
Hosted by Izar Tarandach, Matt Coles, and Chris Romeo
The Security Table is four cybersecurity industry veterans from diverse backgrounds discussing how to build secure software and all the issues that arise!
108 episodes · publishes weekly · latest 2026-07-01 · ~40 min/episode
Rank
#2356
Substance
65.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#2356 of 6182
Substance
Top 38%
outscores 62% of the index
The Security Table ranks #2356 on The B2B Podcast Index with a substance score of 65.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and originality. Three co-hosts who are clearly working practitioners - one has contributed to the OWASP LLM Top 10 channel and has hands-on RPM/NPM experience, and the group demonstrates real depth on threat modeling - but there are no external guests, and the format limits the range of hard-earned practitioner knowledge on display.
Averaged across 1 recently scored episode, with cited evidence.
The STRIDE and NPM discussions contain genuine practitioner insights - prompt injection as a vector not a threat, deterministic controls around non-deterministic AI, and the C undefined-behavior analogy - but they are buried under extended tangents about wheat color schemes, Emacs history, and Oregon Trail that consume a significant fraction of the 59 minutes. The insight-to-filler ratio is poor.
“prompt injection is not a threat by itself...it's a vector. Uh, it's a way to get there. It's something that looks bad, but it's not by itself a threat because it's not doing things”
“the behavior of the AI may be non deterministic, but the controls that you put in it are deterministic. And those controls, they tie to specific scenarios of failure”
The core contrarian thesis - that STRIDE is not broken, just misapplied, and that 'cross-context contamination' is just a renamed version of decades-old buffer-clearing hygiene - is a genuinely fresh and defensible take against the prevailing 'everything is new' narrative. The C undefined-behavior parallel is clever, but the episode doesn't develop these angles far enough to be truly standout.
“how long have we known about the need to clear your buffers before you start a new session of anything that runs in a loop? How long have we known about, uh, mining swap files for passwords?”
“There are things in C that have undefined behaviors...you have. You have undefined defined behavior in the technology and you account for it. Right? That's stride.”
Three co-hosts who are clearly working practitioners - one has contributed to the OWASP LLM Top 10 channel and has hands-on RPM/NPM experience, and the group demonstrates real depth on threat modeling - but there are no external guests, and the format limits the range of hard-earned practitioner knowledge on display.
“I had the chance to go into the channel that's discussing prompt injection itself as a threat and put in there a lot of what I've been putting here on the podcast for a long time”
“databases have parole controls and have had them for what, 30 years? Because that stuff works.”
A handful of concrete data points appear - the 2% npm figure, Let's Encrypt's 7 billion certificates, five named founding sponsors, STRIDE-LM, the Shai Hulud worm vector - but many are sourced from articles being read aloud rather than personal experience, and the STRIDE discussion stays largely abstract without named company examples or measured outcomes.
“Only 2% of npm packages need install scripts to function”
“There were five, five original sponsors. Mozilla, eff, Cisco, Akamai, and Ident Trust”
When the hosts engage the STRIDE article directly there is real back-and-forth and productive pushback - Chris challenges the healthcare example, Matt plays devil's advocate on likelihood vs. categorization - but the conversation repeatedly derails into unproductive banter (wheat, Emacs, Oregon Trail, GitHub acquisition confusion) that eats time without building on prior points.
“Why wouldn't you consider AI in that threat model? Like, this is a strange example.”
“He had something, but he completely went off the rails.”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-security-table" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-security-table/badge.svg" alt="Ranked #151 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Security Table's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.