Real CyberSecurity

Follow Real CyberSecurity
Share on
Copy link to clipboard

The Real Cybersecurity Podcast decrypts the issues and business of technology security. But instead of just scaring you, these industry veterans provide real advice and analysis for organizations trying to make security real today. Hosted by Greg Young and Bill Malik.

Greg Young & Bill Malik


    • Dec 14, 2023 LATEST EPISODE
    • every other week NEW EPISODES
    • 38m AVG DURATION
    • 78 EPISODES


    Search for episodes from Real CyberSecurity with a specific topic:

    Latest episodes from Real CyberSecurity

    Ep. 73 - Breach Disclosure Laws, Water Treatment, Faraday, and Walking Around

    Play Episode Listen Later Dec 14, 2023 46:08


    Greg and Bill discuss how breach disclosure laws could play out while discussing the recent events around SUNBURST, water treatment as targets, and the critical CISO skill of just walking around and talking to people. 

    Ep. 72 - CISOs & the SEC, Cybersec Digital Fight Club, & Twitter

    Play Episode Listen Later Nov 17, 2023 48:23


    Bill reports that Mastodon lives on and how awful Twitter is, we talk about the SEC complaint re: the SolarWinds CISO, and Greg reports on his Digital Fight Club experience in Dallas (and how awesome it was)

    Episode 71 - Biggest Cybersecurity Tech & Idea Fails in 2023

    Play Episode Listen Later Oct 30, 2023 31:59


    Bill and Greg nominate their candidates for biggest fails in cybersecurity in 2023 - we focus on the ideas or technologies that were hyped and just didn't deliver.

    Ep. 70 - Election Security

    Play Episode Listen Later Oct 16, 2023 33:16


    Cybersecurity for elections is likely going to be hitting the news more often. Bill and Greg discuss the big picture issues of election security, why governments struggle with election security at all (spoiler: it isn't because technology isn't available), and a brief discussion of rural and small jurisdictions. Here's the link to the poll book systems graphic we discuss during the episode:https://www.cyber.gc.ca/en/guidance/security-considerations-electronic-poll-book-systems-itsm10101

    Ep. 69 - AI, Breaches, Splunk, and Bears, Oh My

    Play Episode Listen Later Oct 6, 2023 41:37


    An update of the state of AI cybersecurity (including the hype) and a roundup of noteworthy breaches in the news. Also our thoughts on Splunk.

    Ep. 68 - Posture Management in Cybersecurity - A Big Deal

    Play Episode Listen Later Sep 11, 2023 48:52


    This week Bill and Greg dig into posture management - not the chair - but the posture of assets, people, and identities and such. We discuss why infrastructure and operating system companies won't ever make best in breed security, and why infrastructure isn't self-defending.

    Ep. 67 - Guest Jeff Wheatman, GRC, 3rd Party Risk, & More Risk

    Play Episode Listen Later Sep 5, 2023 54:52


    Discussion on risk, GRC, and 3rd party risk with former Gartner analyst who is now with Black Kite. 

    Ep.66 - New SEC Cybersecurity Reporting Rules, & Jonathan Frakes

    Play Episode Listen Later Aug 8, 2023 45:52


    Greg covers the new SEC rules for disclosing cybersecurity incidents, and our celebrity reporter Bill has a brush with greatness in the personage of Jonathan Frakes. 

    Ep. 65 - National Cybersecurity Strategy, Startup FundingChallenges

    Play Episode Listen Later Jul 20, 2023 40:33


    This week in Real Cybersecurity we celebrate the 365 day countdown to Skynet, the Guidelines for the National Cybersecurity Strategy, startup funding challenges,  & recent hack news including Microsoft and Revolut.

