Exploring Information Security - Exploring Information Security

Exploring Information Security - Exploring Information Security

By Timothy De BlockTechnology
Download on the App Store

Exploring Information Security - Exploring Information Security episodes

  • when machines take over the world with Jeff Man
    Summary:

    In this engaging episode of Exploring Information Security, host Timothy De Block sits down with cybersecurity expert Jeff Man. They dive into Jeff's recent experiences at the RSA Conference, his seasoned and sometimes "grumpy old man's perspective" on the pervasive topic of AI, and what he's looking forward to in upcoming speaking engagements. The conversation explores the ever-evolving landscape of cybersecurity, the challenges and hype surrounding new technologies, and the enduring principles of security that remain constant despite technological shifts.

    What You'll Learn:

    • Key takeaways and observations from the RSA Conference, including attendance figures and vendor extravagances.

    • Jeff Man's unique perspective on Artificial Intelligence, separating hype from potential impact.

    • The recurring themes in cybersecurity, highlighting how fundamental problems persist across different technological eras.

    • Insights into the risks and limitations of AI, including its potential for misinformation and Jeff's personal skepticism.

    • A first-hand account of riding in a Waymo self-driving car and reflections on autonomous technology.

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    When Will Machines Take Over The World?
    Jeff Man
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    53 min
  • How to Disconnect From Cybersecurity
    Summary:

    In this heartfelt episode of Exploring Information Security, we sit down with Elizabeth Eggert-Guerrant to talk about the importance of disconnecting from the always-on world of cybersecurity. Elizabeth shares her personal journey, which began with a cruise to Antarctica and led to profound revelations about burnout, digital overload, and the power of being present.

    Drawing from her experience in leadership and her passion for mental health, Elizabeth unpacks how the culture of constant connectivity in cybersecurity—and life in general—can affect our well-being. From sneaking work emails in the bathroom on vacation to re-learning the value of quiet moments and real human connection, this episode explores what it means to truly step away and reset.

    Whether you're an industry veteran or just getting started, Elizabeth offers advice on setting boundaries, recognizing burnout in yourself and your team, and creating space for reflection in a high-pressure industry.

    What You’ll Learn
    • Why disconnecting is critical for mental health in cybersecurity

    • How to identify burnout in yourself and others

    • The value of setting daily rituals and boundaries

    • The role of leadership in fostering mental well-being

    • The pressure of “doing more” on social media—and how to step back

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    How to Disconnect From Cybersecurity
    Elizabeth Eggert-Guerrant
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    38 min
  • How to Implement a Content Security Policy (CSP)
    Summary:

    In this episode of the Exploring Information Security podcast, host Timothy De Block sits down with Jason Gillam, long-time developer turned penetration tester and partner at Secure Ideas. The two dive into the real-world value of Content Security Policy (CSP) and why it remains one of the most underutilized tools in web application defense.

    Jason shares insights from his upcoming talk at ShowMeCon 2025, including surprising statistics from his analysis of over 750,000 domains, where he found that most CSPs are either missing or misconfigured. He breaks down how CSP works, its role in protecting against injection attacks, and strategies for implementing it properly using nonces, hashes, and report-only modes.

    They also discuss:

    • The challenges of educating developers on CSP

    • CSP vs. WAF and where each fits in the security stack

    • How AI and CI/CD can support secure CSP deployment

    • The importance of building security into code rather than bolting it on later

    Whether you're a developer, security professional, or somewhere in between, this episode offers practical and actionable advice on improving your web application security posture.

    Mentioned Resources:
    • OWASP CSP Cheat Sheet

    • Google CSP Evaluator

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    How to Implement a Content Security Policy (CSP)
    Jason Gillam
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    46 min
  • how to monitor the inner workings of a cybercriminal organization
    Summary:

    What does it take to monitor the inner workings of ransomware gangs? In this episode, Matthew Maynard shares his firsthand experience infiltrating cybercriminal communities to gather valuable threat intelligence. From learning the lingo to navigating criminal hierarchies, Matthew sheds light on the surprising structure and behavior of ransomware operators. We discuss the importance of operational security, the surprising transparency of cybercriminal forums, and how researchers can play a critical role in disrupting ransomware infrastructure.

