Cybersecurity 101 with Joe and Larry

Cybersecurity 101 with Joe and Larry

Download on the App Store

Cybersecurity 101 with Joe and Larry episodes

  • Episode 29 - Kirsten Bay, CEO of Cysurance

    Kirsten Bay (CEO & Co-Founder, Cysurance) joined me on Cybersecurity 101 with Joe and Larry to talk about something every business leader is feeling right now:

    Cyber defenses and cyber insurance are no longer separate conversations.

    Your technical controls increasingly drive financial risk, coverage eligibility, and business outcomes.

    A few highlights from our discussion:

    • Why the traditional cyber insurance model has struggled — and how real-time, verified controls can reduce friction and uncertainty

    • Cysurance’s approach: embedded, warranty-backed insurance inside cybersecurity solutions for organizations that meet control requirements

    • The most common gaps we see in the real world: incomplete MFA, patching gaps, and firewall hygiene

    • How AI is accelerating social engineering — and why phishing-resistant MFA and data minimization matter more than ever

    • What warranty coverage can include (depending on program): ransomware, BEC, legal liability, business interruption, and gap coverage for out-of-pocket expenses

    • A practical mindset shift: assume breach, build resilience, and prioritize controls that measurably reduce risk

      If you’re an IT leader trying to lower the total cost of cyber risk—this episode is for you.

      49 min
    • Episode 28 - AI Voice Cloning Scams and Insider Tips from the SOC

      00:00 – 00:22 – Welcome Back

      Larry and Joe return for another engaging episode of Cybersecurity 101.

      00:23 – 03:56 – AI and Voice Cloning Scams

      The hosts discuss the growing threat of AI-powered voice cloning scams targeting the elderly and provide practical tips for avoiding them.

      03:57 – 06:08 – Modern Antivirus Solutions

      Joe explains why built-in tools like Windows Defender outperform legacy products like Norton and McAfee, saving users money and offering superior protection.
      Source: https://www.av-test.org/en/antivirus/home-windows/

      06:09 – 08:45 – Freezing Your Credit

      Joe highlights the importance of freezing credit with major bureaus to protect against identity theft, explaining how it eliminates the need for costly services like LifeLock.
      https://en.wikipedia.org/wiki/Credit_freeze

      08:46 – 12:38 – Public Wi-Fi and VPNs

      A deep dive into the risks of using public Wi-Fi and the scenarios where VPNs can add an extra layer of protection, especially against hotspot impersonation attacks.

      12:39 – 15:45 – Mentoring Future Cybersecurity Professionals

      Larry shares his experience mentoring newcomers to the field, emphasizing the importance of understanding networking basics and applying real-world skills.

      15:46 – 18:45 – SOC Workflow and Tiered Roles

      Joe and Larry break down the structure of a Security Operations Center (SOC), explaining the roles of Tier 1 analysts, Tier 2 shift leaders, and Tier 3 specialists like threat hunters and detection engineers.

      18:46 – 22:06 – Responding to Incidents

      Larry details a recent SOC case involving unusual sign-ins and blocked countries, showcasing the process of verifying legitimate activity.

      22:07 – 28:06 – Human Insight vs. AI in Cybersecurity

      The hosts explore why human instincts remain irreplaceable in handling complex cybersecurity cases, even with advancements in AI.

      28:07 – 30:56 – Planning a SOC Lab

      Joe and Larry brainstorm ideas for a future podcast episode, including building a lab to simulate incidents and share hands-on cybersecurity insights with listeners.

      30:57 – Looking Ahead

      The hosts reflect on their cybersecurity journey and tease upcoming content, including mock incident labs and tutorials to show listeners the day-to-day realities of working in a SOC.

       

      34 min
    • Episode 27 - Protect Yourself Online: Mobile Carrier Breach, Password Tips, and QR Code Scams

      0:06 – 0:22 – Welcome Back!  

      Larry and Joe kick off the latest episode of their podcast with excitement, diving straight into the cybersecurity topics of the day.

      0:56 – 3:56 – The Mobile Carrier Breach  

      Joe breaks down the recent breach involving major telecom carriers (AT&T, Verizon, T-Mobile), discussing how hackers exploited outdated Cisco routers to access sensitive wiretap systems and target political figures.
      https://techcrunch.com/2024/11/14/us-confirms-china-backed-hackers-breached-telecom-providers-to-steal-wiretap-data/

      3:56 – 4:33 – Implications for Everyday Users  

      Joe explains the importance of encrypted communication apps like iMessage, WhatsApp, and Signal, highlighting vulnerabilities in text messaging protocols between iPhone and Android users.

