
Sign up to save your podcasts
Or


No tech stack can guarantee you won't get breached. Joe Erle sits down with Manoj Tandon, CEO and Co-Founder of Dark Rhiino Security and host of the Security Confidential Podcast, to talk about why people remain both the biggest vulnerability and the strongest defense in any organization.
Drawing on more than 200 episodes of his own show, Manoj explains how social engineers go after administrative gatekeepers to pull sensitive data, why attackers would rather exploit human behavior than fight through a firewall, and where AI-driven security tools hit their limits. He also covers third-party supply chain risk and why real defense in depth depends on ongoing training, not just the vendors in your stack.
In this episode: - How social engineers manipulate gatekeepers to steal trade secrets - Why "hackers aren't breaking in, they're logging in" through credential abuse and SIM swapping - Why a perfect AI detection engine is mathematically impossible - How nation-state actors use weaker supply chain vendors to reach bigger targets - Real stories of criminal mistakes that led to major busts - Why defenders play by rules that attackers ignore
Chapters: 00:00 Gatekeepers Exposed 00:29 Show Intro and Guest 01:35 Pregnancy by Algorithm 02:39 Social Engineering for Talent 05:16 Human Element in Security 06:31 Tech Hype vs Defense in Depth 08:06 Phishing and BEC Basics 12:15 Risk Motivation and Supply Chain 13:46 Fighter Jets and AI Warfare 16:38 F-35 Theft and Espionage 19:11 Protecting IP and Trade Secrets 21:38 Dumb Criminals and Money 24:35 AI Accelerates Attackers 26:26 Blue vs Red Team Limits 28:36 Ethical Testing and Dual Use 30:48 Bug Bounties and Pentesting 32:18 SQL Injection Stories 34:16 Prompt Injection and Jailbreaks 37:36 AI Guardrails and Censorship 39:01 Project Panama Controversy 39:31 Critical Thinking in the AI Age 43:57 Kids, Soundbites, and Decision Making 47:01 Star Trek or Skynet 50:05 Sci-Fi Tech Becomes Real 50:58 Where to Find Manoj 51:21 Revenue Resilience Services 52:30 Cyber Insurance Support 53:37 Closing Thanks and Outro
Guest: Manoj Tandon | CEO and Co-Founder, Dark Rhiino Security Website: https://www.darkrhinosecurity.com Security Confidential Podcast: https://www.youtube.com/@SecurityConfidential LinkedIn: https://www.linkedin.com/in/manoj-tandon-drs/
Host: Joe Erle | Cyber Group Practice Leader, C3 Risk & Insurance Services Website: https://www.c3insurance.com/cyber LinkedIn: Joe Erle, MBA, CIC, CRM, TRA, CCIC | LinkedIn X: https://x.com/joe_erle TikTok / Instagram / Facebook: @itscyberjoe
Ransomware Rewind is a practical cybersecurity podcast about real-world cyber risk, incident response, and resilience. We talk with the people on the front lines so you can protect your business before the next attack. Follow the show wherever you listen and leave a rating to help more business leaders find it.
Cybersecurity workers without proper support burn out in under 3 years. With the right training and organizational backing, that number stretches to 12-16 years. Rick Mischka, PhD, breaks down why, and what actually works. Rick's PhD thesis in cyberpsychology focused on rank-and-file practitioners facing constant incident stress, not executives or attackers. He explains why burnout prevention depends on organizational support, time off, role rotation, strong leadership, and individual resilience training, and how to make mindfulness practical enough to resonate with logical, skeptical IT workers.
This episode covers cybersecurity burnout, mindfulness for IT teams, CISO career advice, API security risks, and cyber insurance trends. What is Layer 8 in cybersecurity? It's the human layer, the people using the systems, and most breaches trace back to it rather than the technology itself. What is a fractional CISO?
