Épisodes

  • Surviving a Cardiac Event: Biometric Data and the Risks Nobody Talks About
    Mar 9 2026

    What if the device keeping you alive was also a cybersecurity vulnerability? That's not a hypothetical — it's Victor Barge's reality.

    In this episode of The Audit, IT Audit Labs' Global Delivery Director Victor Barge shares the story of his sudden cardiac event and the life-saving defibrillator now implanted in his chest and the eye-opening security questions that followed. Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum connect Victor's story to the real-world cyber risks organizations ignore every single day.

    What you'll learn in this episode:

    • How modern pacemakers and defibrillators transmit biometric data 24/7 — and what happens if that data is compromised
    • Why the 2017 Abbott pacemaker recall of 500,000 devices is a warning the industry hasn't fully heeded
    • The parallel between reactive healthcare and reactive cybersecurity — and why waiting costs you more
    • Why billion-dollar organizations are still storing passwords in spreadsheets in 2026
    • What continuous monitoring in IT security can learn from real-time cardiac telemetry

    Whether you're a CISO, IT auditor, or just someone wearing a smartwatch, this episode will make you rethink what "sensitive data" really means.

    Voir plus Voir moins
    37 min
  • Secret Service Agent Reveals Undercover Cyber Ops
    Feb 23 2026

    What does it take to go undercover with international cybercriminals — with no backup, no safe house, and no script? In this episode of The Audit, Richard LaTulip, Field CISO at Recorded Future and former U.S. Secret Service agent, pulls back the curtain on three years of undercover operations spanning Thailand, Dubai, Macau, and China. From buying stolen credit card data in bulk to handing cheap government-issued laptops to disappointed hackers, Richard shares the raw, unfiltered reality Hollywood never shows you.

    Co-hosts Joshua J Schmidt, Eric Brown, Nick Mellem, and Jen Lotze dig into the psychology of social engineering, the stark differences between nation-state and financially motivated threat actors, and why your employees are simultaneously your greatest asset and your biggest vulnerability. Richard breaks down how SolarWinds revealed the patience of nation-state operations, why cultural awareness is a cybersecurity weapon, and how organizations can shift security from a cost center to a value driver.

    • 🔑 Key Topics Covered:
    • Undercover operations against international cybercriminal networks — the reality vs. the Hollywood version
    • Nation-state vs. financially motivated threat actors — how their goals fundamentally change defense strategy
    • The ClickFix campaign and social engineering attacks targeting human psychology
    • How Recorded Future delivers actionable, tailored threat intelligence vs. generic feeds
    • Why tabletop exercises need HR, communications, and every department at the table • Cultural dimensions of cybersecurity — from Eastern European honeytraps near nuclear sites to password reuse psychology
    • Turning your security team from a "cost center" into a trusted business ally
    • Operation Carter Chaos — Richard's new book chronicling the untold human side of undercover cyber operations

    📖 Richard's book Operation Carder Kaos is available now on Amazon.

    🔔 Like, share, and subscribe for more in-depth cybersecurity conversations. Don't forget to leave a review — it helps us reach more security professionals like you.

    Voir plus Voir moins
    44 min
  • Cyber News: Advanced Phishing, ClickFix & AI Wearables
    Feb 9 2026

    Microsoft dominates 22% of all phishing attacks, a $800 tool tricks 60% of victims into self-hacking, and Apple's planning a surveillance pin that records everything—welcome to 2025's cybersecurity nightmare. In this episode of The Audit, co-hosts Joshua J Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from IT Audit Labs to dissect three headlines that prove the threat landscape isn't just evolving—it's accelerating. From brand impersonation scams that exploit your brain's pattern recognition to ClickFix malware that bypasses antivirus by weaponizing copy-paste commands, this conversation reveals how attackers are shifting from breaking through defenses to manipulating humans into opening the door themselves.

    What You'll Learn:

    • Why trusted brands like Microsoft, Amazon, and DHL are irresistible phishing targets, especially during high-traffic seasons when vigilance naturally drops
    • How ClickFix attacks exploit legitimate-looking broken websites to trick users into installing malware through their own command prompts—achieving 60% success rates that evade traditional security
    • Real-world consequences of sophisticated social engineering, including a $116,000 wire fraud loss that proves even tech-savvy professionals aren't immune
    • The privacy and consent implications of Apple's rumored 2027 AI wearable with dual cameras and always-on environmental recording
    • Whether constant surveillance is becoming the unavoidable price of technological convenience—and what that means for building security cultures in organizations today

    From training employees to recognize copy-paste scams to navigating the ethics of ambient recording devices, this episode delivers frontline intelligence for security professionals and practical awareness for anyone trying to stay safe online.

    #phishing #clickfix #cybersecurity #socialengineering #applewearable #privacy #malware #infosec #brandimpersonation

    Voir plus Voir moins
    33 min
  • Field Notes: New Year Catch-Up, Coffee, And Team DNA
    Jan 26 2026

    In this episode of The Audit, co-hosts Eric Brown and Nick Mellem dive deep into organizational psychology and team dynamics with a refreshingly honest look at how IT Audit Labs is using assessments like CliftonStrengths, Kolbe, and PRINT to decode their team. This isn't fluffy HR talk—it's strategic workforce optimization that directly impacts how security teams respond to threats, collaborate under pressure, and execute on complex projects.

    Eric and Nick discuss why understanding your team's natural strengths, motivators, and triggers is just as critical as deploying the right tech stack. From reducing meeting bloat to being more intentional with time and resources, they share real-world lessons on building a culture where people operate in their zone of genius. Plus, they tackle the "what tool would you deploy first" scenario—spoiler: it's not what you think.


    🔑 KEY TOPICS COVERED:

    • Why organizational assessments (CliftonStrengths, Kolbe, PRINT) matter for security teams
    • How to be more intentional with meetings, time, and team collaboration
    • First tools to deploy in a new security environment (MFA, YubiKeys, Veronus)
    • The shift from reactive security to proactive team alignment
    • Using AI tools like Gemini to streamline communication and decision-making

    #CliftonStrengths #Cybersecurity #TeamBuilding #ITLeadership #SecurityCulture #CISOLife #InfoSec #OrganizationalPsychology

    Voir plus Voir moins
    27 min
  • AI Architecture: Stop Button Pushing, Start Building
    Jan 12 2026

    What if the difference between AI mediocrity and breakthrough isn't the tool—it's how you architect your approach? Carter Jensen from The Uncommon Business joins the crew to reveal why most people are stuck "button pushing" while others are unlocking 3X productivity gains. This isn't theory; it's the frontline reality of businesses transforming workflows with the right AI architecture.

    If you're tired of surface-level AI hype and ready for actionable intelligence on integrating AI into security, compliance, and everyday business operations, this episode delivers. Whether you're Blockbuster or Netflix is up to you.

    🎯 What You'll Learn:

    • AI Architecture vs. Button Pushing – The mindset shift that unlocks 3-4X productivity gains instead of mediocre results
    • Real Cybersecurity Wins – How IT teams use AI to speed through compliance audits (PCI, CJIS, HIPAA) and tackle complex security workflows
    • Enterprise Implementation Truth – Why expensive AI tools fail without strategy, and what actually works for business adoption
    • The AI Bubble Debate – Is this hype or the biggest business transformation since the internet? Carter brings receipts from the frontlines

    Don't let your team fall behind while competitors architect their way to 4X output. This episode arms IT leaders, CISOs, and security professionals with the mindset shift needed to deploy AI that actually moves the needle. Like, share, and subscribe for more cutting-edge cybersecurity and AI implementation strategies!

    #ArtificialIntelligence #Cybersecurity #AIforBusiness #ITaudit #ComplianceAutomation

    Voir plus Voir moins
    41 min
  • The Audit 2025: Deepfakes, Quantum & AI That Changed Everything
    Dec 29 2025

    In this special year-end episode, Joshua Schmidt revisits the most mind-bending moments from The Audit's 2025 season. From Justin Marciano and Paul Vann demonstrating live deepfakes in real-time (yes, they actually did it on camera) to Bill Harris explaining how Google's quantum experiments suggest parallel universes, to Alex Bratton's urgent warning about the AI adoption crisis happening right now in boardrooms everywhere.

