Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
2021-011- Dr. Catherine J Ullman, the art of communication in an Incident - Part 2 21.03.2021 45:37
In this episode: knowing your audience - discussing the IR impact how did this happen? how deep do you want to tailor your potential discussion? Every level must be asking "what, when, why, how?", not just those in the trenches does the level of incident mean that communication scales accordingly? And much more! Dr. Catherine J. Ullman (@investigatorchi) Incident Response communications Reminder...
2021-010- Dr. Catherine J Ullman, the art of communication in an Incident - Part 1 17.03.2021 34:07
Dr. Catherine J. Ullman (@investigatorchi) Incident Response communications Reminders: Patreon Jeff T. just became a $2 patron! Accepted to CircleCityCon on IR communications! Bsides Rochester Security B-Sides Rochester Spoke at SeaSec meetups: Qualys Update on Accellion FTA Security Incident | Qualys Security Blog Security Advisory | SolarWinds Family Educational Rights and Privacy Act...
2021-009-Jasmine_Jackson-TheFluffy007-analyzing_android_apps-FRida-Part2 07.03.2021 50:01
@thefluffy007 A Bay Area Native (Berkeley) I always tell people my computer journey started at 14, but it really started at 5th grade (have a good story to tell about this) Was a bad student in my ninth grade year - almost kicked out of high school due to cutting. Had a 1.7 GPA. After my summer internship turned it around to a 4.0. Once I graduated from high school, I knew I wanted to continue on...
2021-008-Jasmine jackson - TheFluffy007, Bio and background, Android App analysis - part 1 02.03.2021 52:33
@thefluffy007 A Bay Area Native (Berkeley) I always tell people my computer journey started at 14, but it really started at 5th grade (have a good story to tell about this) Was a bad student in my ninth grade year - almost kicked out of high school due to cutting. Had a 1.7 GPA. After my summer internship turned it around to a 4.0. Once I graduated from high school, I knew I wanted to continue on...
2021-007-News-Google asking for OSS to embrace standards, insider threat at Yandex, Vectr Discussion 21.02.2021 57:01
Links to discussed items: Yandex Employee Caught Selling Access to Users' Email Inboxes (thehackernews.com) Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple | Threatpost Google pitches security standards for 'critical' open-source projects | SC Media (scmagazine.com) Google's approach to secure software development and supply chain risk management | Google Cloud Blog h...
2021-006-Ronnie Watson (@secopsgeek), building a security monitoring system with ELK, and Wazuh - part2 14.02.2021 39:21
Ronnie Watson (@secopsgeek) Youtube: watson infosec - YouTube watsoninfosec (Watsoninfosec) · GitHub Feel free to add anything you like Wazuh - fork of OSSEC ( Migrating from OSSEC · Wazuh · The Open Source Security Platform ) GitHub - ossec/ossec-hids: OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit...
2021-005-Ronnie Watson (@secopsgeek), building a security monitoring system with ELK, and Wazuh 09.02.2021 35:43
Ronnie Watson (@secopsgeek) Youtube: watson infosec - YouTube watsoninfosec (Watsoninfosec) · GitHub Wazuh - fork of OSSEC ( Migrating from OSSEC · Wazuh · The Open Source Security Platform ) GitHub - ossec/ossec-hids: OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and act...
2021-004-Danny Akacki talks about Mergers and Acquisitions - Part 2 03.02.2021 47:45
Discussion on Mergers and acquisitions processes On being acquired, but also if you're acquiring a company Best Practices Best Practices of Mergers and Acquisitions (workforce.com) Best Practices In Merger Integration - Institute for Mergers, Acquisitions and Alliances (IMAA) (imaa-institute.org) The Role of Information Security in a Merger/Acquisition (bankinfosecurity.com) Security Consideration...
2021-003- Danny Akacki, open communications, mergers&acquistions 26.01.2021 46:09
Discussion on Mergers and acquisitions processes On being acquired, but also if you're acquiring a company Best Practices Best Practices of Mergers and Acquisitions (workforce.com) Best Practices In Merger Integration - Institute for Mergers, Acquisitions and Alliances (IMAA) (imaa-institute.org) The Role of Information Security in a Merger/Acquisition (bankinfosecurity.com) Security Conside...