      4:33 – 6:09 – Best Practices for 2FA  

      The hosts emphasize moving away from SMS-based two-factor authentication and adopting authenticator apps or phishing-resistant methods like hardware keys.
      https://techcommunity.microsoft.com/blog/identity/its-time-to-hang-up-on-phone-transports-for-authentication/1751752

      6:25 – 8:55 – Protecting Personal Accounts  

      Larry and Joe discuss practical ways for regular users to improve password security, including using randomized passwords, password managers, and even a physical password vault.

      9:04 – 10:29 – The Pros and Cons of Password Managers  

      Joe explores the trade-offs between web-based solutions like LastPass and local password safes https://pwsafe.org/ secured with hardware keys from Yubico https://www.yubico.com/product/yubikey-5-series/yubikey-5c-nfc/, offering insights into selecting the right solution for your needs.

      10:30 – 12:38 – VPNs and DNS Privacy  

      Joe delves into VPNs, DNS encryption, and how they protect user privacy, while explaining why these measures are essential for blocking ISPs from selling your data to advertisers.
      https://en.wikipedia.org/wiki/DNS_over_HTTPS

      12:39 – 14:54 – Guarding Against Scams  

      Larry shares personal stories of family members targeted by scams, prompting tips from Joe on spotting phishing attempts, verifying suspicious emails, and avoiding QR code traps.

      14:54 – 16:37 – The Wild West of the Internet  

      The conversation turns philosophical as the hosts discuss the current state of online security and the challenges of protecting vulnerable users, including the elderly, from relentless cybercriminals. Reminds me of "The Beekeeper" movie
      https://www.imdb.com/title/tt15314262/

      16:37 – 17:55 – QR Code Scams in the Real World  

      Joe uncovers the risks of QR code fraud, including fake stickers in restaurants or parking meters and malicious links sent in packages, and how to avoid falling victim to these scams.
      https://www.instagram.com/cybersecuritygirl/reel/DCaetPtuBIw/

      18:17 – 20:33 – Simple Security Steps for Everyone  

      Larry asks Joe for his top advice for everyday users, resulting in actionable steps like maintaining unique passwords for every account and writing them down in a secure password book.

      20:33 – 21:50 – Credential Stuffing Explained  

      Joe explains the mechanics of credential stuffing, how hackers automate attacks, and why using different passwords for every account is critical.
      https://en.wikipedia.org/wiki/Credential_stuffing

      21:50 – 22:09 – Planning for the Future  

      Joe reflects on how maintaining a secure and accessible password book can help families manage accounts after a loved one’s passing, underscoring the value of preparedness.

      21 min
    • Episode 26 - From Film to Firewall: Danny's Journey into Cybersecurity
      1. Introduction (0:00)

         - Joe and Larry discuss the episode's focus and introduce Dan Pestolesi.

       

      1. Danny's Background and Interests (0:30)

         - Danny talks about his casual streaming experience (0:52)

         - Story about Danny's dad streaming volleyball matches (1:25)

       

      1. Educational Journey (3:31)

         - Danny's double major in Cinema and Computer Science (3:37)

         - Transition from film to computer science and cybersecurity (6:39)

       

      1. Sports and Team Dynamics (10:45)

         - Importance of sports in Danny's development (12:05)

         - Comparing sports and cybersecurity teamwork (13:30)

       

      1. Danny's Career Transition (14:52)

         - Initial struggles and career decisions post-graduation (16:10)

         - Moving from corporate sales to school district IT (17:22)

         - Starting a part-time IT business (18:28)

       

      1. Interest in Cybersecurity (19:01)

         - Developing interest through classes and projects (19:15)

         - Fascination with the Stuxnet virus (21:21)

       

      1. Key Projects and Skills (22:38)

         - Explanation of MPI Angels and Devils project (24:21)

         - Importance of multithreaded processing and game theory (25:02)

       

      1. Certifications and Career Growth (26:40)

         - Value of Network+ and Security+ certifications (27:16)

