60 Episoden
- In this episode, Ashu Savani, co-founder of TryHackMe, explains how the company's Live Breach product puts teams inside fully-executed, realistic breach simulations built around the threat actors and tech stacks they face, building the reflexes and reporting security leaders need before a real incident hits. Joining him are Roland Toussaint, Senior Director of Incident Response and Security Engineering at ChenMed, and Heather Hinton, CISO at Sitecore.
Want to know:
How can a simulated environment realistically reflect a security team's actual tech stack and the threat actors they care about?
Can TryHackMe's reporting help security leaders prove upskilling progress to auditors and cyber insurance carriers?
How does TryHackMe help teams train for incidents caused by their own people, not just outside attackers?
How granular can training get: can a team run a meaningful exercise in just 15 to 20 minutes?
How are TryHackMe's custom exercises tiered and packaged across its plans?
What's TryHackMe's track record getting cyber insurance carriers to accept its exercises as sufficient proof of readiness?
Does TryHackMe offer anything built specifically around HIPAA for healthcare organizations?
Why is crisis communication often more under-rehearsed than technical response, and how does TryHackMe help teams practice it?
Check out the episode for the answers you need.
Huge thanks to our sponsor, TryHackMe
Live Breach challenges security teams to test their incident response against a rogue AI agent in a realistic, three-hour exercise. The campaign uses a compelling AI-driven attack scenario to create urgency, while highlighting the low-risk setup, actionable readiness insights and practical value of testing teams before a real incident occurs.
Business applicants only, 18+. Applications open 7 October 2026 and close 18 October 2026 at 23:59 EST time. Six companies are selected by a TryHackMe panel from eligible applications, against published criteria; each receives one complimentary simulated Live Breach exercise. No purchase necessary. Full terms: http://tryhackme.com/legal/live-breach-giveaway-terms - In this episode, Joseph Perla, founder and CEO at TrustedRouter, explains how his company's confidential-computing-based LLM router lets teams send prompts to hundreds of AI models while cryptographically verifying, rather than simply trusting, that no one, including TrustedRouter itself, can see the data passing through. Joining him are TC Niedzialkowski, former head of IT & security at Opendoor, and Keith McCartney, svp of security and IT at DNAnexus.
Want to know:
Why hasn't the AI privacy problem already been solved, given how many tools and architectures already exist?
What's wrong with the "zero data retention" promises most AI providers offer today?
How does a confidential virtual machine let a company verify, instead of just trust, that its own router isn't looking at its prompts?
For a use case like HIPAA-covered medical data, does TrustedRouter provide one complete, auditable path from a user's machine to the model and back?
How does remote attestation confirm end-to-end encryption down to the chip level?
Does TrustedRouter's SOC 2 Type 2 attestation cover the AI workload itself, or just its own SaaS interface?
Can customers restrict which data centers or jurisdictions their AI workloads run in?
What happens to a company's existing AI usage monitoring once it starts routing through TrustedRouter?
Check out the episode for the answers you need.
Huge thanks to our sponsor, TrustedRouter
TrustedRouter is the open-source AI gateway for teams that need privacy with proof. It routes hundreds of models through attested confidential compute, keeps prompts and outputs out of logs, verifies the code handling each request, and adds provider failover, spend controls, and OpenAI-compatible APIs for production AI systems. - In this episode, Dean Shroll, senior director of sales engineering at ThreatDown, explains how the company's Nebula and OneView consoles simplify protection across Mac, Linux, and Windows endpoints while its managed detection and response team absorbs the 24/7 monitoring that resource-constrained teams can't staff on their own. Joining him are Jonathan Waldrop, CISO at Acoustic, and Arif Hameed, CISO at C&R Software.
Want to know:
Why is managing security for resource-constrained organizations suddenly getting more attention?
How does ThreatDown keep its console simple without sacrificing depth across Windows, Mac, Linux, and cloud environments?
Where does ThreatDown draw the line between what it automates and what still needs a human analyst?
How does the platform distinguish suspicious behavior from normal DevOps activity without drowning teams in false positives?
What guardrails exist to stop overly broad exclusions from opening up a device?
Who owns what when an MDR provider is involved, and where does that responsibility actually end?
How should a CISO justify an MDR investment to the board when nothing bad happens?
Check out the episode for the answers you need.
