The Cyber Resilience Brief: A SafeBreach Podcast

The Cyber Resilience Brief: A SafeBreach Podcast

Download on the App Store

The Cyber Resilience Brief: A SafeBreach Podcast episodes

  • Ep. 43 - Russian Threat Actors: Useful Fools and Proxy Power

    In this episode, Tova Dvorin and Adrian Culley break down the realities of Russian intelligence and cyber security, separating myth from fact. They explore how Russian state actors rely on proxy actors and cybercriminal marketplaces rather than direct operations, and why attribution challenges make cyber attacks so difficult to trace.

    The discussion highlights the difference between state-sponsored cyber activity and financially motivated cybercrime—and why defenders must rethink traditional assumptions. The episode closes with a look at why continuous threat exposure management is critical for staying ahead of evolving cyber threats.

    Topics include: Russian cyber threats, proxy actors, attribution challenges, and modern cybersecurity strategy.

    13 min
  • Ep. 42 - Iran’s Cyber Shadow War: IRGC, MOIS, and the Battle for Control

    Episode 2 of 6 – Iran’s Cyber Program Explained

    In Iran’s Cyber Shadow War: IRGC, MOIS, and the Battle for Control, we continue our deep-dive into Iran’s cyber operations by exposing the internal power struggle driving its most dangerous digital attacks.

    Iran does not operate a single, unified cyber command. Instead, two rival organizations—the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS)—run competing cyber missions with very different goals, tactics, and tradecraft. One favors loud, destructive attacks designed to intimidate and disrupt. The other specializes in quiet cyber espionage, long-term access, and intelligence collection.

    In this episode, we break down how this rivalry fuels Iranian state-sponsored cyber activity, why both agencies often target the same victims, and how their competition creates real risk for Western governments, critical infrastructure, energy, finance, and private enterprises. We also explore Iran’s use of contractor-based hacking groups, providing speed, innovation, and plausible deniability—while making attribution and defense significantly harder.

    For CISOs and security teams, this episode explains what Iran’s divided cyber command means for detection, dwell time, and continuous adversarial exposure validation—and why defenders must be prepared for both stealthy intrusions and sudden, destructive attacks.

    🎧 In this episode:
    • Iran’s cyber shadow war explained
    • IRGC vs. MOIS: rivalry, missions, and tactics
    • State-sponsored hacking and contractor ecosystems
    • Cyber espionage vs. cyber disruption
    • What Iran’s internal competition means for defenders

    This is Episode 2 of a 6-part series unpacking how Iran builds, deploys, and evolves its cyber power—and what organizations must do to stay ahead.

    11 min
  • Ep. 41 - Iran’s Cyber Awakening: From Stuxnet to Shamoon and Beyond

    How did Iran evolve from a regional actor into one of the world’s most disruptive cyber threat forces?

    In the first episode of our Iran threat series, we trace the pivotal moments that shaped Iran’s modern cyber doctrine — from the Stuxnet attack on Natanz to the rise of destructive wiper malware like Shamoon and today’s era of stealthy, persistent access operations.

    Host Tova Dvorin is joined by Adrian Culley, Offensive Cyber Security Engineer at SafeBreach, to unpack how Iran turned humiliation into capability, embraced a contractor-based APT model, and weaponized cyber operations as a tool of retaliation and asymmetric warfare.

    You’ll learn:

    • Why Stuxnet was Iran’s cyber “Big Bang” moment

    • How Shamoon marked the birth of destructive, message-driven attacks

    • The evolution from noisy disruption to long-term persistence

    • Why Iranian APTs target financial services, energy, and supply chains

    • What today’s geopolitical instability means for Western enterprises and critical infrastructure

    • How CTEM, BAS, and Continuous Automated Red Teaming (CART) help organizations detect and stop Iranian threat actors before they strike

      If you’re a CISO, security leader, or threat intelligence professional, this episode explains why guessing is no longer an option — and why continuous adversarial exposure validation is now essential to defending against Iranian cyber operations.