         - Future plans for certifications (28:08)

       

      1. Job Interviews and Company Fit (27:47)

         - Experience with a 2.5-hour interview (28:25)

         - Importance of cultural fit and team dynamics (30:05)

       

      1. Networking Skills in Cybersecurity (36:01)

          - Larry's educational background in networking (36:08)

          - Real-world application of networking skills (37:00)

       

      1. Teamwork and Communication (38:32)

          - Story about identifying a malicious IP address (38:47)

          - Importance of collaboration in cybersecurity (39:13)

       

      1. Advice for Aspiring Cybersecurity Professionals (40:29)

          - Skills that helped Larry transition into cybersecurity (42:08)

          - Recommendations for learning and certifications (42:26)

          - Using resources like TryHackMe and Udemy (42:48)

       

      1. The Role of Documentation (48:30)

          - Importance of taking notes and reading manuals (48:44)

          - Using AI tools to assist with learning (46:19)

       

      1. Conclusion (52:01)

          - Final thoughts and encouragement for listeners

          - Invitation to connect and learn more about the field

       

      Call to Action:

      - Join the cybersecurity field! Get started for free at https://KC7cyber.com

      - Connect with the KC7 community on Discord! 

      53 min
    • Episode 25 - Unleashing Cyber Potential: The KC7 Journey with Simeon Kakpovi and Greg Schloemer

      Episode Highlights:

       

      Introductions (0:00)

      Simeon Kakpovi’s background (0:52)

      Gregory Schloemer’s background (3:01)

      Larry's Journey to Cybersecurity (5:20)

       

      Transition from sports and coaching to cybersecurity

      Role of faith and mentorship

      Meeting and Partnership (7:08)

       

      How Joe and Larry met

      Similar missions and goals

      KC7 Overview (8:10)

       

      Introduction to KC7 and its impact

      Simeon’s story and vision for KC7 (9:22)

      Development of KC7 (11:38)

       

      Greg’s involvement and development process

      Challenges and successes in creating KC7

      KC7 in Action (12:57)

       

      Demonstration of KC7 platform and features

      Tips and tricks for using KC7 effectively (16:46)

      Expansion and future goals for KC7 (18:14)

      KC7 Summer Camp (19:24)

       

      Overview of the summer camp for students

      Success stories and impact on students

      Generating Realistic Data for KC7 (22:30)

       

      Techniques for creating realistic cybersecurity data

      Use of AI in data generation (23:26)

      Interactive Demo: Creating a Scenario (26:40)

       

      Step-by-step demo of generating a threat scenario with AI

      Explanation of threat actor behaviors and data patterns (31:01)

      Future of KC7 and AI Integration (33:46)

       

      Plans for scaling and improving KC7 with AI

      Vision for automating question generation (34:03)

      Community and Feedback (36:04)

       

      Importance of community support and feedback

      Success stories from KC7 users (38:32)

      Conclusion (39:48)

       

      Final thoughts and appreciation

      Invitation to join the KC7 community https://kc7cyber.com/ and connect on Discord https://discord.com/invite/TmgCUnrArT

      41 min
    • Episode 24 - 12 months later, Larry is still thriving as a SOC Analyst!

      Episode Highlights:

       

      1. Introduction (0:00)

         - Hosts: Joe Stocker and Larry Lishey

         - Larry's new role as a SOC Analyst

       

      1. Larry's Journey to Cybersecurity (0:38)

         - Transition from warehouse management to cybersecurity

         - Motivations and inspirations (1:06)

         - Role of formal education and certifications (4:22)

         - Key learning experiences and helpful resources

       

      1. Day-to-Day as a SOC Analyst (2:23)

         - Typical daily tasks and responsibilities

         - Working with Microsoft Sentinel and other security tools (3:23)

         - The importance of thorough incident investigation

       

      1. Challenges and Rewards (10:00)

         - Initial challenges and overcoming nerves

         - The pressure and importance of accurate incident triage (11:06)

         - Rewarding aspects: customer satisfaction and team support (21:26)

       

      1. Mentorship and Team Dynamics (12:07)

         - The role of mentors in Larry's growth

         - Advice for new SOC analysts: ask questions, find a mentor

         - Team structure and dynamics within the SOC (19:08)

       

      1. Professional Growth and Skills Development (13:36)

         - Key skills and knowledge areas developed over 12 months

         - Specific incident analysis and forensics experiences (14:32)

         - Learning and growth through practical experiences and mentorship

       

      1. Career Transition and Personal Impact (18:52)

         - Life changes from the career transition

         - Balancing work and personal life, including gym routines (29:55)

         - Benefits of remote work and its dynamics

       

      1. Podcast Experiences (31:41)

         - Notable guests and influential conversations (31:57)

         - Favorite moments and topics covered (32:57)

         - Future aspirations for the podcast: more day-to-day SOC operations, specific scenarios

       

      1. AI and Cybersecurity (34:45)

         - Joe's thoughts on AI's impact on cybersecurity

         - Microsoft's Copilot for Security (34:56)

         - Broader societal implications of AI, including deep fakes and cybercrime

       

      1. Conclusion (39:48)

          - Final thoughts and encouragement for listeners

          - Invitation to connect and learn more about the field

       

      Resources:

      - KC7 Cybersecurity Game: https://kc7cyber.com/

      - Education and certification programs  https://www.mycomputercareer.edu/

      - Connect with Larry on LinkedIn https://www.linkedin.com/in/lawrence-lishey-30942020/

      41 min
    • Episode 23 - Larry gets his first job in cybersecurity!

      This is a pretty big deal! After 3 years of studying, Larry is now a SOC Analyst for Joe's company, Patriot Consulting. Joe recently launched a service for medium sized organizations that monitors for security alerts. 

      In this episode, Larry shares his experience thus far and gives some tips for those just beginning the journey. 

      16 min
    • Episode 22- Final Episode! Former Police Officer and IT Pro seeks dream job in cybersecurity

      In the final episode of this series, Joe and Larry discuss their new YouTube channel where all future episodes will be hosted. Please subscribe and follow us there!

      https://www.youtube.com/channel/UCJsqpIC4GSpNwIWTvbSt2rQ

      The advantage of moving to YouTube is that Joe will be able to share his computer screen with Larry to help him gain additional hands on training. 

      In this episode, Joe talks to former police officer Doug Roberts. Like Larry, Doug is currently working in Information Technology but seeking a full time position as a Security Operations Center (SOC) Analyst. 

      Doug has three college degrees including an associates degree in networking, a bachelor's degree, and a master's degree in Cybersecurity. Additionally, Doug has several cybersecurity certifications (Security+, CySA+, CSAP) and he is working towards the CISSP. Despite 6 years of IT experience, degrees and certifications, Doug has found it difficult to land his dream job in cybersecurity. Let's help him out!!  If you know a hiring manager or a company that may be hiring, Doug can be reached on LinkedIN (here).

      50 min
    • Episode 21 - Joe Published a book! ”Securing Microsoft 365”

      Larry completes the "Certified Ethical Hacker" course and then Larry asks Joe about the new book he published "Securing Microsoft 365" available on Amazon https://www.amazon.com/Securing-Microsoft-365-Joe-Stocker/dp/1956630015/ref=sr_1_1?crid=1U874UDJKI0A3&keywords=securing+microsoft+365&qid=1653877474&sprefix=securing+micro%2Caps%2C125&sr=8-1

      47 min
    • Episode 20 - The 25th Anniversary of DDoS with Pankaj Gupta from Citrix

      In this episode we discuss the 25th anniversary of the first DDoS (Distributed Denial of Service) and why this cybersecurity threat is a tricky one to solve. 

      00:00 to 2:00 Intro to Pankaj Gupta (@PankajOnCloud,CITRIX)

      Pankaj leads product and solutions marketing and go to market strategy for cloud, application delivery and security solutions at Citrix. He advises CIOs and business leaders for technology and business model transitions. In prior roles at Cisco, he led networking, cybersecurity and software solution marketing.

      2:20 The 25th anniversary of the first Denial of Service attack against Panix, an Internet Service Provider (1996) (https://en.wikipedia.org/wiki/Denial-of-service_attack#Distributed_attack)

      25 years later, the largest DDoS attack ever recorded targeted  Russian ISP Yandex (https://www.cpomagazine.com/cyber-security/russian-internet-giant-yandex-wards-off-the-largest-botnet-ddos-attack-in-history/). Pankaj notes how this was exactly 25 years later to the month.

