Prabh Nair

Prabh Nair

Prabh Nair
ประเทศ อินเดีย
แนวเพลง เทคโนโลยี
ภาษา EN
จำนวนตอน 150
ล่าสุด 21.09.2026

Prabh Nair hosts a cybersecurity podcast covering cyber risk, ransomware, incident response, SOC operations, GRC, AI security, threat intelligence, digital forensics, ISO 27001, CISSP, CISM, and security leadership. The show is aimed at SOC analysts, auditors, cybersecurity professionals, students, and business leaders. Each episode delivers simple explanations, practical lessons, and real-world examples to help listeners stay ahead in the fast-changing cyber world.

ตอน

  • How to Build a Cybersecurity Program from Scratch | CISO Transformation Playbook 21.09.2026 1ชม. 13นาที
    Master Cybersecurity leadership with insights from Ilyas Kooliyankal, Cyber Security Leader of CyberShelter, on navigating modern industry challenges.Ilyas Kooliyankal joins Prabh Nair to discuss what it takes to succeed in the field today. With nearly three decades of experience across enterprise technology and financial services, Ilyas outlines the essential traits required for those looking to build a successful CISO career.We break down the core components of professional growth, emphasizing that knowledge, understanding, and common sense are just as critical as technical aptitude. The conversation also explores how to effectively prioritize security gaps when managing complex systems, providing a clear roadmap for GRC professionals aiming to advance their expertise.Building a cybersecurity program from scratch is not about buying more tools, copying policies, or implementing every security control available.https://www.linkedin.com/in/illyas/It starts with understanding what the business is trying to protect, how much risk it is willing to accept, and which security gaps create the greatest business impact.In this podcast, Prabh speaks with Illyas, a cybersecurity leader with nearly three decades of experience, about the practical process of building and transforming an enterprise cybersecurity program.The conversation covers:How to define information security risk appetiteWhy risk appetite should come before security strategyHow to perform a business-focused security gap assessmentHow to prioritize critical, high, medium, and low risksWhy externally exposed risks may need immediate actionHow to use existing controls before asking for new technologyHow to link cybersecurity investments to business objectivesHow to justify cybersecurity budgets to managementHow to communicate technical cyber risk in business languageHow to balance security with cloud, SaaS, AI, and digital transformationHow to build an executive cybersecurity dashboardHow to convert risk assessment into a strategic roadmapHow to establish the security operating model, roles, and responsibilitiesHow maturity targets should connect back to risk appetiteThe difference between KRIs and longer-term risk metricsSubscribe for weekly technology infrastructure breakdowns and comment below on what leadership topic you want covered next.#CISO #CyberSecurity #CyberRisk #RiskManagement #GRC #SecurityStrategy #CyberSecurityLeadership #SecurityArchitecture #RiskAppetite #CyberGovernance #CISOMindset #CoffeeWithPrabh
  • How to Investigate Akira Ransomware : Practical Insight 17.09.2026 40นาที
    Join cybersecurity experts Mr. Abhijeet and Mr. Chirayu in this enlightening podcast as they unravel the complexities of the Akira ransomware. Dive deep into their step-by-step investigation, uncovering the critical insights that led to the identification, mitigation, and protection strategies against this formidable cyber threat.https://www.linkedin.com/in/abhijit-tripathy-a84257a3/?originalSubdomain=inhttps://www.linkedin.com/in/chirayu-mahajan-bb1a974a/In this video, our speakers share exclusive documents and logs instrumental in dissecting the ransomware’s mechanisms. Gain practical knowledge on how these seasoned professionals navigated the challenges posed by Akira, developing robust defense tactics to safeguard organizational assets.