    Ep. 64 - Interview with Dr Gene Spafford

    Play Episode Listen Later Jul 7, 2023 53:07


    A real treat for you today, as Bill brought in his friend Spaff for a great chat. One highlight was hearing about his newest book, Cybersecurity Myths and Misconceptions: Avoiding the Hazards and Pitfalls that Derail UsAmazon link to his new book: https://a.co/d/3SCd1nGhttps://en.wikipedia.org/wiki/Gene_Spafford

    Ep. 63 - Secrets, Policy, and AI & Black Swans

    Play Episode Listen Later Jun 28, 2023 49:55


    We discuss Bill's ugly luggage, how new entries to the cybersecurity job market are often exploited, lapsing CISSPs, what really happened around Y2K, the limitations of AI in risk management, and why declassifying in a cavalier manner is catastrophic.

    Ep. 62 - Listener Questions about AI

    Play Episode Listen Later Jun 21, 2023 39:11


    Bill and Greg answer listener questions about AI. And we didn't use ChatGPT for our answers. I think.

    Ep.61 - Report from RSA Conference, and Maritime Cybersecurity.

    Play Episode Listen Later May 2, 2023 38:20


    Our roving reporter Bill gives his impressions of the RSA Conference 2023, his talk on maritime cybersecurity he delivered just an hour before our recording. Greg asserts that without public-private partnership cybersecurity is hobbled vs the bad guys: but only if they each stay in their lanes.

    Ep. 60 - Cybersecurity of AI,& the Impact of a Bay Area Bank Collapse

    Play Episode Listen Later Apr 3, 2023 36:09


    Bill and Greg discuss the security aspects of AI, the 'black box' of AI is vulnerable to being manipulated or polluted, or having biases that aren't evident to subjects., how a Bay Area bank collapse will impact cybersecurity, and Bill's visit to CERIAS' anniversary with Gene Spafford. 

    Ep. 59 - Cyber Security Framework (CSF) & Ransomware Update

    Play Episode Listen Later Mar 13, 2023 41:40


    Bill updates us about the updates to the NIST CSF (Cyber Security Framework), and we talk about the state of ransomware. 

    Ep. 58 Securing FinTech, and a brief mention of AI, and ChatGPT

    Play Episode Listen Later Feb 13, 2023 38:04


    Greg and Bill dig into the unique cybersecurity needs of FinTech, and manage to keep blockchain mentions down to a few mentions. In the 2nd part some brief security impact of ChatGPT and AI. Bill has a great story about naming collisions.

    Ep. 57 - The Crypto Queen, Airline Cybersecurity, and Downsizing vs Skills Gap

    Play Episode Listen Later Jan 27, 2023 37:43


    Bill and Greg try and unravel where the Crypto-Queen has skedaddled to, how all airline IT and cybersecurity are not equal, and how downsizing hasn't made a dent in the cybersec skills gap and people shortage.

    Ep. 56 - Infragard, ChatGPT, Public-Private Partnerships, Russia

    Play Episode Listen Later Dec 19, 2022 41:15


    We cover a lot of recent cybersecurity news, including AI developments, Infragard and the cyberwar part of the Russian/Ukraine war, and why it is the new era of Public-Private Partnerships

    Ep. 55 - Recession Cuts in Cybersec? Trim Here...

    Play Episode Listen Later Dec 8, 2022 49:27


    Greg and Bill discuss options when faced with recession cuts. Cut shelfware, or a platform could be your best bet in getting rid of inefficiencies. Cuts in cybersec aren't a  common thing, but even so, getting rid of inefficacies and shelf ware is a great way to improve security.

    Ep. 54 - Cybersecurity Supply Chain, Secure Code Isn't Secure Forever

    Play Episode Listen Later Dec 5, 2022 46:53


    This week we talk about the issues in the wide-spread use of open source components, and what an attractive target that makes for the bad guys.

    Ep. 53 - Information Theory, Control Systems Vulnerabilities

    Play Episode Listen Later Nov 28, 2022 35:24


    Bill educates us on satellite and control systems vulnerabilities, and we go philosophical on information theory. Sorry about the sound on one channel.

    Ep. 52 - Zero Trust Status,Twitter Drama, and 5.5G?

