Safe Mode Podcast

40 Episodes
Subscribe

By: Safe Mode Podcast

Podcast by Safe Mode Podcast

✂️ Clip this podcast
The world still treats bug hunters like criminals
The world still treats bug hunters like criminals episode artwork
Yesterday at 7:53 PM

Kat Sommer, head of government affairs at NCC Group, joins Safe Mode to unpack the DEF CON talk she gave on how governments around the world are — and mostly aren't — protecting security researchers. Of the roughly 195 jurisdictions on the planet, Sommer found only about 15 have enacted any form of legal safe harbor for vulnerability research, and just one, Portugal, has what she'd call a proper one on the statute book. She walks Greg Otto through the patterns that emerged from that survey: the encouraging shift toward regulating conduct rather than actors, the conditions that actually make sense (don't extort the vend...


The SOC wasn't built for this
The SOC wasn't built for this episode artwork
08/06/2026

Security operations centers have run on the same playbook for decades — collect, queue, triage, investigate, escalate. But attackers now move at machine speed: one recent breach that cost a company 3,600 repos got underway in roughly 87 seconds, far outpacing even a fast 10-minute log-enrichment pipeline. This week, host Greg Otto talks with ExtraHop CEO Greg Clark about the newly announced Agentic SOC Alliance and why he believes traditional SOC architecture can't keep up. Clark breaks down the three-layer stack he says every CISO needs to understand — context (the historical and real-time data an agent needs to reason about a threat), harness (the...


Why Cybersecurity is at the heart of the US-China AI race
Why Cybersecurity is at the heart of the US-China AI race episode artwork
07/30/2026

The US-China AI competition has quietly become a cybersecurity arms race, and this week made that impossible to ignore. Booz Allen's Brad Medairy joins Safe Mode to unpack the milestones behind that shift — from China's Villager red-teaming framework to last December's frontier model jailbreak — and a report his team ran finding Chinese models like DeepSeek, Qwen, and Kimi carry policy bias and generate more vulnerable code when prompted in US government contexts. Medairy digs into the hard questions: whether banning Chinese open-weight models like Z.AI/GLM is even feasible, why CISOs are unknowingly running them under different names, and how...


A builder's view of the AI arms race
A builder's view of the AI arms race episode artwork
07/23/2026

It's been a wild six weeks for frontier AI models — Mythos launched, got yanked offline by the Department of Commerce over export controls, and came back online with new guardrails, all while Five Eyes agencies warned that AI is months away from reshaping the threat landscape. This week on Safe Mode, Greg Otto talks with Armadin's David Slater, who is building directly on top of these frontier models, creating a platform integrating AI into cybersecurity offense and defense. The two dig into what it was actually like watching America's leading models go dark just as Chinese models — namely GLM 5.2 — closed the ga...


What the Section 702 lapse means for cybersecurity
What the Section 702 lapse means for cybersecurity episode artwork
07/16/2026

For the first time in its operational history, FISA Section 702 has lapsed, plunging U.S. intelligence agencies and telecom providers into a highly uncertain "grey zone." In this episode of Safe Mode, host Greg Otto sits down with Glenn Gerstell, former NSA General Counsel and senior adviser at the Center for Strategic and International Studies (CSIS), to navigate the fog of this unprecedented lapse. While the government is temporarily coasting on grandfathered certifications, the operational reality is getting increasingly dicey. Gerstell explains what this lapse actually means for the future of U.S. cyber defense, how political friction is complicating...


What the post-quantum executive order means for CISOs
What the post-quantum executive order means for CISOs episode artwork
07/09/2026

In this week’s episode, Greg speaks with Ellen Boehm, SVP of Strategy and AI Operations at Keyfactor, about what the administration’s post-quantum cryptography executive order means for CISOs and enterprise leaders. Boehm argues that preparing for post-quantum cryptography is not just a technical cryptography challenge, but a leadership and business-risk problem. The conversation covers why compliance deadlines are pushing organizations to act, how CISOs should frame quantum risk for boards and executives, and why cryptographic inventories are a critical first step for any serious migration plan. The discussion also explores how organizations can build cross-functional teams across security, IT...


How security investigators can get the right info out of AI security tools
How security investigators can get the right info out of AI security tools episode artwork
07/02/2026

This week on Safe Mode, Greg sits down with Dov Yoran, CEO and co-founder of Command Zero, to talk about one of the most persistent problems in enterprise security: the investigation gap. Alert volumes keep climbing, SOC teams are drowning in triage, and the tools meant to help are aggregating data without actually reasoning through it. Dov breaks down how the real bottleneck in security operations comes down to expertise — knowing what questions to ask, where to find the data, and how to build a narrative around it. He explains how Command Zero has codified years of SecOps and incident ha...


