All Episodes

Displaying 21 - 40 of 106 in total

Insight: Microsegmentation in Practice Beyond One Big Flat Network

Network microsegmentation can sound like a buzzword until you see how it actually changes the way attackers move inside your environment. In this audio version of our ...

Insight: Credential Stuffing and Password Spraying in Plain English

Credential stuffing and password spraying rarely look dramatic at first, but they sit at the center of many account takeover and fraud stories. In this audio edition, ...

Insight: Making Security Risk Registers Actually Useful

Security risk registers often feel like an audit checkbox, but they can be one of the most practical tools in your security program when they are done well. In this na...

Insight: When “Working as Designed” Breaks Your Security

Business logic flaws can be some of the most damaging weaknesses in an application, yet they rarely show up in scan results or standard test reports. In this episode, ...

Insight: Email Security Essentials for Attachments, Links, and Suspicious Messages

This narrated edition of the Tuesday “Insights” feature from Bare Metal Cyber Magazine explores Email Security Essentials in plain language, with a special focus on at...

Insight: Making Sense of the Cloud Shared Responsibility Model

When a cloud service goes down or behaves strangely, the first minutes are often spent arguing about ownership instead of solving the problem. This narrated Insight wa...

Insight: How User and Entity Behavior Analytics Spots Trouble Early

This narrated Insight walks through User and Entity Behavior Analytics (UEBA) as a practical tool for spotting the weird stuff early. You will hear how UEBA builds a p...

Insight: Understanding the Ransomware Attack Lifecycle

Ransomware attacks do not begin with the ransom note – they unfold through a quiet sequence of steps that often look like routine activity. In this Tuesday “Insights” ...

Insight: Securing Operational Technology and Industrial Control Systems

This audio edition takes you into the world of Operational Technology (OT) and Industrial Control Systems (ICS) security, where digital access and configuration change...

Insight: Browser Security Basics for Real-World Teams

Browser security can feel like a small detail compared to network diagrams and cloud architectures, but for most people in your organization, the browser is where the ...

Insight: Making Sense of Static vs Dynamic App Security Testing

Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) both promise better application security, but they look at your systems in v...

Insight: Watching What Leaves Your Environment Before It Becomes a Breach

Network egress controls can be the difference between a noisy but contained incident and a quiet data leak that nobody spots until it is too late. In this audio Insigh...

Threat-Informed Defense: Using ATT&CK and Models to Plan Improvements

Threat informed defense means using knowledge about real attacks to guide security work, so defensive choices stay connected to how adversaries actually behave in the ...

Triage 101: What Happens When an Alert Fires.

Alert triage is the first pass an analyst makes on incoming security alerts. In those first few minutes, the analyst decides whether something needs fast action or pat...

Logs, Events, and Alerts: Turning Raw Data Into a Story

Logs are the raw notes that help turn messy digital activity into clear security stories. Every website, device, and application constantly writes these notes in the b...

Types of Security Controls: Preventive, Detective, Corrective, and More

Security controls are the many small and large actions, tools, and rules that organizations use to keep information, systems, and people safe from harm. When someone i...

Defense in Depth: Layers That Work Together

Defense in depth is a simple idea that quietly shapes strong cybersecurity for real organizations. Instead of trusting one perfect barrier, defense in depth stacks sev...

Network Segmentation Made Simple

Network segmentation sounds like a complex expert topic, but it starts very simply. If you understand that computers send messages over shared roads, segmentation shap...

You Can’t Secure What You Can’t See: Asset Inventory Basics

Welcome to our exploration of why you cannot secure what you cannot see in cybersecurity. This episode focuses on asset inventory, the simple idea of knowing exactly w...

Patch and Update Management Foundations

Patch and update management is where earlier vulnerability concepts finally turn into concrete daily security actions. When you scan for weaknesses or read about new f...

Broadcast by