    Play Episode Listen Later Nov 17, 2022 35:32


    This episode we answer the question "what is the state of zero trust?", and discuss the Twitter drama, Bill's recent talk in Santa Clara on automotive cybersecurity, and what the fudge is 5.5G (spoiler - not a real thing).

    Ep. 51 - Top 6 Cybersec Business & Tech Issues for 2023

    Play Episode Listen Later Oct 24, 2022 24:38


    Bill and Greg present their top 6 issues you'll likely come across in cybersecurity in 2023. 3 are business related, and 3 are techie.  

    Episode 50 - Lessons from the Uber Hack, and Machine Learning in Cybersecurity

    Play Episode Listen Later Sep 26, 2022 40:51


    Recent hacks of well known tech firms bring us some lessons learned. The biggest lesson is that creating a security debt often doesn't work out.  Maybe a big part of our security staff shortage is we're producing the wrong kinds of security leaders, and good leaders won't go into bad security companies.In the second half we discuss the several roles of machine learning we see today in security.

    Episode 49 - The Cybersecurity Market, and Channels, Backup, and SMB

    Play Episode Listen Later Sep 4, 2022 36:56


    Bill gives the OneDrive screwdriver a 1 star review as a backup hammer. We discuss how this shows that consumer and enterprise security tools are different, and being good for one does not mean naturally it is good as the other - it takes a conscious effort. This leads to how moving to new buying centers takes a conscious effort, and even more so when the buying center isn't adjacent. How small and midsize companies' cybersecurity is so unique.

    Episode 48 - Reports from ReInvent, Black Hat, DEFCON & Crypto Foolishness

    Play Episode Listen Later Aug 26, 2022 40:44


    Bill and Greg report on what Bill saw at AWS ReInvent, and what they've heard from Black Hat/DEFCON (spoiler - nothing earth shattering). The security nonsense continues in the cryptocurrency world. Greg talsk why Continuous Assessment is the most important trend.

    Episode 47 - Industrial Components Hacking, and What About Russia?

    Play Episode Listen Later Aug 9, 2022 42:41


    ICS security course tales, hacking factories, the current state sponsored landscape.

    Episode 46 - Eavesdropping, and the Bad News of Privacy & Security Diverging

    Play Episode Listen Later Jul 27, 2022 41:54


    The Real CyberSecurity podcast talks suspected state-sponsored eavesdropping using equipment providers,  famous incidents involving tampered devices in embassies.Privacy and cybersecurity seem to be diverging and that has to stop.And how awesome the cybersecurity vibe in the US Northeast.

    E45 - Cryptocurrency, and Quantum Crypto

    Play Episode Listen Later Jul 21, 2022 41:52


    Bill and Greg discuss why even though blockchains have great inherent security, the businesses and applications that are using them for cryptocurrency are not. They then explore why we are planning now for Quantum Crypto, and what "Quantum Safe" means.

    Episode 44 - RSA Conference After Action Report

    Play Episode Listen Later Jun 23, 2022 18:08


    Bill gives a post event report on the RSA Conference.

    Episode 42 - Talking to the Board About CyberSec, and Halifax

    Play Episode Listen Later May 24, 2022 38:22


    Bill files his report from his trip to Halifax, how not all cybersec issues are technology, how outsourcing is best as a balanced approach, and how the most complex cybersecurity conversations are actually the business ones.

    Episode 42 - Ukraine, Stuxnet Details Revealed & Are Security Conferences Dead?

    Play Episode Listen Later May 3, 2022 40:45


    Bill discusses the great Microsoft report on the revealed details of the cyberwar aspects of Ukraine & Russia war, and The Countdown to Zero Day book about Stuxnet. And Greg discusses why security conferences need to change.

