
Sign up to save your podcasts
Or


In this episode of the Security Repo Podcast, we dive into the world of zero-day exploits, marketplace dynamics for vulnerability research, and the evolving role of cybersecurity in boardroom decision-making. Guest Evan Dornbush, founder of Desired Effect, shares his journey from government cyber-ops to founding multiple security startups, and explains why attackers don’t care about compliance paperwork. We also explore the real-world consequences of hardware vulnerabilities, how a plug won’t save your hotel lock, and why we might be fooling ourselves by trying to “out-tech” cybercriminals.
https://www.linkedin.com/in/evandornbush/
https://www.desiredeffect.io/
Evan Dornbush is the founder and CEO of Desired Effect, which helps vulnerability researchers get fairly compensated and helps defenders act before attacks begin. He hosts the researcher-focused Hackers On The Rocks podcast. Previously, Evan co-founded Point3 Security, a cybersecurity workforce development firm acquired in 2021, and served as CEO. He co-founded P3F, a cybersecurity research firm acquired in 2021. He led Customer Experience at Vulnerability Research Labs, a security research firm acquired in 2010. He worked as a Computer Network Operator for the National Security Agency. Evan holds an M.S. in computer science from The George Washington University and has four ridiculously good-looking children.
In this episode of the Security Repo Podcast, Eric Woodruff dives deep into the complexities of identity and access management (IAM), from the evolution of Active Directory to the future of non-human identities. He explains the real-world challenges of hybrid environments, governance, and over-engineered identity solutions. Eric also highlights practical ways for newcomers to start learning IAM and emphasizes the importance of soft skills in security roles.https://www.linkedin.com/in/ericonidentity/https://idpro.org/body-of-knowledge/https://ericonidentity.com/Throughout his 25-year career in the IT field, Eric Woodruff has sought out and held a diverse range of roles. Currently the Chief Identity Architect for Semperis; Eric previously was a member of the Security Research and Product teams. Prior to Semperis, Eric worked as a Security and Identity Architect at Microsoft partners, spent time working at Microsoft as a Sr. Premier Field Engineer, and spent almost 15 years in the public sector, with 10 of them as a technical manager.Eric is a Microsoft MVP for security, recognized for his expertise in the Microsoft identity ecosystem. Eric is a strong proponent of knowledge sharing and spends a good deal of time sharing his insights and expertise at conferences as well as through blogging. Eric further supports the professional security and identity community as an IDPro member, working as part of the IDPro Body of Knowledge committee.
Hi everyone, It's Dwayne, host of the security repo podcast. The show is taking a 2-week break over the holidays to give you a chance to catch up on our backlog of security conversations. Our next new episode premieres January 7th, 2026. It's one to look forward to. And I wanted to say a huge thank you to each and every one of our listeners and subscribers. Thanks to you, in 2025, we gained 1300 new subscribers and crossed the 3500 mark on YouTube. Thank you. And I honestly hope you all are learning as much as I am from the amazing guests.I am honored to get to talk to some of the smartest people I have ever met and get to ask them about stuff I care about.I wish you the very best in 2026 and beyond, and may you and your loved ones have the best holiday season ever.Thanks, Dwayne
In this episode of the Security Repo Podcast, Douglas Brush, digital forensics expert and self-proclaimed "CISO Whisperer," shares his journey from early IT consulting to guiding CISOs and boards through complex security decisions. He breaks down his “Dad Bod Security” framework, connecting personal health metrics to meaningful cybersecurity goals, and highlights the need to move beyond vanity KPIs to focus on sustainable security programs. With candid insights on executive communication, legal challenges, and cultural resistance, Douglas offers a blueprint for building trust and progress in modern security leadership.
https://www.linkedin.com/in/douglasabrush/
https://brushcyber.com/
Douglas Brush, the founder of Brush Cyber, excels in data privacy, cybersecurity, litigation, and information governance. His unique combination of technical skills and business insight has earned him the respect and admiration of clients and colleagues.What truly sets Douglas apart is his unwavering dedication to his clients. He understands that protecting data in today’s digital age is a technical challenge and a business imperative. Whether testifying as an expert witness or providing virtual CISO services, Douglas always brings his A-game with an engaging yet intelligent approach. He translates bits and bytes to dollars and cents like no other professional in his field.In fact, he’s so good at what he does that he is a federally court-appointed Court Appointed Neutral (formally known as a “Special Master”) and neutral expert in high-profile litigation matters.
Douglas Brush is a beacon of light in a world where data breaches and cyberattacks are becoming increasingly common. He is always ahead of what is coming next, and you’d think he’s got his crystal ball. He’s a leader who inspires confidence and empowers organizations to embrace the digital age without fear. With Douglas at the helm, organizations can rest assured that their data is safe, allowing them to focus on their core business objectives and drive growth in the digital economy. Douglas is a heavyweight in his field, with over three decades of experience in information governance, data privacy, cybersecurity, and dispute consulting is second to none. His unique approach, blending technical expertise with a light-hearted touch, sets him apart, making the complex world of cybersecurity and privacy more accessible and engaging. His unique ability to break down complex technical concepts into easy-to-understand language has made him a sought-after speaker at industry events and conferences.
