Obtenez 3 mois à 0,99 $/mois

OFFRE D'UNE DURÉE LIMITÉE
Page de couverture de Simply Defensive

Simply Defensive

Simply Defensive

Auteur(s): Simply Cyber Media Group
Écouter gratuitement

À propos de cet audio

Join us for Simply Defensive, a podcast dedicated to exploring the world of defensive cybersecurity through the lens of real-world experts. In each episode, we'll interview leading professionals from the cybersecurity industry, delving into their experiences, challenges, and innovative solutions. Whether you're a seasoned cybersecurity veteran or just starting to learn about the field, Simply Defensive offers valuable insights and practical advice to help you stay ahead of the curve. Tune in as we discuss the latest threats, emerging technologies, and best practices for protecting your organization from cyberattacks. ========================= Connect with your hosts: Josh Mason: https://www.linkedin.com/in/joshuacmason Wade Wells: https://www.linkedin.com/in/wadingthrulogs ========================= Simply Cyber empowers people who want a rewarding cybersecurity career 💪 ========================= ========================= All the ways to connect with Simply Cyber https://SimplyCyber.io/Socials =========================2025 Simply Cyber Media Group Gestion et leadership Économie
Épisodes
  • From Pre-Law to FLARE: How Josh Stroschein Became Google's Malware Analyst
    Dec 1 2025

    In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Josh Stroschein — aka The Cyber Yeti — a former professor turned reverse engineer now working on one of the largest malware analysis teams in the world.


    Josh shares his unconventional path through .NET development, credit card processing security, and academia before landing at Google. He opens up about teaching reverse engineering while learning it himself, building educational CTFs, and the realities of making it as a full-time reverse engineer in an industry where those roles are rare.


    What you'll hear:

    🔹 From pre-law to pilot training to PhD in cybersecurity

    🔹 How teaching RE forced him to truly master it

    🔹 Life inside Google's FLARE team (via Chronicle → Mandiant)

    🔹 Flareon CTF — the RE challenge that's run for 12 years

    🔹 A wild Black Hat NOC story involving an infected Mac and Atomic Stealer

    🔹 Using AI to build malware samples for training labs

    🔹 Why going low-level is the best advice for blue teamers


    Chapters:

    00:00 Introduction and Welcome

    00:50 Josh's Connection to Dr. Gerald Auger

    02:00 The Non-Traditional Path: Pre-Law, Pilot Training & .NET Dev

    05:00 Getting Into Security at a Credit Card Processor

    07:00 Teaching Reverse Engineering at Dakota State

    10:00 Flareon CTF and Educational CTF Design

    14:00 Is Reverse Engineering Offensive or Defensive?

    17:00 How Rare Are Full-Time RE Roles?

    21:00 The Path to Google: Chronicle, Mandiant & FLARE

    25:00 Learning Through Teaching and YouTube Content

    28:00 Black Hat NOC Story: Catching Atomic Stealer Live

    33:00 Using AI to Create Malware Training Samples

    37:00 Building a Defang Tool (and .NET Nightmares)

    40:00 Advice for Blue Teamers: Go Low-Level


    🎧 Find Josh Stroschein:

    → Website: https://www.thecyberyeti.com

    → YouTube: The Cyber Yeti

    → Podcast: The Cyber Yeti Podcast


    👥 Connect with the Hosts:
    → Josh Mason: https://www.linkedin.com/in/joshuacmason/
    → Wade Wells: https://www.linkedin.com/in/wadingthrulogs/
    → Swimlane: https://www.linkedin.com/company/swimlane


    🎙️ Listen on Your Favorite Platform:
    → Spotify: https://open.spotify.com/show/72QTocT5FSTSPV7o1UcMS4
    → Apple Podcasts: https://podcasts.apple.com/us/podcast/simply-defensive/id1773806182
    → Full Playlist: https://youtube.com/playlist?list=PL4Q-ttyNIRAr6DVrsASx1-Fv-TsooJ3M4


    👍 If you enjoyed this episode, don't forget to like, subscribe, and share with your fellow defenders. Every week, Josh Mason and Wade Wells bring you practical, no-fluff conversations with cybersecurity professionals who are doing the work.


    =========================
    All the ways to connect with Simply Cyber
    https://SimplyCyber.io/Socials
    =========================
    This podcast is presented by Simply Cyber Media Group

    Voir plus Voir moins
    40 min
  • Building Zero Trust Tools: Inside ThreatLocker with Product Manager Yuriy Tsibere
    Nov 24 2025

    In this episode of Simply Defensive, hosts Josh Mason and Wade Wells welcome Yuriy Tsibere, Product Manager at ThreatLocker, for a behind-the-scenes look at how security products actually get built.


    Yuriy's path to cybersecurity started in Ukraine, where he worked in telecom during sophisticated APT campaigns that lasted over a year. Now at ThreatLocker, he shapes the tools defenders use daily—from allow listing to compliance automation.


    Episode Highlights:

    • What product managers actually do at security companies
    • APT attack patterns: social engineering meets technical exploitation
    • How allow listing, ring fencing, and network control protect endpoints
    • Defense Against Configuration (DAC): automating FedRAMP, HIPAA, and NIST compliance
    • Why misconfigurations remain one of the biggest security gaps
    • Balancing strict security with real-world usability
    • Yuriy's top advice for defenders: Educate your personnel

    Key Takeaway: Most breaches still come from employees clicking without paying attention. Security products matter, but user education accounts for the largest share of issues. Yuriy also emphasizes that when compliance drift happens—when systems become uncompliant—it should trigger an investigation into what changed and why.