Inside Operation Disruption Week: Taking Down Southeast Asia's Scam Machine
Inside Operation Disruption Week: Taking Down Southeast Asia's Scam Machine episode artwork
06/25/2026

What does it actually take to dismantle an industrial-scale scam operation running bulletproof hosting, distributed ASNs, and crypto laundering across multiple countries? Mike Sweeney of Silent Push was in the room during Operation Disruption Week and tells us exactly how it went down — the intelligence, the coordination, and why this public-private model could be a blueprint for future cyber disruption efforts. Plus, reporter Tim Starks on the open source supply chain crisis: the volunteer maintainers holding up the internet, the threat groups coming after them, and the policy vacuum left behind after the Biden administration's momentum stalled.


Zero days, zero order: The chaos reshaping vulnerability disclosure
Zero days, zero order: The chaos reshaping vulnerability disclosure episode artwork
06/18/2026

The rules of responsible disclosure were written for a different era — one where humans found bugs, humans reported them, and 90 days felt like plenty of time to patch. That era is over. In this episode, Greg sits down with Gal Elbaz, co-founder and CTO of Oligo Security, to unpack how AI-assisted vulnerability research is breaking the frameworks the security industry has relied on for decades. From MITRE admitting it can no longer keep up with the volume of CVE reports, to Linus Torvalds saying the same about the Linux kernel, the cracks in the system are impossible to ignore. Gal dr...


Why the autonomous SOC Is the wrong goal
Why the autonomous SOC Is the wrong goal episode artwork
06/11/2026

On this week's episode, we're joined by Mike Nichols, General Manager of Security at Elastic, fresh off the Gartner Security and Risk Summit in the D.C. area, where AI dominated every conversation on the conference floor. Mike walks us through what CISOs are actually asking about, what a real agentic SOC looks like in practice, and why keeping humans on the loop is the key philosophical distinction that separates a thoughtful AI implementation from a reckless one. The conversation covers "tribal knowledge," shadow AI, prompt injection, model sovereignty, and the exploding attack surface that AI agents themselves create, with...


The last layer standing
The last layer standing episode artwork
06/04/2026

What happens when an "assume breach" scenario turns into a total corporate wipeout? In this episode of Safe Mode, host Greg welcomes Brandon Willitts, Director of Cyber Resilience at Everpure, to pull back the curtain on a devastating "malwareless" attack that deleted over 80,000 endpoints at a Fortune 100 company. When adversaries exploit valid credentials to compromise the entire identity plane, your own endpoint management tools can be weaponized against you. Brandon breaks down how separating the storage layer from the identity blast radius—and leveraging immutable snapshot technology—allowed a non-technical engineer to jumpstart a full recovery in just days rather than...


From Two Weeks to Three Days: The KEV Deadline Debate
From Two Weeks to Three Days: The KEV Deadline Debate episode artwork
05/29/2026

Drawing on his experience from his time in government working directly on CISA’s Known Exploited Vulnerabilities (KEV) catalog, Todd Beardsley, VP of Security Research at runZero, explains what it actually took behind the scenes to get a vulnerability added: verifying that real exploitation occurred, confirming the incident mattered to federal interests (including state/local governments, critical infrastructure, or allied nations), and ensuring there was a concrete remediation option before publishing. He walks Greg through how those judgments tied back to Binding Operational Directive 22-01 and how deadlines were set and adjusted from the two-week baseline—context that frames the rece...


Can specialized security survive Daybreak and Mythos?
Can specialized security survive Daybreak and Mythos? episode artwork
05/21/2026

In this episode, we sit down with Lior Div, CEO of 7AI, at a moment when the ground is shifting under the entire security industry. With AI lowering the barrier to entry for attackers, supply chain compromises spreading at worm speed, and OpenAI and Anthropic racing to plant their flags in enterprise cyber defense, the pressure on defenders has never been more acute. We push Div on the hard stuff — whether agentic defense actually closes the asymmetry gap or just keeps pace with it, what Mini Shai-Hulud exposes about the blind spots in how we trust software, how the arrival of...


Why access brokers have stubbornly remained successful
Why access brokers have stubbornly remained successful episode artwork
05/14/2026

Anna Pham of Huntress joins Safe Mode to discuss the current landscape of initial access brokers and how their tactics continue to support ransomware operations. She explains that attackers are still finding success with drive-by downloads, Trojanized installers, fake browser updates, click-fix attacks, exposed RDP, VPN weaknesses, and vulnerable edge devices. The conversation also covers how access is monetized, what defenders can look for before ransomware deployment, and why limited endpoint visibility often leaves organizations exposed. Fam emphasizes that basic cyber hygiene still matters: close exposed ports, enforce MFA, use complex passwords, apply least privilege, patch systems, and maintain broad...


Can you prove which agent did what?
Can you prove which agent did what? episode artwork
05/07/2026

In this week's episode, Greg Otto talks with Howard Ting, CEO of Opal Security, about the growing security challenges created by AI agents inside the enterprise, especially around identity governance, access control, and runtime authorization. As organizations adopt coding agents, workplace assistants, and other AI tools, traditional approaches to managing human access are being pushed beyond their limits by the speed, scale, and context required for agent-driven decisions. The conversation explores the risks of shadow AI, overprivileged agents, unintended data exposure, and the difficulty of enforcing least privilege when agents act on behalf of employees across sensitive systems. It also...


How government and Industry can raise the cost of cybercrime
How government and Industry can raise the cost of cybercrime episode artwork
04/30/2026

Sophos CEO Joe Levy and Director of Government Partnerships Alex Rose join Safe Mode from Washington, D.C. to discuss what meaningful public-private cybersecurity partnership looks like right now—moving beyond “window dressing” to real operational collaboration with agencies like CISA and the FBI. They break down the shift from Secure by Design to Secure by Demand, arguing that procurement and market forces must pressure software vendors to ship safer defaults, while AI simultaneously accelerates both vulnerability discovery and attacker capability. The conversation also spotlights why small and midsize businesses are disproportionately exposed yet often underserved, and previews Sophos’s upcoming...


Proving Identity in the age of agents
Proving Identity in the age of agents episode artwork
04/23/2026

As AI makes deepfakes and voice cloning more convincing, attackers are shifting away from traditional vulnerabilities and focusing on identity as the easiest path to account takeover and fraud. In this conversation, Eran Haggiag of Glide Identity discusses what it will take to protect identity in an agentic world—how to prove a real user approved an action, how to establish accountability when software acts on someone’s behalf, and why cryptographic, hardware-rooted signals may be the clearest way out of the cat-and-mouse cycle. In our reporter chat, Greg talks with Matt Kapko about what led to the Vercel breach that...


The federal government's most underrated cybersecurity tool
The federal government's most underrated cybersecurity tool episode artwork
04/16/2026

In this episode of Safe Mode, we sit down with Philip George, Executive Technical Strategist at Merlin Group to talk about the real challenges federal agencies face at the intersection of cybersecurity, AI adoption, and post-quantum cryptography. Philip breaks down the disconnect between cyber spending and mission outcomes, why rushing into AI without sound identity management and data integrity is a recipe for disaster, and what evolving federal cryptographic requirements and shortened certificate lifecycles mean for government IT. We dig into why visibility — simply knowing what's on your network — remains the most powerful defensive posture regardless of the threat, explore the...


What does industry think of the White House's cybersecurity strategy?
What does industry think of the White House's cybersecurity strategy? episode artwork
04/10/2026

Bob Ackerman (founder of Allegis Cyber and a partner at DataTribe) joins Safe Mode to talk about where the new national cybersecurity strategy is trying to push the industry—especially around more open, coordinated “active disruption” with government support (and what that does not mean, like hack-back). He shares what he’s hearing from leaders who want clearer “rules of the road,” and why it’s tough to move from reactive collaboraBob Ackerman (founder of Allegiance Cyber and a partner at DataTribe) joins Safe Mode to talk about where the new national cybersecurity strategy is trying to push the industry—especially around more...


When iPhone exploits turn into commodities
When iPhone exploits turn into commodities episode artwork
03/26/2026

A sophisticated iPhone exploit kit known as DarkSword has escaped the world of targeted espionage and landed in public view—leaked on GitHub in a form that researchers say is trivial to repurpose and deploy. With the barrier to entry collapsing to “copy, paste, host,” the immediate concern is no longer whether advanced actors can use it, but how quickly criminal groups and opportunistic attackers will operationalize it against the enormous population of out-of-date iOS devices.
 In this episode, Jame’s Michael Covington joins us for a practitioner-level breakdown of what the DarkSword leak changes, who’s exposed, and what defenders ca...


Behind the scenes of the Socksescort takedown
Behind the scenes of the Socksescort takedown episode artwork
03/19/2026

In this episode, we sit down with Chris Formosa to break down the Socksescort disruption—a proxy botnet powered by AVRecon that compromised edge devices at scale. Chris walks us through why the operation was so dangerous, how investigators tracked its command-and-control infrastructure, and what changed between the 2023 disclosure and the eventual takedown in coordination with the Department of Justice. We also dig into why edge devices remain prime targets, where most organizations still have visibility gaps, and what the next evolution of this threat could be. In our reporter chat, Greg Otto and Tim Starks break down DarkSword, a iO...


What comes next for Trump's cybersecurity plan?
What comes next for Trump's cybersecurity plan? episode artwork
03/12/2026

On this episode of Safe Mode, Greg Otto and Tim Starks look past the headline release of President Trump’s new cyber strategy and focus on what comes next: the promised follow-on guidance, the rollout of an interagency “cell” spanning DOJ, State, FBI, DoD and others that pairs cyber operations with diplomacy and arrests, and the state-by-state critical infrastructure pilot programs designed to test what actually works before scaling. In our interview segment, acting Federal CISO Mike Duffy lays out his priorities for 2026.


A plea to improve quantum security in the federal government
A plea to improve quantum security in the federal government episode artwork
03/05/2026

In this episode, we sit down with Gharun Lacy, Deputy Assistant Secretary for the Cyber and Technology Security Directorate at the U.S. Department of State, who issues a stark warning: no organization can defend against quantum-enabled cyber threats alone. Hear Lacy explain why adversaries like China are already harvesting encrypted data today—planning to crack it years from now when quantum computers arrive. He breaks down the "harvest now, decrypt later" threat and why your encrypted data may outlive multiple leadership cycles, creating risks that stretch across generations like an accordion through time. Lacy challenges both public and private se...


Is the 'Shields Up' era of CISA over?
Is the 'Shields Up' era of CISA over? episode artwork
02/26/2026

One year into the second Trump administration, the Cybersecurity and Infrastructure Security Agency (CISA) is facing what former officials and industry partners describe in stark terms: “decimated,” “amateur hour,” and “pretty much fallen apart.” In this episode, Greg Otto dives in with Tim Starks to unpack what’s happened inside the nation’s lead civilian cyber defense agency—and what it could mean for the country’s ability to withstand the next major cyber crisis. In the interview segment, we bring two experts from the DOD's Cyber Crime Center to speak about what they're seeing on the threat landscape.


Should you still trust your password manager?
Should you still trust your password manager? episode artwork
02/19/2026

In this episode, Greg explores the gap between password manager marketing claims of "Zero Knowledge Encryption" and the reality uncovered by Swiss researchers who found 25 attacks against Bitwarden, LastPass, and Dashlane. Professor Kenny Patterson joins Greg to discuss why the industry's "honest-but-curious" security model is dangerously inadequate compared to a "malicious server" threat model, diving into three critical vulnerability categories: account recovery mechanisms that allow attackers to swap encryption keys, seemingly innocent features like icon fetching that leak passwords, and "vault malleability" where individual item encryption lets attackers cut-and-paste data between vault fields. They also discuss how legacy code support...


No exceptions: How Amazon killed the password and unified security
No exceptions: How Amazon killed the password and unified security episode artwork
02/12/2026

In this episode, we sit down with Stephen Schmidt, SVP & Chief Security Officer at Amazon, to explore the engineering and leadership required to run a "no exceptions" identity program at a global scale. Most organizations suffer from the "fragmentation problem"—a mix of high-security cloud apps and vulnerable legacy systems. Stephen explains how Amazon unified its authentication standard to ensure that every internal account, from a fresh developer environment to a legacy application from 2003, meets the same rigorous bar. In our reporter chat, Greg talks with Derek Johnson on why your AI doctor does not have the same privacy protections as...


What leaders can learn from the WEF's Cybersecurity Outlook
What leaders can learn from the WEF's Cybersecurity Outlook episode artwork
02/05/2026

AI is reshaping cybersecurity faster than most organizations can govern it—and the risk no longer stops at the edge of the enterprise. In this episode, Greg speaks with Brian Dye, CEO of Corelight, about the World Economic Forum’s Global Cybersecurity Outlook 2026: why fraud and phishing are rising on the CEO agenda, why ransomware still dominates operations, and how leaders can build measurable resilience amid growing third‑party and cloud dependencies. In the reporter chat, Greg talks with Derek Johnson on the reaction at the recent NASS conference to the raid on election efforts in Fulton County, Georgia. Join Virtru...