A part-time CISO who advises multiple companies instead of working full-time at one, often a good fit for mid-market companies not yet ready for a full-time hire. In this episode you'll learn:
Why cybersecurity teams burn out faster than almost any other IT role
The two things leadership must provide to prevent burnout
How to introduce mindfulness to teams that dismiss it as "foo foo"
Why API integrations are the most underrated security risk today
What CISOs should ask before accepting a new role
Why fractional CISO work makes sense for mid-market companies
00:54 Introduction
00:55 Meet Rick Mischka
01:57 Why Cyberpsychology
03:32 Burnout Prevention Tactics
05:35 Forced Vacations Culture
06:37 MSPs Reduce Burnout
07:36 Leadership Support Examples
09:54 Mindfulness For IT
14:06 Perfectionism And AI Stress
16:19 Layer Eight Humans
18:19 Better Awareness Training
22:01 Underrated API Integrations
23:49 AI Access And APIs
26:03 Hidden API Attack Surface
26:43 Securing APIs With Policy
28:09 CISO Seat At Table
30:08 Interview Red Flags
31:25 Fractional CISO Reality
33:03 AI Hype And Energy
35:09 Conspiracies China Data
39:35 Credit Freeze And Scores
43:26 Debt Stress And Burnout
44:15 Cyber Burnout Findings
45:56 Mindset And Recovery
48:56 Wrap Up And Where
To Find Guest: Rick Mischka, Ph.D. | AVANT Communications
LinkedIn: https://www.linkedin.com/in/rick-mischka
YouTube Channel: https://www.youtube.com/@rickmischka
Host: Joe Erle | Cyber Group Practice Leader, C3 Risk & Insurance Services
www.c3insurance.com/cyber
LinkedIn: / joeerle
X: https://x.com/joe_erle
TikTok / Instagram / Facebook: @itscyberjoe
Ransomware Rewind is a practical cybersecurity podcast focused on real-world cyber risk, incident response, and resilience. We talk to the people on the front lines so you can protect your business before the next attack. Please like and subscribe if you found this podcast valuable.
#Cybersecurity #CISO #Burnout #cyberpsychology
Joe Erle sits down with Joshua Nicholson, Founder & CEO of DarkStack7 and Host of Cybersecurity America Podcast, to break down the critical incident response mistakes that leave companies with no choice but to pay ransoms.
Joshua exposes the most common breach vulnerabilities still being exploited in 2026 including unpatched firewalls, missing MFA, excessive local admin rights, and AI tools like Microsoft Copilot leaking confidential HR data. He explains why identity has become the new security perimeter, how removing local admin rights stops lateral movement, and why every organization needs pre-provisioned break-glass access before a crisis hits.
You'll also learn:
How to fix dangerous logging and licensing blind spots
Practical ways to patch systems without causing panic Lessons from real disaster recovery failures
How DDoS attacks are used to increase ransom pressure
A simple tabletop exercise playbook that actually works
How strong cyber hygiene helps satisfy cyber insurance underwriters
What Happens when AI Hacks Collide
Timestamps:
00:35 – Intro Teaser
02:38 – MFA and Security Hygiene
06:04 – Identity Perimeter Shift
06:55 – Local Admin and LAPS
08:25 – Least Privilege Culture
12:00 – Patching Without Panic
15:59 – Disaster Recovery Lessons
18:59 – DDoS and Ransom Pressure
22:00 – Tabletop Exercise Playbook
25:27 – Logging and Licensing Gaps
27:37 – Finding Joshua and Services
28:42 – AI Breaches and Microsoft Copilot
30:46 – AI Risks and Market Crash
33:40 – Wrap Up and Thanks
Guest: Joshua Nicholson | Founder & CEO, DarkStack7
LinkedIn: https://www.linkedin.com/in/joshuarnicholson
Cybersecurity America Podcast https://www.youtube.com/@cybersecurityamerica_show
Hosts:
Joe Erle | Cyber Group Practice Leader, C3 Risk & Insurance Services
LinkedIn: https://www.linkedin.com/in/joeerle
X: https://x.com/joe_erle
TikTok / Instagram / Facebook: @itscyberjoe
Ransomware Rewind is a practical cybersecurity podcast focused on real-world cyber risk, incident response, and resilience. We talk to the people on the front lines so you can protect your business before the next attack.
Like, subscribe, and hit the bell for more insights on ransomware, cyber insurance, and building a stronger security posture.
You can also listen on Spotify or Apple podcasts!
I appreciate your support! Thx!
#Ransomware #CyberSecurity #IncidentResponse #MFA #IdentitySecurity #LeastPrivilege #CyberInsurance #AISecurity #MicrosoftCopilot #DarkStack7 #RansomwareRewind
In this latest episode of Ransomware Rewind, we dive into the alarming surge of cyberattacks targeting the manufacturing sector and critical infrastructure.
With over 2,100 ransomware attacks recorded in the first three quarters of 2025 alone, industrial environments are now the primary frontline for cyber risk. Joe Erle and Mike Dowdy sit down with Josh Ross, Co-Founder and CEO of Ironloop, to dismantle the myth of the "air gap" and explore how modern hackers are moving laterally from IT networks into the factory floor.