      12 min
    • Ep. 40 - CRINK: The Cyber Threat Accelerating Right Now

      China. Russia. Iran. North Korea.

      As geopolitical tensions escalate—especially involving China and Iran—their cyber activity isn’t slowing down. It’s converging. In this episode of The Cyber Resilience Brief, Tova Dvorin and Adrian Culley unpack CRINK: an intelligence-community term rarely used in the commercial market, but critical for defenders to understand now.

      CRINK isn’t a formal alliance so much as it’s a shared playbook. Chinese pre-positioning, Russian disruption, Iranian sabotage, and North Korean cybercrime combine into a full-spectrum, asymmetric threat targeting critical infrastructure and enterprises.

      If your security strategy relies on alerts, assumptions, or patching alone, you’re already behind.

      This episode explains why—and how to move from guessing to proving your defenses work.

      16 min
    • Ep. 39 - The Shadow War is Already Here: How CISOs Must Prepare for Cyber Conflict

      The Shadow War is already underway — and it’s being fought in cyberspace.

      In this episode of The Cyber Resilience Brief, host Tova Dvorin and cybersecurity strategist Adrian Culley explore how escalating global tensions are redefining modern warfare and what that means for CISOs and security teams today.

      We break down how nation-state cyber threats from Russia, China, Iran, and North Korea are operating in a state of persistent engagement — planting access, stealing data, disrupting critical infrastructure, and preparing for future conflict.

      Learn why reactive security is no longer enough and how Breach and Attack Simulation (BAS), Continuous Automated Red Teaming (CART), and Adversarial Exposure Validation (AEV) help organizations defend against advanced persistent threats.

      The Shadow War isn’t coming — it’s already here.

      12 min
    • Ep. 38: The Evolution of Offensive Cybersecurity

      Offensive cybersecurity didn’t start with phishing or ransomware; it began with codebreaking, curiosity, and a drive to understand how systems fail.

      In this episode of The Cyber Resilience Brief, host Tova Dvorin and SafeBreach Senior Sales Engineer Adrian Culley explore the evolution of offensive security — from early hacking and penetration testing to modern Breach and Attack Simulation (BAS) and continuous adversarial exposure validation.

      You’ll learn why point-in-time testing is no longer enough, how BAS enables safe testing of live production environments, and what CISOs need to build measurable, continuously validated cyber resilience.

      18 min
    • Ep. 37 - Emennet Pasargad Exposed: How Iran’s IRGC Cyber Unit Targets Organizations — and How to Stop Them

      Emennet Pasargad is one of the most active and aggressive Iranian cyber threat groups operating today — tied directly to the Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command.

      In this episode of Cyber Resilience Brief, SafeBreach Senior Sales Engineer Adrian Culley breaks down who Emennet Pasargad really is, how they operate through shell companies and phishing campaigns, and why their tactics pose both cybersecurity and geopolitical risks.

      You’ll learn how this Iranian nation-state group abuses email, malware delivery, and command-and-control infrastructure — and why traditional security awareness training isn’t enough. More importantly, we explore how adversary emulation, continuous control validation, and real-world attack simulation can help organizations identify gaps, harden defenses, and stop IRGC-linked attacks before they cause damage.

      Key topics include:

      • Who Emennet Pasargad is and their ties to the IRGC

      • Common tactics, techniques, and procedures (TTPs), including phishing and lateral movement

      • The difference between cyber simulation vs. adversary emulation

      • How organizations can proactively defend against Iranian cyber threats

      • Why continuous cyber resilience testing is now a regulatory and business imperative

        For more information on protective measures against Iranian threat actors, check out our SafeBreach blog post.

        14 min
      • Ep. 36 - TIBER-EU Explained: How Threat-Led Red Teaming Is Redefining Cyber Resilience

        Threat-led red teaming is no longer optional in Europe — it’s becoming the foundation of cyber resilience.

