The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
#29Practical Cybersecurity with Jen Stone84.0 / 100Get badge
← The Index
Practical Cybersecurity with Jen Stone artwork
Ops▲74 this period

Practical Cybersecurity with Jen Stone

Hosted by SecurityMetrics

Listed under Education

★5.0on Apple Podcasts · 4 recent reviews

Practical Cybersecurity , hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation.

120 episodes · publishes fortnightly · latest 2026-08-04 · ~33 min/episode

Rank

#29

Substance

84.0

/ 100

Breakdown

Scored 2026-08
Updated monthly

Ops rank

#5 of 121

Best B2B Ops Podcasts →

Across the index

#29 of 1566

Substance

Top 2%

outscores 98% of the index

Why it scores where it does

Practical Cybersecurity with Jen Stone ranks #29 on The B2B Podcast Index with a substance score of 84.0 out of 100, scored across 3 recent episodes. It scores highest on guest caliber and specificity & evidence. Guests are well-credentialed practitioners with relevant operational scale: VP of assessment (21 years in cybersecurity), VP of technology who built the monitoring product, and VP of forensic investigation (16 years in role). All work at a firm actively doing merchant compliance and breach forensics. They speak from hands-on experience, not theory. This is real operator knowledge.

The five-dimension breakdown

Averaged across 3 recently scored episodes, with cited evidence.

Insight Density

17.3 / 20

The episode delivers solid, actionable insights about eSkimming attacks, PCI compliance (6.4.3 and 11.6.1), and the friction between security requirements and merchant operations. However, the content is somewhat repetitive - the same core points (merchants struggle with script inventory, third-party attribution is messy, alerts need refinement) are circled multiple times. A smart B2B operator learns the landscape but doesn't encounter many genuinely novel mechanisms or surprising technical details.

“We're not seeing customers reduce the number. I mean, there's just so much pressures from marketing, from PR, from everyone else who's trying to optimize the experience.”

“The attackers have just found a clever way of circumventing the same-origin policy, the protection that that iframe provides, and it's usually something happening on the merchant side of things; A plugin that was out of date, a SQL injection vulnerability”

Originality

14.7 / 20

The episode covers well-trodden compliance and security frameworks (PCI DSS, iframe vs. redirect trade-offs, supply chain attack rise) without substantial contrarian or first-principles analysis. The zero-malware attack example is an interesting edge case, but the broader argument - that merchants struggle with compliance and tool burden exists - is predictable. No fresh angle on how to fundamentally rethink the problem.

“An iframe has inherent security features - same-origin policy that offers a whole lot more security than just a payment redirect.”

“Secure is also susceptible to timeframe. Right? I can have my web server 100% secured and locked down. I've done everything within my ability today, but if tomorrow there's a zero-day that undoes all the preparation that I've done today.”

Guest Caliber

18.0 / 20

Guests are well-credentialed practitioners with relevant operational scale: VP of assessment (21 years in cybersecurity), VP of technology who built the monitoring product, and VP of forensic investigation (16 years in role). All work at a firm actively doing merchant compliance and breach forensics. They speak from hands-on experience, not theory. This is real operator knowledge.

“I'm Gary Glover, I'm the VP of our assessment team here at SecurityMetrics. Been doing cybersecurity for about 21 years.”

“I'm Chad Horton, I'm the VP of technology here at SecurityMetrics. I'm the individual who coded the original design for the Shopping Cart Monitor product.”

Specificity & Evidence

18.0 / 20

The episode includes concrete examples (iframe bypass attacks starting November 2020, Bitwarden CLI and npm compromises, a law firm HR person marking N/A on all scripts, the zero-malware attack case) and references specific PCI requirements (6.4.3, 11.6.1). However, it lacks quantified data: no percentages of merchants breached, no timeline breakdowns on detection, no cost figures for remediation, and no specifics on how often Shopping Cart Monitor catches skimmers or false-positive rates.

“We had one merchant where they got so overwhelmed managing this list that they just stopped it and they're like, no, we're done. We're not going to do this. And it was no more than like 2 or 3 weeks after they stopped logging in and monitoring those and authorizing them that they got hit by a skimmer”

“They'd gone in and found an analytic script, a legitimate analytic script that had the capability of capturing everything on the page. But if properly configured, it would exclude credit card data. The attackers had gone in and just added a little flag”

Conversational Craft

16.0 / 20

Jen Stone asks setup questions and some follow-ups ("What happens when we don't have the right kinds of protections?", "How often really are you getting malware issues?"), but rarely pushes back, challenges claims, or forces the guests deeper. The conversation feels collaborative rather than interrogative. When guests hint at tensions ("it's both brilliant and painful," "check the box on a not-real solution"), Stone doesn't probe the contradiction hard. Limited genuine disagreement or tension.

“So let's say just from an operational point of view. So we've got a business leader or IT director who's listening to this podcast and saying, you know what, I have an iframe doing our e-commerce.”

