14:48 Advice for Aspiring Cybersecurity Professionals

17:58 Women in Cybersecurity: Building Community

20:59 The Intersection of Art and Cybersecurity

24:04 Zabrina's Vision for a Cybersecurity Museum

27:02 Lifestyle Polygraph: Fun Questions with Zabrina

30:09 Key Takeaways and Closing Thoughts

View Details

summary

In this episode, the conversation begins with a significant data breach at Star Health Insurance, affecting over 31 million individuals. The discussion delves into the complexities of insider threats, particularly focusing on the alleged involvement of the company's CISO. The episode transitions to an introduction of Dr. Sunny Ware, a web application penetration tester, who shares her journey from software development to cybersecurity. Dr. Sunny discusses her role in penetration testing, the importance of understanding application logic, and the use of AI in her work. The episode concludes with a lifestyle polygraph segment, where Dr. Sunny shares personal insights and experiences, emphasizing the importance of mentorship in cybersecurity.

takeaways

  • Star Health Insurance experienced a major data breach affecting millions.
  • Insider threats are predicted to be a significant risk in 2025.
  • Dr. Sunny Ware transitioned from software development to cybersecurity.
  • Understanding application logic is crucial in penetration testing.
  • AI can be a valuable tool in penetration testing.
  • Bug bounty programs offer focused opportunities for security testing.
  • Mentorship is important for the next generation of cybersecurity professionals.
  • Dr. Sunny emphasizes the creativity involved in coding and security.
  • Vulnerability disclosure programs differ from bug bounty programs.
  • Dr. Sunny's passion for teaching and sharing knowledge is evident.

titles

  • The Star Health Insurance Data Breach: A Deep Dive
  • Insider Threats: The New Face of Cybersecurity Risks
  • Meet Dr. Sunny Ware: A Cybersecurity Trailblazer
  • The Art of Penetration Testing with Dr. Sunny
  • Exploring AI's Role in Cybersecurity

sound bites

  • "Star Health Insurance suffered a significant data security incident."
  • "There's a hacker and then there's this kind of cool insider twist."
  • "The alleged hackers claimed that Star Health's CISO facilitated the breach."
  • "Insider threats are going to be the risk to prepare for in 2025."
  • "I came from very humble beginnings."
  • "I think coding is like making a painting on a blank canvas."
  • "I want to capitalize on the experience I already have in web API."
  • "I use AI almost every day on every pen test."
  • "I actively do bug hunting."
  • "I want to make sure that if there's anything I can share to help."

chapters

00:00 Data Breach at Star Health Insurance

06:06 Insider Threats and Whistleblowers

07:05 Introduction to Dr. Sunny Ware

30:14 Dr. Sunny's Career Path and Penetration Testing

37:00 Lifestyle Polygraph with Dr. Sunny

48:55 Key Takeaways and Closing Thoughts

View Details

A new school in San Antonio called Nukudu offers a paid training program followed by a guaranteed job in cybersecurity. The program aims to address the shortage of cyber jobs and provides hands-on training to ensure candidates are prepared for the workforce.

Our guest, Dr. Thomas Hyslop, an assistant professor at the University of South Florida, shares his experience in law enforcement and the importance of interagency collaboration in combating cybercrime. He also discusses the Master of Science in Cybercrime program at USF, which focuses on digital forensics and criminal investigation. The future of cybercrime is concerning as large criminal organizations are becoming more sophisticated and mimicking nation states in their capabilities. Investigating international cybercrime is challenging due to the need for cooperation between countries and the slow response times. Changes in international treaties and agreements are needed to expedite investigations. Dr. Highslip ran a museum of vintage technology and is looking for a place to house it permanently. He enjoys swimming in Mirror Lake, biking on Champs-Elysees, and running in DC for his ideal triathlon. His favorite junk food treat is Bit-O-Honey and he loves all kinds of pies. Guns N' Roses is his favorite hair metal band and his favorite song is Paradise City. He enjoys playing metal songs at social gatherings and believes that Appetite for Destruction is a timeless album. Dr. Highslip has what it takes to join the fantasy cybersecurity squad and is a force multiplier with his expertise in incident response and alternative theories for obtaining information from foreign governments.

takeaways

  • Nukudu offers a paid training program followed by a guaranteed job in cybersecurity to address the shortage of cyber jobs.
  • Interagency collaboration is crucial in combating cybercrime, and federal law enforcement plays a significant role in stopping cybercriminals.
  • The Master of Science in Cybercrime program at the University of South Florida focuses on digital forensics and criminal investigation.
  • Team building and collaboration are essential skills in cybersecurity and are emphasized in the education of future cybersecurity professionals. Large criminal organizations are becoming more sophisticated and mimicking nation states in their cyber capabilities.
  • Investigating international cybercrime is challenging due to slow response times and the need for cooperation between countries.
  • Changes in international treaties and agreements are needed to expedite investigations.
  • Dr. Highslip ran a museum of vintage technology and is looking for a permanent location to house it.
  • His ideal triathlon includes swimming in Mirror Lake, biking on Champs-Elysees, and running in DC.
  • His favorite junk food treat is Bit-O-Honey and he loves all kinds of pies.
  • Guns N' Roses is his favorite hair metal band and Paradise City is his favorite song.
  • Dr. Highslip has what it takes to join the fantasy cybersecurity squad and is a force multiplier with his expertise in incident response and alternative theories for obtaining information from foreign governments.

titles

  • The Role of Interagency Collaboration in Combating Cybercrime
  • Emphasizing Team Building and Collaboration in Cybersecurity Education Indulging in Junk Food: Bit-O-Honey and Pies
  • Challenges in Investigating International Cybercrime

Sound Bites

  • "Nukudu offers a paid training program followed by a guaranteed job."
  • "Dr. Thomas Hyslop led a DCIS undercover operation."
  • "The Master of Science in Cybercrime program focuses on digital forensics and criminal investigation."
  • "The future of cybercrime is concerning as large criminal organizations are becoming more sophisticated and mimicking nation states in their capabilities."
  • "Investigating international cybercrime is challenging due to slow response times and the need for cooperation between countries."
  • "Dr. Highslip ran a museum of vintage technology and is looking for a permanent location to house it."

Chapters

00:00 Nukudu: A New School Offering Paid Training and Guaranteed Job Placement in Cybersecurity

06:21 The Role of Interagency Collaboration in Combating Cybercrime

19:07 The Master of Science in Cybercrime Program at the University of South Florida

25:48 Emphasizing Team Building and Collaboration in Cybersecurity Education

26:42 The Future of Cybercrime

27:11 Investigating International Cybercrime

31:25 Preserving Vintage Technology

37:30 The Ideal Triathlon

43:03 Indulging in Junk Food

45:23 Rocking Out with Guns N' Roses

49:11 Dr. Highslip: A Valuable Addition to the Fantasy Cybersecurity Squad

View Details

Summary

Kenya's efforts to enhance its cybersecurity and technological progress through partnerships with the US and major tech companies. The focus is on responsible state behavior in cyberspace and addressing mobile app security. The role of public-private partnerships in promoting a robust digital economy and infrastructure. The conversation then transitions to an interview with Maretta Morovitz, a cybersecurity expert at MITRE, discussing her career path, the importance of mentorship, and the impact of ADHD on her work. The discussion also covers MITRE Engage, which focuses on cyber denial, deception, and adversary engagement, and highlights the use of simple yet effective techniques like decoy credentials. In this conversation, Maretta Morovitz discusses the importance of thinking creatively and outside the box when it comes to cybersecurity solutions, especially for organizations with limited budgets. She emphasizes the need for simplicity and proactive measures in cybersecurity. Maretta also highlights the value of interdisciplinary collaboration in the field, involving professionals from various backgrounds such as human behavioral scientists and graphic designers. She shares a successful collaboration between MITRE and HSBC in the field of deception operations. Maretta also talks about her passion for dance and her unique talent of reciting the alphabet backwards.

Keywords

Kenya, cybersecurity, technological progress, partnerships, responsible state behavior, mobile app security, public-private partnerships, digital economy, infrastructure, interview, Maretta Morovitz, career path, mentorship, ADHD, MITRE Engage, cyber denial, deception, adversary engagement, decoy credentials, cybersecurity, low budget solutions, simplicity, proactive measures, interdisciplinary collaboration, deception operations, dance, talent

Takeaways

  • Kenya is forging partnerships with the US and major tech companies to enhance its cybersecurity and technological progress.
  • The focus is on responsible state behavior in cyberspace and addressing mobile app security.
  • Public-private partnerships play a crucial role in promoting a robust digital economy and infrastructure.
  • Mentorship is important in career development, and having mentors who provide opportunities and support can be instrumental in success.
  • ADHD can present challenges but also bring unique strengths to the workplace.
  • MITRE Engage focuses on cyber denial, deception, and adversary engagement, using simple yet effective techniques like decoy credentials. Thinking creatively and outside the box is crucial in cybersecurity, especially for organizations with limited budgets.
  • Simplicity and proactive measures are key in cybersecurity to effectively address threats.
  • Interdisciplinary collaboration involving professionals from various backgrounds can bring new perspectives and solutions to the field.
  • Deception operations can be a valuable tool in cybersecurity, and successful collaborations in this area have been seen between organizations like MITRE and HSBC.
  • Passions and talents outside of cybersecurity, such as dance, can bring unique perspectives and skills to the field.

Sound Bites

  • "Sometimes the real solution is something very low tech or just kind of outside the box, low budget."
  • "Being proactive has to be simple."
  • "We definitely need more of that interdisciplinary approach."

Chapters

00:00 Kenya's Cybersecurity Partnerships

03:24 Addressing Mobile App Security

07:13 Interview with Maretta Morovitz

11:35 Cyber Deception and Adversary Engagement

29:12 The Importance of Simplicity and Proactive Measures

30:07 Interdisciplinary Collaboration in Cybersecurity

31:06 Successful Collaboration in Deception Operations

34:44 Bringing Unique Perspectives and Skills to Cybersecurity

Follow Maretta Morovitz on LinkedIn: Maretta Morovitz

Follow MITRE on Twitter: @MITREcorp

Learn more about MITRE Engage: MITRE Engage

View Details

Summary

The conversation discusses the extradition case of Julian Assange and the role of the US prison system in the decision. It also explores Tanya Janca's role at Semgrep and her passion for affordable cybersecurity education. Additionally, it touches on Tanya's experience in election security and the importance of transparency in the process. Tanya discusses her volunteer work with the Canadian government, where she helps educate students about cybersecurity. She talks about the importance of teaching young people about privacy, protecting digital devices, and understanding cyber threats. Tanya also mentions her involvement in the Cyber Titan competition and her efforts to promote cybersecurity as a career. She shares her experience writing the book 'Alice and Bob Learn Application Security' and her unique approach to making technical concepts accessible through stories and different learning styles. Tanya also talks about the importance of mentoring and how she has benefited from mentors throughout her career.

