Episodes

  • The Cyber Hero Adventure - Making Security Engaging and Fun with Gary Berman
    Mar 31 2026

    Join cybersecurity expert Joseph Carson and guest Gary as they explore innovative ways to make cybersecurity engaging, fun, and accessible. Discover how humor, storytelling, and community involvement can transform the industry and attract new talent.

    Chapters

    00:00 Welcome to the Cybersecurity Chaos

    02:32 From Fear to Fun in Cybersecurity

    05:27 The Journey of a Cyber Advocate

    08:09 The Importance of Community and Collaboration

    10:45 Bringing Laughter Back to Cybersecurity

    13:13 Rebranding Cybersecurity for New Talent

    16:00 The Power of Words in Cybersecurity

    18:43 Innovative Approaches to Cyber Awareness

    21:29 Lessons from Kids: Simplifying Cybersecurity

    24:39 The Inner Child and Cognitive Dissonance

    26:40 Gamification and Learning Innovations

    28:19 Storytelling in Cybersecurity

    29:15 Cybersecurity Starts at Home

    30:36 Community Engagement and Employee Connection

    32:14 The Importance of Acknowledgment

    34:13 Finding Joy in Everyday Life

    35:11 Humor as a Coping Mechanism

    40:04 The Power of Positive Thinking

    45:02 Mission Accomplished: Fun and Safety

    Resources

    Cyber Heroes Comics - https://cyberheroescomics.com/

    Gary's LinkedIn Profile - https://www.linkedin.com/in/gary-berman/

    Show More Show Less
    47 mins
  • Inside the Digital Battlefield: Cybersecurity in Geopolitical Conflicts with Chris Kubecka
    Mar 17 2026

    Join Joseph Carson in this insightful episode as he interviews cybersecurity expert Chris Kubecka. They discuss critical infrastructure security, cyber warfare, geopolitical risks, and the evolving landscape of digital threats, providing valuable lessons for cybersecurity professionals and policymakers.

    Key Topics

    Cybersecurity in critical infrastructure

    Geopolitical cyber threats and hybrid warfare

    Evolving landscape of digital threats and resilience


    Sound bites

    "GPS jamming has been a massive challenge."

    "Digital Empires: China, Europe, and the US."

    "Radio communications are a vital fallback."


    Chapters

    1. 00:00 Introduction and Background of Chris Kubecka
    2. 01:37 Cybersecurity Challenges in Critical Infrastructure
    3. 03:37 Evolving Nature of Cyber Threats
    4. 05:45 The Role of Drones in Modern Warfare
    5. 07:25 Hybrid Warfare and Global Diplomacy
    6. 10:10 The Shift in Global Cybersecurity Dynamics
    7. 12:18 The Importance of International Cooperation
    8. 14:33 Privacy and Ethics in Cybersecurity
    9. 16:50 Historical Context and Regional Cooperation
    10. 18:55 Cyber Attacks on Civilian Infrastructure
    11. 22:04 Personal Experiences in Estonia
    12. 24:10 Geopolitical Tensions and Cybersecurity
    13. 25:52 Challenges in Maritime Connectivity
    14. 28:16 Critical Infrastructure Vulnerabilities
    15. 30:22 The Role of Radio in Authoritarian Regimes
    16. 33:43 International Maritime Law and Cybersecurity
    17. 37:46 Recent Projects and Activism in Cybersecurity
    18. 39:51 Staying Informed in a Rapidly Changing Landscape


    Resources

    Chris Kubecka's LinkedIn - https://www.linkedin.com/in/chriskubecka/

    Field Tested: How to Hack a Modern Dictatorship with AI - https://www.amazon.com/dp/B0C7F4XYZ

    Show More Show Less
    45 mins
  • How Gamification and Community Help Beginners Break Into Cloud and AI Security
    Mar 3 2026

    In this episode of the Security by Default podcast, host Joe Carson speaks with Ian Austin, co-founder of Pwned Labs, about his journey in cybersecurity, the evolution of learning in the field, and the challenges of Cloud and AI security. Ian shares insights on transitioning into cybersecurity roles, the importance of community engagement, and the need for continuous learning in an ever-evolving industry. They discuss the significance of gamification in training and the current trends in cloud security, emphasizing the importance of hands-on experience and collaboration.

