Cybersecurity Awesomeness Podcast

40 Episodes
Subscribe

By: Enterprise Management Associates

The Cybersecurity Awesomeness Podcast from Enterprise Management Asscoaites (EMA) features cybersecurity expert Chris Steffen discussing critical cybersecurity issues. They cover everything from the challenges of certificate management and the cyber workforce talent shortage to deep. Available on all major platforms, this podcast offers credible, well-regarded insights into today's top security topics.

✂️ Clip this podcast
Cybersecurity Awesomeness Podcast - Episode 170
#170
Last Friday at 10:00 AM

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Lital Asher-Dotan and Mitchum Boles from Intezer to explore the rise of the AI Security Operations Center (SOC). Building on hot industry discussions from Black Hat, the conversation unpacks how AI-driven operations are fundamentally transforming traditional security workflows.

Steffen and his guests emphasize that an AI SOC moves far beyond basic alert shuffling or traditional automation by using deep forensic reasoning, external threat context, and behavioral analysis to eliminate noise and reduce false positives. Rather than eliminating human analysts, the guests argue that...


Cybersecurity Awesomeness Podcast - Episode 169
#169
08/14/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen shares his key takeaways from Black Hat, highlighting the event's practitioner-driven focus. Steffen breaks down three major themes dominating post-conference discussions.

First, the exponential explosion of non-human identities (NHIs) driven by agentic AI has made robust identity governance a critical enterprise priority. Second, organizations are finally budgeting and prioritizing data security, recognizing that Data Security Posture Management (DSPM) and Data Loss Prevention (DLP) must act as absolute prerequisites before deploying autonomous AI solutions. Finally, Steffen addresses the growing pushback against "AI for AI's sake," noting that...


Cybersecurity Awesomeness Podcast - Episode 168
#168
07/31/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen delivers a comprehensive preview of the upcoming Black Hat conference, highlighting the key themes and trends dominating Hacker Summer Camp. Steffen emphasizes that Artificial Intelligence remains front and center, with enterprise leaders heavily focused on balancing agentic AI productivity gains with strict governance.

This AI proliferation is driving a massive surge in non-human identities, creating critical challenges for Privileged Access Management (PAM) and Data Security Posture Management (DSPM). Steffen also previews discussions around LLM-driven vulnerability management, the ongoing push for passwordless account recovery, and the expanding...


Cybersecurity Awesomeness Podcast - Episode 167
#167
07/24/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Alex Salazar, founder and CEO of Arcade.dev, to explore the critical intersection of Artificial Intelligence, security, and agentic workflows. As AI transitions from a passive search tool to active "agents" capable of executing real-world tasks—such as modifying code, managing workflows, or handling data—traditional security paradigms are severely tested.

Salazar emphasizes a vital distinction: model guardrails (teaching an AI "character" and ethics) are not enough, just as raising a well-behaved child doesn't mean handing them the keys to a bank account. True...


Cybersecurity Awesomeness Podcast - Episode 166
#166
07/17/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen tackles the growing enterprise challenge of "Token Sprawl"—an unintended consequence of rapid, unmonitored AI adoption. As organizations integrate AI agents into development, security operations, and routine tasks, many are suffering from severe "sticker shock" as unmanaged consumption of AI tokens leads to ballooning, unpredictable costs.

Steffen draws parallels between today's token sprawl and the early, unoptimized days of cloud computing, noting that the issue isn't necessarily the pricing of tokens themselves, but the lack of governance. He explores how this creates friction between technical teams—who...


Cybersecurity Awesomeness Podcast - Episode 165
#165
07/10/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen welcomes Saqib Ahmad from Gigamon to discuss the pressing necessity of Post-Quantum Cryptography (PQC) readiness. While quantum computing may seem distant, the hosts highlight the immediate and severe threat of "Harvest Now, Decrypt Later" attacks. Adversaries are actively exfiltrating encrypted data today, betting on the future capability of quantum computers to break standard algorithms like RSA and ECC.

The conversation emphasizes that quantum vulnerability is a unique business risk, particularly for sectors handling long-term sensitive data such as government, healthcare, and intellectual property. Saqib underscores that...