Keywords

Julian Assange, extradition, US prison system, cybersecurity education, Semgrep, election security, transparency, volunteer work, Canadian government, cybersecurity education, privacy, digital devices, cyber threats, Cyber Titan, promoting cybersecurity, career, Alice and Bob Learn Application Security, technical concepts, stories, learning styles, mentoring

Takeaways

  • The extradition case of Julian Assange highlights the differences in prison systems between the US and other Western democracies.
  • Tanya Janca's role at Semgrep involves community management and education in the field of cybersecurity.
  • Affordable cybersecurity education is crucial for organizations to effectively use security tools and integrate them into their programs.
  • Election security requires centralization, knowledge sharing, and transparency to ensure public trust in the process. Volunteer work with the Canadian government focuses on educating students about cybersecurity, including topics like privacy and protecting digital devices.
  • Promoting cybersecurity as a career is important, and initiatives like the Cyber Titan competition help engage high school students in learning about cybersecurity.
  • Tanya's book 'Alice and Bob Learn Application Security' uses stories and different learning styles to make technical concepts accessible.
  • Mentoring is valuable for personal and professional growth, and Tanya has both benefited from mentors and become a mentor herself.

Titles

  • The Importance of Transparency in Election Security
  • Cybersecurity as a Career: The Cyber Titan Competition
  • The Value of Mentoring: Tanya's Experience as a Mentor and Mentee

Sound Bites

  • "I am head of community and education, which is a role they made up just for me."
  • "They decided, I think in 2017, we need to make a task force to make sure they know cyber."
  • "Defenders need to understand attacks or they can't be good at defending, right? Like we're teaching them ethics as we teach them how to hack."
  • "Alice and Bob are going to learn secure coding this time."

Chapters

00:00 The Extradition Case of Julian Assange

08:18 Affordable Cybersecurity Education at Semgrep

30:40 Tanya's Volunteer Work with the Canadian Government

31:35 Promoting Cybersecurity as a Career

34:02 Making Technical Concepts Accessible: 'Alice and Bob Learn Application Security'

39:45 The Value of Mentoring

View Details

Summary

In this episode of the No Password Required podcast, host Jack Clabby and co-host Kayley Melton interview Tamiko Fletcher, the CISO at Kennedy Space Center. Tamiko shares her journey from a small town in South Carolina to working at NASA and discusses her role as a CISO. She emphasizes the importance of mentorship, outreach, and diversity in the cybersecurity field. Tamiko also talks about the unique challenges of cybersecurity at NASA, such as patching during launches and balancing innovation with security.

She emphasizes the need to know and learn about individuals' strengths, interests, and motivations in order to effectively place them on teams and utilize their skills. Tamiko also shares her experiences working at NASA and the changes she has witnessed over the years, including the evolution of IT and the increasing diversity at the Kennedy Space Center. She highlights the excitement and pride she feels when witnessing a launch and the impact of NASA's work on the world.

Keywords

NASA, cybersecurity, CISO, career trajectory, mentorship, outreach, diversity, patching, innovation, security, NASA, Kennedy Space Center, cybersecurity, teamwork, understanding people, IT evolution, diversity, launches, personal experiences, imposter syndrome, work-life balance, advocating for oneself, UFOs

Takeaways

  • Tamiko Fletcher shares her journey from a small town in South Carolina to working at NASA as the CISO at Kennedy Space Center.
  • She highlights the importance of mentorship, outreach, and diversity in the cybersecurity field.
  • Tamiko discusses the unique challenges of cybersecurity at NASA, such as patching during launches and balancing innovation with security.
  • She emphasizes the need for flexibility and adaptability in the ever-changing cybersecurity landscape. Understanding and valuing people is crucial in the workplace, as it allows for effective team placement and utilization of individual skills.
  • The evolution of IT and the increasing diversity at NASA's Kennedy Space Center have been significant changes over the years.
  • Witnessing a launch at NASA is an exciting and prideful experience, reminding employees of the impact of their work.
  • Advocating for oneself and setting boundaries is important for maintaining work-life balance and overall well-being.

Sound Bites

  • "I'm from a small town called Manning, South Carolina. If you look it up on the map, it's near Travel America. It's probably the best thing we got going for it, honestly."
  • "Success stories like yours are common at NASA. And it's also based on one's definition of success, right? So everyone has their own definition of what success is for them."
  • "I try to actually know and learn people... because I want to understand what makes them tick so I know where to place them on a team."
  • "We are human first and then we are who our job is. And I want to be able to utilize that person, that whole person, what makes them happy, what makes them excited to come in every day."
  • "I have a vast variety of folks on the team who help get cyber done."

Chapters

00:00 Introduction and Welcome to the Podcast

08:00 Education and Career Trajectory

25:48 Challenges and Innovations in Cybersecurity at NASA

34:4 8Building a Team and Emphasizing Diversity

41:30 The Diversity of the Cyber Team at NASA

54:25 Instilling Values in Teams to Change the Work Environment

View Details

Summary

Roman Sanikov, is the president of Constellation Cyber and specializes in cyber threat intelligence. In this episode, Roman discusses the importance of collaboration and transparency in the cybersecurity industry, particularly in combating ransomware attacks. He also emphasizes the need for a holistic approach to cybersecurity, involving education and empowerment for both employees and consumers. In this episode, Roman Reinhart shares his experiences as an undercover agent in the cybercrime world. He discusses maintaining a persona, dealing with forum behavior, and memorable arrests. He also emphasizes the importance of redemption and second chances. Roman also talks about his involvement with Helpster USA, an organization dedicated to providing life-saving treatment to young people in developing economies. He shares his hobbies of mushrooming and highlights the satisfying moments at work. Finally, he reflects on the cultural differences he experienced after moving overseas.

Takeaways

  • Pig butchering schemes are a significant cause of financial losses globally, and it is important to approach the topic with compassion and nuance.
  • Many scammers involved in these schemes are forced into this life against their will, either through human trafficking or being lured into it with false promises.
  • Collaboration and transparency are crucial in the cybersecurity industry to effectively combat ransomware attacks and mitigate their secondary and tertiary impacts.
  • A holistic approach to cybersecurity, involving education and empowerment for employees and consumers, is necessary to create a more secure environment. Maintaining a persona in the cybercrime world requires careful observation and adaptation.
  • Memorable arrests can lead to redemption and second chances for individuals involved in cybercrime.
  • Helpster USA provides life-saving treatment to young people in developing economies.
  • Mushrooming is a rewarding hobby that allows for outdoor exploration and collection.
  • Satisfying moments at work include helping clients have eureka moments and making positive changes.
  • Cultural differences, such as politeness, can take time to understand and adapt to.

Chapters

00:00 Introduction to Pig Butchering Schemes (opening conversation)

02:18 Online Scams and Exploitation

03:41 Forced Labor and Human Trafficking

04:41 Approaching Scams with Compassion

05:39 Guest Introduction: Roman Sanikov

07:01 Roman's Role at Constellation Cyber

08:22 Promoting Transparency in Ransomware Incidents

10:17 Mitigating Secondary and Tertiary Impacts of Ransomware Attacks

11:14 The Ripple Effect of Ransomware Attacks

13:10 The Importance of Collaboration in Cybersecurity

14:58 Roman's Career Path and Background

19:34 Educating and Empowering Employees and Consumers

21:28 Avoiding Victim-Blaming in Cybersecurity

24:16 The Need for Collaboration and Transparency in the Industry

25:10 Balancing Non-Traditional Pursuits with College

26:37 Undercover Work and Building Relationships

33:07 Maintaining a Persona

36:25 Dealing with Forum Behavior

38:18 Memorable Arrests

41:25 Redemption and Second Chances

45:13 Helpster USA

48:16 Eccentricities of NHL Players

50:56 Life's Unexpected Moments

56:19 The Joy of Mushrooming

58:43 Satisfying Moments at Work

01:01:04 Learning Politeness in America

View Details

Summary

In this episode, Jo Anna joins Carlton Fields P.A. Jack Clabby and KnowBe4’s VP of Remote Publishing Teams Kayley Melton to tell the story of how her career has changed since starting at Rice University 17 years ago. From her early days as a receptionist at a hair salon to her current role as a security analyst, Jo Anna shares her journey in the cyber world and her fascination with artificial intelligence, stemming from her compliance-related responsibilities. Emphasizing a realism-based view on AI, she passionately advocates for a comprehensive understanding of AI, emphasizing that it’s neither inherently good nor bad.

Takeaways

  • Stolen recordings from popular artists can sell for high prices on the black market.
  • Cyber criminals are involved in various illegal activities, including stealing cryptocurrency and trading stolen, unreleased rap recordings.
  • Law enforcement plays a crucial role in investigating and apprehending cyber criminals, and these crimes can have real-life consequences.
  • The intersection of cybersecurity and AI presents challenges in assessing the risks associated with AI technologies.
  • Community outreach and education are important in promoting cybersecurity awareness and encouraging more people to pursue careers in the field.

Chapters

00:00 Stolen Recordings and Cyber Criminals

01:29 Arrest of a Florida Man and Stolen Rap Recordings

02:27 The Allegations and Nicknames

03:26 The Connection Between Cyber Crime and Rap Music

04:23 Real-Life Consequences of Cybersecurity Crimes

05:52 The Role of Law Enforcement in Cybersecurity Crimes

06:50 Introduction of Guest Joanna Parker-Martin

07:18 Joanna's Role at Rice University

08:15 Protecting Data at Rice University

09:08 Joanna's Journey into Cybersecurity

10:04 Overcoming Challenges and Changing Career Paths

18:14 Joanna's Interest in Artificial Intelligence

19:22 The Intersection of Cybersecurity and AI

20:46 The Challenges of Assessing AI Risk

21:13 The Inevitability of AI

22:37 The Risks of Facial Recognition Technology

27:26 Joanna's Involvement with WiCys

29:48 Community Outreach and Cybersecurity Education

30:10 Misconceptions About Cybersecurity Professionals

32:32 The Lifestyle Polygraph

43:35 Joanna's Preference for Sponge Cake in Strawberry Shortcake

View Details

SummaryThe conversation discusses the arrest of Ola Segun Simpson Adagorin, a Nigerian national facing US federal charges for a business email compromise scheme. The collaboration between the FBI and Ghana is highlighted, along with the role of the legal attache job in solving crimes with international impact. The scheme and indictment details are explored, emphasizing the sophistication of the attack. Dr. Diana Burley, Vice Provost for Research and Innovation at American University, shares insights on cybersecurity education and workforce readiness. The importance of understanding human behavior in cybersecurity is discussed, along with strategies for engaging in conversations and addressing the search for cyber unicorns. In this episode, the importance of password security and the various methods to enhance it are discussed. The conversation covers common password mistakes, the use of password managers, multi-factor authentication, biometric authentication, and the future of password security.

