Cybersecurity Awesomeness Podcast podcast artwork

PODCAST · technology

Cybersecurity Awesomeness Podcast

The Cybersecurity Awesomeness Podcast from Enterprise Management Asscoaites (EMA) features cybersecurity experts Chris Steffen and Ken Buckler discussing critical cybersecurity issues. They cover everything from the challenges of certificate management and the cyber workforce talent shortage to deep. Available on all major platforms, this podcast offers credible, well-regarded insights into today's top security topics.

Publisher-supplied feed metadata · PodParley refreshed Jun 12, 2026 · Source feed

  1. 161

    Cybersecurity Awesomeness Podcast - Episode 167

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen is joined by Alex Salazar, founder and CEO of Arcade.dev, to explore the critical intersection of Artificial Intelligence, security, and agentic workflows. As AI transitions from a passive search tool to active "agents" capable of executing real-world tasks—such as modifying code, managing workflows, or handling data—traditional security paradigms are severely tested.Salazar emphasizes a vital distinction: model guardrails (teaching an AI "character" and ethics) are not enough, just as raising a well-behaved child doesn't mean handing them the keys to a bank account. True security requires robust governance, delegated authority, and runtime permissions. Rather than giving autonomous agents direct, unmitigated access to systems, Salazar advocates for deterministic, runtime security layers that evaluate every requested action before execution. Ultimately, the guests agree that while agentic AI introduces novel risks, the industry will adapt through better authorization frameworks, much like previous shifts to cloud and virtualization.

  2. 160

    Cybersecurity Awesomeness Podcast - Episode 166

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen tackles the growing enterprise challenge of "Token Sprawl"—an unintended consequence of rapid, unmonitored AI adoption. As organizations integrate AI agents into development, security operations, and routine tasks, many are suffering from severe "sticker shock" as unmanaged consumption of AI tokens leads to ballooning, unpredictable costs.Steffen draws parallels between today's token sprawl and the early, unoptimized days of cloud computing, noting that the issue isn't necessarily the pricing of tokens themselves, but the lack of governance. He explores how this creates friction between technical teams—who prioritize productivity over cost—and finance teams, who require budget predictability. The episode emphasizes that solving this requires more than just budget caps; it demands AI optimization. By selecting the right model for specific workloads—matching tasks to specialized AI strengths—and implementing stricter internal discipline, organizations can move from wasteful AI consumption to high-value, sustainable innovation.

  3. 159

    Cybersecurity Awesomeness Podcast - Episode 165

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen welcomes Saqib Ahmad from Gigamon to discuss the pressing necessity of Post-Quantum Cryptography (PQC) readiness. While quantum computing may seem distant, the hosts highlight the immediate and severe threat of "Harvest Now, Decrypt Later" attacks. Adversaries are actively exfiltrating encrypted data today, betting on the future capability of quantum computers to break standard algorithms like RSA and ECC.The conversation emphasizes that quantum vulnerability is a unique business risk, particularly for sectors handling long-term sensitive data such as government, healthcare, and intellectual property. Saqib underscores that successful migration to quantum-safe environments begins with network visibility—organizations cannot protect what they cannot see. He advocates for a strategic roadmap centered on asset discovery, data classification, and above all, crypto-agility. By maintaining the flexibility to swap out cryptographic standards as threats evolve, organizations can better insulate themselves against the looming quantum landscape, regardless of when "Q-Day" finally arrives.

  4. 158

    Cybersecurity Awesomeness Podcast - Episode 164

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen shifts to a solo format, addressing a pervasive fear dominating the industry: that Artificial Intelligence is destined to eliminate IT and cybersecurity jobs. Steffen challenges this "fear narrative," arguing that history shows technological shifts—from virtualization to cloud computing—consistently drive job growth and evolution rather than total displacement.Citing projections from the World Economic Forum, Steffen emphasizes that while AI will displace certain roles, it will simultaneously create significantly more new positions. He explains that AI acts as an augmentative tool, handling high-volume, menial tasks while leaving critical judgment, ethics, and triage to human professionals. Specifically, within cybersecurity, the demand for human expertise in signal-to-noise analysis, application security, and offensive validation is surging. Steffen concludes that success lies in adaptation; professionals should embrace AI as the next essential technical skill, treating it as an evolution of their toolkit rather than an existential threat to their livelihood.

  5. 157

    Cybersecurity Awesomeness Podcast - Episode 163

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and co-host Ken Buckler are joined by Simon Pamplin, CTO of Certes AI, to demystify the urgent threat of quantum computing. The conversation pivots away from the "mythical" future of quantum and focuses on the pressing reality of "Harvest Now, Decrypt Later" attacks, where adversaries exfiltrate encrypted data today with the intent to monetize it once quantum-enabled decryption becomes viable.Pamplin challenges the industry’s tendency to frame quantum risk solely as a network security issue, arguing instead that it is a critical business risk that carries profound legal and reputational consequences. The hosts and Pamplin explore the transition to lattice-based post-quantum cryptography (PQC) and the vital importance of robust key management. As the consensus on "Q-Day"—the point at which current encryption is rendered obsolete—accelerates toward the 2029–2030 timeframe, the episode serves as a vital call to action: prioritizing data-centric security hygiene is no longer optional for modern enterprises.

  6. 156

    Cybersecurity Awesomeness Podcast - Episode 162

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore a pressing security shift: adversaries are increasingly bypassing traditional credential theft to exploit the AI systems already embedded within corporate environments. The hosts discuss how "agentic" AI solutions often operate with overprivileged non-human identities, granting bots excessive access to data and infrastructure that far exceeds their functional requirements.This resurgence of "standing access" for machine accounts—a vulnerability CISOs thought they had mitigated—is being exacerbated by the rapid, near-universal adoption of AI development tools. Using real-world examples, ranging from inadvertent AI-generated discounts to the complex liability of autonomous vehicles, Chris and Ken illustrate the risks of prompt injection and data poisoning. The episode serves as a critical call to action for security teams: to treat AI agents with the same rigorous identity management and just-in-time provisioning standards historically reserved for human users before these misconfigurations lead to massive data exfiltration.

  7. 155

    Cybersecurity Awesomeness Podcast - Episode 161

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the often-misunderstood world of mainframe computing. Despite the pervasive narrative that mainframes are "antiquated" technology, the hosts argue that they remain the gold standard for availability, integrity, and resilience in high-stakes environments like banking, healthcare, and government.The discussion clears up common misconceptions, noting that modern mainframes are not just running legacy code like COBOL, but are fully capable of integrating with modern development tools and languages. Steffen and Buckler highlight that while the cloud offers flexibility, it lacks the sheer stability and performance consistency of the mainframe. For security professionals, the episode serves as a powerful reminder that "older" doesn't mean "insecure." In many cases, these systems provide a level of physical and logical isolation that modern, network-dependent architectures struggle to match. Ultimately, the hosts invite listeners to rethink the mainframe's role in the modern stack, proving it remains the undisputed champion of mission-critical compute.

  8. 154

    Cybersecurity Awesomeness Podcast - Episode 160

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler discuss transformative announcements from the Microsoft Build Conference 2026. The central focus is Microsoft’s shift toward ARM-based architecture in partnership with NVIDIA, exemplified by the new RTX Spark superchip. This development marks a pivotal transition: moving personal AI agents from cloud-reliant models to high-performance, local desktop environments.The hosts argue that this architectural evolution is a "security-first" milestone, allowing for local AI compute that significantly reduces privacy risks, data leakage, and the need for cloud-based credit systems. Beyond personal privacy, the discussion highlights the environmental benefits of distributed computing, noting that local processing mitigates the massive energy and land demands of hyperscale data centers. Steffen and Buckler conclude that the rapid democratization of AI is occurring faster than expected, signaling a new era where powerful, secure AI agents function as teammates rather than mere tools, fundamentally reshaping the future of personal computing.

