Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

2021-011- Dr. Catherine J Ullman, the art of communication in an Incident - Part 2 21.03.2021

In this episode: knowing your audience - discussing the IR impact how did this happen? how deep do you want to tailor your potential discussion? Every level must be asking "what, when, why, how?", not just those in the trenches does the level of incident mean that communication scales accordingly? And much more!   Dr. Catherine J. Ullman (@investigatorchi) Incident Response communications Reminder...

2021-010- Dr. Catherine J Ullman, the art of communication in an Incident - Part 1 17.03.2021

Dr. Catherine J. Ullman (@investigatorchi)   Incident Response communications   Reminders: Patreon Jeff T. just became a $2 patron! Accepted to CircleCityCon on IR communications! Bsides Rochester Security B-Sides Rochester   Spoke at SeaSec meetups: Qualys Update on Accellion FTA Security Incident | Qualys Security Blog   Security Advisory | SolarWinds   Family Educational Rights and Privacy Act...

2021-009-Jasmine_Jackson-TheFluffy007-analyzing_android_apps-FRida-Part2 07.03.2021

@thefluffy007 A Bay Area Native (Berkeley) I always tell people my computer journey started at 14, but it really started at 5th grade (have a good story to tell about this) Was a bad student in my ninth grade year - almost kicked out of high school due to cutting. Had a 1.7 GPA. After my summer internship turned it around to a 4.0. Once I graduated from high school, I knew I wanted to continue on...

2021-008-Jasmine jackson - TheFluffy007, Bio and background, Android App analysis - part 1 02.03.2021

@thefluffy007 A Bay Area Native (Berkeley) I always tell people my computer journey started at 14, but it really started at 5th grade (have a good story to tell about this) Was a bad student in my ninth grade year - almost kicked out of high school due to cutting. Had a 1.7 GPA. After my summer internship turned it around to a 4.0. Once I graduated from high school, I knew I wanted to continue on...

2021-007-News-Google asking for OSS to embrace standards, insider threat at Yandex, Vectr Discussion 21.02.2021

Links to discussed items: Yandex Employee Caught Selling Access to Users' Email Inboxes (thehackernews.com) Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple | Threatpost Google pitches security standards for 'critical' open-source projects | SC Media (scmagazine.com)   Google's approach to secure software development and supply chain risk management | Google Cloud Blog h...

2021-006-Ronnie Watson (@secopsgeek), building a security monitoring system with ELK, and Wazuh - part2 14.02.2021

Ronnie Watson (@secopsgeek) Youtube: watson infosec - YouTube watsoninfosec (Watsoninfosec) · GitHub   Feel free to add anything you like Wazuh - fork of OSSEC ( Migrating from OSSEC · Wazuh · The Open Source Security Platform )   GitHub - ossec/ossec-hids: OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit...

2021-005-Ronnie Watson (@secopsgeek), building a security monitoring system with ELK, and Wazuh 09.02.2021

Ronnie Watson (@secopsgeek) Youtube: watson infosec - YouTube watsoninfosec (Watsoninfosec) · GitHub Wazuh - fork of OSSEC ( Migrating from OSSEC · Wazuh · The Open Source Security Platform )   GitHub - ossec/ossec-hids: OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and act...

2021-004-Danny Akacki talks about Mergers and Acquisitions - Part 2 03.02.2021

Discussion on Mergers and acquisitions processes On being acquired, but also if you're acquiring a company Best Practices Best Practices of Mergers and Acquisitions (workforce.com) Best Practices In Merger Integration - Institute for Mergers, Acquisitions and Alliances (IMAA) (imaa-institute.org) The Role of Information Security in a Merger/Acquisition (bankinfosecurity.com) Security Consideration...

2021-003- Danny Akacki, open communications, mergers&acquistions 26.01.2021

Discussion on Mergers and acquisitions processes On being acquired, but also if you're acquiring a company Best Practices Best Practices of Mergers and Acquisitions (workforce.com)   Best Practices In Merger Integration - Institute for Mergers, Acquisitions and Alliances (IMAA) (imaa-institute.org)   The Role of Information Security in a Merger/Acquisition (bankinfosecurity.com)   Security Conside...