Opportunistic by Default: How OT gets pulled into the blast radius
Opportunistic by Default: How OT gets pulled into the blast radius episode artwork
01/29/2026

In this episode of Safe Mode, we look at how opportunistic campaigns—often starting as loud disruption like DDoS—can probe for weak points and, in some cases, move closer to operational technology and industrial control systems. Using a recent Justice Department case tied to pro‑Russia hacktivist groups as a jumping-off point, we discuss what this pattern says about the OT threat landscape in 2025, from remote access and trust boundaries to engineering workflows and data integrity risk. Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, joins to explain what defenders should prioritize now to keep “noise” from becoming real-world...


How do you win a conflict most Americans can’t see?
How do you win a conflict most Americans can’t see? episode artwork
01/22/2026

Retired Lt. Gen. Charlie “Tuna” Moore, former deputy commander of U.S. Cyber Command, joins Safe Mode to break down his new paper on “dominating the digital space” and a whole-of-society strategy for defending the United States from cyber aggression. Host Greg Otto digs into why cyber deterrence often fails below the threshold of armed conflict and what a National Cyber Operations Team—integrating private-sector talent under Cyber Command oversight—could look like in practice. Plus, journalist Matt Kapko returns to unpack the messy ethics and incentives behind ransomware negotiations after new guilty pleas spotlight just how unregulated the space can be.


What's powering the 'Steroid Era' of cybercrime?
What's powering the 'Steroid Era' of cybercrime? episode artwork
01/15/2026

Greg sits down with Adam Myers, Head of Counter Adversary Operations at CrowdStrike, and Elia Zaitsev, CTO of CrowdStrike, to discuss why 2025 has been dubbed the "steroid era" for cybercrime due to AI's transformative impact on both attackers and defenders. The conversation reveals alarming statistics—a 442% increase in AI-powered voice-based phishing attacks, average adversary breakout times dropping to just 48 minutes, and 81% of intrusions now operating without any malware at all—while also exploring how adversaries are exploiting vulnerabilities faster and using AI to write exploits. However, the experts explain how AI is also empowering defenders through agentic security systems like Crow...


The Access‑Trust Gap: Why security can’t see what work depends on
The Access‑Trust Gap: Why security can’t see what work depends on episode artwork
12/18/2025

In our final episode of 2025, Dave Lewis, global advisory CISO for 1Password, joins Greg Otto to unpack the “access‑trust gap”: the growing mismatch between what employees (and tools like AI assistants) can access at work and what security teams can actually see, verify, and control. Dav explains how this gap shows up in everyday ways—logins that bypass intended controls, personal devices used for work, and teams adopting apps or AI tools faster than IT can govern them—and why that combination creates quiet but serious risk. You’ll hear practical advice on narrowing the gap with stronger identity checks, smar...


How AI has complicated enterprise mobile security
How AI has complicated enterprise mobile security episode artwork
12/11/2025

In this episode of Safe Mode, Jim Dolce, CEO of Lookout, reveals that 40% of phishing attacks now target mobile devices—yet CISOs are drastically underspending on mobile security compared to email protection. Jim demonstrates how AI-powered attacks have become devastatingly effective, showing how his team created a voice-cloning impersonation attack in 15 minutes that fooled over half their employees into surrendering credentials, bypassing even multi-factor authentication. He explains why credential theft is now the #1 attack vector, costing $4-5 million per breach, and how modern smishing attacks use scraped social media data to craft hyper-personalized messages that are nearly impossible for humans to...


Breaking down the latest era of Chinese cyberespionage with Booz Allen's Nate Beach-Westmoreland
Breaking down the latest era of Chinese cyberespionage with Booz Allen's Nate Beach-Westmoreland episode artwork
12/04/2025

In this episode, we sit down with Nate Beach-Westmoreland, Head of Strategic Cyber Threat Intelligence at Booz Allen, to explore the evolving sophistication of Chinese cyber operations and their implications for U.S. national security. Our guest breaks down how the PRC leverages trusted-relationship abuse, network edge exploitation, and AI-powered influence campaigns to infiltrate critical infrastructure, evade detection, and operate below escalation thresholds that limit allied responses. From supply chain compromises to the weaponization of artificial intelligence in information warfare, this conversation reveals the strategic chess game playing out in cyberspace—and what the U.S. and its allies must do...