Takeaways

  • Collaboration between law enforcement agencies is crucial in solving cybercrime cases with international implications.
  • Understanding human behavior is essential in addressing cybersecurity challenges and shaping effective policies.
  • Digital literacy and foundational cybersecurity skills should be integrated into education across disciplines.
  • Creating a culture of cybersecurity requires a balance between rules and creativity, and a focus on psychological safety.
  • Engaging in conversations with strangers can be facilitated by finding common interests and making personal connections. Create strong and unique passwords for each online account.
  • Avoid common password mistakes such as using personal information or easily guessable patterns.
  • Consider using a password manager to securely store and generate passwords.
  • Enable multi-factor authentication whenever possible for an added layer of security.
  • Biometric authentication, such as fingerprint or facial recognition, can provide convenient and secure access to devices and accounts.
  • Passwordless authentication methods, such as biometrics or hardware tokens, may become more prevalent in the future.
  • Stay informed about emerging technologies and best practices in password security.

Chapters

00:00 Introduction and Arrest of Ola Segun Simpson Adagorin

01:24 Collaboration between FBI and Ghana

03:15 Scheme and Indictment Details

04:44 Legal Attache Job and Collaboration

06:10 Deterrence and Sealed Indictments

07:36 Introduction of Dr. Diana Burley

08:31 Dr. Burley's Background and Role at American University

09:23 Interest in Cybersecurity and Technology

10:21 American University's Role in Educating Policymakers

12:15 Engaging with Leaders and Shaping Policy

13:36 Engaging with Students and Future Leaders

14:28 American University's Focus on Policy and Research

15:27 Misconceptions about the Cybersecurity Workforce

16:23 Digital Literacy and Foundational Cybersecurity Skills

18:45 Retaining Skilled Members in the Academic Environment

19:43 Benefits of Engaging as a University Faculty Member

20:37 Understanding Human Behavior in Cybersecurity

22:05 Insights from Research on Human Behavior

23:25 Understanding Employee Behavior in Cybersecurity

24:47 Creating a Culture of Cybersecurity

27:08 Strategies for Initiating Conversations with Strangers

31:50 The Cyber Unicorn Project

35:08 Addressing the Search for Cyber Unicorns

41:45 Lifestyle Polygraph

50:57 Understanding Irrational Behavior and Self-Awareness

53:37 Engaging in Conversations with Strangers

02:30 The Importance of Password Security

10:15 Common Password Mistakes

18:45 Password Managers

27:10 Multi-Factor Authentication

35:40 Biometric Authentication

44:20 Passwordless Authentication

52:30 Future of Password Security

58:21 Conclusion

View Details

Summary

In this episode, Jack Clabby and Kayley Melton discuss the upcoming Sunshine Cyber Conference and their collaboration with Winn Schwartau. They also talk about the importance of diverse cybersecurity talent and their plans for a joint session at the conference. The hosts then interview Lisa Plaggemier, the executive director at the National Cybersecurity Alliance, who shares her career journey and the role of creativity and curiosity in cybersecurity. They also discuss the impact of COVID-19 on the cybersecurity industry and the importance of humor and satire in cybersecurity training. The episode concludes with a lifestyle polygraph segment. In this episode, the conversation covers various topics related to comedy, storytelling, and implementing change in organizations. The power of the internet is discussed, highlighting the potential consequences of online content. The guest shares her favorite comedy movies, emphasizing the comedic element in her expertise. The use of humor in training and awareness programs is explored, along with the challenges of implementing change in organizations. Dealing with roadblocks in security and the passion for security awareness are also discussed. The episode concludes with information on how to get in touch with the guest and a recap of what was learned.

Takeaways

  • The Sunshine Cyber Conference features keynote speakers from the No Password Required podcast, including Winn Schwartau.
  • The hosts will be doing their first on-site remote recording at the Sunshine Cyber Conference, featuring keynote speaker Tamiko Fletcher.
  • The National Cybersecurity Alliance focuses on training and awareness, using creativity and humor to engage and educate people.
  • Comedy movies, such as Monty Python and the Holy Grail, can be a source of expertise and inspiration.
  • Humor can be effectively used in training and awareness programs to engage and educate participants.
  • Implementing change in organizations can be challenging, but finding allies and overcoming roadblocks is essential.

Chapters

00:00 Introduction

01:28 Fishing for Potential, the RTFM Guide to Diverse Cybersecurity Talent

02:25 Live On-Site Remote Recording and Keynote Speakers

03:51 Sunshine Cyber Conference and Registration

04:46 Interview with Lisa Plaggemier

05:15 Background and Role at the National Cybersecurity Alliance

05:53 Transition to Security and Marketing Collaboration

06:22 Incident Response and Training and Awareness

07:20 Leadership and Skills in Cybersecurity

08:18 Kubikle Series and Creativity in Security

09:17 Curiosity and Creativity in Cybersecurity

10:48 Naming and Shaming in Pen Tests and Phishing Testing

11:41 DDoS Attack and Incident Response

12:38 Neurodiversity and Cybersecurity

13:21 Leading a Team During COVID-19

14:21 Creating Engaging Training Content

15:19 Global Data and Data Privacy Laws

16:18 Humor and Satire in Cybersecurity Training

18:47 Kubikle Series and Satire in Cybersecurity

20:41 Creating Kubikle Series and Future Plans

23:03Trust in Password Managers

24:22 The Importance of Curiosity in Cybersecurity

25:52 The Oh Behave Report and Behavioral Science

26:50 Communicating Security Information Effectively

28:44 Naming and Shaming in Phishing Testing

29:39 Accepting Risk and Escalation Plans

30:38 The Role of Security Teams and HR

32:35 Building Trust in Password Managers

33:32 Global Data and Cybersecurity Awareness

36:51 The Importance of Curiosity in Cybersecurity Hiring

40:03 The Underground Student-Led Newspaper

41:12 The Significance of Curiosity and Creativity in Career

50:44 The Power of the Internet

51:14 Favorite Comedy Movies

52:12 Using Humor in Training and Awareness

53:38 Implementing Change in Organizations

54:55 Dealing with Roadblocks in Security

55:45 Passion for Security Awareness

56:06 How to Get in Touch

56:37 What Was Learned

57:11 Closing Remarks

View Details

Jayson Street — Chief Adversarial Officer at Secure Yeti, a DEF CON Groups Global Ambassador, and a world-class awkward huggerJayson Street, the dynamic Chief Adversarial Officer at Secure Yeti, has worn many masks throughout his life and career. He was once named a “World-Class Hacker” on the National Geographic series "Breakthrough Cyber-Terror," but he prefers the simpler title of Hacker, Helper, and Human.In this episode, Jayson joins Carlton Fields P.A.’s Jack Clabby and KnowBe4’s VP of Remote Publishing Teams Kayley Melton to talk about his journey of self-discovery that led him from being an award-winning janitor at McDonald's to one of the world’s most infamous ethical hackers. From his early childhood, Jayson has embraced hacking as a way of life, embodying the spirit of relentless exploration, innovation, and resilience. Like our favorite co-host Kayley, Jayson uncovered a new layer of his identity in his adulthood when he discovered that he is neurodivergent. He dives deep into how this new understanding altered his perception of himself, allowed him to embrace the various “masks” he wears throughout life, and discovered that his unique mind is actually his superpower. He also shares extraordinary stories of how he gained entry into some of the hardest-to-access cyber targets in the world.To start off the show, Jack and Kayley talk about the celebrity that’s topping the Hacker Celebrity Hot List as the celeb whose name is used most by cybercriminals when creating online scams. Hint: he’s just Ken…You can follow Jayson on LinkedIn here: https://www.linkedin.com/in/jstreet/You can follow Jayson on Twitter here: @jaysonstreetYou can learn more about Jayson here: https://jaysonestreet.comYou can learn more about Secure Yeti here: https://www.secureyeti.com/

View Details

Kristin Demoranville — CEO and Founder of AnzenSage, defender of the food sector, and friend to primates What is the role of cybersecurity in food safety? Kristin Demoranville, CEO and Founder of AnzenSage, is committed to shielding the food sector from potential cybersecurity threats and ensuring the resilience of the entire food supply chain. Her dedication is not just a professional pursuit; it's a mission to prevent any compromise to public health. In this episode, Carlton Fields Cybersecurity Attorney Jack Clabby and No Password Required producer Rex Wilson speak with Kristin about everything from the deployment of autonomous tractors to the secure refrigeration of airport food, and Kristin sheds light on the other facets of daily life that are linked to the food supply chain. Kristen also shares how her love for wildlife led to her working with primates at the Louisville Zoo before making the transition into cybersecurity, and the value that podcasting has brought to her life. Kristen’s podcast, the Bites & Bytes Podcast, is her platform for discussing cybersecurity and food safety, and is recommended listening for fans of No Password Required. Bites & Bytes has fast become a medium for Kristin to share insights, connect with audiences, and explore the intersections of her diverse interests. Jack and Rex also delve into the intricacies of the Environmental Protection Agency's recent decision not to include cybersecurity in water system audits, and the questions this may raise about the security of water utility infrastructure.You can follow Kristin on LinkedIn here: https://www.linkedin.com/in/demoranvillekristin/ You can follow Kristin on Twitter here: @demokris You can learn more about AnzenSage here: https://www.anzensage.com/

View Details

Jessica Gulick — Founder and Commissioner of the US Cyber Games, CEO of the cyber marketing firm Katzcy, and someone who values perseverance over perfection Jessica Gulick is a woman of many trades. She is the Founder and CEO of the cyber marketing firm Katzcy, the Founder and Commissioner of the US Cyber Games, and a trailblazer who is working to make cybersecurity a sport that thrives. In this episode, Jessica joins Carlton Fields P.A.’s Jack Clabby and KnowBe4’s Kayley Melton to share her experiences as a female entrepreneur and the role that perseverance has played throughout her career. She also talks about the inception of the US Cyber Games, its commitment to bringing together elite cyber athletes, coaches, and industry leaders, and the purpose she hopes it will serve in the cyber world. Jack and Kayley also discuss the recent developments of Droidish, which may sound like a new Star Trek language but is actually the language being developed by the US military to allow AI drones to communicate with one another to become useful “tools” for many different purposes.You can follow Jessica on LinkedIn here: https://www.linkedin.com/in/jessicagulick/ You can follow Jessica on Twitter here: @CyberRiskLadyYou can learn more about US Cyber Games here: https://www.playcyber.com/

View Details

Allan Liska —Threat Intelligence Analyst at Recorded Future, the Ransomware Sommelier, and a guy with a mildly exciting expense accountAllan Liska is a Threat Intelligence Analyst at Recorded Future. In this episode, Allan returns to No Password Required to talk with Carlton Fields Attorney Jack Clabby and KnowBe4’s Kayley Melton about his experiences in the ever-evolving battlefield of cyber threats, what has changed in ransomware since his first time on the show, and his perspective on the power of AI in the battle against cyber threats. He also updates us on his passion project: the upcoming release of the Yours Truly, Johnny Dollar comic book. In this thrilling new venture, Allan breathes new life into iconic insurance investigator Johnny Dollar by casting him in a role that hits close to home: a ransomware investigator. The best part was that he gifted the No Password Required team the chance to act out a scene from the comic. Jack and Kayley also talk about the dismantling of Qakbot, marking one of the largest-ever U.S.-led enforcement actions against a botnet (and also marking one of the best U.S. mission titles - Operation Duck Hunt.) You can follow Allan on LinkedIn here: https://www.linkedin.com/in/allan2/ You can follow Allan on Twitter here: @uuallan You can learn more about Recorded Future here: https://www.recordedfuture.com/

