
Sign up to save your podcasts
Or


In this episode, Tova Dvorin and Adrian Culley break down the realities of Russian intelligence and cyber security, separating myth from fact. They explore how Russian state actors rely on proxy actors and cybercriminal marketplaces rather than direct operations, and why attribution challenges make cyber attacks so difficult to trace.
The discussion highlights the difference between state-sponsored cyber activity and financially motivated cybercrime—and why defenders must rethink traditional assumptions. The episode closes with a look at why continuous threat exposure management is critical for staying ahead of evolving cyber threats.
Topics include: Russian cyber threats, proxy actors, attribution challenges, and modern cybersecurity strategy.
Episode 2 of 6 – Iran’s Cyber Program Explained
In Iran’s Cyber Shadow War: IRGC, MOIS, and the Battle for Control, we continue our deep-dive into Iran’s cyber operations by exposing the internal power struggle driving its most dangerous digital attacks.
Iran does not operate a single, unified cyber command. Instead, two rival organizations—the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS)—run competing cyber missions with very different goals, tactics, and tradecraft. One favors loud, destructive attacks designed to intimidate and disrupt. The other specializes in quiet cyber espionage, long-term access, and intelligence collection.
In this episode, we break down how this rivalry fuels Iranian state-sponsored cyber activity, why both agencies often target the same victims, and how their competition creates real risk for Western governments, critical infrastructure, energy, finance, and private enterprises. We also explore Iran’s use of contractor-based hacking groups, providing speed, innovation, and plausible deniability—while making attribution and defense significantly harder.
For CISOs and security teams, this episode explains what Iran’s divided cyber command means for detection, dwell time, and continuous adversarial exposure validation—and why defenders must be prepared for both stealthy intrusions and sudden, destructive attacks.
🎧 In this episode:
• Iran’s cyber shadow war explained
• IRGC vs. MOIS: rivalry, missions, and tactics
• State-sponsored hacking and contractor ecosystems
• Cyber espionage vs. cyber disruption
• What Iran’s internal competition means for defenders
This is Episode 2 of a 6-part series unpacking how Iran builds, deploys, and evolves its cyber power—and what organizations must do to stay ahead.
How did Iran evolve from a regional actor into one of the world’s most disruptive cyber threat forces?
In the first episode of our Iran threat series, we trace the pivotal moments that shaped Iran’s modern cyber doctrine — from the Stuxnet attack on Natanz to the rise of destructive wiper malware like Shamoon and today’s era of stealthy, persistent access operations.
Host Tova Dvorin is joined by Adrian Culley, Offensive Cyber Security Engineer at SafeBreach, to unpack how Iran turned humiliation into capability, embraced a contractor-based APT model, and weaponized cyber operations as a tool of retaliation and asymmetric warfare.
You’ll learn:
Why Stuxnet was Iran’s cyber “Big Bang” moment
How Shamoon marked the birth of destructive, message-driven attacks
The evolution from noisy disruption to long-term persistence
Why Iranian APTs target financial services, energy, and supply chains
What today’s geopolitical instability means for Western enterprises and critical infrastructure
How CTEM, BAS, and Continuous Automated Red Teaming (CART) help organizations detect and stop Iranian threat actors before they strike
If you’re a CISO, security leader, or threat intelligence professional, this episode explains why guessing is no longer an option — and why continuous adversarial exposure validation is now essential to defending against Iranian cyber operations.
China. Russia. Iran. North Korea.
As geopolitical tensions escalate—especially involving China and Iran—their cyber activity isn’t slowing down. It’s converging. In this episode of The Cyber Resilience Brief, Tova Dvorin and Adrian Culley unpack CRINK: an intelligence-community term rarely used in the commercial market, but critical for defenders to understand now.
CRINK isn’t a formal alliance so much as it’s a shared playbook. Chinese pre-positioning, Russian disruption, Iranian sabotage, and North Korean cybercrime combine into a full-spectrum, asymmetric threat targeting critical infrastructure and enterprises.
If your security strategy relies on alerts, assumptions, or patching alone, you’re already behind.
This episode explains why—and how to move from guessing to proving your defenses work.
The Shadow War is already underway — and it’s being fought in cyberspace.
In this episode of The Cyber Resilience Brief, host Tova Dvorin and cybersecurity strategist Adrian Culley explore how escalating global tensions are redefining modern warfare and what that means for CISOs and security teams today.
We break down how nation-state cyber threats from Russia, China, Iran, and North Korea are operating in a state of persistent engagement — planting access, stealing data, disrupting critical infrastructure, and preparing for future conflict.
