Podcast charts
Published by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm. Tune in and take the reins of your cybersecurity journey—let’s ride into excellence together! 🚀
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into training mode and get concrete about threat modeling concepts and methodologies. We define threat modeling the way the exam cares about it: proactive, iterative, and designed to produce security requirements and prioritised countermeasures that feed your SDLC and risk register. We break down the three starting perspectives (asset-centric, attack-centric, and system-centric), then anchor STRIDE to data flow diagrams and trust boundaries so you can identify what security property is actually being violated, not just recite acronyms. We also cover the difference between identifying and ranking threats so you don’t fall into the classic traps: DREAD ranks threats you already found, while PASTA starts with business objectives and risk appetite and is built for risk-centric outputs leaders can fund. We talk attack trees, why MITRE ATT&CK is an input rather than a methodology, and why your threat actor catalog must include authorized non-human identities and vendor integrations that can operate outside intended scope. If this helps, subscribe, share it with a study buddy, and leave a quick review so more CISSP candidates can find it. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t be your finish line. From there, we tie the real-world scenario directly to CISSP Domain 8 Software Development Security and the secure SDLC. I lay out a clear, exam-friendly framework for assessing third-party and acquired software risk: Software Composition Analysis (SCA), Software Bill of Materials (SBOM), vendor and publisher risk assessment, and runtime plus pipeline controls. We talk about why SCA is necessary but incomplete, how a living SBOM enables fast exposure checks when a new campaign hits, and why Executive Order 14028 is pushing SBOM adoption into “expected” territory for many organisations. We also get practical about CI/CD pipeline security: dependency pinning, trusted publishing workflows, signed commits, OIDC, and package signing and verification approaches like Sigstore and Cosign. Finally, we run through scenario-based practice questions that highlight common CISSP traps and the manager mindset the exam rewards. If you want more episodes like this, subscribe, share it with a developer or security lead, and leave a quick review so more CISSP candidates can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail One careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal’s linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-triggered failure mode worth building into your security awareness habits. Then we shift into CISSP Question Thursday with a rapid, practical run through CISSP Domain 7.1 style topics in digital forensics and incident response. We break down what comes first when handling digital evidence (forensic copy before analysis), how to examine a suspicious file without detonating it (static analysis), and what makes an incident report useful under pressure (a clear timeline of events and actions taken). We also cover insider threat artifacts, mobile device forensics tools like Cellebrite UFED, and why chain of custody is the backbone that keeps evidence credible from collection to court. Along the way, we talk about root cause analysis, anomaly-based detection for network traffic, and why clear writing beats big jargon when you’re briefing executives, legal, or a board. If you want exam-ready thinking that also maps to real investigations, you’ll get it here. Subscribe for weekly CISSP training, share this with a teammate who scans QR codes too fast, and leave a review with the topic you want next. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own. From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk. We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You’ll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast. Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail One bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls. We start with the uncomfortable reality behind modern AI adoption: vendors ship powerful models, teams connect third parties, and employees reach for whatever chatbot is quickest. From AI-powered lending platforms that promise speed and fairness, to shadow AI that starts with a simple copy paste of customer data, the common thread is the same. Policies are not protection unless you can detect, enforce, and prove what’s happening with data, models, and vendors. Then we get practical. We walk through what examiners and auditors actually look for, why NIST AI RMF and existing third-party risk management rules are becoming the default playbook, and how to build evidence that holds up. Expect clear guidance on independent bias testing, explainability, contract language like right to audit and incident notification SLAs, and why model revalidation must be triggered by material change rather than an annual calendar cycle. We also tie the work back to CISSP domains and run practice questions designed to expose the “easy” answers that fail in real governance. If you’re responsible for security, compliance, or risk, this is your roadmap for governing AI before it governs you. Subscribe, share with a teammate, and leave a review so more CISSP candidates and security leaders can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper decommissioning, continuous monitoring, tight access control, and disciplined cloud asset inventories. From there, we shift into CISSP Domain 6.1 and the real work of designing and validating assessment, test, and audit strategies. We explain how we approach building a security assessment and testing program from the ground up: clear objectives, tight scope, risk-based prioritisation, stakeholder alignment, and baselines grounded in frameworks like NIST CSF, ISO 27001, CIS Benchmarks, and NIST SP 800-53. The aim is simple: identify vulnerabilities, validate security controls, and turn findings into remediation that leadership can act on. We also break down core security testing methods you will see on the CISSP and in real organisations: vulnerability assessment, penetration testing (white box, black box, gray box), fuzz testing, SAST and DAST for application security, plus red team, blue team, and purple team collaboration. Finally, we demystify SOC 1 vs SOC 2 and Type 1 vs Type 2 reports, why they matter for third-party risk management, and how cyber resilience thinking (including the Cyber Resiliency Index) ties everything back to continuity and trust. If this helps, subscribe, share the show with a colleague studying CISSP, and leave a review with the topic you want next. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail A six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when you’re dealing with production Linux servers, desktops, cloud workloads, and Android devices. Then we unpack the security mechanics in clear terms: a use-after-free race condition, an impossibly thin race window, and the way memory corruption turns into privilege escalation. We also talk about what makes this case extra concerning, including the report that it can be triggered from inside Chrome’s rendering sandbox. If you’ve ever relied on sandboxing, kernel boundaries, or “we run scanners” as your safety net, this story forces a more honest view of defense in depth. From there we connect the dots to CISSP Domain 8 software development security and real secure SDLC practice. We walk through where SAST, DAST, fuzzing, KASAN-style instrumentation, and AI-assisted code review help and where they fail, especially for concurrency bugs. The real takeaway is a layered detection strategy: automated testing plus manual secure code review for high-blast-radius code, support for external researchers through bug bounty programmes, and a patch management process that moves in days with verification and regression testing so incomplete fixes do not slip through. If this helps you think like a manager, subscribe, share the episode with a study buddy, and leave a review so more CISSP candidates can find it. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Imagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach. I walk through what’s being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries. We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora’s box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership. Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident. We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it’s not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician. Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what’s inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors. If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Your endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old comfort of “we have EDR, so we’re covered” turns into a single point of failure. We unpack the reporting on a highly active ransomware operation and its toolset, then zoom in on the technical path that makes this work: BYOVD, bring your own vulnerable driver. With admin access, attackers load a legitimate but vulnerable signed driver, escalate into kernel mode, and terminate security processes from below the privilege stack. From there, we shift to what matters for real security programs: defence in depth, kernel integrity protections like HVCI and KMCI, strict driver allow and block policies, and aggressive driver hygiene to reduce attack surface. Then we put on the CISSP lens. We tie the scenario to Domain 7 security operations (EDR limits, incident response, monitoring), Domain 3 security architecture and engineering (layered controls, hardening), and Domain 1 security and risk management (risk = threat × vulnerability × impact, plus threat landscape shifts). The big takeaway is simple: your job isn’t to find the fanciest tool, it’s to build a program that still works when one control fails and to communicate that risk clearly to leadership. If this helps you think like a manager and study smarter, subscribe for weekly CISSP-focused breakdowns, share the episode with a teammate, and leave a review so more people can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Someone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of science fiction. From there, I get practical with post-quantum planning: what the NIST post-quantum cryptography standards signal, why quantum key distribution is still niche for most organisations, and the big architectural idea to remember for the CISSP and for real enterprise security programs: crypto agility. We walk through concrete steps like building a cryptographic inventory, mapping where RSA and elliptic curve crypto live, identifying data with 10 to 20 year secrecy needs, and pushing vendors for a clear PQC roadmap. Then we pivot into CISSP Domain 1 supply chain risk management (SCRM and CSCRM). I explain why supply chains are a prime target, how modern supply chain attacks can ride in through poisoned open source packages, and what SolarWinds showed the world about scale and impact. We close with the nuts and bolts that actually reduce third-party risk: lifecycle supplier management, meaningful assessments (on-site when it matters), document and policy review, audits, and minimum security requirements baked into contracts and SLAs. If you want more training, check out CISSP Cyber Training, subscribe for weekly updates, share this with a friend who owns risk, and leave a quick review so more CISSP candidates can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Your software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines. I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We connect each technique to the CISSP mindset so you can spot it in scenario questions and, more importantly, recognise it in your own environment. Along the way, I explain why Node.js, Python, and Rust projects are especially exposed, how automation can turn “latest version” convenience into an enterprise incident, and why developer environments often become an overlooked attack surface. Then we get practical with controls you can actually implement: pausing automatic dependency updates when compromise is suspected, adding human approval for critical packages, rotating credentials immediately, enforcing MFA on developer and registry accounts, and using private or trusted registries to mirror and vet dependencies. I also zoom out to show how to build supply chain security into the secure SDLC with software composition analysis (SCA), code signing, checksum verification, audit logging, continuous monitoring, and an SBOM so you can respond fast when a package turns toxic. If this helps you tighten your dependency management and level up your CISSP prep, subscribe, share this with a teammate, and leave a quick review so more security pros can find the show. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail The breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack. From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment. To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5. Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Your firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it’s too late: memory. We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolation. From there, we unpack how modern operating systems enforce separation with paging, segmentation, and strict read, write, execute controls. You’ll hear why Meltdown and Spectre were such a big deal, how speculative execution can leak passwords and encryption keys from privileged memory, and why patching decisions are never just “apply everything” but a risk-based vulnerability management call that depends on visibility into what you run. Next, we connect memory protection to virtualization security. We break down hypervisors, guest and host isolation, Type 1 versus Type 2 designs, and the threats that keep security teams up at night: VM escape, side-channel leakage through shared CPU resources, and the operational hazards of memory overcommitment. Then we bring in hardware roots of trust through TPMs: secure boot, measured boot, key storage for full disk encryption, TPM 2.0 types, and how HSM-style key management shows up in cloud environments. We close with practical best practices, from firmware and microcode updates to choosing encryption controls that fit your actual risk. If you’re studying for the CISSP or building a real-world security strategy, subscribe, share this with a teammate, and leave a review so more security pros can find it. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail AI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of CISSP thinking and real security leadership. We walk through what is driving the mess: board-level pressure, AI FOMO, and the dangerous habit of treating AI agents like old-school automation. Then we get concrete. We talk about why many enterprises still lack an inventory of AI agents, why traditional security tooling is tuned for human behaviour anomalies, and what it actually takes to be audit-ready. We cover practical governance frameworks like tiered autonomy, why observability is more than collecting output logs, and how to design decision-path tracing with execution records and decision logs you can act on. To make it actionable for exam prep and day-to-day work, I close with CISSP-style practice questions on the exact scenarios you will face: detection gaps, human approval bottlenecks, least privilege for agents, proving decisions during audits, and architecting platforms that balance operational efficiency with risk management. If you are serious about passing, I also share how my CISSP Sprint cohort is structured to force momentum, including booking your exam date early. Subscribe for weekly CISSP-focused training, share this with a teammate building AI workflows, and leave a review so more security pros can find the show. What part of AI agent governance is your biggest blind spot right now? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Your security program can be airtight and still get wrecked by someone else’s breach. We open with a Wired-style reality check: third-party app ecosystems and data brokers collecting location analytics at massive scale, then getting hacked or resold in ways your users never expected. If your organisation issues mobile devices, this is where security awareness, MDM controls, and clear “don’t allow tracking unless required” guidance stops being a nice-to-have and starts becoming risk reduction. From there, we dig into CISSP Domain 2.3: provisioning resources securely, with the mindset of a senior security professional. We walk through information ownership versus asset ownership, why “IT owns the data” is often the wrong answer, and how classification (public, internal, confidential and beyond) drives least privilege and need-to-know access. We also cover the practical friction points: owners who don’t realise they’re owners, systems spread across teams, and the need to document decisions so risk acceptance is explicit instead of accidental. We then connect the dots across asset management, configuration management systems, and modern cloud operations. Expect talk on lifecycle tracking, secure disposal, rogue devices and shadow IT, plus the unique headaches of virtual sprawl, snapshots, tagging, data residency, and the cloud shared responsibility model. If you’re studying for the CISSP exam or trying to run a cleaner security programme at work, you’ll leave with a clearer map of what to inventory, who to hold accountable, and which controls keep resources from drifting into chaos. Subscribe for weekly CISSP-focused training, share this with a teammate who manages cloud or endpoints, and leave a review with the hardest “ownership” problem you’ve seen in the wild. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail BitLocker feels like a safety net until you see how a single bypass can change the whole risk picture. Today we react to the Yellow Key vulnerability (noted in the news and referenced as CVE 2645585) and use it as a practical CISSP training moment: a public proof of concept is available, a vendor patch is not, and the attack hinges on physical access. That mix forces you to think clearly about what “high risk” actually means, why “critical” is not always the right label, and how real security teams respond when the perfect fix does not exist yet. We connect the story to CISSP domains you are actively tested on. Domain 3 shows up in the basics of data at rest encryption and the uncomfortable truth that encryption is only as strong as its implementation. Domain 7 shows up in zero-day vulnerability management, compensating controls, and the need to have patch deployment ready to move the moment Microsoft ships a fix. We also highlight why secure boot and firmware integrity checks matter, and why endpoint detection may not help when an attacker can silently read files with little to no logging signal. Then we shift into five exam-style questions designed to sharpen your decision-making: how to classify risk using likelihood and impact, how to spot absolute-language distractors, which CIA triad principle is actually failing when data is accessed without detection, and why data minimisation can reduce breach impact more than “adding another tool.” If you’re studying for the CISSP exam and want practice that feels like real life, this is built for you. Subscribe for weekly CISSP practice, share this with a study partner, and leave a review so more candidates can find the show. What control would you tighten first if a BitLocker bypass hit your fleet tomorrow? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Default passwords are the kind of problem everyone “knows” about and yet they still open doors for attackers every day. We start with a quick reality check on router security and why factory settings, legacy gear, and unmanaged IoT and OT devices can turn a simple misconfiguration into redirect attacks, man-in-the-middle exposure, DDoS headaches, or silent monitoring. If you’re studying for the CISSP or defending a real network, you’ll walk away with a clearer sense of what to fix first and how to roll changes out without creating change-management chaos. Then we shift into CISSP Domain 1.6: understanding requirements for investigation types. We break down administrative, criminal, civil, and regulatory investigations and why the burden of proof changes everything. We talk through why HR and legal need to be involved early, when law enforcement is (and is not) helpful, and how sloppy evidence handling can get key artifacts thrown out. We also cover e-discovery and legal holds, using the Electronic Discovery Reference Model (EDRM) to make the process easier to remember and apply. To close, we get practical about evidence: admissibility, chain of custody, and the forensics basics that protect data integrity, including media, memory, network, software, and embedded device analysis, plus the value of write blockers and disciplined documentation. If you want to pass the CISSP and operate like a calm, credible security professional during an incident, this is the mindset. Subscribe for weekly CISSP-focused training, share this with a teammate, and leave a review with the investigation topic you want us to tackle next. Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Eight terabytes of stolen schematics is not just a scary number, it is a reminder that cyber risk becomes business risk fast. We start with the Wired report on the Foxconn ransomware attack and unpack what a claim like that could mean in the real world: intellectual property exposure, supply chain disruption, customer impact, and the uncomfortable truth that recovery is only one part of the story when data walks out the door. From there, we switch into CISSP Domain 7 Security Operations mode and work through practical exam-style questions with the “how would this hold up at work” mindset. We break down why live forensics imaging can be the right call during an insider threat investigation, using the order of volatility and the kinds of RAM artifacts that disappear the moment you shut a machine down. We also tackle a Patch Tuesday nightmare scenario where a CVSS 9.8 vulnerability is already being exploited but the change advisory board will not meet for ten days, and we explain why an emergency change process plus compensating controls is the mature security operations answer. We also cover a common privileged access failure where a domain admin uses an elevated account for email and browsing, and how least privilege plus a privileged access workstation (PAW) architecture can prevent a single phish from becoming domain compromise. Finally, we sharpen the fundamentals with an RTO/RPO recovery timeline question and a SIEM brute force threshold miss that illustrates false negatives and the need for better tuning and behavioural baselines. Subscribe for weekly CISSP training, share this with a study partner, and leave a review so more security pros can find the show. What topic do you want me to turn into practice questions next? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us Fan Mail Next Peak: https://nextpeak.net/services/icr/ A regional conflict can spike your cyber risk even if your offices never move and your headcount never changes. That is the uncomfortable reality behind geopolitical cyber risk, and it is why I brought on Helen Lee, Director of Intelligence Cyber Research at NextPeak, to break down how global flashpoints turn into real security problems for businesses of every size. If your security program only reacts to today’s alerts, you are already behind the curve. We dig into what “geopolitical cyber risk” actually means, why awareness so often fails to become action, and how to bridge that gap with practical, decision ready outputs. Helen shares concrete examples that make the risk feel real: how hardware and supply chains can become national security issues, why router ecosystems can create broad exposure, and how second and third order effects in semiconductor production can introduce new vulnerabilities across your tech stack. We also talk about the World Economic Forum data showing that organisations expect geopolitical tensions to increase cyber risk while many are still adjusting their posture. From there, we get operational. We cover where this work fits in an existing security stack, how to “bake it in” at the governance, risk, and compliance layer, and why threat intelligence teams will be critical for monitoring geocyber indicators and handing off actionable guidance to the SOC and leadership. Helen walks through offerings like a geopolitical cyber risk index, assessments, advisory support, customised reporting, and future focused tabletop exercises that test readiness for plausible scenarios years ahead. If you are studying for the CISSP, this conversation ties directly to Security and Risk Management, third party risk, supply chain risk, and communicating risk to executives and boards. Subscribe for more practical CISSP focused conversations, share this with a security leader who owns vendor risk, and leave a review so more people can find the show. What is the biggest geopolitical risk you think your organisation is ignoring right now? Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.