View Details

Courtney H. Jackson — CEO of Paragon Cyber Solutions, family-night game champion, and calculated-risk takerCourtney H. Jackson is the CEO of Paragon Cyber Solutions, a Tampa-based cybersecurity solutions provider. If Courtney’s name sounds familiar, that may be because she was awarded the Global 2022 Cybersecurity Woman Entrepreneur of the Year! In addition, Courtney is a 2023 Business Woman of the Year Honoree and a veteran of the U.S. Navy, where she was introduced to the world of cyber and IT. In this episode of No Password Required, Courtney joins Carlton Fields P.A. Jack Clabby and KnowBe4’s Kayley Melton to talk about her path to becoming a CEO, the resources that she wished she’d had when starting her career in this industry, how she uses a Cybersecurity Apprenticeship program approved by the Department of Education and Department of Veterans Affairs and SkillBridge to fill her growing team with talent, and the “one” family-night game that brings out her family’s competitive spirit.Jack and Kayley also talk about the unlikely duo behind the 2016 Bitfinex hack - one of whom is most known by her persona as the aspiring rapper “Razzlekhan.” You can follow Courtney on LinkedIn here: https://www.linkedin.com/in/courtneyhjackson/ You can follow Courtney on Twitter here: @mrschjackson You can learn more about Paragon Cyber Solutions here: https://paragoncybersolutions.com/

View Details

Lisa Ventura — founder of Cyber Security Unity, Member of the Order of the British Empire, and appreciator of 80s soap operas

Lisa Ventura MBE is the founder of Cyber Security Unity, a UK-based organization seeking to unite the cyber security industry globally. Lisa is also a proud neurodivergent person; after being diagnosed in her adulthood with autism and ADHD, she gained a wider understanding of who she is, how she can use her unique traits to make the world better, and how she can advocate for neurodivergent talent in the cyber industry.

In this episode of No Password Required, Lisa joins Carlton Fields, P.A.’s Jack Clabby and KnowBe4’s Kayley Melton to share how she went from working on the UK version of “Who Wants to be a Millionaire?” to becoming an award-winning leader in the cybersecurity industry. She also tells us about receiving her honorary award from the British Parliament, her love of 1980s U.S. soap operas, and the sci-fi world she’d most want to live in.

Jack and Kayley discuss the drastic increase in the amount of cash Americans lost to text-messaging scams in recent years. Why is this type of attack showing so much growth? How can consumers continue moving forward? They talk about all of that and more.

A special thanks to the great Sarina Gandy for producing this episode.

You can connect with Lisa on Twitter here: @cybergeekgirl

You can connect with Lisa on her personal website here: https://lisaventura.co.uk/

You can learn more about Cyber Security Unity here: https://csu.org.uk/

View Details

Nick Biasini - Threat researcher at Cisco Talos and a veteran of the highest profile cyber incidents who roasts his own coffee beans

Nick Biasini leads a team of threat researchers at Cisco Talos who patrol the cutting edge of the threat landscape. Not only has he investigated some of the most significant cyberattacks in history, but he also has hands-on experience with the 1980 Olympic bobsled track. In this episode of No Password Required, Nick joins Carlton Fields’s Jack Clabby and KnowBe4’s Kayley Melton to talk about his start as an FAA security analyst, some of his top discoveries during his threat research days, and the value of getting comfortable with failure. He shares his story of investigating the SamSam ransomware and his predictions for how AI might be able to support businesses in the future. Kayley and Jack break down the $10 million reward for information leading to the arrest or conviction of alleged Russian ransomware affiliate Mikhail Matveev.

You can connect with Nick on Twitter here: @infosec_nick

Check it out on YouTube here: https://tinyurl.com/4mtbd4ed

View Details

Gotham Sharma is a cybersecurity consultant, writer, educator, and stand-up comic. He’s on a mission to help folks build successful careers in information security through his latest venture, AccessCyber.co. In his training, Gotham leverages humor to make security awareness and education relatable to audiences of various technical backgrounds. Inspired by satire publications like The Onion, Gotham recently launched an infosec magazine called Brute Farce Attack, one of the many projects on his growing list of side hustles. In this episode of No Password Required, Gotham joins Carlton Fields’s Jack Clabby and KnowBe4’s Kayley Melton to share how his life changed after a well-intentioned anti-mentor inspired him. Jack and Kayley discuss IARPA’s plan to hack hackers’ brains as the agency considers reimagining security with cyberpsychology-informed network defenses.You can connect with Gotham on Twitter here: @GothamJSharmaYou can learn more about AccessCyber here: https://accesscyber.co/ You can learn more about Brute Farce Attack here: https://www.brutefarceattack.com/

View Details

Bianca Lewis, also known by her hacker handle BiaSciLab, is a next-generation teenage hacker and the CEO of Girls Who Hack. Bianca’s cybersecurity journey started at age 11 when she was part of a team who successfully compromised a simulated election-reporting system at DEF CON 26. She has since become a national conference speaker and advocate for recruiting girls into the cyber industry. In this episode of No Password Required, Bianca joins Jack Clabby and KnowBe4’s Kayley Melton to share her experiences as a teenage hacker, her advice for being a confident public speaker, and her other biggest passion in life: the theatre. Jack and Kayley discuss the joint investigation between German police, the FBI, and law enforcement in Ukraine and the Netherlands and how they took down the DoppelPaymer ransomware group.You can connect with Bianca on Twitter here: @BiaSciLabYou can learn more about Girls Who Hack here: https://girlswhohack.com/You can learn more about Secure Open Vote here: https://secureopenvote.com/

View Details

Louis Nyffenegger is the founder and CEO of PentesterLab. On this episode of No Password Required, Louis shares how he built his penetration-testing training company, why empathy is crucial to application security, and what can be learned from having hobbies you’re not good at. He also tells us his favorite pen testing story, explains the early days of smartwatch security, and describes his journey from France to Australia. The entire No Password Required team (Ernie, Jack, Rex, Devin, and Sarina) celebrate Ernie’s final episode by participating in a game show challenge about his life. Learn how many tattoos he has, how many countries he’s been to, and more juicy facts that we’ve all been dying to know. You can connect with Louis on Twitter here: @snyff You can learn more about the PentesterLab here: https://www.pentesterlab.com/

View Details

Joey deVilla is a Senior R&D Content Engineer at Auth0, a division of Okta. After hours, Joey is known as the Accordion Guy and spends his time playing music and sharing his nerdy takes on his two personal blogs. In this episode, Joey joins Jack and guest-host Tashya Denose (host of the Do We Belong Here podcast) to talk about his love for the tech community, his unique assortment of passions, hobbies, and jobs, and how he continues to trust the serendipity of his life even when the path seems unclear. Tashya and Jack talk about DoNotPay’s $1 million offer to lawyers to let AI take their place before the Supreme Court and what this kind of technology could mean for the future. You can connect with Joey here: globalnerdy.com and here: joeydevilla.com You can learn more about the Legendary Nanaimo Bar here: https://www.nanaimo.ca/about-nanaimo/nanaimo-bars

View Details

General (Ret.) Frank McKenzie is the Executive Director of the Global and National Security Institute at the University of South Florida and the Executive Director of Cyber Florida. In April 2022, General McKenzie retired from the Marine Corps after completing over 42 years of service. He joins the No Password Required team to discuss the evolution of his leadership style over time, a typical morning for a four-star military general, and his preference for Star Trek over Star Wars. In honor of the holidays, Ernie and Jack discuss one of the most iconic (and shocking) Christmas movies of all time - Gremlins.

View Details

Andy Sekela is the Private Sector Coordinator for the FBI Tampa Division, who may just be on a mission to have the world’s coolest resumé. In this episode, Andy joins the No Password Required team to talk about his diverse career path, including his time as an officer on a nuclear submarine, public corruption investigations, and his best “wow, I’m an FBI agent” story. He also explains the FBI's role in investigating cybersecurity breaches, what happens after an IC3 report, and career opportunities at the agency. Jack and Ernie discuss the dark web's recent offer for sale of 487 million WhatsApp numbers and how modern businesses handle suspected website scraping.

View Details

Hannah Sutor is the Senior Product Manager at GitLab and Digital Privacy Advocate at The Privacy Chick. Hannah joins the No Password Required team to talk about how she discovered privacy and cybersecurity in college, what she expects for the future of usernames and passwords, and her adventures while traveling in an RV with her family for a year. Bonus: she also reveals her recipe for the best pumpkin spice latte. Ernie and Jack discuss the proposed U.S. labeling program for IoT consumer devices and some potential cyber and privacy implications.

View Details

Charles Shirer is the Chief Executive Officer of GlobalWave Consulting, an IT and cybersecurity consultancy. Known as the @bsdbandit to his 20,000+ Twitter followers, Charles is often considered the most positive person in cybersecurity (and for good reason!). In this episode, Charles joins the No Password Required team to tell us about how his childhood love for video games led to his passion for everything computer-related, what inspires him to share motivational messages on Twitter, and the importance of striving for a positive mindset in life. Jack and Ernie discuss the United Kingdom’s potential privacy enforcement against TikTok, and the regulatory regime for collecting the personal data of minors.

View Details

Kayley Melton is the Vice President of Security Awareness Company Courseware and Labs at KnowBe4. Although she can’t share too much about what the "labs" portion of her job entails, let's face it, the secrecy makes her even cooler. Kayley joins the No Password Required team to tell us about her journey from an Appalachian farm to fine arts major at a self-described “bougie” college, and from there to VP at a leading security awareness company and the challenges that she overcame to get there. Kayley also shares the story of how a Craigslist ad changed her life, who the Chewbacca is to her Han Solo, and the lessons she’s had to learn as a woman in this industry. Ernie, Jack, and Pablo discuss something likely to shock 90s babies; the cybercriminal “TarTarX” has stolen the data of 69 million Neopets users.

View Details

Serge Jorgensen is a founding partner and CTO at Sylint Group, where he provides response and remediation guidance on international espionage incidents, cyber-security attacks, and counter cyber-warfare. An engineer by training, he has a bias for action over theory. In this episode, Serge joins the No Password Required team to talk about his time in the industry, his experience coaching sailing at the Paralympic Games, and his favorite childhood toy. Ernie, Jack, and Pablo discuss the cybercriminals that are posing as Twitter employees and journalists to breach academic and Middle East policy data. In the Technologue segment, Pablo teaches the team the history of the world’s largest hacking competition, DEF CON.