    Topics Discussed:
    • How Matthew got started monitoring cybercriminal groups

    • The business model and hierarchy of ransomware gangs

    • Use of AI, insider threats, and criminal marketing tactics

    • Tools and platforms used by cybercriminals (Tor, Tox, Telegram, etc.)

    • Lessons learned from forums, breach leaks, and failed infiltration attempts

    • The value of open-source intelligence in tracking threat actors

    • Why reputation matters—both for threat actors and researchers

    • Operational safety tips for researchers entering dark web spaces

    Guest Bio:

    Matthew Maynard is a cybersecurity professional and threat researcher who specializes in tracking the behavior of ransomware gangs and cybercriminal forums. He shares his insights through articles on Hacker Noon and speaks regularly at conferences like ShowMeCon.

    Links & Resources:

    • Ransomware.live

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    How to Monitor the Inner Workings of a Cybercriminal Organization
    Matthew Maynard
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    48 min
  • Gamifying Your Incident Response Playbook with Anushree Vaidya
    Summary:

    In this episode, Tim speaks with Anushree Vaidya about her upcoming presentation at ShowMeCon: Ransomware Rampage: Gamifying Your Incident Response Playbook. Anushree shares her passion for making cybersecurity training more interactive, emphasizing how gamifying the ransomware incident response process can transform traditional playbook exercises into dynamic, collaborative experiences.

    Anushree explains how ransomware-specific playbooks differ from general incident response plans, the benefits of hands-on exercises for diverse teams, and how organizations of all sizes can adapt her training approach internally. She also discusses overlooked early indicators of ransomware attacks, communication challenges between technical teams and leadership, and how proactive preparation can significantly reduce the pain of an incident.

    Topics Discussed
    • Why ransomware-specific playbooks matter

    • Turning incident response into a team-based, gamified learning experience

    • Building ransomware exercises that include IT, security, PR, HR, and leadership teams

    • Common gaps in ransomware detection and proactive preparation

    • Coaching technical teams on communication during incidents

    • Using AI to stay up to date with threat intelligence and reports

    • Tailoring incident response playbooks for different industries and organizational sizes

    Key Takeaways
    • Participants will leave Anushree’s presentation with a customizable ransomware playbook and tools to take back to their organizations.

    • Gamified incident response exercises promote better communication, quicker learning, and stronger collaboration across teams.

    • Early detection and proactive measures like business impact analysis are critical to minimizing ransomware damage.

    • Communication planning—including legal, internal, and external messaging—is essential for effective response.

    Connect with Anushree
    • LinkedIn: Anushree Vaidya

    • Women in CyberSecurity (WiCyS) Midwest Chapter Member

    Anushree is passionate about connecting with others in cybersecurity, particularly in the Midwest region. Her DMs are always open for those who want to discuss ransomware, threat hunting, incident response, and cybersecurity strategy.

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    Gamifying Your Incident Response Playbook
    Anushree Vaidya
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    32 min
  • What is the Human Behavior Conference (HUBE)?
    Summary:

    Chris Hadnagy returns to the podcast to discuss the upcoming Human Behavior Conference (HUBE CON), a unique event blending psychology, neuroscience, and cybersecurity. Hosted in Orlando, FL, the 2025 conference focuses on the theme of "Influence and InfoSec"—with a diverse speaker lineup covering everything from nonverbal communication to neurodiversity in the cybersecurity field.

    In this episode, Chris and Tim dive into how the conference is designed to foster deep learning and genuine human connection. They discuss how the sessions go beyond standard talks with hands-on trainings, interactive discussions, and practical takeaways for both cybersecurity professionals and those outside the industry. Chris also highlights how the conference has evolved over the years, the importance of accessibility for introverts, and what attendees can expect from this year's upgraded format.

    Chris also shares updates on the Innocent Lives Foundation (ILF), a nonprofit focused on helping law enforcement identify and stop child predators, and touches on cutting-edge work at Social-Engineer, LLC—including new services involving deepfake social engineering simulations.

