The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Human-Centered Security
Human-Centered Security artwork

No Threat Intel Team? No Problem. Let’s Pretend You Do! with Mike Kosak

Human-Centered Security · 2025-08-25 · 50 min

0:00--:--

Key moments - from our scoring

Substance score

42 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality6 / 20
Guest Caliber12 / 20
Specificity & Evidence7 / 20
Conversational Craft9 / 20

Setting up a threat intelligence function doesn't require a large dedicated team - it starts with asking the right questions. Mike Kosak walks through a practical framework for establishing PIRs (Priority Intelligence Requirements) using a thought exercise that forces organizations to identify what they protect, what threat actors find valuable, and what tactics those actors employ. The conversation uses a concrete example: a fictional smartwatch and smart glasses company collecting audio, video, biometric data, and location information. This becomes the basis for understanding threat modeling using frameworks like STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) plus Privacy, which helps teams systematically identify attack vectors. Kosak emphasizes that PIRs operate at the organizational level and remain relatively static, whereas threat modeling zooms into specific products or systems. Critical to success is stakeholder engagement - talking to sales, marketing, security teams, and information officers to cast a wider net and avoid blind spots (as happened with the Target breach through an HVAC contractor). The intelligence cycle (planning, collection, analysis, production, dissemination) matters most in the production and dissemination phases, where analysis must be communicated clearly and actionably to drive decisions.

Key takeaways

  • →Priority Intelligence Requirements (PIRs) are foundational questions your organization must answer to protect itself, built by identifying what you protect, what threat actors want, their tactics and techniques, and what you need to know to defend against them.
  • →Threat modeling frameworks like STRIDE-P help product teams systematically identify attack vectors by diagramming systems, dependencies, and controls from an attacker's perspective.
  • →Stakeholder involvement across sales, marketing, security, and leadership is essential to avoid critical blind spots - what one team thinks is unimportant may be attractive to threat actors or enable supply chain attacks.
  • →The distinction between static, organization-wide PIRs and time-bounded Critical Intelligence Requirements (CIRs) allows threat intelligence to scale from foundational questions down to specific, temporary focuses like emerging CVEs.
  • →Communication and dissemination of intelligence is as critical as collection and analysis; intelligence locked away in a silo provides no value to the organization.

Guests

Mike Kosak

Topics in this episode

supply chain attacksPriority Intelligence Requirements (PIRs)STRIDE-P threat modeling frameworkCritical Intelligence Requirements (CIRs)Threat actor tactics, techniques, and procedures (TTPs)Target HVAC contractor breachAdam Szostak's threat modeling frameworkDissemination and communication of threat intelligenceStakeholder engagement in threat intelligenceSmart watches and smart glasses security modeling

Questions this episode answers

What's the difference between threat intelligence and just collecting security information?

Threat intelligence is information that has been analyzed to extract deeper meaning and patterns - 'rubbing some thinking on it,' as Kosak says. A collection of IP addresses is data; identifying who owns them, where they come from, and how they're used together becomes intelligence.

How do you start a threat intelligence program if you don't have a dedicated team?

Begin by identifying Priority Intelligence Requirements (PIRs) using a thought exercise: determine what your organization protects, what threat actors find valuable, which actors target you, and how they operate. Then iterate those questions across stakeholder groups to refine them before launching collection and analysis.

Why should threat intelligence teams talk to sales and marketing, not just security?

Different departments understand different threats and business priorities. Sales and marketing can reveal which threat actors find your organization or its connections valuable - like how Target was breached through an HVAC contractor - helping prevent blind spots.

What's the STRIDE-P threat modeling framework and why does it matter?

STRIDE-P (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege, and Privacy) is a structured framework that prompts teams to systematically consider attack vectors across all dimensions of a product or system, making threat analysis orders of magnitude more complete than ad-hoc approaches.

How do Priority Intelligence Requirements differ from Critical Intelligence Requirements?

PIRs are broad, static, organization-level questions meant to guide long-term threat intelligence strategy, while CIRs are narrowly focused, time-bounded requests (like responding to a new CVE) that typically expire after 30 days or when the specific threat passes.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode delivers a coherent introductory framework for threat intelligence - PIRs thought exercise, signal-vs-noise filtering, feeding data into SIEMs - but the density of non-obvious insights is low. Most of the runtime is spent on foundational definitions and social back-and-forth rather than hard-won practitioner knowledge a savvy operator couldn't find in a blog post.

intelligence is information that's been analyzed to glean another layer of meaning out of it
even just doing something as simple as, as the Threat intelligence team when that report comes in, doing a quick check to see, even see if we have the technology before it gets pushed out

Originality

6 / 20

The episode recycles well-established frameworks - the CIA intelligence cycle, STRIDE/STRIPED (credited to Microsoft), MITRE ATT&CK - without reframing or challenging them. The 'rub some thinking on it' line is colourful but not a novel idea, and analogies like painting the Golden Gate Bridge are well-worn.

my old boss in the government, the way he used to describe it was, you got to rub some thinking on it
it's like painting the Golden Gate bridge. Like as soon as you get done, you got to start back at the other end

Guest Caliber

12 / 20

Mike Kosak is a genuine practitioner - government intelligence deployments, senior principal analyst at LastPass - with credible real-world experience. The conversation does not fully extract the depth his background implies; anecdotes stay at illustrative rather than instructive level, and the LastPass breach context, which would be uniquely valuable, is barely touched.

on one of my deployments I was in a part of the organization, uh, that was called the analysis and production cell. And it was a constant point that our colonel used to drive home
we're part of uh, a, uh, password manager alliance, you know, and that sort of thing where we, you know, we talk to our, our peers

Specificity & Evidence

7 / 20

The episode names a handful of concrete tools and resources (MITRE ATT&CK, Feedly, Google Threat Intelligence, MSTIC, Feedly, LastPass Labs) and briefly cites the Target/HVAC breach. However, there are no real metrics, dollar figures, timelines, or detailed case studies; the primary worked example is a fictional smartwatch company constructed live on-air.

you could even just go to the mitre, ATT and CK page. Odds, uh, are they've ident. They've got a page on those threat actors
Google threat Intelligence is pushing a lot of stuff out. Mystic from Microsoft. You can find a lot of really, really good free reporting

Conversational Craft

9 / 20

The host shows genuine curiosity - spontaneously applying concepts (the Alice/AI-agent manipulation scenario, the UX-repository analogy) and asking clarifying follow-ups on metrics and accountability. However, she almost never challenges or stress-tests the guest's claims, frequently validates with 'yeah, absolutely,' and the self-quizzing segment, while charming, consumes time without advancing substance.

when you say false positives, do you mean maybe. Let me. I won't even try to inject what I think you mean. Can you just explain what you mean by false positives in this?
if I'm the owner of the business...who do you think is best suited to take on threat intelligence as part of their role?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B70%
  • Speaker A30%

Most-used words

threat86intelligence58information32organization25data23part18mike16important16pirs16security15start15becomes15back14team14folks12critical12

Episode notes

In this episode, Mike Kosak explains what threat intelligence really is (Mike’s former boss said you have to “rub some thinking on it.”), how to define priority intelligence requirements (PIRs), how to treat model, where to find threat intel, and how to keep in actionable with tight feedback loops - not panic. Key takeaways: Threat intel ≠ data. It’s analyzed info focused “ walls-out ” (what’s outside your org), then shared clearly so people can act. Start with PIRs. Ask: What are we protecting? What is most valuable to our company? What might threat actors want? How do they operate? What do we need to know to defend? Do this with a broad set of stakeholders, not just the security team. Communicate clearly and with context. Intelligence is only valuable if it’s shared in a way others can understand and act on. Avoid overwhelming people with raw data or inducing panic - provide actionable insights that are right-sized for the audience. Mike’s advice: “As a threat intelligence analyst, if you’re doing your job right, when somebody hears from you they know they need to act on it.

Full transcript

50 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome, everyone, to Human Centered Security. I am your host, Heidi Trost, and I'm with Mike Kosak. You may have listened to Mike's episode he was on with Jordan German. They were talking about UX and security. You know, where that overlap happens, where that magic happens. But Mike is on today, and, um, he is the senior principal intelligence analyst at LastPass, and he wrote a really interesting couple of articles on the LastPass blog, and one of them was setting up a threat intelligence program from scratch. And it was so fascinating to me that I asked him to come back on the podcast so he could talk a little bit about that. Um, and I already. I was so excited about this episode that I already named it, which I don't typically do, and I called it no Threat Intel Team. No problem. Let's pretend you do. So with that, let's kick it off. Thanks for joining, Mike.

Speaker B: Yeah, absolutely. Thanks for having me back, Heidi. I really enjoyed our last conversation, and we've been super excited about this one, too. So thanks again.

Speaker A: Awesome. M. Okay, so for folks who are unfamiliar with the term, what does threat intelligence mean?

Speaker B: Sure. Great place to start. So, you know, if we split it apart, if we think about threats, um, classically, that's sort of defined as a function of intent and capability of a threat actor. So, um, if somebody intends to do you harm, what are they trying to do and how good are they at it? And when you assess those two, then you kind of have a rough idea of what kind of threat they pose, how serious the threat they pose is. Intelligence, um, is really important as well to take a deeper look at, because that's where that often gets used almost interchangeably with information. Uh, and there's really an important difference. And that difference is intelligence is information that's been analyzed to glean another layer of meaning out of it. So it's one thing to just get, you know, a bunch of data, like here's. You know, here's a bunch of IP addresses, um, that may be associated with a threat actor. Intelligence comes from taking a look at that and identifying patterns around its usage. Where is it coming from? Who do we think this belongs to? So, my old boss in the government, the way he used to describe it was, you got to rub some thinking on it. So you take the. You take the information and then you rub some thinking on it. Now you've got some intelligence. Um, and that's really important. Um, so it's. And when we look at it big picture, the way, uh, I'll often describe it, too, is, um, Walls out versus walls in. So, you know, you've got your security operations teams that'll be looking at stuff that's going on inside your organization. Threat intelligence really should be focused on what's outside the organization so that you can report that back to your security operations team and they can prepare themselves.

Speaker A: It was almost like you prepared that answer, because that was so helpful. I love it. Okay, so I'm thinking like the outside in analogy, how as a threat intelligence person, your title is principal intelligence analyst. How do you work with other people at your organization?

Speaker B: So a lot of it, there's, there's a mix. Um, a lot of it's sort of automated, so, you know, collecting intelligence and, and then, you know, pushing it into the, to the right formats or, or feeds. So if you've got a sim or a source, something like that, you know, you've got that automated angle. Um, the other side of it that's really important too, is just talking to people. So that's, you know, and I think we touched on this a little bit in our previous podcast, but that's, that's something that's super important. That often doesn't happen with threat intelligence programs. They sort of get, or even if it's just a person who has this assigned as an other duty, uh, they kind of get stuck in a dark corner and they say, hey, go look for this stuff. And it's assumed that they're spooky and creepy and you just kind of leave them alone and they get the information for you and you say, hey, great, thanks. Uh, what's really important is interacting with everybody or as many different organizations.

Speaker A: Just to be real, Mike is in his basement right now.

Speaker B: I am literally in my basement. Yeah. So LastPass has in fact holed me up in my basement. Um, they know, they understand, but, uh, yeah, reaching out and talking with as many people as you can to, um, both sort of highlight what the threats are, get them to understand what threat intelligence is, because that's. And they can become your eyes and ears out there as well. Uh, so really it's as many people as you can interact with in your organization, the better.

Speaker A: Yeah. And in the last podcast, we talked a lot about how you communicate that. Communicating well, communicating concisely, not, um, you know, being careful about what you're saying and not inducing panic. Right. And, and giving people actionable things to do. So we might, maybe we'll get to that. But I just wanted to kind of like double click on that because I think the communication piece is often not talked about. And I really want folks to understand that this is something that you are advocating for. Yeah.

Speaker B: And when we think about threat intelligence, um, this goes back to CIA's old guidance and their publications. When they were first sort of formalizing a lot of their intelligence analysis programs with Sherman Kent, they came up with the intelligence intelligence cycle, which starts with, starts, uh, with planning, then it goes to collection, analysis, uh, production, and then dissemination. So it's, and it's just a constant wheel that goes around. Um, and so, you know, that's incorporating all of that into any threat intelligence program is really important. And you know, when we talk about that communication side of it, that's where that production and dissemination angle really comes in. So making sure that what you're doing, it's one thing just to collect information, but if you're just sitting on it, then it's not helping anybody. Um, I remember on one of my deployments I was in a part of the organization, uh, that was called the analysis and production cell. And it was a constant point that our colonel used to drive home was, hey, it's not just analysis, it's analysis and production. Like, it's great that you as the intelligence analyst know this, but if you're not telling other people about it, it's not helping anybody. And that's, that's really important to think about with the threat intelligence program too.