Josh explains why critical systems from water utilities to overlooked cyber-physical assets like HVAC are becoming high-impact attack paths. We discuss the harsh reality that replacing end-of-life legacy systems is often impossible, making defense-in-depth and practical remediation the only viable path forward.
Key Topics Covered in This Episode:
The Air Gap Illusion: Why your systems aren't as isolated as you think.
Exploiting Firewalls: How IT/OT connections become gateways for ransomware.
Securing Underfunded Infrastructure: The unique challenges of protecting water and public utilities.
Practical Remediation: Why Ironloop focuses on configuration validation and lifecycle monitoring. On-Prem Privacy: Building a security architecture that never touches the cloud. If you are a CISO, a plant operator, or a security leader in the industrial space, this episode provides a masterclass in reducing downtime risk and protecting legacy environments.
Episode Chapters — Key Moments
00:00 – Intro Highlight
01:55 – Ransomware and Manufacturing: The 2025 Data
04:08 – Air Gaps Aren't Enough: The Myth of Isolation
06:01 – Water Systems and Defense in Depth
08:26 – Firewalls Exploited: Lateral Movement into OT
10:21 – Old vs. New: The Problem with Legacy Systems
22:12 – Manufacturing Drones and the Future of Logistics
25:17 – AI in Manufacturing: Predictive Maintenance or Risk?
31:13 – Budgetary Concerns: Security for Underfunded Plants
33:53 – The Data Problem: Monitoring Without Cloud Exposure
36:05 – Starting a Software Company Now: Ironloop's Origin
Expert Guest: Josh Ross | Co-Founder of Ironloop
LinkedIn: / josh-ross1
Website: https://www.ironloop.com
Host: Joe Erle | Cyber Group Practice Leader at C3 Insurance
LinkedIn: / joeerle
X: https://x.com/joe_erle
TikTok: / itscyberjoe
Instagram: / itscyberjoe
Facebook: / joeerle
Co-Host: Mike Dowdy
LinkedIn: / mikedowdy
Don't forget to like, subscribe, and hit the bell for more insights on industrial cybersecurity!
Ransomware Rewind, OT Security, Manufacturing, Cybersecurity 2026, SCADA, Industrial Control Systems, Josh Ross, Ironloop, Cyber Insurance, Risk Management
In this episode of the Ransomware Rewind podcast, host Joe Erle (@joe_erle) interviews John Bruggeman, Chief Information Security Officer (CISO) at CBTS and OnX, on emerging cybersecurity threats like AI model poisoning and prompt injection attacks. With over 25 years of experience in cybersecurity, John explains how unsanitized inputs and as few as 250 malicious data points can cause "brain rot" or model decay in large language models (LLMs), resulting in unreliable outputs, hidden backdoors, and long-term AI vulnerabilities.
John explains real-world AI attack vectors, including tool poisoning through hidden HTML code in emails, agent session smuggling in enterprise tools like Microsoft Copilot, and remote code execution risks that enable data exfiltration or excessive resource consumption. The discussion also covers recent DNS outages at Microsoft and AWS, illustrating how critical infrastructure weaknesses exacerbate AI security risks.
John shares practical cybersecurity best practices for protecting AI systems: always sanitize inputs, enforce human-in-the-loop oversight, keep clean backups for model recovery, and integrate ethical guardrails inspired by Isaac Asimov's laws of robotics. They explore ethical concerns in AI, such as Reddit-driven misinformation campaigns, AI's psychological impact on vulnerable users like teenagers, and why LLMs aren't truly sentient (they're just advanced next-word predictors). Plus, a lively debate on AI's future: utopian Star Trek scenarios vs. dystopian Skynet dangers.
Packed with actionable insights on AI security, data poisoning prevention, and cybersecurity strategies, this episode is a must-listen for CISOs, IT leaders, security professionals, and businesses deploying AI in high-risk environments. Tune in to Ransomware Rewind for expert advice on safeguarding your AI models, preventing prompt injection, and staying ahead of cyber threats. Available now. Listen on your favorite podcast platform!
