Sprocket Security
Ahead of the Breach
Welcome to the Ahead of the Breach, the podcast dedicated to equipping security experts and practitioners with the knowledge and insights needed to excel in the future of cybersecurity. Join us as we explore innovative strategies, emerging trends, actionable takeaways to help security leaders stay ahead.
Author
Sprocket Security
Category
Podcast website
Latest episode
May 1, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily 01.05.2026 31:06
Most security teams test their detections once a year. Gary Lobermier, Lead Adversarial Security Engineer at Northwestern Mutual, built something different: a custom automation platform that executes hundreds of MITRE ATT&CK techniques daily across Windows, macOS, Linux, and AWS, giving his team real-time signal on whether their defenses actually hold. In this episode, Gary breaks down why off...
Zoom's Andy Grant on Offensive Intuition and Letting Hackers Hunt 09.04.2026 31:07
What happens when you remove timeboxes, rigid scope, and checklist-driven testing from offensive security? In this episode of Ahead of the Breach, we sit down with Andy Grant to explore what it looks like to build an intuition-driven offensive security program, one designed to let skilled engineers follow the signal instead of the schedule. Drawing from more than a decade in consulting and product...
Accenture's Daniel Barnes on SAML exploitation and what really matters in pentesting 04.03.2026 34:36
What makes a vulnerability truly shocking is simplicity, once you notice the assumption everyone else missed. In this episode, Daniel shares a memorable SAML/SSO privilege escalation from a real engagement, then zooms out into what it takes to grow as a penetration tester: handling uncertainty, collaborating through roadblocks, and building the fundamentals that make creative problem-solving possi...
T. Rowe Price's Matthew Winters on Threat Hunting, Graph Thinking, and Making Adversaries Cry 11.02.2026 36:40
What does effective threat hunting actually look like inside large, complex environments? In this episode of Ahead of the Breach, we sit down with Matthew Winters of T. Rowe Price to unpack what it means to hunt threats at scale and why the hardest part isn’t finding suspicious behavior, but deciding where to look in the first place. Matthew brings a practitioner’s perspective shaped by years in S...
Citi's Ryan Hays Navigating Risk and Resilience at Scale 06.01.2026 22:34
What does navigating risk really look like at global scale? In this episode of Ahead of the Breach, host Casey Cammilleri sits down with Ryan Hays from Citi to explore how security teams operate inside one of the world’s largest financial institutions. Ryan shares real-world perspective on managing risk, building resilience, and making security decisions in environments defined by complexity, regu...
Microsoft's Tori Westerhoff on Offensive Security in the Age of AI 23.12.2025 32:17
In this episode of Ahead of the Breach, host Casey Cammilleri sits down with Tori Westerhoff, a member of Microsoft’s AI Red Team, to explore what offensive security looks like in the age of large language models and AI-driven systems. Tori breaks down how AI red teaming differs from traditional security testing, what it takes to identify real-world abuse cases in generative models, and why unders...
Nevada Air National Guard's Nikita Belikov on Real-World Cyber Defense at Scale 17.12.2025 33:52
In this episode of Ahead of the Breach, host Casey Cammilleri sits down with Nikita Belikov of the Nevada Air National Guard to explore what cybersecurity looks like inside a military and critical-infrastructure environment. Nikita shares insight into defending high-stakes systems where availability, resilience, and mission readiness are non-negotiable. The conversation covers how military cyber t...
MacArthur Foundation's Seth Arnoff on Top AI and Quantum Threats 12.12.2025 22:50
Live from Black Hat 2025, host Casey Cammalleri sits down with Seth Arnoff, a cybersecurity engineer at the John D. and Catherine T. MacArthur Foundation, to talk about what it really looks like to run security at a mission-driven organization with a lean team. Seth walks through the day-to-day reality—patching, vuln management, and log triage—alongside bigger culture-forward initiatives like goin...
F-Secure Corporation’s Megan Squire on How Infostealers Are Quietly Taking Over Cybercrime 02.12.2025 30:23
Live from Black Hat USA 2025, host Casey Cammilleri sat down with cyber threat-intelligence researcher Megan Squire to break down one of the fastest-growing and most misunderstood pillars of modern cybercrime: infostealers. Megan, a computer-science PhD and seasoned threat-tracking expert, walks us through how infostealers have evolved into a massive underground economy powering identity theft, fr...
What Makes Hybrid Pentesting So Powerful? 30.09.2025 1:18
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses what makes hybrid pentesting so powerful. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why you're looking for an...
GreyNoise’s Andrew Morris on Internet Background Noise as Data 23.09.2025 29:09
What if you could predict major security vulnerabilities weeks before they're publicly disclosed? Andrew Morris , Founder & Chief Architect at GreyNoise Intelligence , built a global sensor network that does exactly that by tracking internet-wide scanning patterns that spike 3-4 weeks before critical vulnerabilities become public knowledge. This transforms the chaotic noise of billions of dail...
How Does Expert-Driven Offensive Security Provide Comprehensive Risk Insight? 16.09.2025 1:33
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses how expert-driven offensive security provides comprehensive risk insight. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summ...
Sprinklr’s Roger Allen on Why Vendor Telemetry Only Gets You 90% There 09.09.2025 24:06
Modern attackers have abandoned obvious indicators and now mimic legitimate engineering activities so closely that traditional detection methods fail. Roger Allen , Sr. Director, Global Head of Detection & Response at Sprinklr , has watched this evolution firsthand. He gives Casey the rundown of how his team's response involves outcome-based detection strategies that focus on what attackers ac...
Why is Continuous Pentesting a Must for Dynamic Environments? 02.09.2025 1:42
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses why continuous pentesting is a must for dynamic environments. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why y...
Armis’ Andrew Grealy on Left-of-Boom Threat Actor Intelligence 26.08.2025 28:09
What if you could predict which vulnerabilities threat actors will weaponize months before CISA adds them to their Known Exploited Vulnerabilities list? Andrew Grealy , Head of Armis Labs , has built exactly that capability, providing organizations with threat intelligence that arrives 3-12 months ahead of traditional indicators. His "left of boom" approach changes how security teams prioritize pa...
How Do You Build an Offensive Security Program from Scratch? 19.08.2025 2:45
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses how to build an offensive security program from scratch. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why you're...
Covert Entry: Tools, Tricks, and True Stories from the Field 12.08.2025 31:39
What happens when a covert entry specialist turns a Super Bowl hotel room into a rooftop breach point? Brent White , Sr. Principal Security Consultant & Covert Entry Specialist at Dark Wolf Solutions , offers Casey his approach to physical security testing that goes far beyond lock picking, rooted in understanding human psychology and building systematic infiltration strategies. Brent shares h...
What Should You Ask Before Choosing an Offensive Security Platform? 05.08.2025 2:45
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey covers what you should ask before choosing an offensive security program. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why...
Phillip Wylie on How IoT Devices Become Corporate Network Entry Points 29.07.2025 28:50
After 21 years in cybersecurity, Phillip Wylie , Penetration Tester & Podcast Host at The Phillip Wylie Show , has learned how a critical flaw in how most organizations approach security testing when a "low-risk" vulnerability suddenly became exploitable between scheduled assessments. He shares this knowledge with Casey , and more, including why annual penetration testing creates dangerous gap...
What Tools Do You Need for an Offensive Security Stack? 22.07.2025 2:08
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses the tools needed for an offensive security stack. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why you're lookin...
AccessIT Group’s Brett Price on Governance-Driven Cybersecurity 15.07.2025 35:25
Many cybersecurity programs fail because they prioritize tools over understanding what they're protecting. Brett Price , Lead Cybersecurity Consultant & vCISO at AccessIT Group , brings decades of experience to explain why data discovery and governance create more security value than any technology purchase. His approach starts with mapping critical data to business functions before implementi...
What Steps Should You Take to Build a Modern Pentesting Program? 08.07.2025 3:34
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses 5 steps to building a modern pentesting program. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why you're looking...
Parthasarathi Chakraborty on Building Architectural Assurance Functions 01.07.2025 42:13
Most security architecture programs struggle to demonstrate their value because they focus on creating diagrams rather than driving implementation. Parthasarathi Chakraborty , Former Deputy CISO at Natixis CIB , shares his approach to transforming security architecture from theoretical frameworks to measurable business impact. With experience across Fortune 15 banks to mid-market companies, Parth...
What Are the Common Myths About Continuous Pentesting? 24.06.2025 2:32
Welcome to a special edition of Ahead of the Breach, where our host Casey Cammilleri answers the top questions our listeners have asked us. In today's episode, Casey addresses the most common myths around continuous pentesting. Would you like to have Casey answer one of your questions in a future episode? Email podcast@sprocketsecurity.com with your question and a short summary of why you're look...
Rocket Lawyer’s Tim Silverline on Why Clean Pentest Reports Can Be Red Flags 17.06.2025 17:08
When Tim Silverline received a pentest report that was essentially a clean bill of health with zero evidence of actual testing, he knew his security program had a problem. As Vice President of Security at Rocket Lawyer , this experience sparked a complete transformation from annual security theater to continuous, evidence-based testing that provides actionable intelligence — with Sprocket! In his...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.