  9. 153

    Cybersecurity Awesomeness Podcast - Episode 159

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler revisit a foundational IT principle: the Single Point of Failure (SPOF). Using the mantra "two is one, and one is none," the hosts explore why modern organizations often overlook critical dependencies that, if compromised, can bring down entire systems.The discussion traverses the spectrum from analog to digital, using the infamous train failures at Denver International Airport (DIA) as a prime example of a catastrophic physical SPOF that leaves thousands of travelers stranded. On the technical side, the hosts contrast fragile, linear network designs with the resilient, "spider-web" architecture of the modern internet and the hierarchical, distributed nature of the Domain Name System (DNS).Ultimately, Chris and Ken emphasize that while total redundancy is often cost-prohibitive, effective risk management requires identifying your most critical assets and building deliberate, tiered resilience—ensuring that when a failure inevitably occurs, the entire system doesn't collapse.

  10. 152

    Cybersecurity Awesomeness Podcast - Episode 158

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler shift focus from software to the often-overlooked realm of hardware security. The conversation centers on a recent Government Accountability Office (GAO) report detailing federal efforts to identify and remove telecommunications and surveillance equipment containing intentional backdoors and vulnerabilities linked to foreign actors—specifically from the People's Republic of China.The hosts emphasize that hardware integrity is a critical national security concern, not just an enterprise compliance hurdle. While they caution listeners against panic-buying new routers, they highlight the inherent risks of using "end-of-life" hardware that no longer receives security patches. Ken and Chris advocate for rigorous asset inventories and proactive replacement cycles, noting that even "legendary" workhorses like the classic WRT54G eventually reach the end of their secure lifecycle. Ultimately, the episode serves as a vital reminder: security requires vigilance at every layer of the stack, starting with the physical devices on your network.

  11. 151

    Cybersecurity Awesomeness Podcast - Episode 157

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler dissect Google’s recent discovery of the first clearly documented AI-assisted zero-day exploit. A threat actor utilized a Large Language Model (LLM) to develop a Python script designed to bypass two-factor authentication (2FA) on a widely used open-source system administration tool.The hosts highlight the "smoking guns" that betrayed the AI’s involvement: an uncharacteristic abundance of educational docstrings, specific Python formatting typical of LLM training data, and a telltale hallucinated CVSS score. While this signals a productivity boost for adversaries, Chris and Ken offer a witty yet grounded take: AI doesn’t instantly transform a novice into a "development wizard." The technology often mirrors the operator’s technical gaps, leading to documented code that is "ripe for the picking" by defenders. Ultimately, the duo emphasizes that while the toolkit has shifted, the solution remains anchored in fundamental cyber hygiene—rigorous patching, skeptical link-clicking, and a granular understanding of network dependencies.

  12. 150

    Cybersecurity Awesomeness Podcast - Episode 156

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler tackle the controversial intersection of digital privacy and state legislation. The discussion centers on Utah’s recent mandate requiring adult content providers to verify ages even when users are behind a VPN. This creates a technical "catch-22," forcing providers to either implement invasive identity checks or block privacy-enhancing tools entirely—a move the hosts argue is both technically infeasible and a threat to legitimate encryption use cases.The conversation extends to California’s 2027 law, which aims to push age verification onto operating system providers. Chris and Ken break down the "whack-a-mole" reality of tracking rotating IP blocks and the inevitable collision with international privacy regulations. They warn that these laws, often drafted by "tech-illiterate" legislators, risk pushing states into a digital "stone age."Ultimately, the hosts call on security professionals to advocate for privacy and offer their technical expertise to policymakers to prevent the enactment of unenforceable, privacy-destroying mandates.

  13. 149

    Cybersecurity Awesomeness Podcast - Episode 155

    In this special "Star Wars Day" edition of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler bridge the gap between sci-fi fantasy and modern security awareness. Utilizing the legendary franchise as a backdrop, the hosts deconstruct the glaring cybersecurity failures of the Galactic Empire to provide actionable lessons for today’s information security professionals.The discussion highlights a total lack of port security and network authentication, famously exploited by R2-D2 to gain administrative control over complex systems through simple physical links.Chris and Ken move into data integrity and insider threats, citing the deletion of the planet Kamino from the Jedi archives as a failure that underscores the critical need for file integrity monitoring and immutable backups. Finally, the duo examines the success of social engineering and "tailgating" throughout the series, drawing parallels to real-world threats like dressing as maintenance staff or carrying large boxes to bypass physical security checkpoints. By analyzing these galactic blunders, the episode reminds listeners that foundational cyber hygiene remains the ultimate defense against the "Dark Side."

  14. 148

    Cybersecurity Awesomeness Podcast - Episode 154

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the radical evolution of exploit triage following the RSAC 2026 conference. They highlight Anthropic’s "Mythos," a sophisticated red-teaming AI capable of autonomously discovering and chaining vulnerabilities without human oversight. Unlike traditional hacking methods that rely on static kits, modern AI toolkits can scan massive IP ranges for every vulnerability in history—essentially automating the "needle in a haystack" search for attackers. This shift is particularly dangerous for legacy environments—essentially creating "Terminator" moments for infrastructure—where Windows XP embedded is still found in modern EV chargers.Citing Shodan statistics, the hosts reveal the alarming presence of public-facing legacy systems: approximately 5,000 instances of Windows Vista/Server 2008, 2,000 Windows Server 2003 systems, and 4 public Windows XP servers running IIS. Steffen and Buckler conclude that we have entered an "AI arms race" where automated adversaries outpace manual defenses, making continuous scanning and robust cyber hygiene vital for survival.

  15. 147

    Cybersecurity Awesomeness Podcast - Episode 153

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler dive into the FCC’s 2026 ban on foreign-made routers and the growing national security risks lurking in consumer hardware. The hosts break down how Russian intelligence (GRU) is currently weaponizing unpatched home routers to execute DNS hijacking. By silently altering DNS settings, attackers can monitor your traffic or redirect you to spoofed websites to harvest banking and social media credentials.The discussion highlights that cybersecurity hygiene isn't just for "high-value targets." Even if you aren't guarding state secrets, opportunistic threat actors use these vulnerabilities for high-volume ransomware and blackmail schemes. To combat this, the hosts advocate for:-- Firmware vigilance: Updating router software and changing default passwords immediately.-- DNS Sovereignty: Manually configuring devices to use secure public providers like Cloudflare (1.1.1.1), Google (8.8.8.8), or Quad9 (9.9.9.9).Ultimately, this episode serves as a candid reminder: your "toy" hardware is a gateway, and it’s time to lock the door.

  16. 146

    Cybersecurity Awesomeness Podcast - Episode 152

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore Google’s recent quantum computing milestone, which significantly accelerates the timeline for "Q-Day." Google’s research suggests that the physical qubit requirement to crack a Bitcoin signature could be slashed from millions to just 500,000, with scalable systems potentially arriving by 2029. While the hosts clarify that today’s blockchain remains secure for now, the announcement underscores an urgent need for organizations to adopt Post-Quantum Cryptography (PQC).The discussion highlights how traditional computing is hitting physical barriers, making quantum specialized power the next logical step for high-intensity tasks. Beyond security risks, Steffen and Buckler discuss the "Star Trek-esque" benefits of quantum, including near-instant DNA sequencing for personalized medicine and the potential for zero-latency deep-space communication via quantum entanglement. Ultimately, the episode serves as a crucial call to action: PQC is no longer a distant science project but a looming requirement. Security professionals must educate themselves and demand quantum-readiness strategies from their vendors to ensure long-term data protection.

  17. 145

    Cybersecurity Awesomeness Podcast - Episode 151

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler offer a comprehensive recap of RSAC 2026, cutting  through the noise of 40,000 attendees to deliver critical takeaways from the industry’s "Super Bowl." While AI dominated nearly 80% of vendor booths, the hosts differentiate between "marketecture" and meaningful innovation. They emphasize that deploying agentic AI without robust Data Security Posture Management (DSPM) is a recipe for unmanaged data sprawl and "Shadow AI" risks, where sensitive proprietary information is accidentally leaked into public models.A significant portion of the discussion focuses on the maturation of identity management, noting a shift toward granular guardrails for AI agents to prevent overprivileged access. The duo also debunks the myth of AI as a headcount replacement for SOC analysts, highlighting its lack of "tribal knowledge" and innovative problem-solving. Beyond the AI hype, the conversation touches on the urgency of Post-Quantum Cryptography (PQC) and the evolving role of the CISO—transitioning from a "head nerd" to a strategic risk manager under new regulatory mandates. Ultimately, the episode serves as a reminder that foundational data governance remains the true anchor in a high-velocity threat landscape.

  18. 144

    Cybersecurity Awesomeness Podcast - Episode 150

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler prepare for the 2026 RSAC in San Francisco. Dubbed the "Super Bowl" of security, the event expects over 45,000 attendees and 600 vendors at the Moscone Center. Chris, managing a schedule of nearly 40 meetings, joins Ken to navigate the overwhelming noise of the show floor.The duo identifies Agentic AI and autonomous solutions as the dominant—yet potentially distracting—themes of the year. They caution against the "silver bullet" mentality, urging leaders to focus on securing AI agents against hallucinations and IP leaks rather than viewing them as total replacements for human staff. Beyond the AI hype, they highlight the critical arrival of "Q-Day" and the necessity of Post-Quantum Cryptography (PQC) readiness. The hosts encourage listeners to visit the Innovation Sandbox and Early Stage Expo for emerging tech while maintaining a steadfast commitment to foundational cyber hygiene. Ultimately, they embrace the conference theme, "The Power of Community," emphasizing that face-to-face networking remains the industry’s most valuable asset.

  19. 143

    Cybersecurity Awesomeness Podcast - Episode 149

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler prepare for the RSA Conference (RSAC), often described as the "Super Bowl" of cybersecurity by talking about the EMA Vendor Vision report. To help attendees navigate the overwhelming presence of over 600 exhibitors, the hosts break down EMA’s "Vendor Vision" report, which spotlights ten essential innovators. The discussion covers a broad technological spectrum, ranging from Straker’s cutting-edge adversarial AI in the Early Stage Expo to Sky High Security’s leadership in Data Security Posture Management (DSPM).Key highlights include AWS’s unified cloud security suite, Acalvio's deception technologies, F5’s API-driven AI protections, and the evolving identity landscape spearheaded by Yubico and SailPoint. The hosts also examine the maturation of Privileged Access Management through Delinea and Keeper Security, alongside Proofpoint’s focus on human-centric vulnerabilities and business email compromise. By filtering the noise of the Moscone Center, this episode provides a strategic roadmap for identifying the technical trends that will define the industry for the coming months. It serves as an indispensable guide for anyone looking to maximize their impact and insight during the conference.

  20. 142

    Cybersecurity Awesomeness Podcast - Episode 148

    In this episode of the Cybersecurity Awesomeness Podcast, hosts Chris Steffen and Ken Buckler explore the shifting priorities of Chief Information Security Officers (CISOs) as they navigate the transition from rapid AI adoption to a more disciplined, risk-aware strategy. As of 2026, the "deploy first, secure later" mentality is facing a reckoning, particularly regarding autonomous or agentic AI. The discussion highlights alarming real-world incidents—such as an AI agent deleting a production database during a code freeze and another wiping a Meta executive's inbox despite repeated "stop" commands—to illustrate the volatility of unmanaged AI.The conversation characterizes AI as a paradox: a tool with "graduate-level intelligence but the gullibility of an eight-year-old." The hosts argue that marginal productivity gains cannot justify catastrophic risks like data destruction or unauthorized access. Ultimately, the episode emphasizes that AI should not be pursued at the expense of foundational security pillars like identity management. CISOs are urged to apply existing human-centric guardrails to AI agents, ensuring these tools remain business enablers rather than liabilities.

  21. 141

    Cybersecurity Awesomeness Podcast - Episode 147

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler explore the looming reality of quantum computing and its inevitable collision with modern encryption standards. The discussion centers on Q-Day—the theoretical point at which quantum processors reach approximately 100,000 qubits, making current AES-256 encryption vulnerable to near-instantaneous decryption. The hosts emphasize the Harvest Now, Decrypt Later strategy, where adversaries stockpile encrypted sensitive data today in anticipation of tomorrow’s quantum capabilities.While acknowledging the Quantum Dividend—the massive potential for breakthroughs in medicine and engineering—the conversation serves as an urgent call to action for security professionals. Organizations must move beyond traditional binary mindsets to adopt quantum-resistant algorithms, as the transition is a multi-year endeavor rather than an overnight fix. Even for those skeptical of the timeline, the push toward quantum readiness represents a necessary evolution in global security standards. Ultimately, the episode underscores that being quantum ready is no longer a futuristic luxury but a foundational requirement for protecting long-term intellectual property and state secrets in an increasingly complex digital landscape.

  22. 140

    Cybersecurity Awesomeness Podcast - Episode 146

    In this "Cybersecurity 101" episode, Chris Steffen and Ken Buckler demystify quantum computing and its looming implications for modern encryption. Ken contrasts traditional binary bits—static ones and zeros—with qubits, using the analogy of a spinning coin to represent the multiple simultaneous states quantum computers can process. This immense power allows quantum systems to solve complex problems in milliseconds that would take traditional computers lifetimes. However, significant physical hurdles remain, such as the requirement for near-absolute zero cooling environments.The most pressing security concern discussed is "Q-Day" and the "Harvest Now, Decrypt Later" strategy. Malicious actors are currently stockpiling encrypted government secrets, financial records, and intellectual property, waiting for quantum technology to become viable enough to shatter current encryption standards. The hosts emphasize the urgent necessity of Post-Quantum Cryptography (PQC) to protect long-term sensitive data. Chris concludes by noting his upcoming research report on PQC, highlighting how organizations must prepare for a universe where current digital safeguards may soon become obsolete.

  23. 139

    Cybersecurity Awesomeness Podcast - Episode 145

    In this episode, Chris Steffen and Ken Buckler dissect the federal government’s evolving—and somewhat strained—approach to cybersecurity. A major catalyst for the discussion is the recent withdrawal of agencies like CISA, the FBI, and the NSA from the RSAC conference following former CISA head Jen Easterly’s appointment there. While potentially a move toward fiscal responsibility—given the $5,000 per-person total cost of the event—the hosts warn this retreat could stifle vital public-private partnerships and recruitment efforts.The discussion also tackles systemic talent issues within the military. Experts often face a "promotion trap," being moved into management just as they peak technically, while private-sector salaries can reach 10x their military pay. To counter this, units like the Maryland Air National Guard are pivoting from traditional aircraft to dedicated cyber missions. Ultimately, the hosts argue that the government risks falling behind on emerging technology adoption by absenting itself from the industry's largest collaborative forums. This "cyber-isolationism" could leave federal agencies ill-equipped to handle rapidly evolving threats.

  24. 138

    Cybersecurity Awesomeness Podcast - Episode 144

    In this episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen and Simon Wijckmans, CEO of C-side, discuss the critical visibility gap in client-side security. While organizations invest heavily in infrastructure and server-side protection, the user's browser remains a largely unmonitored attack vector. Historically, solutions like Content Security Policies and JavaScript agents have proven brittle or easily bypassed by sophisticated scripts that can hide from crawlers or override security hooks.The conversation highlights a major shift driven by PCI DSS 4.0, which now mandates the monitoring and authorization of client-side scripts. Simon explains that modern browser changes regarding third-party cookies finally support more effective proxy-based approaches. This allows security teams to inspect and block malicious third-party scripts before they reach the end user, preventing data exfiltration like credit card skimming. The hosts urge security professionals to move beyond "head in the sand" tactics, emphasizing that robust browser security is now a regulatory and operational necessity for total asset protection.