“So I would be interested to know, Aaron, you are doing these kinds of inspections, forensic activity against e-commerce pages all day, every day. You know, you have a huge breadth of experience in this. How often really are you getting malware issues on pages where maybe the merchant thought they were just fine?”

Standout episodes

  • The Expert Guide to Defeating eSkimmers (ep. 8)

    2026-05-26

    86
  • AI Didn't Change the Rules, It Raised the Stakes (ep.13)

    2026-08-04

    85
  • Which PCI SAQ Do You Actually Need? (ep. 10)

    2026-06-23

    81

Rank over time

2 periods tracked.

Episodes

3 scored on substance · 63 tracked in total.

  • AI Didn't Change the Rules, It Raised the Stakes (ep.13)

    2026-08-04 · 39 min

    85 / 100
  • Which PCI SAQ Do You Actually Need? (ep. 10)

    2026-06-23 · 35 min

    81 / 100
  • The Expert Guide to Defeating eSkimmers (ep. 8)

    2026-05-26 · 30 min

    86 / 100

What listeners say on Apple Podcasts

★★★★★
Cyber security and compliance made interesting and simple
This is a fantastic podcast that I’ve loved since it came out. My only complaint is there aren’t more episodes! Keep up the great work!

- Ricky279977

★★★★★
Super helpful podcast!
This podcast is great for those who want to learn more about cyber security or become more secure.

- i_luv_the_beatles

Frequently asked

What is Practical Cybersecurity with Jen Stone's substance score?
Practical Cybersecurity with Jen Stone scores 84.0 out of 100 for substance and ranks #29 on The B2B Podcast Index. That puts it ahead of 98% of the B2B podcasts we rank and #5 of 121 in Ops. The score reflects insight density, originality, guest caliber, specificity and conversational craft across recent episodes - not downloads.
Is Practical Cybersecurity with Jen Stone worth listening to?
Yes - Practical Cybersecurity with Jen Stone outscores 98% of the B2B ops podcasts and shows we rank on substance, so a ops operator is likely to come away with something useful.
Who hosts Practical Cybersecurity with Jen Stone?
Practical Cybersecurity with Jen Stone is hosted by SecurityMetrics.
How often does Practical Cybersecurity with Jen Stone publish?
Practical Cybersecurity with Jen Stone publishes fortnightly, has 120 episodes, released its most recent episode on 2026-08-04.
Which Practical Cybersecurity with Jen Stone episode should I start with?
Our highest-scoring recent episode is "The Expert Guide to Defeating eSkimmers (ep. 8)" (86/100) - a good place to start.

Show off your #5 rank in Ops

Add this badge to your site - it links back here and updates automatically as you rank.

Ranked #5 on The B2B Podcast Index
Embed code
<a href="https://index.fame.so/show/practical-cybersecurity-with-jen-stone" target="_blank" rel="noopener">
  <img src="https://index.fame.so/badge/practical-cybersecurity-with-jen-stone/badge.svg" alt="Ranked #5 on The B2B Podcast Index" width="360" height="136" />
</a>
Markdown & other formats →

Track Practical Cybersecurity with Jen Stone's rank

Get an email whenever this show moves up or down the Index. Monthly at most, no spam.

Listen / subscribe:WebsiteSpotifyRSS

Frequently discusses

Companies, products and tools that come up most across this show's episodes.

ToastPCI Security Standards CouncilVerifoneIngenicoPaxSecurityMetricsShopping Cart MonitorShopping Cart InspectPCI DSS

Guests who've appeared

Aaron Willis · 2Michael SimpsonGary GloverChad Horton

Topics this show covers

The themes that come up most across this show's episodes.

Shopping Cart Monitor · 2Agentic AIPCI DSS 4.0.1Security MetricsSpectre AIE-commerce skimmingMFA fatigueSession hijacking and credential compromiseNext.js framework attacksPayment redirects vs. iframesToast point of sale systemPCI Self-Assessment Questionnaire (SAQ)SAQ ASAQ A-EPSAQ DSAQ P2PESAQ BSAQ B-IP

More Ops podcasts

See all →
  • Cyber Leaders

    SANS Institute

    89.2
  • The Operations Podcast with Fexingo

    Fexingo

    88.6
  • Security & GRC Decoded

    Raj Krishnamurthy

    86.4
  • Rethink Imaging

    Imalogix

    84.3
  • Value Based Care Advisory (VBCA) Podcast

    Carenodes

    82.0
  • The Growth Operator with Fexingo

    Fexingo

    81.8

Similar shows

Podcasts that dig into the same topics.

  • Making Data Simple

    Making Data Simple

    88.5
  • Masters of Privacy

    Sergio Maldonado

    86.5
  • Security & GRC Decoded

    Raj Krishnamurthy

    86.4
  • Cyber Sentries: AI Insight to Cloud Security

    TruStory FM

    83.6
  • The AI Forecast

    Cloudera

    83.5
  • SaaS Backwards

    Ken Lempit

    83.2