2021-002-Elastic Search license changes, Secure RPC patching for windows, ironkey traps man's $270 million in Bitcoin 19.01.2021

  Secure RPC issue -  Netlogon Domain Controller Enforcement Mode is enabled by default beginning with the February 9, 2021 Security Update, related to CVE-2020-1472 – Microsoft Security Response Center How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (microsoft.com) Netlogon Domain Controller Enforcement Mode is enabled by default beginning with the F...

2021-001-news, youtuber 'dream' doxxed, solarwind passwords bruteforced, malware attacks 12.01.2021

Dream Doxxed: Minecraft YouTuber Dream Doxxed Following Speedrun Controversy (screenrant.com) Def Noodles on Twitter: "STANS TAKING IT TOO FAR: Dream doxed after posting a picture of his kitchen on his 2nd Twitter account. Dream has not published statement about situation yet in his public accounts. https://t.co/QuKpIYRODQ" / Twitter Osint issues… found him by breadcrumbs and using zillow internal...

2020-046-solarwinds-fireeye-breaches-GE-medical-device-issues-and-2021_predictions 17.12.2020

End of year podcast   Blumeria sponsorship NEWS:   IT company SolarWinds says it may have been hit in 'highly sophisticated' hack | Reuters   FireEye hacked: US cybersecurity firm FireEye hit by 'state-sponsored' attack - BBC News     https://krypt3ia.wordpress.com/ - 16 december 2020   Microsoft flexing muscle to shutdown c2: Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary...

SPONSORED- Nathanael Iversen from Illumio, future of microsegmentation, 07.12.2020

BrakeSec Sponsored Interview with Nathanael Iversen   Questions, comments, and other content goes here:   Illumio Nathanael Iversen BDS Podcast Messaging   Topic: Overview of development and deployment of micro-segmentation   Where does segmentation fit into your security strategy?  Micro-segmentation is a preventive measure deployed to create and enforce access at the workload layer. It does not...

2020-045-Marco Salvati, supporting open source devs, incentivizing leeching companies who don't give back- part2 07.12.2020

https://www.hak4kidz.com/activities/cdcedu.html Online CTF training using Cisco's Workshop platform. They did something similar in Spring of 2020. There will be an online panel where kids can ask questions about information security. Occurs on December 12th. Check out the link for more info. Robert M. for upping his patreon to $5 Top 25 Data Security Podcasts You Must Follow in 2020 (feedspot.com)...

2020-044-Marcello Salvati (@byt3bl33d3r), porchetta industries, supporting opensource tool creators, sponsorship model 02.12.2020

https://www.hak4kidz.com/activities/cdcedu.html Online CTF training using Cisco's Workshop platform. They did something similar in Spring of 2020. There will be an online panel where kids can ask questions about information security. Occurs on December 12th. Check out the link for more info. Robert M. for upping his patreon to $5 Top 25 Data Security Podcasts You Must Follow in 2020 (feedspot.com)...

2020-043-Software_Defined_Radio-Sebastien_dudek-RF-attacks- IoT and car RF attacks 24.11.2020

Sébastien Dudek -  @FlUxIuS @penthertz Why we are here today? Software Defined Radio (sdr-radio.com) What kind of hardware or software do you need?  Why would a security professional want to know how to use SDR tools and attacks? What other kinds of attacks can be launched? (I mean, other than replay type attacks) Door systems (badge systems) NFC? Contactless credit card attacks  Smart building/ho...

SPONSORED Podcast: Katey Wood from Illumio on deployment and using WIndows Filtering Platform 17.11.2020

**Apologies on the Zoom issues** This is the 2nd of 3 sponsored podcast interviews with Illumio about Their zero trust product.  Katey Wood is the Director of Product Marketing at Illumio. https://www.linkedin.com/in/kateywood/ Topic: Conversation on segmentation and ransomware Topic Background:  The attack surface and vulnerabilities are on the rise, along with cyber attacks Why? Remote everythin...

2020-042-Kim Crawley and Phillip Wylie discuss "Pentester Blueprint", moving into pentesting career 15.11.2020

Phillip Wylie @philipwylie  and kim Crawley @kim_crawley Amazon: The Pentester BluePrint: Your Guide to Being a Pentester: 9781119684305: Computer Science Books @ AmazonSmile November 24th for paper copy Steven levy: Hackers: Heroes of the Computer Revolution: Steven Levy: 9781449388393: Amazon.com: Books Why did you write the book? What is a pentester? Skills needed Education of hacker Building a...

2020-041- Conor Sherman, IR stories, cost of not prepping for an incident 10.11.2020

" Between stimulus and response there is a space. In that space is our power to choose our response. In our response lies our growth and our freedom. --Victor Frankl https://smile.amazon.com/Mans-Search-for-Meaning-audiobook/dp/B0006IU470   https://twitter.com/conordsherman   Conor Sherman - IR stories and more  Security Strategy and Incident Response, eZCater Confident Defense Podcast - https://w...

2020-040- Jeremy Mio, State of Ohio Election Security 02.11.2020

Previous Election Security podcast: https://brakeingsecurity.com/2018-042-election-security-processes-in-the-state-of-ohio     Jeremy Mio (@cyborg00101)   https://itsecurity.cuyahogacounty.us/   Ohio Counties Meet LaRose's Deadline to Strengthen Election Security - Ohio Secretary of State (ohiosos.gov)   (added cybersecurity Directives during 2018 last podcast -jmio) Directive 2018-15 (6/21/18) -...

2020-039-Philip Beyer-leadership- making an impact 28.10.2020

Phil Beyer -  Bio (CISO at Etsy) Importance on books about behavioral science. "Thinking Fast and Slow": https://smile.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555   "Predictably irrational":  https://smile.amazon.com/Predictably-Irrational-Revised-Expanded-Decisions/dp/0061353248/ http://humanhow.com/list-of-cognitive-biases-with-examples/ Influence: the Psychology of Persuasion: ...

SPONSORED PODCAST: Neil Patel, Illumio on Microsegmentation, and adopting the Zero Trust philosophy 23.10.2020

Spokesperson: Neil Patel (Sr. Technical Marketing Engineer)  Topic: Zero trust and segmentation market   http://brakeingsecurity.com/2020-023-jame-nelson-from-illumio-cyber-resilence-business-continuity   What is Zero Trust and why should companies adopt a Zero Trust philosophy?   Amanda: What are one of the more important steps someone should take when looking to implement zero trust? How does se...

2020-038-Phil_Beyer-etsy-CISO-leadership-making-an-impact 20.10.2020

Phil Beyer -  Bio (CISO at Etsy) Importance on books about behavioral science. "Thinking Fast and Slow": https://smile.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555   "Predictably irrational": https://smile.amazon.com/Predictably-Irrational-Revised-Expanded-Decisions/dp/0061353248/ http://humanhow.com/list-of-cognitive-biases-with-examples/ Influence: the Psychology of Persuasion: ht...

2020-037-Katie Moussouris, Implementing VCMM, diversity in job descriptions - Part 2 11.10.2020

Introduce Katie (bio) (@k8em0) CEO and Owner, LutaSecurity The scope of the VCMM (what is it?) VCMM - Vulnerability Coordination Maturity Model  https://www.lutasecurity.com/vcmm Just covers the internal process? To ready an org for a bug bounty program or to accept vulns from security researchers? You mentioned not playing whack-a-mole, when it comes to responding at the beginning of a vuln discl...

2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1 06.10.2020

Introduce Katie (bio) (@k8em0) CEO and Owner, LutaSecurity The scope of the VCMM (what is it?) VCMM - Vulnerability Coordination Maturity Model  https://www.lutasecurity.com/vcmm Just covers the internal process? To ready an org for a bug bounty program or to accept vulns from security researchers? You mentioned not playing whack-a-mole, when it comes to responding at the beginning of a vuln discl...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.