
Hosted by Chris Hughes
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries.
213 episodes · publishes weekly · latest 2026-06-27 · ~31 min/episode
Rank
#530
Substance
76.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#530 of 6182
Substance
Top 9%
outscores 91% of the index
Resilient Cyber ranks #530 on The B2B Podcast Index with a substance score of 76.0 out of 100, scored across 1 recent episode. It scores highest on specificity & evidence and insight density. The episode is anchored by several concrete figures drawn from the guest's own published forecast - 40%+ YoY CVE growth, one-in-five CVEs from GitHub, 164% Mozilla spike, 3,000 PatchStack WordPress CVEs, 14x projected commit increase - which is above average for the genre. Dollar figures and named breach case studies are absent, and some claims (AI exploitation 'coming') remain hand-wavy.
Averaged across 1 recently scored episode, with cited evidence.
The episode delivers a handful of genuinely useful data-driven claims - GitHub's outsized share of CVE issuance, the exploitability-stays-flat finding despite raw volume surge, and the procurement-leverage angle for forcing CNA quality. However, the guest spends substantial airtime on well-known fundamentals (CMDB, 'we don't know what's on our networks') and the host's long affirming responses eat into the content clock.
“GitHub is now publishing one in five CVEs that are published”
“NVD was just basically correcting their homework for them. Filling in CPE, filling in CBSs and then presenting good clean data to the public”
The 'rain versus flood' framing is a serviceable metaphor for distinguishing raw CVE count from actionable exploitability, and the idea of treating CVE data quality as a procurement lever is a relatively underused angle. But most other content - OWASP top 10 unchanged, attackers use old vulns, know your assets - is standard vulnerability management canon.
“if you had a pen tester give you a finding last year in a report and then an AI tool found it this year, you could probably get the time to fix it because the new cool AI tool said that it was there”
“we need to start see having people see CBE Data, uh, as a product that they're paying for”
Gamblin is a credible domain practitioner who built and maintains real open-source tooling (CVE ICU, Rogo Labs), co-authors CVE trend research that gets cited in the community, and has hands-on history in the CVE space at Kenneth Security. He is not a career thought-leader, but he is also not a senior operator who has run a security function at scale, which caps the ceiling.
“I used to work for a startup called Kenneth Security and we were in the CVE space”
“I sit down and we tried to figure out a good way to describe this so people could understand”
The episode is anchored by several concrete figures drawn from the guest's own published forecast - 40%+ YoY CVE growth, one-in-five CVEs from GitHub, 164% Mozilla spike, 3,000 PatchStack WordPress CVEs, 14x projected commit increase - which is above average for the genre. Dollar figures and named breach case studies are absent, and some claims (AI exploitation 'coming') remain hand-wavy.
“we're just at about over 40% growth year over year”
“Patch Stack has put out just over 3,000 CVEs. If I don't run WordPress anywhere on my network there, those are 3,000 CVEs I don't have to even think about”
The host shows some craft - he correctly anticipates the 'forcing function' follow-up and does pull apart the three structural drivers rather than accepting a lumped answer. But his questions are frequently long and leading, he rarely challenges a claim, and the episode has a fan-interview tone ('you're one of my go-to resources') that forecloses productive tension.
“help us pull those apart a little bit because they're very different kind of forces from different ent, but they all get kind of lumped together in one big scary number”
“my follow up question to you when you said like you know, the, the responsibility or burdens falling to those who it should have been with to begin with, the cnas was going to be like what forcing function is there?”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/resilient-cyber" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/resilient-cyber/badge.svg" alt="Ranked #59 on The B2B Podcast Index" width="360" height="136" />
</a>Track Resilient Cyber's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
Security & GRC Decoded
Raj Krishnamurthy
B2B SaaS Talks with Fexingo
Fexingo
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
Ship It Weekly
Teller's Tech - DevOps, SRE and Cloud Podcast
Cybersecurity Ecosystem Show
Cybersecurity Ecosystem Show
Knowledgebase Ninjas
Gowri Ramkumar