View Details

Tashya Denose is a Senior Manager of Cybersecurity Analysis at Capital One and the Director of Brand & Marketing at Black Girls in Cyber. In this episode, Tashya joins the No Password Required team to discuss her passion for making everyone feel welcome in the cybersecurity world, the state of the cybersecurity pipeline and what needs to be done, and a LOT of other rad stuff (including her feelings about the word “rad” making a comeback!) Ernie, Jack, and Pablo discuss the rogue freelancers that were taking advantage of remote work opportunities to hide their true identities and earn money for North Korea. Pablo presents the new Technologue game show where the team attempts to answer questions about the first-ever computer worm.

View Details

Vice Admiral Mike McConnell is the former director of the National Security Agency (NSA) and the current Executive Director of Cyber Florida. In this two-part episode, VADM McConnell stuns the No Password Required team to silence with stories of his life, which just so happens to resemble a riveting Grisham novel. A few highlights include the reason he refuses to drink cheap beer (or formaldehyde), some iconic moments during his time at the NSA, and more. Ernie, Jack, and Pablo break down the Strengthening Cybersecurity Act and the biggest commitment one can make: cowboy boots. In the Technologue segment, Pablo discusses the importance of cloud vulnerability evolution.

View Details

Vice Admiral Mike McConnell is the former director of the National Security Agency (NSA) and the current Executive Director of Cyber Florida. In this two-part episode, VADM McConnell stuns the No Password Required team to silence with stories of his life, which just so happens to resemble a riveting Grisham novel. A few highlights include the reason he refuses to drink cheap beer (or formaldehyde), some iconic moments during his time at the NSA, and more. Ernie, Jack, and Pablo break down the Strengthening Cybersecurity Act and the biggest commitment one can make: cowboy boots. In the Technologue segment, Pablo discusses the importance of cloud vulnerability evolution.

View Details

Dr. Melissa Dark is the Founder of DARK Enterprises, a non-profit organization dedicated to developing and supporting cybersecurity education at the secondary level. Before that, Dr. Dark worked in graduate and college cybersecurity education for over 20 years, as a professor at Purdue University. In this episode, Dr. Dark joins the No Password Required team to discuss her career in “training the trainers,” the early days of cybersecurity education as an academic subject, and how to encourage cybersecurity awareness among today’s students. Ernie and Jack discuss the Pinellas Park, Florida, cybersecurity analyst alleged to have stolen almost $600,000 in cryptocurrency and how he supposedly did it.

View Details

Larry Whiteside Jr. is the President and Director of Cyversity, an organization whose mission is to achieve consistent representation of women and underrepresented minorities in the cyber industry through programs designed to diversify, educate, and empower. As someone who has experienced the value of mentorship firsthand throughout his life, both as a child and an adult, Larry is passionate about creating a space in the cyber field where everyone is valued and heard. In this episode, Larry joins the No Password Required team to discuss the mentors who helped turn his life around as a teen, the coolest motorcycle-riding character of all time, and the value of honoring every person's individual perspective in life. Ernie, Jack, and Pablo discuss the potential cyber consequences of the Ukraine conflict. In the Technologue segment, Pablo breaks down the Cloud and its benefits.

View Details

Thomas Vaughn is the current Chief Information Security Officer (CISO) of the City of Tallahassee and the former CISO of Florida. A kindhearted introvert who began his career in the Army and then the U.S. Coast Guard, Thomas thrives on helping other people however he can, whether it’s with cybersecurity practices or serving as a volunteer fireman in his spare time. In this episode, Thomas joins the No Password Required team to talk about his journey from the military to cybersecurity, the top-tier candy that he can’t live without, and the philosophical lessons that he carries with him throughout his life. Ernie, Jack, and Pablo discuss the UCF student who created an algorithm to track Elon Musk’s private jet. In the Technologue segment, Pablo explains web tracking and what it means for the everyday internet user.

View Details

Debbie Janeczek is the Cyber Threat Management Leader and Technology Executive at Wells Fargo. At her core, Debbie is an outdoorswoman who is passionate about conquering the mountains of Colorado and beyond with her sidekick, her dog, Jack. In this episode, Debbie joins the No Password Required team to talk about her journey from becoming a Naval Intelligence officer where she hated all things cybersecurity to becoming a leader in the industry thanks to inspiration from the great leaders surrounding her (lucky for us!) Debbie is passionate about practicing mindfulness and embracing nature to maintain a healthy work-life balance and stay grounded in the chaos of the ever-changing cybersecurity world. Ernie and Jack (co-host Jack, not dog Jack) discuss the relaunching of the darknet market AlphaBay by one of the previous founders who escaped the bust in 2017, DeSnake, and the long-standing debate of how exactly to pronounce his name.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

In this lost episode from season 1 of No Password Required, Jack Clabby sits down with hosts Ernie Ferraresso and Bill McQueen to discuss cyber liabilities and the potential legal consequences that businesses face from cybersecurity breaches and, more importantly, what they can do to protect themselves. Note that this episode was recorded on 2/27/2020.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

In this early-pandemic episode, Allan Liska, a senior security architect at Recorded Future discusses ransomware, why the best cybersecurity advice will almost never land you a talk at Black Hat, and why calling someone JarJar cuts way deeper than calling them a script kitty. The team also discusses Alan's path into the cybersecurity world; we knew the No Password Required tradition of atypical paths into the cyber world was safe when he started his journey with a sociology degree and a willingness to crawl under a desk.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Asim Fareeduddin is the Vice President of IT Security & Regulatory Controls Assurance at the RELX Group. In addition to his impressive professional resume, Asim is a guy who is never afraid to take a chance - from stand-up comedy to teaching masters-level students at Georgia State University; he’s done it all. In this episode, Asim joins the No Password Required team to talk about how he went from an accountant to Vice President of a global company, how becoming a dad has changed him, and his most cherished accomplishment - high-fiving Busta Rhymes at the 2006 B.E.T. Awards. Ernie and Jack talk about why fist bumps have officially surpassed handshakes as the coolest greeting. More importantly, they discuss cyber workforce development and why right now may be the best time for new workers to join the industry.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Winn Schwartau is a security, privacy, infowar, and cyber-terrorism expert who has been paving the way in cybersecurity since 1983. He is often referred to as the “Civilian Architect of Information Warfare” and is known for his straight-shooting, no-BS originality. In this episode, Winn joins the No Password Required team to talk about how he went from the world of rock-and-roll to cybersecurity, times when he pissed off the CIA, and why Louis Armstrong wasn't the best teacher he ever had (you read that right!) Ernie, Clabby, and Pablo talk about the reality of cybersecurity policies and employee training. In the Positively Cyber segment, Pablo introduces Snoop Dogg as the Dark Net Intelligence Analyst of our fictitious organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Charity Wright is a Cyber Threat Intelligence Analyst at Recorded Future who specializes in Chinese threats and disinformation. Charity is a Super Mario-loving extrovert who utilizes her research and inferencing skills in both of her full-time jobs; threat analyst and mom. Charity is a Chinese Linguist who often spends her workdays scrolling through social media searching for trolls and Chinese disinformation/propaganda. In this episode, Charity joins the No Password Required team to talk about how she came to be a linguist in the U.S. military, possibilities of where China will go in the future, and why curiosity has been one of the most essential aspects of her career. Ernie, Clabby, and Pablo talk about Clabby’s “Yahoo! news rule” and the channels they use to stay informed in the ever-changing cyber industry. In the Positively Cyber segment, Pablo introduces the sophisticated, yet mysterious, Jay Gatsby as the Chief Financial Officer of our fictitious cybersecurity organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Dr. Greg Hall is a Research Scientist at the Institute for Human-Machine Cognition and the University of West Florida. Dr. Hall is a Corvette-driving car lover who considers ALF to be one of the classics and has great taste in hats. He also does research in full-spectrum cyber operations and contributes to the Florida Cyber Range, a digital platform that provides training and testing solutions for academic, government, military, and industry. In this episode, Dr. Hall joins the No Password Required team to discuss his research in full-spectrum cyber operations, why the sit-and-spin has made a place in history as the best (and possibly most dangerous) childhood toy, and more. Ernie, Clabby, and Pablo discuss the government’s Rewards for Justice Program and the new $10 million reward for information. In the “Positively Cyber” segment, Pablo challenges Clabby by welcoming Harvey Specter to our fictitious cybersecurity organization as a Privacy and Cybersecurity Lawyer.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Dan Burke is the Cyber Practice Leader at Woodruff Sawyer, one of the largest insurance brokerage and consulting firms in the US. Dan is a natural optimist and family man who believes every day is going to be the best day and the next shot will always be his greatest golf shot. In this episode, Dan joins the No Password Required team to talk about his personal connection to Colby-jack cheese, the most misunderstood things about cyber risk and insurance, and his bucket-list golfing spots. Ernie, Clabby, and Pablo discuss the recent Colonial Pipeline/Bitdefender controversy and the pros and cons of publicizing intelligence that could help ransomware victims. In the “Positively Cyber” segment, Pablo introduces the iconic Winston Wolfe to our fictitious cybersecurity organization as a Data Loss Prevention freelancer.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Phillip Tarrant is the SOC Technical Manager at Compuquip Cybersecurity who is passionate about many things in life, including his pet chickens, building things both with and without a keyboard, disconnecting in nature, and welcoming people into the field of cybersecurity. In this episode, Phillip joins the No Password Required team to talk about his unique journey into the field of cybersecurity, why chicken diapers are crossing the line, why the Empire is in serious need of some data protection policies, and more. Ernie, Clabby, and Pablo discuss the presidential administration’s new cybersecurity initiatives in response to the SolarWinds attack and what they mean for the future. In the “Positively Cyber” segment, Pablo compares two members of the Mystery Incorporated gang and analyzes whether Scooby-Doo or Velma would be the better fit for our fictitious cybersecurity organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Rachel Tobac is the CEO and co-founder of Social Proof Security who hopes to one day work herself out of a job by improving education and awareness of social engineering attacks. In this episode, Rachel joins the No Password Required team to talk about her path from studying behavioral psychology to starting a successful cybersecurity company, why shih tzus would be the best canine cybersecurity professional, how her quirky skills serve as an asset to her company, her passion for improving diversity in the cyber and technology industries, and more. BONUS: she sings an info-sec sea shanty that is as catchy as it is informative. Clabby and Ernie talk about the recent hack on the Molson Coors Beverage Company, and in the “Positively Cyber” segment, Pablo analyzes why the Mandalorian would be the perfect fit for showing our new recruits “the way” in our fictitious cybersecurity organization. You should check this episode out soon; if Rachel is correct about the time travel butterfly effect, you may never get another chance...

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Roger Grimes is the defense-driven evangelist at KnowBe4 who confidently defines himself as the best in the world at defending against hackers. In this episode, Roger joins the No Password Required team to discuss how being a terrible accountant led him to the world of cybersecurity, why octopi cannot be trusted, and why music is the best way to create powerful connections. Additionally, Clabby and Pablo discuss insights from the National Security Agency’s 2020 cybersecurity year in review. In the “Positively Cyber” segment, Pablo analyzes why Hermione Granger’s work ethic and determination would make her the perfect fit for Senior Director of Threat Intelligence in our fictitious cybersecurity organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Shane Young is a penetration tester at Rapid7 whose real-life acting and cyber skills would have been a great addition to the “Oceans 11” team. In this episode, Shane joins the No Password Required team to share some of his exciting stories as a penetration tester, how hacking his high school's network got him into the world of cybersecurity, and why LEGO bricks are really made for adults, not kids. Additionally, Shane, Ernie, and Clabby discuss The Mandalorian and the Star Wars universe (no spoilers!) Clabby and Ernie explore the controversial GoDaddy phishing campaign and the ethical ramifications of company phishing tests. In the “Positively Cyber” segment, Pablo Torres analyzes why Mulan has the skills and dedication to be a savvy network defender in our fictitious cybersecurity organization.