Episode Chapters — Key Moments00:00 First Leak — Prompt attacks begin 02:00 Breaches & Insurance — Who pays when it breaks 05:30 Human Error — Why people cause most damage 10:00 Model Decay — When systems slowly forget 15:30 Training Data Risk — Bad data, bad outcomes 22:00 LLM Attacks — Hackers follow the spotlight 30:00 Red Teaming — Break it before they do 38:00 Guardrails — Rules that keep speed safe 46:00 Startups — Small teams, big targets 55:00 The Future — What keeps CISOs awake
Guest: John Bruggeman, Chief Information Security Officer at CBTS and OnX
LinkedIn: / johnbruggeman
Website: http://www.huc.edu/
Host: Joe Erle, Cyber Group Practice Leader at C3 Insurance
LinkedIn: / joeerle
X: https://x.com/joe_erle
TikTok: / itscyberjoe
Instagram: / itscyberjoe
Facebook: / joeerle
Mike Dowdy
LinkedIn: / mikedowdy
Listen on Apple Music, Spotify, and YouTube.
Thanks for listening and don't forget to follow the pod and leave a review.
Ever wondered what handling deadly anthrax at the US Capitol has in common with battling ransomware in 2025? What if the next big cyber attack isn't from hackers in a basement—but from quantum computers shattering your encryption overnight? In this unmissable episode of Ransomware Rewind, cybersecurity legend Wil Klusovsky spills insider secrets that could save your business from total chaos.
Wil, a 24-year US Marine vet turned cyber strategist (LinkedIn: /wilklu, host of Keyboard Samurai), draws chilling parallels between war and digital battles. From post-9/11 preparedness drills to why most orgs still suck at basics like asset management, he breaks it all down with no-BS advice.
Episode Highlights That'll Keep You Up at Night:This episode is rocket fuel for CISOs, IT pros, and anyone dodging 2025's AI-powered phishing beasts. Wil's blend of humor, history, and hard truths makes it a must-listen. Catch it now before the next breach hits—because as Wil says, "You're going to deal with an incident; be ready to move fast."
Tune in to Ransomware Rewind for more breakdowns on cyber threats, data breaches, and security solutions. Stay ahead of ransomware attacks, phishing scams, and emerging cyber risks.
Guest: Wil Klusovsky, Cybersecurity Podcaster & IT Advisor
LinkedIn: https://www.linkedin.com/in/wilklu/
Links: https://www.wilklu.me/linktree
Keyboard Samarai Pod: https://www.youtube.com/@KeybdSamurai
Hosts: Joe Erle — Cyber Group Practice Leader, C3 Insurance
LinkedIn: https://www.linkedin.com/in/joeerle
X/Twitter: https://x.com/joe_erle
TikTok: https://www.tiktok.com/@itscyberjoe
Instagram: https://www.instagram.com/itscyberjoe
Meta/Facebook: https://www.facebook.com/joeerle
Questions about cyber insurance? Email [email protected] or go to www.c3insurance.com/cyber
Mike Dowdy — Voice AI Developer & Entrepreneur
LinkedIn: https://www.linkedin.com/in/mikedowdy
Thanks for listening and don't forget to like and subscribe for more episodes like this!
ransomware, cybersecurity, cyber threats, security training, human element in security, cybersecurity strategy, IT risk management, cyber resilience, security program design, business continuity
CISOs, CEOs & Business Owners: What To Say (and NOT Say) When Ransomware Hits – Or You'll Lose Millions in Reputation
90% of companies survive the hack… but die from the crisis communications disaster that follows.
Kevin Dinino (Head of Communications at top cybersecurity PR firm KCD PR) reveals the exact playbook that saved Fortune 500 companies during real breaches — and the fatal mistakes that tanked others.
You'll learn:
✅ The 48-hour rule that saves reputations (and stock prices)
✅ 3 statements that instantly destroy trust & trigger lawsuits
✅ CEO media-training crash course you can run in one afternoon
✅ Why cyber insurers now reject claims without a comms plan
✅ How deepfakes + AI leaks are rewriting breach PR in 2025
✅ Step-by-step ransomware crisis comms playbook + templates
Timestamps:
00:00 – Intro 00:04 – Ransomware Rewind
06:45 – The 48-hour reputation rule
12:30 – Real breach war stories
19:20 – Executive media training
27:40 – Deepfakes & AI crisis nightmare
34:15 – Your 2025 ransomware PR playbook
👤 Guest: Kevin Dinino – Head of Communications, KCD PR
LinkedIn: https://www.linkedin.com/in/kevindininokcdpr/
Website: https://www.kcdpr.com
🎤 Hosts: Joe Erle – Cyber Insurance Practice Leader, C3 Insurance
LinkedIn: https://www.linkedin.com/in/joeerle
X/Twitter: https://x.com/joe_erle
TikTok: https://www.tiktok.com/@itscyberjoe
Instagram: https://instagram.com/itscyberjoe
Need cyber insurance help? → [email protected]
Mike Dowdy – Voice AI Developer & Tech Entrepreneur
LinkedIn: https://www.linkedin.com/in/mikedowdy
🎧 Listen to more episodes: https://podcasts.apple.com/us/podcast/cyber-insiders/id1540640713
👉 Subscribe so you're ready BEFORE the ransom demand lands.
