Episodes

Sept. 7, 2026

Password Length vs Complexity: Why Longer Always Wins

Password length vs complexity isn't a close call. Dr. Mike Saylor joins Curtis and Prasanna to explain why the capital letter, the number, and the special character your bank demands do less for you than simply adding characters. Mike walks through the rainbow table project — an operation that has spent years computing password hashes nonstop and will sell you 20 terabytes of the results. Nobody cracks your password. They look it up. The catch, and the whole reason this episode matters, is that...
Aug. 31, 2026

RDP Security Best Practices Every Admin Ignores Until It's Too Late

RDP security best practices come down to one rule most admins break on day one: that protocol has no business facing the internet. Dr. Mike Saylor and Prasanna Malaiyandi join me to break down why RDP earned the nickname Ransomware Deployment Protocol, who's out there scanning for your open port right now, and what to actually do about it. Here's the part that gets me. Every Windows box ships with this thing turned on. You didn't ask for it. Nobody handed you a manual. It's just there, running,...
Aug. 24, 2026

Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line. We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks d...
Aug. 17, 2026

Backup Security Best Practices: Lessons From a Real Red Team Breach

Backup security best practices start with one uncomfortable truth: if you haven't checked your backup server for a default password, someone else might check it for you. In this episode, Prasanna and Mike Saylor join me to dig into how backup systems become the easiest way into your network — and the easiest way out for stolen data. We walk through the real story of a red teamer who used a backup server's weak credentials to restore a domain controller straight outside the company's firewall, th...
Aug. 10, 2026

Building a Cybersecurity Culture in Your Company (Encore)

Building a cybersecurity culture in your company doesn't take a bigger budget — it takes a weekly habit. In this final episode of our encore series, returning guest snorkel42, a longtime Reddit voice in InfoSec, breaks down how he turned a company with zero dedicated security staff into one with a real security culture, just by committing to one small improvement every week instead of waiting on the next six-figure product. We picked this one to bring back because of how it performed with you —...
Aug. 3, 2026

Cybersecurity Best Practices for Individuals (Encore)

Cybersecurity best practices for individuals aren't complicated — they're just often ignored, and that's exactly what this encore episode digs into. This is a rerun of one of our most-engaged episodes, brought back not just because of how many people downloaded it, but because of how much of it people actually stuck around for. Curtis and Prasanna sat down with Mark Shriner, host of the SecureTalk podcast, for a wide-ranging conversation about what it actually takes to protect yourself online — ...
July 27, 2026

Stopping Ransomware Lateral Movement Before It Spreads

Ransomware lateral movement is exactly what it sounds like — once an attacker's inside your network, they start crawling around looking for more to encrypt, and stopping that crawl is often the difference between a bad day and a catastrophe. In this encore episode, part four of our seven-episode series pulling the best of the archives back into your feed, W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to break down exactly how attackers move once they...
July 20, 2026

Ransomware Response Checklist: Prevent It, Slow It, Survive It

This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack. This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back. Curtis Preston and Pras...
July 13, 2026

How to Protect Backups from Ransomware (Encore)

How to protect backups from ransomware starts with a hard truth: attackers aren't just encrypting your data anymore, they're stealing it first — and no backup system on earth undoes an exfiltration. In this encore episode of The Backup Wrap-Up, Curtis and Prasanna dig into what real immutability looks like versus the marketing version, why root access quietly undermines most "immutable" storage claims, the difference between virtual and true physical air gaps, and the exact questions you should ...
July 6, 2026

What Is Data Deduplication? (Encore)

What is data deduplication, and why does Curtis call it the single most important development in backup over the last 30 years? In this encore episode, W. Curtis Preston and Prasanna Malaiyandi break down exactly how dedupe works, why it's not the same as compression, and why the fine print of your dedupe domain determines how much storage you actually save. This episode originally aired as part of the Backup to Basics series, and it's back because listeners couldn't get enough of it — not just...
June 22, 2026

The REDCap Attack that Phishing-Resistant MFA Could Have Stopped

Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it. A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin cred...
June 15, 2026

California Election Fraud? (Pt 2)

California election fraud claims are flooding social media — and most of them fall apart under basic scrutiny. In this follow-up episode, longtime San Diego County poll worker W. Curtis Preston tackles the wave of viral fraud allegations head-on, with sources so you can check his work yourself. Topics covered: the LA mayoral race "statistically impossible" surge for Nithya Raman, the AP reporting error that got blamed on fraud, claims that Spencer Pratt voters were having ballots rejected for s...
June 8, 2026

California Election Counting Explained by an Actual Poll Worker

California election counting has confused — and frankly ticked off — a lot of people, and I get it. I'm W. Curtis Preston, I've worked every California election since the 2016 presidential primary, and I've managed the polls at multiple elections here in San Diego County. This episode, I'm going solo to explain exactly what's going on, why it takes so long, what the "red mirage" actually is, and why none of it is fraud. Sorry to disappoint some of you. If you've ever had a family member call yo...
May 25, 2026

