
Hosted by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam.
363 episodes · publishes weekly · latest 2026-06-29 · ~32 min/episode
Rank
#3119
Substance
61.4
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#3119 of 6182
Substance
Top 50%
outscores 50% of the index
CISSP Cyber Training Podcast ranks #3119 on The B2B Podcast Index with a substance score of 61.4 out of 100, scored across 5 recent episodes. It scores highest on insight density and specificity & evidence. The episode delivers solid mid-tier substance with a real case study (Zapier/Token Security breach) that illustrates concrete cloud security failures and a four-phase TPRM framework applicable to practitioners. However, it relies heavily on explaining obvious concepts (least privilege, vendor inventory tracking, OAuth tokens) and includes repetitive reinforcement that dilutes insight density. The Zapier breakdown is valuable but relatively surface-level; deeper technical or strategic nuance is limited.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers solid mid-tier substance with a real case study (Zapier/Token Security breach) that illustrates concrete cloud security failures and a four-phase TPRM framework applicable to practitioners. However, it relies heavily on explaining obvious concepts (least privilege, vendor inventory tracking, OAuth tokens) and includes repetitive reinforcement that dilutes insight density. The Zapier breakdown is valuable but relatively surface-level; deeper technical or strategic nuance is limited.
“56 of companies that are using agentic AI in some form do not have a process to track SaaS to SaaS connections”
“you need to build your vendor inventory. Now, this is a list of every SaaS app, API connection, integration. I mean every single one”
The Zapier breach case is genuinely recent and illustrative, but the underlying frameworks - tiered vendor classification, SOC 2 checks, quarterly audits, policy ownership - are standard TPRM playbook material. The host repackages canonical best practices (least privilege, breach notification timelines, vendor contracts) without fresh counterintuitive angles. The 4-week action plan is practical but not novel for anyone familiar with GRC processes.
“Know your vendor inventory. Then then we're gonna get into phase two, which is due diligence and assessment. Phase three is ongoing monitoring and governance, and phase four is your policy ownership”
“Do they have SOC 2 type 2, ISO 27,000 one, or are they equivalent?”
This is a solo host episode with no guest interview. Sean Gerber appears to be a CISSP trainer/podcaster rather than a practitioner currently operating at scale or with deep vendor risk management experience in a large enterprise. The episode lacks the credibility boost that comes from interviewing a CISO who recently managed a major breach response or a procurement lead running a sophisticated TPRM program.
“I'm your host of the Action Packing Format Podcast”
“I've sat on the other side of that table as a CISO trying to explain to the board why a vendor we trusted is just cost us a six-figure incident response”
The Zapier/Token Security case provides concrete attack chain detail (Lambda exploitation, IAM misconfigurations, NPM token extraction, 1,100+ files accessed). The stat on 56% of orgs lacking SaaS connection tracking is specific. However, beyond the breach narrative, specificity drops: TPRM framework lacks named examples of vendor policies, no real metrics on remediation timelines, no dollar figures on breach impact costs, and generic references to SOC 2 and ISO 27001 without context on what gap remediation actually looks like.
“Researchers from Token Security recently demonstrated a five-steck step attack chain that nearly compromised Zapier”
“they found this role and it had additional uh allowances that it basically provided”
The host delivers a structured, organized monologue with logical progression from case study to framework, but there is no back-and-forth dialogue, no genuine pushback on claims, and no challenge of assumptions. The rhetorical devices (Hulk Hogan analogy, 'never drink water downstream' metaphor) feel like filler rather than incisive questioning. A solo format limits the opportunity for the type of sharp Q&A and follow-up that distinguishes conversational craft; the episode reads more as a lecture than a podcast dialogue.
“I can say I'm six foot five and I'm built like a rock or like Hulk Hogan. Right, God rest his soul. But are you right?”
“you never drink water downstream. Yeah, because all kinds of critters do things upstream that you do not want”
First period on the Index - history builds from here.
10 scored on substance · 60 tracked in total.
CCT 359: ShinyHunters vs. Oracle - Supply Chain Risk Every CISSP Must Know
2026-06-29 · 43 min
CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know
2026-06-22 · 43 min
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP
2026-06-15 · 32 min
CCT 356: Supply Chain Attacks Are Exploding in 2026 - Here's What the NCSC Wants You to Do
2026-06-08 · 42 min
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes
2026-06-04 · 24 min
CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY
2026-06-01 · 37 min
CCT 353: AI Agent Governance Essentials - CISSP Practice Questions
2026-05-28 · 28 min
CCT 352: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY
2026-05-25 · 40 min
CCT351: BitLocker Bypass Reality Check (YellowKey) and CISSP Practice Questions
2026-05-21 · 24 min
CCT 350: Investigation Types Made Simple - CISSP Training (Replay)
2026-05-18 · 45 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/cissp-cyber-training-podcast-cissp-training-program" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/cissp-cyber-training-podcast-cissp-training-program/badge.svg" alt="Ranked #183 on The B2B Podcast Index" width="360" height="136" />
</a>Track CISSP Cyber Training Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
Secure & Simple
Dejan Kosutic
The Backup Wrap-Up
W. Curtis Preston (Mr. Backup)
Cyber Security Business
K logix
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
Disambiguation
Michael Fauscette
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson