
Hosted by Simply Cyber Media Group
Join us for Simply Defensive, a podcast dedicated to exploring the world of defensive cybersecurity through the lens of real-world experts. In each episode, we'll interview leading professionals from the cybersecurity industry, delving into their experiences, challenges, and innovative solutions.
42 episodes · publishes weekly · latest 2026-05-04 · ~37 min/episode
Rank
#1036
Substance
72.3
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#1036 of 6182
Substance
Top 17%
outscores 83% of the index
Simply Defensive ranks #1036 on The B2B Podcast Index with a substance score of 72.3 out of 100, scored across 3 recent episodes. It scores highest on guest caliber and insight density. Jason Haddix is a credible, hands-on practitioner with demonstrable depth: former CISO at Ubisoft, co-founder of Arcanum, field CISO at Flare, instructor on AI red/blue team methodologies, and active researcher publishing novel findings (mass assignment vulnerabilities in LLM APIs). He speaks from recent consulting engagements and real organizational implementation experience, not theoretical positioning.
Averaged across 3 recently scored episodes, with cited evidence.
The episode contains substantive technical insights about AI security, context engineering, and defense strategies that a blue teamer would find actionable, but is interspersed with tangential personal banter and scheduling discussions that dilute the density. The core AI security content (guardrails vs. input validation, RAG implementation, prompt engineering methodology) is solid but occupies perhaps 50% of the runtime.
“input validation is a losing game with AI because natural language has so many, like a natural language system has so many bypasses”
“the domain has gone past prompt engineering to now what we call context engineering, right? Which includes rag”
Jason presents genuinely fresh thinking on AI defense that diverges from mainstream web-application security patterns. The shift from input validation to classifier-based guardrails and defense-in-depth for AI systems is counterintuitive and well-argued. However, the concept of stages of adoption and RAG-augmented systems, while clearly explained, are not entirely novel in the AI discourse.
“really feel that input validation is a losing game with AI because natural language has so many, like a natural language system has so many bypasses”
“shift away from your normal security mindset of like input validation”
Jason Haddix is a credible, hands-on practitioner with demonstrable depth: former CISO at Ubisoft, co-founder of Arcanum, field CISO at Flare, instructor on AI red/blue team methodologies, and active researcher publishing novel findings (mass assignment vulnerabilities in LLM APIs). He speaks from recent consulting engagements and real organizational implementation experience, not theoretical positioning.
“you've been the CISO at UB soft. You've been a bug crowd”
“we have been like doing some consulting, going to organizations as part of this new random service that we built called the an AI scaling Assessment”
Jason provides concrete examples (Flare's work with stealer logs, Ubisoft's 22,000-employee VDI challenges, custom detection bot examples, RAG implementation with full company tool stack profiles) but lacks hard metrics, dollar figures, or detailed timelines that would elevate this further. References to 'year and a half' implementation timelines and organizational examples are present but sparse; much advice remains at the framework level.
“when you get Steeler logs and you look at those and you're like, okay, an employee's laptop has been infected with actual Malware”
“we had 22,000 employees, so the VDI solution...would've been so expensive and crushed our security budget and our IT budget”
The hosts ask reasonable technical questions and Jason responds substantively, but there is minimal productive pushback, challenge, or deep follow-up. Josh and Wade ask setup questions but rarely probe contradictions or demand evidence. The conversation drifts frequently into personal asides (D&D, Signal messaging, laptop nuking anecdotes) without returning to pressure-test Jason's claims or explore edge cases.
“I have a good AI question for you”
“Have you seen any other ones telling their bots to use methamphetamines?”
First period on the Index - history builds from here.
3 scored on substance · 42 tracked in total.
S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career Growth
2026-05-04 · 31 min
S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hired in Cybersecurity
2026-03-17 · 39 min
From Blue Team Challenges to AI Innovations: A Conversation with Jason Haddix
2026-02-24 · 32 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/simply-defensive" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/simply-defensive/badge.svg" alt="Ranked #85 on The B2B Podcast Index" width="360" height="136" />
</a>Track Simply Defensive's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.