The Art of Security

The Art of Security

Fortra
Држава Сједињене Државе
Језик EN
Епизоде 16
Последња 16.09.2026

Cybersecurity isn't an exact science. It's where art and science meet, informed by experience, tested in battle and reimagined to tackle evolving adversaries. In The Art of Security, Josh Davies and Tyler Reguly break down how security actually works in practice. From zero-day exploits and emerging threats to rethinking long-standing best practices, they explore what holds up — and what doesn't — in today's rapidly changing landscape. Each episode delivers practical insights, informed perspectives, and real-world context to help security professionals and tech enthusiasts stay ahead of evolving threats and build smarter, more resilient defenses.

Епизоде

  • Security Theater: Feeling Safe vs. Being Secure 16.09.2026 33мин
    What happens when cybersecurity programs prioritize visible activity over meaningful risk reduction? Security theater can reassure executives and end users, but that reassurance becomes dangerous when dashboards, checkbox compliance, and inflated metrics distract teams from the controls that actually reduce exposure. In this episode of The Art of Security, Josh Davies and Tyler Reguly examine the line between communicating security effectively and merely performing it. They challenge conventional thinking about security metrics, product marketing, threat hype, compliance, and the pressure to make security programs look productive. Key takeaways Why activity metrics such as alerts triaged, vulnerabilities patched, and detections created may not reflect improved security How threat hype and named vulnerabilities can redirect limited resources away from higher-priority risk Why security visibility and clearly assigned asset ownership provide a stronger foundation for meaningful measurement How security teams can demonstrate control effectiveness without relying on checkbox compliance or misleading ROI calculations Security should create confidence because controls are validated, assets are monitored, and responsibilities are clear, not because a dashboard looks impressive. 👍 Like the video if the discussion challenged how you measure security 💬 Tell us which cybersecurity metrics your team finds genuinely useful 🔔 Subscribe for practical conversations with cybersecurity practitioners and researchers
  • CalPhishing: When Calendar Invites Become the Lure 02.09.2026 37мин
    Calendar invites have become part of the trusted infrastructure of daily life, and attackers are taking advantage. In this episode, the team examines the resurgence of CalPhishing, an attack technique that uses legitimate calendar workflows, HTML content, attachments, spoofed organizers, and trusted platforms to evade defenses and compromise accounts. Fortra security engineer and FIRE team member Daud Jawad joins hosts Josh Davies and Tyler Reguly to break down the calendar phishing techniques reaching users today. They explore why these attacks can bypass traditional email security controls, how trusted workflows lower users' defenses, and why organizations may need to reconsider how they process and test calendar invitations. Key takeaways How attackers use calendar invite bodies, HTML attachments, spoofed organizers, and legitimate vendor infrastructure to deliver phishing lures Why CalPhishing can evade email authentication, filtering, browser protections, and other established security controls How calendar-based attacks can target credentials, session tokens, OAuth consent, device codes, and trusted internal workflows How organizations can reduce exposure through calendar processing controls, user education, cross-channel verification, and calendar-based phishing simulations Read Daud's related blog on Fortra.com Don't let the next threat sneak onto your calendar. Subscribe to The Art of Security podcast.
  • AI-Powered Red Teaming: Where Automation Works and Where It Falls Short 19.08.2026 32мин
    AI can accelerate red team operations, but how much autonomy is too much when production systems and sensitive data are at stake? In Episode 13 of The Art of Security, co-host Josh Davies speaks with Pieter Ceelen of Fortra's Outflank and Cobalt Strike red teams about the opportunities and risks surrounding AI-powered red teaming. They examine where AI can strengthen adversary simulation, why fully autonomous testing demands caution, and how rules of engagement must evolve as AI becomes part of offensive security operations. The conversation explores: Where AI can support reconnaissance, vulnerability research, initial access, reporting, and post-exploitation analysis Why human oversight remains critical in sensitive and production environments How red teams can balance automation, operational risk, and potential reward Whether AI will change the skills needed by the next generation of penetration testers How AI could reshape vulnerability discovery, zero-day research, and the ongoing contest between attackers and defenders Listen to the full episode for a practical perspective on using AI to advance red team operations without losing sight of judgment, accountability, or risk.
  • Lights, Camera, Cyberattack: What Hollywood Gets Right and Wrong About Hacking 05.08.2026 39мин