    Discussion Points:

    • How the Human Behavior Conference bridges behavioral science and cybersecurity

    • Creating a conference you want to attend

    • Balancing science and practicality in session content

    • Building a community for introverts and extroverts alike

    • Why audience interaction creates stronger learning moments

    • The expanding role of AI in podcast production and social engineering

    • A preview of topics and speakers at this year’s HUBE CON

    • Updates from the Innocent Lives Foundation and Social-Engineer, LLC

    Resources Mentioned:

    • Human Behavior Conference (HUBE CON)

    • Innocent Lives Foundation

    • Social-Engineer, LLC

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    What is the Human Behavior Conference (HUBE)
    With Chris Hadnagy
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    33 min
  • [RERELEASE] How to deal with the "experience required" paradox

    In this exciting edition of the Exploring Information Security (EIS) podcast, I talk with Jerry Bell about overcoming the "experience required" requirement on infosec job postings.

    Jerry recently had a blog post on his site (malicious link) titled, "Dealing With The Experience Required Paradox For Those Entering Information Security." It is a wonderful article with actionable items on what people can do to overcome that stipulation on job postings. Jerry is also a co-host for the Defensive Security podcast.

    In this episode we talk about:

    • Activities that can be done to overcome "experience required"

    • Who is does this requirement apply

    • Our own personal experiences and suggestions for overcoming the paradox

    How to deal with the "experience required" paradox
    With Jerry Bell

    [RSS Feed] [iTunes]

    31 min
  • [RERELEASE] How to ZAP your websites

    Originally posted on September 11, 2014.

    In the seventh edition of the Exploring Information Security (EIS) podcast, I talk with Zed Attack Proxy (ZAP) creator and project lead Simon Bennetts.

    Simon is the project lead for ZAP an OWASP Open Web Application Security Project. He has a developer background and originally built the tool to help developers build better applications. The tool was so good that it caught the eye of the security community and is now used by developers, people just getting into security and veteran pen testers. You can follow him on Twitter @psiinon and find out more on the tool by going to the project site on OWASP.

    In this interview we cover:

    • What is ZAP and how did the project get started?

    • Who should utilize ZAP?

    • What skill level is need to start using ZAP?

    • Where should ZAP be used?

    • How you can get involved in the project.

    How to ZAP your websites
    With Simon Bennetts

    [RSS Feed] [iTunes]

    18 min
  • [RERELEASE] How to ZAP your websites (Copy)

    Originally posted on September 11, 2014.

    In the seventh edition of the Exploring Information Security (EIS) podcast, I talk with Zed Attack Proxy (ZAP) creator and project lead Simon Bennetts.

    Simon is the project lead for ZAP an OWASP Open Web Application Security Project. He has a developer background and originally built the tool to help developers build better applications. The tool was so good that it caught the eye of the security community and is now used by developers, people just getting into security and veteran pen testers. You can follow him on Twitter @psiinon and find out more on the tool by going to the project site on OWASP.

    In this interview we cover:

    • What is ZAP and how did the project get started?

    • Who should utilize ZAP?

    • What skill level is need to start using ZAP?

    • Where should ZAP be used?

    • How you can get involved in the project.

    [RSS Feed] [iTunes]

    18 min
  • How Do Ransomware Gangs Work?
    Summary:

    In this episode of Exploring Information Security, we dive deep into the dark, complex world of ransomware gangs with returning guest Kyle Andrus. Drawing on leaked chat logs, real-world cases, and extensive incident response experience, Kyle helps us understand the internal operations, motivations, and evolution of these cybercriminal organizations.

    We explore how ransomware gangs are structured like modern corporations—with developers, access brokers, negotiators, HR, and even customer support. Kyle also shares insights into how these gangs are adapting to legal pressure, sanctions, and the cybersecurity community’s defensive advancements.

    Topics covered:
    • The organizational structure of ransomware gangs

    • Ransomware-as-a-Service (RaaS) models and profit sharing

    • Affiliate programs, access brokers, and laundering tactics

    • The impact of geopolitics on ransomware operations

    • Creative pressure tactics, including triple extortion and SEC complaints

    • The role of insider threats and chat log leaks (e.g., Conti)

    • Use of AI by defenders and attackers

    • The evolving response of law enforcement and regulation

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    How do ransomware gangs work?
    Kyle Andrus
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    1 hr

About Exploring Information Security - Exploring Information Security

From the publisher's feed

The Exploring Information Security podcast interviews a different professional each week exploring topics, ideas, and disciplines within information security. Prepare to learn, explore, and grow your…

More shows like Exploring Information Security - Exploring Information Security

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners