Dr. Jason Edwards
Bare Metal Cyber
Welcome to Bare Metal Cyber, the podcast that bridges cybersecurity and education in a way that’s engaging, informative, and practical. Hosted by Dr. Jason Edwards, a seasoned cybersecurity expert and educator, this weekly podcast brings to life the insights, tips, and stories from his widely-read LinkedIn articles. Each episode dives into pressing cybersecurity topics, real-world challenges, and actionable advice to empower professionals, educators, and learners alike. Whether navigating the complexities of cyber defense or looking for ways to integrate cybersecurity into education, Bare Meta...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Jul 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
SBOM & Chill: You Don’t Need Every Ingredient—Just the Allergens 24.12.2025 35:31
In this episode, we strip away the noise surrounding Software Bills of Materials and reframe them through a fresh lens: allergens. Instead of drowning in endless dependency lists, you’ll learn how to identify the handful of components that can actually break your security posture—known exploited vulnerabilities, crypto and authentication stacks, choke-point libraries, abandoned projects, legal tra...
Insight: Asset Inventory Basics for Real-World Defenders 23.12.2025 15:20
In this narrated Insight, we unpack cyber asset inventory as the quiet backbone of a modern security program. You will hear what cyber asset inventory really means in today’s mix of on-prem, cloud, and SaaS, and where it fits among your existing tools and processes. We walk through why “you can’t secure what you can’t see” is not just a slogan, but a practical reality for vulnerability management,...
Certified: How CCISO Signals You’re Ready for Executive Security Leadership 22.12.2025 10:00
The Certified Chief Information Security Officer (CCISO) exam is built for security leaders who are ready to move from running tools to running a program, and this narrated episode walks through what that shift really means. You will hear a clear breakdown of what CCISO is, who it is designed for, and how it differs from more technical certifications you may know. The episode is based on my Monday...
Cyber Talks: Tracking School Swatters and Shooters: Turning Online Leakage Into Action with Detective Richard Wistocki 18.12.2025 54:51
In my conversation with Detective Richard Wistocki (Ret.) , we talked candidly about a reality that many school leaders and law enforcement professionals already feel in their bones: online threats are constant, confusing, and often paralyzing. This Cyber Talk, developed by BareMetalCyber.com, focuses on what it really takes to track school swatters and potential shooters through “leakage” in soc...
Tabletop Telenovela: Turning Your IR Plan into a Drama People Remember 17.12.2025 24:00
In this episode, you’ll learn how to transform a traditional, forgettable tabletop exercise into something unforgettable: a telenovela. We explore how to recast roles as characters with motives, build dramatic arcs with twists and cliffhangers, and use realistic props to make your IR plan come alive. Instead of walking through checklists, you’ll hear how to stage a story your team will actually re...
Insight: Turning Patch and Update Management into a Strength 16.12.2025 14:49
Patch and update management rarely makes headlines, but it quietly determines how exposed your environment really is. In this audio Insight, we walk through the foundations of a solid patch and update management practice, from intake of vendor advisories and scan results through testing, change windows, rollout, and verification. You will hear how this discipline sits between security, operations,...
Certified: Stepping Into Security Leadership with CISM 15.12.2025 11:16
This episode takes you inside the world of the Certified Information Security Manager (CISM), a certification that helps professionals grow from hands-on security work into roles that shape programs, policies, and risk decisions. In clear, beginner-friendly language, the narration explains what CISM is, who it is really for, and how it changes the way you think about governance, risk management, a...
Cyber Talks: Phishing in the Age of Agentic AI: Craig Taylor on Culture, Literacy, and the New Human Firewall 11.12.2025 55:35
In my Cyber Talks conversation with Craig Taylor the co-founder and CEO of CyberHoot , we dive into a problem that is evolving faster than most organizations can keep up: phishing in the age of agentic AI . Cyber Talks, developed by BareMetalCyber.com , is all about learning from practitioners who are pushing the field forward, and Craig has spent three decades on the front lines of security, risk...
Email Is Your Unpatchable Legacy App 10.12.2025 28:28
In this episode, we explore why email is both the oldest and most dangerous application in your enterprise. You’ll learn how protocols built in the 1970s still carry modern business logic, why attackers thrive on its openness, and how Business Email Compromise has evolved into one of the most profitable cybercrimes in history. The discussion traces the history of email’s insecure DNA, the patchwor...
Insight: How CVEs and CVSS Turn Vulnerabilities into Decisions 09.12.2025 14:38
Understanding vulnerability data can feel like learning a new language, especially when every report is packed with identifiers and scores. In this narrated Insight, we walk through the relationship between software vulnerabilities, Common Vulnerabilities and Exposures (CVE), and the Common Vulnerability Scoring System (CVSS). You will hear how vulnerabilities move from discovery to public CVE rec...
Certified Monday: Seeing Systems Like an Auditor with the CISA Certification 08.12.2025 11:25
This episode walks through the Certified Information Systems Auditor (CISA) certification in clear, beginner-friendly language, focusing on what it really means to think like an IT auditor. You will hear how CISA frames technology in terms of controls, evidence, and risk, and why that perspective matters if you want to move closer to audit, governance, or technology risk roles. The narration is ba...
Weekly Cyber News Rollup, December 5th, 2025 05.12.2025 18:04
This is your weekly cyber news roll-up for the week ending December 5th, 2025. Holiday shopping dominates the threat landscape, with industrial scale fake Christmas and Cyber Monday stores siphoning card data while a massive breach at Korean retail giant Coupang exposes tens of millions of shoppers. At the same time, attackers are burrowing into the software factory, from exposed secrets in cloud...