Stop 90% of Ransomware Attacks with Basic Cyber Hygiene

Basic cyber hygiene — patch management, password management, and MFA — is responsible for stopping roughly 90% of the ransomware attacks that could hit your organization. This episode is the overview: what those three things are, why they matter, and what happens when you skip them. WannaCry infected over 200,000 systems worldwide. A patch existed. People just hadn't applied it. Rackspace lost an entire business line — not because the attack was sophisticated, but because a workaround gave them...
May 18, 2026

Claude Deletes a Company — But It's Not Really Claude's Fault

Claude deletes a company — and the internet immediately blamed the AI. But this story is really about backup design, credential management, and least privilege. An AI coding agent running Claude via Cursor deleted PocketOS's entire production database and all its backups in nine seconds. One bad design decision at a time, a startup built itself a disaster waiting to happen. Claude just happened to be the thing that set it off. Here's what you need to understand: the AI violated the principles i...
May 11, 2026

How Honeypots and Canary Files Catch Attackers Before They Strike

Honeypots and canary files are two of the most underused tools in cybersecurity — and in this episode, Dr. Mike Saylor and I break down exactly how they work and why you should be using them. The short version: they're tripwires. They tell you a bad guy is poking around your network before anything gets encrypted. Mike walks through his layered security analogy, explains the three different ways organizations use honeypots — learning attacker tactics, distraction, and testing — and then we get ...
May 4, 2026

Network Segmentation to Prevent Ransomware: What the UCSF Attack Taught Us

Network segmentation to prevent ransomware isn't just a nice-to-have — the UCSF ransomware attack proves it's what separates a contained incident from a catastrophe. UCSF got hit. Their segmented network kept the damage from spreading across their entire operation. That's the difference we're talking about in this episode. Dr. Mike Saylor — my co-author on Learning Ransomware Response and Recovery — joins me and Prasanna to break down exactly how network segmentation works, why it matters for r...
April 27, 2026

Stop Using VSS as a Backup Before Ransomware Deletes Your Shadow Copies

Stop Using VSS as a Backup Before Ransomware Deletes Your Shadow Copies Ransomware deletes shadow copies using your own built-in Windows tools against you — and if VSS was your backup plan, you just found out the hard way that it wasn't. In this episode, W. Curtis Preston (Mr. Backup), Prasanna Malaiyandi, and Dr. Mike Saylor break down exactly what shadow copies are, why they don't qualify as a real backup, and how attackers are weaponizing vssadmin to wipe your recovery options before you even...
April 20, 2026

Ransomware Sanctions, OFAC, and the Lazarus Group: A Real Case Study

Ransomware sanctions are something most companies never think about — until they're staring down a ransom demand from a group the US government has already put on a sanctions list. In this episode, Dr. Mike Saylor walks us through a real incident involving a construction company, hundreds of millions in active contracts, and the Lazarus Group — a North Korean state-sponsored threat actor. Before that company could pay a single dollar in ransom, they had to figure out whether doing so would trigg...
April 13, 2026

The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your Problems

The cost of a ransomware attack goes way beyond the ransom itself — and most organizations don't find that out until it's too late. In this episode of The Backup Wrap-up, W. Curtis Preston (Mr. Backup) and co-host Prasanna Malaiyandi sit down with Dr. Mike Saylor of Black Swan Cybersecurity to walk through every category of cost that hits when ransomware strikes. The case that kicks everything off: UVM Health Network, October 2020. Over 1,300 servers encrypted, staff forced back to paper record...
April 6, 2026

How Polymorphic Malware Evades Detection — And What to Do About It

Polymorphic malware is the kind of threat that changes its own code — its signature, its behavior, even the command-and-control server it reports to — specifically so your antivirus can't catch it. In this episode, Dr. Mike Saylor of Black Swan Cybersecurity joins Prasanna and me to break down exactly how this works, why signature-based detection keeps losing the race, and what defenders actually need to do differently. Mike walks us through ViraLock, one of the most well-known early examples o...
March 26, 2026

Emergency Episode: The PyPI Software Supply Chain Attack You Need to Know About

A PyPI software supply chain attack hit LiteLLM — a library pulled into developer environments 97 million times a month — and if you use it, you may already be compromised. This wasn't a fake package or a typo-squatting trick. Attackers stole real credentials, published malicious code as the real thing, and walked out with SSH keys, cloud credentials, Kubernetes tokens, API keys, and more — all encrypted and sent home before anyone knew what happened. I'm doing something I've never done before:...
March 23, 2026

Fileless Malware: The Attack That Lives in Memory

Fileless malware is one of the most dangerous attack types out there — it never writes to your hard drive, lives entirely in RAM, and can steal your credentials before your antivirus has any idea it's there. In this episode, I bring in Dr. Mike Saylor — my co-author on Learning Ransomware Response & Recovery — to break down exactly how this attack works, why it's so hard to detect, and what you can actually do to protect yourself. Mike walks us through how fileless malware hides in memory, how ...
March 16, 2026

Living Off the Land Attack: Hackers Using Your Own Tools Against You

A living off the land attack is one of the sneakiest techniques in a ransomware operator's playbook — and in this episode, Dr. Mike Saylor breaks down exactly what it is, how it works, and what your organization can actually do about it. Instead of bringing their own tools into your environment (which might trip your alarms), attackers just use what's already there. PowerShell. WMI. RDP. The same tools your admins run every single day. To your monitoring systems, it looks completely normal. Tha...