Building a cybersecurity culture in your company doesn't require a bigger budget — it requires a weekly habit, and this encore episode shows you exactly how one team pulled it off.

This is the final episode in our encore series, where we brought back the episodes that connected with you most — not just by download count, but by how much of each episode you actually stuck around for. This one hit both marks, and plenty of you came back to it more than once.

Our guest is snorkel42, a longtime Reddit voice in InfoSec with a series of posts on what he calls "security cadence." He worked at a company with no dedicated InfoSec team, a data center full of unused six-figure security tools, and a habit of blaming every incident on a product they didn't own yet. So he challenged his team to a six-month experiment: one security change a week, no new vendor purchases allowed. By the end, leadership wasn't just noticing — they were asking the team to spend more, because they could see the results.

We get into how that six-month experiment turned into a lasting cybersecurity culture, the early friction points the team had to work through, and how snorkel42 decides what makes it into a security cadence post. Then we shift into practical ground: MFA and why not all forms of it are equal, the SIM jacking risk baked into SMS-based codes, and the push-notification bombing tactics attackers use to wear down tired users until they hit "yes." We close on patching, WannaCry, and snorkel42's case for building your cybersecurity culture around how attacks actually function instead of chasing whatever exploit is in the news that week.

If you're the one quietly holding security together at your company, or you're trying to make the case that culture matters as much as the next purchase, this conversation is for you.

00:00:00 — Cold open: you already own the tools you need

00:01:36 — Show intro and disclaimers

00:04:05 — Guest introduction: snorkel42's Reddit history and security cadence series

00:05:53 — Where the term "security cadence" came from

00:08:40 — Early challenges building the habit

00:44:57 — MFA, password security, and why not all MFA is equal

00:47:46 — SIM jacking and push-notification fatigue attacks

00:51:45 — Patching, WannaCry, and why chasing zero-days misses the point

Subscribe for more conversations on backup, recovery, and cyber recovery, and check out the full back catalog of The Backup Wrap-Up wherever you listen.