
Hosted by Infosec
Learn how to break into cybersecurity, build new skills and move up the career ladder. Each week on the Cyber Work Podcast, host Chris Sienko sits down with thought leaders from Carbon Black, IBM, CompTIA and others to discuss the latest cybersecurity workforce trends.
392 episodes · publishes weekly · latest 2025-08-18 · ~35 min/episode
Rank
#1583
Substance
69.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#1583 of 6182
Substance
Top 26%
outscores 74% of the index
Cyber Work ranks #1583 on The B2B Podcast Index with a substance score of 69.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and specificity & evidence. Jim Broome is a genuine long-tenured practitioner - ISS X-Force, DirectDefense CTO, hands-on OT and physical red team work, US Olympic team security testing - not a thought-leader type. He speaks from real operational experience at scale, though he is a regional/mid-tier name rather than a globally recognised figure.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains genuine practitioner insights - red team readiness criteria, the MIT-grad clustering exploit, AI/SOAR noise discussion - but is heavily diluted by biographical anecdotes, team name-drops, disaster-bingo banter, and generic career advice. Useful content is present but sparse relative to 57 minutes.
“a pin test is what we now call a red team. Uh, so it was a $25,000 no questions asked, no scope asked. We will just tell you when we're gonna start. And that's it.”
“I had a lot of big multinational companies that, for whatever reason, I got really lucky at the time. MIT was graduating a lot of Compsci guys and early InfoSec, uh, builders that they all read from the same manual. So, uh, the running gag was, uh, I would call the company up, find out where their Boston office was. Get the IP range for that and I would attack that office 'cause I knew exactly the blueprint on how to break in.”
There are a few genuinely interesting observations - the MIT-grad monoculture as an attack surface, OT security's false sense of air-gap safety, hiring from event planning and education for soft skills. But the bulk of the framing (punch-in-the-mouth metaphor, red teams not being pass/fail, soft skills matter most) is well-worn security-podcast wisdom.
“OT still lives in this, um, utopia that no one's ever gonna get access to the tools. And so really the, the only thing preventing, uh, bad things from happening is just getting access to this one app or this one piece of hardware”
“the foundational, um. Skillset that we're looking for, which is actually soft skills. They already know how to communicate. So, you know, one of the biggest things we've, uh, been very successful with is people looking at career change early in their career”
Jim Broome is a genuine long-tenured practitioner - ISS X-Force, DirectDefense CTO, hands-on OT and physical red team work, US Olympic team security testing - not a thought-leader type. He speaks from real operational experience at scale, though he is a regional/mid-tier name rather than a globally recognised figure.
“I was one of the very first companies. It was literally us and like at stake, uh, you know, we were the only two real big companies on, the. Private sector doing this type of work”
“we've actually supported them through multiple, um, you know, uh, years of testing, so I can, you know, we can go back and definitely have beer conversations over the first Beijing in Olympics all the way to”
The episode is above average on specificity: named clients (Symantec 1996-97, Wizards of the Coast 2002, Chrysler), concrete numbers ($25k no-scope tests, 185,000 Chrysler employees, $8M RSA token proposal, 4.4 brute-force attempts per hour, domain admin in 10 minutes). The MIT-company anecdote loses credit for keeping names vague, and several security observations remain hand-wavy.
“did one of the very first pen tests for Semantic way back in the day. so like 1996 and 97”
“we got really lucky at the time. MIT was graduating a lot of Compsci guys”
The host asks a few substantively useful questions (red team readiness metrics, phishing vs. red teaming distinction) but predominantly runs a warm PR-style chat. He telegraphs answers before the guest finishes, never pushes back on any claims, and burns significant time on generic openers (childhood computers, what are you reading) and banter about disaster bingo and ants.
“can you talk about what metrics companies should use when determining the appropriate time to carry out red teaming? Like what, what should they already have done and put in place before they even think about getting you and your team on the phone?”
“I'm not gonna ask you to name or shame any companies that, uh, were especially unprepared”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/cyber-work" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/cyber-work/badge.svg" alt="Ranked #113 on The B2B Podcast Index" width="360" height="136" />
</a>Track Cyber Work's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.