Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
History
TV & Film
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts126/v4/15/d7/c7/15d7c74b-bb3f-7514-c917-84742b7da8ec/mza_18017058307658190158.jpg/600x600bb.jpg
Safe Mode Podcast
Safe Mode Podcast
116 episodes
1 week ago
In our final episode of 2025, Dave Lewis, global advisory CISO for 1Password, joins Greg Otto to unpack the “access‑trust gap”: the growing mismatch between what employees (and tools like AI assistants) can access at work and what security teams can actually see, verify, and control. Dav explains how this gap shows up in everyday ways—logins that bypass intended controls, personal devices used for work, and teams adopting apps or AI tools faster than IT can govern them—and why that combination creates quiet but serious risk. You’ll hear practical advice on narrowing the gap with stronger identity checks, smarter device trust, cleaner SaaS governance, and simple guardrails for safe AI use that don’t crush productivity.
Show more...
News
RSS
All content for Safe Mode Podcast is the property of Safe Mode Podcast and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
In our final episode of 2025, Dave Lewis, global advisory CISO for 1Password, joins Greg Otto to unpack the “access‑trust gap”: the growing mismatch between what employees (and tools like AI assistants) can access at work and what security teams can actually see, verify, and control. Dav explains how this gap shows up in everyday ways—logins that bypass intended controls, personal devices used for work, and teams adopting apps or AI tools faster than IT can govern them—and why that combination creates quiet but serious risk. You’ll hear practical advice on narrowing the gap with stronger identity checks, smarter device trust, cleaner SaaS governance, and simple guardrails for safe AI use that don’t crush productivity.
Show more...
News
Episodes (20/116)
Safe Mode Podcast
The Access‑Trust Gap: Why security can’t see what work depends on
In our final episode of 2025, Dave Lewis, global advisory CISO for 1Password, joins Greg Otto to unpack the “access‑trust gap”: the growing mismatch between what employees (and tools like AI assistants) can access at work and what security teams can actually see, verify, and control. Dav explains how this gap shows up in everyday ways—logins that bypass intended controls, personal devices used for work, and teams adopting apps or AI tools faster than IT can govern them—and why that combination creates quiet but serious risk. You’ll hear practical advice on narrowing the gap with stronger identity checks, smarter device trust, cleaner SaaS governance, and simple guardrails for safe AI use that don’t crush productivity.
Show more...
1 week ago
32 minutes 35 seconds

Safe Mode Podcast
How AI has complicated enterprise mobile security
In this episode of Safe Mode, Jim Dolce, CEO of Lookout, reveals that 40% of phishing attacks now target mobile devices—yet CISOs are drastically underspending on mobile security compared to email protection. Jim demonstrates how AI-powered attacks have become devastatingly effective, showing how his team created a voice-cloning impersonation attack in 15 minutes that fooled over half their employees into surrendering credentials, bypassing even multi-factor authentication. He explains why credential theft is now the #1 attack vector, costing $4-5 million per breach, and how modern smishing attacks use scraped social media data to craft hyper-personalized messages that are nearly impossible for humans to detect. Jim's urgent message: enterprises must protect mobile devices with the same rigor as email systems, using AI-powered defenses to combat AI-powered threats.
Show more...
2 weeks ago
38 minutes 49 seconds

Safe Mode Podcast
Breaking down the latest era of Chinese cyberespionage with Booz Allen's Nate Beach-Westmoreland
In this episode, we sit down with Nate Beach-Westmoreland, Head of Strategic Cyber Threat Intelligence at Booz Allen, to explore the evolving sophistication of Chinese cyber operations and their implications for U.S. national security. Our guest breaks down how the PRC leverages trusted-relationship abuse, network edge exploitation, and AI-powered influence campaigns to infiltrate critical infrastructure, evade detection, and operate below escalation thresholds that limit allied responses. From supply chain compromises to the weaponization of artificial intelligence in information warfare, this conversation reveals the strategic chess game playing out in cyberspace—and what the U.S. and its allies must do to regain the advantage.
Show more...
3 weeks ago
29 minutes 37 seconds

Safe Mode Podcast
How Visa's CISO turns a 'paranoid and pessimisitic mindset' into positive security outcomes
Visa CISO Subra Kumaraswamy joins Safe Mode to discuss the global scale and complexities of cybersecurity at Visa, from managing a billion transactions daily to maintaining a resilient, “paranoid” defensive posture. Subra reveals how his team blends innovation, threat intelligence, and layered security architectures—not just to protect Visa, but to uplift the wider payment ecosystem—including strategies for defending against supply chain attacks, leveraging AI, and preparing for deepfakes and post-quantum computing. The episode provides a look behind the scenes at how Visa is working to ensure trust and reliability in payments for its global network of cardholders, partners, and merchants.
Show more...
1 month ago
46 minutes 21 seconds

Safe Mode Podcast
What security teams should do to prepare for the quantum computing future
Rebecca Krauthamer, CEO of QSecure, joins Safe Mode to delve into the rapidly shifting landscape of quantum computing and cybersecurity. The conversation covers the latest government and industry responses to the quantum threat, the urgency of adopting post-quantum encryption, and practical metrics for agencies and organizations. Listen in as the complexities and urgency of preparing for “Q-Day” are unpacked, offering key insights for policy makers, technologists, and anyone concerned with data security’s future.
Show more...
1 month ago
40 minutes 26 seconds

Safe Mode Podcast
How MSP's are dealing CISA changes
On this week’s Safe Mode, Greg welcomes Jason Pufahl, VP of Security Services at Vancord. Jason shares deep insights into the evolving managed security landscape, focusing on challenges faced by small and mid-sized businesses and the practical fundamentals they need for strong cybersecurity. He also discusses the evolving role of CISA and the importance of making threat intelligence and resources broadly accessible to help organizations of all sizes strengthen their cybersecurity posture.
Show more...
1 month ago
32 minutes 43 seconds

Safe Mode Podcast
Mobilizing Main Street: Inside the Cyber Civic Engagement Program
In this episode of Safe Mode, Betsy Cooper, founding director of the Aspen Institute’s Policy Academy, details a new initiative designed to mobilize ordinary citizens as cybersecurity policy advocates. The Cyber Civic Engagement program, supported by Craig Newmark Philanthropies’ Take9 campaign, offers virtual training sessions to equip participants with effective communication techniques, policy writing know-how, and access to one-on-one advocacy coaching. As digital threats multiply, Cooper argues that community storytelling and grassroots engagement are essential tools for prompting government action and ensuring critical local services are protected.
Show more...
2 months ago
30 minutes 1 second

Safe Mode Podcast
A reset on information sharing
Kevin Greene, chief cybersecurity technologist for the public sector at BeyondTrust, joins Greg to unpack the fallout from the recent lapse of the CISA information sharing bill and what it means for both public and private sector cyber defenses. The conversation dives into how the threat landscape has shifted since the bill’s original passage, the limitations of relying solely on indicators of compromise, and the need for more proactive, behavior-based analytics. Kevin shares insights on identity management—including the challenges of both human and machine identities—and emphasizes that meaningful information sharing must be modernized to stay relevant.
Show more...
2 months ago
35 minutes 26 seconds

Safe Mode Podcast
Rethinking resilience with WatchTowr CEO Benjamin Harris
This episode of Safe Mode features a nuanced conversation with Ben Harris, CEO of Watchtower, who delves into the complexities of vulnerability management in today’s threat landscape. Harris discusses why traditional patching is no longer a guarantee of security, revealing how sophisticated attackers are staying persistent even after organizations update and remediate systems—particularly in the challenging context of edge devices and black-box appliances. Drawing on real-world research and recent incidents involving vendors like Oracle, Cisco, and Avanti, the interview highlights the urgent need for resilience, increased transparency from companies, and a cultural shift toward proactive detection.
Show more...
2 months ago
35 minutes 32 seconds

Safe Mode Podcast
What's it like to go through the FedRAMP process?
This week on Safe Mode, we talk with Scott Montgomery, VP of Federal at Island, about the realities of achieving FedRAMP authorization. Scott demystifies the often daunting FedRAMP process, shares lessons learned from real-world experience, and reveals the biggest pitfalls organizations face. From data sensitivity requirements to the growing importance of automation in security compliance, this episode is essential listening for anyone navigating federal cloud standards or considering a move into the government tech space. In our reporter chat, Greg talks with Matt Kapko about a whirlwind week around Clop's targeting of Oracle.
Show more...
2 months ago
31 minutes 7 seconds

Safe Mode Podcast
Andesite's Brian Carbaugh on how lessons from the CIA can power an AI-powered SOC
In this week's episode of Safe Mode, Greg Otto talks with Brian Carbaugh, CEO of Andesite, who reveals how lessons learned in the CIA are transforming Andesite’s unique, human-first approach to AI-driven cybersecurity. Carbaugh shares behind-the-scenes stories about building a “bionic SOC,” where cutting-edge artificial intelligence works seamlessly with analysts, amplifying their skills, streamlining investigations, and making security operations not just more efficient but genuinely exciting. In our reporter chat, Greg and Matt Kapko dive into a week's worth of critical vulnerabilities and government emergency directives, and how enterprises have responded in kind.
Show more...
2 months ago
27 minutes 6 seconds

Safe Mode Podcast
Censys’ Silas Cutler on how adversaries chain vulns together for big attacks
In this episode of Safe Mode, Greg talks with Silas Cutler, principal security researcher at Census, how ransomware attackers chain together overlooked vulnerabilities, especially in platforms like SharePoint, and why patch fatigue leaves defenders at risk. Silas breaks down advanced ways criminals maintain access even after patches, and explains what makes government and critical sectors prime targets. We discuss the real challenges of incident response, threat intelligence, and preventing long-term damage—especially in complex cloud and hybrid environments. In our reporter chat, Greg talks with Tim Starks about two marquee stories this week: a look at how the government information sharing law renewal has sputtered, and a new China-linked espionage campaign has researchers sounding the alarms. https://cyberscoop.com/cyber-threat-information-law-hurtles-toward-expiration-with-poor-prospects-for-renewal/
Show more...
3 months ago
26 minutes 55 seconds

Safe Mode Podcast
Veracode’s Chris Wysopal on the security issues with AI code development
On this episode of Safe Mode, we’re joined by a renowned cybersecurity expert and CyberScoop 50 winner, Veracode co-founder and CTO Chris Wysopal, to discuss the fast-evolving landscape of AI-assisted software development. Chris shares insights from a recent study examining over 100 large language models and their tendency to introduce security vulnerabilities in generated code. The conversation delves into why a staggering 45% of AI-generated code samples contained vulnerabilities and why improvements in AI reasoning haven’t translated to more secure outputs. Chris emphasizes the critical need for enhanced security testing and better quality training data, discussing both the challenges and opportunities ahead as AI adoption accelerates. Tune in for a thoughtful exploration of the intersection between AI, secure coding, and what the future holds for developers and enterprises alike. In our reporter chat, Greg talks with Derek Johnson about work that OpenAI and Anthropic have done with the U.S. and U.K. government to secure their models.
Show more...
3 months ago
32 minutes 14 seconds

Safe Mode Podcast
Phosphorus’ Sonu Shankar on IoT Vulnerabilities and Salt Typhoon Tactics
In this episode, Greg Otto talks with Sonu Shankar, President at Phosphorus, to discuss the unique security challenges facing today’s rapidly expanding Internet of Things landscape, where traditional endpoint protections are ineffective. The episode explores how everyday devices with default passwords and outdated firmware open organizations up to significant risk. Shankar highlights the tactics of groups like Salt Typhoon, who exploit these weak spots to infiltrate and persist within networks. The conversation underscores the pressing need for deeper asset inventory and active discovery in critical environments. In our reporter chat, Greg talks with Matt Kapko about a supply-chain attack on npm that turned out to be pretty close to a false alarm.
Show more...
3 months ago
23 minutes 50 seconds

Safe Mode Podcast
Halcyon’s Cynthia Kaiser on the state of ransomware
In this episode, Greg Otto talks with Cynthia Kaiser Sr. Vice President of Halcyon’s Ransomware Research Center, discussing the latest ransomware operations and exploring the latest shifts in the cyber threat landscape. Greg and Cynthia discuss the rise of new groups like DragonForce, SafePay, and Fog, and the decline of once-dominant names such as LockBit and BlackBasta. They also discuss unique tactics and tools employed by emerging players, discuss the impact of law enforcement and internal group dynamics, and examine why certain industries are now prime targets. Learn how attackers choose their victims, the early warning signs organizations should watch for, and the most frequent pitfalls in ransomware defense. In our reporter chat, Greg talks with Matt Kapko about the deep drive into an accused ransomware affiliate that has been given a long leash by law enforcement while he awaits trial.
Show more...
3 months ago
29 minutes 13 seconds

Safe Mode Podcast
What happens if CISA 2015 lapses?
In this episode of Safe Mode, host Greg Otto talks with Tim Starks about what would happen if the nation’s information sharing law – known as CISA 2015 – expires at the end of September. In our interview segment, Greg talks with Kevin Hanes, CEO of Reveal Security, exploring the critical and often overlooked world of machine identity security. From the blind spots in privileged access management that focus too heavily on human users while machines hold increasingly sensitive roles, to the operational challenges of securing identities in cloud-native, containerized, and AI-powered environments, Kevin shares practical insights on scaling visibility and maintaining accountability across fragmented teams.
Show more...
4 months ago
24 minutes 41 seconds

Safe Mode Podcast
Dave DeWalt on how to get a board to buy in on cybersecurity
In this episode of Safe Mode, host Greg Otto talks with Dave DeWalt, founder and CEO of NightDragon, about advising boards and portfolio companies on making cyber a first-order business issue, not an afterthought. We’ll explore how emerging technologies and remote work reshape risk profiles, when a CISO belongs in the board conversation—or even in a board seat—and what training and metrics actually move the needle across non-technical teams. We’ll also unpack how to motivate leaders outside of IT to own cyber risk, the structures that drive enterprise-wide accountability, and what information boards should demand to ensure the right risks are being prioritized. From calibrating cyber risk appetite in shifting threat environments to staying ahead of evolving regulations across sectors like power and aviation, we’ll get practical on governance and disclosure. In our reporter chat, Greg talks with Derek Johnson about the president’s possible push to end mail-in voting, and why the efforts are dead on arrival.
Show more...
4 months ago
31 minutes 23 seconds

Safe Mode Podcast
Are enterprises having the right AI security conversations?
In this episode of Safe Mode, host Greg Otto sits down with Chris Sestito, CEO of HiddenLayer Technologies, to discuss the evolving landscape of AI security and where current protection strategies are falling short. Sestito shares insights on how leading enterprises are rethinking their approach to AI asset protection, reveals real-world examples where traditional security measures failed against AI-specific threats, and explains the unique vulnerabilities that conventional cybersecurity tools struggle to address. The conversation explores the tension between rapid AI innovation and regulatory frameworks, with Sestito offering his perspective on what smarter, more adaptive AI regulation should look like and how policymakers can balance innovation with robust security protections. Don't miss this deep dive into the future of AI security, insider threats in AI-driven workplaces, and Sestito's top recommendations for government regulators crafting new AI security laws In our reporter chat, Greg talks with Tim Starks about what the federal government is doing to meet the demands put forth in President Trump’s cybersecurity executive order.
Show more...
4 months ago
47 minutes 23 seconds

Safe Mode Podcast
What is CISA’s focus moving forward
On this episode of Safe Mode, Greg Otto sits with two CISA leaders, Chris Butera, Acting Executive Assistant Director for CISA’s Cybersecurity Division, and Bob Costello, CIO of CISA, at the 2025 Black Hat USA Conference to discuss numerous different topics: the recent Microsoft Sharepoint vulnerability, the upcoming CIRCIA rulemaking, the future of the JCDC, state and local cyber grants, and the emphasis they are placing to strengthening public-private partnerships. In our reporter chat, Greg talks with Matt Kapko about what they both heard during their conversations at the Black Hat conference.
Show more...
4 months ago
36 minutes 38 seconds

Safe Mode Podcast
Inside the AI Action Plan with Dreadnode’s Daria Bahrami
On this episode of Safe Mode, host Greg Otto sits down with Daria Bahrami, Head of Policy at Dreadnode, for an in-depth exploration of the new AI Action Plan and its sweeping implications for critical infrastructure security. From the technical hurdles in securing vital systems to the growing need for “secure-by-design” technology standards, Daria breaks down what’s at stake as artificial intelligence becomes both a linchpin and a potential liability in our national cyber defenses. In our reporter chat, Greg talks with Tim Starks about the motion on Capitol Hill to confirm CISA Director nominee Sean Plankey.
Show more...
5 months ago
33 minutes 24 seconds

Safe Mode Podcast
In our final episode of 2025, Dave Lewis, global advisory CISO for 1Password, joins Greg Otto to unpack the “access‑trust gap”: the growing mismatch between what employees (and tools like AI assistants) can access at work and what security teams can actually see, verify, and control. Dav explains how this gap shows up in everyday ways—logins that bypass intended controls, personal devices used for work, and teams adopting apps or AI tools faster than IT can govern them—and why that combination creates quiet but serious risk. You’ll hear practical advice on narrowing the gap with stronger identity checks, smarter device trust, cleaner SaaS governance, and simple guardrails for safe AI use that don’t crush productivity.