Cybersecurity Awesomeness Podcast - Episode 164
#164
07/03/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen shifts to a solo format, addressing a pervasive fear dominating the industry: that Artificial Intelligence is destined to eliminate IT and cybersecurity jobs. Steffen challenges this "fear narrative," arguing that history shows technological shifts—from virtualization to cloud computing—consistently drive job growth and evolution rather than total displacement.

Citing projections from the World Economic Forum, Steffen emphasizes that while AI will displace certain roles, it will simultaneously create significantly more new positions. He explains that AI acts as an augmentative tool, handling high-volume, menial tasks whil...


Cybersecurity Awesomeness Podcast - Episode 163
#163
06/26/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and co-host Ken Buckler are joined by Simon Pamplin, CTO of Certes AI, to demystify the urgent threat of quantum computing. The conversation pivots away from the "mythical" future of quantum and focuses on the pressing reality of "Harvest Now, Decrypt Later" attacks, where adversaries exfiltrate encrypted data today with the intent to monetize it once quantum-enabled decryption becomes viable.

Pamplin challenges the industry’s tendency to frame quantum risk solely as a network security issue, arguing instead that it is a critical business risk that ca...


Cybersecurity Awesomeness Podcast - Episode 162
#162
06/19/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore a pressing security shift: adversaries are increasingly bypassing traditional credential theft to exploit the AI systems already embedded within corporate environments. The hosts discuss how "agentic" AI solutions often operate with overprivileged non-human identities, granting bots excessive access to data and infrastructure that far exceeds their functional requirements.

This resurgence of "standing access" for machine accounts—a vulnerability CISOs thought they had mitigated—is being exacerbated by the rapid, near-universal adoption of AI development tools. Using real-world examples, ranging from inadvertent AI-generated discounts to t...


Cybersecurity Awesomeness Podcast - Episode 161
#161
06/12/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the often-misunderstood world of mainframe computing. Despite the pervasive narrative that mainframes are "antiquated" technology, the hosts argue that they remain the gold standard for availability, integrity, and resilience in high-stakes environments like banking, healthcare, and government.

The discussion clears up common misconceptions, noting that modern mainframes are not just running legacy code like COBOL, but are fully capable of integrating with modern development tools and languages. Steffen and Buckler highlight that while the cloud offers flexibility, it lacks the sheer stability...


Cybersecurity Awesomeness Podcast - Episode 160
#160
06/05/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler discuss transformative announcements from the Microsoft Build Conference 2026. The central focus is Microsoft’s shift toward ARM-based architecture in partnership with NVIDIA, exemplified by the new RTX Spark superchip. This development marks a pivotal transition: moving personal AI agents from cloud-reliant models to high-performance, local desktop environments.

The hosts argue that this architectural evolution is a "security-first" milestone, allowing for local AI compute that significantly reduces privacy risks, data leakage, and the need for cloud-based credit systems. Beyond personal privacy, the discussion highlights th...


Cybersecurity Awesomeness Podcast - Episode 159
#159
05/29/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler revisit a foundational IT principle: the Single Point of Failure (SPOF). Using the mantra "two is one, and one is none," the hosts explore why modern organizations often overlook critical dependencies that, if compromised, can bring down entire systems.

The discussion traverses the spectrum from analog to digital, using the infamous train failures at Denver International Airport (DIA) as a prime example of a catastrophic physical SPOF that leaves thousands of travelers stranded. On the technical side, the hosts contrast fragile, linear network...


Cybersecurity Awesomeness Podcast - Episode 158
#158
05/22/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler shift focus from software to the often-overlooked realm of hardware security. The conversation centers on a recent Government Accountability Office (GAO) report detailing federal efforts to identify and remove telecommunications and surveillance equipment containing intentional backdoors and vulnerabilities linked to foreign actors—specifically from the People's Republic of China.

The hosts emphasize that hardware integrity is a critical national security concern, not just an enterprise compliance hurdle. While they caution listeners against panic-buying new routers, they highlight the inherent risks of using "end-of-life" ha...


Cybersecurity Awesomeness Podcast - Episode 157
#157
05/15/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler dissect Google’s recent discovery of the first clearly documented AI-assisted zero-day exploit. A threat actor utilized a Large Language Model (LLM) to develop a Python script designed to bypass two-factor authentication (2FA) on a widely used open-source system administration tool.

The hosts highlight the "smoking guns" that betrayed the AI’s involvement: an uncharacteristic abundance of educational docstrings, specific Python formatting typical of LLM training data, and a telltale hallucinated CVSS score. While this signals a productivity boost for adversaries, Chris and Ken offe...


Cybersecurity Awesomeness Podcast - Episode 156
#156
05/08/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler tackle the controversial intersection of digital privacy and state legislation. The discussion centers on Utah’s recent mandate requiring adult content providers to verify ages even when users are behind a VPN. This creates a technical "catch-22," forcing providers to either implement invasive identity checks or block privacy-enhancing tools entirely—a move the hosts argue is both technically infeasible and a threat to legitimate encryption use cases.

The conversation extends to California’s 2027 law, which aims to push age verification onto operating system providers. Chris...


Cybersecurity Awesomeness Podcast - Episode 155
#155
05/01/2026

In this special "Star Wars Day" edition of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler bridge the gap between sci-fi fantasy and modern security awareness. Utilizing the legendary franchise as a backdrop, the hosts deconstruct the glaring cybersecurity failures of the Galactic Empire to provide actionable lessons for today’s information security professionals.

The discussion highlights a total lack of port security and network authentication, famously exploited by R2-D2 to gain administrative control over complex systems through simple physical links.

Chris and Ken move into data integrity and insider threats, citing the de...


Cybersecurity Awesomeness Podcast - Episode 154
#154
04/24/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the radical evolution of exploit triage following the RSAC 2026 conference. They highlight Anthropic’s "Mythos," a sophisticated red-teaming AI capable of autonomously discovering and chaining vulnerabilities without human oversight. Unlike traditional hacking methods that rely on static kits, modern AI toolkits can scan massive IP ranges for every vulnerability in history—essentially automating the "needle in a haystack" search for attackers. This shift is particularly dangerous for legacy environments—essentially creating "Terminator" moments for infrastructure—where Windows XP embedded is still found in modern EV charg...


Cybersecurity Awesomeness Podcast - Episode 153
#153
04/17/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler dive into the FCC’s 2026 ban on foreign-made routers and the growing national security risks lurking in consumer hardware. The hosts break down how Russian intelligence (GRU) is currently weaponizing unpatched home routers to execute DNS hijacking. By silently altering DNS settings, attackers can monitor your traffic or redirect you to spoofed websites to harvest banking and social media credentials.

The discussion highlights that cybersecurity hygiene isn't just for "high-value targets." Even if you aren't guarding state secrets, opportunistic threat actors use these vulnerabilities fo...


Cybersecurity Awesomeness Podcast - Episode 152
#152
04/10/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore Google’s recent quantum computing milestone, which significantly accelerates the timeline for "Q-Day." Google’s research suggests that the physical qubit requirement to crack a Bitcoin signature could be slashed from millions to just 500,000, with scalable systems potentially arriving by 2029. While the hosts clarify that today’s blockchain remains secure for now, the announcement underscores an urgent need for organizations to adopt Post-Quantum Cryptography (PQC).

The discussion highlights how traditional computing is hitting physical barriers, making quantum specialized power the next logical step for hi...


Cybersecurity Awesomeness Podcast - Episode 151
#151
04/03/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler offer a comprehensive recap of RSAC 2026, cutting  through the noise of 40,000 attendees to deliver critical takeaways from the industry’s "Super Bowl." While AI dominated nearly 80% of vendor booths, the hosts differentiate between "marketecture" and meaningful innovation. They emphasize that deploying agentic AI without robust Data Security Posture Management (DSPM) is a recipe for unmanaged data sprawl and "Shadow AI" risks, where sensitive proprietary information is accidentally leaked into public models.