Learn why reactive security is no longer enough and how Breach and Attack Simulation (BAS), Continuous Automated Red Teaming (CART), and Adversarial Exposure Validation (AEV) help organizations defend against advanced persistent threats.
The Shadow War isn’t coming — it’s already here.
Offensive cybersecurity didn’t start with phishing or ransomware; it began with codebreaking, curiosity, and a drive to understand how systems fail.
In this episode of The Cyber Resilience Brief, host Tova Dvorin and SafeBreach Senior Sales Engineer Adrian Culley explore the evolution of offensive security — from early hacking and penetration testing to modern Breach and Attack Simulation (BAS) and continuous adversarial exposure validation.
You’ll learn why point-in-time testing is no longer enough, how BAS enables safe testing of live production environments, and what CISOs need to build measurable, continuously validated cyber resilience.
Emennet Pasargad is one of the most active and aggressive Iranian cyber threat groups operating today — tied directly to the Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command.
In this episode of Cyber Resilience Brief, SafeBreach Senior Sales Engineer Adrian Culley breaks down who Emennet Pasargad really is, how they operate through shell companies and phishing campaigns, and why their tactics pose both cybersecurity and geopolitical risks.
You’ll learn how this Iranian nation-state group abuses email, malware delivery, and command-and-control infrastructure — and why traditional security awareness training isn’t enough. More importantly, we explore how adversary emulation, continuous control validation, and real-world attack simulation can help organizations identify gaps, harden defenses, and stop IRGC-linked attacks before they cause damage.
Key topics include:
Who Emennet Pasargad is and their ties to the IRGC
Common tactics, techniques, and procedures (TTPs), including phishing and lateral movement
The difference between cyber simulation vs. adversary emulation
How organizations can proactively defend against Iranian cyber threats
Why continuous cyber resilience testing is now a regulatory and business imperative
For more information on protective measures against Iranian threat actors, check out our SafeBreach blog post.
Threat-led red teaming is no longer optional in Europe — it’s becoming the foundation of cyber resilience.
In this episode of The Cyber Resilience Brief, host Tova Dvorin is joined by Adrian Culley, SafeBreach’s offensive security expert for Europe and the UK, to break down the TIBER-EU framework and why it’s reshaping how financial institutions and critical infrastructure organizations approach cyber defense.
Originally developed by the European Central Bank, TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) goes far beyond traditional penetration testing. It simulates real-world adversaries, real attack paths, and real operational pressure — aligning tightly with modern regulations such as DORA, NIS2, and the EU Cyber Resilience Act.
In this episode, we cover:
What TIBER-EU is and why regulators are embracing intelligence-led red teaming
How DORA and TIBER-EU work together to enforce continuous operational resilience
Why point-in-time penetration tests are no longer enough
The evolving role of Breach & Attack Simulation (BAS) in preparing for TIBER-EU assessments
How Adversary Exposure Validation (AEV) reveals real blast radius and business impact
Why Continuous Automated Red Teaming (CART) is emerging as the “always-on” complement to regulator-mandated tests
Whether you’re a CISO, security architect, red teamer, or risk leader, this episode explains how Europe’s regulatory frameworks are pushing the industry toward continuous, adversary-centric security validation — and why organizations outside the EU should be paying close attention.
🎙️ If cyber resilience is a journey — TIBER-EU defines the terrain.
In this episode of the Cyber Resilience Brief, hosts Tova Dvorin and Adrian Culley clearly and practically explain some of the most commonly used — and most commonly misunderstood — terms in modern cybersecurity.
Together, they break down:
This episode focuses on plain-language explanations, real-world context, and why these terms exist in the first place.
If you’ve ever heard these acronyms used interchangeably — or wanted a grounded explanation you can actually reuse — this episode is for you.
The Jaguar Land Rover cyberattack has already cost the UK billions — and exposed a critical weakness in modern cybersecurity: supply chain risk. In this episode of The Cyber Resilience Brief, SafeBreach hosts Tova Dvorin and Adrian Culley sit down with Steve Cobb, CISO of SecurityScorecard, to unpack what really happened, why groups like Scattered Spider, ShinyHunters, and Lapsus are becoming more coordinated, and what CISOs must do now to protect against cascading third-party failures.
We break down:
How the Jaguar Land Rover breach unfolded
Why third-party and fourth-party risk is now first-party risk
The rise of coordinated cybercrime collectives
Why “trust but validate” must be the new supply chain mantra
Actionable steps to strengthen resilience and visibility across vendors
What the JLR incident means for national security, global operations, and the future of supply chain cybersecurity
Whether you're a CISO, resilience leader, threat analyst, or supply chain security professional, this episode delivers essential insights into one of the most significant cyberattacks in UK history.
From the publisher's feed