    Hollywood can turn a cyberattack into glowing graphics, frantic typing, and total system control in seconds. But beneath the technical nonsense, hacker movies sometimes capture something real about cybersecurity. In this episode of The Art of Security, co-hosts Josh Davies and Tyler Reguly revisit hacker movies and shows including Hackers, WarGames, Sneakers, Mr. Robot, The Matrix Reloaded, and more. They examine what Hollywood gets right, what it gets spectacularly wrong, and the real-world security lessons hiding behind the drama. The conversation explores: Why Hackers remains a cybersecurity cult classic Whether hackers can really control traffic lights and broadcasts How real security tools and techniques appear on screen Why fictional hackers have inspired generations of practitioners Are hacker movies helping audiences understand cybersecurity, or have they been teaching us the wrong lessons all along? Listen now, then tell us: Which hacker movie gets cybersecurity right, and which one gets it completely wrong? Make sure to subscribe now so you don't miss any episodes!
  • AI Governance in Action: How to Secure AI Without Slowing Innovation 22.07.2026 35мин
    Your AI has access. But does It have too much? AI can help organizations move faster, automate work, and unlock new opportunities. But when AI systems can access sensitive data, connect to business tools, or take actions on a user's behalf, governance becomes an operational security priority. In this episode of The Art of Security, co-host Josh Davies speaks with Gina Cardelli, Principal Security Strategist at Fortra, about how organizations can adopt AI without losing visibility or control. They examine what recent AI security incidents can teach businesses about excessive permissions, exposed infrastructure, third-party tools, shadow AI, and the risks of moving too quickly. Gina also explains how threat modeling, continuous monitoring, least privilege, and cross-functional AI councils can help organizations understand an AI system's potential blast radius and manage risk as its capabilities evolve. Listen to learn: Why AI governance cannot be treated as a one-time policy exercise How to threat model AI use cases before deployment Why continuous monitoring is essential for AI systems and agents How third-party AI tools can introduce data and supply chain risks What organizations can do about shadow AI Why many AI security failures still begin with familiar vulnerabilities How to introduce practical controls without bringing AI innovation to a halt AI governance doesn't have to be perfect on day one. But organizations need to understand how AI is being used, what it can access, and what could happen if something goes wrong. AI security is evolving quickly. Subscribe to The Art of Security for more conversations that help you keep pace.
  • Not Curious? Cybersecurity Isn't the Career for You — A Student's Honest Take 08.07.2026 47мин
    Is cybersecurity really facing a skills shortage or are businesses just unwilling to train the next generation? In episode 10 of The Art of Security, Josh Davies and Tyler Reguly are joined by Dema Gorkun, cybersecurity student at MacEwan University, leader of the Student Ethical Hacking Club, and OWASP collaborator. Dema shares a candid student's-eye view of what today's cybersecurity education gets right, where it falls short, and how curiosity, home labs, and community involvement matter more than any resume. From vibe coding pitfalls to phishing projects that triggered emergency CEO meetings, this conversation explores the future of cybersecurity talent — and how to stand out in an AI-driven hiring landscape. Whether you're a student, a hiring manager, or a seasoned practitioner wondering how to mentor the next wave of talent, this episode offers a refreshing, unfiltered look at how we create the security artists of the future. 🎧 Don't miss an episode — subscribe to The Art of Security today
  • What Canada's Bill C-8 Means for Cybersecurity 01.07.2026 4мин
    Canada's Bill C-8 has received Royal Assent. But what does that actually mean for cybersecurity teams, critical infrastructure operators, telecommunications providers, and vendors selling into Canadian organizations? In this bonus episode of The Art of Security, Brent Arnold of INQ Law about the impact of Bill C-8, also known as An Act Respecting Cyber Security. They discuss the law's focus on telecommunications security, critical cyber systems, minimum cybersecurity requirements, incident preparedness, and the growing importance of supply chain risk. This bonus conversation follows episode 9, After the Breach: Ransomware, Data Loss, and the Legal Fallout. Subscribe to The Art of Security so you don't miss future episodes on cybersecurity, data breaches, legal risk, and incident response.
  • After the Breach: Ransomware, Data Loss, and the Legal Fallout 24.06.2026 45мин
    What really happens after a data breach? In this episode of The Art of Security, hosts Josh Davies and Tyler Reguly are joined by Brent Arnold of INQ Law to unpack the legal, operational, and business fallout that follows a breach. From ransomware negotiations and breach reporting obligations to data loss, regulatory risk, and recovery planning, Brent shares what organizations need to know when a cyber incident becomes a legal crisis. The conversation also explores why preparation matters, how process failures often matter as much as technical ones, and why knowing where your sensitive data lives is critical before an incident happens. If you work in cybersecurity, risk, compliance, or business leadership, this episode offers a practical look at what comes next when data is exposed, stolen, or held hostage. Listen now for practical insights on ransomware response, legal risk, and recovery.