Speaker A: Well, not only telling them, but making sure that they understand and can do something about it. And do something about it. Right?

Speaker B: Yeah, absolutely.

Speaker A: All right, so let's dive a little bit deeper. You, in the article that I referenced, how to set up a Threat Intelligence Program from Scratch, you talk about priority intelligence requirements, or PIRs. Mhm. What are those?

Speaker B: Sure. So really, in sort of plain language, these are the questions that your organization needs to have answered in order to protect. Protect itself. That's really what it boils down to. And, and it's so critical to take the time it's foundational to any threat intelligence program to establish these pirs, because if you can articulate your question, then you can go out and find answers. But if you don't even know what questions you're trying to answer, it's just chaos. So can you give me some examples? Yeah, yeah. So, um, you know, and, and then I'll, I'll kind of, I'll, I'll blow it out a little bit from this. But, um, you know, so if, if you're, if you're in the technology sector like myself, so one of the first questions I would ask myself if I'M establishing PIRS is okay, what threat actors have historically or are currently targeting the technology sector. So you know, I need to understand that and then I would kind of take a few steps back from that. So once I understand who they are, how do they do this, what are their tactics, techniques and procedures? Where can I find this information? You kind of, you kind of drive out from there. Um, so you know, when, when I, when I talk about it, especially to new organizations who are sort of establishing this capability, there's a thought exercise that I talk people through and that I go through in that blog post as well, where it's, you know, the first. And again, sticking to really a plain language because you want to be able to scale this irrespective of the size of your organization. Um, what are you protecting? So that involves sitting down, you know, internally with, with your threat intelligence team or just your person. If it's just, um, what are you protecting? What does your company think is most valuable? And that could be intellectual property, that could be finances. All of these things are probably going to figure into it to some degree. But it really requires you to sit and think and cast a wide net about what's important to you because it's, you know, the, the first instinct is going to be probably whatever your main product is. Um, but there are other things too that you need to consider. Um, the second step is then thinking about it from the threat actors perspective. So what do you have that you may not even consider but that threat actors are interested in? So an example we often use is if you are a company who is supporting the critical infrastructure sectors, any of them. Um, and maybe you're just, you know, you just sort of think you're tangentially involved, you're providing some sort of software to them, but you're not really part of the critical infrastructure. Doesn't matter. That can be absolutely attractive to threat actors who are going to try and use that to get their foot in the door to the critical infrastructure sector. So you've, that's sort of the second part of the threat exercise is taking.

Speaker A: Isn't that what happened with the target breach? That happened.

Speaker B: Yes, you know, great example. Yeah. Through the H Vac contractor. Um, that's.

Speaker A: Yeah. I was going to say you could be like making sandwiches for. Yeah, it doesn't really matter what it is, it's just that connection.

Speaker B: Yeah, yeah, yeah. Taking a look at those business to business connections is really important too and can often get overlooked. Um, so once you kind of take that angle and think about it, from that perspective, then you start to think, uh, about who it's valuable to you think about how do they operate. Like I said, what are their. You know, once you can kind of get an idea of who's going to be targeting you, Is it cyber criminal groups, is it nation states? Which nation states are more likely than others? Um, then you can take a step back and there's a ton of great open source resources out there that will identify how they operate. So here's the tactics, techniques and procedures that they use and that sort of thing. Um, and then once you can identify that, you take another step and say, okay, well, knowing that, what do I need to know to protect myself? Um, and then that's. That really sort of creates your pirs there. Those questions that you've created from that thought exercise become your pirs.

Speaker A: Um, okay, let me put this for a second. Yeah, let's see. Let's see if Heidi was listening.

Speaker B: Okay, sure.

Speaker A: What's important? Like what, what information. What data is to your organization? Yeah, what, what data are data and information systems, like the systems that support that data or that information? What might threat actors want? What might be interesting and valuable to them? What tactics and techniques might the threat actors use? And then how do. Oh, man, I lost. I didn't get the last question. The last one. Okay, so it's using like the open source. No, that was for the tactics and techniques. What was the last one?

Speaker B: Yeah, the last one was, um, what do I need to know to protect myself knowing that those are the. Yeah, and then that, ah, that. Chris, you know, you did really well.

Speaker A: That. And that crystallized 75%. Okay.

Speaker B: Yeah. And that'll. That'll sort of crystallize your pirs, or at least that first draft of it. Um, the other thing I'll say too, when thinking about these pirs, is there's a couple of, you know, that's the thought exercise, um, that you do internally, but I think it's worth doing a couple of iterations with that with other groups within your organization as well. So, you know, you start with the initial brainstorm within your threat intelligence organization, be it one person or 10, let's get together and talk about it. What are we worried about? And then you go out and you talk to your stakeholders. So you cast a really wide net. Is it, Is it, you know, do you take a step out to your security organization? If you've got a larger security organization, your information, uh, you know, information officer, however else it's split out. Um, and then you talk to other Other organizations you wouldn't necessarily think about like sales. We'll go out and talk to our sales teams and our marketing teams, what keeps them up at night. And that's usually the way I'll phrase it to them, like, what are you worried about that could happen, um, from a cyber perspective. And then you, you know, you kind of iterate through that, through that series of questions across that ever growing circle. And at the end, like I said, you kind of crystallize around those pirs, and then you're, you're halfway to having a threat intelligence program.

Speaker A: Yeah. And I just want to say that I've seen this in the wild where certain, the folks who were initially tasked with this omitted pieces of really critical information because they didn't, they just didn't involve a larger group. And then they realized, oh wow, we missed, you know, some of these really, really critical things just because we were kind of in our own heads and not, you know, not thinking about the broader business. So definitely support that. Talking to a wider range of stakeholders.

Speaker B: Yeah, it's the classic where you stand, uh, stand depends on where you sit. And getting those perspectives from other organizations will really open the aperture on what you're looking at, what you're concerned about.

Speaker A: So is this a good time to talk about threat modeling and where that fits in to this?

Speaker B: Yeah, yeah, sure. So, um, you know, once you, once you have pirs, that's sort of for the larger organization and then, you know, I know we had talked about if you have sort of a fictional company, um, that that's building smart watches or something along those lines.

Speaker A: Oh yeah. Do you want me to just provide a brief description and we can.

Speaker B: Yeah, sure, that'd be great.

Speaker A: Okay, perfect, Perfect. Okay, so think, think about a. Um, so Mike and I talked about this before and we thought it would be useful to just have, have an organization that we can have in our mind and go through an example. So imagine that you're on a team that's building smartwatches and smart glasses. Right. Um, so you're capturing audio and video, you're capturing users personal information, biometric data, location data. Maybe you have AI agents built into this just to add a little flavor and fun. Right. Um, so the AI agents have access to users email to their calendar, to their social media, to their bank accounts, to their Venmo account. Um, and your, the smart glasses are, you know, if you think of like the meta glasses, they're able to record the world around you. Right. So like if Mike and I were face to face, I could record our conversation. Maybe Mike doesn't even know that that's happening. So there's, there's lots and lots of data that, you know, that it's collecting and also can take action on behalf of users because of that AI agent. So with that in mind, you know, we're building these products. Products. We're kind of going to walk through this, this scenario. Okay.

Speaker B: Yeah. So if, if we're taking it from that perspective. So, you know, and we'll assume that we've started with the company pirs, so, you know, you've, you've taken the bigger look at the company itself. So obviously there's intellectual property, there's, you know, financial assets you need to protect. There's your general attack.

Speaker A: Oh, see, I forgot intellectual property. Mike. Mike is my stakeholder being like Heidi, how did you forget our intellectual property?

Speaker B: Well, that's, yeah, and that's, that's sort of the big picture. And then when you start to look at specific things like, um, either applications or platforms, and this would be across the board within your, within your organization, um, particularly if you're technology oriented like we're talking about here, like smartwatches and smart glasses, then it's worth sitting down and doing some threat modeling, which is really taking a look at how your product works in a lot of detail. Um, you don't want it to get to such a level of detail because you can, you know, you can really split hairs and it can become overwhelming. You don't want to go too far down the rabbit hole with it. But sit down, diagram out your product, what its dependencies are, what the controls, uh, you have in place are, and everything else around it. And then look at it from the threat actor perspective and document all of the ways that you are concerned about somebody getting into that, you know, conducting a cyber attack on it. Um, one of the threat models that I find really useful is the striped threat model, um, which, uh, you know, so, and I know I'm not going to remember all of them right now, but you know, when we think threat modeling for a long time was around stride, that was one of the main models that people would use. I think Microsoft actually came up with it initially, um, but now they've added stripes, which is like, um, spoofing, denial of service identity. Um, that's not bad. I'll start there. I think I'm going to stop before I really embarrass myself and just really make some up. But now it's moving to striped, which adds privacy as part of it too. And Especially when we're talking about this, uh, you know, stuff like smart glasses and smartwatches, that privacy angle becomes really important. Um, so, you know, it's. That helps you align what attack vectors you're looking at for that particular product. So you build out a threat model. You diagram everything there. It helps you identify what the potential attack vectors are, what your potential weaknesses are, what your strengths are, and then you can use that to build pirs around that specific product as well. So, you know, you've got. It's like a level down from what we just talked about. You're basically doing that same thing, but product focus. And then you've got a bit more of an established model around it, too. Like I said, that striped model is super helpful, and especially because it features privacy so prominently.

Speaker A: That can be a really good. It's S, T, I, S, T, R, I, P, E. Right.

Speaker B: Striped with a D. Oh, striped.

Speaker A: Okay.

Speaker B: Yeah.

Speaker A: Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privileges. And then the P is for privacy, like private.

Speaker B: Private information. Yep.

Speaker A: Yeah. Okay, perfect. Awesome. And I'll. I'll just nod to Adam Szostak's threat modeling framework, which is, what are we working on? What can go wrong? What are we going to do about it? Did we do a good job?

Speaker B: Yeah, yeah.

Speaker A: Which is essentially like what you were talking about before, like you were focusing on, like, what are we working on? And, um, what can go wrong? Right. And then using the different items in the acronym, um, you can kind of go through and be like, okay, like, of. Of these things, like using these as a framework, like, what. What can go wrong? Right.

Speaker B: Yeah. There's.

Speaker A: Just to break it down in case folks, like, weren't, you know, you're thinking like, okay, from like, a spoofing perspective, like, what can go wrong? Like, in this area.

Speaker B: Yeah, yeah. And, you know, there's. There's. There are so many great models out there. Like you mentioned Adams and the stripe model, really. Because it can be intimidating, especially if you're just starting out with this. Um, but there's. Having these models just makes it so much easier, and it prompts you for the right questions. And. And you're going to be orders of magnitude more prepared than any other organization that isn't doing this.

Speaker A: Yep.

Speaker B: So. Yeah. So then, you know, you go through that process. Yeah, you go through that process with, with, you know, for instance here it would be, you know, if you're looking at.

Speaker A: And.

Speaker B: And you could break it down, as I said, to however many levels you really feel like you need to. But if we stick to a higher level. So you do this with your smart glasses and you're looking at could somebody denial of service by shutting down some of your dependencies. Like if you're relying on ChatGPT for some of this, then somebody, DDoS is ChatGPT and now all of a sudden you've lost functionality. It's a great way to go through that. Um, and then from there you can identify again that drives your pirs. And then you can start to look at collection from there and you go through that same series of questions. It's just now it's down another level and, and do that as many times as you need and keep iterating on that.

Speaker A: Yeah, let me dive a little bit deeper and kind of tease out the differences and similarities and the overlap between threat modeling and these priority intelligence requirements. So it sounds like threat modeling is really understanding your system and the vulnerability of your system, right?

Speaker B: Yeah.

Speaker A: And that helps with these priority intelligence requirements.

Speaker B: Yes.

Speaker A: Does that sound accurate?

Speaker B: Okay, absolutely.

Speaker A: Yeah.

Speaker B: It's, it's. Threat modeling is almost a. And I'm sure there are people who will disagree with me and I totally understand why. And I know as a threat intel guy, everything to me is threat intel. But, um, but it is almost a subset of that like you were. It is, it is a way to diagram a threat analysis of generally it's more technically focused. Um, it can be done at a higher level, but it tends to be more application focused, product focused, something along those lines, as opposed to organizationally focused. Um, I see.

Speaker A: That makes sense.

Speaker B: Yeah. Um, the other thing I'll add too is when we think about pirs, um, they do tend to be big picture because you want them to be relatively static, you want them to cast a wide net. You don't want them to be useless where you're covering everything. You know, I want to know everything that happens on a Monday, I want to know everything that happens on a Tuesday. You know, you don't want them to be that broad. Um, there's another level down from pirs. If as you start to mature in an organization, they're called, there's a million names for them. I've always called them critical intelligence requirements. Those tend to be more focused questions, like if a CVE comes out and you want to focus your collection on that, you stand up, what's called a critical intelligence requirement. And it tends to be very focused, very time boundaries. So it should automatically expire after like 30 days or something like that. But that's again, more mature is if, you know there's a specific threat you're worried about, that's how you kind of focus your collection on those as they come through.

Speaker A: Can I ask a question? Um, just to see if I'm on the right track going back to the threat modeling and the priority intelligence requirements. So if I'm thinking about these smart glasses and I'm going to call our end user Alice, I'm concerned that Alice is going to over rely on what this AI agent that's part of our smart glasses. Right. I'm concerned that she's going to kind of establish a relationship with this AI agent and she's going to trust everything that the AI agent says. Right. So if a threat actor is able to manipulate the AI agent, it can then manipulate Alice. Right?

Speaker B: Yeah.

Speaker A: So, uh, that to me is threat modeling. Right. Like I'm thinking, okay, so Alice has established this relationship and like, you know, she's trusting this AI agent. And one of the things that could potentially happen is that the AI agent is taken over by a threat actor who can then manipulate Alice. Right?

Speaker B: Yep.

Speaker A: So that you can use that. Right. And think about, okay, so how would a threat actor actually do this? And uh, you know, what are the particular tactics and techniques and how do we protect ourselves from that? Does that sound right?

Speaker B: That is precisely right. Yeah. So, you know, you think about. You do, you do. Yeah, yeah, you. So like that would be like, okay, you know, as you're drawing out the diagram and you have like user interaction, um, and then you could have data poisoning and you know, to manipulate the AI model exactly as you're saying, and then you start to. Okay, well then how do we prevent that? What controls do we have in place and that sort of thing. Very good. Yep. 100% awesome.

Speaker A: Well, and it's also, you know, this stuff is really complex. Like I'm, you know, I'm taking like the human side of it. But you know, you, uh, I, you said it, you know, it's very, it can be very technical, but I think it also can be, it can be very human and technical at the same time. Right?

Speaker B: Yeah, yeah, yeah. Like if you're, you know, another great example, even with something like that is if you're looking at, um, you know, if you're threat modeling, access to an application, you've also got to include simple stuff like if they have, if they need to log in, you've got to consider phishing, you've got to consider customer or employee education. Like there's absolutely that human element to it that can't be left out.

Speaker A: Yeah. Well, you mentioned one of the things that you, you have done with LastPass for that exact same reason. Right. Like threat actors were sending communications pretending to be LastPass. And you realize that this was happening, obviously. And you help, you tried to communicate with users and let them know, you know how to distinguish between what was deceptive versus legitimate communications. Right? Yeah, it probably happens all the time. You're like, whoa.

Speaker B: Oh, no, no, mercifully it doesn't. We're happy about that. Yeah. So, uh. But yeah, no, and that is, that is one of the core parts of our job too, is when we see stuff like that, getting that word out for that very reason.

Speaker A: Yeah. So for folks going back to the smart glasses example, like, okay, so I've identified these, uh, I've identified the information and the data that is critical. I've also done an exercise thinking about what's critical for, or what is interesting for threat actors. Where do I go to learn about tactics and techniques, like what are, what are the tools and resources available to me?

Speaker B: Yeah, that is, that becomes that next step. So that when I was talking about an intelligence cycle earlier, collection is what falls under, is what that falls under. And that's the next step. And really that depends on your resources and what you have available. Um, you know, it depends on people, process of technologies. That's the way we kind of split it up as we talk about it is as they often do. But, um, you know, there's, there's a ton of great open source stuff out there. There's a ton of great open source communities. You know, if you've identified your threat actors, you could even just go to the mitre, ATT and CK page. Odds, uh, are they've ident. They've got a page on those threat actors. And you know, you can start there.

Speaker A: Um, and for folks listening, it's M I T R E R E. Yep.

Speaker B: It's Attack Ampersand. Yeah.

Speaker A: Yes. Okay. Just wanted to call that out because it can be confusing, but yeah, that is an excellent resource. I mean, honestly, that'd be the first place that I would go to just to kind of get a sense if this was brand new to me.

Speaker B: Yeah, yeah. And a lot of the security research companies and cybersecurity companies out there put a lot of that data out for free. You know, Google threat Intelligence is pushing a lot of stuff out. Mystic from Microsoft. You can find a lot of really, really good free reporting if you're a company that, if you're A small company with not a lot of resources, you can, you can find pretty much everything you need. You know, it really just comes down to a degree of granularity and some

Speaker A: of the tools that you're probably using as a small company, like Microsoft. Um, like if you're using LastPass, you probably have like, you know, threat intelligence feeds or, you know, articles or whatever that you're pushing to customers, you know, because you want them to stay safe.

Speaker B: Yeah, yeah, we've got our LastPass Labs blog. Um, you know, yeah, Microsoft has MSTIC, their threat intelligence center. Google has Google Threat Intelligence. AWS is pushing stuff out. Amazon has their threat intelligence teams and they'll publish all that stuff and push it all out there. Um, as you sort of progress based on resources, you can start to look at threat intelligence vendors, paid intelligence feeds. Um, obviously the avenues open up the more money you have available to you. But, um, really figuring out that core data and where you're going to get it becomes that next aspect. Um, and then how do you ingest it becomes, becomes the next thing. So you identify what your sources are and then you figure out how you're going to bring it in. Do you want to use it? Could be something. Again, if you're just kicking things off and you're a person doing this part time, you know, do you set up a feedly account and you just identify what sources you want to pull from? Um, you want to use RSS feeds. You know, there's a lot of good free stuff out there that you can use to answer those questions. Um, and then, you know, again, it sort of steps up from there. If you want to, if you really want to start formalizing your program and ingesting that data in a single place. For threat intelligence, there are threat intelligence platforms that are free. If you want to use those, there are obviously paid ones. It just kind of ramps up from there as far as where you get the data from and then how you sort of collect it and put it in one place and use it.

Speaker A: Yeah, you know, it almost feels like there's plenty of data. Right? Like I, like I, I have done some of this myself, like, just like collecting it. Like, just tell me what's going on. Right. The hard part is analyzing that and being like, okay, so what does that mean for us? Uh, yeah, okay, so help me, Mike, because this is, I'm just drowning, I'm drowning in data.