        In this episode of The Cyber Resilience Brief, host Tova Dvorin is joined by Adrian Culley, SafeBreach’s offensive security expert for Europe and the UK, to break down the TIBER-EU framework and why it’s reshaping how financial institutions and critical infrastructure organizations approach cyber defense.

        Originally developed by the European Central Bank, TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) goes far beyond traditional penetration testing. It simulates real-world adversaries, real attack paths, and real operational pressure — aligning tightly with modern regulations such as DORA, NIS2, and the EU Cyber Resilience Act.

        In this episode, we cover:

        • What TIBER-EU is and why regulators are embracing intelligence-led red teaming

        • How DORA and TIBER-EU work together to enforce continuous operational resilience

        • Why point-in-time penetration tests are no longer enough

        • The evolving role of Breach & Attack Simulation (BAS) in preparing for TIBER-EU assessments

        • How Adversary Exposure Validation (AEV) reveals real blast radius and business impact

        • Why Continuous Automated Red Teaming (CART) is emerging as the “always-on” complement to regulator-mandated tests

          Whether you’re a CISO, security architect, red teamer, or risk leader, this episode explains how Europe’s regulatory frameworks are pushing the industry toward continuous, adversary-centric security validation — and why organizations outside the EU should be paying close attention.

          🎙️ If cyber resilience is a journey — TIBER-EU defines the terrain.

           

          14 min
        • Ep. 35 - BAS, APTs, AEV, and CTEM Explained: A Practical Guide to Cybersecurity Acronyms

          In this episode of the Cyber Resilience Brief, hosts Tova Dvorin and Adrian Culley clearly and practically explain some of the most commonly used — and most commonly misunderstood — terms in modern cybersecurity.

          Together, they break down:

          • What Breach and Attack Simulation (BAS) actually means in practice
          • How Advanced Persistent Threats (APTs) operate — and why persistence matters
          • What Adversarial Exposure Validation (AEV) is (and what it isn’t)
          • How CTEM (Continuous Threat Exposure Management) connects these concepts
          • The difference between attack simulation and adversary emulation
          • This episode focuses on plain-language explanations, real-world context, and why these terms exist in the first place.

            If you’ve ever heard these acronyms used interchangeably — or wanted a grounded explanation you can actually reuse — this episode is for you.

            18 min
          • Ep. 34 - Inside the Jaguar Land Rover Cyberattack: Supply Chain Failure, Scattered Spider, and the New Threat Ecosystem

            The Jaguar Land Rover cyberattack has already cost the UK billions — and exposed a critical weakness in modern cybersecurity: supply chain risk. In this episode of The Cyber Resilience Brief, SafeBreach hosts Tova Dvorin and Adrian Culley sit down with Steve Cobb, CISO of SecurityScorecard, to unpack what really happened, why groups like Scattered Spider, ShinyHunters, and Lapsus are becoming more coordinated, and what CISOs must do now to protect against cascading third-party failures.

            We break down:

            • How the Jaguar Land Rover breach unfolded

            • Why third-party and fourth-party risk is now first-party risk

            • The rise of coordinated cybercrime collectives

            • Why “trust but validate” must be the new supply chain mantra

            • Actionable steps to strengthen resilience and visibility across vendors

            • What the JLR incident means for national security, global operations, and the future of supply chain cybersecurity

              Whether you're a CISO, resilience leader, threat analyst, or supply chain security professional, this episode delivers essential insights into one of the most significant cyberattacks in UK history.

              15 min

            About The Cyber Resilience Brief: A SafeBreach Podcast

            From the publisher's feed

            The Cyber Resilience Brief is your 15-minute pulse on how organizations can build stronger defenses and achieve true cyber resilience. Each episode dives into the practical realities of Breach and Attack Simulation (BAS), adversarial exposure validation, and the evolving strategies that keep modern enterprises secure.