  • Learning Cybersecurity: Education, Experience, and AI 10.06.2026 44мин
    Cybersecurity is one of the few professions where the learning never stops. New technologies, evolving threats, and the rapid rise of AI constantly reshape what security professionals need to know. In this episode of The Art of Security, Josh Davies and Tyler Reguly sit down with Dr. Mansour Alqarni of Fanshawe College to explore the current state of cybersecurity education and what it takes to build the next generation of security professionals. They discuss the cybersecurity skills gap, the role of colleges and universities in preparing students for the workforce, the balance between theory and hands-on experience, and whether cybersecurity should be considered an entry-level career path. The conversation also dives into the impact of AI on security operations, hiring, and education and why critical thinking and continuous learning may be more important than ever. Whether you're a student considering a career in cybersecurity, a hiring manager evaluating talent, or a seasoned practitioner looking to stay ahead of industry changes, this episode offers valuable insights into how cybersecurity professionals are trained, developed, and prepared for the challenges ahead. Topics covered: • The different paths to a cybersecurity career • Teaching security in the age of AI • Practical experience vs academic theory • AI's impact on SOC analysts and security teams • The importance of soft skills and trust Subscribe now for more expert insights and security conversations.
  • Named Vulnerabilities, CVEs & the Problem With Security Hype 27.05.2026 37мин
    Why do vulnerabilities like Heartbleed, PrintNightmare, and Log4Shell get memorable names while thousands of other CVEs go unnoticed? In this episode of The Art of Security, Josh Davies and Tyler Reguly debate whether named vulnerabilities help cybersecurity awareness or create dangerous hype cycles. From CVE identifiers and responsible disclosure to media sensationalism and "boy who cried wolf" fatigue, the conversation explores how branding vulnerabilities impacts SOC teams, executives, researchers, and the wider industry. A must-watch for SOC analysts, threat researchers, vulnerability management teams, CISOs, business leaders, and cybersecurity practitioners who want to understand how vulnerability naming and security hype shape real-world response, risk perception, incident prioritization, and executive decision-making.
  • Supply Chain Compromise: Trust Is the Target 13.05.2026 31мин
    We're told to patch fast, trust updates, and rely on the software ecosystems that power modern business. But what happens when that trust becomes the attack vector itself? In this episode of The Art of Security, Josh Davies and Tyler Reguly dive into the growing world of software supply chain compromise — from malicious open source packages and compromised dependencies to sleeper-agent style attacks that quietly infiltrate trusted projects for years before striking at scale. Josh and Tyler unpack how attackers are weaponizing trust, automation, and AI-assisted development to spread compromise at scale, while exploring practical defenses and why today's "patch immediately" mindset may no longer be enough. When trust is the delivery mechanism, every dependency becomes part of your attack surface. Make sure to subscribe to the podcast!
  • The Art of Collective Defense 29.04.2026 38мин
    When one organization gets breached, attackers don't just win — they get better. In this episode of The Art of Security, we explore a powerful idea: Cybersecurity isn't a solo fight but a shared one. And when defenders collaborate, everyone gets stronger. Josh Davies and Tyler Reguly are joined by Jennifer Quaid and Bob Gordon from the Canadian Cyber Threat Exchange (CCTX) to break down what effective collaboration really looks like in practice. From real-world intelligence sharing to cross-industry cooperation, they unpack how organizations can turn threat data into actionable defense and why keeping insights siloed only benefits attackers. You'll learn: Why "when one wins, we all win" is more than just a slogan How intelligence sharing improves detection, response, and resilience The role of trust, community, and diverse perspectives in cybersecurity If you think cybersecurity is just about tools and technology, this conversation will challenge that assumption. Because in today's threat landscape, defense is a team sport. Subscribe for more real-world insights on cybersecurity, threat intelligence, and the decisions that shape effective defense.
  • Stop Patching Everything: Rethinking Vulnerability Management with RSnake 15.04.2026 32мин
    In this episode of The Art of Security, Josh Davies and Tyler Reguly take a hard look at vulnerability management (VM) — one of the oldest and most widely adopted practices in cybersecurity — and ask a simple question: are we doing it wrong? Joined by special guest Robert "RSnake" Hansen, we unpack the critical differences between vulnerability management and patch management, and explore why treating them as the same thing may be holding organizations back. From the overwhelming volume of CVEs to the limitations of scoring systems like CVSS, this conversation challenges conventional thinking. Why do so few vulnerabilities actually lead to real-world breaches or business loss? And if that's the case, why are security teams still trying to patch everything? This episode is all about cutting through the noise and focusing on what truly reduces risk. If you've ever felt overwhelmed by vulnerability backlogs or questioned whether your VM program is actually making an impact, this conversation will challenge your assumptions — and give you a new lens to think about security.
  • Trust No One (Especially on April Fools) 01.04.2026 33мин
    It's April 1st which means nothing can be taken at face value. In this special April Fools' episode of The Art of Security, Josh Davies and Tyler Reguly dive into the long history of pranks in tech and cybersecurity — from spaghetti trees and RFC jokes to Google's legendary gags. But this isn't just a nostalgia trip as Tyler and Josh discuss humor, history, and have a serious conversation about trust, authority, and responsibility in cybersecurity today. This episode blends humor, history, and a serious conversation about trust, authority, and responsibility in cybersecurity today. Whether you're in security, tech, or just love a good prank, this episode will make you think twice before clicking anything on April 1st. Like, subscribe, and share if you enjoy the show!
  • The Art of the Adversary: Scripted Sparrow 18.03.2026 34мин
    Business email compromise is getting smarter, and Scripted Sparrow is proving it. Discover how the Scripted Sparrow threat group is running one of the most prolific BEC campaigns targeting organizations worldwide. In this episode of The Art of Security, we're joined by Fortra cybersecurity researcher John Wilson who breaks down how Scripted Sparrow executes highly targeted social engineering attacks that trick organizations into paying fraudulent invoices. Instead of traditional phishing, this group uses spoofed email conversations, fake executive coaching invoices, and carefully crafted tactics to bypass security controls and manipulate employees. Understanding how attackers think is the first step to stopping them. Make sure to subscribe to The Art of Security for more insights on cyber threats, adversary tactics, and real-world security strategies.
  • Who Watches the Watchman? 04.03.2026 31мин
    In this episode, Tyler Reguly and Josh Davies dig into a tough but necessary question: Who's keeping an eye on the people who keep us secure? They break it down across three fronts — security vendors, internal security teams, and third-party providers — exploring what happens when the protectors themselves become the risk. From vendor breaches that ripple across customers to insider threat cases involving security pros with too much unchecked access, the conversation highlights the real-world tension between trust and oversight. Josh and Tyler also discuss what truly makes a security partner trustworthy, along with the growing role of AI in security operations. The takeaway? In cybersecurity, it always comes back to one principle: Trust but verify. 🔔 Don't forget to subscribe!
  • The Art of Cyber Hygiene: Building Security from the Ground Up 04.03.2026 29мин
    In our first episode, Josh Davies and Tyler Reguly dive into the foundational concept of cyber hygiene. What are the true "basics of the basics?" Is it vulnerability management and hardened configurations? Is it integrity monitoring as your digital smoke alarm? Or does modern resilience demand identity controls and layered monitoring from day one? Through sharp debate, real-world analogies (from Lego foundations to kitchen fires), and practical insight, they explore what organizations must get right before building anything else. If you're launching a security program or rethinking your foundations, this episode challenges you to ask: Are your basics strong enough to withstand today's adversaries? Don't forget to subscribe!
  • The Art of Security with Tyler Reguly 03.03.2026
    After 10 years of asking, Tyler Reguly is finally stepping behind the mic for The Art of Security. Join Tyler and his cohost Josh Davies as they talk cybersecurity, creativity, and why protecting the digital world is as much an art as it is a science, plus a few laughs along the way. 🔔Don't forget to subscribe!
  • The Art of Security with Josh Davies 03.03.2026
    Mert Josh Davies, one half of The Art of Security. Join Josh and his co-host Tyler Reguly for fresh perspectives, healthy debate, and practical ideas you can actually apply to your cybersecurity strategy. 🔔Don't forget to subscribe! 
  • Get to Know Josh and Tyler 02.03.2026 17мин
    In this pre-launch episode, hosts Josh Davies and Tyler Reguly pull back the curtain on their journeys into cybersecurity, sharing the experiences, pivots, and passion that shaped their careers and perspectives. Together, Josh and Tyler lay the groundwork for the podcast, establishing not just their credentials, but the real-world experiences that inform their perspectives. This episode sets the foundation for future conversations, giving listeners a clear sense of the expertise, authority, and practical insight they bring to the evolving world of cybersecurity. Don't forget to subscribe!

Популаран у

Овај подкаст се појављује и у подкаст листама ових земаља.