    What You'll Learn:

    • How adversaries are using free tools to create convincing deepfakes for job interviews and social engineering attacks—and why this represents a national security threat
    • Why NASA shut down its quantum computer after getting results that "challenge contemporary thinking" (and the wild theories circulating about what they discovered)
    • The critical mistake companies are making with AI integration: racing ahead without governance, security frameworks, or responsible use policies
    • How the Pi-hole community exemplifies open-source security at its best—enterprise-grade protection at fractions of the cost
    • Why IT teams saying "no" to AI isn't realistic, and what responsible AI adoption actually looks like

    This isn't just a recap—it's a wake-up call. These conversations reveal the inflection points where standing still means falling behind. Whether you're a CISO, security analyst, IT auditor, or business leader trying to navigate AI adoption, these clips offer the perspective you need heading into 2026.

    Don't wait until 2026 to realize you missed the critical shift. Subscribe now for cutting-edge cybersecurity insights that keep you ahead of evolving threats.

    #cybersecurity #deepfake #quantumcomputing #AI #infosec #ethicalhacking #cyberdefense #2025yearinreview

    Voir plus Voir moins
    23 min
  • Gaming to Cybersecurity: How AI Agents Fight Alert Overload
    Dec 15 2025

    What if you could hire an army of AI security analysts that work 24/7 investigating alerts so your human team can focus on what actually matters? Edward Wu, founder and CEO of DropZone AI, joins The Audit crew to reveal how large language models are transforming security operations—and why the future of cyber defense looks more like a drone war than traditional SOC work.

    From his eight years at AttackIQ generating millions of security alerts (and the fatigue that came with them), Edward built DropZone to solve the problem he helped create: alert overload. This conversation goes deep on AI agents specializing in different security domains, the asymmetry problem between attackers and defenders, and why deepfakes might require us to use "safe words" before every Zoom call.

    What You'll Learn:

    • How AI tier-1 analysts automate 90% of alert triage to find real threats faster
    • Why attackers only need to be right once, but AI can level the playing field
    • Real-world deepfake attacks hitting finance teams right now
    • The societal implications of AI-driven social engineering at scale
    • Whether superintelligence will unlock warp engines or just better spreadsheets

    If alert fatigue is crushing your security team, this episode delivers the blueprint for fighting back with AI. Hit subscribe for more conversations with security leaders who are actually building the future—not just talking about it.

    #cybersecurity #AIforCybersecurity #SOC #SecurityOperations #AlertFatigue #DropZoneAI #ThreatDetection #IncidentResponse #CyberDefense #SecurityAutomation

    Voir plus Voir moins
    35 min
  • Critical Infrastructure: Everything is Connected and Vulnerable
    Dec 1 2025

    When hackers target the systems controlling your water, power, and transportation, the consequences go far beyond data breaches—people can die. Leslie Carhartt, Technical Director of Incident Response at Dragos, pulls back the curtain on one of cybersecurity's most critical blind spots: industrial control systems that keep society running but remain dangerously exposed.

    What You'll Learn:

    • Why industrial control systems can't be updated like your laptop—and what that means for security
    • How threat actors are using AI to generate custom malware for power plants and water treatment facilities
    • The real state of critical infrastructure security (spoiler: forget about air gaps)
    • Why commodity ransomware has become an existential threat to industrial operations
    • The five critical controls organizations should implement right now to defend OT environments

    Don't wait until your organization becomes the next headline. Like, share, and subscribe for more in-depth security intelligence that goes beyond the buzzwords.

    #industrialcybersecurity #criticalinfrastructure #OTsecurity #ICS #SCADA #dragos #incidentresponse #ransomware #AIthreats #cybersecurity #infosec

    Voir plus Voir moins
    33 min