How Visa's CISO turns a 'paranoid and pessimisitic mindset' into positive security outcomes
How Visa's CISO turns a 'paranoid and pessimisitic mindset' into positive security outcomes episode artwork
11/20/2025

Visa CISO Subra Kumaraswamy joins Safe Mode to discuss the global scale and complexities of cybersecurity at Visa, from managing a billion transactions daily to maintaining a resilient, “paranoid” defensive posture. Subra reveals how his team blends innovation, threat intelligence, and layered security architectures—not just to protect Visa, but to uplift the wider payment ecosystem—including strategies for defending against supply chain attacks, leveraging AI, and preparing for deepfakes and post-quantum computing. The episode provides a look behind the scenes at how Visa is working to ensure trust and reliability in payments for its global network of cardholders, partners, and merc


What security teams should do to prepare for the quantum computing future
What security teams should do to prepare for the quantum computing future episode artwork
11/13/2025

Rebecca Krauthamer, CEO of QSecure, joins Safe Mode to delve into the rapidly shifting landscape of quantum computing and cybersecurity. The conversation covers the latest government and industry responses to the quantum threat, the urgency of adopting post-quantum encryption, and practical metrics for agencies and organizations. Listen in as the complexities and urgency of preparing for “Q-Day” are unpacked, offering key insights for policy makers, technologists, and anyone concerned with data security’s future.


How MSP's are dealing CISA changes
How MSP's are dealing CISA changes episode artwork
11/06/2025

On this week’s Safe Mode, Greg welcomes Jason Pufahl, VP of Security Services at Vancord. Jason shares deep insights into the evolving managed security landscape, focusing on challenges faced by small and mid-sized businesses and the practical fundamentals they need for strong cybersecurity. He also discusses the evolving role of CISA and the importance of making threat intelligence and resources broadly accessible to help organizations of all sizes strengthen their cybersecurity posture.


Mobilizing Main Street: Inside the Cyber Civic Engagement Program
Mobilizing Main Street: Inside the Cyber Civic Engagement Program episode artwork
10/30/2025

In this episode of Safe Mode, Betsy Cooper, founding director of the Aspen Institute’s Policy Academy, details a new initiative designed to mobilize ordinary citizens as cybersecurity policy advocates. The Cyber Civic Engagement program, supported by Craig Newmark Philanthropies’ Take9 campaign, offers virtual training sessions to equip participants with effective communication techniques, policy writing know-how, and access to one-on-one advocacy coaching. As digital threats multiply, Cooper argues that community storytelling and grassroots engagement are essential tools for prompting government action and ensuring critical local services are protected.


A reset on information sharing
A reset on information sharing episode artwork
10/23/2025

Kevin Greene, chief cybersecurity technologist for the public sector at BeyondTrust, joins Greg to unpack the fallout from the recent lapse of the CISA information sharing bill and what it means for both public and private sector cyber defenses. The conversation dives into how the threat landscape has shifted since the bill’s original passage, the limitations of relying solely on indicators of compromise, and the need for more proactive, behavior-based analytics. Kevin shares insights on identity management—including the challenges of both human and machine identities—and emphasizes that meaningful information sharing must be modernized to stay relevant.


Rethinking resilience with WatchTowr CEO Benjamin Harris
Rethinking resilience with WatchTowr CEO Benjamin Harris episode artwork
10/16/2025

This episode of Safe Mode features a nuanced conversation with Ben Harris, CEO of Watchtower, who delves into the complexities of vulnerability management in today’s threat landscape. Harris discusses why traditional patching is no longer a guarantee of security, revealing how sophisticated attackers are staying persistent even after organizations update and remediate systems—particularly in the challenging context of edge devices and black-box appliances. Drawing on real-world research and recent incidents involving vendors like Oracle, Cisco, and Avanti, the interview highlights the urgent need for resilience, increased transparency from companies, and a cultural shift toward proactive detection.


What's it like to go through the FedRAMP process?
What's it like to go through the FedRAMP process? episode artwork
10/09/2025

This week on Safe Mode, we talk with Scott Montgomery, VP of Federal at Island, about the realities of achieving FedRAMP authorization. Scott demystifies the often daunting FedRAMP process, shares lessons learned from real-world experience, and reveals the biggest pitfalls organizations face. From data sensitivity requirements to the growing importance of automation in security compliance, this episode is essential listening for anyone navigating federal cloud standards or considering a move into the government tech space. In our reporter chat, Greg talks with Matt Kapko about a whirlwind week around Clop's targeting of Oracle.