Scaling Open Source Observability and Managing Risk in the Software Supply Chain – Avi Press
In this episode of the Security Repo Podcast, Avi Press, founder and CEO of Scarf, dives deep into the evolving world of open source observability and its intersection with security. He unpacks how better visibility into software usage can inform both defensive strategies and smarter commercialization, while raising concerns over the concentrated risk in critical open source dependencies. Avi also shares his thoughts on dependency management, security tooling, and the importance of nuanced data collection in a privacy-conscious world.
https://about.scarf.sh/
Avi Press is the Founder and CEO of Scarf, a company focused on open source usage analytics. We process over 2 billion open source package downloads every day. Open source maintainer and advocate. Functional programming enthusiast. Avi serves on the Haskell Foundation board, as well as the Haskell.org committee. Avi is a former engineer at Pandora and is based in Oakland, California
In this episode of the Security Repo Podcast, Jeffrey Bell, Principal Security Engineer and founder of CatchingPhish.com, discusses the confusion surrounding the naming conventions of threat actor groups across different security vendors. He explains how companies like CrowdStrike, Palo Alto, and Mandiant label the same adversaries with different names due to marketing and commercialization pressures, creating challenges for threat intelligence. Jeffrey also introduces MITRE ATT&CK Groups as a reliable, centralized resource to demystify these aliases and strengthen defenses based on shared TTPs.
https://catchingphish.com
https://attack.mitre.org/groups/
https://github.com/mcdwayne/mitre-gang-lookup
Jeffrey Bell is a Principal Information Security Engineer and Threat Intelligence Lead at a Pharmaceutical Intelligence company. He graduated from UNC-Charlotte with a B.S. in Computer Science, specializing in Cybersecurity. Jeffrey has over 6 years of experience in Threat Intelligence, Incident Response, and Security Engineering. When not working, he writes for his blog, catchingphish.com, and loves to ski! He currently live near the beach in North Carolina.
In this episode of the Security Repo Podcast, David Cross, CISO at Atlassian and former Microsoft, Google, and Oracle security leader, shares his journey from Navy electronic warfare to global cybersecurity leadership. He offers hard-won insights on breaking into the industry, the evolving demands of the CISO role, and the practical impacts of AI on security operations. David also delivers candid advice for aspiring professionals and emphasizes the value of veterans in the cybersecurity workforce.
https://www.linkedin.com/in/david-b-cross-b856657/
David started his work in security with his five years’ active-duty service with the aviation electronic warfare community of the United States Navy. David was awarded with numerous honors including a Navy Achievement Medal, Southwest Asia Service Medal, Armed Forces Service Medal and NATO medal for his combat-based tours. David is now the CISO for Atlassian after 6.5 years as the CISO for the Oracle SaaS Cloud Security organization. Previously, David was a Director and built the Google Cloud Security Engineering organization for 3 years with his preceding 18 years spent with Microsoft in numerous security platform, cloud, product and engineering leadership roles. David is also a Venture Partner with Rain Capital VC. David holds a B.S. in CIS as well as an MBA with a MIS concentration along with 30+ issued patents with all in security technology related areas.
In this episode of the Security Repo Podcast, Dwayne McDaniel sits down with Amy Devine, a systems architect who transitioned from embedded wireless systems to cybersecurity. Amy shares the eye-opening story behind her Blue Team Con talk on how misdirected emails exposed sensitive personal data and what that means for digital identity. The conversation dives deep into privacy, data brokers, and what we sacrifice when companies prioritize convenience over security.
https://github.com/bitsdanceforme/email_scrubbing
https://bitsdanceforme.blog/
https://www.linkedin.com/in/bitsdanceforme/
Amy Devine worked in embedded systems development of wireless protocols before switching over to cybersecurity. She currently works as a Systems Architect for AV while also contributing to her cybersecurity community. Her talks to the local community include securing your email and how to avoid online scams. When she’s not sitting at a keyboard, you can find her working out in her other happy place - her home gym. Or running errands. Or trying to keep up with her kid. Or sleeping. You can find her online at her somewhat out of date website https://bitsdanceforme.blog/
She has a bachelors in Computer Engineering from the University of Illinois and a masters in cybersecurity from DePaul University.
In this episode of the Security Repo Podcast, we sit down with Darren Desmond, a seasoned CISO with a background in UK military intelligence, to unpack his unconventional journey from fish and chips to threat intelligence. He shares how his military forensics experience shaped his InfoSec leadership and dives deep into the evolving role of the CISO in a world increasingly driven by AI. Darren also gives candid insights into AI governance, red flags in hiring, and why the basics of cybersecurity still matter most.https://www.linkedin.com/in/desmondo/Darren Desmond is an information security leader and Certified Information Systems Security Professional with diverse experience in security risk management within the UK Defence sector, global online gambling industry, a major UK telecommunications & media company, a ‘Big Four’ managed services company and latterly as the CISO at one of the UK’s most recognizable brands.
In this episode of the Security Repo Podcast, we sit down with Martín Villalba, founder of InfoSecMap, to explore how his platform is transforming the way InfoSec professionals discover global events, communities, and CFPs. We dive into the origin story of InfoSecMap, its recent growth surge, and its strategic partnerships with organizations like OWASP. Martín also shares practical advice on building strong security cultures and the importance of addressing root causes over chasing vulnerabilities.https://infosecmap.com/LinkedIn: https://www.linkedin.com/in/wmvillalba/Twitter:https://twitter.com/act1vand0W. Martín VillalbaFounder & Principal, C13 SecurityFounder & Principal, InfoSecMapMartín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.
From the publisher's feed