Check out our companion blog!

Cybersecurity Episodes

June 10, 2024

XDR vs SIEM: Do you need to choose?

In this episode, we explore the differences between XDR and SIEM, two crucial tools in the world of security monitoring. Our guest, Dez Rock, CEO of SIEMonster, shares her fascinating journey from professional hacker to building an affordable, scalable SIEM solution that encompasses SOAR and XDR capabilities. We discuss the importance of evaluating security tools based on their true capabilities rather than just market perception, and Dez provides real-world examples of how SIEMonster's SIEM/XDR...
June 3, 2024

Strengthening Your Cybersecurity Blue Team: Pro Tips

In this episode, we explore the essential strategies and best practices for building and optimizing a blue team cybersecurity approach. Our guest, Mike Sailor, shares his expertise on how organizations can effectively prepare for and respond to cyber incidents. From establishing relationships with law enforcement to conducting tabletop exercises and understanding cyber insurance policies, Mike provides valuable insights to help companies strengthen their cybersecurity posture. Throughout the ...
May 27, 2024

Thinking Like a Hacker: Red Team Cyber Security Strategies

In this popular episode from last year, we explore the fascinating world of red team cyber security with Dwayne Laflotte, a seasoned expert in offensive cybersecurity. Dwayne shares his wealth of knowledge and experience, diving into the tactics and strategies employed by red teams to identify vulnerabilities and strengthen an organization's defenses. From exploiting backup systems to the importance of least privilege and strong passwords, this episode is a must-listen for anyone interested in b...
Dec. 25, 2023

Get Ready Before You Get Got: Ransomware Response Planning

This timely episode features an in-depth discussion between cybersecurity expert Melissa Palmer (@vmiss) and hosts W. Curtis Preston and Prasanna Malaiyandi on the crucial role preparation and planning play in effectively responding to and recovering from the inevitable ransomware attack. They stress that flying by the seat of your pants without an incident response plan when ransomware hits leads to chaotic, inefficient efforts and substantially higher costs. Melissa outlines pragmatic steps o...
Aug. 28, 2023

Are password managers no longer an option?

In this episode, we look at the latest Ransomware Trends Report from Veeam, which gives us a view into the sobering world of ransomware attacks and the critical lessons they teach us about cyber defense. Join W. Curtis Preston (Mr. Backup) and Prasanna Malaiyandi, as they break down the key insights from the report. We explore the ruthless tactics of ransomware operators, the eye-opening stats on recovery time, and the evolving strategies of cyber insurers. From the importance of robust password...
Aug. 14, 2023

Red team leader shares how to think like a hacker

Our guest this week is a specialist at offensive cybersecurity; that is, they keep you safe by attacking you and showing you your vulnerabilities. They're a red team. We've got the leader of their red team, Duanne Laflotte, to help us understand how hackers think – and what we can do to stop them. He confirmed some of the recommendations we often make (Ahem: password managers good), but showed us some defenses aren't that helpful. A particularly relevant part to our backup audience is what he to...
Aug. 7, 2023

Blue team stories from the cyber attack trenches

Nothing tells the story like a good story, right? This week we have Mike Saylor, the CEO of Black Swan, a cybersecurity company. Boy, has he been in the trenches. He tells some great stories about responding to cyber attacks. They're great stories and he's a great storyteller. We also learn about FBI Infragard, a partnership between the FBI and the private sector. We hope you enjoy the episode. Mentioned in this episode: Interview ad
July 31, 2023

Should you disclose your cyber attack?

This week the SEC has made a new rule that publicly traded companies must disclose any cyber attacks within four days. What if you're not a publicly traded company in the US? Should you reveal what happened to you? We bring in a wireless cyber security expert, Scott Schober of Berkeley Varitronics Systems, to talk about this topic. Closely related is also what should you do when you personally make a big mistake. Should you tell your boss? What if you're a boss and someone makes a mistake? How s...
July 24, 2023

Backup security is abysmal, says backup security expert

During this recording, Mr. Backup asked our guest how many backup systems that he had looked at had at least one critical security flaw, he said pretty much 100%. Holy. Cow. Doron Pinhas runs a company called Continuity Software, that does security assessments of storage and backup and recovery systems. They got the permission of some of their customers to anonymize and publish their findings, and the results were abysmal. (You can read the report yourself here.) He said it was extremely rare to...
July 10, 2023

Former Green Beret advises us on Cyber Security

Today we are proud to have as our guest, Zach Fuller, a founding partner of the Silent Sector, a cybersecurity firm -- and a former Green Beret who served in combat. We talk a little about how his service made him the person he is today, and how it lead him ultimately into helping people protect their own data. We talk about his top few things he wishes people would do to secure their environments (in addition to Mr. Backup's usual suggestions of password management, MFA, and patch management). ...
June 12, 2023

Cyber expert not happy with state of cybersecurity today

This week we talk with Eric Jeffery, a cybersecurity SE and host of the Cyber Security Grey Beard podcast, and he is just a little miffed about how organizations are responding to cyber attacks today. It's not so much about how they respond to the attack itself; it's how they communicate what happened to the public – if at all. He's submitting what happened at the LA Unified School District as his case in point. He's a bit fired up, so this will be a fun one. Mentioned in this episode: Intervi...
April 24, 2023

What can you learn from the LastPass hack?

Last year LastPass suffered two hacks that left their customer's data exposed. What can you learn from this event, even if you're not a LastPass customer? We use this hack as an example of what your company should do (or not do) if it ever suffers such a hack. We also talk about password managers, and what this hack means to those who use them. You do use one, right? This is a great episode, chock full of information. We hope you enjoy it. Mentioned in this episode: Interview ad
April 3, 2023

Can you apply least privilege to private data?

You know how we tell you to limit the amount of privilege each admin gets, in order to limit the blast radius if their account is compromised? What if you could apply that concept to applications that use private data to accomplish their task? We blindly give everything we have on each person to just about any app that needs anything. But if you had an app that only needs first name and email address, why not just give it that? And if it asks for more than that, what if you had a way to give it ...
March 27, 2023

Six vulnerabilities your password manager might have

I was shocked to learn that my favorite password manager had a few known vulnerabilities, and you might be shocked too! We found this great research paper from the University of York, and invited one of the co-authors on to discuss it. Siamek Shahandasthi, an Associate Professor from the University of York, explained all the vulnerabilities discussed in the paper, and why each is important. I was able to verify that at least one is still found in my current password manager. How many are in your...
March 13, 2023

Preparing an incident response plan for ransomware

An incident response plan is the key to successfully surviving a ransomware attack, and it's a bit like Dramamine. The time to get one is too late to get one. @Vmiss (Melissa Palmer) joins us again to talk about this important topic. We talk about the important role cyber insurance companies can play in helping you find an IR team and helping you develop a plan. (They can actually force you to do so in order to get coverage.) @vmiss was a blast to talk to again, and we're sure you'll enjoy this ...