    Key Takeaways

    1. Ian Austin is a co-founder of Pwned Labs, specializing in cloud and AI security training.
    2. His journey in cybersecurity began with help desk roles and evolved into penetration testing.
    3. Creating content is a great way to learn and contribute to the community.
    4. Cloud security presents unique challenges that require ongoing education and adaptation.
    5. Gamification in training enhances engagement but should not overshadow practical learning.
    6. Community involvement is crucial for personal and professional growth in cybersecurity.
    7. Transitioning into security roles can be done from various backgrounds, including sysadmin and help desk.
    8. Continuous learning is essential in the fast-paced cybersecurity landscape.
    9. Mentorship can significantly impact career development and confidence.
    10. Cloud security is a growing field with increasing demand for skilled professionals.


    sound bites

    "Learning is a great way to learn."

    "Community is a powerful thing."

    "Cloud is hard to secure."


    Chapters

    00:00 Introduction to the Podcast and Guest

    00:40 Ian Austin's Journey in Cybersecurity

    06:40 Transitioning into Security Roles

    10:54 Evolution of Learning in Cybersecurity

    16:19 The Importance of Community in Learning

    22:58 Challenges in Cloud Security

    28:46 Staying Updated in the Cybersecurity Field


    Resources:

    https://pwnedlabs.io/

    https://www.linkedin.com/in/ian-austin/

    Show More Show Less
    33 mins
  • Cracking Passwords and the Future of Passwords with Evil Mog
    Feb 17 2026

    In this episode of the Security by Default podcast, host Joe Carson welcomes Evil Mog, an expert in password cracking and cybersecurity. They discuss the importance of Hacker Jeopardy in making cybersecurity fun, the ongoing challenges with passwords, and the evolving role of AI in password cracking. The conversation also touches on incident response, the significance of documentation, and the future trends in cybersecurity, including the shift towards passwordless authentication and the impact of AI on both attackers and defenders.

    Takeaways

    1. Hacker Jeopardy is a fun way to engage with cybersecurity.
    2. Teaching others helps reinforce your own knowledge.
    3. Passwords will remain a necessary evil in security.
    4. AI is enhancing password cracking methodologies.
    5. Documentation is crucial in incident response.
    6. The cost of hacking is increasing due to advanced techniques.
    7. Collaboration between red and blue teams is essential.
    8. Insider threats are on the rise in cybersecurity.
    9. Password management is fundamentally an asset management issue.
    10. Future trends indicate a shift towards passwordless authentication.


    Sound bites

    "Teaching helps you learn better."

    "Security is about enabling the business."

    "The cost of hacking is rising."


    Chapters

    1. 00:00 Introduction to Evil Mog and Hacker Jeopardy
    2. 02:37 The Importance of Community and Teaching in Cybersecurity
    3. 05:22 Password Security: The Louvre Incident
    4. 07:59 The Evolution of Authentication Methods
    5. 10:35 Challenges in Asset Management and Password Management
    6. 13:15 Operational Technology (OT) Security Challenges
    7. 15:53 The Role of Documentation in Cybersecurity
    8. 18:42 AI in Cybersecurity: Automation and Password Recovery
    9. 21:52 AI in Password Cracking
    10. 24:56 Enhancing Human Capabilities with AI
    11. 27:18 The Evolution of Cybercrime
    12. 30:02 Trends and Predictions for Cybersecurity
    13. 34:41 Collaboration in Cybersecurity
    14. 37:24 The Future of Cybercrime and AI
    Show More Show Less
    42 mins
  • Exploring Identity Security Trends with Charles Chase
    Feb 3 2026

    In this episode of the Security by Default podcast, host Joe Carson speaks with Charles Chase about his journey into the cybersecurity field, focusing on identity security and privilege access management. They discuss the evolving trends in identity security, the importance of maintaining identity hygiene, and the impact of regulations like NIST 2 and DORA on organizational practices. The conversation also covers the shift towards passwordless security, the role of AI in identity management, and resources for those looking to enter the field. The episode concludes with reflections on the importance of identities in business and society.

