RunSafe Security

Exploited: The Cyber Truth

Education EN ↓ 50 episodes

Exploited: The Cyber Truth is a hard-hitting, no-fluff podcast exposing the realities of today’s cyber threat landscape and risks to critical infrastructure. Through candid conversations with top cybersecurity experts, industry leaders, and frontline defenders, the show breaks down recent high-profile vulnerabilities and exploits and covers innovative strategies used to stop them. To keep critical infrastructure safe, defenders need the upper hand. Tune in and get the cyber truth.

Author

RunSafe Security

Category

Education

Podcast website

runsafesecurity.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

When the Grid Gets Hit: Inside OT Incident Response in Energy & Renewables 10.07.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and special guest Derrick Bethea, NERC Compliance Manager and OT Cybersecurity Leader at Cypress Creek Energy, for an inside look at how utilities and renewable energy operators prepare for, respond to, and recover from cyber incidents. Drawing on years of experience securing operationa...

From Compliance to Resilience: Securing Digital Mission Systems at Military Scale 25.06.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Lt. Gen. (Ret.) Bill Bender, former Chief Information Officer of the U.S. Air Force, to discuss what it takes to build true cyber resilience across some of the world's most complex digital environments. Drawing on his experience overseeing a $17 billion IT portfolio and helping esta...

Seeing the Invisible: Asset Discovery, Segmentation, and the Reality of OT Security 11.06.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by Shane Fry, CTO of RunSafe Security, and Andrew McPhee, Solutions Manager for Industrial Security at Cisco, to examine why visibility is one of the biggest challenges in OT cybersecurity. As industrial environments become more connected, organizations are struggling to identify unknown assets, understand hidden dependenc...

The Cyber-Physical Truth: What We Get Wrong About Attacks on Critical Infrastructure 28.05.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joseph M. Saunders and Danielle “DJ” Jablanski, Cybersecurity Consulting Program Lead for Operational Technology at STV and former OT Cybersecurity Strategist at CISA, to examine what defenders often get wrong about attacks on critical infrastructure. With experience across government, threat intell...

You Can’t Patch Your Way Out of This: What Mythos Means for the Future of Cybersecurity 21.05.2026

In this episode of Exploited: The Cyber Truth , RunSafe Security Founder and CEO Joe Saunders and EVP and CSO Doug Britton join us for a strategic discussion on what Anthropic’s “Mythos moment” means for the future of cyber defense. Joe and Doug explore why AI-driven vulnerability discovery marks a fundamental turning point for enterprises, critical infrastructure, and national security. As AI acc...

The Next Cyber Crisis Won’t Be One Hospital—It Could Be the Entire Health System 14.05.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Greg Garcia, Executive Director for Cybersecurity of the Health Sector Coordinating Council (HSCC) Cybersecurity Working Group, to examine how ransomware, third-party dependencies, and interconnected healthcare infrastructure are shaping cyber risk across the healthcare sector. Draw...

Trust at Machine Speed: AI, DevSecOps, and Zero Trust in National Security Software 30.04.2026

Artificial intelligence is moving faster than the policies, security controls, and acquisition processes designed to govern it—especially in national security environments where preventing failure is mission-critical. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by Nicolas Chaillan, the host of In the Nic of Time and Former DAF CSO, to examine a central question: how...

The Invisible Attack Surface: Cybersecurity for Embedded Systems 16.04.2026

Embedded systems power everything from critical infrastructure to defense systems, yet vulnerabilities in those systems often go unseen and unaddressed. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and special guests Mario Zuniga and Matt Janson of MITRE to discuss the “invisible attack surface” lurking within embedded and cyber-p...

AI vs. Vulnerabilities: Who Really Wins? 26.03.2026

Artificial intelligence is transforming cybersecurity but not in the way many expect. While defenders are using AI to accelerate detection, triage, and threat hunting, adversaries are leveraging the same tools to scale reconnaissance, automate exploit development, and dramatically increase the speed of attack. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe S...

AI Wrote the Code—Who Owns the Risk? 12.03.2026

In this episode of Exploited: The Cyber Truth, host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and embedded systems expert Jacob Beningo to explore how AI is changing the software development lifecycle for embedded and firmware teams. Together, they unpack the risks and responsibilities that come with AI-generated code. While AI can accelerate development and aut...

From NIST to Nation-State: Securing Embedded Systems through Compliance and Trust 26.02.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Cordell Robinson, CEO of Brownstone Consulting, to explore how security frameworks like NIST 800-53 are evolving from paperwork exercises into real drivers of security maturity. From continuous monitoring and secure-by-design development to Software Bills of Materials (SBOMs) and vu...

The OT Mistakes Attackers Count On—And How to Fix Them Before They Do 12.02.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joseph M. Saunders and OT/ICS security expert Mike Holcomb, founder of UTILSEC, for a candid discussion about the weaknesses attackers exploit inside industrial environments. Mike shares what he repeatedly finds during assessments of large OT and ICS networks: no effective firewall between IT and OT...

Balancing Speed and Security: The Open Source Dilemma in Embedded Development 29.01.2026

In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and embedded systems expert Elecia White , host of Embedded.fm and author of Making Embedded Systems , to discuss the trade-offs of using open source in embedded development. The conversation goes beyond debates about “open vs. proprietary” to explore how a single libr...

Beyond Defense: Building Cyber Resilience in Autonomous and Connected Mobility 15.01.2026

Autonomous and connected vehicles are reshaping transportation, but increased software complexity and connectivity introduce serious security and safety challenges that can’t be solved with traditional perimeter defenses. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and Hemanth Tadepalli, Senior Cybersecurity &am...

2026 ICS Security Predictions: What’s Next for Critical Infrastructure 30.12.2025

As industrial control systems become more connected, more Linux-based, and more exposed to IT-style threats, 2026 is shaping up to be a turning point for ICS security. In this end-of-year predictions episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security Founder & CEO Joseph M. Saunders and CTO Shane Fry to discuss what will define ICS and critical infrastructu...

When Vehicles Aren’t Just Machines: Cybersecurity, Autonomy & What’s Next 18.12.2025

As vehicles evolve into always-connected, software-defined systems, cybersecurity decisions increasingly shape privacy, safety, and trust on the road. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joseph M. Saunders and special guest Sean McKeever, Global Product Cybersecurity Lead at Marelli, for a candid discussion on what it really means to...

When Open Source Gets You Into Hot Water: Copyleft Risk in Embedded Systems 11.12.2025

Open source accelerates development in embedded systems, but hidden license obligations can quickly create legal and operational risk. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and Salim Blume, Director of Security Applications, for a look at how copyleft risk emerges and why compliance in embedded products is...

The Asymmetric Advantage: How Cybersecurity Can Outpace Adversaries 04.12.2025

In this episode of Exploited: The Cyber Truth , host Paul Ducklin sits down with RunSafe Founder and CEO Joseph M. Saunders to explore why the future of cyber defense depends on disrupting attacker economics rather than racing to keep up with every new threat. Joe breaks down how organizations can gain an asymmetric advantage by reducing exploitability across entire classes of vulnerabilities, esp...

Smarter Vulnerability Management in OT Systems: Building Resilience 20.11.2025

As OT environments face rising geopolitical tensions, ransomware threats, and aging infrastructure, vulnerability management has never been more complex. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Stuxnet expert Ralph Langner, Founder and CEO of Langner, Inc. Ralph shares from his decades of firsthand experience defending in...

Clean Files, Safe Operations: Defending Federal and OT Systems from AI-Driven Threats 13.11.2025

AI is fueling both innovation and new attack tactics. In this episode of Exploited: The Cyber Truth, host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and Kelly Davis, Senior Solutions Architect at Glasswall, to uncover how AI-powered malware is slipping through traditional detection in federal and defense environments—and what can be done about it. Kelly breaks do...

Designing Security into Life-Critical Devices: Where Innovation Meets Regulation 06.11.2025

As healthcare becomes increasingly connected, cybersecurity is now as critical to patient safety as the devices themselves. In this episode of Exploited: The Cyber Truth , host Paul Ducklin sits down with RunSafe Security Founder and CEO Joseph M. Saunders to explore how medical device manufacturers can design protection into every phase of product development—from concept to deployment and beyond...

How Generative AI Is Addressing Warfighter Challenges 30.10.2025

When we think of generative AI in defense, many think of how it will be used on the frontlines. But it actually serves a much wider purpose in helping warfighters plan, prepare, and execute missions. In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by RunSafe Security Founder and CEO Joseph M. Saunders and Arthur Reyenger, Generative AI Strategy Executive at Ask Sage, In...

What the 2025 SBOM Minimum Elements Mean for Software Supply Chain Security 23.10.2025

CISA and DHS have raised the bar for software transparency with the first major update to the Minimum Elements for an SBOM since 2021—expanding what every software supplier must disclose. But what does this really mean for developers, embedded system teams, and security leaders trying to protect critical infrastructure? In this episode of Exploited: The Cyber Truth , host Paul Ducklin is joined by...

Collaboration in Cyberspace with Madison Horn 16.10.2025

Safeguarding critical infrastructure demands more than just technology—it requires unity. In this episode of Exploited: The Cyber Truth , host Paul Ducklin sits down with RunSafe Security CEO Joseph M. Saunders and Madison Horn, National Security & Critical Infrastructure Advisor at World Wide Technology, to explore how collaboration across government and industry is shaping a stronger, more s...

Risk Reduction at the Core: Securing the Firmware Supply Chain 09.10.2025

The software supply chain often gets all the attention, but what about its foundation? In this episode of Exploited: The Cyber Truth , RunSafe Security Founder and CEO Joseph M. Saunders explores why securing the firmware supply chain is critical as attackers look to target the lowest layers of devices. Joe explains how firmware vulnerabilities in embedded and connected devices—across healthcare,...

Listen to the Exploited: The Cyber Truth podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.