Rafal (Wh1t3Rabbit) Los
Down the Security Rabbithole Podcast (DtSR)
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...
Author
Rafal (Wh1t3Rabbit) Los
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DtSR Episode 565 - All Tiller, No Filler 22.08.2023 54:40
TL;DR: This week's episode is packed with content, as the one and only Jim Tiller joins James and me for a podcast that ...well ...does a fair bit of analysis of Black Hat, the industry, and several other things that are probably top of mind for you as well. Let's not spoil it for you - give it a listen (and watch the video, it's good) YouTube Video: https://youtube.com/live/se5M5vq...
DtSR Episode 564 - What Happens at Black Hat 23 15.08.2023 41:26
TL;DR: On this episode of post-Black Hat 2023, my buddy Will Gragido joins me to talk about what we saw, what we learned, and what shenanigans transpired. We're focused on marketing and booths - how do vendors differentiate, what do conferencegoers take away, and what makes your booth or offering unique? What about AI? Yeah, we talk about all of that. YouTube Video: https://youtube.com/live/c...
DtSR Episode 563 - AI Washing Black Hat 2023 Pre-Gaming 08.08.2023 40:47
TL;DR This week is Black Hat 2023, or "Hacker Summer Camp" if you prefer. That means that the hype machine will be working overtime, times 10, so here's an episode made to throw some cold water on the madness, and poke a little fun before things go entirely sideways. I hope you enjoy this show, and as always, I welcome your comments on LinkedIn! Guest Karim Hijazi LinkedIn: https://...
DtSR Episode 562 - Is There Even a BYOD Debate Anymore? 01.08.2023 1:00:02
TL;DR: I crashed a party on Security Uncorked and the crew that was having the discussion was kind enough to indulge me and my "bombs" (questions, really) - so I decided to have JJ and Josh on DtSR, and James and I continued the debate and conversation. This was so much more fun than it should have been, but the result is something I think we can be happy with - a healthy debate, some co...
DtSR Episode 561 - Telling Generative AI Your Corporate Secrets 25.07.2023 38:47
TL;DR: This week my old buddies Jason Clark and James Robinson join James and me to talk about "AI" and the realm of possibilities (and risks) that it is. We discuss Artificial Intelligence (AI) as a generational leap in technology - but also the risks it poses for corporations (and real-life, real people too). Listen to the pod in your ears, and watch the video - trust me, you'll l...
DtSR Episode 560 - AppSec Philosophers 18.07.2023 43:38
TL;DR: This week's episode is a come-back episode from the appearance I did on Dan Kuykendall's "Dan on Dev" podcast a couple of days ago. We started such a fun conversation, we just couldn't let it end there. We go through some interesting (in my opinion) history of the AppSec space, Dan does a little "back in my day" stuff, and I get all "Get off my lawn&q...
DtSR Episode 559 - The Law of Diminishing Returns Ride Again 11.07.2023 38:33
TL;DR You've got a slightly different episode this week - it's just James and I on the mic to talk through one of my favorite topics. But first! ... we have to talk about "Threads" and the social media "too much" that's happening. Then we talk about the Law of Diminishing Returns in cyber security -from budget to effort - "How much is good enough?" YouT...
DtSR Episode 558 - The Problems Of Massive Scale 04.07.2023 52:19
Tl;DR: ** Happy Birthday America! ** This week the podcast is celebrating America's birthday by releasing an episode that is a conversation with one of my favorite Canadians. Mark Nunnikhoven is one of the foremost cloud and large scale security professionals, and if anyone in security understands how to explain some of the stresses and strains of security at massive scale it's Mark...
DtSR Episode 557 - Changing Culture and Not Getting Fired 26.06.2023 35:58
TL;DR: On this week's episode we have an expert in leadership with experience in the Federal/Military sector as well as the civilian side. Bo talks about how culture can be changed, ways to approach your constituents, and which styles of information dissemination work best in organizations both large and small. If you're thinking about how to get your team more "security aware"...
DtSR Episode 556 - Will Regulation Price Out the Competition 20.06.2023 47:43
TL;DR: On this software security and regulation-focused episode of the podcast, the OG of AppSec (Jeff Williams) joins James & I to talk about the latest spate of regulations that require self-attested transparency about what companies are doing with respect to securing their software via supply chain and direct action. Jeff contends this is a good thing and it's hard to argue that transp...
DtSR Episode 555 - Why Can't We Figure Out the Developer Security Relationship 13.06.2023 1:03:18
TL;DR: On this 555th episode, James Wickett joins James and me on an interesting discussion on AppSec, developer relationships, and why we just can't seem to make it work. Or maybe we're making it work but not giving ourselves credit? Listen in to this conversation and find out. This one will hook you in, as James, James, and I have a slightly depressing conversation that I think ends i...
DtSR Episode 554 - This is Why AppSec Can't Have Nice Things 06.06.2023 46:44
TL;DR This week's episode goes down the AppSec rabbit hole with Francesco Cipollone (call him "Frank") as we discuss some of the ins and outs of the modern software security challenge. We're all over the place on topics, but the message, in the end, is sane. YouTube video replay: https://youtube.com/live/tJ6pvV3f0uA Guest: Francesco Cipollone LinkedIn: https://www.linkedin.c...
DtSR Episode 553 - Leadership Series - Selling Cyber Security 31.05.2023 58:22
TL;DR: In case you missed the epic LinkedIn Live livestream, here's the podcast version of the conversation with Chris Scanlan (President and Chief Commercial Officer at ExtraHop). James and I talk to Chris about his career, how he picks his next job, his team, and his thoughts on high-performance organizations. Sales is a topic many of our competitive podcasts in this space don't cover...
DtSR Episode 552 - VPN And Other Dinosaur Tales 23.05.2023 43:28
TL;DR: On this week's episode of Down the Security Rabbithole Podcast - Steve Riley visits to talk tall tales of VPN and other connectivity of yore, what it's evolving to, and why it's a generational leap. The conversation with Steve is always a good one, and catch Steve here before you catch him on the Cloud Security Podcast (beat you to it guys!) Guest Steve Riley LinkedIn: https:...
DtSR Episode 551 - Patching Prioritizing and Punting 16.05.2023 48:57
TL;DR: On this week's show, Grant joins us to discuss an episode that draws inspiration from a LinkedIn discussion with Patrick Garrity [ original post ] ( whom could not make our recording, sorry Patrick ). The gist of it is this - patching is hard, there are now 925 KEVs (known exploited vulnerabilities) on CISAs list, and that's a truck-ton. The discussion threads the needle between w...
DtSR Episode 550 - Lift Shift and Fail to the Cloud 09.05.2023 53:14
TL;DR: On this week's episode, the one and only Jeff Collins joins Rafal & James to talk about the shift to the cloud and what's gone wrong in the years since the collective "we" announced that the cloud was the answer. Feels like a decade has passed, and I think it has, since the start and we're observing increased complexity and varying degrees of security increase/d...
DtSR Episode 549 - Wheres The Beef From RSAC 2023 02.05.2023 39:35
TL;DR: This episode is a bit of a rant, a bit of an analysis, and an interview with returning podcast guest Ray Canzanese, Jr. from RSA Conference 2023. Yep, I went so you didn't have to... so in this show you'll get a few impressions, and maybe you'll agree or disagree on the themes and things we're seeing. Maybe you'll even be compelled to write something up or leave a c...
DtSR Episode 548 - What's HR Got to Do With It 25.04.2023 39:03
TL;DR: Cyber Security seems to always be a technical topic. This week, we're taking it down a different lane as we discuss HR (right, Human Resources, remember those folks?) with Tom Venables. Tom's got seat time in the space, consulting with HR partners for various clients so he knows a thing or two about the processes and where they break down. Listen in, and then go take a look at you...
DtSR Episode 547 - Don't Believe All the Cyber Hype 18.04.2023 48:25
TL;DR: This week on the podcast we have Nathan Hamiel, Senior Director of Research at Kudelski Security on the podcast to talk about HYPE . It's a conversation rooted in skepticism, but also optimism in a strange mix that only Nathan can bring from his extensive experience and well-thought-out talking points. YouTube Recorded LiveStream: https://youtube.com/live/ayPrWr-VWv0 Guest Nathan Hamie...
DtSR Episode 546 - Rethinking SecOps Tooling Strategy 11.04.2023 48:17
TL;DR: Mark Simos of Microsoft joins Rafal & James this week to talk about why the 'tools-centric' security operations (SecOps) approach is failing us, and what an 'outcome centric' approach means and more importantly, how we get there. We discuss "vision versus execution", the history of "how we got here" and answer some questions we didn't know we...
DtSR Episode 545 - Security Products Are Too Complex 04.04.2023 47:30
TL;DR: This week's guest is Will Gragido, who has some significant experience developing security products. Will and I (Rafal) have a sit-down for a conversation about security products, their complexity then, now, and in the future. Point solutions, platforms, and portfolios - we discuss all the options you're faced with as a buyer - and attempt to suggest some solutions to the madness....
DtSR Episode 544 - CrowdStrike Global Threat Report March 2023 28.03.2023 39:43
TL;DR: This week on the podcast, my buddy Adam Meyers graciously joins the show from his "undisclosed location" deep under the Meyers compound to break apart the latest threat report. I'm sure you've read it, but if you haven't you can get it at the link below. On this show, Adam and Rafal talk about what's in the report, what's not in the report, and the delta w...
DtSR Episode 543 - National Cyber Security Policy Daydreams (2023) 21.03.2023 1:02:56
TL;DR This week, on the podcast, Rafal and James host Brian Chidester and Jordan Burris to talk about the latest National Cyber Security Strategy from the Biden White House. It's an interesting piece of national policy that outlines our cyber security priorities as a nation - and you'll have to forgive me for calling it "aspirational". The four of us discuss the likelyhood of t...
DtSR Episode 542 - Distilling 20 Years of CISO Wisdom 14.03.2023 37:06
TL;DR: On this week's episode of the podcast, James joins me to co-host a great episode with an old friend - Ray Emerly. Ray is a long-time veteran of the CISO chair, and no stranger to working at all aspects of the security leadership role. We talk through a number of important topics, ask him what's changed (and what hasn't) and of course we have a stumper at the end. Listen to th...
DtSR Episode 541 - The Calculus of Cyber Insurance 14.03.2023 46:23
** This episode is being re-published due to an issue with the RSS feed/provider ** TL;DR: We've talked about cyber insurance a lot here on this podcast, and this episode is yet another angle on the topic. Nate Smolenski joins us to discuss his view, from the perspective of a CISO. This is a great conversation for those who are still investigating Cyber Insurance, or realizing that their poli...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.