
Sign up to save your podcasts
Or


This week on the Signal vs. Noise cybersecurity podcast: a small school district in Vermont found a ransom note on one of its servers.
More than three weeks later, its school board voted, in public, NOT to pay.
Security professionals, lawyers, the insurer and law enforcement all did the work. The board made the call.
At a 40-person company there's no board meeting. The board is you.
Why the worst week of your year is a bad time to find out who decides, the one question to ask your insurance broker before you need the answer, and why it's worth settling who makes the call on a quiet day.
Five minutes, hosted by Jane.
This week on the Signal vs. Noise cybersecurity podcast: an online whisky shop in the UK told its customers that their names, email addresses, phone numbers and shipping addresses had been taken.
The shop wasn't broken into, and neither was the platform it runs on.
The company behind one of its add-ons was, and that add-on held a key to the shop's customer information. The platform turned the key off.
The founder's name went on the apology.
Why the apps you install hand keys to companies you never evaluated, and the two questions to ask before anyone clicks install on the next one: what does it get to see, and who can turn it off?
Five minutes, hosted by Jane.
This week on the Signal vs. Noise cybersecurity podcast: one person with a laptop and an AI chatbot broke into 395 organizations in 48 countries, most of them schools, through the same piece of printing software.
In twelve of them the attacker ended up holding the keys to the whole network. In the other 383, the attacker got the print server and the passwords on it, and stopped there.
The difference was not budget or headcount. It was what one boring box was allowed to reach.
Why you have something like that box, why patching cannot be the whole plan when the warning, the fix and the attack all land in the same week, and the one question to ask your IT company tonight: if that box got hit, what could it reach?
Five minutes, hosted by Jane.
Full edition: signal.echocyber.io
This week on the Signal vs. Noise cybersecurity podcast: on September second the government published seven things that are being broken into right now, and you can read all seven without knowing whether one of them is yours.
That is not a competence problem. Attached to the list was something easy to miss, a rule for deciding which ones could wait, two questions long and written in plain English.
Why the translation already exists, for free, and why it was addressed to somebody else.
Five minutes, hosted by Jane.
This week on the Signal vs. Noise cybersecurity podcast: a flaw that could have handed your identity system to a stranger left no trace inside your company, and that was the good outcome.
One layer down, a flaw in VMware vCenter went from disclosure to exploitation in five days, and the campaign that followed reached three hundred and sixty one addresses across forty seven countries.
Nobody looked any of them up by name.
Why "we're too small to be a target" is not how any of this works.
Five minutes, hosted by Jane.
This week on the Signal vs. Noise cybersecurity podcast: eighty one million sign-in attempts in two weeks, seventy eight accounts taken over, and a lot of the companies behind them had multi-factor authentication switched on and enforced.
Nobody's phone buzzed.
Why the question every insurance form, vendor questionnaire and audit control asks about MFA is the wrong one, and what the right one costs to answer.
Five minutes, hosted by Jane.
Full edition: signal.echocyber.io.
This week on the Signal vs. Noise cybersecurity podcast: what an AI assistant can actually reach inside a working business.
A client folder it can open, an encrypted exchange it has no path to, and the reasoning behind where that line got drawn.
Plus the three parts of the setup that do not hold up.
Five minutes, hosted by Jane.
Full edition: signal.echocyber.io.
This week on the Signal vs. Noise cybersecurity podcast: what actually happens inside the meeting where an AI project finally gets ended.
The first thing that surfaces is rarely the decision. It is the AI nobody approved, already wired into the shared inbox and the CRM.
One signal from the week's security news, traced through the cascade.
Five minutes, hosted by Jane.
Full edition: signal.echocyber.io
This week on the Signal vs. Noise cybersecurity podcast: the AI project that has sat on your leadership agenda for three quarters without ever being approved or killed.
There is always a meeting where a bet gets started and never one where a bet gets killed, so the no arrives late, as a rollback, after you have already paid for it.
One signal from the week's security news, traced through the cascade. Five minutes, hosted by Jane.
Full edition: signal.echocyber.io.
This week on the Signal vs. Noise cybersecurity podcast: the AI agent nobody owns.
It was approved in the spring, built by a contractor, wired in by someone who has since left, and it still reads your whole mailbox.
Keeping an agent is not the same as governing one.
One signal from the week's security news, traced through the cascade. Five minutes, hosted by Jane.
Full edition: signal.echocyber.io.
From the publisher's feed