    Takeaways

    1. Charles Chase fell into cybersecurity from a military background.
    2. The importance of understanding what you don't know in identity security.
    3. Organizations often have dormant accounts that pose security risks.
    4. Regulatory bodies are pushing organizations to improve their identity security practices.
    5. The shift towards passwordless security is gaining momentum.
    6. AI is becoming a valuable tool in identity management.
    7. Identity hygiene is crucial for reducing risks in organizations.
    8. The commoditization of identity solutions allows smaller businesses to implement security measures.
    9. Engaging with customers is key to understanding their unique identity security needs.
    10. The future of identity management is focused on user experience and automation.


    Sound bites

    "What do I not know?"

    "It's a learning tool."

    "It's a fun industry."


    Chapters

    1. 00:00 Introduction to the Podcast and Guest
    2. 00:47 Charles Chase's Journey into Cybersecurity
    3. 02:22 Trends in Identity Security and Best Practices
    4. 05:54 Understanding Dormant Accounts and Their Risks
    5. 09:54 The Shift Towards Passwordless Security
    6. 12:45 The Role of AI in Identity Management
    7. 18:35 The Importance of Digital Identity in Society
    8. 26:45 Resources for Entering the Identity Space
    9. 30:49 Conclusion and Final Thoughts


    Keywords

    cybersecurity, identity security, privilege access management, trends, best practices, passwordless security, AI in identity management, regulatory impact, identity hygiene, resources for cybersecurity

    Show More Show Less
    30 mins
  • Cyber Ops and OSINT with the Grugq
    Jan 20 2026

    In this episode of the Security by Default podcast, host Joseph Carson engages with the Grugq, a cybersecurity expert and PhD student, discussing his journey into the field, the evolution of cybersecurity practices, and the complexities of information warfare. The Grugq shares insights on anti-forensics, the importance of understanding human behavior in cybersecurity, and the current landscape of cyber warfare, particularly in the context of the ongoing conflict in Ukraine. The conversation highlights the challenges and changes in the cybersecurity field, emphasizing the need for clarity and understanding in a chaotic information environment.

    Takeaways

    1. The Grugq's journey into cybersecurity began with a Unix book.
    2. He transitioned from internships to freelancing in cybersecurity.
    3. Moving to Thailand helped reduce living costs while consulting.
    4. Understanding anti-forensics is crucial for effective cybersecurity.
    5. The rules of cyber warfare differ significantly from peacetime operations.
    6. Information warfare involves changing how people interpret information.
    7. The Grugq emphasizes the importance of human behavior in cybersecurity.
    8. Staying updated in cybersecurity requires monitoring current events and engaging with experts.
    9. The evolution of cybersecurity tools has made it easier for new actors to operate.
    10. The Grugq's PhD research focuses on the realities of cyber warfare.

    Additional Resources:

    https://x.com/thegrugq

    https://github.com/grugq

    Show More Show Less
    46 mins
  • From Prosecutor to CSO: Joe Sullivan on Cybersecurity Leadership, Crisis, and Resilience
    Jan 6 2026

    In this episode of the Security by Default podcast, host Joseph Carson interviews Joe Sullivan, a prominent figure in cybersecurity. They discuss Joe's journey from a federal prosecutor to the Chief Security Officer at Facebook, exploring the challenges and expectations in transitioning from government to private sector roles. The conversation delves into the evolving landscape of cybersecurity, the impact of ransomware, and the importance of crisis management and preparedness. Joe shares valuable lessons for aspiring security executives and highlights the significance of understanding technology in leadership roles. The episode concludes with Joe's current projects, including his nonprofit initiative, Ukraine Friends, which provides laptops to children affected by the war in Ukraine.

    Takeaways

    1. Security is possible for everyone.
    2. Joe Sullivan's journey reflects a unique path into cybersecurity.
    3. Transitioning from government to private sector presents challenges.
    4. Understanding corporate culture is crucial for success.
    5. Measuring success in cybersecurity requires clear metrics.
    6. Ransomware has fundamentally changed the cybersecurity landscape.
    7. Security leaders are increasingly reporting to CEOs.
    8. Crisis management is essential for organizational resilience.
    9. Aspiring security executives should focus on business understanding.
    10. Giving back to the community is a vital part of the cybersecurity profession.


    Sound bites

    1. "Security is possible for everyone."
    2. "I got an MBA through osmosis."
    3. "The expectations were so high."


    Chapters

    1. 00:00 Introduction to Security by Default Podcast
    2. 01:02 Joe Sullivan's Journey into Cybersecurity
    3. 05:10 Transition from Government to Private Sector
    4. 11:06 Navigating the Corporate Landscape
    5. 15:48 Measuring Success in Security
    6. 20:04 The Impact of Ransomware on Cybersecurity
    7. 28:01 The Evolving Role of Security Leaders
    8. 30:57 Understanding Business Strategy in Security
    9. 32:59 Risk Management and Business Partnership
    10. 33:52 Navigating Technology Risks
    Show More Show Less
    48 mins
  • Laughing with Cyber - A Standup Comedy Special with Ian
    Dec 23 2025

    In this episode of the Security by Default podcast, host Joseph Carson welcomes Ian Murphy, a cybersecurity expert and stand-up comedian. They discuss Ian's unconventional journey into cybersecurity, his experiences at the MOD and Symantec, and his transition to self-employment and comedy. Ian shares insights on the importance of storytelling in both cybersecurity awareness and comedy, as well as navigating online criticism and audience interactions. The conversation highlights the need for humor in serious industries and the value of real human connections.

    Takeaways

    1. Ian's journey into cybersecurity was unplanned and unconventional.
    2. The importance of storytelling in both cybersecurity and comedy.
    3. Self-employment offers freedom but comes with challenges.
    4. Humor can be a powerful tool in serious industries.
    5. Navigating online criticism requires thick skin and perspective.
    6. Comedy is subjective, and not everyone will appreciate it.
    7. Real human interactions are essential in today's digital age.
    8. Learning from experiences is crucial for growth in any field.
    9. Networking and peer relationships are vital for success.
    10. Life is better when you find joy and laughter in everyday situations.


    Titles

    From Cybersecurity to Comedy: Ian Murphy's Journey

    The Power of Storytelling in Cybersecurity and Comedy


    Sound bites

    "I wanted to be a footballer."

    "Comedy is subjective."

    "You need to grow the fuck up."


    Chapters

    1. 00:00 Introduction to the Podcast and Guest
    2. 00:56 Ian's Origin Story and Journey into Cybersecurity
    3. 06:29 Experiences at MOD and Symantec
    4. 10:44 Transitioning to Self-Employment and Freedom
    5. 14:27 The Switch to Stand-Up Comedy
    6. 22:05 The Impact of Humor in Cybersecurity Awareness
    7. 30:06 Audience Feedback and Social Media Interaction
    8. 31:54 The Power of Audience Engagement
    9. 34:49 Navigating Controversy in Comedy
    10. 37:43 The Art of Timing and Response
    11. 40:47 Comedy as a Reflection of Life
    12. 43:44 The Evolution of Comedy and Storytelling
    13. 49:53 Learning
    Show More Show Less
    57 mins