  25. 137

    Cybersecurity Awesomeness Podcast - Episode 143

    In this episode of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler discuss a humorous yet sobering encounter with a failed AI-driven scam. Ken recently received a common "advance fee" investment scam email, but with a unique twist: the attacker accidentally sent the Python source code instead of the intended message. The code contained telltale signs of AI generation, including placeholder instructions like "replace this with the actual import" for the Gemini SDK.The hosts explain that while this specific attacker failed "successfully," the incident provides concrete proof that scammers are using generative AI to replace the broken English of past scams with highly literate, convincing phishing lures. This shift makes it increasingly difficult for users to spot fraud through traditional "tells." Chris emphasizes that manual defense is no longer sufficient against automated bot armies. To stay protected, organizations must integrate AI-driven security tools to match the speed and sophistication of these evolving threats. As Ken notes, the future of these attacks will likely escalate into deepfakes and multimodal social engineering.

  26. 136

    Cybersecurity Awesomeness Podcast - Episode 142

    In this episode, Chris Steffen and Ken Buckler are joined by Jim LaRoe, CEO of Symphion, to discuss the often-ignored threat of printer and IoT security. Jim reveals a startling set of "winning lottery numbers": printers account for 20% of network endpoints, yet 99% remain unprotected. With 67% of organizations reporting a printer-related security incident last year, these devices serve as a critical yet vulnerable vector for lateral movement and credential harvesting.Jim explains this widespread neglect through his "Five O's," citing the lack of a formal Owner and their Origin as business equipment rather than IT endpoints. Because printers process highly sensitive data and frequently lack unified management platforms, they offer a 360-degree risk landscape for cybercriminals. The conversation emphasizes that "locking the front door" by declaring a dedicated security owner and integrating print fleets into a unified security strategy is essential. Symphion provides a turnkey solution to bridge this visibility gap, ensuring these "graveyard endpoints" are hardened, monitored, and securely managed.

  27. 135

    Cybersecurity Awesomeness Podcast - Episode 141

    In this episode, Chris Steffen and Ken Buckler discuss the alarming security and privacy implications of the "Internet of All Things." The hosts highlight how manufacturers are connecting everything—from AI-powered treadmills to smart toothbrushes—often without considering the associated risks.A primary concern is the shift toward recurring revenue models, where companies gate-keep hardware features behind monthly subscriptions. Beyond the cost, Ken warns of the physical security threats posed by Bluetooth-enabled appliances. He explains how broadcasting devices can inadvertently signal a resident's presence or daily habits to malicious actors in close proximity.The discussion also addresses the myth of data anonymization, noting that aggregated consumer data is easily de-anonymized and sold to third parties. The hosts conclude that when a device offers "value-add" connectivity, the consumer’s personal data is often the actual product. They urge listeners to adopt a critical mindset regarding the risk-to-benefit ratio of every connected device they bring into their homes.

  28. 134

    Cybersecurity Awesomeness Podcast - Episode 140

    Chris Steffen and Ken Buckler from EMA discuss privacy concerns around generative AI.

  29. 133

    Cybersecurity Awesomeness Podcast - Episode 139

    Chris Steffen and Ken Buckler from EMA present their 2026 Cybersecurity Predictions.

  30. 132

    Cybersecurity Awesomeness Podcast - Episode 138

    Chris Steffen and Ken Buckler from EMA discuss API security.

  31. 131

    Cybersecurity Awesomeness Podcast - Episode 137

    Chris Steffen and Ken Buckler from EMA discuss attacks via SEO outreach on news sites.

  32. 130

    Cybersecurity Awesomeness Podcast - Episode 136

    Chris Steffen and Ken Buckler from EMA discuss what they are thankful for in cybersecurity.

  33. 129

    Cybersecurity Awesomeness Podcast - Episode 135

    Chris Steffen and Ken Buckler from EMA discuss the Cloudflare outage and what availability means in the technology space.

  34. 128

    Cybersecurity Awesomeness Podcast - Episode 134

    Chris Steffen and Ken Buckler from EMA discuss securing AI LLMs.

  35. 127

    Cybersecurity Awesomeness Podcast - Episode 133

    Chris Steffen and Ken Buckler from EMA discuss trends in network security.

  36. 126

    Cybersecurity Awesomeness Podcast - Episode 132

    Chris Steffen and Ken Buckler from EMA discuss phishing and deep fakes for Cybersecurity Awareness Month.

  37. 125

    Cybersecurity Awesomeness Podcast - Episode 131

    Chris Steffen and Ken Buckler from EMA discuss insider threats for Cybersecurity Awareness Month.

  38. 124

    Cybersecurity Awesomeness Podcast - Episode 130

    Chris Steffen and Ken Buckler from EMA discuss mobile device protection and public Wi-Fi concerns for Cybersecurity Awareness Month.

  39. 123

    Cybersecurity Awesomeness Podcast - Episode 129

    Chris Steffen and Ken Buckler from EMA discuss data security and software updates for Cybersecurity Awareness Month.

  40. 122

    Cybersecurity Awesomeness Podcast - Episode 128

    Chris Steffen and Ken Buckler from EMA discuss MFA and password managers for Cybersecurity Awareness Month.

  41. 121

    Cybersecurity Awesomeness Podcast - Episode 127

    Chris Steffen and Ken Buckler from EMA discuss the government's investment in developing the cybersecurity workforce.

  42. 120

    Cybersecurity Awesomeness Podcast - Episode 126

    Chris Steffen and Ken Buckler from EMA discuss the increase in nation state attacks on small and medium sized businesses.

  43. 119

    Cybersecurity Awesomeness Podcast - Episode 125

    Chris Steffen and Ken Buckler from EMA present Cybersecurity 101: Ransomware.

  44. 118

    Cybersecurity Awesomeness Podcast - Episode 124

    Chris Steffen and Ken Buckler from EMA discuss  the largest ever recorded DDoS attack, and the efforts used to stop it.

  45. 117

    Cybersecurity Awesomeness Podcast - Episode 123

    Chris Steffen and Ken Buckler from EMA discuss cybersecurity's role at the start the new school year.

  46. 116

    Cybersecurity Awesomeness Podcast - Episode 122

    Chris Steffen and Ken Buckler from EMA discuss proactive vs. reactive cybersecurity. 

  47. 115

    Cybersecurity Awesomeness Podcast - Episode 121

    Chris Steffen and Ken Buckler from EMA present a Black Hat 2025 Wrap-Up and discuss AI security.

  48. 114

    Cybersecurity Awesomeness Podcast - Episode 120

    Chris Steffen and Ken Buckler from EMA discuss data governance for agentic AI.

  49. 113

    Cybersecurity Awesomeness Podcast - Episode 119

    Chris Steffen and Ken Buckler from EMA present a preview of Black Hat 2025.

  50. 112

    Cybersecurity Awesomeness Podcast - Episode 118

    Chris Steffen and Ken Buckler from EMA discuss the latest Zero Day attack on SharePoint.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

The Cybersecurity Awesomeness Podcast from Enterprise Management Asscoaites (EMA) features cybersecurity experts Chris Steffen and Ken Buckler discussing critical cybersecurity issues. They cover everything from the challenges of certificate management and the cyber workforce talent shortage to deep. Available on all major platforms, this podcast offers credible, well-regarded insights into today's top security topics.

HOSTED BY

Enterprise Management Associates

CATEGORIES

Frequently Asked Questions

How many episodes does Cybersecurity Awesomeness Podcast have?

Cybersecurity Awesomeness Podcast currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Cybersecurity Awesomeness Podcast about?

The Cybersecurity Awesomeness Podcast from Enterprise Management Asscoaites (EMA) features cybersecurity experts Chris Steffen and Ken Buckler discussing critical cybersecurity issues. They cover everything from the challenges of certificate management and the cyber workforce talent shortage to...

How often does Cybersecurity Awesomeness Podcast release new episodes?

Cybersecurity Awesomeness Podcast has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Cybersecurity Awesomeness Podcast?

You can listen to Cybersecurity Awesomeness Podcast on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Cybersecurity Awesomeness Podcast?

Cybersecurity Awesomeness Podcast is created and hosted by Enterprise Management Associates.
URL copied to clipboard!