Speaker B: Like, yeah, no, that is, that is the classic threat intelligence problem. And it's, it's an issue that analysts face and companies Realize analysts face too all the time is it's just information overload. There's just too much data out there. So separating that signal from the noise becomes really important. Um, some of that is you identify your initial feeds and then you start to feed those into your customers and your partners. A lot of that is based on feedback. Um, hey, this is good data, but we're getting a lot of false positives. Okay, well then now I need to neck that down a little bit. And that becomes a sort of ongoing cycle as well. So you, you take that feedback and then you adjust from there.

Speaker A: When you say false positives, do you mean maybe. Let me. I won't even try to inject what I think you mean. Can you just explain what you mean by false positives in this?

Speaker B: Yeah, sure. So, so let's say this. So, like, um, I'll use an IP feed as an example. So, okay, I went out and I identified this open source IP feed. These are, you know, supposed to have been identified as malicious IPs. And then we feed that into our SIEM, uh, and we keep getting a bunch of hits on it. But then when we look, there's really nothing there. So now, you know, our security team is investigating leads that aren't good. Okay, so how do we cut those out? Do we need to consider using a totally different feed? Are we getting some good stuff in here? That's. That is probably 90% of what you know, especially the more technically oriented threat intelligence analysts will end up doing is trying to kind of.

Speaker A: And then they go back to you and say, mike, you're feeding us crap. These.

Speaker B: Yep. Uh, I've had that conversation so many times. Uh, and I. Yeah, I feel, I feel for them. Like, I, you know, it's. It's sad that it's like the less I hear from the security operations teams, it means I'm doing my job better. So I like all of them. So I like talking to them, but I'm sad that they don't talk to me.

Speaker A: Okay, that's really helpful. Okay, so you, you want. You want meaningful, actionable M intelligence, right? That. That isn't producing. That isn't M forcing your security team to take action on things that are benign or, you know, are just. Are nothing.

Speaker B: Yeah. And a lot of it can even be sort of standing in the way for the rest of your team. So, you know, one of the things we do on our team is if you, if you look at vulnerability management and vulnerability, you know, any vulnerability management team has the potential to be overwhelmed because there's so many reports of vulnerabilities and everybody will freak out. It's, you know, it's got CVSS score of 10. We all need to panic. Um, even just doing something as simple as, as the Threat intelligence team when that report comes in, doing a quick check to see, even see if we have the technology before it gets pushed out or before it gets pushed into anything. Um, you know, so you can kind of help prevent. Put it in perspective like you were talking about what's actionable. Putting it in perspective before, before people freak out. Hey, Yep, we're seeing this. You know, X Company's got this vulnerability, but they're not in our environment. We use, you know, a different, A different product from them. Um, that sort of stuff is critical as well.

Speaker A: Yeah, yeah. It's almost like you act as a filter, like I think about. Okay, so I'm looking at, like, even if I'm just looking like at a LinkedIn feed, and naturally, most of my LinkedIn feed is all about cybersecurity. Right. So I see all these different things and I'm like, okay, like, I get it. You know, another breach, another, you know, another technique that I hadn't heard of before or hadn't considered before. But, but what does that actually mean for me? And I wish sometimes that I had a person like you and I could just be like, okay, Mike, like, what does that mean for me? What does that mean for my organization? Can you just break it down, right? Like, you're just my, my expert who kind of weeds. Weeds out these, you know, all these different. You said, uh, signal versus noise, right? Like that was.

Speaker B: Yeah, yeah, yeah. It's, it's if, as a threat intelligence analyst, if you're doing your job right, then when somebody hears from you, they know they need to act on it. You know, you don't want to be. And I think we talked about this in the previous podcast. You don't want to be the Chicken Little where. And that's easy to do. You know, you can, you can make everybody freak out about everything, but then they're going to get tired and it's going to be warning fatigue and they're not going to listen to you anymore. You want to be judicious in throwing that flag. Um, and that just builds the trust and kind of helps people know when they do need to act and take it seriously.

Speaker A: To what degree are you providing specific recommendations versus just communicating like this is happening and maybe assigning, uh, some sort of score to it or whatever, but not really telling them what to do about it. How do you fit into that?

Speaker B: Uh, it depends on the organization. Oftentimes, um, here everybody else is so much smarter than I am that I often can just kind of say, hey, here's the threat. And then they know what to do about it. But there is an aspect, and I've been in other organizations where any sort of part of the reporting and often it'll depend on what the customers want too. Sometimes they'll say, hey, I got it. You know, threat intel guy. You go back to coloring. Thanks for telling me about this. I've got it from here. Uh, but you know, uh, I have been part of organizations too where they're like, don't tell me this is an issue without, without providing some sort of solution to it. And that's totally cool too. So, you know, okay, well, you know, there'll be a, We've seen this POC that's, that's now in the wild if we're sticking with vulnerabilities. Um, this. So we're starting to see some activity around this, but the vendor hasn't released a patch yet. But here are mitigations that people are putting out there that may be useful and here's the reporting on it in case we want to implement these. Um, so that's part of it too. It really just depends on the organization.

Speaker A: Yeah, yeah, I would imagine like the smaller the organization is, the more that they're going to want to know, like, what do we actually do with this information? What are your recommendations for us?

Speaker B: Yeah, yeah.

Speaker A: Awesome. Okay, so let's talk about, um, we're kind of like closing that like circular framework that you were talking about earlier. This isn't a one and done thing, Right? I bet you wish like at the end of the week, like, oh, my job is done.

Speaker B: Right.

Speaker A: Yeah, but it's a, it's a cyclical thing. It's like it's ah, a never ending thing. So what does that look like? And what, what, what best practices or what recommendations do you have for folks?

Speaker B: Yeah, I always say it's like painting the Golden Gate bridge. Like as soon as you get done, you got to start back at the other end. Like that's basically what it is. Uh, so it is, there's, there should be. If it's done right, there should be a constant feedback loop. So there should be. You know, like I was talking about with security operations team, if they're telling me the feed is noisy, then I need to change it. Um, you know, it could be something as tactical as that. It can be going back to the pirs. It should be at least minimum annual revisitation and that means across the board. So internally, conversations with stakeholders, everything else. And it should be conversations like it. Uh, you know, I've tried in the past to do this with, hey, here's a feedback form, let me know what you're thinking. And you get almost none, something back, like getting somebody onto a call and saying, is this useful? You know, what's keeping you up at night? Now that sort of thing is really, really important. Um, you know, that's part of it. Having those check ins at least quarterly too. You know, just having those conversations is absolutely critical. Um, you know, taking a look at whatever sort of statistics you have internally, like are people reading your stuff? Are they acting on it? You know, we, we will measure, you know, for instance, um, how many incidents are kicked off based on our data or investigations are kicked off based on our data or anything like that. Having those internal statistics or metrics can be useful as well. Um, you can gauge. Are we adding value here too?

