
Sign up to save your podcasts
Or


Secure routing and switching are foundational elements of network security. In this episode, we explore how routers and switches operate, and how attackers exploit their misconfigurations or weaknesses to gain access or disrupt communication. Topics include route hijacking, ARP poisoning, MAC flooding, and VLAN hopping. You’ll learn best practices for hardening these devices, including access control lists (ACLs), management plane protection, port security, and proper firmware management. Ensuring routing and switching infrastructure is properly secured is a critical skill for any CISSP responsible for protecting the integrity of network environments.
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are crucial for identifying and stopping threats in real time. This episode explores how these tools work, their deployment strategies, and how they integrate with broader security operations. You’ll learn about signature-based and anomaly-based detection, false positives, evasion techniques, and tuning practices. We also cover network-based and host-based implementations, and how alerts are correlated in a Security Information and Event Management (SIEM) platform. IDS and IPS are key components of active defense and threat response.
Layered security—known as defense in depth—is a core concept in cybersecurity architecture. This episode focuses on how firewalls and demilitarized zones (DMZs) serve as essential layers in protecting internal networks. We explore different types of firewalls (packet filtering, stateful, next-gen), the design of DMZs for public-facing services, and how to enforce traffic controls between zones. You'll also learn how to implement rule sets, audit firewall logs, and support intrusion detection systems. This is critical knowledge for securing enterprise perimeters and enforcing trust boundaries.
Segmentation limits the spread of attacks and improves control over traffic flows within a network. In this episode, we examine both traditional network segmentation and microsegmentation techniques. You’ll learn how VLANs, firewalls, and subnetting create macro boundaries, while software-defined networking enables granular control over traffic between workloads and devices. We discuss how segmentation supports least privilege access, improves detection, and reduces risk. CISSPs must know how to design segmented architectures that balance performance, visibility, and security.
Secure communication protocols form the backbone of protected digital environments. In this episode, we explore widely used secure protocols like HTTPS, SSH, SFTP, and SNMPv3. You’ll learn how each one provides confidentiality, integrity, and authentication for various types of data exchanges—from web traffic and file transfers to remote administration and device management. We cover protocol strengths, configuration tips, and common pitfalls. CISSPs must understand which protocols are appropriate for specific use cases and how to deploy them effectively in enterprise environments.
The OSI and TCP/IP models provide a layered approach to understanding how data is transmitted, received, and managed across networks. In this episode, we refresh your understanding of these models and their significance in network security. We explore the function of each layer—from physical cabling to application-level protocols—and explain how attacks and defenses map to specific layers. You’ll also learn how these models aid in troubleshooting, forensic analysis, and control implementation. Mastery of these foundational models helps CISSPs design and secure resilient networked systems.
Understanding how networks are built and connected is foundational for any security professional. In this episode, we review core network architecture concepts, including the structure and purpose of Local Area Networks (LANs), Wide Area Networks (WANs), and the global Internet. We examine how data moves across these networks and where vulnerabilities may appear, from physical access points to routing protocols. You’ll also learn about segmentation, perimeter controls, and traffic flow management. A solid grasp of network architecture is necessary for applying controls and preventing unauthorized access.
Downtime is not an option for mission-critical systems. In this episode, we dive into fault tolerance, redundancy, and high availability—design strategies that ensure continuity despite component failures or unexpected disruptions. You’ll learn the differences between active-active and active-passive configurations, the role of clustering, load balancing, failover mechanisms, and geographically distributed resources. We also cover the importance of regular testing and monitoring to validate these systems. Building resilient infrastructure is a core CISSP competency and a vital part of risk mitigation planning.
Supervisory Control and Data Acquisition (SCADA) systems and embedded devices operate some of the most critical infrastructure in the world—from energy grids to transportation systems. This episode explores the unique challenges of securing these environments, including limited resources, outdated firmware, lack of patching, and real-time operational requirements. We cover best practices for access control, network isolation, vendor management, and secure configuration. As cyber threats increasingly target industrial systems, it’s crucial for CISSPs to understand how to protect these specialized and high-impact platforms.
Technological innovation continues to transform the security landscape. In this episode, we examine how emerging technologies such as the Internet of Things (IoT), Artificial Intelligence (AI), and machine learning are impacting security architecture. We discuss the benefits and vulnerabilities of these systems, including expanded attack surfaces, device sprawl, privacy concerns, and autonomous decision-making risks. You’ll also learn strategies for integrating these technologies securely using layered defenses, segmentation, and monitoring. CISSPs must understand both the opportunity and risk that innovation brings to cybersecurity.
From the publisher's feed