Cybersecurity Threat Modeling: A Navy Officer’s Playbook for When Patching Fails episode artwork

EPISODE · Jun 16, 2026 · 1H 11M

Cybersecurity Threat Modeling: A Navy Officer’s Playbook for When Patching Fails

from Full Metal Packet

How should security teams manage vulnerabilities when patching is impossible or incomplete? Ben Lipczynski explains contextual threat modeling, legacy-system risk, and defense in depth.Security leaders will learn how to identify critical systems, reduce hundreds of scan findings to meaningful actions, and prepare around operational consequences.Ben is the Director of Security and Regulatory Services at Origina and a former British Royal Navy officer with 12 years operating nuclear submarines and global networks. He brings an operator-level perspective on what separates a contained incident from a months-long operational nightmare.He explains:◼ Why siloed teams and poor system knowledge cause more breaches than sophisticated attacks ever do◼ Why upgrading to the latest version often introduces more vulnerabilities than it removes◼ How 700 scan findings came down to 20 real actions after proper contextual analysis◼ Why the CVE volume problem is about to get significantly worse and what to do about it◼ Why defense in depth, not patching, is the only strategy that holds up when an attacker gets insideTime Stamps:(0:00) Introduction(0:53) What corporate security teams get wrong vs. the military(2:22) The submarine mindset: 90% training, 10% operations(4:48) Operational clarity in the military: everyone knows the mission and their role(6:59) Military structure vs. corporate agility — opposites or the same need?(10:38) Why Ben left the Navy for cybersecurity(14:32) "Take a marching pace" — thinking before acting in incident response(18:09) The iPad water treatment plant story — OT connectivity creep in the real world(25:30) The myth of N-minus-one: legacy doesn't mean insecure(28:10) Open source dependency risk — 60% of vulnerabilities aren't in the core code(31:01) Slop squatting: attackers pre-registering AI-hallucinated package names(33:00) What to do when you can't patch — contextual risk-based defense in depth(36:26) The patch validation problem — exploits now arrive within hours of a CVE(44:00) Fully patched, still taken down — architecture beats updates(51:26) Log4J case study: why deleting the library beat the patch cycle(55:23) Practical advice for security teams managing legacy systems(1:02:22) The CVE volume crisis — is the current patching model even tenable?(1:07:21) Bold prediction: CVE text itself will become an attack vector for AI agentsConnect with the speakers ⬇️:Ben Lipchinski: https://www.linkedin.com/in/benlipczynskisecurity/Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/Powered by Control D

Episode metadata supplied by the publisher feed · Published Jun 16, 2026

Embed this episode

Ready to play

Cybersecurity Threat Modeling: A Navy Officer’s Playbook for When Patching Fails

0:00 1:11:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Beauty Boss Banter Natalie Sue Welcome to Beauty Boss Banter, where glam meets grit and business meets beauty! Join me, Natalie Sue, your go-to beauty boss, as we dive into the world of beauty, trends, and entrepreneurship. Get ready for candid conversations with industry experts, behind-the-scenes glimpses into the beauty biz, and empowering stories that will inspire the beauty boss within you. Tune in weekly for your dose of beauty wisdom, entrepreneurial insights, and the secrets to success in the ever-evolving world of beauty. Unleash your inner beauty boss with Beauty Boss Banter - because being fabulous is a full-time job!" 🎙️💄✨ #BeautyBossBanter #GlamMeetsGrit #BusinessAndBeauty" Explicit Satanic Panic Show with Kwame Wahkan (The Satanic Panic Show) Kwame Wahkan/Famcast Media Podcast Network Metalhead, multi-Instrumentalist, blogger, and grassroots activist. These are my opinions on news, social issues, religion, video games, metal, and punk. This is a free speech zone. If you have an opinion, you're more than welcome to express yourself without fear of getting censored or blocked. WARNING: I can be politically incorrect at times. "I'm not happy about it, but I'd rather feel like shit than be full of shit. And if I offend you, oh I'm sorry, maybe you need to be offended. But here's my apology and one more thing. Fuck you." -Suicidal Tendencies Explicit Crush Anxiety Dr. Aly Wood The Crush Anxiety Podcast is the ultimate destination for high achievers battling anxiety, offering a powerful mix of science-backed strategies and insights from the top thought leaders in the field.  Join Dr. Aly Wood (psychiatrist and life coach) as we dive into practical strategies for tackling stress, mastering your mindset, embracing discomfort, and optimizing your time.  Get ready to crush anxiety, reach new heights, and unlock your full potential! Explicit

Frequently Asked Questions

How long is this episode of Full Metal Packet?

This episode is 1 hour and 11 minutes long.

When was this Full Metal Packet episode published?

This episode was published on June 16, 2026.

Can I download this Full Metal Packet episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!