Cyber Talks: Excel Is Not Your GRC Solution: Scaling Governance Beyond Spreadsheets 04.12.2025 48:26
Excel is great for many things — but it is not a governance, risk, and compliance (GRC) platform. In this Cyber Talk developed by BareMetalCyber.com, Dr. Jason Edwards sits down with Dean Charlton , Managing Director of DC CyberTech , to unpack why even the most well-intentioned GRC programs stall out when they live in spreadsheets. Dean walks through the real-world pain points of “Excel-driven” G...
Shadow SaaS: 1,000 Apps, 0 Approvals, Unlimited Risk 03.12.2025 28:32
In this episode, we pull back the curtain on Shadow SaaS—the hidden world of unsanctioned apps quietly multiplying across the enterprise. You’ll learn how a single “Sign in with Google” click can spawn a durable, invisible connection, why OAuth tokens never seem to die, and how browser extensions and plug-ins form entire shadow ecosystems. We trace the blast radius from data leaks to compliance fa...
Insight: Cyber Kill Chain and Attack Lifecycles 02.12.2025 10:37
This narrated Insight walks through the Cyber Kill Chain (CKC) and broader cyber attack lifecycle models as practical tools for real-world defenders. You’ll hear how CKC breaks an intrusion into recognizable stages, from reconnaissance to actions on objectives, and how that gives analysts and engineers a common storyline for messy, real-world incidents. The audio stays vendor-neutral and plain-lan...
Certified: CompTIA Security+ as Your Cybersecurity Launchpad 01.12.2025 12:11
Step into the world of CompTIA Security+ (Security+) with this narrated guide designed for early-career technologists and career-changers. This episode explains what Security+ actually covers, who it is really for, and why so many entry-level security and IT roles call it out by name. You will hear how the exam objectives translate into real skills around threats, defenses, secure design, and day-...
Weekly Cyber News Rollup, November 28th, 2025 28.11.2025 19:10
This is your weekly cyber news roll-up for the week ending November 27th, 2025. This week revolves around quiet dependencies turning into loud problems, from abandoned calendar links that can be hijacked to analytics and customer platforms leaking sensitive context. You will hear about a breach at an OpenAI analytics vendor that exposes who is building on artificial intelligence, A I, projects and...
Zero Trust Theater: We Put a Fancy Gate on a Cardboard Wall 26.11.2025 29:23
In this episode, we uncover the reality of “Zero Trust theater”—where organizations invest in flashy front gates like MFA prompts, dashboards, and vendor logos while leaving the walls behind them flimsy and unprotected. Listeners will learn how these illusions are built, where attackers push through the cardboard, and the specific tactics adversaries use to bypass props. From consent phishing and...
Weekly Update: Cyber News for the Week ending 21 November, 2025 21.11.2025 30:14
This is your weekly cyber news roll-up for the week ending November 21st, 2025. We track a crippling cyberattack on a major automaker that shut factories and erased hundreds of millions in profit. We also follow a suspected China aligned espionage group that turned an artificial intelligence, A I, coding agent into an automated intrusion assistant. Fresh consumer and supporter data breaches, inclu...
Cyber Talks - Break Things Safely: A High-Value Cyber Exercise Program with Daniel Hammond 20.11.2025 48:05
Don’t wait to learn the fire drill while the building’s on fire. In this Cyber Talk developed by BareMetalCyber.com, Army veteran and cyber resilience strategist Daniel Hammond shows how to move past check-the-box drills and turn exercises into a core learning culture. He walks through goal-driven planning (so every exercise serves a sponsor’s real need), the HSEEP spectrum from seminars and works...
XDR, EDR, NDR, MDR, WTF-DR? 19.11.2025 29:01
In this episode, we cut through the alphabet soup of cybersecurity—EDR, NDR, XDR, MDR, and even the tongue-in-cheek WTF-DR. You’ll learn what each of these acronyms really means, how they differ, and where they overlap. More importantly, you’ll gain clarity on how they fit together in practice, why no single tool is enough, and how to build a layered defense without wasting budget on hype. Through...
Weekly Cyber News Rollup, November 14th, 2025 14.11.2025 12:15
This is your weekly cyber news roll-up for the week ending November 14th, 2025. This week centers on phones, clouds, and core identity systems under pressure from well funded attackers who prefer to move quietly. You will hear how new spyware campaigns abuse Samsung devices and WhatsApp features, while hotel and travel scams blend real booking details with fresh malware delivery. The episode also...
Phishing ‘Hunger Games’: May the Odds Be Ever in Your Favor (They Aren’t) 12.11.2025 31:06
In this episode, we explore phishing as a rigged arena where attackers decide the rules and employees become the unwilling contestants. You’ll learn how phishing has evolved from clumsy spam into precision-engineered deception powered by AI, reverse proxies, and multi-channel choreography. We unpack the psychology that adversaries exploit—urgency, authority, and scarcity—and show how identity prot...
Weekly Cyber News Rollup, November 7th, 2025 08.11.2025 16:03
This is this week’s cyber news for November third through November seventh, twenty twenty-five. The week unfolded with relentless attacks on edge infrastructure, high-stakes data breaches, and fresh discoveries in global espionage campaigns. Cisco faced active exploitation of its Secure Firewalls and routers, SonicWall confirmed a state-backed backup theft, and Conduent revealed exposure of over t...
The Cult of the Dashboard: Vanity Metrics Anonymous 05.11.2025 29:27
In this episode, The Cult of the Dashboard: Vanity Metrics Anonymous , we expose the seductive world of flashy dashboards and meaningless numbers. Listeners will learn why organizations cling to vanity metrics, how executive reports can hide more than they reveal, and what truly matters when measuring security. From the psychological pull of green stoplights to the perverse incentives that reward...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.