LEGO® is a trademark of the LEGO Group of companies, which doesn't sponsor, authorize, or endorse this podcast.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Melinda Lemke is the Head of Information Security at King & Spalding with a decade of leadership experience in the cyber industry. In this episode, Melinda joins the No Password Required team to talk about her experience as a woman and leader in this field, how professional mentors can enhance success, and the best yacht-rock bands of all time. Maybe most importantly, the team discusses the John Hughes movie universe and why Kevin McAllister is a better problem-solver than Ferris Bueller. Additionally, Ernie and Clabby explore the importance of password security and real-world ransomware attacks, including the ransomware attacks on Miami-Dade county schools. In the “Positively Cyber” segment, Pablo Torres explores the reasons why John Wick would be the perfect candidate for an elite penetration-tester position in our fictitious cybersecurity organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

Stephen “Scuba” Gary is a cyber intelligence professor at the University of South Florida with over 15 years of experience in the cybersecurity industry. In this episode, Scuba joins the No Password Required team to discuss his journey in the field of cybersecurity, how one gets the nickname Scuba without scuba diving, and why math nerds throw the best parties. Scuba, Ernie, and Clabby analyze ransomware attacks in Florida, security lessons to be learned from the 2020 elections, and more. In the “Positively Cyber” segment, Pablo Torres explores why Peter Quill, aka the Star Lord, aka the leader of the Guardians of the Galaxy, would be a perfect fit for Chief Technology Officer in a fictitious cybersecurity organization.

Follow us on Facebook, Instagram, Twitter and LinkedIn | @NoPasswordPod

View Details

With the rise of cybercrime comes the need for cyber forensics, and this episode’s guest, Dr. LeGrande Gardner has been in the field of digital evidence for more than 30 years. Currently, he is an instructor in the Criminology Department at the University of South Florida, where he also serves as the Director of the MS in Cybercrime degree program and administrates the Graduate Certificate Program in Digital Forensics.  

Co-hosts Bill McQueen and Ernie Ferraresso joined Dr. Gardner for a discussion about digital evidence, its role in the justice community, and opportunities for the future. The field of cyber forensics started rather simply, as a way to detect and connect the pieces of a crime.  As evidence was being submitted into the justice system, a need for increased scientific methodologies and protocols grew to preserve legal integrity and the rights of the accused.  

Cyber forensic professionals are able to examine a range of devices, networks--even the cloud--to uncover criminal activity and gather evidence that can lead to legal prosecution. Dr. Gardner discusses how advances in computer science have made an impact in the ability to locate criminals. In his first example, he shares how hash algorithms are used to catch pedophiles and provide a digital footprint to catch larger pedophile rings. Next, he details the Target breach, where criminals were able to hack the nationwide retailer via their air conditioning’s computerized system. Then, he talks about how search warrants involving cybercrime uncovered how criminals were using their neighbor’s open IP addresses, putting routers unknowingly in their attics, and other deviousness that thwarted detection and capture. Unfortunately, Dr. Gardner reveals, international criminals are even more elusive, but that having solid cyber forensics can help law enforcement agencies from multiple countries coordinate efforts.

Cyber forensics now has several sub-specialties, such as cloud forensics, network forensics, malware forensics, IoT forensics, and vehicle forensics.  Many colleges and universities are developing programs and training around these expanding and evolving sub-specialties. Dr. Gardner points out that this is a great time to be a cybercriminal and there will be an increased need for cyber forensic technicians and digital evidence specialists to combat the widespread crime.  

There is a push for law enforcement officers to receive training in cyber forensics to facilitate crime scene collections, recognize patterns, and maintain protocols.  Dr. Gardner’s history in law enforcement and as a Task Force Agent with the FBI’s Cyber Crime Unit gave him a special insight to device and data collection at crime scenes and he shares his thoughts on training opportunities in police academies.  

Hackers and cyber criminals aren’t the only reasons the field of cyber forensics is growing.  Corporations are also employing their own forensic teams. Companies use digital evidence to substantiate their security and to protect themselves if a situation with an employee requires documentation.  Civil matters are increasingly including digital evidence, and professionals are being called upon to provide expert testimony.

The need for cyber forensics professionals is growing exponentially, according to Dr. Gardner. There is no end in sight for the potential of this field and the importance it will play in protecting our security and stopping crime.

TIME STAMPS

00:43  Meet Our New Co-host: Ernie Ferraresso, Associate Program Director of Cyber Florida

02:43 Who is Dr. LeGrande Gardner, Director of the MS in Cybercrime Degree Program, University of South Florida

03:15  What is Cyber Forensics and Digital Evidence?

04:47  Recognizing the field of Cyber Forensics

05:59  Following the Rules of Evidence and Procedure

06:33  The Growing Impact of Digital Evidence and Digital Exploitation  

07:35  Evolving Field of Cyber Forensic Careers

08:58  Collecting Cyber Forensic Data  

09:51  Digital Evidence as a Science

12:52 Components of Digital Evidence

13:45 Hash Algorithms, Digital DNA

14:25 Child Pornography Hash Algorithms

14:55  Hash Algorithms are like Fingerprints  

16:37  Verifying and Preserving Digital Evidence Using Scientific Protocols

18:29  Training to be a Cyber Forensic Technician or Specialists

21:34  Specialized Cyber Forensic Fields

24:01 Criminals, Digital Evidence & Law Enforcement

26:30 Training Law Enforcement for Digital Evidence Collection

28:24 Finding Breaches and Identifying Vulnerabilities

31:00 How to Start a Cyber Forensic Investigation

31:29 Cyber Forensic Incident Response

34:38  Cyber Police of the Future

35:35  Trends in Cyber Forensic Prosecutions

37:05 International Cyber Criminals and Cyber Forensics

38:19 Every Cop as a Cyber Cop

38:39 How is Cybercrime Changing  

41:26 The Future of the Cyber Forensic Field

42:24  Corporate Digital Forensic Units and Civil Courts

44:43  Cyber Forensic Academics, Digital Certifications and Careers

View Details

Kerry Long’s role at IARPA is to make the Intelligence Community more secure in the tech world. His vision of the future of cloud computing is to fundamentally change the way we use computers to be more secure. His hope is to redesign how all of us interact with computers to get ahead of hackers and breaches. His program, VirtUE, will soon be released to the world as open source code to promote cloud security and ingenuity. He also philosophizes about what cyber space really means as the only truly human-created domain.

When asked what is the most critical aspect of cloud security, Mr. Long answered, “Depending on users to secure their environment.” The current shared service model has cloud hosts providing a hypervisor (or virtual machine monitor [VMM]) and physical security of the data center while the user is responsible for their own data security. Most users are not security experts and they shouldn’t be, as Long argues that the cloud providers need to take on more security responsibilities. He points out that small-to-medium-sized businesses rarely have adequate IT resources to properly secure their own servers and, therefore, the cloud is a much more secure option because of hypervisors and other systems being updated nearly every day.

Long goes on to detail how we build things without knowing the ramifications because engineers can’t fathom every possible way a user would or could use it. The problem with pre-cloud computing is that we were stuck with those decisions for decades. “What I love about the cloud is it constantly gives you a chance to do-over.The cloud is anything that we want it to be. The cloud providers change out their infrastructure every 18 months to two years with brand new hardware. They are innovating and adding new things every week, every two weeks, and taking things out that don’t work. It’s an amazing opportunity as an engineer to say ‘hey, actually I thought I was smart, but I’m smarter now.’

VirtUE (Virtuous User Environment) is an IARPA program managed by Mr. Kerry Long that is an example of using the cloud and re-engineering it to be more secure for tomorrow. Traditional memory computers are running too many roles at once while in comparison cloud computing can separate roles. VirtUE is trying to engineer ways to make the separate environments function seamlessly for users while maintaining the security. This program is coming to an end soon, and will be released as open source code for the world to examine and work on.

VirtUE is related to SCITE (Scientific advances to Continuous Insider Threat Evaluation)

Link to IARPA: www.iarpa.gov IARPA facilitates the transition of research results to their Intelligence Community customers for operational application.

Link to IARPA profile for Kerry Long: https://www.iarpa.gov/index.php/20-program-managers

Mr. Kerry Long’s Research Areas at IARPA: Cloud security, evolving security using the technologies of the Cloud, hypervisor security and instrumentation, novel operating system monitoring techniques, malicious cyber behavior detection analytics, edge computing

TIME STAMPS

00:07 Cloud Computing

01:11 Who is Kerry Long, IARPA, Cybersecurity

02:00 Mission of IARPA

02:45 Cloud Security and Potential of Cloud Computing

03:59 Getting Ahead of Security Breaches

05:35 What is the most critical aspect of cloud security?

07:11 Cloud security options for businesses and individuals

09:58 What data is at risk of being stolen?

12:38 Cyber Engineering

13:50 Cloud Engineering & Infrastructure

15:18 What is a VirtUE – Virtuous User Environment?

18:59 How Safe is our Cyber Community?

21:00 Redesigning Computing with the Cloud

23:22 The Future of Computing

24:18 VirtUE as Open Source

View Details

This is part two of a two-part special edition that was recorded at the 2019 Cyber Florida Conference. In the first part, a panel of cybersecurity experts discussed “Cybersecurity and the C-Suite,” while the second part discusses partnerships and opportunities that bridge the gap for qualified cybersecurity personnel and our interconnected cyber ecosystem. The panel was moderated by Sprint’s Chief Information Security Officer Mark Clancy. On the panel sat three cybersecurity professionals who have years of expertise: Diane Janosek, Commandant of NSA's National Cryptologic School; Andy Zolper, SVP, CISO, and Head of Technology at Raymond James Financial; and Terry Roberts, CEO and Founder of WhiteHawk, Inc. (To learn more about Janosek, Zolper, and Roberts, listen to the The No Password Required Podcast episode titled “Cybersecurity in the C-Suite.”)

This No Password Required episode began with the question, “What can the big guy do to help the small guy?” and panelists discussed the role of large corporations and technology service providers. Often small-to-mid-sized organizations are understaffed when it comes to their IT department and/or they are solely reliant on external providers for their security. Many larger organizations and service providers are making the investment to provide advanced security protocols because it impacts their products and, for some, it gives them a competitive edge in the marketplace. Larger corporations and service providers are carrying the responsibility of protecting smaller organizations, but it is a symbiotic relationship. Smaller organizations must do their part to have good cyber hygiene and understand their risks and their roles in preventing those risks.

