LBMC

Cybersecurity Sense

Welcome to Cybersecurity Sense, the podcast where real-world security meets practical insights. Hosted by LBMC's Mark Burnette, this show goes beyond compliance checklists to explore the fast-moving world of cybersecurity.

Author

LBMC

Category

Technology

Latest episode

Dec 2, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ransomware Awareness 28.04.2022

In this episode, Host William Parks shares ransomware awareness tips and cybersecurity best practices to keep your company safe from attacks.

Women in Cybersecurity 24.03.2022

To celebrate Women's History Month, LBMC interviews a panel of our women cybersecurity experts on their unique career journeys, what advice they would give to women looking to work in the field, and goals for the future. 

Hiring Perspectives 08.12.2020

In this episode, the LBMC team gives listeners insight into what to expect when interviewing for a role in information security. Learn what qualities hiring managers are looking for as you prepare for your job interview.

Information Security Careers (Part 2) 10.11.2020

Part two of our Information Security Careers podcast series. Our panel of experts share their paths to their first infosec jobs and provide advice for pursuing a career in the field.

Information Security Careers 21.10.2020

Learn how a few members of the LBMC Information Security team got started in their careers, and what you should consider when going into the field. 

What is the Cybersecurity Maturity Model Certification (CMMC)? 21.10.2020

In this episode, Caryn Wooley joins us to discuss the Cybersecurity Maturity Model Certification (CMMC). Learn why the Department of Defense created the model to improve security for government contractors and subcontractors. Hear what you can do to start preparing for CMMC today.

HITRUST Guide 18.09.2020

Nancy Spizzo, Senior Manager at LBMC Information Security, joins Bill Dean to talk about HITRUST and the new LBMC Information Security HITRUST Guide being released later this fall. 

PCI Pen Testing 10.07.2020

In this episode Bill Dean and Stewart Fey discuss penetration testing for PCI compliance. Learn about the differences between penetration testing and vulnerability assessments, and what is needed to meet requirements for PCI compliance.

The Return to a "New Normal" 20.05.2020

In this episode Nancy Spizzo joins Bill Dean to discuss re-entry to the workplace. They'll discuss what items you should consider from a security and technology perspective as organizations plan to reopen their facilities. 

The Impact of Remote Work on IT Audits 06.05.2020

In this episode, Chelsea Smith talks with Bill Dean about the impact of remote work on IT audits during the COVID-19 pandemic. 

Using Zoom Securely 22.04.2020

Zoom is soaring in popularity as a large population of remote workers are using it for video conferencing. With it's surging popularity, the platform's loose security protocols made it an easy target for hackers to take advantage and disrupt calls. "Zoombombing" allowed anyone to login to unprotected links to intrude on the calls often sharing lewd photos and videos. Listen to our most recent podc...

Not All Phishing Assessments Are Equal 09.04.2020

In this episode, LBMC's cybersecurity experts discuss the topic of social engineering via phishing. Learn the difference in using phishing software solutions versus penetration testing services for your cybersecurity program.

MFA is NOT a Silver Bullet 09.04.2020

LBMC Cybersecurity expert, Derek Rush, joins Bill Dean as they discuss the benefits and limitations of multi-factor authentication. 

HITRUST Conference Overview 16.08.2019

The LBMC Information Security team recaps the 2019 HITRUST conference that was held in Texas in May. The team talks about the latest news on third-party assurance, HITRUST CSF adoption and controls implementation, SOC 2 + HITRUST, and the latest initiatives in the quality sub committee.

Key Insights on PCI DSS Version 4.0 29.05.2019

In this podcast, LBMC Information Security's Mark Burnette offers a summary and perspective on the council's insights—specifically addressing the three likely changes for the next version of the PCI DSS.

New Tools for PCI Compliance 15.05.2019

In this podcast, LBMC Information Security's Bill Dean and John Dorling discuss some of the new tools available to help merchants who are trying to achieve PCI compliance.

2018 Was Second-Most Active Year for Data Breaches 20.03.2019

2018 was one of the biggest years for data breaches to date, with more than 6,500 data breaches reported throughout the year. In this podcast, LBMC Information Security's Bill Dean dives deeper into these recent data breach statistics and why it's important to keep investing in the hard work involved with combating cyber-attacks to prevent data breaches in the days to come.

Targeted Attacks Compared to Opportunistic Attacks 03.10.2018

All companies are subject to opportunistic attacks, but do you know if you are subject to a targeted attack based on the data you generate or maintain? In this podcast, LBMC Information Security's Bill Dean addresses this question while diving deeper into the key differences between targeted attacks and opportunistic attacks.

Incident Response Should Be Common Sense 16.08.2018

Since incident response issues are no longer just an IT issue and can often involve legal issues, it is important for organizations to develop an incident response team, seek outside expertise, and have an overall action plan in the event of an incident. In this podcast, LBMC Information Security's Bill Dean discusses how a complex situation like incident response can be purely based on common sen...

Attack Simulation 18.07.2018

In a previous podcast, we discussed purple-teaming as it compares to a conventional penetration test. Let's now build on that approach, starting with the differences between attack simulation and conventional penetration tests. The methodology of attack simulation is the assumption that the network or a system will become compromised and the current controls will not prevent the infection. So, how...

Purple-Teaming 10.07.2018

Most penetration testers are considered "red team," while most defenders are considered "blue team." Thus, the irony of a conventional penetration test is that these two groups are typically pitted against each other. When the red teams and blue teams are working together, you have what's called a "purple team." While purple-teaming has not always been a thing, it can be a win for both groups. Pur...

GDPR and Preparing for DSARs 08.05.2018

The EU's  General Data Protection Regulation (GDPR)  permits users certain rights (referred to as "data subject access rights" or "DSARs" in the documentation) that organizations will need to be prepared to accommodate  if they must comply with GDPR . For organizations to be prepared to respond, it's important to have a clear understanding of DSARs  before you risk consuming too much time, money,...

GDPR—How to Prepare 08.05.2018

As organizations determine whether the E.U.'s General Data Protection Regulation (GDPR) is applicable to them, there are several important things to consider when it comes to compliance. Among those things involves preparing for and responding to personal data breaches  which is not just a requirement of the GDPR; it's a good business practice in general), data consent , and how you are protecting...

Does GDPR Apply to Me? 08.05.2018

As the May 25, 2018 GDPR enforcement date fast approaches, many organizations are asking, "How does the GDPR will apply to my organization?" As the GDPR extends to U.S. organizations  that offer services to or monitor behaviors of E.U. citizens, it's important to understand how to classify your organization's data to determine GDPR applicability . While the GDPR presents new challenges for organiz...

Why Employees Are Your Number One Risk 19.04.2018

The question is not, "Will your employees will get your company hacked?" but rather "When will your employees get your company hacked?" A recent article  from HITECH Answers highlights this sad reality of human-error being the most common reason for a cyber intrusion and data compromise. So, while employee actions can circumvent most every security control you have invested in, security awareness...

Listen to the Cybersecurity Sense podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.