
Sign up to save your podcasts
Or


In this engaging episode of Exploring Information Security, host Timothy De Block sits down with cybersecurity expert Jeff Man. They dive into Jeff's recent experiences at the RSA Conference, his seasoned and sometimes "grumpy old man's perspective" on the pervasive topic of AI, and what he's looking forward to in upcoming speaking engagements. The conversation explores the ever-evolving landscape of cybersecurity, the challenges and hype surrounding new technologies, and the enduring principles of security that remain constant despite technological shifts.
What You'll Learn:
Key takeaways and observations from the RSA Conference, including attendance figures and vendor extravagances.
Jeff Man's unique perspective on Artificial Intelligence, separating hype from potential impact.
The recurring themes in cybersecurity, highlighting how fundamental problems persist across different technological eras.
Insights into the risks and limitations of AI, including its potential for misinformation and Jeff's personal skepticism.
A first-hand account of riding in a Waymo self-driving car and reflections on autonomous technology.
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this heartfelt episode of Exploring Information Security, we sit down with Elizabeth Eggert-Guerrant to talk about the importance of disconnecting from the always-on world of cybersecurity. Elizabeth shares her personal journey, which began with a cruise to Antarctica and led to profound revelations about burnout, digital overload, and the power of being present.
Drawing from her experience in leadership and her passion for mental health, Elizabeth unpacks how the culture of constant connectivity in cybersecurity—and life in general—can affect our well-being. From sneaking work emails in the bathroom on vacation to re-learning the value of quiet moments and real human connection, this episode explores what it means to truly step away and reset.
Whether you're an industry veteran or just getting started, Elizabeth offers advice on setting boundaries, recognizing burnout in yourself and your team, and creating space for reflection in a high-pressure industry.
What You’ll LearnWhy disconnecting is critical for mental health in cybersecurity
How to identify burnout in yourself and others
The value of setting daily rituals and boundaries
The role of leadership in fostering mental well-being
The pressure of “doing more” on social media—and how to step back
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode of the Exploring Information Security podcast, host Timothy De Block sits down with Jason Gillam, long-time developer turned penetration tester and partner at Secure Ideas. The two dive into the real-world value of Content Security Policy (CSP) and why it remains one of the most underutilized tools in web application defense.
Jason shares insights from his upcoming talk at ShowMeCon 2025, including surprising statistics from his analysis of over 750,000 domains, where he found that most CSPs are either missing or misconfigured. He breaks down how CSP works, its role in protecting against injection attacks, and strategies for implementing it properly using nonces, hashes, and report-only modes.
They also discuss:
The challenges of educating developers on CSP
CSP vs. WAF and where each fits in the security stack
How AI and CI/CD can support secure CSP deployment
The importance of building security into code rather than bolting it on later
Whether you're a developer, security professional, or somewhere in between, this episode offers practical and actionable advice on improving your web application security posture.
Mentioned Resources:OWASP CSP Cheat Sheet
Google CSP Evaluator
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
What does it take to monitor the inner workings of ransomware gangs? In this episode, Matthew Maynard shares his firsthand experience infiltrating cybercriminal communities to gather valuable threat intelligence. From learning the lingo to navigating criminal hierarchies, Matthew sheds light on the surprising structure and behavior of ransomware operators. We discuss the importance of operational security, the surprising transparency of cybercriminal forums, and how researchers can play a critical role in disrupting ransomware infrastructure.
Topics Discussed:How Matthew got started monitoring cybercriminal groups
The business model and hierarchy of ransomware gangs
Use of AI, insider threats, and criminal marketing tactics
Tools and platforms used by cybercriminals (Tor, Tox, Telegram, etc.)
Lessons learned from forums, breach leaks, and failed infiltration attempts
The value of open-source intelligence in tracking threat actors
Why reputation matters—both for threat actors and researchers
Operational safety tips for researchers entering dark web spaces
Matthew Maynard is a cybersecurity professional and threat researcher who specializes in tracking the behavior of ransomware gangs and cybercriminal forums. He shares his insights through articles on Hacker Noon and speaks regularly at conferences like ShowMeCon.
Links & Resources:
Ransomware.live
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Tim speaks with Anushree Vaidya about her upcoming presentation at ShowMeCon: Ransomware Rampage: Gamifying Your Incident Response Playbook. Anushree shares her passion for making cybersecurity training more interactive, emphasizing how gamifying the ransomware incident response process can transform traditional playbook exercises into dynamic, collaborative experiences.
Anushree explains how ransomware-specific playbooks differ from general incident response plans, the benefits of hands-on exercises for diverse teams, and how organizations of all sizes can adapt her training approach internally. She also discusses overlooked early indicators of ransomware attacks, communication challenges between technical teams and leadership, and how proactive preparation can significantly reduce the pain of an incident.
Topics DiscussedWhy ransomware-specific playbooks matter
Turning incident response into a team-based, gamified learning experience
Building ransomware exercises that include IT, security, PR, HR, and leadership teams
Common gaps in ransomware detection and proactive preparation
Coaching technical teams on communication during incidents
Using AI to stay up to date with threat intelligence and reports
Tailoring incident response playbooks for different industries and organizational sizes
Participants will leave Anushree’s presentation with a customizable ransomware playbook and tools to take back to their organizations.
