
Hosted by Risky Business Media
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros.
100 episodes · publishes weekly · latest 2026-07-01 · ~54 min/episode
Rank
#427
Substance
77.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#427 of 6183
Substance
Top 7%
outscores 93% of the index
Risky Business ranks #427 on The B2B Podcast Index with a substance score of 77.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and conversational craft. Daf Studded is the actual founder of PortSwigger/Burp Suite - a real operator who built a dominant tool over two decades - and Adam Boileau and James Wilson are clearly working practitioners with hands-on red-team and vulnerability research experience; no pure thought-leaders or career podcast guests, though the news-commentary format limits how deeply any expertise is demonstrated.
Averaged across 1 recently scored episode, with cited evidence.
The episode spans many topics and surfaces several genuinely non-obvious technical points - Carlini's gibberish-distillation finding, the log-resale business model underpinning cheap Claude tokens, and the LLM-driven EDR binary analysis methodology - but the format is primarily rapid news commentary, so ideas are rarely developed beyond a paragraph before moving on.
“you can actually just throw gibberish at it. And the response you get is just as telling because at the end of the day you're trying to match the patterns in the token distribution, not even the words itself”
“the real reason it's so cheap is because they're collecting the logs. And that's the real business here, not the selling you five bucks a month worth of claude”
There are a handful of fresh angles - the DRM/end-to-end-attestation analogy applied to LLM API distillation, and the genuinely disturbing CSAM-injection-as-anti-analysis-evasion prediction - but the bulk of the show is reactive news commentary rather than first-principles argument, and the sponsor interview stays close to safe product positioning.
“There is no concept of like I was thinking about how we did DRM in itunes...there's no end to end attestation. There is no real end to end encryption in the sense of that would prevent uh, a proxy sitting in the middle”
“It's not just about shipping the CSAM as the means to defeat this. It's shipping injected prompts to generate the CSAM on demand so that there is no actual way to filter this”
Daf Studded is the actual founder of PortSwigger/Burp Suite - a real operator who built a dominant tool over two decades - and Adam Boileau and James Wilson are clearly working practitioners with hands-on red-team and vulnerability research experience; no pure thought-leaders or career podcast guests, though the news-commentary format limits how deeply any expertise is demonstrated.
“Because our tooling has solved a lot of those edge cases over couple of decades, uh, it's much more likely that the tools will work and will achieve what the model was actually trying to achieve”
“obviously SpectreOps does a lot of red teaming. Uh, they have a big interest in understanding how security products work so that you can evade them”
The episode names specific tools (RR Web, Cortex XDR, LibSSH2, ImageMagick), cites a Carlini co-authored paper, references the Chinatalk article by name, and gives some figures ($3.4B damage, 18-month sentence), but benchmark comparisons are hedged and many security incidents are discussed without verifiable numbers or timelines.
“GLM 5.2 is the real huge flavor of the month, and that, in fact, is showing better scores in cybersecurity benchmarks than even the, I uh, think the Codex 5.5 cyber models”
“there's an ImageMagick bug where you can supply uh, a binary alongside and through like path confusion, it'll run that binary instead of the system provided one”
Patrick Gray asks sharp follow-up questions, flags epistemic uncertainty about unverified documents, and steers the conversation toward uncomfortable territory (CSAM injection) that most hosts would skip; the sponsor interview is predictably soft given the commercial relationship, which pulls the score down from higher marks.
“Now Adam, Adam, you actually noticed that it looked like the LLM thought it was doing some sort of CTF challenge or something, right? Why did you, how did you determine that?”
“I will note too, that that letter that's been passed around, we have seen wired referrals to this letter, um, but we haven't been able to confirm that the letter that's being passed around on social media is authentic”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/risky-business" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/risky-business/badge.svg" alt="Ranked #49 on The B2B Podcast Index" width="360" height="136" />
</a>Track Risky Business's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.