A significant portion of the discussion focuses on the maturation of identity management, not...


Cybersecurity Awesomeness Podcast - Episode 150
#150
03/20/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler prepare for the 2026 RSAC in San Francisco. Dubbed the "Super Bowl" of security, the event expects over 45,000 attendees and 600 vendors at the Moscone Center. Chris, managing a schedule of nearly 40 meetings, joins Ken to navigate the overwhelming noise of the show floor.

The duo identifies Agentic AI and autonomous solutions as the dominant—yet potentially distracting—themes of the year. They caution against the "silver bullet" mentality, urging leaders to focus on securing AI agents against hallucinations and IP leaks rather than viewing them as t...


Cybersecurity Awesomeness Podcast - Episode 149
#149
03/13/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler prepare for the RSA Conference (RSAC), often described as the "Super Bowl" of cybersecurity by talking about the EMA Vendor Vision report. To help attendees navigate the overwhelming presence of over 600 exhibitors, the hosts break down EMA’s "Vendor Vision" report, which spotlights ten essential innovators. The discussion covers a broad technological spectrum, ranging from Straker’s cutting-edge adversarial AI in the Early Stage Expo to Sky High Security’s leadership in Data Security Posture Management (DSPM).

Key highlights include AWS’s unified cloud security...


Cybersecurity Awesomeness Podcast - Episode 148
#148
03/06/2026

In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the shifting priorities of Chief Information Security Officers (CISOs) as they navigate the transition from rapid AI adoption to a more disciplined, risk-aware strategy. As of 2026, the "deploy first, secure later" mentality is facing a reckoning, particularly regarding autonomous or agentic AI. The discussion highlights alarming real-world incidents—such as an AI agent deleting a production database during a code freeze and another wiping a Meta executive's inbox despite repeated "stop" commands—to illustrate the volatility of unmanaged AI.

The conversation characterizes AI a...


Cybersecurity Awesomeness Podcast - Episode 147
#147
02/27/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore the looming reality of quantum computing and its inevitable collision with modern encryption standards. The discussion centers on Q-Day—the theoretical point at which quantum processors reach approximately 100,000 qubits, making current AES-256 encryption vulnerable to near-instantaneous decryption. The hosts emphasize the Harvest Now, Decrypt Later strategy, where adversaries stockpile encrypted sensitive data today in anticipation of tomorrow’s quantum capabilities.

While acknowledging the Quantum Dividend—the massive potential for breakthroughs in medicine and engineering—the conversation serves as an urgent call to action for secu...


Cybersecurity Awesomeness Podcast - Episode 146
#146
02/20/2026

In this "Cybersecurity 101" episode, Chris Steffen and Ken Buckler demystify quantum computing and its looming implications for modern encryption. Ken contrasts traditional binary bits—static ones and zeros—with qubits, using the analogy of a spinning coin to represent the multiple simultaneous states quantum computers can process. This immense power allows quantum systems to solve complex problems in milliseconds that would take traditional computers lifetimes. However, significant physical hurdles remain, such as the requirement for near-absolute zero cooling environments.

The most pressing security concern discussed is "Q-Day" and the "Harvest Now, Decrypt Later" strategy. Malicious actors are curr...


Cybersecurity Awesomeness Podcast - Episode 145
#145
02/13/2026

In this episode, Chris Steffen and Ken Buckler dissect the federal government’s evolving—and somewhat strained—approach to cybersecurity. A major catalyst for the discussion is the recent withdrawal of agencies like CISA, the FBI, and the NSA from the RSAC conference following former CISA head Jen Easterly’s appointment there. While potentially a move toward fiscal responsibility—given the $5,000 per-person total cost of the event—the hosts warn this retreat could stifle vital public-private partnerships and recruitment efforts.

The discussion also tackles systemic talent issues within the military. Experts often face a "promotion trap," being moved into m...