    Resources Mentioned:

    • ThreatLocker Zero Trust Endpoint Protection
    • Defense Against Configuration (DAC) for compliance monitoring
    • Zero Trust World Conference

    Perfect for blue teamers, SOC analysts, security engineers, and anyone interested in how security products evolve from concept to deployment.

    Connect with Yuriy Tsibere (Guest) on LinkedIn: https://www.linkedin.com/in/yuriy-tsibere/


    🔗 Links & Resources:
    → ThreatLocker Free Trial: https://www.threatlocker.com/simplydefensive
    → Zero Trust World Conference: https://www.intlcybersec.org/zerotrustworldmain


    👥 Connect with the Hosts:
    → Josh Mason: https://www.linkedin.com/in/joshuacmason/
    → Wade Wells: https://www.linkedin.com/in/wadingthrulogs/
    → Swimlane: https://www.linkedin.com/company/swimlane


    🎙️ Listen on Your Favorite Platform:
    → Spotify: https://open.spotify.com/show/72QTocT5FSTSPV7o1UcMS4
    → Apple Podcasts: https://podcasts.apple.com/us/podcast/simply-defensive/id1773806182
    → Full Playlist: https://youtube.com/playlist?list=PL4Q-ttyNIRAr6DVrsASx1-Fv-TsooJ3M4


    👍 If you enjoyed this episode, don't forget to like, subscribe, and share with your fellow defenders. Every week, Josh Mason and Wade Wells bring you practical, no-fluff conversations with cybersecurity professionals who are doing the work.


    💡 Brought to you by ThreatLocker – Secure your business with zero trust application control. https://www.threatlocker.com/simplydefensive


    =========================
    Sponsored by @ThreatLocker - Free 30-day trial visit:
    https://www.threatlocker.com/simplydefensive
    =========================
    All the ways to connect with Simply Cyber
    https://SimplyCyber.io/Socials
    =========================
    This podcast is presented by Simply Cyber Media Group

    Voir plus Voir moins
    36 min
  • Cyber Insurance Explained: What Blue Teams Need to Know Before an Incident
    Nov 17 2025

    From teaching AP art history to brokering cyber insurance deals. 🎓➡️🛡️


    In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Andy Runyan from Yukon to break down everything blue teamers need to know about cyber insurance — before an incident happens. Andy shares his unconventional journey from fourth-generation educator and baseball coach to becoming a cyber insurance specialist, and explains why understanding your policy is just as important as your incident response plan.


    What you'll hear:
    🔹 How cyber insurance actually works (and what it doesn't cover)
    🔹 Why having an incident response retainer matters — before you need it
    🔹 The role of cyber insurance in incident response and recovery
    🔹 Third-party contract requirements and state mandates on the rise
    🔹 Common mistakes companies make when filing claims
    🔹 FTC Safeguard Rules and what they mean for businesses
    🔹 How to prepare your organization for cyber insurance requirements
    🔹 What lowers premiums (and what should, but doesn't)


    Why This Matters for Blue Teamers:
    If you're in a SOC or handling incident response, you will interact with cyber insurance at some point. Understanding how policies work, what triggers coverage, and how to prepare can make the difference between a smooth recovery and a catastrophic financial loss. This episode gives you the insider knowledge to help your organization be ready.


    ⏱️ Timestamps:
    00:00 Introduction and Welcome
    00:15 Andy's Unique Background: From Teacher to Cyber Insurance
    03:00 Getting Into Cyber Insurance in 2019
    04:00 The Wild West of Cyber Insurance During COVID
    06:00 When Companies Actually Buy Cyber Insurance
    08:00 What Blue Teamers Need to Know About Insurance
    10:00 The Problem with Incident Response Retainers
    12:00 How Insurance Companies Handle IR vs. What You Need
    15:00 Multi-Factor Authentication and Premium Discounts
    18:00 Why Having an IR Plan Doesn't Lower Your Premium (But Should)
    21:00 Third-Party Contract Requirements on the Rise
    24:00 State Mandates: What's Coming Next?
    27:00 FTC Safeguard Rules and Compliance Reality
    30:00 Where to Learn More About Yukon


    🔗 Connect with Andy Runyan:
    → Yukon Website: https://www.ukon.com
    → LinkedIn: https://www.linkedin.com/in/andy-runyan
    → Email: andy.runyan@ukon.com


    👥 Connect with the Hosts:
    → Josh Mason: https://www.linkedin.com/in/joshuacmason/
    → Wade Wells: https://www.linkedin.com/in/wadingthrulogs/
    → Swimlane: https://www.linkedin.com/company/swimlane


    🎙️ Listen on Your Favorite Platform:
    → Spotify: https://open.spotify.com/show/72QTocT5FSTSPV7o1UcMS4
    → Apple Podcasts: https://podcasts.apple.com/us/podcast/simply-defensive/id1773806182
    → Full Playlist: https://youtube.com/playlist?list=PL4Q-ttyNIRAr6DVrsASx1-Fv-TsooJ3M4


    👍 If you enjoyed this episode, don't forget to like, subscribe, and share with your fellow defenders. Every week, Josh Mason and Wade Wells bring you practical, no-fluff conversations with cybersecurity professionals who are doing the work.


    =========================
    Sponsored by @ThreatLocker - Free 30-day trial visit:
    https://www.threatlocker.com/simplydefensive
    =========================
    All the ways to connect with Simply Cyber
    https://SimplyCyber.io/Socials
    =========================
    This podcast is presented by Simply Cyber Media Group

    Voir plus Voir moins
    33 min
Pas encore de commentaire