Full Metal Packet Cybersecurity Podcast

Cybersecurity Threat Modeling: A Navy Officer’s Playbook for When Patching Fails


Listen Later

How should security teams manage vulnerabilities when patching is impossible or incomplete? Ben Lipczynski explains contextual threat modeling, legacy-system risk, and defense in depth.

Security leaders will learn how to identify critical systems, reduce hundreds of scan findings to meaningful actions, and prepare around operational consequences.

Ben is the Director of Security and Regulatory Services at Origina and a former British Royal Navy officer with 12 years operating nuclear submarines and global networks. He brings an operator-level perspective on what separates a contained incident from a months-long operational nightmare.

He explains:

◼ Why siloed teams and poor system knowledge cause more breaches than sophisticated attacks ever do

◼ Why upgrading to the latest version often introduces more vulnerabilities than it removes

◼ How 700 scan findings came down to 20 real actions after proper contextual analysis

◼ Why the CVE volume problem is about to get significantly worse and what to do about it

◼ Why defense in depth, not patching, is the only strategy that holds up when an attacker gets inside

Time Stamps:

(0:00) Introduction

(0:53) What corporate security teams get wrong vs. the military

(2:22) The submarine mindset: 90% training, 10% operations

(4:48) Operational clarity in the military: everyone knows the mission and their role

(6:59) Military structure vs. corporate agility — opposites or the same need?

(10:38) Why Ben left the Navy for cybersecurity

(14:32) "Take a marching pace" — thinking before acting in incident response

(18:09) The iPad water treatment plant story — OT connectivity creep in the real world

(25:30) The myth of N-minus-one: legacy doesn't mean insecure

(28:10) Open source dependency risk — 60% of vulnerabilities aren't in the core code

(31:01) Slop squatting: attackers pre-registering AI-hallucinated package names

(33:00) What to do when you can't patch — contextual risk-based defense in depth

(36:26) The patch validation problem — exploits now arrive within hours of a CVE

(44:00) Fully patched, still taken down — architecture beats updates

(51:26) Log4J case study: why deleting the library beat the patch cycle

(55:23) Practical advice for security teams managing legacy systems

(1:02:22) The CVE volume crisis — is the current patching model even tenable?

(1:07:21) Bold prediction: CVE text itself will become an attack vector for AI agents

Connect with the speakers ⬇️:

Ben Lipchinski: https://www.linkedin.com/in/benlipczynskisecurity/

Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/

Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/

Powered by Control D

...more
View all episodesView all episodes
Download on the App Store

Full Metal Packet Cybersecurity PodcastBy Control D