Unspoken Security

Unspoken Security

Download on the App Store

Unspoken Security episodes

  • Evolution of the Security Integration Landscape

    In this episode of Unspoken Security, host AJ Nash sits down with Eric Yunag, EVP of Product and Services at Convergint. They explore how security integration is changing as organizations face a fast-moving threat landscape and rising expectations from leaders and regulators. Eric explains why today’s environment demands a new approach—one that connects hardware, software, and services in a more dynamic, real-time ecosystem.

    Eric shares how integrators help companies navigate not just the technical, but also the legal and operational complexity of modern security. He describes how shifting to cloud platforms, unifying physical and digital identities, and balancing privacy with business outcomes all add new layers of challenge. The conversation highlights the growing use of AI and “visual intelligence”—using camera data for both security and business insight—as organizations look to do more with their investments.

    Throughout the discussion, Eric makes the case for trusted, neutral advisors who help organizations build smarter, more connected security systems. He shows how today’s integrators are positioned to guide clients through tough choices, benchmark best practices, and unlock value that goes far beyond traditional security.

    Send us Fan Mail

    Support the show

    56 min
  • Do We Even Need Operational Technology-Specific Threat Intelligence?

    In this episode of Unspoken Security, host AJ Nash sits down with Danielle Jablanski from STV to break down the hard truths of operational technology (OT) security. Danielle explains why critical infrastructure - from water and transportation to manufacturing - remains vulnerable, tracing the challenge back to legacy systems, vendor complexity, and the lack of clear, industry-wide standards. She argues that many organizations have poor visibility into their assets and often rely on outdated assumptions about risk and business impact.

    Danielle calls out the pitfalls of flashy security solutions and emphasizes the need for basic, proven practices like network segmentation and clear asset management. She highlights the disconnect between IT and OT, showing how real-world safety and business operations depend on bridging this gap with honest communication and practical controls. Rather than chasing after hype, Danielle urges leaders to focus on building resilience: knowing what matters, assessing real risks, and strengthening what you can control.

    Throughout the conversation, Danielle offers a grounded perspective on why OT security demands more than checklists and compliance. She points to the need for shared data, better early warning systems, and a broader base of professionals willing to dig into the complexities - before an incident forces everyone’s hand.

    Send us Fan Mail

    Support the show

    1 hr 12 min
  • Can We Social Engineer the Bad Guys to Shut Them Down? (Encore of Ep 32)

    In this encore presentation of Unspoken Security Episode 32 (originally published on 3 April 2025), host AJ Nash sits down with Chris Birch, an intelligence practitioner with nearly 30 years of experience, to discuss the ever-evolving landscape of social engineering. Chris's unique perspective comes from leading teams that actively engage with threat actors, turning the tables on those who typically exploit vulnerabilities.

    Chris details how social engineering is simply human manipulation, a skill honed from birth. He explains how attackers leverage fear and greed, the fastest and cheapest ways to manipulate individuals. He also dives into how attacks have evolved, highlighting the dangers of increasingly sophisticated tactics like deepfakes and the blurring lines between legal and illegal applications of social engineering.

    The conversation also explores the crucial role of organizational culture in cybersecurity. Chris emphasizes that awareness, not just education, is key to defense. He advocates for sharing threat intelligence widely within organizations and across industries, empowering everyone to become a sensor against social engineering attempts. Chris also shares a surprising personal fear, offering a lighthearted end to a serious discussion.

    Send us Fan Mail

    Support the show

    1 hr 7 min
  • Why Incident Response Keeps Failing

    In this episode of Unspoken Security, host AJ Nash sits down with Zoë Rose, SecOps Manager at Canon EMEA. They explore the real-world barriers to building effective incident response programs and discuss why so many organizations struggle to move beyond reactive firefighting.

    Zoë shares her perspective from both consulting and in-house roles, pointing out that most incident response teams are overwhelmed, under-resourced, and stuck dealing with basics that never get fixed. She explains why expensive tools and new technology often miss the mark when organizations skip foundational work—like asset inventories, clear policies, and tuned alerts. Zoë urges listeners to focus on practical steps, such as documenting processes, improving communication, and building trust between technical teams and business leaders.

    Throughout the conversation, Zoë breaks down how real change happens: by investing in people, closing skills gaps, and fostering a culture where mistakes drive learning instead of blame. The episode ends with a reminder that effective security is not about quick fixes or flashy tools, but about honest assessment, teamwork, and steady improvement.



    Send us Fan Mail

    Support the show

    1 hr 7 min
  • The Future of Cyber Threat Intelligence

    In this episode of Unspoken Security, host AJ Nash sits down with Charlotte
    Guiney, Cyber Threat Intelligence Manager at Toyota Financial Services. They
    explore what it takes to build threat intelligence programs that work for both
    security teams and the wider business. Charlotte cuts through the noise,
    stressing that buy-in is step one—and that it’s often the hardest step. She
    shares how understanding internal customers and their priorities leads to
    early wins, which are key to building trust and showing the value of
    intelligence.

    Charlotte explains that not every organization needs the same level of
    maturity. Small companies might only need basic monitoring, while larger
    enterprises face more complex challenges. She notes that successful
    programs link intelligence to business needs, not just security threats. This
    approach helps teams prioritize what matters most and communicate risk in
    ways business leaders understand.