Motivating smaller organizations to have a proactive cyber culture is often dependent on two things: communication and risk. A panelist emphasizes that the success of motivation revolves around language. The key to communicating with C-level executives and business stakeholders is to provide information as it relates to them, using their industry-specific lingo, demonstrating their profit and loss potentials, and illustrating how it impacts their community. By answering “how can we partner in a way that shows that we want to mitigate risks to a point that we’re a stronger business partner” can solve some of the gaps in cybersecurity. “Don’t wait for someone to offer, ask,” is the advice of Andy Zolper when it comes to mitigating risks.

Mark Clancy asked the panel, “How do you cyberize the CEO?” Cyberizing the CEO often begins with a review of their cybersecurity risk profile. By mapping risks to reputation and quantifying revenue to business impact can be the necessary wake-up call. “Cyberizing” was a phrase coined in part 1 of this series that is interpreted as educating/training C-level professionals to understand their company’s tech, their role in cybersecurity and operations, and their leadership in corporate cyber culture. “Cyberizing” encourages insight that helps build an adequate IT team or relationship with technology service providers. Cyberizing naturally encourages investing in employees as the greatest assets. It holds the belief that employees are responsible for maintaining good cyber hygiene, managing customer and partner relationships, and evolving with technology.

Another solution offered is “cyberizing the principal.” This involves instilling the value of cybersecurity as soon as a child is handed technology. One panelist advocates for developing educational programs that incorporate cybersecurity in programs from elementary to college, with her belief that it will carryover good cyber hygiene from the home to the public and business sectors.

Another component of closing the cybersecurity personnel gap is by encouraging information sharing in new ways, as well as, encouraging IT professionals to transition through various sectors and educational opportunities to keep their experience fresh and relevant. The panel discussed some of the current issues and possible solutions that involve sharing information, the importance of nonprofit interlocutors, the problem with classified versus unclassified information sharing, zero trust, and more. The cybersecurity experts also discussed educational opportunities, crossover through sectors and the role of leveraging academia and cyber labs to find solutions.

In the final segment of the podcast, the guests discuss some of the highlights of the 2019 Cyber Florida Conference and list topics that they would like explored at the future conferences.

You can find part 1 and 2, as well as other episodes of No Password Required Podcast, on our website at https://cyberflorida.org/podcast/. This special edition was recorded at the 2019 Cyber Florida Conference in Tampa, Florida. Learn about upcoming Cyber Florida events, including the Annual Conference, at cyberflorida.org or follow us on social media.

TIME STAMPS

01:30 Partnering Competitively & Cyber Ecosystem

07:17 Cyberizing the CEO

10:43 Cyberizing the Principal

13:48 Public-Private Partnerships

15:51 Nonprofit Interlocutor & Scaling Partnerships

17:32 Collaborating for Information Sharing

19:00 Zero Trust

24:42 Classified vs Unclassified Sharing

25:30 Surprises from the Cyber Florida Conference

View Details

During Cyber Florida Conference 2019, a panel of respected cybersecurity experts gathered to share their insights on how cybersecurity impacts the C-level professional, changes in accountability and business models, and what it means to build a cyber-strong workforce. The panel was moderated by Mark Clancy, Chief Information Security Officer (CISO) for Sprint. The esteemed guests on the panel were Diane Janosek, NSA Commandant of the National Cryptologic School; Andy Zolper, SVP, CISO, and Head of Technology Infrastructure for Raymond James Financial; and Terry Roberts, Founder and President of WhiteHawk, Inc.

C-level professionals have been a driving force in developing business and securing infrastructures. Recent breaches resulting in CEO firings and similar repercussions are impacting the way many C-level leaders are engaging with technology and their workforce’s cyber culture. Cyber Florida took the opportunity at the conference to help both the C-level professionals and stakeholders who are part of their decision-making process with a discussion titled “Cybersecurity and the C-Suite.” The panelists discussed why it is vital for C-level executives to embrace cybersecurity education and innovation. The experts spoke to what factors C-level leadership face in their organization and workforce in relation to security, networking, and data fundamentals. A large portion of the conversation focused on identifying what it takes to onboard a workforce in this computer-centric modern life (with the phrase “cyberize” being coined to discuss the process), and understanding the crossover that is occurring because of the inter-connectivity of roles and risks.

Panelists discussed case studies and resources, such as cyber executive programs, where C-level professionals can:

  • learn the basics of cybersecurity,
  • embrace accountability at the C-level,
  • identify the risks and opportunities of current infrastructure and future tech,
  • learn how certain business models are changing as a response to technology,
  • establish pillars for a robust cyber culture,
  • understand independent cyber risk ratings as a commodity,
  • develop a cyber-strong workforce, and
  • create a constructive response plan to cybersecurity attacks and cybercrimes.

This is a two-part edition with the second part discussing the personnel gap in cybersecurity and what can be done about it. You can find parts 1 and 2, as well as other episodes of No Password Required podcast, on our website at https://cyberflorida.org/podcast/. This special edition was recorded at Cyber Florida Conference 2019 in Tampa, Florida. Learn about upcoming Cyber Florida events, including the annual conference, at cyberflorida.org or follow us on social media.

TIME STAMPS

00:42 Who is Diane Janosek, Cybersecurity Expert, Cyber Security Woman of the Year

02:03 Who is Andy Zolper, CISO at Raymond James Financial

02:45 Who is Terry Roberts, Cybersecurity Exchange

03:58 How to Communicate Cybersecurity to Leadership

07:25 C-Level Accountability, Cyber Risk Ratings are a Commodity, Cyber Executive Program

09:53 Hiring a Cybersecurity Workforce and Training a Cybersecurity Culture

15:55 Innovation in Education for Cybersecurity and Cyber Risk Training

18:50 Identifying, Leading and Managing Critical Skills

21:54 Cyberize Your Team, Workforce Crossovers, and Cyber Defense Ecosystem

26:07 Business Interruption and Constructive Actions to Address Cyber Crimes

27:35 Cyber Executive Programs and Case Management

View Details

Cyber threat intelligence is a conceptual term with an international impact. Agencies around the world are racing to identify and stop cybercriminals from infecting and infiltrating networks to use our data against us. In this episode of No Password Required, Dr. Sagar Samtani, assistant professor of information systems and decision sciences at the University of South Florida, explains the cyber threat intelligence (CTI) life cycle and what you and/or your organization should do to help protect data assets and prevent cyberattacks.

Data is the prime target of many cybercriminals, yet what data they are searching depends on their goals. Are they scraping for social security numbers? Obtaining passwords? Collecting credit card numbers? Or worse? And why? It’s hard to imagine all the ways that data can be exploited.

Your data is widely available depending on where and how you store your data and whom you give permission to access that information. Personal choices, like having a smartphone, can be a gateway to someone collecting your data. Being on the grid with a social security number, health insurance, financial accounts, all these bits of information are housed somewhere, and cybercriminals know this. With the help of artificial intelligence (AI), cybercriminals are able to scrape data faster than ever before and with the launch of quantum machines, our security choices will be paramount to protecting our identity and data assets.

Cyber threat intelligence is helping individuals and industries protect themselves by understanding what is important, what are the exploits, and how to effectively respond. It is also helping to refine artificial intelligence algorithms to better assist in threat analytics. Dr. Samtani describes how industries are responding to industry-specific cybercrimes and developing response standards, protocols, and frameworks. He gives the example of the healthcare industry and HIPAA compliance as well as financial institutions and their evolving PCI compliance protocols. Understanding why a data asset is a target is a key facet to the cyber threat intelligence life cycle.

What are the Four Phases of Cyber Threat Intelligence?

  1. Identify what assets you (an organization) possess that hold value, e.g., a social security number, and how to protect those assets
  2. Data collection that is relevant to those critical cyber assets
  3. Threat analytics – whether traditional or AI techniques are being utilized
  4. Operational Intelligence – how is the compromised data actually used or exploited

Dr. Samtani explains there are two basic types of cyber threat intelligence analytics. First are the traditional threats, such as malware analysis. The second category is quickly changing as artificial intelligence evolves: data mining, text mining, and natural language processing based on pattern and techniques. Building systems that are designed to log and report data is crucial to discovering breaches and reporting them to prevent further penetration.

Once Data is Stolen, Where Does it Go?

Dr. Samtani discusses how hackers, cybercriminals, even geopolitical threat actors are using the data. He explains how the Dark Web is playing a role as a marketplace and toolbox for hackers. He details the four basic platforms--forums, Dark Web marketplaces, darknet carding shops, and internet relay chat--that cybercriminals use to complete their tasks and possibly grow their notoriety. Hacker behavior on the Dark Web is unlike traditional crime circuits where anonymity is preferred. There are tiers of hacker and they can use their screen names to build their reputation for monetization, credibility, and recognition. Artificial intelligence is being fine-tuned to help detect cybercriminals through intelligent predictions.

Security Protocols and the Danger of Oversharing

Individuals, organizations, developers, and even marketers play a role in security. Developers who were once tasked in racing product to market are now evolving to build-in and protect against exploits. Cultures are changing to bring awareness of the dangers of oversharing and learning from other’s breaches and incidents. Dr. Samtani and No Password Required host Bill McQueen discuss how oversharing can be as simple as a phone call asking what version a software is on and divulging that information, likening that to handing over the keys to a car.

The Study of Cybersecurity Science

As computing evolves, so do the crimes; the cybersecurity field is in the infancy of where it will be potentially. Developing talented professionals to stop cybercriminals, building frameworks and protocols, and advocating for strong cyber cultures at home and in the workplace will be essential to the future. There is ample opportunity for employment and research in the field of cybersecurity, cyber threat research, and cyber threat intelligence.

TIME STAMPS

1:12 Who is Dr. Sagar Samtani

1:30 How Does AI Automate Cybercrime and Cyber Threat Intelligence

3:08 The Four Phases of the Cyber Threat Intelligence Life Cycle

7:43 How Do You Rate and Respond to a Cyber Threat

10:03 Industry Specific Frameworks for Threat Identification and Mitigation

10:24 Data Characteristics in Cybersecurity

11:20 Defcon and AI Village

11:48 Tuning Algorithms for Cybersecurity

12:54 How are Hackers Fighting Against AI Detection

13:53 Developing Organizational Strategies to Counter Cybercrime

15:19 Cybersecurity/AI Ethics and Rules

18:40 Dark Web & Data

19:38 Dark Web Platforms

22:53 Access to Dark Web Platforms

23:50 Hacker Notoriety – Reputation, Monetization and Detection

27:40 Developers & Cyber Security Protocols

29:35 Double-Edged Sword of Sharing Cybersecurity Capabilities

30:40 Operational Intelligence and Risk Management

31:58 Hacker Behavior on the Dark Web/Darknet

33:40 What Can We Do to Protect Ourselves? Following the CTI Lifecycle

35:44 Cybersecurity Science as a Legitimate Field

View Details

Each year, businesses are losing $12-$13 billion dollars because of cybercrime. One criminal tool is called the Business E-mail Compromise (BEC), aka “The Man in the Middle Attack.” It begins when criminals use information, like that readily found on social media platforms, to target an employee. The criminal may phone or email the employee, gain their trust, steal their identity, compromise and access their emails and the business network (including human resources, banking and client accounts) and so on, all for the ultimate goal of stealing large sums of money.

