Discover
Security Cocktail Hour
Security Cocktail Hour
Author: Joe Patti and Adam Roth
Subscribed: 3Played: 15Subscribe
Share
© Joe Patti and Adam Roth
Description
Security veterans Joe Patti and Adam Roth welcome a diverse lineup of cybersecurity and information security experts to share their insights at the virtual bar. From cutting edge topics like AI and Operational Technology (OT) to the realities of careers and mental health, you'll get the inside view of what's happening across the industry and what it's really like to work in these fields, from the people who do it every day.
Reach us at [email protected] or @SecCocktailHour on Twitter.
88 Episodes
Reverse
Election security expert Antonia-Laura Pup talks with co-hosts Joe Patti and Adam Roth about how attacks are coming not just from the cyber world, but also through influencers and social media. Romania had to annul an election in response. And the small nation of Moldova fought back with the tools Antonia believes other countries will need to deploy to defend democracy.Antonia is a Romanian security researcher focused on these issues in her home country and others.In this episode:Why Romania's presidential election was annulled and why explaining that decision mattered.What the declassified reports on the Romanian election described about coordinated TikTok accounts, influencer payments, and attacks on election systems.20:32 How the annulment deepened public distrust in Romania.26:34 How Moldova handled their own election interference issues.32:08 Moldova's pre-election disclosures, public warnings, civil-society fact-checking, and outside cyber help formed its response.43:29 The wider lesson: why Antonia sees political will, not just technical capacity, as decisive, and why she does not want the military policing people's minds.57:11 EU cyber sanctions: a potential response to cyberattacks, but too slow to be the whole answer.
What does a cyber policy cover when technology risk reaches beyond stolen data? AI-related mistakes, reliance on vendors, business interruption, and physical consequences can raise different questions for different kinds of insurance. One policy cannot be assumed to answer them all.Michelle Faylo, Lockton's U.S. Cyber & Technology Leader, joins Joe Patti and Adam Roth to unpack cyber coverage and technology E&O; first- and third-party loss; physical versus nonphysical consequences; a competitive insurance market; and why war exclusions become difficult when attribution is contested. Michelle also talks about the controls insurers look for, broker conversations throughout the policy year, and what CISOs and boards need to understand before renewal. This episode is a general discussion, not insurance or legal advice.Michelle Faylo at Lockton: https://global.lockton.com/us/en/news-insights/lockton-names-michelle-faylo-u-s-cyber-and-technology-leaderSecurity Cocktail Hour: https://securitycocktailhour.com/#CyberInsurance #TechnologyRisk #RiskManagement
Running a vulnerability scan is easy. Deciding what matters, what is noise, and what a business should do next is the real work.Michael Simmons, founder of Elysium Trace, joins Joe Patti and Adam Roth to discuss business-focused vulnerability reporting for MSPs, IT consultants, and smaller security teams. They cover false positives, context, risk acceptance, repeatable reporting, automation, and why human judgment still matters.Michael describes Elysium Trace and its product approach from his own experience. Learn more: https://elysiumtrace.com/
Cybersecurity was built for enterprises. Gaurav Keerthi explains what that leaves behind for the companies without a cyber team, and why their exposure becomes everyone else’s problem.Gaurav, CEO of StrongKeep and a cybersecurity leader in the public and private sectors, joins Joe Patti and Adam Roth to break down why smaller organizations are still expected to buy, operate, and manage enterprise-style security. They discuss supply-chain risk, the “hopes and prayers” gap, cybersecurity’s IKEA problem, and what a usable baseline could look like for ordinary companies.Episode Takeaways:Most organizations do not have a dedicated cybersecurity professional.Enterprise security programs cannot fully protect an organization when exposed suppliers remain unprotected.Security products need to be simpler, more bundled, and more realistic for companies without specialist teams.Doing something proportionate is better than doing nothing while waiting for a perfect plan.Guest:- Gaurav Keerthi, CEO, StrongKeep- LinkedIn: https://sg.linkedin.com/in/gaurav-keerthi- StrongKeep: https://www.strongkeep.com/Resources:- CyCon: https://cycon.org/- NATO Cooperative Cyber Defence Centre of Excellence: https://ccdcoe.org/Security Cocktail Hour Podcast:- https://securitycocktailhour.com
Eva Galperin explains how stalkerware, ordinary phone access, coercion, and weak privacy defaults can let someone close create devastating real-world harm.In this episode, we cover:What stalkerware is and why hiding from the user mattersWhy intimate-partner abuse changes the cybersecurity threat modelPrivacy as consent and control, not isolationWhy end-to-end encryption is not magic if the endpoint is compromisedPassword managers, VPN myths, patching, and backupsWhat security teams miss when they only focus on exotic adversariesGuest: Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware.Resources:EFF Surveillance Self-Defense: https://ssd.eff.org/Coalition Against Stalkerware: https://stopstalkerware.org/