Huge thanks to our sponsor, ThreatDown
ThreatDown delivers elite Managed Detection and Response purpose-built for resource-constrained teams with high-efficacy protection without complexity. Combining artificial intelligence and expert analyst judgment, ThreatDown intercepts sophisticated attacks with speed and accuracy, scaling security effortlessly. Recognized by MRG Effitas, AVLab, and G2, ditch fragmented tools for fast, 24/7 protection without overhead. - In this episode, Leo Taddeo, CEO and President at AppGate, explains how the company's zero trust network access platform cloaks internet-facing infrastructure from discovery, uses direct-routed architecture instead of cloud-routed hairpinning to avoid the latency tax, and layers in continuous, context-aware policy checks that go beyond device posture and MFA. Joining him are Ross Young, co-host of CISO Tradecraft, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program at Temple University.
Want to know:
Why does securing remote access remain one of the top attack vectors year after year?
How does AppGate's direct-routed architecture avoid the latency and throughput limits of cloud-routed competitors?
What happens to a user's access when the circumstances that justified it change, like a closed service ticket?
How does cloaking network infrastructure stop an adversary's reconnaissance before it starts?
What's the fallback when a controller hosted in a customer's own data center goes down?
How does AppGate defend against credential replay and man-in-the-middle attacks that bypass MFA entirely?
What does AppGate's per-user licensing model mean for organizations managing multiple devices and enclaves?
Check out the episode for the answers you need.
Huge thanks to our sponsor, AppGate
AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate safeguards enterprises and government agencies worldwide. Learn more at appgate.com. - In this episode, Sagar Batchu, CEO of Speakeasy, explains how the Speakeasy AI control plane lets organizations adopt AI everywhere and still prove it's governed — putting every agent, tool, and MCP server behind a single security layer that authenticates each action, enforces policy, and inspects every session for prompt injection and data exfiltration. Pressure-testing the approach are George Finney, CISO at The University of Texas System, and Nick Espinosa, host of The Deep Dive Radio Show.
Want to know:
Why is knowing what your AI agent can access still an unsolved problem, and how much of it traces back to the identity and data governance we never fixed for humans?
Should an AI agent ever be allowed to take an action no individual can fully understand, even when it's statistically more effective than the human alternative?
Where's the line between legitimate governance and surveillance, and how do you assure employees you're not building a panopticon?
Are there decisions and departments that should stay permanently in human hands, off-limits to agents entirely?
When an agent acts through a company's API and something goes wrong, who's actually responsible: the employee, the company, the model developer, the API provider, or the governance platform?
Could a control plane have flagged the week's biggest AI incident before it escalated?
Is adopting this really as simple as switching on enterprise settings and plugging in an API, whether you're an SMB or the Fortune 1?
What is "cognitive surrender," and why does Speakeasy's CEO think it's the one quality companies most need to protect?
Check out the episode for the answers you need.
A huge thanks to our sponsor, Speakeasy.
Speakeasy is the enterprise AI control plane. It governs every AI agent, tool, and MCP server from one place. Every connection is authenticated, every policy enforced, and every agentic action inspected and logged. So organizations can scale AI adoption with visibility and control.
Copy for below Banner: AI usage is outgrowing your enterprise controls. Speakeasy is the AI control plane that governs every agent, assistant, and MCP server from one layer. Each connection is authenticated, each policy enforced, and every action recorded. So you stay in control as AI adoption scales."
Weitere Nachrichten Podcasts
Trending Nachrichten Podcasts
Über Security You Should Know
What if you could get a no-nonsense look at security solutions in just 15 minutes? Security You Should Know, the latest podcast from the CISO Series, does just that.
Hosted by Rich Stroffolino, each episode brings together one security vendor and two security leaders to break down a real-world problem and the solution trying to fix it. Expect straight answers on:
How to explain the issue to your CEO
What the solution actually does (and doesn't do)
How the pricing model works
Then, our security leaders ask the tough questions to see what sets this vendor apart.
Subscribe now and and stay ahead of the latest security solutions. Visit CISOseries.com for more details.
Security You Should Know: Connecting security solutions with security leaders.
Podcast-WebsiteHöre Security You Should Know, Thema des Tages und viele andere Podcasts aus aller Welt mit der radio.at-App

Hol dir die kostenlose radio.at App
- Sender und Podcasts favorisieren
- Streamen via Wifi oder Bluetooth
- Unterstützt Carplay & Android Auto
- viele weitere App Funktionen
Hol dir die kostenlose radio.at App
- Sender und Podcasts favorisieren
- Streamen via Wifi oder Bluetooth
- Unterstützt Carplay & Android Auto
- viele weitere App Funktionen


Security You Should Know
Code scannen,
App laden,
loshören.
App laden,
loshören.
Security You Should Know: Zugehörige Podcasts


























