The cyber weekly

The cyber weekly

By Deogratius Okello, Josephine Olok and Angella NabbanjaBusinessNewsEducationSelf-ImprovementTech NewsCareers
Download on the App Store

The cyber weekly episodes

  • Can You Trust Digital Forensics Tools? | Julian Derry on Digital Evidence

    Can you trust a digital forensics tool simply because it displays results on a dashboard? Not according to digital forensics professional Julian Derry.

    In this episode of The Cyber Weekly, Julian joins Deo Okello to explain why investigators must go beyond graphical interfaces and independently validate digital evidence.

    πŸ” In this episode, you'll discover:

    βœ… Why digital forensics tools can produce misleading results.

    βœ… How to validate evidence using raw data and multiple tools.
    βœ… How to investigate timestamp manipulation and anti-forensics.
    βœ… Why hands-on virtual labs are essential for learning.
    βœ… How to build a cybersecurity portfolio without expensive certifications.
    βœ… Why AI assistants and cloud platforms matter in future investigations.
    βœ… The practical tools, habits, and communities that help digital forensics professionals grow.

    Chapters

    00:00 Welcome and guest introduction
    02:02 Why digital forensics? The missing left shoe story πŸ‘Ÿ
    04:23 From bank hardware support to security
    06:45 Breaking into forensics beyond the textbooks
    11:16 Why you can't trust the GUI
    13:23 Case study: when the MFT tool misbehaved
    17:17 Detecting time stomping (anti-forensics)
    19:53 Android, iOS, macOS and Linux: same principles
    21:08 Why forensics is reactive
    21:42 Standing out without expensive certifications
    25:59 Emerging evidence: AI assistants and the cloud ☁️
    28:08 Quick fire: 5 tools every analyst needs
    33:07 Where to follow Julian's work (X, GitHub, Hive Consult)
    38:02 Closing

    πŸ’‘ Julian's advice to aspiring professionals: Build your skills, document your findings, and show your work publicly.

    πŸŽ™οΈ Whether you're a cybersecurity student, SOC analyst, digital forensics enthusiast, or experienced investigator, this conversation will challenge how you think about digital evidence.

    πŸ‘ Like, comment, and subscribe to The Cyber Weekly for conversations that make cybersecurity careers and expertise easier to understand.

    πŸ’¬ QUESTION:Have you ever encountered a tool that produced unexpected results? What did you do?

    #TheCyberWeekly #DigitalForensics #CyberSecurity #DFIR #DigitalEvidence #CyberSecurityCareers

    39 min
  • Stop Relying on Firewalls How an Engineer Defends Critical Financial Infrastructure πŸ”

    πŸŽ™οΈ Welcome to The Cyber Weekly Podcast!

    In this episode, Deo Okello sits down with Venuste Niyodusenga, Senior Network Engineer at the National Bank of Rwanda. He holds CISSP, CCSP, CCNP, PMP and AWS Solutions Architect Professional credentials and has a Master's from Carnegie Mellon University Africa. He has 10+ years across IT, SCADA and industrial systems, and cybersecurity consulting.

    πŸ”₯ In this episode you'll learn:

    βœ… Why perimeter-only security fails against stolen credentials and session cookies
    βœ… What identity-driven defense in depth looks like: MFA, least privilege, just-in-time access, device posture and AAA
    βœ… How to handle unpatched critical systems in a bank without causing an outage
    βœ… The biggest architectural shift African financial institutions must prepare for (hint: fighting AI with AI)
    βœ… How to break the "experience trap" and get into cybersecurity without waiting for permission

    1 min
  • From Fixing Printers to CISO: Grant Hughes' Unlikely Cybersecurity Journey

    Ever feel stuck in a help desk role, wondering if cybersecurity is even reachable without a degree or years of "experience"? Grant Hughes was exactly there β€” until he sent one cold email that changed his career forever.

    In this episode of The Cyber Weekly Podcast, Grant Hughes (CISO at The Nascent Group, Founding President of the ISC2 Cape Town Chapter) breaks down:

    How he went from desktop support to CISO with zero security certs

    The exact conversation that got him his first break in security
    Why most security awareness training fails β€” and what actually works
    The real reason you don't need 5 years of experience to break in
    The one skill every newcomer needs right now

    πŸ”— Connect with Grant Hughes:

    Portfolio: https://granthughes.co.za/

    LinkedIn: https://www.linkedin.com/in/grant-hughes-52196569/

    YouTube: https://www.youtube.com/@granthughes4989

    🌍 African Tech Talent Support Project: https://isc2capetownchapter.com/africa-tech-talent-support-project/

    🏒 ISC2 Cape Town Chapter: https://www.linkedin.com/company/isc2-cape-town-chapter/

    πŸ’Ό The Nascent Group: https://nascent.group/

    Β LinkedIn: https://www.linkedin.com/company/nascent-group-global/

    Chapters

    00:53 Β Meet Grant Hughes: From help desk to CISO
    02:05 Β The one takeaway Grant wants you to leave with
    03:12 Β What pulled him from IT support into cybersecurity
    04:56 Β The cold email that changed his life
    08:39 Β What 6 years on the front lines taught him
    10:40 Β Why the basics keep evolving
    11:26 Β What security culture really means
    16:44 Β Handling employee pushback and busy schedules
    19:34 Β Why explaining "why" makes training stick (the password story)
    20:15 Β No certs, no experience? Here's your path in
    24:11 Β The power of networking (and why it beats applying blind)
    26:14 Β AI, soft skills, and what's next for cybersecurity
    30:00 Β Where to find Grant + the African Tech Talent Support Project

    32 min
  • Why Most CISOs Don't Know What Their Business Actually Does

    🚨 Most CISOs can explain every control on their stack but ask them what the business actually sells, and they go quiet.

    In this episode of The Cyber Weekly, Deo sits down with Jake Bernardes CISO at Gambit Security, ex-pen tester, chartered accountant, and a guy who learned Chinese and German before ever touching cybersecurity.

    We get into:

    πŸ’° The "Minimum Viable Business" framework for justifying security spend
    🧩 Why GRC is broken (and how to fix the forgotten "R")
    πŸ€– Which security roles AI will kill and which ones it can't touch
    πŸ“œ Why Jake thinks certifications are mostly pointless
    🌐 Why your network matters more than your CISSP
    πŸŽ™οΈ Building leadership on transparency, vulnerability, and authenticity

    Β 

    Here the links

    Random Access Memories: https://randomaccessmemories.io

    Jake Bernardes on LinkedIn: https://www.linkedin.com/in/jakeleobernardes/

    Random Access Memories on YouTube: https://www.youtube.com/@RandomAccessMemoriesPod

    Β 

    If you're in GRC, trying to break into cybersecurity, or leading a security team through the AI shift this conversation will change how you think about your career.

    00:00 Intro: The Intersection of Chinese & Cybersecurity

    01:19 Who is Jake Bernardes?
    03:18 How Accounting Creates Better CISOs
    04:14 The "Minimum Viable Business" & Proving ROI
    08:26 Why GRC is Broken (And How to Fix It)
    13:02 The Future of GRC Engineering & Automation
    17:32 Why Cyber Certifications Are "Pointless"
    19:24 AI is Killing Tier 1 SOC Jobs: What to do next
    22:43 The 3 Pillars of True Leadership

    #TheCyberWeekly #CISO #Cybersecurity #GRC #RiskManagement #CyberCareers #InfoSec #CyberLeadership πŸ”πŸŽ™οΈπŸ“ˆ

    26 min
  • Why Most Cybersecurity Salespeople Fail (And How to Fix It)

    In this episode of The Cyber Weekly Podcast, hosts Deogratius Okello and Angella Nabbanja sit down with MΔƒdΔƒlin Bratu β€” General Manager and Founder of Sectio Aurea (operating under the brand Phi). MΔƒdΔƒlin brings 20 years of experience across cybersecurity, governance, risk, and enterprise technology, sharing insights from his career at IBM, CA Technologies, and Eviden/Atos. He breaks down the realities of implementing frameworks like NIS2 and ISO 27001 in complex operational environments, why compliance must move beyond "paperwork security," and how he utilizes the expert-network model to deliver real-world security solutions. Whether you're starting out in GRC or looking to build your own consultancy, this conversation is packed with hard-earned lessons on compliance, operational friction, and building a resilient security program. 🎧

    Connect with our guest:

    Personal LinkedIn: https://www.linkedin.com/in/madalin-bratu/
    Company LinkedIn: https://www.linkedin.com/company/1-61803
    Website: https://www.phi.ro


    Β #CyberSecurity πŸ” #SalesStrategy πŸ’Ό #Entrepreneurship πŸš€ #TheCyberWeeklyPodcast πŸŽ™οΈ #CareerAdvice πŸ“ˆ #B2BSales 🀝 #CyberSecuritySales πŸ›‘οΈ #Podcast 🎧

    42 min
  • Heather Reed - She Turned 5 Volunteers Into 75 Cybersecurity Ambassadors πŸ”

    Only 40% of her company completed the annual security awareness training. Human error was the #1 risk on the register. So she stopped writing policies and started recruiting people. πŸ‘₯

    In this episode of The Cyber Weekly Podcast, Deo Okello sits down with Heather Reed β€” cybersecurity leader, Cyber Security Woman of the Year finalist, competitive cookie designer πŸͺ and former Cookie Wars contestant on the Food Network.

