DiscoverRansomware Rewind
Ransomware Rewind
Claim Ownership

Ransomware Rewind

Author: Joe Erle

Subscribed: 3Played: 8
Share

Description

Our podcast covers major data breaches, digital privacy issues, and the quirks of internet culture with a mix of humor and insight.

Why Subscribe?

Stay Informed: Get the latest updates on cybersecurity threats, ransomware attacks, and cyber insurance trends.

Engaging Content: We break down complex topics with a lighthearted approach, making them easy to understand.

Expert Insights: Learn from industry experts and our own experiences in the cybersecurity field.

We dive deep into the latest in cybersecurity, cyber insurance, and ransomware.

Mike Dowdy is the former president of two hosting companies and has been in the trenches of cyber security for over ten years. He has tribal knowledge on protecting yourself from threats and what to do if you are a victim.

Joe S Erle, MBA, CIC, CRM, TRA knows firsthand the devastating effects of not having a cyber security insurance plan. Despite the dry nature of cyber insurance Joe's advice is entertaining, fun, and educational.
25 Episodes
Reverse
Cybersecurity workers without proper support burn out in under 3 years. With the right training and organizational backing, that number stretches to 12-16 years. Rick Mischka, PhD, breaks down why, and what actually works. Rick's PhD thesis in cyberpsychology focused on rank-and-file practitioners facing constant incident stress, not executives or attackers. He explains why burnout prevention depends on organizational support, time off, role rotation, strong leadership, and individual resilience training, and how to make mindfulness practical enough to resonate with logical, skeptical IT workers. This episode covers cybersecurity burnout, mindfulness for IT teams, CISO career advice, API security risks, and cyber insurance trends. What is Layer 8 in cybersecurity? It's the human layer, the people using the systems, and most breaches trace back to it rather than the technology itself. What is a fractional CISO?  A part-time CISO who advises multiple companies instead of working full-time at one, often a good fit for mid-market companies not yet ready for a full-time hire. In this episode you'll learn: Why cybersecurity teams burn out faster than almost any other IT role The two things leadership must provide to prevent burnout How to introduce mindfulness to teams that dismiss it as "foo foo" Why API integrations are the most underrated security risk today What CISOs should ask before accepting a new role Why fractional CISO work makes sense for mid-market companies 00:54 Introduction 00:55 Meet Rick Mischka 01:57 Why Cyberpsychology 03:32 Burnout Prevention Tactics 05:35 Forced Vacations Culture 06:37 MSPs Reduce Burnout 07:36 Leadership Support Examples 09:54 Mindfulness For IT 14:06 Perfectionism And AI Stress 16:19 Layer Eight Humans 18:19 Better Awareness Training 22:01 Underrated API Integrations 23:49 AI Access And APIs 26:03 Hidden API Attack Surface 26:43 Securing APIs With Policy 28:09 CISO Seat At Table 30:08 Interview Red Flags 31:25 Fractional CISO Reality 33:03 AI Hype And Energy 35:09 Conspiracies China Data 39:35 Credit Freeze And Scores 43:26 Debt Stress And Burnout 44:15 Cyber Burnout Findings 45:56 Mindset And Recovery 48:56 Wrap Up And Where To Find Guest: Rick Mischka, Ph.D. | AVANT Communications LinkedIn: https://www.linkedin.com/in/rick-mischka YouTube Channel: https://www.youtube.com/@rickmischka Host: Joe Erle | Cyber Group Practice Leader, C3 Risk & Insurance Services www.c3insurance.com/cyber LinkedIn: / joeerle  X: https://x.com/joe_erle TikTok / Instagram / Facebook: @itscyberjoe Ransomware Rewind is a practical cybersecurity podcast focused on real-world cyber risk, incident response, and resilience. We talk to the people on the front lines so you can protect your business before the next attack. Please like and subscribe if you found this podcast valuable. #Cybersecurity #CISO #Burnout #cyberpsychology
Joe Erle sits down with Joshua Nicholson, Founder & CEO of DarkStack7 and Host of Cybersecurity America Podcast, to break down the critical incident response mistakes that leave companies with no choice but to pay ransoms. Joshua exposes the most common breach vulnerabilities still being exploited in 2026 including unpatched firewalls, missing MFA, excessive local admin rights, and AI tools like Microsoft Copilot leaking confidential HR data. He explains why identity has become the new security perimeter, how removing local admin rights stops lateral movement, and why every organization needs pre-provisioned break-glass access before a crisis hits. You'll also learn: How to fix dangerous logging and licensing blind spots Practical ways to patch systems without causing panic Lessons from real disaster recovery failures How DDoS attacks are used to increase ransom pressure A simple tabletop exercise playbook that actually works How strong cyber hygiene helps satisfy cyber insurance underwriters What Happens when AI Hacks Collide Timestamps: 00:35 – Intro Teaser 02:38 – MFA and Security Hygiene 06:04 – Identity Perimeter Shift  06:55 – Local Admin and LAPS 08:25 – Least Privilege Culture 12:00 – Patching Without Panic 15:59 – Disaster Recovery Lessons 18:59 – DDoS and Ransom Pressure 22:00 – Tabletop Exercise Playbook 25:27 – Logging and Licensing Gaps 27:37 – Finding Joshua and Services 28:42 – AI Breaches and Microsoft Copilot 30:46 – AI Risks and Market Crash 33:40 – Wrap Up and Thanks Guest: Joshua Nicholson | Founder & CEO, DarkStack7 LinkedIn: https://www.linkedin.com/in/joshuarnicholson Cybersecurity America Podcast https://www.youtube.com/@cybersecurityamerica_show Hosts: Joe Erle | Cyber Group Practice Leader, C3 Risk & Insurance Services LinkedIn: https://www.linkedin.com/in/joeerle X: https://x.com/joe_erle TikTok / Instagram / Facebook: @itscyberjoe   Ransomware Rewind is a practical cybersecurity podcast focused on real-world cyber risk, incident response, and resilience. We talk to the people on the front lines so you can protect your business before the next attack. Like, subscribe, and hit the bell for more insights on ransomware, cyber insurance, and building a stronger security posture. You can also listen on Spotify or Apple podcasts!  I appreciate your support! Thx!   #Ransomware #CyberSecurity #IncidentResponse #MFA #IdentitySecurity #LeastPrivilege #CyberInsurance #AISecurity #MicrosoftCopilot #DarkStack7 #RansomwareRewind
Joe Erle interviews Sam Jadali of Melurna about how companies unknowingly leak sensitive data and how that data gets sold and used for retargeting and other nefarious puroses.   Sam explains that Molerna "tags" data and tracks its journey across the internet to provide privacy and compliance intelligence, helping enterprises, carriers, and brokers understand what data is being exfiltrated and by which vendors.    The discussion covers pixel/session replay risks, escalating class actions, and regulatory exposure (including HIPAA concerns), Gen Z's declining expectations of privacy, and AI-driven targeting that could intensify manipulation and even influence politics.  They also discuss God Mode data access for $50 and what Sam learned from the experience.    00:00 Podcast Intro 01:03 What Melurna Does 01:37 God Mode Discovery 04:14 Inside Data Spy 05:56 Third Party Risk 07:20 Apps And Data Brokers 09:09 Gen Z And Consent 10:36 Health Data Retargeting 12:24 AI Hyper Targeting 14:31 Melurna For Compliance 16:56 Insurance And Pixels 18:08 Privacy Tools And Consent 19:50 Star Trek Or Skynet 21:55 Wrap Up And Contact Guest: Sam Jadali | Co-Founder of Melurna LinkedIn:   / sam-jadali   Website: https://securitywithsam.com/about-sam/ Host: Joe Erle | Cyber Group Practice Leader at C3 Insurance LinkedIn:   / joeerle   X: https://x.com/joe_erle TikTok:   / itscyberjoe   Instagram:   / itscyberjoe   Facebook:   / joeerle   Host: Mike Dowdy LinkedIn:   / mikedowdy     Don't forget to like, subscribe, and hit the bell for more insights on industrial cybersecurity! Data Privacy, Cybersecurity, Data Brokers, Melurna, AI Surveillance, Ransomware, Pixel Tracking, Class Action Lawsuits   RANSOMWARE REWIND is a deep dive into the reality of cyber risk. We talk to the people on the front lines to find practical ways to stay resilient in an uncertain digital world.
In this latest episode of Ransomware Rewind, we dive into the alarming surge of cyberattacks targeting the manufacturing sector and critical infrastructure. With over 2,100 ransomware attacks recorded in the first three quarters of 2025 alone, industrial environments are now the primary frontline for cyber risk. Joe Erle and Mike Dowdy sit down with Josh Ross, Co-Founder and CEO of Ironloop, to dismantle the myth of the "air gap" and explore how modern hackers are moving laterally from IT networks into the factory floor. Josh explains why critical systems from water utilities to overlooked cyber-physical assets like HVAC are becoming high-impact attack paths. We discuss the harsh reality that replacing end-of-life legacy systems is often impossible, making defense-in-depth and practical remediation the only viable path forward. Key Topics Covered in This Episode: The Air Gap Illusion: Why your systems aren't as isolated as you think. Exploiting Firewalls: How