Gamified incident response exercises promote better communication, quicker learning, and stronger collaboration across teams.
Early detection and proactive measures like business impact analysis are critical to minimizing ransomware damage.
Communication planning—including legal, internal, and external messaging—is essential for effective response.
LinkedIn: Anushree Vaidya
Women in CyberSecurity (WiCyS) Midwest Chapter Member
Anushree is passionate about connecting with others in cybersecurity, particularly in the Midwest region. Her DMs are always open for those who want to discuss ransomware, threat hunting, incident response, and cybersecurity strategy.
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
Chris Hadnagy returns to the podcast to discuss the upcoming Human Behavior Conference (HUBE CON), a unique event blending psychology, neuroscience, and cybersecurity. Hosted in Orlando, FL, the 2025 conference focuses on the theme of "Influence and InfoSec"—with a diverse speaker lineup covering everything from nonverbal communication to neurodiversity in the cybersecurity field.
In this episode, Chris and Tim dive into how the conference is designed to foster deep learning and genuine human connection. They discuss how the sessions go beyond standard talks with hands-on trainings, interactive discussions, and practical takeaways for both cybersecurity professionals and those outside the industry. Chris also highlights how the conference has evolved over the years, the importance of accessibility for introverts, and what attendees can expect from this year's upgraded format.
Chris also shares updates on the Innocent Lives Foundation (ILF), a nonprofit focused on helping law enforcement identify and stop child predators, and touches on cutting-edge work at Social-Engineer, LLC—including new services involving deepfake social engineering simulations.
Discussion Points:
How the Human Behavior Conference bridges behavioral science and cybersecurity
Creating a conference you want to attend
Balancing science and practicality in session content
Building a community for introverts and extroverts alike
Why audience interaction creates stronger learning moments
The expanding role of AI in podcast production and social engineering
A preview of topics and speakers at this year’s HUBE CON
Updates from the Innocent Lives Foundation and Social-Engineer, LLC
Resources Mentioned:
Human Behavior Conference (HUBE CON)
Innocent Lives Foundation
Social-Engineer, LLC
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this exciting edition of the Exploring Information Security (EIS) podcast, I talk with Jerry Bell about overcoming the "experience required" requirement on infosec job postings.
Jerry recently had a blog post on his site (malicious link) titled, "Dealing With The Experience Required Paradox For Those Entering Information Security." It is a wonderful article with actionable items on what people can do to overcome that stipulation on job postings. Jerry is also a co-host for the Defensive Security podcast.
In this episode we talk about:
Activities that can be done to overcome "experience required"
Who is does this requirement apply
Our own personal experiences and suggestions for overcoming the paradox
[RSS Feed] [iTunes]
Originally posted on September 11, 2014.
In the seventh edition of the Exploring Information Security (EIS) podcast, I talk with Zed Attack Proxy (ZAP) creator and project lead Simon Bennetts.
Simon is the project lead for ZAP an OWASP Open Web Application Security Project. He has a developer background and originally built the tool to help developers build better applications. The tool was so good that it caught the eye of the security community and is now used by developers, people just getting into security and veteran pen testers. You can follow him on Twitter @psiinon and find out more on the tool by going to the project site on OWASP.
In this interview we cover:
What is ZAP and how did the project get started?
Who should utilize ZAP?
What skill level is need to start using ZAP?
Where should ZAP be used?
How you can get involved in the project.
[RSS Feed] [iTunes]
Originally posted on September 11, 2014.
In the seventh edition of the Exploring Information Security (EIS) podcast, I talk with Zed Attack Proxy (ZAP) creator and project lead Simon Bennetts.
Simon is the project lead for ZAP an OWASP Open Web Application Security Project. He has a developer background and originally built the tool to help developers build better applications. The tool was so good that it caught the eye of the security community and is now used by developers, people just getting into security and veteran pen testers. You can follow him on Twitter @psiinon and find out more on the tool by going to the project site on OWASP.
In this interview we cover:
What is ZAP and how did the project get started?
Who should utilize ZAP?
What skill level is need to start using ZAP?
Where should ZAP be used?
How you can get involved in the project.
[RSS Feed] [iTunes]
In this episode of Exploring Information Security, we dive deep into the dark, complex world of ransomware gangs with returning guest Kyle Andrus. Drawing on leaked chat logs, real-world cases, and extensive incident response experience, Kyle helps us understand the internal operations, motivations, and evolution of these cybercriminal organizations.
We explore how ransomware gangs are structured like modern corporations—with developers, access brokers, negotiators, HR, and even customer support. Kyle also shares insights into how these gangs are adapting to legal pressure, sanctions, and the cybersecurity community’s defensive advancements.
Topics covered:The organizational structure of ransomware gangs
Ransomware-as-a-Service (RaaS) models and profit sharing
Affiliate programs, access brokers, and laundering tactics
The impact of geopolitics on ransomware operations
Creative pressure tactics, including triple extortion and SEC complaints
The role of insider threats and chat log leaks (e.g., Conti)
Use of AI by defenders and attackers
The evolving response of law enforcement and regulation
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners