
Sign up to save your podcasts
Or


In Episode 69 of CYBR.SEC.CAST, hosts Michael Farnum and Sam Van Ryder sit down with Crush Security CEO Joshua Jones, CTO Josh Johnson, and JB Poindexter & Co. CISO John Barrow to explore a growing problem facing security leaders: the inability to effectively evaluate, compare, and manage cybersecurity products at scale.
SHOW NOTES:
Things Mentioned:
EPISODE 69 Timestamps:
00:00 – Introduction and Sponsor Disclosure
Michael Farnum introduces Crush Security as the episode sponsor and frames the discussion around real-world CISO challenges involving cybersecurity purchasing and vendor management.
05:00 – Joshua Jones' Cybersecurity Journey
Jones recounts entering cybersecurity during the early days of MFA, building global sales and consulting organizations, and eventually identifying inefficiencies in the reseller ecosystem that inspired Crush Security.
09:15 – Josh Johnson's Path from Digital Forensics to AI
Johnson discusses his background in computer forensics, incident response, consulting, and cybersecurity leadership before co-founding Crush Security.
11:45 – John Barrow's Evolution from Military Intelligence to CISO
Barrow explains how his nontraditional background became a leadership advantage, helping him bridge communication gaps between security teams and executive leadership.
17:00 – The Hidden Cost of Security Tool Sprawl
The group examines how organizations accumulate overlapping technologies, duplicate capabilities, and unnecessary spending while struggling to understand what they actually own.
21:30 – Why Traditional VAR Models Fall Short
Jones argues that too many reseller relationships remain transactional and fail to provide the strategic guidance security leaders need.
24:30 – Using AI to Evaluate Security Products
Johnson explains how Crush maps cybersecurity products, controls, compliance frameworks, and capabilities to help organizations identify gaps, overlaps, and alternatives.
29:00 – The Coming Explosion of Security Categories
The panel discusses how AI is enabling vendors to rapidly expand into adjacent markets, creating even more confusion for buyers evaluating security platforms.
33:30 – Crush Security's Vision for a 'Super VAR'
Jones outlines the company's vision of combining AI, security architecture, contract intelligence, and procurement guidance into a unified platform for security leaders.
35:20 – Final Thoughts
The panel closes by reflecting on why cybersecurity procurement remains largely unsolved and why data-driven decision making may finally change that reality.
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support or apply to our Scholarship Program:
Subscribe to the podcast:
In this episode:
Cybersecurity has built its learning model around breaches, but as Wendy Nather explains, the real value lies in the incidents that almost happened. In this CYBR.SEC.CAST episode with hosts Michael Farnum and Sam Van Ryder, she makes the case for shifting focus to near-misses: the attacks stopped by a single decision, control, or moment of awareness. These unseen saves reveal how defenses actually work in real time, yet they rarely get shared due to trust, legal, and cultural barriers. Until the industry starts capturing and learning from these quieter wins, it will continue optimizing for failure instead of understanding success.
SHOW NOTES:
Things Mentioned:
EPISODE 66 Timestamps:
Do you have a question for the hosts? Reach out to us at [email protected]
In this episode, hosts Michael Farnum and Sam Van Ryder sit down with Valerie Moon, Executive Director of the Institute for Critical Infrastructure Technology (ICIT) for a wide-ranging discussion about cybersecurity policy, workforce development, and the growing threats facing critical infrastructure.
Things Mentioned:
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support CYBR.SEC.Careers Non-Profit Efforts
Apply to the CYBR.SEC.Careers Scholarship
Listen to our other show:
Thank you to our Media Partners:
CYBR.SEC.CON. and OT.SEC.CON.
CYBR.SEC.CON. and CYBR.HAK.CON.
Dragos CEO and U.S. National Guard Lt. Col. Rob Lee joins hosts Michael Farnum and Sam Van Ryder to discuss why he returned to military service, the growing cyber threats to critical infrastructure, and the role exercises like Cyber Fortress play in preparing both government and private sector operators for real-world cyber incidents.
SHOW NOTES:
Things Mentioned:
Episode 64 Timestamps:
6:48 – Why Lee returned to military service
Lee explains how calls from government and military leaders prompted him to return to the National Guard to help address unresolved questions around defending operational technology (OT) during conflict.
9:33 – Role in the 91st Cyber Brigade
Lee describes his position as executive officer and the mission of the Army National Guard’s cyber brigade.
14:52 – Cyber Fortress exercise explained
Lee walks through the origins of Cyber Fortress and how it evolved from a state-level exercise into a broader operational technology training environment.
17:53 – How Cyber Fortress works
The exercise combines training, red-team simulations, and participation from infrastructure operators to practice responding to real OT cyber incidents.
20:10 – Cyber conflict and civilian infrastructure
Lee discusses the growing risk of state actors targeting hospitals, utilities, and other civilian infrastructure.
24:23 – Cyber attacks that lead to loss of life
Lee argues the cybersecurity community must acknowledge that cyber operations have already contributed to real-world deaths.
27:04 – The role of cyber in modern warfare
The discussion explores how cyber capabilities are increasingly intertwined with traditional military conflict.
Do you have a question for the hosts? Reach out to us at [email protected]
In this episode of CYBR.SEC.CAST, the hosts sit down with Dr. Kelley Misata, CEO of Sightline Security, to explore the often-overlooked cybersecurity challenges facing nonprofit organizations. Misata shares her powerful origin story — how a personal experience with cyberstalking led her to pursue a PhD in cybersecurity and ultimately launch a nonprofit dedicated to helping mission-driven organizations assess and improve their security posture.
She also discusses the misconceptions surrounding nonprofit cybersecurity, the communication gap between security professionals and nonprofit leaders, and why “nonprofit” is simply a tax designation, not a reflection of an organization’s sophistication or risk exposure.
Misata also explains how Sightline Security’s Kickstart program, built around a simplified interpretation of the NIST Cybersecurity Framework, helps nonprofits identify practical security priorities and build sustainable cyber resilience.
SHOW NOTES:
Things Mentioned:
Website for Sightline Security: https://sightlinesecurity.org/
Kickstarter program: https://sightlinesecurity.org/kickstart
Upcoming CYBR.SEC.Community events: https://www.cybrsecmedia.com/conference/
CYBR.SEC.Careers: https://www.linkedin.com/company/cybr-sec-careers/about/ fundraisers:
Cards for a Cause: https://www.linkedin.com/posts/cybr-sec-careers_cybrseccareers-nonprofit-cybersecurity-activity-7436794892787359744-v4Cz
CYBR CLAY SHOOT: https://www.linkedin.com/posts/cybr-sec-careers_cybrclayshoot-cybersecurity-cybercareers-activity-7435353518951084033-1iw9
Proceeds support CYBR.SEC.Careers mission is to build a strong, diverse workforce by providing career exposure, access to education and certifications, and mentorship for students and veterans pursuing careers in cybersecurity.
EPISODE 63 Timestamps:
4:14 – Kelley Misata’s origin story
Dr. Misata explains how she unexpectedly entered cybersecurity after being the victim of cyberstalking while working at a technology company.
5:25 – Turning a personal crisis into a cybersecurity PhD
Instead of retreating from the experience, Misata pursued a PhD in cybersecurity to better understand how the technology behind the attacks worked.
6:09 – Early work with the Tor Project and open source security
Her research journey led to working with the Tor Project and later serving as president of the Open Information Security Foundation.
6:27 – Researching cybersecurity risks facing nonprofits
Misata describes her doctoral research studying nonprofits that assist domestic violence and human trafficking victims, focusing on how organizations protect both their operations and the people they serve.
8:44 – The moment she realized nonprofits cared about cybersecurity
Her dissertation survey received far more responses than expected, revealing that nonprofit organizations were eager to engage on cybersecurity issues.
9:00 – From dissertation to mission: founding Sightline Security
Encouraged by colleagues, Misata launched Sightline Security in 2018 to help nonprofits understand and assess their cybersecurity posture.
12:00 – Debunking the “security poverty line” myth
Misata explains that nonprofits aren’t necessarily under-resourced—they simply operate under different financial and operational models than traditional businesses.
14:24 – The communication gap between security pros and nonprofits
She shares an example where security practitioners assumed nonprofits lacked basic controls, but the real issue was simply a language mismatch around security terminology.
16:09 – The wide range of nonprofit cybersecurity maturity
Nonprofits span the entire spectrum—from small volunteer organizations to large institutions with enterprise-level infrastructure and IT teams.
19:57 – Why “nonprofit” is just a tax designation
Phil and Michael are joined by Kevin Pentecost, Information Security Director at SMP and co-host of the Cyber Distortion podcast, and co-host Jason Papillon, Founder & CEO of Cipher Nova.
This week Michael and Sam are talking to Bytewhisper CEO and previous HOU.SEC.CON. speaker, John Dickson! They discuss his journey from the Air Force into cybersecurity, his long-standing passion for application security, and why AI security testing isn’t fundamentally separate from traditional penetration testing.
Things Mentioned:
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support CYBR.SEC.Careers Non-Profit Efforts
Apply to the CYBR.SEC.Careers Scholarship
Subscribe to the podcast:
Listen to our other show:
In this episode:
In this episode, Michael and Sam sit down with Dr. Dustin Sachs (DCS), CEO and founder of Psybercog Labs, to explore why humans - not technology - are often the limiting factor in cybersecurity. They dive into cognitive overload, bias, and decision fatigue, and how these hidden forces shape security outcomes. Dustin also shares his unconventional path into cyber and explains how Psybercog Labs uses behavioral science to uncover decision-making blind spots and help organizations execute smarter, more effective security strategies.
Things Mentioned:
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support CYBR.SEC.Careers Non-Profit Efforts
Apply to the CYBR.SEC.Careers Scholarship
Listen to our other show:
In this episode:
This week, Michael and Sam chat with educator, founder, and OT.SEC.CON. opening keynote speaker Mike Holcomb! They discuss his free, in-person training coming up on March 31 in Houston, how - like many others - the movie War Games played a role in his journey into the cybersecurity industry, and how his focus has shifted toward OT/ICS security education.
Things Mentioned:
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support or apply to our Scholarship Program:
Subscribe to the podcast:
Listen to our other show:
In this episode:
Michael and Sam are talking to the new VP and Editor-in-Chief of CYBR.SEC.Media, Bill Brenner! They discuss his extensive 20+ year career journey from traditional journalism to cybersecurity media, the importance of supporting the mental health of cyber defenders, and his vision for CYBR.SEC.Media.
Things Mentioned:
Do you have a question for the hosts? Reach out to us at [email protected]
Keep up with CYBR.SEC.CON.:
Keep up with CYBR.SEC.Media:
Check out our Conferences and Events:
Support or apply to our Scholarship Program:
Subscribe to the podcast:
In this episode:
From the publisher's feed
Join CYBR.SEC.CON. cofounders Michael and Sam each week as they chat with conference speakers about the latest topics and trends in the cybersecurity space.