    The conversation also dives into the future of threat intelligence. Charlotte
    sees a growing role for automation and AI, especially for basic tasks, but
    believes people are still needed to bridge gaps and build relationships across
    the business. She closes with a reminder to keep things in perspective,
    echoing a lesson from her childhood at clown camp: sometimes you need to
    step back and find humor, even in serious work.

    Send us Fan Mail

    Support the show

    50 min
  • Is Anyone Able to Accurately Calculate Risk?

    In this episode of Unspoken Security, host A.J. Nash sits down with Dr. J. Lugo Santiago, Chief Operating Officer at QBRIC, to dig into how organizations actually calculate cyber risk—and why most current models fall short. Lugo explains that understanding risk is much more than looking at past incidents or relying on static checklists. Instead, he argues that real foresight comes from blending human insight, diverse data, and scenario planning to anticipate both likely and unexpected threats.

    Lugo challenges the habit of focusing only on what’s already happened. He shows why leaders need to account for changing threats, business priorities, and even social trends—not just technical vulnerabilities or compliance checkboxes. The conversation underlines that effective risk management means more than patching yesterday’s gaps. It requires building a culture where leaders feel the real impact of risk and use that discomfort to drive stronger decisions.

    Together, Nash and Lugo discuss why organizations must move beyond stoplight charts and generic risk scores. They call for practical, forward-looking approaches that tie risk to business value and encourage honest conversations—because seeing risk clearly is the first step to real resilience.

    Send us Fan Mail

    Support the show

    1 hr 4 min
  • Bringing Humanity to Security (Encore of Ep 22)

    In this episode of Unspoken Security, host A.J. Nash sits down with Dominic Vogel, founder of Vogel Leadership & Coaching, to discuss the importance of bringing humanity back into the cybersecurity field. Dominic shares his journey from corporate burnout to becoming an advocate for kindness and authenticity in an industry often focused on metrics and technology.

    Dominic explains how leading with empathy and building real, human connections can transform the workplace. He emphasizes that in a high-stress field like cybersecurity, creating positive environments is crucial for maintaining mental well-being and productivity. 

    The conversation also touches on Dominic’s leadership approach, where he prioritizes relationships and kindness over traditional, rigid business strategies. Tune in to learn how Dominic is reshaping cybersecurity leadership by focusing on people first, showing that a human-centered approach can lead to long-term success in both business and personal life.

    Send us Fan Mail

    Support the show

    44 min
  • Redefining National Security

    In this episode of Unspoken Security, host A.J. Nash sits down with Lauren
    Zabierek, Senior Vice President for the Future of Digital Security at the
    Institute for Security and Technology. Together, they examine how the
    traditional view of national security often overlooks the people it seeks to
    protect. Lauren shares why national security must move beyond military
    and government, and instead focus on the everyday risks that affect
    everyone—whether that’s cybersecurity, healthcare, or even climate safety.

    Lauren makes a strong case for widening the lens on security. She explains
    why protecting people requires new thinking and fresh policies, not just
    more funding for defense. She also describes the need for face-to-face
    connections and open dialogue to rebuild trust and unity in a fractured
    world.

    The conversation turns to software and the Secure by Design movement.
    Lauren outlines how changing incentives for software companies can lead
    to safer products. She draws on lessons from automotive and aviation
    safety to show paths forward, and encourages listeners to help drive
    demand for secure technology across all industries.

    Send us Fan Mail

    Support the show

    57 min
  • Security Awareness for the Connected Generation

    In this episode of Unspoken Security, host A.J. Nash sits down with Marley Salveter, Director of Marketing at Unspoken Security. They explore how digital privacy and security awareness look different for younger generations who have grown up in a world where sharing personal data is routine, not a choice. Marley shares her perspective on adapting to life online, where building a personal brand and protecting personal information often overlap for today’s professionals.

    Marley explains how her generation views data privacy as an accepted tradeoff, not a conscious decision, and why traditional corporate security training rarely feels relevant. She discusses the real risks of living in public—how threats feel less urgent until they get personal and why the rapid response of tech platforms can mask the lasting impact of breaches. She and A.J. dig into the challenge of communicating security risks to a connected generation that rarely sees tangible consequences.

    Together, they reflect on how open conversations bridge generational gaps and why storytelling and relatable dialogue help people internalize security lessons. Marley argues that making security personal is key to lasting change—especially for those building their careers and brands in the public eye.

    Send us Fan Mail

    Support the show

    1 hr 3 min
  • They’re Hacking the People!

    In this episode of Unspoken Security, host AJ Nash welcomes Ivan Novikov, CEO of Wallarm, to discuss the fundamental shifts in API security. They explore how APIs have evolved from internal tools to the public-facing backbone of mobile apps, IoT, and AI. This change has dramatically expanded the threat surface, making traditional security methods obsolete.

    Ivan explains why older approaches, like signature-based detection and RegEx, fail against modern attacks. He details Wallarm's unique solution: a real-time decompiler that analyzes the actual payload of API requests. This technique allows for deep inspection of complex and nested data formats, identifying malicious code that standard tools miss.

    The conversation also looks to the future, examining the security risks posed by the rapid adoption of AI agents. Ivan concludes with a stark comparison between physical and cyber threats. In the digital world, attacks are constant and aggressive. Success depends less on the tools you have and more on who you are and how you use them.

    Send us Fan Mail

    Support the show

    44 min

About Unspoken Security

From the publisher's feed

Unspoken Security is a raw and gritty podcast for security professionals who are looking to understand the most important issues related to making the world a safer place, including…