Rafal (Wh1t3Rabbit) Los
Down the Security Rabbithole Podcast (DtSR)
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...
Author
Rafal (Wh1t3Rabbit) Los
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DtSR Episode 587 - A Framework for Defensible Security Programs w Bo Birdwell 3-3 08.02.2024 33:24
Tl;DR: Part 3 of 3 : This episode is the big reveal with details and a how-to, in a 3-part series presented by Bo Birdwell , on how to build a defensible security program using compliance to drive greater security improvement. The accompanying video is a must-watch because it has the slides Bo is talking through, and you're not going to want to miss that. YouTube Video: https://youtube.com/li...
DtSR Episode 587 - A Framework for Defensible Security Programs w Bo Birdwell 2-3 07.02.2024 43:43
Tl;DR: Part 2 of 3 : This episode is the set-up, the problem statement, and overview of Bo's approach, in a 3-part series presented by Bo Birdwell , on how to build a defensible security program using compliance to drive greater security improvement. The accompanying video is a must-watch because it has the slides Bo is talking through, and you're not going to want to miss that. YouTube...
DtSR Episode 587 - A Framework for Defensible Security Programs w Bo Birdwell 1-3 06.02.2024 31:47
Tl;DR: Part 1 of 3 : This episode is the introduction of a 3-part series presented by Bo Birdwell , on how to build a defensible security program using compliance to drive greater security improvement. The accompanying video is a must-watch because it has the slides Bo is talking through, and you're not going to want to miss that. YouTube Video: https://youtu.be/MJNwn6sbxcM Have something to...
DtSR Episode 586 - Trending Security Services w Joel Scambray 30.01.2024 40:20
TL;DR: This week Joel Scambray joins James and I to talk about the trends and observations from the world of professional services. Joel is a long-time leader in the professional services delivery space in cybersecurity, and he has some interesting insights to share about where we are and where we could potentially be going. YouTube Video: https://youtube.com/live/LtDgSlnJyik Have something to say...
DtSR Episode 585 - James Beeson: A CISO Life 23.01.2024 48:39
TL;DR: This episode is part of the Leadership series of episodes, with the one and only James Beeson . James is one of the quintessential CISOs who is successful in both his craft and business world. I had the pleasure to work with James and his team many years ago and I can't wait for you to hear his insights and lessons learned. If you can get either some coaching or insights from James -...
DtSR Episode 584 - Explaining the Tech w Chris Davis 16.01.2024 46:31
TL;DR: This week, I virtually sat down 1 on 1 with my long-time friend, cyber security veteran, and fellow smartass Christopher Davis to talk about the state of pre-sales (sales engineering) in our industry. We've both done it, being both seller and buyer of security products and services -- and we can complain about the state of things. Chris offers some solid advice, so take notes! Have s...
DtSR Episode 583 - 2024 Is Going To Be a Doozy 09.01.2024 42:51
TL;DR: As we talked about last year, Jim Tiller is joining us as a regular guest on an episode that looks forward (uncomfortably) to 2024 with all the mayhem and disappointment it will no doubt bring to the cybersecurity industry. What's coming? Let's talk about it... and we're not holding back. YouTube video: https://youtube.com/live/B5K4WQg0S7A Link James referenced: https://www...
DtSR Episode 582 - RTO or GTFO with Bill Pelletier 02.01.2024 43:38
TL;DR: On this first episode of 2024, what better way to ring in the new year than to discuss the evolution of (knowledge) work? For this show, my friend Bill Pelletier joins as the Statler to my Waldorf as we discuss where knowledge work was a decade ago, where it is today (post-Covid), and what it could be if we thread the needle just right. In the end, one thing is for certain - the "futur...
DtSR Episode 581 - Everything On The Internet All At Once 26.12.2023 53:07
TL;DR: This week, our good friend Jeff Collins joins Rafal & James to talk about the "everything" being on the Internet now. Whether it's presents for the kids, connected devices in the kitchen, or stuff at the office - everything seems to be on the Internet and could be a potential exposure for you, your family, or your company. How do we deal with all of this? YouTube video...
DtSR Episode 580 - Of Cyber and Snowflakes 19.12.2023 53:57
TL;DR: Your favorite podcast is back, after a short break, and bringing you another packed episode with Brandon Dunlap & Jim "All Tiller, no filler" Tiller where we discuss Kelly Shortridge's column " Security Isn't Special ". Some things we agree with, some things we don't, but we talk through it thoroughly. That's part of the fun! Join the pod, and see...
DtSR Episode 579 - Mike Towers on Trust in the Digital Age 28.11.2023 38:00
TL;DR: This week I'm joined by Mike Towers - a gentleman who has "digital trust" literally in his job title. This is an episode where we attempt to start the conversation of trust in an age of digital everything. Of course, the backdrop for today's discussion is the mayhem over at OpenAI - and if that's not a great place to start, I don't know what is. Is anyone else...
DtSR Episode 578 - Maybe A Modern Day SOC Discussion 21.11.2023 1:01:48
TL;DR: I finally decided that Erik Bloch' s LinkedIn posts have provoked a certain interest in a conversation about what a "modern-day" SOC should look and behave like. I then invited Jim Tiller and Anton Chuvakin (because they have some opinions), on the show to join James and me to discuss this. It didn't quite go to plan. YouTube Video: https://youtube.com/live/cgKpTTmCUrs...
DtSR Episode 577 - CISOs Turn at the Big Kids Table 14.11.2023 42:46
TL;DR: On this episode of the pod, Jim Tiller and I talk through the hot takes published about the SEC vs SolarWinds and Brown, and why so many people are getting it all wrong. I highly encourage you to go read the actual indictment before giving your opinion. Link to the SEC page: https://www.sec.gov/news/press-release/2023-227 YouTube video: https://youtube.com/live/9z4g9p3BW-Y My YouTube "...
DtSR Episode 576 - Fixing Executive Security Events 07.11.2023 45:58
TL;DR: Executive Conference organizers - this episode is for YOU. On today's episode of the podcast, it's just James and I on the microphone discussing all of these executive security events you may be getting invited to. They're just generally bad - people with big titles rattling off corporate marketing speak, with low attendance and low value. Or ...is there a better way? We disc...
DtSR Episode 575 - Crushed Under a Mountain of Security Tools 31.10.2023 43:03
TL;DR: This week on the pod, Andrew Morris & Tom Venables from Turnkey Consulting join me for a semi-regular check-in from the consultancy world as we discuss the overwhelming problem with technology. Specifically, we talk about tools strategies for budget squeezes, filling niche use cases, and how to rationalize what you've got if you want more. Come check out the video - Tom's back...
DtSR Episode 574 - HealthCare CyberSecurity is Sick 24.10.2023 39:14
TL;DR: This week on an interesting show that dives into the world of healthcare cybersecurity, Dan Dodson joins James and I to discuss the state of things, the reason for some of the chaos, and what the future outlook could be. The challenges are many, the outlook can be bleak, and while we have challenges both in business and technology (a la technical debt) - there is hope for a bright, secure,...
DtSR Episode 573 - The Urge to Converge 17.10.2023 45:02
TL;DR This week on the podcast Jerry Plaza from Netskope joins us to talk about the (re?)convergence between the network and security functions as policy, enforcement, and connectivity necessarily once again converge. It's been a long journey - but this time we think it's going to stick - hear why. Youtube video: https://youtube.com/live/RbobEfNMk2M Guest Gerry Plaza LinkedIn: https://ww...
DtSR Episode 572 - Managing Vendors Sucks 10.10.2023 43:27
TL;DR Working with security vendors is tough - and it's not getting better. Market consolidation, product maturity, innovation - all of that has to be factored in to develop a strategy and deal with the constant change. Whatever your current strategy - Brent, Rafal, and James discuss some options and how it could be. YouTube Video: https://youtube.com/live/R2-CKVBsexI Guest Brent Deterding Li...
DtSR Episode 571 - Can We Talk About the vCISO 03.10.2023 45:53
TL;DR: On this episode of the podcast - Rafal is joined by long-time friends and colleagues, Jim Tiller, Matt Shufeldt, and reformed analyst Anton Chuvakin to discuss the role and value of the virtual CISO. Or maybe it's the "fractional CISO". Or maybe it's something else? We work through value prop, how to pick a worthwhile partner in a fractional CISO, and advice for avoiding...
DtSR Episode 570 - Starting a Conversation About Securing the Food Supply_Part 2 28.09.2023 35:07
TL;DR; This is part 2 of 2 - for this amazing topic! Please join us for both parts, and check out the full-length video online and available RIGHT NOW. On this episode of the DtSR Podcast, I welcome Kristin Demoranville and Nelson Estrada Hernandez to talk about the food industry and how cyber security can and should be a vital part in this absolutely critical topic. YouTube Video (full 62 minutes...
DtSR Episode 570 - Starting a Conversation About Securing the Food Supply_Part 1 26.09.2023 30:55
TL;DR; This is part 1 of 2 - for this amazing topic! Please join us for both parts, and check out the full-length video online and available RIGHT NOW. On this episode of the DtSR Podcast, I welcome Kristin Demoranville and Nelson Estrada Hernandez to talk about the food industry and how cyber security can and should be a vital part in this absolutely critical topic. YouTube Video (full 62 minutes...
DtSR Episode 569 - Keeping Secrets a Secret 19.09.2023 39:07
TL;DR: This week's show features Oded Hareven, Co-Founder & CEO at Akeyless, and we cover some topics that are important, but brand new to us. Oded started a secrets management company and addressed some of the challenges and new technology with us. First, we discuss the "secret zero" problem (the one I worry about quite often), then zero-knowledge secrets management, and finall...
DtSR Episode 568 - Breaches Cyber Insurance White Castle and the SEC 12.09.2023 50:37
TL;DR: This week we are starting a quarterly segment with Sean Scranton and Shawn Tuma - that's right folks, you'll get our favorite breach coach aka "The oh-shit moment guy" and one of the most knowledgeable cyber insurance people together on the podcast four times a year (at least). So what did we cover on this show? Oye - looks like White Castle (yeah, my favorite of all tim...
DtSR Episode 567 - SMBs The Forgotten CyberSecurity Voices 05.09.2023 38:47
TL;DR: I'm so excited to announce this podcast. This week the one and only Dominic Vogel joins me on the show to talk about SMBs - you know, those building blocks of the economy that most vendors pretend don't exist because it doesn't make them big $$$. And it's a whopper of a conversation with insights, ideas, and conversation that is looking to change things for the better. H...
DtSR Episode 566 - Kellman's Irreverent Cloud Security Take 29.08.2023 42:18
TL;DR: Kellman's been one of the guests I've been chasing for years but he's always been too busy or too tied up in corporate requirements to be on the podcast - but now he's available and here we are. Kellman's got a lot of years behind him slinging network security gear, so it's a bit of a surprise to some that he has pivoted hard into cloud concepts and has some ha...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.