2021-002-Elastic Search license changes, Secure RPC patching for windows, ironkey traps man's $270 million in Bitcoin 19.01.2021 46:50
Secure RPC issue - Netlogon Domain Controller Enforcement Mode is enabled by default beginning with the February 9, 2021 Security Update, related to CVE-2020-1472 – Microsoft Security Response Center How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (microsoft.com) Netlogon Domain Controller Enforcement Mode is enabled by default beginning with the F...
2021-001-news, youtuber 'dream' doxxed, solarwind passwords bruteforced, malware attacks 12.01.2021 46:57
Dream Doxxed: Minecraft YouTuber Dream Doxxed Following Speedrun Controversy (screenrant.com) Def Noodles on Twitter: "STANS TAKING IT TOO FAR: Dream doxed after posting a picture of his kitchen on his 2nd Twitter account. Dream has not published statement about situation yet in his public accounts. https://t.co/QuKpIYRODQ" / Twitter Osint issues… found him by breadcrumbs and using zillow internal...
2020-046-solarwinds-fireeye-breaches-GE-medical-device-issues-and-2021_predictions 17.12.2020 52:02
End of year podcast Blumeria sponsorship NEWS: IT company SolarWinds says it may have been hit in 'highly sophisticated' hack | Reuters FireEye hacked: US cybersecurity firm FireEye hit by 'state-sponsored' attack - BBC News https://krypt3ia.wordpress.com/ - 16 december 2020 Microsoft flexing muscle to shutdown c2: Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary...
SPONSORED- Nathanael Iversen from Illumio, future of microsegmentation, 07.12.2020 36:30
BrakeSec Sponsored Interview with Nathanael Iversen Questions, comments, and other content goes here: Illumio Nathanael Iversen BDS Podcast Messaging Topic: Overview of development and deployment of micro-segmentation Where does segmentation fit into your security strategy? Micro-segmentation is a preventive measure deployed to create and enforce access at the workload layer. It does not...
2020-045-Marco Salvati, supporting open source devs, incentivizing leeching companies who don't give back- part2 07.12.2020 44:33
https://www.hak4kidz.com/activities/cdcedu.html Online CTF training using Cisco's Workshop platform. They did something similar in Spring of 2020. There will be an online panel where kids can ask questions about information security. Occurs on December 12th. Check out the link for more info. Robert M. for upping his patreon to $5 Top 25 Data Security Podcasts You Must Follow in 2020 (feedspot.com)...
2020-044-Marcello Salvati (@byt3bl33d3r), porchetta industries, supporting opensource tool creators, sponsorship model 02.12.2020 29:18
https://www.hak4kidz.com/activities/cdcedu.html Online CTF training using Cisco's Workshop platform. They did something similar in Spring of 2020. There will be an online panel where kids can ask questions about information security. Occurs on December 12th. Check out the link for more info. Robert M. for upping his patreon to $5 Top 25 Data Security Podcasts You Must Follow in 2020 (feedspot.com)...
2020-043-Software_Defined_Radio-Sebastien_dudek-RF-attacks- IoT and car RF attacks 24.11.2020 31:42
Sébastien Dudek - @FlUxIuS @penthertz Why we are here today? Software Defined Radio (sdr-radio.com) What kind of hardware or software do you need? Why would a security professional want to know how to use SDR tools and attacks? What other kinds of attacks can be launched? (I mean, other than replay type attacks) Door systems (badge systems) NFC? Contactless credit card attacks Smart building/ho...
SPONSORED Podcast: Katey Wood from Illumio on deployment and using WIndows Filtering Platform 17.11.2020 42:53
**Apologies on the Zoom issues** This is the 2nd of 3 sponsored podcast interviews with Illumio about Their zero trust product. Katey Wood is the Director of Product Marketing at Illumio. https://www.linkedin.com/in/kateywood/ Topic: Conversation on segmentation and ransomware Topic Background: The attack surface and vulnerabilities are on the rise, along with cyber attacks Why? Remote everythin...
2020-042-Kim Crawley and Phillip Wylie discuss "Pentester Blueprint", moving into pentesting career 15.11.2020 1:10:39
Phillip Wylie @philipwylie and kim Crawley @kim_crawley Amazon: The Pentester BluePrint: Your Guide to Being a Pentester: 9781119684305: Computer Science Books @ AmazonSmile November 24th for paper copy Steven levy: Hackers: Heroes of the Computer Revolution: Steven Levy: 9781449388393: Amazon.com: Books Why did you write the book? What is a pentester? Skills needed Education of hacker Building a...
2020-041- Conor Sherman, IR stories, cost of not prepping for an incident 10.11.2020 1:17:47
" Between stimulus and response there is a space. In that space is our power to choose our response. In our response lies our growth and our freedom. --Victor Frankl https://smile.amazon.com/Mans-Search-for-Meaning-audiobook/dp/B0006IU470 https://twitter.com/conordsherman Conor Sherman - IR stories and more Security Strategy and Incident Response, eZCater Confident Defense Podcast - https://w...
2020-040- Jeremy Mio, State of Ohio Election Security 02.11.2020 1:03:35
Previous Election Security podcast: https://brakeingsecurity.com/2018-042-election-security-processes-in-the-state-of-ohio Jeremy Mio (@cyborg00101) https://itsecurity.cuyahogacounty.us/ Ohio Counties Meet LaRose's Deadline to Strengthen Election Security - Ohio Secretary of State (ohiosos.gov) (added cybersecurity Directives during 2018 last podcast -jmio) Directive 2018-15 (6/21/18) -...
2020-039-Philip Beyer-leadership- making an impact 28.10.2020 56:39
Phil Beyer - Bio (CISO at Etsy) Importance on books about behavioral science. "Thinking Fast and Slow": https://smile.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555 "Predictably irrational": https://smile.amazon.com/Predictably-Irrational-Revised-Expanded-Decisions/dp/0061353248/ http://humanhow.com/list-of-cognitive-biases-with-examples/ Influence: the Psychology of Persuasion: ...
SPONSORED PODCAST: Neil Patel, Illumio on Microsegmentation, and adopting the Zero Trust philosophy 23.10.2020 33:18
Spokesperson: Neil Patel (Sr. Technical Marketing Engineer) Topic: Zero trust and segmentation market http://brakeingsecurity.com/2020-023-jame-nelson-from-illumio-cyber-resilence-business-continuity What is Zero Trust and why should companies adopt a Zero Trust philosophy? Amanda: What are one of the more important steps someone should take when looking to implement zero trust? How does se...
2020-038-Phil_Beyer-etsy-CISO-leadership-making-an-impact 20.10.2020 41:45
Phil Beyer - Bio (CISO at Etsy) Importance on books about behavioral science. "Thinking Fast and Slow": https://smile.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555 "Predictably irrational": https://smile.amazon.com/Predictably-Irrational-Revised-Expanded-Decisions/dp/0061353248/ http://humanhow.com/list-of-cognitive-biases-with-examples/ Influence: the Psychology of Persuasion: ht...
2020-037-Katie Moussouris, Implementing VCMM, diversity in job descriptions - Part 2 11.10.2020 39:18
Introduce Katie (bio) (@k8em0) CEO and Owner, LutaSecurity The scope of the VCMM (what is it?) VCMM - Vulnerability Coordination Maturity Model https://www.lutasecurity.com/vcmm Just covers the internal process? To ready an org for a bug bounty program or to accept vulns from security researchers? You mentioned not playing whack-a-mole, when it comes to responding at the beginning of a vuln discl...
2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1 06.10.2020 37:08
Introduce Katie (bio) (@k8em0) CEO and Owner, LutaSecurity The scope of the VCMM (what is it?) VCMM - Vulnerability Coordination Maturity Model https://www.lutasecurity.com/vcmm Just covers the internal process? To ready an org for a bug bounty program or to accept vulns from security researchers? You mentioned not playing whack-a-mole, when it comes to responding at the beginning of a vuln discl...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.