      3:15 What is a DDoS Attack? 1) Connection overload 2) Volumetric like ICMP flood 3) Application Layer 

      5:20 Coinminer as an example of Denial of Service when CPU is exhausted

      6:00 Why are we still talking about DDoS 25 years later? Pankaj states that they are now easier than ever to perform. 

      7:00 Larry asks about the connection between ransomware and DDoS

      9:00 Pankaj describes how the motivation for DDoS has shifted from hacktivism to financial motivation 

      9:30 Joe asks how much it costs for an attacker to operate 

      10:00 Pankaj explains that unskilled attackers with access to the Dark web can orchestrate attacks

      11:45 Joe discusses how many attackers target healthcare despite how this hurts people

      12:45 Pankaj discusses that while federal laws exist, very few are prosecuted for DDoS attacks.

      13:50 Larry asks whether businesses are paying the ransom 

      14:15 Pankaj says paying the ransom is never recommended. Instead, Pankaj recommends investing in DDoS protection solutions

      15:25 Joe asks whether tools exist to quantify costs for downtime to justify the expense of DDoS prevention solutions. 

      16:30 Pankaj explains how it is not just the economic impact of downtime that is to be factored into the equation but also the damage to reputation by losing customer’s trust. 

      17:30 Pankaj describes three trends that will cause DDoS attacks to increase in the future (things will get worse rather than better). This is due to increased bandwidth for 5G, exponential growth of IoT devices, and the improved computation power. 

      18:30 What is IoT? (Internet of Things). This is any device that has an internet connection such as a Nanny Camera, home router, or NEST Thermostat. Bad actors exploits vulnerabilities to transform these devices into a “BOT Network” that the attackers can then use in mass quantity against a single target. This forms the source for the DDoS attacks. All of these devices combined will send packets to the victim website. 

      20:50 What solutions exist for DDoS? Joe explains how he has solved DDoS historically using services from CloudFlare. 

      22:00 Joe explains how he configured DDoS protection by configuring DNS, and the weakness when attackers discover the direct IP using OSINT

      23:15 Joe asks Pankaj how does Citrix compare with competitors 

      23:35 Pankaj describes four key criteria when selecting a DDoS solution. 1) The solution should protect against a variety of types of DDoS attacks 2) Can the solution scale? As DDoS attacks increase in size 20% Year over Year (it’s expected to be 3 terabits). 3) The advantage of a cloud-based solution is that it can auto-scale in bandwidth whereas an on-premises DDoS solution cannot guard against bandwidth saturation. 

      25:50 Joe asks Pankaj if Citrix uses its own data centers (does it have exposures if data centers like Google, Amazon or Microsoft). Pankaj describes the Citrix solution as having the scale to handle 12 terabits of scrubbing across multiple points of presence (pop). 

      29:00 Pankaj describes two types of DDoS solutions, Always-ON, or On-Demand.  If you are an e-commerce website then Always-on may make more sense even though it costs more than on-demand because every minute that you cannot sell your products will lose money. 

      31:00 DDoS attacks can be a diversion tactic to distract IT and SECOPS teams so that the attackers can perform other types of attacks such as financial fraud (Wire Fraud, SWIFT, etc)

      32:40 Larry asks: What is the difference between a buffer overflow and DDoS? Pankaj explains that a buffer overflow could be used as a type of DDoS since it could impact the availability of the service.

      34:00 Joe describes how DDoS strikes at the heart of one of the three components of the CIA Triad “Confidentiality, Integrity, and Availability.” 

      35:00 For businesses interested in learning more about Citrix solutions, Pankaj recommends using this contact form on the Citrix website: https://www.citrix.com/contact/form/inquiry/

      36:30 Joe asks what market is Citrix chasing: Small Business, Mid-Market or Enterprise? Pankaj responds that all businesses need DDoS protection, and how cloud-based solutions are easier to implement. 

      DISCLAIMER: Larry and Joe received no compensation in any form from anyone for our Podcast. This is a "hobby" podcast - we don't even have advertisements! 

      39 min

    About Cybersecurity 101 with Joe and Larry

    From the publisher's feed

    Joe Stocker, CEO of a Microsoft Consulting company (”www.PatriotConsultingTech.com”) and author of the bestselling book on Amazon ”Securing Microsoft 365”, mentors his friend Larry on his journey to a career in Cybersecurity.