🚀 In This Episode, You Will Discover:Dual Extortion Tactics: The double-edged threat posed by Akira ransomware and how it leverages victim data for ransom.Hybrid Encryption Techniques: Unpacking the encryption strategies that make Akira a formidable foe.Living Off The Land Attacks: Insights into how attackers use legitimate tools for malicious purposes.Reflective Injection Attacks: A deep dive into how Akira bypasses conventional detection methods.The Shadowy World of Initial Access Brokers: Understanding the brokers that provide gateways for ransomware attacks.PowerSploit's Role: Exploring how the PowerShell Mafia’s toolkit aids in the spread of Akira.Reconstructing RDP Bitmap Cache: A look at how investigators piece together user actions from remote desktop protocol data.Mr. Abhijeet and Mr. Chirayu not only share their riveting journey uncovering Akira but also arm you with the knowledge to identify, mitigate, and shield your organization against such sophisticated cyber threats.🌐 Stay Safe in the Cyber World: Whether you’re a cybersecurity rookie or a seasoned professional, this podcast is packed with invaluable insights that will elevate your understanding and preparedness against cyber threats.#CyberSecurity #AkiraRansomware #InfoSec #RansomwareInvestigation #DataProtection #ThreatIntelligence #CyberAttack #DigitalDefense #TechInsights #PowerSploit #InitialAccessBroker #DualExtortion #HybridEncryptionPart 2https://youtu.be/PUdvXHpKNjE✨ Don’t forget to subscribe for more exclusive content, and hit that bell icon so you never miss out on cybersecurity insights. Like, share, and comment below with your thoughts or questions for our experts!Playlist CISO Talkhttps://www.youtube.com/playlist?list=PL0hT6hgexlYz1LzzrLwTiSt5d_kO_0QsEPlaylist Network Securityhttps://www.youtube.com/playlist?list=PL0hT6hgexlYzX6AWwcyDbAZQUKYJL2MdtGRC Interview Questionshttps://youtu.be/4TyfNtFGAC4Internal Auditor Playlist https://www.youtube.com/playlist?list=PL0hT6hgexlYyNWBcGYfabwumCr0GKmLWvHow to make career progression post #isc2 and #isaca https://www.youtube.com/watch?v=PT0fnCWzAFA&pp=ygUJZ3JjIHByYWJoHow to make career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=102s&pp=ygUJZ3JjIHByYWJoHow to Build PIMShttps://www.youtube.com/watch?v=IwAseU4ZmuQHow to Implement 27001 in an organization https://www.youtube.com/watch?v=sQqJH2naU6IHow to conduct PIAhttps://www.youtube.com/watch?v=z1BD7exH2Ow&t=774sHow to Make an career in GRChttps://www.youtube.com/watch?v=_S4t9S5N4Ts&t=7sTelegram Grouphttps://t.me/InfoseclearningStart your career in cybersecurity with free resources https://lnkd.in/g89gxkzc Cybersecurity Career: How to Make a Career in Cybersecurity 2022 https://lnkd.in/gCGBnRM7Pentesting Career https://lnkd.in/gQYenKYdTelegram Group Linkhttps://t.me/InfoseclearningCybersecurity Guidehttps://www.youtube.com/playlist?list=PL0hT6hgexlYwdYBW6yqUQMuRqvABiQPXk#ransomware #cybersecurity #infosec #hacking
  • How to Prepare for CGRC Certification in 2026 14.09.2026 42นาที
    Many professionals come from ISO 27001, audit, compliance, or traditional cybersecurity backgrounds. But CGRC is strongly aligned with NIST publications, system authorization, security and privacy control assessment, and the Risk Management Framework lifecycle.In this podcast episode, Prabh speaks with Aamir about his CGRC preparation journey, the difference between ISO-based GRC thinking and NIST-based GRC thinking, and why CGRC is useful for professionals working in governance, risk, compliance, security authorization, FedRAMP, control assessment, and AI governance.In this episode, we discuss:What CGRC certification isWhy CGRC requires NIST-based thinkingDifference between ISO-based GRC and NIST-based GRCWhy NIST RMF is central to CGRC preparationHow CGRC is different from CISSP, CCSP, CISA, CRISC and ISO 27001Why system authorization boundaries matterWhy control implementation and assessment are importantHow compliance becomes a lifecycle processWhy POA&M is important in risk assessment and remediationHow FISMA, FedRAMP, NIST, COBIT and ISO connect in GRC thinkingWhy CGRC is relevant for security and privacy integrationHow CGRC connects with AI governance and algorithmic riskKey NIST publications for CGRC preparationHow to prepare using the CBK and structured training materialsWhy candidates must think like a risk governance advisorAamir also explains that CGRC professionals should be able to support the full security lifecycle:Define authorization boundariesIdentify and categorize systemsSelect and implement controlsAssess control effectivenessSupport authorization decisionsMaintain continuous monitoringTrack remediation through POA&MAlign compliance with business and mission risk
  • Inside the Ransomware War Room | Human Side of Cybercrime with Jon DiMaggio 10.09.2026 41นาที
