
Hosted by SecurityMetrics
Practical Cybersecurity , hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation.
117 episodes · publishes fortnightly · latest 2026-06-23 · ~33 min/episode
Rank
#101
Substance
83.5
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#101 of 6183
Substance
Top 2%
outscores 98% of the index
Practical Cybersecurity with Jen Stone ranks #101 on The B2B Podcast Index with a substance score of 83.5 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and insight density. Guests are well-credentialed practitioners with relevant operational scale: VP of assessment (21 years in cybersecurity), VP of technology who built the monitoring product, and VP of forensic investigation (16 years in role). All work at a firm actively doing merchant compliance and breach forensics. They speak from hands-on experience, not theory. This is real operator knowledge.
Averaged across 2 recently scored episodes, with cited evidence.
The episode delivers solid, actionable insights about eSkimming attacks, PCI compliance (6.4.3 and 11.6.1), and the friction between security requirements and merchant operations. However, the content is somewhat repetitive - the same core points (merchants struggle with script inventory, third-party attribution is messy, alerts need refinement) are circled multiple times. A smart B2B operator learns the landscape but doesn't encounter many genuinely novel mechanisms or surprising technical details.
“We're not seeing customers reduce the number. I mean, there's just so much pressures from marketing, from PR, from everyone else who's trying to optimize the experience.”
“The attackers have just found a clever way of circumventing the same-origin policy, the protection that that iframe provides, and it's usually something happening on the merchant side of things; A plugin that was out of date, a SQL injection vulnerability”
The episode covers well-trodden compliance and security frameworks (PCI DSS, iframe vs. redirect trade-offs, supply chain attack rise) without substantial contrarian or first-principles analysis. The zero-malware attack example is an interesting edge case, but the broader argument - that merchants struggle with compliance and tool burden exists - is predictable. No fresh angle on how to fundamentally rethink the problem.
“An iframe has inherent security features - same-origin policy that offers a whole lot more security than just a payment redirect.”
“Secure is also susceptible to timeframe. Right? I can have my web server 100% secured and locked down. I've done everything within my ability today, but if tomorrow there's a zero-day that undoes all the preparation that I've done today.”
Guests are well-credentialed practitioners with relevant operational scale: VP of assessment (21 years in cybersecurity), VP of technology who built the monitoring product, and VP of forensic investigation (16 years in role). All work at a firm actively doing merchant compliance and breach forensics. They speak from hands-on experience, not theory. This is real operator knowledge.
“I'm Gary Glover, I'm the VP of our assessment team here at SecurityMetrics. Been doing cybersecurity for about 21 years.”
“I'm Chad Horton, I'm the VP of technology here at SecurityMetrics. I'm the individual who coded the original design for the Shopping Cart Monitor product.”
The episode includes concrete examples (iframe bypass attacks starting November 2020, Bitwarden CLI and npm compromises, a law firm HR person marking N/A on all scripts, the zero-malware attack case) and references specific PCI requirements (6.4.3, 11.6.1). However, it lacks quantified data: no percentages of merchants breached, no timeline breakdowns on detection, no cost figures for remediation, and no specifics on how often Shopping Cart Monitor catches skimmers or false-positive rates.
“We had one merchant where they got so overwhelmed managing this list that they just stopped it and they're like, no, we're done. We're not going to do this. And it was no more than like 2 or 3 weeks after they stopped logging in and monitoring those and authorizing them that they got hit by a skimmer”
“They'd gone in and found an analytic script, a legitimate analytic script that had the capability of capturing everything on the page. But if properly configured, it would exclude credit card data. The attackers had gone in and just added a little flag”
Jen Stone asks setup questions and some follow-ups ("What happens when we don't have the right kinds of protections?", "How often really are you getting malware issues?"), but rarely pushes back, challenges claims, or forces the guests deeper. The conversation feels collaborative rather than interrogative. When guests hint at tensions ("it's both brilliant and painful," "check the box on a not-real solution"), Stone doesn't probe the contradiction hard. Limited genuine disagreement or tension.
“So let's say just from an operational point of view. So we've got a business leader or IT director who's listening to this podcast and saying, you know what, I have an iframe doing our e-commerce.”
“So I would be interested to know, Aaron, you are doing these kinds of inspections, forensic activity against e-commerce pages all day, every day. You know, you have a huge breadth of experience in this. How often really are you getting malware issues on pages where maybe the merchant thought they were just fine?”
First period on the Index - history builds from here.
2 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/practical-cybersecurity-with-jen-stone" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/practical-cybersecurity-with-jen-stone/badge.svg" alt="Ranked #7 on The B2B Podcast Index" width="360" height="136" />
</a>Track Practical Cybersecurity with Jen Stone's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.