Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
2021-035-GRC selection discussion, TechSecChix, and the 'job description problem' 29.09.2021 1:06:57
GRC tools (Governance Risk and Compliance) @ki_twyce_ @TechSecChix INfosec unplugged Security Happy Hour Eric's cyberpoppa show Cyber Insight show - cohost Blumira is hiring https://www.blumira.com/careers/ https://www.cio.com/article/3206607/what-is-grc-and-why-do-you-need-it.html https://www.pwc.ch/en/insights/fs/10-pitfalls-when-implementing-grc-technology-and-how-to-avoid-th...
2021-034-Khalilah Scott, good GRC tool practices - part1 29.09.2021 43:59
GRC tools (Governance Risk and Compliance) @ki_twyce_ @TechSecChix INfosec unplugged Security Happy Hour Eric's cyberpoppa show Cyber Insight show - cohost Blumira is hiring https://www.blumira.com/careers/ https://www.cio.com/article/3206607/what-is-grc-and-why-do-you-need-it.html https://www.pwc.ch/en/insights/fs/10-pitfalls-when-implementing-grc-technology-and-how-to-avoid-th...
2021-033-Kim_Crawley, 8 steps to better security-Part2 20.09.2021 41:49
8 Steps to Better Security: A Simple Cyber Resilience Guide to Business is done all final editing and will be published by @WileyTech on October 5th. Pre-orders are available now via Amazon, Barnes & Noble, and other retailers. Sponsored Link: https://amzn.to/3k3pDAN Amazon teaser: " Harden your business against internal and external cybersecurity threats with a single accessible resource...
SPONSOR: Blumira's Patrick Garrity 16.09.2021 48:10
Blumira- Per crunchbase: " Blumira's end-to-end platform offers both automated threat detection and response, enabling organizations of any size to more efficiently defend against cybersecurity threats in near real-time. It eases the burden of alert fatigue, complexity of log management and lack of IT visibility. Blumira's cloud SIEM can be deployed in hours with broad integration coverage across...
2021-032--Author_Kim_crawley-8-Simple_Rules_for_Cybersecurity 14.09.2021 42:10
8 Steps to Better Security: A Simple Cyber Resilience Guide to Business is done all final editing and will be published by @WileyTech on October 5th. It is available now via Kindle. Pre-orders are available now via Amazon, Barnes & Noble, and other retailers. Sponsored Link: https://amzn.to/3k3pDAN Amazon teaser: " Harden your business against internal and external cybersecurity threats wi...
2021-031- back in the saddle, conference discussion, company privacy 03.09.2021 1:02:07
"bel paese, ma più caldo del buco del culo di Satana" https://www.theverge.com/22648265/apple-employee-privacy-icloud-id https://mysudo.com/ https://arstechnica.com/information-technology/2021/09/npm-package-with-3-million-weekly-downloads-had-a-severe-vulnerability/ https://www.bleepingcomputer.com/news/security/bluetooth-braktooth-bugs-could-affect-billions-of-devices/ www.infoseccampout.com www...
2021-030-incident response, business goal alignment, showing value in IR -p2 22.08.2021 45:58
https://blog.teamascend.com/6-phases-of-incident-response https://www.securitymetrics.com/blog/6-phases-incident-response-plan Recent vulnerabilities got Bryan thinking about incident response. Are organizations speedy enough to keep up? If the spate of vulns continue, what can we do to ensure we are dealing with the most important issues? How do we communicate those issues to management? How sho...
2021-029- incident response, PICERL cycle, showing value in IR, aligning with business goals -p1 15.08.2021 40:08
https://blog.teamascend.com/6-phases-of-incident-response https://www.securitymetrics.com/blog/6-phases-incident-response-plan Recent vulnerabilities got Bryan thinking about incident response. Are organizations speedy enough to keep up? If the spate of vulns continue, what can we do to ensure we are dealing with the most important issues? How do we communicate those issues to management? How sho...
2021-028-Rebekah Skeete - social engineering techniques and influences 08.08.2021 53:30
BlackGirlsHack was created to share knowledge and resources to help black girls and women breakthrough barriers to careers in information security and cyber security. The vision for Black Girls Hack (BGH) is to provide resources, training, mentoring, and access to black girls and women and increase representation and diversity in the cyber security field and in the executive suites. Rebekah Skeet...
2021-027-Black Girls Hack COO Rebekah Skeete! 02.08.2021 1:08:57
BlackGirlsHack was created to share knowledge and resources to help black girls and women breakthrough barriers to careers in information security and cyber security. The vision for Black Girls Hack (BGH) is to provide resources, training, mentoring, and access to black girls and women and increase representation and diversity in the cyber security field and in the executive suites. Rebekah Skeet...
2021-026-Triaging threat research, Jira vulns, Serious Sam vuln, Systemd vulns, and HiveNightmare 28.07.2021 56:38
https://www.mindtools.com/pages/article/newHTE_95.htm https://www.infoq.com/news/2021/07/microsoft-linux-builder-mariner/ https://www.productplan.com/glossary/action-priority-matrix/ More PrintNightmare issues: https://www.bleepingcomputer.com/news/microsoft/windows-10-july-security-updates-break-printing-on-some-systems/ " "After installing updates released July 13, 2021 on domain controllers (...
2021-025-Dan Borges, Author of Adversarial Techniques from Packt Publishing 19.07.2021 48:17
Dan Borges - Author @1njection Buy the book on Amazon: https://www.amazon.com/Adversarial-Tradecraft-Cybersecurity-real-time-computer-ebook-dp-B0957LV496/dp/B0957LV496?_encoding=UTF8&me=&qid=&linkCode=ll1&tag=bdspod-20&linkId=8f2daf0b3563cbbc2cee6a2d2138149d&language=en_US&ref_=as_li_ss_tl https://news.sophos.com/en-us/2021/07/04/independence-day-revil-uses-supply-chain-exploit-to-attack-hund...
2021-024-Dan Borges, Author of Adversarial Techniques from Packt Publishing 10.07.2021 35:08
Dan Borges - Author @1njection Buy the book on Amazon: https://www.amazon.com/Adversarial-Tradecraft-Cybersecurity-real-time-computer-ebook-dp-B0957LV496/dp/B0957LV496?_encoding=UTF8&me=&qid=&linkCode=ll1&tag=bdspod-20&linkId=8f2daf0b3563cbbc2cee6a2d2138149d&language=en_US&ref_=as_li_ss_tl https://news.sophos.com/en-us/2021/07/04/independence-day-revil-uses-supply-chain-exploit-to-attack-hundr...
2021-023-d3fend framework, DLL injection types, more solarwinds infections 30.06.2021 57:39
Pihole setup Conference talk https://www.reuters.com/technology/microsoft-says-new-breach-discovered-probe-suspected-solarwinds-hackers-2021-06-25/ https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html https://www.ehackingnews.com/2021/06/attackers-pummelled-gaming-industry.html https://www.bleepingcomputer.com/news/microsoft/windows-11-wont-work-without-a-tpm-w...
2021-022-github policy updates targeting harmful software, Ms. Berlin discusses WWHF, CVSS discussion 22.06.2021 48:25
Ms. Berlin's conference report WWFH (reno, NV) Her next appearances will be at Defcon 2021 and BlueTeam Con 2021! https://www.infosecurity-magazine.com/news/amazon-prime-day-phishing-deluge/ https://www.ehackingnews.com/2021/06/threat-actors-use-google-drives-and.html https://www.kennasecurity.com/blog/vulnerability-score-on-its-own-is-useless/ https://portswigger.net/daily-swig/nist-charts-course...
2021-021-Security Sphynx, ZeroTrust, implementation prep- part2 16.06.2021 54:26
EO from President Biden asked for a plan to create Zerotrust implementation in the next 90 days (well, 70ish days now… as of 23 May) https://twitter.com/SecuritySphynx/status/1390475868032618496 @securitySphynx "CIO: Zero Trust is the way…" What is the optimal configuration (read: easiest) zero trust config? Are there different ways to implement Zero Trust?` https://solutions.pyramidci.com/blog/po...
2021-020: Security Sphynx, Preparing for ZeroTrust implementation - Part1 06.06.2021 42:39
Full show notes are available here: https://docs.google.com/document/d/14dCpXeQ520IcZC3m007zVPhlIPXKgfv0LkqVnbDx0fc/edit?usp=sharing EO from President Biden asked for a plan to create Zerotrust implementation in the next 90 days (well, 70ish days now… as of 23 May) https://twitter.com/SecuritySphynx/status/1390475868032618496 @securitySphynx "CIO: Zero Trust is the way…" What is the optima...
2021-019-Joe Gray, OSINT CTFs, gamifying and motivating to do the right thing 28.05.2021 47:13
part 2: CTF OSINT discussion How people will give additional information, even if they aren't receiving points for it. Gamifying and motivating people to 'do the right thing', like offering a chance to win a lottery for a covid vaccine, or free sports tickets to get a shot, or gift cards when reporting phishes. Joe Gray @C_3PJoe OSINTION https://theosintion.com New book… ship date? How to ge...
2021-018-LawyerLiz, Pres. Biden's EO, and the clueless professor 22.05.2021 1:04:03
Elizabeth Wharton: @lawyerliz on Twitter Executive Order: ( https://www.americanbar.org/groups/public_education/publications/teaching-legal-docs/what-is-an-executive-order-/ ) " An executive order is a signed, written, and published directive from the President of the United States that manages operations of the federal government. They are numbered consecutively, so executive orders may be refere...
2021-017-Joe Gray on his future book, the OSINT loop, motivators, and gamification - part1 18.05.2021 46:46
Joe Gray @C_3PJoe OSINTION https://theosintion.com New book… ship date? How to get it? https://www.amazon.com/Practical-Social-Engineering-Joe-Gray/dp/171850098X/ https://nostarch.com/practical-social-engineering "Gray provides a very accessible look at social engineering that should be essential reading for pentesters and ethical hackers." — Ian Barker, BetaNews Story (Bryan: found my s...
2021-016-researchers knowingly add vulnerable code to linux kernel, @pageinsec joins us to discuss -part2 05.05.2021 45:19
Updates to the Linux kernel controversy: https://lwn.net/SubscriberLink/854645/334317047842b6c3/ @pageinSec on Twitter Dan Kaminsky obit: https://www.theregister.com/2021/04/25/dan_kaminsky_obituary/ Spencer Geitzen: http://brakeingsecurity.com/2018-024-pacu-a-tool-for-pentesting-aws-environments https://en.wikipedia.org/wiki/Milgram_experiment https://lore.kernel.org/lkml/20210421130105...
2021-015-researchers knowingly add vulnerable code to linux kernel, @pageinsec joins us to discuss -part1 27.04.2021 47:26
@pageinSec on Twitter Dan Kaminsky obit: https://www.theregister.com/2021/04/25/dan_kaminsky_obituary/ Spencer Geitzen: http://brakeingsecurity.com/2018-024-pacu-a-tool-for-pentesting-aws-environments https://en.wikipedia.org/wiki/Milgram_experiment https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh@linuxfoundation.org/ https://cse.umn.edu/cs/statement-cse-linux-kernel-research...
2021-014-Slipstreaming blocked by Chrome, Slack being used for malware, plus dork and deskjockeys! 13.04.2021 51:59
Chrome Blocks Port 10080 to Prevent Slipstreaming Hacks - E Hacking News - Latest Hacker News and IT Security News https://www.reddit.com/r/netsec/comments/jlu3cf/nat_slipstreaming/ Samy Kamkar - NAT Slipstreaming v2.0 Slack and Discord are Being Hijacked by Hackers to Distribute Malware - E Hacking News - Latest Hacker News and IT Security News Texan's alleged Amazon bombing effort fizzles: M...
2021-013-Liana_McCrea-Garrison_Yap-cecil_hotel, Elisa_Lam-physical_security-part2 07.04.2021 58:34
Reparations.tech *Public Safety Coordinators -Field Operations (Road Incidents) -Specialized Buildings (The Library, Medical Facilities, CCR) *Public Safety Officers A. Discuss Training - SOP Creation *SOPs are very custom and dependent on the organization. There are no "NIST" standards. [IN CYBER: Frameworks for Physical Security ---> ] *Think on your feet, many plans often get thrown out th...
2021-012-physical security discussion with @geecheethreat and @garrisony75 -pt1 30.03.2021 33:10
Bios for guests Reparations.tech *Public Safety Coordinators -Field Operations (Road Incidents) -Specialized Buildings (The Library, Medical Facilities, CCR) *Public Safety Officers A. Discuss Training - SOP Creation *SOPs are very custom and dependent on the organization. There are no "NIST" standards. [IN CYBER: Frameworks for Physical Security ---> ] *Think on your feet, many plans often...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.