In this podcast, Stacy Arruda, a cybersecurity threat specialist, provides insight on how individuals and businesses can better protect themselves against cybercriminals and take steps to prevent criminals from stealing their money or exploitation them in other ways. BECs have seen a 1300% increase since 2015, and, as Arruda says, “it’s no longer a question of 'if,' it’s 'when,' and not just 'when' but when you discover that the bad guys are inside your network.” Businesses have options and they begin with training employees and reporting problems quickly. Having a strong corporate culture that trains employees about proper handling of emails, account security, personal information, and reporting can make a tremendous difference.

Stacy Arruda is a former FBI supervisory special agent with more than 20 years of experience in cybersecurity and counterintelligence.She is the CEO of the ARRUDA Group, a cyber threat consultancy firm, and the Executive Director of the not-for-profit Florida Information Sharing and Analysis Organization (FL-ISAO).

Stacy details how cyber criminals use social media to profile potential victims, building trust to gain access to networks. Anyone can be a target, and cybercriminals do their homework by connecting the dots to gain access to large payouts.

Arruda notes that women, in particular, seem to overshare information on social media, nearly every aspect of their lives, and it’s a problem. As an educator and speaker, Arruda speaks on how women can better safeguard their information, warning that online activity can escalate to physical threats and exploitation.

Children can also be targeted. Predators can use simple techniques to lure information from children and they can cross-reference social media to gain information about the family. Gaining a real name online can have a criminal scrolling a family’s social media profile and readily finding things like an email, place of work, child’s school, and after-school activities. Monitoring a child’s online activity and restricting shared information is important to the entire family’s safety.

The business email compromise,(BEC), also known as “The Man in the Middle Attack,” is a cybersecurity scam that is typically short-lived and aimed at stealing information and money. “Once they send that email, and you click on that email, the bad guy has a lot of avenues that they can go down. Once they're sitting on the network, they can steal data, they can introduce ransomware and shut down the network. They can sit on the computers and they can wait for invoices to come in and wait for payments and steal money,” states Arruda.

Well-organized criminals, terrorists and spies use the information that is innocuously shared by us to gain our trust so that they can:

  • Target email attacks
  • Access compromised emails and files anywhere on the network
  • Access human resources
  • Access business accounts, such as banking
  • Disguise themselves as business representatives
  • Disguise themselves as clients
  • Authorize wire transfers to accounts all over the world
  • Change account routing information in a record or during a transaction

Arruda recommends that companies should have security drills, much like fire drills, to implement a response plan and reinforce the company’s culture on security.

The FBI has a unit called the Recovery Asset Team, where companies can report a compromise for the possibility of freezing accounts to stop the wire transfer. Time is of the essence relative to how quickly a bank will process a wire transfer; two weeks is far too long, and the money will likely be unrecoverable.

SOME KEY POINTS:

Security is often a failure because of two factors:

  • Human error, such as misconfiguring software, oversharing information, lack of training on how to spot and report criminal activity, and
  • Convenience, such as not taking the time to update system patches, using multifactor authentication, and using our own records to contact clients versus using information found in their email.

For the individual, Arruda shares that human error and oversharing can be the gateway to being compromised. Having system patches up-to-date, strong passwords, and reducing one’s cyber footprint, such as oversharing personal details or falling for scams because they know our likes and dislikes, can be key to preventing cybersecurity threats at home.

Defense-in-Depth is a tactic that individuals can use to protect themselves. Having our systems patched, running a firewall, running antivirus software scans, using strong passwords are examples of how an individual or business can add layers of defense against cyber criminals.

An untrained employee is a liability and changing company culture to encourage calls to higher-ups to confirm requested transactions is a must.

BEC - 1300% increase since 2015, and it’s getting worse because “it’s an easy way for criminals to make a lot of money quickly” and defense-in-depth is one way to hinder BEC criminals.

Posting on the internet so openly, especially on social media, is creating opportunities for criminals to target and manipulate individuals. Controlling your footprint on the internet is vital, and being elusive may discourage a criminal from targeting someone.

Businesses can also add a layer of protection by not sharing/oversharing personal information about their employees, such as the CEO is married to so-and-so and their children’s names are Tom, Becky, and Mike and their ages. Criminals profile and store this information, and this creates unnecessary risk.

The FL-ISAO, which helps to build cyber resilience for the state of Florida, has an agreement with the Department of Homeland Security to encourage removing the corporate stigma of sharing information to prevent data breaches, hacking, cyber incidents, cyberattacks, and other cybercrimes. Trends show that reporting to the Internet Crime Complaint Center has increased and more and more victims are willingly coming forward. While this is critical, more can be done so the FL-ISAO is expanding to provide training, tips and business support to prevent cybercrimes. Organizations can contact Arruda via www.flisao.org or via email at info@arrudagroup.com

TIME STAMPS

1:00 About Stacy Arruda, Cybersecurity Expert

1: 38 Oversharing on Social Media Can Compromise Your Security

2: 51 Using Email to Breach Your Network

6:41 Reporting Cyber Incidents & Breaches – Time Matters

7:14 Using Defense-In-Depth to Stop Cyber Crimes

9: 11 How Convenience Can Cost Billions

9:50 Human Error: A Major Factor in Cybercrime

12:41 BEC Crimes

19:00 Cybercrime Rings Stole $11 Million

21:28 Victims, Including Businesses, Should Break the Silence

22:26 Building a Corporate Cyber Culture to Stop Data Breaches & Cyber Crimes

27:08 Women: Targets of Cyber Crime

30:22 Cybercriminals Targeting Children

35:52 Florida Information Sharing and Analysis Organization (FL-ISAO)

View Details

From wearables, cellphones, and thermostats to point-of-sale systems, clouds, and critical infrastructure, our world is connected. We’re part of the Internet of Things (IoT) at work, at home, even in our cars and, of course, in our pockets. There are more than 27 billion devices in the world that connect in some way to the internet, and each of those items pose an access threat. Cybersecurity experts like Ed Cabrera, the Chief Cybersecurity Officer for Trend Micro and former Secret Service officer and National Cybersecurity and Communications Integration/Homeland Security advisor, are identifying how data breaches happen and what can be done to prevent them. Ed investigates technology from every aspect, from hotspots to artificial intelligence and machine learning.

More Than Your Computer Is At Risk

Vulnerabilities are all around:

  • simple connectivity through a wireless fish tank thermostat was all that was needed to access the enterprise system of a casino,
  • the Mirai botnet attack targets networked devices, such as home routers and IP cameras,
  • the apps we download,
  • the patches we forget, and
  • the sources we trust all matter.

Traditionally, risk management for connectivity wasn’t first and foremost in a designer’s mind but increasingly companies’ reputations and responsibilities are being questioned and impacted by product breaches. This is affecting the way leadership and designers approach their products.

Cabrera suggests that we use the same diligence that we protect our businesses should be applied to our personal lives. Consumers need to investigate if devices that they bring into their home, like Amazon's Alexa, smart TV’s and IP cameras, even printers and smart home services, are subject to threats and what manufacturers are doing to prevent breaches.

Corporate Culture & Cyber Education

The evolution of cybersecurity is also changing the executive level of companies. Chief Security Officers and IT managers are keystones in understanding what their developers and researchers are finding and relaying that information to other executives and board members. Cabrera says that CSO’s need to be Chief Translating Officers to ensure decision makers understand the threats and how to prevent them.

Businesses also play a role in growing the cyber community and closing the personnel gap. There is large gap between currently taught IT and engineering skills and those needed for machine learning and AI. This gap is causing a shortage, and Cabrera estimates that there are 300,000 openings nationally right now in the cybersecurity industry. He advocates for apprenticeship models to foster a partnership between education and employment. The apprenticeship model also addresses the soft skills needed to be an integral part of a company.

These workers are needed as cybercriminals and nation-state actors are relying on automated crypto ransomware, cyberattacks, cyber manipulation, and identity theft. In 2016, automation helped cybercriminals attempt more than one billion attacks, but now criminals are being pickier to reap a larger reward. Organizations and governments of all sizes continue to be at risk.

What is an IoT? 02:52

Connectivity is the Door to Data Breaches 03:57

Digital Extortion 07:15

Corporate Culture 07:55

Examples of IoT Breaches 09:11

Machine Learning and AI Skill Gaps 11:34

Chief Translating Officer 14:25

Apprenticeship Models 17:22

Hacking Medical Records 22:37

Culture of Cybercriminals 24:34

Crypto Ransomware and Automation 26:25

View Details

Can a piece of dust on your touchscreen compromise your data? The answer is yes. We learn how from No Password Required Podcast guest Roger A. Grimes, KnowBe4’s data-driven defense evangelist, whose mission is to educate others about cybersecurity issues that can compromise computers. He shares two of the largest threats of cyberattacks impacting companies: social engineering and unpatched software. His simple advice for avoiding 99% of cyber risks: “Patch your stuff and don’t get tricked into doing something you shouldn’t; you do those two things and you will not get hacked.”

Roger is a prolific author, blogger and speaker. He shares his 30+ years of penetration testing/ethical hacking expertise with companies and tech professionals to improve their security and defend their network. In this interview, he talks about man-in-the-middle attacks and other social engineering scams that open doors for data breaches. He examines the lack of improvement in technical controls and the proliferation of adversaries and continuous daily malware attempts. Roger also discusses the future of computing with quantum supremacy on the horizon and the threat it poses to public key cryptography.

Topics in Order:

Who is Roger A. Grimes?

Hacking Isn’t That Hard

Is Misinformation Part of the Cybersecurity Problem

Anti-Virus and Firewalls Don’t Work - Close Your Computer Exploits by Patching Software

10 Ways I Can Hack You

Recognizing Red Flags of Social Engineering

Why is Hacking Still Such a Problem

How to Hack Passwords & Multi-factor Authentication

The Truth Behind Password Lengths and Password Policies

How to Never Be Hacked

Is that Dust or Hair on Your Touchscreen? Nope, it’s an Embedded Scam

What are the Two Biggest Cybersecurity Risks?

Have You Heard of this Scam? Security Awareness Training and Social Engineering

Creating a Cyber Culture for Your Employees through Security Awareness Training

The End of Classic Computing

Will Quantum Computers Launch in 2019? The Sprint for Quantum Supremacy

A Better Future with Quantum Models

The Downside of Quantum Computers: Breaking the Public Key Cryptography

The Coming Quantum Break

Post-Quantum Encryption and Susceptibility

Has the Quantum Crypto Break Already Happened?

Is Quantum Supremacy a Big Deal or the Next Y2K?

What is Crypto-Agility and Will it Matter with Quantum Computing?

Is Society Becoming Tolerant of Hacking and Cybercrime? Why and What Do We Do About It?