    Heather came into security from marketing, people leadership and compliance, and she says that non-traditional path became her biggest advantage. She never carried the "Department of No" reputation, because she'd spent years on the other side of it.

    We get into:

    πŸ”Ή How she built a cybersecurity ambassador network from 5 departments to 75 ambassadors β€” and hit 100% training completion
    πŸ”Ή Why she chose the friendliest people in the business, not the most technical
    πŸ”Ή The 4 years it took to bring 23 factories and 8,000 employees into the ISMS β€” and how they scored their best audit ever
    πŸ”Ή What a real "yes, if" conversation sounds like when the business wants speed
    πŸ”Ή Tabletop exercises that actually work (hint: ask your execs what keeps them up at night)
    πŸ”Ή Handling DLP and insider risk without turning security into the police πŸš”
    πŸ”Ή AI agents, guardrails, and why security leaders should be talking to startups
    πŸ”Ή Her honest answer to "did you ever feel you didn't belong?" β€” and why that question is only ever asked of women
    πŸ”Ή Three things any security leader can do in the next 90 days to shift culture

    31 min
  • 90 days from technical to IT risk professional

    ⚠️ One overlooked technical issue could become a major financial, operational or reputational crisis.

    But what exactly is IT risk, and why do organizations invest so much in managing it?

    In this episode of The Cyber Weekly Podcast, Deo Okello sits down with IT risk and security professional Peter Muhumuza to break down IT risk in practical, easy-to-understand language.

    You will learn:

    πŸ” How technical weaknesses become business risks

    πŸ“Š How organizations classify and track risks
    βš–οΈ Which risks can be accepted and which require immediate action
    πŸš€ How risk professionals support innovation without becoming β€œMr. No”
    🀝 Why third-party and vendor risk assessments matter
    ☁️ The risks created by cloud concentration and AI adoption
    βœ… Why passing an audit does not mean risk management is complete
    πŸ“ˆ How technical professionals can begin transitioning into IT risk within 90 days

    Peter also explains why effective IT risk management is about more than fixing technical problems. It requires understanding business priorities, regulatory obligations, operational downtime and financial exposure.

    If you work in cybersecurity, IT, banking, fintech, audit, governance or risk management, this conversation is for you.

    πŸ‘ Like this episode

    πŸ’¬ Share your biggest IT risk lesson in the comments
    πŸ”” Subscribe to The Cyber Weekly Podcast for more practical cybersecurity conversations
    πŸ“€ Share this episode with someone interested in IT risk

    #TheCyberWeekly #ITRisk #RiskManagement #Cybersecurity #InformationSecurity #GRC #ThirdPartyRisk #CloudSecurity #CyberRisk #ITGovernance

    45 min
  • Your Business Is NOT Too Small to Be Hacked 🚨

    Think your company is too small for cybercriminals to care about? Think again. 🚨

    On this episode of The Cyber Weekly, cybersecurity leader and vCISO Brandon Krieger breaks down what businesses need to understand about cybersecurity right now.

    We discuss:

    πŸ” What a fractional vCISO actually does

    πŸ€– Why AI adoption needs security guardrails
    🏒 Why small businesses are attractive targets
    πŸ›‘οΈ The cybersecurity basics companies often overlook
    πŸ”Ž Why every organization should consider a security gap assessment
    πŸ“ˆ How cybersecurity professionals can work toward becoming a vCISO
    πŸ’Ό Why understanding business is just as important as understanding security

    Β 

    • Follow Brandon Krieger: https://www.linkedin.com/in/brandonkrieger/
    • Follow KNSS Consulting Group: https://www.knssconsulting.com
    • Like and Follow our LinkedIn page: https://www.linkedin.com/company/thecyberweekly
    • Like and Follow our X page: https://twitter.com/thecyberweekly
    • Brandon makes an important point: cybersecurity professionals must understand the business they are protectingβ€”not just the technology

      42 min
    • The Unexpected Risks of Cloud Security That Experts Are Overlooking
      Cybersecurity in the Cloud: The Hidden Threats and Future of Digital Defense