    Episode 41 - Why CyberSec Pros Quit, Gartner's Top 7 Sec Trends, and APIs

    Play Episode Listen Later Apr 12, 2022 35:05


    Greg and  Bill review two pieces - Top reasons cybersec people leave their jobs by SecurityMagazine.com, and the Top 7 CyberSecurity Trends by Gartner as reported on by VentureBeat. Kudos to Peter Firstbrook for his comments that clarified the article and press release. Bill gives a really good description of the issues around Identity of Things. Greg opines we're about to enter the golden age of API richness in security, especially APi-API.

    Episode 40 - Hacked Traffic Signs, Mesh CyberSec, Ukraine War COMSEC

    Play Episode Listen Later Mar 31, 2022 42:37


    Hacked traffic enunciator boards, the reports of the top passwords from a hack, how poor communications security is in the news for the Ukraine war,  security education, and internet of things chat. And a tutorial on Mesh Cybersecurity.

    Episode 39 - Ransomware and Ukraine

    Play Episode Listen Later Mar 21, 2022 40:20


    Bill and Greg discuss the impact should Russia disconnect form the internet, Pi Day, Conti Ransomware group messages, and the dynamic of Ransomware - how does the war in Ukraine change ransomware now that state sponsored entities are busy?

    Episode 38 - Web 3.0, CyberScams & Money-laundering: the High and Low Tech

    Play Episode Listen Later Feb 16, 2022 48:25


    Will Bill (not to be confused with Kill Bill, because we really like Bill) be going to prison for tax evasion? Maybe, if you believe the sketchy letter he got in the snail-mail from "The Federal Tax Authorities". Scammers continue to evolve. They haven't gone away because they are still making money.  In this episode we discuss some recent  scam trends, and a case from last week of the FBI seizing billions in Bitcoin from alleged money launderers.

    Ep 37 - Privacy Week - How We Don't Have Much Privacy But We Can Get It Back

    Play Episode Listen Later Jan 28, 2022 32:51


    We're in a strange place in the cycle of Data Privacy. We give it away, but seem most concerned about it. Greg and Bill pull on some threads including social media, encryption, VPNs, and how we got here. Happy Data Privacy Week!

    Episode 36 - Holiday Scams, Some Different Talk About Log4J

    Play Episode Listen Later Dec 22, 2021 43:35


    I think the Union of Cybersecurity Workers Local 404 says we have to talk about Log4J. except we'll discuss some different aspects of it. Avoiding holiday scams and talking to your families about them. Some positive comments about Australian cybersecurity culture.

    Episode 35: When Physical and Cyber Security Collides

    Play Episode Listen Later Nov 25, 2021 52:35


    We dip into some history of hacking and spying where the technical security and physical security were both involved.  The Thing, U2 and SR71 planes, ransomware as a service, bugged embassies, ... so much to discuss! Cybersecurity companies with poor physical security are not to be trusted. Why embedding security in silicon is and will continue to be bad.

    Episode 34 - The Morris Worm, F12 Responsible Disclosure, and Tar

    Play Episode Listen Later Nov 10, 2021 45:56


    This episode we roast the continuing  awfulness of companies and politicians who accuse vulnerability researchers of hacking, Bill gives a history lesson on tarry substances used on crypto boards, and how the Morris Worm changed history. 

    Week 4 of Cybersecurity Awareness Month - Social Media Security

    Play Episode Listen Later Oct 25, 2021 17:23


    National Cybersecurity Awareness Month (NCSAM) is October! In this special week 4 of 4 (the finish line!)  of  NCSAM episode we are speaking to consumers and individuals about social media security. A lot of security professionals have zero social media presence, but that's not the reality for most people. You can engage without undertaking high risk.  And being respectful of the privacy and security others in your posts and feeds.  Listen in and join us!

    Week 3 of Cybersecurity Awareness Month - Password Management

    Play Episode Listen Later Oct 18, 2021 14:19


    National Cybersecurity Awareness Month (NCSAM) is October! In this special week 3 of 4 of  NCSAM episode we are speaking to consumers and individuals about passwords - those security things we all love to hate. But still, we have to protect them. Greg and Bill talk about some ways to make them easier to manage, and how to choose them. We also say the word entropy a lot, because it makes us sound more serious. 