IT/OT connections become gateways for ransomware. Securing Underfunded Infrastructure: The unique challenges of protecting water and public utilities. Practical Remediation: Why Ironloop focuses on configuration validation and lifecycle monitoring. On-Prem Privacy: Building a security architecture that never touches the cloud. If you are a CISO, a plant operator, or a security leader in the industrial space, this episode provides a masterclass in reducing downtime risk and protecting legacy environments. Episode Chapters — Key Moments  00:00 – Intro Highlight 01:55 – Ransomware and Manufacturing: The 2025 Data 04:08 – Air Gaps Aren't Enough: The Myth of Isolation 06:01 – Water Systems and Defense in Depth 08:26 – Firewalls Exploited: Lateral Movement into OT 10:21 – Old vs. New: The Problem with Legacy Systems 22:12 – Manufacturing Drones and the Future of Logistics 25:17 – AI in Manufacturing: Predictive Maintenance or Risk? 31:13 – Budgetary Concerns: Security for Underfunded Plants 33:53 – The Data Problem: Monitoring Without Cloud Exposure 36:05 – Starting a Software Company Now: Ironloop's Origin Expert Guest: Josh Ross | Co-Founder of Ironloop LinkedIn:   / josh-ross1   Website: https://www.ironloop.com  Host: Joe Erle | Cyber Group Practice Leader at C3 Insurance  LinkedIn:   / joeerle   X: https://x.com/joe_erle TikTok:   / itscyberjoe   Instagram:   / itscyberjoe   Facebook:   / joeerle   Co-Host: Mike Dowdy LinkedIn:   / mikedowdy   Don't forget to like, subscribe, and hit the bell for more insights on industrial cybersecurity! Ransomware Rewind, OT Security, Manufacturing, Cybersecurity 2026, SCADA, Industrial Control Systems, Josh Ross, Ironloop, Cyber Insurance, Risk Management
In this episode of the Ransomware Rewind podcast, host Joe Erle (@joe_erle) interviews John Bruggeman, Chief Information Security Officer (CISO) at CBTS and OnX, on emerging cybersecurity threats like AI model poisoning and prompt injection attacks. With over 25 years of experience in cybersecurity, John explains how unsanitized inputs and as few as 250 malicious data points can cause "brain rot" or model decay in large language models (LLMs), resulting in unreliable outputs, hidden backdoors, and long-term AI vulnerabilities. John explains real-world AI attack vectors, including tool poisoning through hidden HTML code in emails, agent session smuggling in enterprise tools like Microsoft Copilot, and remote code execution risks that enable data exfiltration or excessive resource consumption. The discussion also covers recent DNS outages at Microsoft and AWS, illustrating how critical infrastructure weaknesses exacerbate AI security risks. John shares practical cybersecurity best practices for protecting AI systems: always sanitize inputs, enforce human-in-the-loop oversight, keep clean backups for model recovery, and integrate ethical guardrails inspired by Isaac Asimov's laws of robotics. They explore ethical concerns in AI, such as Reddit-driven misinformation campaigns, AI's psychological impact on vulnerable users like teenagers, and why LLMs aren't truly sentient (they're just advanced next-word predictors). Plus, a lively debate on AI's future: utopian Star Trek scenarios vs. dystopian Skynet dangers. Packed with actionable insights on AI security, data poisoning prevention, and cybersecurity strategies, this episode is a must-listen for CISOs, IT leaders, security professionals, and businesses deploying AI in high-risk environments. Tune in to Ransomware Rewind for expert advice on safeguarding your AI models, preventing prompt injection, and staying ahead of cyber threats. Available now. Listen on your favorite podcast platform! Episode Chapters — Key Moments 00:00 First Leak — Prompt attacks begin 02:00 Breaches & Insurance — Who pays when it breaks 05:30 Human Error — Why people cause most damage 10:00 Model Decay — When systems slowly forget 15:30 Training Data Risk — Bad data, bad outcomes 22:00 LLM Attacks — Hackers follow the spotlight 30:00 Red Teaming — Break it before they do 38:00 Guardrails — Rules that keep speed safe 46:00 Startups — Small teams, big targets 55:00 The Future — What keeps CISOs awake Guest: John Bruggeman, Chief Information Security Officer at CBTS and OnX  LinkedIn:   / johnbruggeman   Website: http://www.huc.edu/ Host: Joe Erle, Cyber Group Practice Leader at C3 Insurance LinkedIn:   / joeerle   X: https://x.com/joe_erle TikTok:   / itscyberjoe   Instagram:   / itscyberjoe   Facebook:   / joeerle   Mike Dowdy LinkedIn:   / mikedowdy    Listen on Apple Music, Spotify, and YouTube. Thanks for listening and don't forget to follow the pod and leave a review. 
loading
Comments