#Ransomware #CrisisCommunications #CyberBreach #ReputationManagement #CyberInsurance #CISOTips #DataBreach #PublicRelations #ExecutiveMediaTraining #Deepfakes #Cybersecurity2025
ransomware crisis communication, cyber breach PR, what to say during ransomware attack, CEO media training, cyber insurance requirements 2025, deepfake crisis, KCD PR, Kevin Dinino, Joe Erle, Ransomware Rewind
What happens when a brutal ransomware attack flips your entire career upside down—and launches you into the front lines of the biggest cyber war of our time?
In this explosive episode, cybersecurity advisor Nick Oles (Entoo Security) pulls back the curtain on his wild origin story: the day ransomware hit him personally, ignited an obsession, and ultimately birthed his must-read book, How to Catch a Phish.
Nick doesn't hold back. We dive deep into:
Whether you're a seasoned CISO or someone who just wants to stop being low-hanging fruit, this conversation is pure rocket fuel—packed with eye-opening insights, laugh-out-loud moments, and immediately actionable defenses.
Hit play now and turn your "it won't happen to me" into "try me."
🔗 Guest
Nick Oles Cybersecurity Advisor
LinkedIn: https://www.linkedin.com/in/nick-o-8b5b6349
Website: https://www.entoosecurity.com/
Support Nick by purchasing his book here on Amazon
🎙 Hosts
Joe Erle, Cyber Group Practice Leader at C3 Insurance
X: /joe_erle
https://x.com/joe_erle
TikTok: /itscyberjoe
https://www.tiktok.com/@itscyberjoe
Instagram: /itscyberjoe
https://www.instagram.com/itscyberjoe/
Meta: /joeerle
https://www.facebook.com/joeerle/
LinkedIn: /joeerle
https://www.linkedin.com/in/joeerle/
Questions about cyber insurance?
📩 Email: [email protected] or request a quote at www.c3insurance.com/cyber
Mike Dowdy, Voice AI Developer & Entrepreneur
LinkedIn:
https://www.linkedin.com/in/mikedowdy/
cybersecurity, phishing, how to catch a phish, nick oles, entoo security, ransomware rewind, cyber insurance, cyber insurance podcast, cyber threats, cybersecurity podcast, cybersecurity training, phishing awareness, ciso, cybersecurity for small business, cyber risk, ransomware, cyber attacks, incident response,, remote work security, AI cybersecurity, joe erle, c3 insurance, mike dowdy, cyber podcast, cyber security expert interview
In this episode of Ransomware Rewind, Joe and Mike sit down with Andrew Klucsarits, Director and IT Security and Risk Manager at IT Solutions to talk Cybersecurity including modern ransomware trends and operational security for enterprise business.
They analyze high-impact supply-chain attacks (including discussion of the Dragon Force incident and vendor risks tied to tools like ConnectWise).
In addition, they outline how adversaries exploit human and vendor weaknesses through social engineering exploits.
Lastly, they provide pragmatic guidance for building resilient defenses using data-driven security programs and third-party risk assessments.
Disaster recovery planning and AI risk mitigation is also covered in this info-packed episode.
Guest: Andrew Klucsarits
LinkedIn / https://www.linkedin.com/in/andrewklucsarits/
Hosts: Joe Erle, Cyber Group Practice Leader at C3 Insurance
X / /joe_erle
Tiktok / / itscyberjoe
Insta / / itscyberjoe
Meta / / joeerle
LinkedIn / / joeerle
Questions about cyber insurance?
Email [email protected]
Mike Dowdy, Voice AI Developer & Entrepreneur
LinkedIn / / mikedowdy
Thanks for listening and don't forget to subscribe.
ransomware, supply chain attack, Dragon Force, ConnectWise, third party risk, third party vendor security, disaster recovery, backup strategy, AI security, social engineering, incident response, cybersecurity podcast, data driven security, vendor risk assessment, ransomware recovery, cyber resilience
From the publisher's feed