      If you’re managing cloud infrastructure or responsible for cybersecurity in a hybrid environment, overlooking emerging threats can leave your organization exposed before you even notice the gap. In this episode, Muhiire Bill, a seasoned IT security professional with nearly a decade in financial institutions, reveals the cloud security blind spots most teams miss. From misconfigured cloud resources and weak access controls to API vulnerabilities and social media reconnaissance, this conversation uncovers the real risks hiding behind β€œsecure” systems. Bill also breaks down how organizations can balance usability, compliance, and protection without slowing the business down.Β  You’ll learn:

      • Why misconfigured cloud settings create massive breach risks
      • How multi-factor authentication and role-based access can strengthen defenses
      • Why API security is becoming one of the biggest threats in cloud environments
      • How continuous compliance helps teams stay ahead of attackers
      • Practical ways to align security with real-world operations
      • If you work in IT, security, cloud operations, or leadership, this episode gives you the insight you need to avoid common mistakes and build a stronger security culture. Bill’s experience across financial and manufacturing sectors brings a practical, real-world perspective to one of today’s most important tech conversations. Stay ahead of the curve hit play now.

        40 min
      • πŸ” From Floppy Disk Viruses to the SOC β€” 15 Years in Cybersecurity | Brett @ Cyber Weekly

        πŸŽ™οΈ Cyber Weekly | Episode with Brett (@infosecbret)

        What turns a kid whose family PC got wrecked by a boot sector virus into a security professional with 15+ years in IT and a Master's in Information Assurance? In this episode, host Deo Okello sits down with Brett to trace that path β€” and to talk honestly about what the job actually looks like once the "unicorns and rainbows" phase wears off.

        We get into why information assurance is really just cybersecurity with the spotlight on data, why AI is now the threat he worries about most, and what "doing the basics well" looks like in practice. πŸ”

        ⏱️ In this episode:

        - The Windows 95 floppy virus that started it all πŸ’Ύ
        - IT β†’ SOC analyst: how the transition actually happened
        - Information assurance explained (and why the CIA triad still matters)
        - Why phishing is still the risk that never goes away 🎣
        - AI in the hands of ransomware gangs β€” and the well-meaning employee pasting production code into an LLM πŸ€–
        - What Patch Tuesday teaches us about vulnerability management
        - Defenders have to be right 100% of the time. Attackers only need once. βš”οΈ
        - Brett's top 3: go back to basics, patch all the things, invest in your people πŸ“ˆ
        - The one takeaway: never stop learning 🧠

        πŸ’¬ Favourite line from the episode? Drop it in the comments.

        πŸ‘ Like, subscribe, and hit the bell for weekly conversations on security, threats, and the people defending against them.

        πŸ”— CONNECT WITH BRET

        X (Twitter): https://x.com/infosec_bret

        YouTube: https://www.youtube.com/c/BretWitt

        πŸ“Œ REFERENCED IN THIS EPISODE

        The "Mythos" story Bret mentions at ~10:00 β€”

        Anthropic's Claude Mythos 5 and Fable 5 launched June 9, 2026. On June 12
        the US Commerce Department imposed export controls after researchers
        found a way to prompt the model into identifying software vulnerabilities
        and, in one case, producing working exploit code. Anthropic pulled both
        models globally. Controls were lifted June 30 and access restored July 1.

        - Anthropic's statement (June 12): https://www.anthropic.com/news/fable-mythos-access

        - Anthropic on restoring access: https://www.anthropic.com/news/redeploying-fable-5
        - Forbes breakdown: https://www.forbes.com/sites/anishasircar/2026/06/16/anthropic-disabled-fable-5-and-mythos-5-after-a-us-export-control-order-heres-what-happened/
        - CNBC on controls being lifted: https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html

        #CyberSecurity πŸ” #InfoSec πŸ›‘οΈ #InformationAssurance πŸ“Š #CyberWeekly πŸŽ™οΈ #SecurityPodcast 🎧 #SOCAnalyst πŸ‘¨β€πŸ’» #Ransomware 🚨 #Phishing 🎣 #AISecurity πŸ€– #PatchTuesday 🩹 #VulnerabilityManagement ⚠️ #ThreatIntelligence πŸ•΅οΈ #ITCareers πŸ“ˆ #CyberCareers πŸš€ #BlueTeam πŸ”΅ #SupplyChainAttack ⛓️ #TechPodcast 🎬 #NeverStopLearning 🧠 #CyberAwareness πŸ‘οΈ

        18 min

      About The cyber weekly

      From the publisher's feed

      Dive into the world of cybersecurity, book reviews, and effective management strategies, including how to communicate with a board. If this piques your interest, join the club!