    Week 2 of Cybersecurity Awareness Month - Device Security

    Play Episode Listen Later Oct 12, 2021 17:54


    National Cybersecurity Awareness Month (NCSAM) is October! In this special week 2 of 4 of  NCSAM episode we are speaking to consumers and individuals about device security. All your phones, TVs, and routers and such. protect yourself, and not just this month.

    Week 1 of Cybersecurity Awareness Month - Surfing Safely

    Play Episode Listen Later Oct 4, 2021 14:03


    National Cybersecurity Awareness Month (NCSAM) is October! In this special week 1 of 4 of  NCSAM episode we are speaking to consumers and individuals about surfing (the web) safely.

    Episode 33 - Security Startups and CyberSecurity Fame

    Play Episode Listen Later Sep 22, 2021 55:03


    Some reality about security startups, the fool's gold and FOMO-stress of fame in social media and conferences for cybersecurity, some career advice, Bill has some great advice about what makes a good organization and some criteria for buying companies, and Greg points out that the difference in cybersecurity companies who have  stock market success vs those whose target is making the best cybersecurity matters when you are buying stock vs buying products.

    Episode 32 - Orange Books, Spam, and How the Big IT Vendors Struggle With Security

    Play Episode Listen Later Sep 15, 2021 57:30


    Greg and Bill talk some cybersecurity history about the Orange Book, and how fundamentally the approach to what we put security into has changed.  Big IT vendors have trouble with security because it isn't their core business.

    Episode 30 - DevSecOps, Zero Trust, and Conference Celebs

    Play Episode Listen Later Aug 5, 2021 52:39


    Bill and Greg cover the history of app security testing,  why it is neglected, web application firewalls, code scanners, and how the devsecops loop is still mostly aspirational. Some thoughts on Zero Trust, and ... The Zachman Framework! DEFCON is here, trade show giveaways, and the most memorable celebrity keynotes.

    Episode 31 - Bread, Tinder, and About That CyberSec Whitehouse Meeting

    Play Episode Listen Later Aug 3, 2021 57:31


    Greg and Bill discuss, if in charge for a day, what they would change in cybersecurity to break the cycle we are in. Greg has big issues about that meeting of CEOs concerning cybersecurity at the White House. Bill talks defect analysis. How challenging the CISO job is in government, and we salute you. AI and security clearances!

    Episode 29 - Ransomware and The Money of It, and What Business Will Be Like In 2022

    Play Episode Listen Later Jul 28, 2021 41:36


    We start out with a few presentation tips, and do a status check on these unprecedented pajama-bottom wearing times. How the cybsersecurity culture in companies will be different in 2022. Complexity in the new hybrid telework/in-person will be exploited. SASE as a good tool to accommodate new business processes. What the near term of Ransomware as a service is. The biggest impact on Ransomware would be interrupting payments. We talk about our big current topics - XDR, Zero Trust, Resilience, Supply Chain, and SASE.

    Episode 28 - Keeping Secrets, Rise of Ransomware, Ethics in Cybersecurity

    Play Episode Listen Later Jun 14, 2021 61:44


    Balancing security education with security technology. Real risk: livestock are a bigger threat than sharks, and what about self-driving cars. The role of federal governments in tamping down ransomware activity. Small and Midsize Organization security. The dark arts of the Common Criteria and Formal Methods. Bill drives the Trolley Car in the Trolley Car Problem.

    Episode 27 - How Virtual Cybersecurity Conferences Can Be Better. And Zoom Backgrounds

    Play Episode Listen Later Jun 1, 2021 36:07


    Was in-person RSAC only a year ago? Selling passwords for candy bars, thinking back to RSA 2020, the good and bad of virtual events, and green M&Ms. Virtual cybersecurity events need to be a rethinking of the event format, not the worst of both worlds. And stop recording sessions months in advance. And Zoom backgrounds.

    Claim Real CyberSecurity

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel