Security Conversations

Three Buddy Problem

The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).

Author

Security Conversations

Category

Technology

Latest episode

Jul 4, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Andrew Morris, Founder and CEO, GreyNoise Intelligence 31.05.2018

Founder and CEO of GreyNoise Intelligence Andrew Morris ( andrew___morris ) talks about his “anti threat-intelligence” company, the ways SOCs are using it to filter through scanning noise and the trials and tribulations of bootstrapping a start-up.   https://securityconversations.com/wp-content/uploads/2018/05/andrew_morris.mp3

Yoav Leitersdorf, Managing Partner , YL Ventures 21.05.2018

Managing Partner at YL Ventures, Yoav Leitersdorf ( ylventures ), explains the surge in cybersecurity investments in Israel, the priorities for his $75 million fund and which sectors are ripe for the picking.   https://securityconversations.com/wp-content/uploads/2018/05/ep30-yoav_leitersdorf.mp3

Juan Andrés Guerrero-Saade, Principal Security Researcher, Recorded Future 14.05.2018

Principal Security Researcher at Recorded Future’s Insikt Group, Juan Andrés Guerrero-Saade ( juanandres_gs ), explains the nuances of good threat intelligence, sheds light on nation-state hacker activity and warns that adversaries don’t have to be “sophisticated” to launch successful attacks.   https://securityconversations.com/wp-content/uploads/2018/05/juan_andres_guerrero_saade.mp3

Robert M. Lee, Chief Executive Officer, Dragos Inc. 10.05.2018

The founder and CEO of Dragos, Inc. Robert M. Lee ( RobertMLee ) cuts through the hype around threats to critical infrastructure and offers a matter-of-fact take on active defense, “hacking-back,” and nation-state espionage operations.   https://securityconversations.com/wp-content/uploads/2018/05/ep28-robert-m-lee.mp3

Brandon Dixon, Vice President, RiskIQ 09.05.2018

VP of Product at RiskIQ Brandon Dixon ( @9bplus ) delves into nation-state cyber operations, explains why it’s dangerous to underestimate North Korea’s capabilities, and his passion for roasting the perfect coffee bean. https://securityconversations.com/wp-content/uploads/2018/05/ep27-brandon-dixon.mp3

Ryan Huber, Security Architect, Slack 08.05.2018

Slack security architect Ryan Huber talks about the gargantuan task of defending an organization with 8 million daily active users, burnout, and fatigue in security teams and a range of issues around bug bounties and penetration testing.

Ivan Arce, CTO at Quarkslab 04.05.2018

Chief Technology Officer at Quarkslab Ivan Arce ( @4dgifts ) tells stories about the birth of penetration testing platforms, the concentration of hacking talent in Argentina, and his focus on security problems in the Android ecosystem. https://securityconversations.com/wp-content/uploads/2018/05/ivan_arce_01.mp3

Sinan Eren, Founder and CEO, Fyde 02.05.2018

Founder and CEO of Fyde (@ FydeApp ) Sinan Eren discusses the “iOS-ification” of platforms and the security ramifications, the dangers of running AV software, the iOS vs. Android security argument, and his new venture to address mobile phishing attacks. https://securityconversations.com/wp-content/uploads/2018/05/Ep-24-sinan_eren.mp3

Stephen Ridley, Founder and CTO, Senrio 30.04.2018

Founder and CTO at Senrio Stephen Ridley ( @s7ephen ) talks about the abysmal state of IoT security, his recent exploitation of an IP camera, and router to exfiltrate corporate data and his experience as a minority in the security industry. https://securityconversations.com/wp-content/uploads/2018/04/Ep23-stephen-ridley.mp3

Mischel Kwon, Founder and CEO, MKA Cyber 26.04.2018

Founder and CEO at MKACyber Mischel Kwon joins the podcast to address the state of the SOC (Security Operations Center) and how businesses should deal with issues around excessive alerts, incident response times, and outdated metrics.

Rick Holland, CISO and VP of Strategy, Digital Shadows 24.04.2018

CISO and VP of Strategy at Digital Shadows Rick Holland discusses his path in the information security industry, advancements in the threat intel space, and his passion for good bar-b-que.

Thomas Ptacek, Founder, Latacora 23.04.2018

Latacora Security founder Thomas Ptacek joins the podcast to weigh in on the cybersecurity skills shortage, his approach to recruiting and hiring, and what needs to be done to address diversity in the industry.

Zane Lackey, Chief Security Officer, Signal Sciences 16.04.2018

Co-founder and Chief Security Officer at Signal Sciences Zane Lackey riffs on DevOps, the almost impossible task of defending organizations from intruders, bug bounties versus penetration testing, and the pros and cons of launching a company with venture capital investment.

Haroon Meer, CEO, Thinkst Applied Research 12.04.2018

Thinkst founder Haroon Meer talks about building a security company from scratch without VC funding, using Canaries to pinpoint signs of intruder activity, advancements in security research, and the state of the bug bounty market.

David (int eighty), Dual Core 11.04.2018

Red teamer and security researcher by day, nerdcore rapper by night, ‘int eighty’ joins the podcast to talk about his work breaking into computer systems, common security mistakes that people make, and his double life as a musician in Dual Core.

Dennis Fisher, Editor-in-Chief, Decipher 05.04.2018

Veteran cybersecurity writer Dennis Fisher joins the podcast to talk about his new journalism venture at decipher.sc, his preference for long-form writing, and the trends worth following in the security space.

Tim Maurer, Scholar, Carnegie Endowment for International Peace 05.03.2018

Tim Maurer, a scholar at the Carnegie Endowment for International Peace, talks about nation state-backed hacking activity and the dangers of breaking trust in the global financial system.

Will Lin, Principal and Founding Investor, ForgePoint Capital 02.03.2018

Principal and founding investor at ForgePoint Capital Cybersecurity William Lin talks about venture capital activity in the security space, sectors that are ripe for investment, missed bets on successful companies, and the cybersecurity talent shortage.

Pete Chronis, CISO, Turner Broadcasting 26.02.2018

Chief Information Security Officer at Turner Broadcasting Pete Chronis discusses his new book on solving the cybersecurity conundrum, the day-to-day grind of securing a global media organization, and the role of the CISO in the modern world.

Brad Arkin, Chief Security Officer, Adobe 23.02.2018

Adobe’s Chief Security Officer Brad Arkin talks about setting and managing risk management priorities, protecting company infrastructure, the challenges of securing software, and the looming death of Adobe Flash Player.

Aanchal Gupta, Director of Security, Facebook 14.02.2018

Director of Security at Facebook Aanchal Gupta joins the podcast to share her story and provide guidance for young women struggling to overcome societal obstacles.

Tom Conklin, Director of Security and Compliance, Vera Security 08.02.2018

Senior Director of Security and Compliance at Vera Security Tom Conklin talks about the pros and cons of using bug bounty programs, the challenges of managing risk in smaller companies, and why user awareness training is an ongoing headache for security administrators.

John Terrill, CISO, Fox News, Fox Business and Fox Television 06.02.2018

Chief Information Security Officer at Fox News, Fox Business, and Fox Television John Terrill joins the podcast to talk about life in the CISO trenches and makes a bold prediction that could significantly change the cybersecurity narrative.

Christopher Ahlberg, CEO, Recorded Future 30.01.2018

Co-founder and CEO of Recorded Future Christopher Ahlberg discusses the emergence of threat intelligence as a valuable security tool, the morals and ethics surrounding disclosure of nation-state attacks and the importance of tracking adversaries beyond the wall.

Masha Sedova, co-founder, Elevate Security 26.01.2018

As businesses struggle with security awareness training for employees, Elevate Security co-founder Masha Sedova argues that the focus should be on “behavior change” and recommends the use of positive motivation and available tools to get employees to make better security decisions.

Listen to the Three Buddy Problem podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.