Cybersecurity Awesomeness Podcast - Episode 144
#144
02/06/2026

In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and Simon Wijckmans, CEO of C-side, discuss the critical visibility gap in client-side security. While organizations invest heavily in infrastructure and server-side protection, the user's browser remains a largely unmonitored attack vector. Historically, solutions like Content Security Policies and JavaScript agents have proven brittle or easily bypassed by sophisticated scripts that can hide from crawlers or override security hooks.

The conversation highlights a major shift driven by PCI DSS 4.0, which now mandates the monitoring and authorization of client-side scripts. Simon explains that modern browser changes regarding...


Cybersecurity Awesomeness Podcast - Episode 143
#143
01/30/2026

In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler discuss a humorous yet sobering encounter with a failed AI-driven scam. Ken recently received a common "advance fee" investment scam email, but with a unique twist: the attacker accidentally sent the Python source code instead of the intended message. The code contained telltale signs of AI generation, including placeholder instructions like "replace this with the actual import" for the Gemini SDK.

The hosts explain that while this specific attacker failed "successfully," the incident provides concrete proof that scammers are using generative AI to replace...


Cybersecurity Awesomeness Podcast - Episode 142
#142
01/23/2026

In this episode, Chris Steffen and Ken Buckler are joined by Jim LaRoe, CEO of Symphion, to discuss the often-ignored threat of printer and IoT security. Jim reveals a startling set of "winning lottery numbers": printers account for 20% of network endpoints, yet 99% remain unprotected. With 67% of organizations reporting a printer-related security incident last year, these devices serve as a critical yet vulnerable vector for lateral movement and credential harvesting.

Jim explains this widespread neglect through his "Five O's," citing the lack of a formal Owner and their Origin as business equipment rather than IT endpoints. Because printers...


Cybersecurity Awesomeness Podcast - Episode 141
#141
01/16/2026

In this episode, Chris Steffen and Ken Buckler discuss the alarming security and privacy implications of the "Internet of All Things." The hosts highlight how manufacturers are connecting everything—from AI-powered treadmills to smart toothbrushes—often without considering the associated risks.

A primary concern is the shift toward recurring revenue models, where companies gate-keep hardware features behind monthly subscriptions. Beyond the cost, Ken warns of the physical security threats posed by Bluetooth-enabled appliances. He explains how broadcasting devices can inadvertently signal a resident's presence or daily habits to malicious actors in close proximity.

The discussion also...


Cybersecurity Awesomeness Podcast - Episode 140
#140
01/09/2026

Chris Steffen and Ken Buckler from EMA discuss privacy concerns around generative AI.


Cybersecurity Awesomeness Podcast - Episode 139
#139
12/19/2025

Chris Steffen and Ken Buckler from EMA present their 2026 Cybersecurity Predictions.


Cybersecurity Awesomeness Podcast - Episode 138
#138
12/12/2025

Chris Steffen and Ken Buckler from EMA discuss API security.


Cybersecurity Awesomeness Podcast - Episode 137
#137
12/05/2025

Chris Steffen and Ken Buckler from EMA discuss attacks via SEO outreach on news sites.


Cybersecurity Awesomeness Podcast - Episode 136
#136
11/28/2025

Chris Steffen and Ken Buckler from EMA discuss what they are thankful for in cybersecurity.


Cybersecurity Awesomeness Podcast - Episode 135
#135
11/21/2025

Chris Steffen and Ken Buckler from EMA discuss the Cloudflare outage and what availability means in the technology space.


Cybersecurity Awesomeness Podcast - Episode 134
#134
11/14/2025

Chris Steffen and Ken Buckler from EMA discuss securing AI LLMs.


Cybersecurity Awesomeness Podcast - Episode 133
#133
11/07/2025

Chris Steffen and Ken Buckler from EMA discuss trends in network security.


Cybersecurity Awesomeness Podcast - Episode 132
#132
10/31/2025

Chris Steffen and Ken Buckler from EMA discuss phishing and deep fakes for Cybersecurity Awareness Month.


Cybersecurity Awesomeness Podcast - Episode 131
#131
10/24/2025

Chris Steffen and Ken Buckler from EMA discuss insider threats for Cybersecurity Awareness Month.