Speaker A: Um, let me pause for a second. Maybe this is really geeking out. But how are you tracking this stuff? And like how would you track that there was an action taken? So I'm thinking, I'm thinking about like how do you actually track all of the, the information that you're aggregating? And I'm assuming it's a lot and it's over time, then you're sending it to somebody else and you're hoping that they're taking action on it. Like how do you, like how does that work? That seems.

Speaker B: Oh no, Heidi, again, another 100% like that is you have hit the crux of the issue that every threat intelligence programs deals with. Like how do you. The question of metrics and threat intel is a constant conversation and issue. And how do you do this in a meaningful way? Um, because you know, it's one of those things. Yes, I can, I can tell you how many reports we've ingested and that sort of thing. Um, and that's useful, but then I'm just telling you how many things we pulled in. And that's also entirely out of my control. If threat actors are quiet, then the numbers go down. Then if you're reading metrics raw, like then it looks like oh, well, what happened here? And there's, there's no context to it. And so now you're placing metrics in basically outside of your control that you could be judged. Yeah. So, um, that actionability really becomes the core of it. And There's a couple different ways to do that. Like I said, one way is to tie it to actions, um, taken. So, you know, incidents kicked off, uh, vulnerability investigation started, stuff like that, where you can really tie it to something. Um, you can take a bit broader approach around operationalizing threat intelligence where you can, it becomes a bit more granular. But if you see something that's particularly interesting or a threat that could impact you, you mark that, you assess it against your controls and this all becomes sort of another whole process as a subset of threat intelligence. Um, measure it against your controls, test it and that sort of thing. Um, document any steps that were taken or is it a, you know, risk accept issue or are we covered? Um, and then you keep all of that as an artifact to say, okay, you know, and then you can quantify all of that at the end of the year. Here are the steps that were taken. We drove these actions. And then you have metrics that you can point to to show value. Um, you know, we are, uh, quantifiably safer because we have this threat intelligence program based on these actions and you can tell that story.

Speaker A: I'm thinking of like, so I come from a UX research background and we build repositories of, We've done all of these different studies and this information is useful for future studies. You know, it's useful for folks who are new to the organization to get a sense of the things that we've done before and the stuff that we already know about our users. So again, you know, uh, a research repository is, is a way to glean these insights. Right, that are evergreen. Right. Um, and then you can also kind of dig deeper into, okay, what was this actual study, you know, looking into? So I'm just curious, like when you were talking about this, it reminded me of research repositories as like a central, I don't know, database or, you know, repository. Is that something that you're, you're, you're building and maybe like AI is helping facilitate this. I'm just curious like how, you know, you're gathering all this information and it's, it's good, right? Like you need a central place for it.

Speaker B: Yeah, yeah. And there's, and there's sort of two aspects to that that, you know, that we're looking at. And there's one that I was just talking about that's really sort of action oriented. But then also to your point about the, you know, the AI usage, um, all that reporting that we pull in and stuff like that, creating a queryable database Using AI, where we can say, hey, what sort of reporting have we pulled in on scattered spider and what other tactics that we've seen associated with them? And then you can align that with whatever we're looking at. That's absolutely part of it too. And that's a really good point. I hadn't thought about it that way. That there's almost two databases that you have one on the threat intelligence reporting that becomes hopefully queryable and um, as a repository. And then there's also the actions taken and being able to quantify the steps and really kind of show that the effects of having a threat intelligence program.

Speaker A: Yeah, so interesting. And so interesting. Uh, the more that I dive into, uh, security, I'm like, there's so much overlap like in terms of the common problems that we have. Right. Like UX research. Same thing. Like you get a lot of data, there are a lot of studies going on in different groups and you know, there's often not a central place to be like, oh, they, they looked at that. Oh, like this would be helpful for my research. It's. Yeah, it's so, so interesting.

Speaker B: Yeah, yeah, yeah, that's um, the other thing I would say too, that uh, you know, in addition to internal databases and that sort of thing is really emphasizing external engagement for threat intelligence programs, like relying on what other people have already done. Because one of the things that really makes being in threat intelligence enjoyable is it tends to be a super. And because they're afraid of that stove piping. Because stove piping only helps the threat actors. So you know, hey, we saw piping, me and Mike. Oh, so, so like just keeping your information in your little channel. So, you know.

Speaker A: Got it.

Speaker B: Um, yeah, so like, you know, we've got, you know, we're part of uh, a, uh, password manager alliance, you know, and that sort of thing where we, you know, we talk to our, our peers, um, and it's all about sharing information. There's no real pride of ownership or anything like that when it comes to threat information because it fundamentally helps everybody to share this sort of thing. So um, that's one of the really cool aspects of it is, you know, I may not have seen something, but I can go out and I can pulse the community and I bet somebody else has and they're going to tell me about it and they're going to share that information. And so you can, you know, you're, you're as strong as a collective community instead of just kind of, you know, an army of one.

Speaker A: Yeah, that's, that's Great. Um, if, if you're a new company, maybe you just have like a handful. You're a startup, you just have a handful of people. Right. What are, what are maybe like the top three things that you would tell these folks who are under resourced. Right. Under staffed. And I'm probably doing a ton of other things like what are the top three things I should be thinking about or doing?

Speaker B: Yeah, so, so if I'm in that company and I've just been brought on and I am doing threat intel part time, like this is an other duty as assigned. Hey, you're the threat intel guy on top of everything else you're doing. So yeah, first thing I do is that thought exercise I talked about. If I have PIRS now I have questions I can answer. Um, then depending on my resources, I figure out where I'm going to get that information from. So I take a couple of hours. And especially, you know, if it's, if it's got to be big and quick, then yeah, I'm looking at feedly, I'm looking at RSS feeds. I um, may use uh, like Chat GPT or some, some other LLM or something like that. Um, uh, to summarize, uh, that information as it comes in. Um, and then I'm going to use that to kind of help me with my reporting and then I'm going to start pushing that out and so, you know, and that becomes, what's the best way that becomes sort of part of your customer conversations too. How do you want this data? Do you want an email? Do you want it? Um, you know, if any of the feeds that I get, I'm probably going to try and attach into, you know, our security controls and that sort of thing to feed them with, with the tactical intelligence. But everything else is going to be how do I push this out in a way that's meaningful to the customers? And then I go from there and I just start refining. So as long as I'm pulling data in, that's helpful and I'm getting good feedback and I, you know, and I've only got a couple hours, you know, a week to do it, then that's a win. And we are, you know, in that organization is now fundamentally more secure than it was. Even just 12 hours of, you know, working resources before, um, it makes a really rapid difference.

Speaker A: That's great advice. I really like that. Okay, so who do you think? It's just very succinct and like you said, you can do it in a few hours a week. Yeah. Um, if there is no dedicated person. And you, you know, you're looking. So if I'm the owner of the business, maybe.

Speaker B: Mhm.

Speaker A: And I'm looking around at my, at the folks who work with me, who do you think is best suited to take on threat intelligence as part of their role?

Speaker B: Yeah. So um, whoever your IT person is, as close as you can get to an IT person because they're going to have, they're going to be the closest to being able to take the steps to mitigate those threats. So you know, if you're in control of the email setup and the network and stuff like that, then as if nothing else, as long as you're getting that information and you're in charge of that stuff, you know what the threat environment looks like and it becomes a bit of a self licking ice cream cone where like you're feeding yourself the information then you're taking the steps to fix it. But, but at least you know when you can take the steps. So if you're going to identify one person that, that's who I would identify. Identify with a role like that.

Speaker A: Yeah, that makes sense. Awesome. And for like accountability. Right? Like, so if that person is doing the threat intelligence, they're like gathering the information, but they're also the person charged with doing something about it. How do you, you know, I'm just like thinking about like checks and balances. Like how do you evaluate that this person is doing what they're supposed to be doing? Does that make sense? Yeah.

Speaker B: No. Yeah. It's always tough when somebody's grading their own math in a way and. Yeah, yeah. Um, I mean there's an aspect of it like if you're not getting popped then they're doing their job. Like that's, you know what I mean? Like there's, that's definitely part of it. Yeah, you know, it's, it's worth, um, you know that's, that's a really good question. Especially if you're resource limited. Because I would say, you know, in larger organizations I'll have a second line and a third line audit and everything else. And you're, you know, like in my previous roles we've had all of that. So somebody was making sure we were doing our job. Multiple people were making sure we were doing our job. Um, and a small organization like that, I think it really does come down to action and effect. Like if, if you're not having, you know, if it's a five person organization, you're not having security incidents, then then you're doing pretty good. Like that's, that's probably, that's probably about as much resources as you can apply to it. Um, you know, maybe a once a year stand down to have somebody else, like an external person take a look or something like that. But it becomes challenging with resources. It can get expensive and difficult fast because you need the expertise as well. Um, you know, some sort of third party coming in to take a look. Could be, could be an answer to.

Speaker A: Yeah, I was thinking about the metrics that you were talking about before and like, how could that, that one person who's doing threat intelligence part time, you know, do it? Like maybe you have a quarterly like risk committee meeting or you know, you just, you have these, these quarterly or monthly, you know, standups with your team and you can kind of go through these things. Um, mostly I was thinking about the founder who might not have any sort of security knowledge or might not even be that technical and yet has this person on the engineering team or like you said, on the IT team who's doing this threat to intel and like this, you know, she has no idea. Like if this, you know, if, if, if they're doing a good job, it's really hard to evaluate. So.

Speaker B: Yeah, that was, yeah, that's, no, that's a great way to look at it. And that sort of plain language translation to your point is really important too. Um, you think about just. And that's where the uh, threat to action breakdown can come in really helpful. Like, hey, we saw these IPs were being used, we changed our firewall to block them. And it can be as simple as that, uh, in a way that non technical people can understand.

Speaker A: Awesome. All right, Mike. I feel like this is a good way, A good way and a good time to wrap up the episode. Any, any parting words for folks or anything that you, you want to call out or places that you want folks to, to check out. Maybe a blog post, anything.

Speaker B: Yeah. So yeah, if you, if you check, uh, all this is written down on, on LastPass Labs. Like we've got a couple of blog posts up there. Um, I am obviously super passionate about this. Happily give advice on this stuff all day long. Um, you know, and I just want to hammer the point home again about the external engagement that's so important. Take some time. Whoever it is that's doing this, reach out to your ISACs, if they're around the information sharing and analysis centers for your sector. Um, go to local conferences, just, you know, get on any social media. There's really robust communities on there sharing information and answering questions. Even if it's just one person doing it three hours a week, you're not alone. So, yeah, reach out for help.

Speaker A: Great advice. Thank you so much, Mike. This was so interesting and so helpful. Really appreciate you taking the time.

Speaker B: Thank you, Heidi. This is great. Thank you so much again for having me back.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Lay of the Land: How Attackers Move in '26mnemonic security podcast · on supply chain attacks94 / 100
  • Built Fast, Broken Faster: MCP & AI App Security - with GitGuardian’s Gaetan FerryCyber Sentries: AI Insight to Cloud Security · on supply chain attacks94 / 100
  • Code War with Allie MellenAfternoon Cyber Tea with Ann Johnson · on supply chain attacks85 / 100
  • AI-Accelerated Supply Chain Attacks with Mackenzie JacksonRunAs Radio · on supply chain attacks83 / 100
  • Stories from an Expert Threat Hunter with Taz WakeCyber Leaders · on supply chain attacks82 / 100
  • Future-proofing and StorytellingCyber Security Business · on supply chain attacks80 / 100

More from Human-Centered Security

All episodes →
  • We Regret to Inform You: Your Phishing Training Did Nothing with Ariana Mirian94 / 100
  • XDR, EDR, SIEM, SOAR…Snooze: Cybersecurity Marketing Real Talk with Gianna Whitver71 / 100
  • Human-Centered Security In the Wild: Jordan Girman and Mike Kosak On Security and Product Team Collaboration at Lastpass81 / 100
  • From Tools to Teammates: (Dis)Trust in AI for Cybersecurity with Neele Roch85 / 100
  • Introducing Human-Centered Security: The Book67 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Human-Centered Security episodes →