The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
#3121CISSP Cyber Training Podcast61.4 / 100Get badge
← The Index
CISSP Cyber Training Podcast artwork
Engineering & DevToolsNEW this period

CISSP Cyber Training Podcast

Hosted by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

Listed under Education › Courses

★4.6on Apple Podcasts · 5 recent reviews

Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam.

369 episodes · publishes weekly · latest 2026-08-10 · ~32 min/episode

Rank

#3121

Substance

61.4

/ 100

Breakdown

Scored 2026-07
Updated monthly

Engineering & DevTools rank

#183 of 289

Best B2B Engineering & DevTools Podcasts →

Across the index

#3121 of 6181

Substance

Top 50%

outscores 50% of the index

Why it scores where it does

CISSP Cyber Training Podcast ranks #3121 on The B2B Podcast Index with a substance score of 61.4 out of 100, scored across 5 recent episodes. It scores highest on insight density and specificity & evidence. The episode delivers solid mid-tier substance with a real case study (Zapier/Token Security breach) that illustrates concrete cloud security failures and a four-phase TPRM framework applicable to practitioners. However, it relies heavily on explaining obvious concepts (least privilege, vendor inventory tracking, OAuth tokens) and includes repetitive reinforcement that dilutes insight density. The Zapier breakdown is valuable but relatively surface-level; deeper technical or strategic nuance is limited.

The five-dimension breakdown

Averaged across 5 recently scored episodes, with cited evidence.

Insight Density

15.6 / 20

The episode delivers solid mid-tier substance with a real case study (Zapier/Token Security breach) that illustrates concrete cloud security failures and a four-phase TPRM framework applicable to practitioners. However, it relies heavily on explaining obvious concepts (least privilege, vendor inventory tracking, OAuth tokens) and includes repetitive reinforcement that dilutes insight density. The Zapier breakdown is valuable but relatively surface-level; deeper technical or strategic nuance is limited.

“56 of companies that are using agentic AI in some form do not have a process to track SaaS to SaaS connections”

“you need to build your vendor inventory. Now, this is a list of every SaaS app, API connection, integration. I mean every single one”

Originality

13.2 / 20

The Zapier breach case is genuinely recent and illustrative, but the underlying frameworks - tiered vendor classification, SOC 2 checks, quarterly audits, policy ownership - are standard TPRM playbook material. The host repackages canonical best practices (least privilege, breach notification timelines, vendor contracts) without fresh counterintuitive angles. The 4-week action plan is practical but not novel for anyone familiar with GRC processes.

“Know your vendor inventory. Then then we're gonna get into phase two, which is due diligence and assessment. Phase three is ongoing monitoring and governance, and phase four is your policy ownership”

“Do they have SOC 2 type 2, ISO 27,000 one, or are they equivalent?”

Guest Caliber

6.8 / 20

This is a solo host episode with no guest interview. Sean Gerber appears to be a CISSP trainer/podcaster rather than a practitioner currently operating at scale or with deep vendor risk management experience in a large enterprise. The episode lacks the credibility boost that comes from interviewing a CISO who recently managed a major breach response or a procurement lead running a sophisticated TPRM program.

“I'm your host of the Action Packing Format Podcast”

“I've sat on the other side of that table as a CISO trying to explain to the board why a vendor we trusted is just cost us a six-figure incident response”

Specificity & Evidence

14.8 / 20

The Zapier/Token Security case provides concrete attack chain detail (Lambda exploitation, IAM misconfigurations, NPM token extraction, 1,100+ files accessed). The stat on 56% of orgs lacking SaaS connection tracking is specific. However, beyond the breach narrative, specificity drops: TPRM framework lacks named examples of vendor policies, no real metrics on remediation timelines, no dollar figures on breach impact costs, and generic references to SOC 2 and ISO 27001 without context on what gap remediation actually looks like.

“Researchers from Token Security recently demonstrated a five-steck step attack chain that nearly compromised Zapier”

“they found this role and it had additional uh allowances that it basically provided”

Conversational Craft

11.0 / 20

The host delivers a structured, organized monologue with logical progression from case study to framework, but there is no back-and-forth dialogue, no genuine pushback on claims, and no challenge of assumptions. The rhetorical devices (Hulk Hogan analogy, 'never drink water downstream' metaphor) feel like filler rather than incisive questioning. A solo format limits the opportunity for the type of sharp Q&A and follow-up that distinguishes conversational craft; the episode reads more as a lecture than a podcast dialogue.

“I can say I'm six foot five and I'm built like a rock or like Hulk Hogan. Right, God rest his soul. But are you right?”

“you never drink water downstream. Yeah, because all kinds of critters do things upstream that you do not want”

Standout episodes

  • CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

    2026-06-04

    69
  • CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know

    2026-06-22

    68
  • CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP

    2026-06-15

    59

Rank over time

First period on the Index - history builds from here.

Episodes

10 scored on substance · 66 tracked in total.

  • CCT 359: ShinyHunters vs. Oracle - Supply Chain Risk Every CISSP Must Know

    2026-06-29 · 43 min

    52 / 100
  • CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know

    2026-06-22 · 43 min

    68 / 100
  • CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP

    2026-06-15 · 32 min

    59 / 100
  • CCT 356: Supply Chain Attacks Are Exploding in 2026 - Here's What the NCSC Wants You to Do

    2026-06-08 · 42 min

    59 / 100
  • CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

    2026-06-04 · 24 min

    69 / 100
  • CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

    2026-06-01 · 37 min

    59 / 100
  • CCT 353: AI Agent Governance Essentials - CISSP Practice Questions

    2026-05-28 · 28 min

    73 / 100
  • CCT 352: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY

    2026-05-25 · 40 min

    55 / 100
  • CCT351: BitLocker Bypass Reality Check (YellowKey) and CISSP Practice Questions

    2026-05-21 · 24 min

    53 / 100
  • CCT 350: Investigation Types Made Simple - CISSP Training (Replay)

    2026-05-18 · 45 min

    57 / 100

What listeners say on Apple Podcasts

★★★★★
Awesome Stuff
This podcast was essential in helping me pass the CISSP exam Shon is entertaining and explains everything so well. Thank you, Shon!

- AndrewCISSP

★★★★★
Significant resource to pass the CISSP
This podcast offers listeners the opportunity to test themselves on CISSP topics with multiple choice answers. Understanding all of the concepts is KEY to passing the test. This podcast was one of the resources I used to pass my test on the first time. Thank you Shon for sharing this valuable resource.

- Scott Jensen

Frequently asked

What is CISSP Cyber Training Podcast's substance score?
CISSP Cyber Training Podcast scores 61.4 out of 100 for substance and ranks #3121 on The B2B Podcast Index. That puts it ahead of 50% of the B2B podcasts we rank and #183 of 289 in Engineering & DevTools. The score reflects insight density, originality, guest caliber, specificity and conversational craft across recent episodes - not downloads.
Is CISSP Cyber Training Podcast worth listening to?
Yes - CISSP Cyber Training Podcast outscores 50% of the B2B engineering & devtools podcasts and shows we rank on substance, so a engineering & devtools operator is likely to come away with something useful.
Who hosts CISSP Cyber Training Podcast?
CISSP Cyber Training Podcast is hosted by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur.
How often does CISSP Cyber Training Podcast publish?
CISSP Cyber Training Podcast publishes weekly, has 369 episodes, released its most recent episode on 2026-08-10.
Which CISSP Cyber Training Podcast episode should I start with?
Our highest-scoring recent episode is "CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes" (69/100) - a good place to start.

Show off your #183 rank in Engineering & DevTools

Add this badge to your site - it links back here and updates automatically as you rank.

Ranked #183 on The B2B Podcast Index
Embed code
<a href="https://index.fame.so/show/cissp-cyber-training-podcast-cissp-training-program" target="_blank" rel="noopener">
  <img src="https://index.fame.so/badge/cissp-cyber-training-podcast-cissp-training-program/badge.svg" alt="Ranked #183 on The B2B Podcast Index" width="360" height="136" />
</a>
Markdown & other formats →

Track CISSP Cyber Training Podcast's rank

Get an email whenever this show moves up or down the Index. Monthly at most, no spam.

Listen / subscribe:WebsiteRSS

Frequently discusses

Companies, products and tools that come up most across this show's episodes.

CISSP Cyber Training · 10CSO Magazine · 3PyPI · 2AWS · 2Python · 2npm · 2BitLocker · 2ShinyHuntersOraclePeopleSoftSalesforceSnowflakeSolarWindsVerizonMythosGitHubOAuthESET

Guests who've appeared

Sean Gerbert

Topics this show covers

The themes that come up most across this show's episodes.

Chain of custody · 2OAuth tokens · 2Signal (encrypted messaging)Root Cause Analysis (RCA)Digital forensicsPhishing attacksstatic analysisMalicious QR codesForensic copyingCelebrite UFED mobile forensics toolAnomaly-based detectionSalesforceSnowflakeThird party risk managementSolarWindssupply chain attacksShinyHunters threat groupOracle PeopleSoft

More Engineering & DevTools podcasts

See all →
  • Ship It Weekly

    Teller's Tech - DevOps, SRE and Cloud Podcast

    85.6
  • Unsupervised Learning with Jacob Effron

    by Redpoint Ventures

    84.6
  • Podcast Archives

    Podcast Archives - Software Engineering Daily

    84.0
  • DevOps Daily with Fexingo

    Fexingo

    82.4
  • The Pragmatic Engineer

    Gergely Orosz

    82.2
  • The Engineering Leadership Podcast

    The Engineering Leadership Community (ELC)

    80.8

Similar shows

Podcasts that dig into the same topics.

  • Secure & Simple

    Dejan Kosutic

  • Cyber Work

    Infosec

  • Cyber Security Business

    K logix

    69.2
  • The Backup Wrap-Up

    W. Curtis Preston (Mr. Backup)

  • Trust Issues

    Bruno Lecoq

    78.2
  • Shielded

    PQShield

    73.4