    Ransomware is not only a technical problem.Behind every ransomware attack, there are people — operators, affiliates, initial access brokers, negotiators, developers, money launderers, and criminal leaders making decisions under pressure.In this podcast episode, Prabh speaks with Jon DiMaggio, cybercrime investigator, founder and principal researcher at Arkham Cyber, and author of The Art of Cyber Warfare, about the human side of ransomware operations.Jon explains why organizations make a major mistake when they treat ransomware only as malware, encryption, indicators of compromise, backups, and recovery.The real adversary is human.To defend better, security teams must understand attacker motivation, fear, ego, trust, negotiation behavior, relationships, mistakes, and internal conflicts.In this episode, we discuss:Why ransomware is not only a technical problemWhy understanding the human adversary mattersHow ransomware groups operate behind the scenesThe role of initial access brokersHow affiliate teams work inside ransomware-as-a-service ecosystemsHow ransomware operators manage extortion and negotiation pressureWhy human intelligence matters in cybercrime investigationHow dark web research helps reveal attacker behaviorHow Jon investigated the LockBit ransomware groupWhy attacker psychology, ego, trust, and internal conflict matterHow technical intelligence and human intelligence work togetherHow MITRE ATT&CK, Cyber Kill Chain, and Diamond Model help defendersWhy technical indicators alone are not enoughHow ransomware negotiation patterns can manipulate victimsHow law enforcement and private-sector intelligence can support disruptionHow AI may increase the speed, scale, and automation of ransomware attacksWhy defenders must combine telemetry, threat intelligence, and human behavior analysisLinkedin Profilehttps://www.linkedin.com/in/jondimaggio/https://www.amazon.in/Art-Cyberwarfare-Investigators-Ransomware-Cybercrime-ebook/dp/B09BKLRH8P#Ransomware #ThreatIntelligence #CyberCrime #DarkWeb #LockBit #IncidentResponse #SOC #CISO #CyberSecurity #HumanIntelligence
  • How to Crack JEE: AIR 59 Shares Study Routine, Mistakes and College Advice 07.09.2026 33นาที
    JEE preparation is not only about studying for long hours.It is about discipline, consistency, the right strategy, emotional control, mock test analysis, and making smart decisions during the final phase of preparation.In this podcast, Prabh speaks with Ishaan Singh, who achieved All India Rank 59 in JEE, about his preparation journey, study routine, coaching experience, final-week strategy, college selection, and the skills students should build beyond academics.Ishaan shares practical advice for JEE aspirants and parents who are trying to understand what really matters during preparation and after results. In this episode, we discuss:Ishaan’s JEE preparation journeyHow he built a disciplined study routineHow to manage school, coaching, self-study and personal activitiesWhy focused study blocks and regular breaks matterWhy avoiding social media helped him stay focusedHow to analyze mock tests and identify weak areasWhat to revise in the final week before JEEWhy previous year questions are importantWhy students should avoid difficult new problems just before the examWhy handwritten notes can improve learningRole of coaching in structure, testing and peer supportWhy students should not constantly compare themselves with othersHow to handle setbacks during preparationHow to choose a good engineering college beyond rankingsWhy students should speak with current students and alumni before choosing a collegeImportance of curriculum quality, peer group, internships, research exposure and campus cultureGap between college education and industry skillsWhy skills matter beyond college tagsHow students from non-CSE branches can still build careers in software and technologyHow AI tools can support learning when used correctlyOne of the strongest takeaways from this session:#JEE #JEEPreparation #Engineering #IIT #StudentLife #CareerGuidance #CollegeSelection #Education #Parents #CoffeeWithPrabh
  • Privacy Ops Masterclass | Building Trust Across Product, AI and Security 03.09.2026 51นาที
    Privacy does not fail only because organizations do not have policies.Many times, privacy fails because it comes too late.After the product is designed.After the code is written.After the vendor is onboarded.After the data flow is already live.After the AI use case has already started using personal data.In this podcast/session, Prabh discusses the practical meaning of Operationalising Privacy across Product, AI and Security.This session focuses on how privacy can move from paperwork to real execution inside organizations.We discuss why privacy by design fails when privacy is reviewed only after design is complete, and why privacy must be embedded into product development, engineering workflows, AI programs, security reviews, data-flow mapping, risk scoring, and day-to-day business decisions.https://www.linkedin.com/in/devika-subbaiah-infosec/In this session, we cover:- Why privacy should not appear only at the end of product design- Why privacy by design must be embedded before code is written- What Privacy Operations really means- Difference between privacy policy and privacy operations- Why DPO oversight and Privacy Ops execution are not the same role- How product, security, legal, business and privacy teams should work together- Why data flow diagrams should be living maps, not one-time documents- How vendor changes, retention changes and subprocessors affect privacy risk- Why privacy risk should not be viewed only through a legal lens- Why privacy risk and security risk must both be assessed- How dual-axis risk scoring can help evaluate organizational risk and individual harm- How an Activity-First Data Model can reduce repeated privacy documentation- How RoPA, DPIA, TIA, LIA and consent records can be generated from a common activity record- Why privacy must scale across products, functions and AI programs- Why every privacy framework field ultimately represents a real person and a real riskThe key message is simple:Privacy that only works on the day it was checked is not privacy.Organizations need privacy systems that are operational, scalable, evidence-driven, and embedded into daily decision-making.Watch the full session and comment below:What is the biggest privacy challenge in your organization — product design, AI usage, vendor risk, data mapping, privacy operations, or DPO execution?#PrivacyOps #DataProtection #PrivacyByDesign #AIGovernance #CyberSecurity #GRC #DPDP #GDPR #ProductSecurity #PrivacyEngineering #CoffeeWithPrabh
  • Threat Modeling for Agentic AI: Stop Treating Agents Like APIs 31.08.2026 53นาที
    Agentic AI is changing the way applications are designed, tested, deployed, and secured.Traditional application security focuses on APIs, authentication, authorization, databases, code, sessions, and technical attack surfaces.But Agentic AI introduces a different challenge.A user may not need technical knowledge to influence the system.A simple natural language prompt can make an AI agent classify intent, call a tool, retrieve data, generate a response, trigger a workflow, or influence a business decision.In this podcast episode, Prabh speaks with Akansha about Threat Modeling for Agentic AI Systems, using a practical customer support chatbot architecture as the case study.The architecture discussed includes:Classifier agentResponder agentQA reviewer agentHuman approval processRetrieval databaseTool integrationsLogging and monitoringRefund workflowThird-party integrationsThe session explains how a customer request flows through different agents, how intent is classified, how responses are generated, how refund requests are reviewed, and why human approval is important for high-risk financial actions.Content Reference https://github.com/smartdevil09/AI-Security-Professional-Roadmap/blob/main/AI%20security%20concepts/Threat%20Modelling%20Agentic%20Architecture.pdfLinkedin Profilehttps://www.linkedin.com/in/akesharwani/In this episode, we discuss:How Agentic AI differs from traditional application securityWhy prompts and natural language interactions create new risksWhy threat modeling should happen before production deploymentWhy stakeholder engagement is criticalHow to understand the business problem before identifying threatsHow to create an asset inventory for AI systemsHow to identify business assets and AI assetsHow to prepare data flow diagrams for multi-agent systemsHow to define trust boundaries between users, agents, tools, databases, and third partiesWhy refund workflows need stronger approval controlsWhy human approval is required for critical financial transactionsWhy logging and monitoring must be carefully designedHow to avoid logging sensitive PII dataHow attackers may exploit AI agents using prompt injectionHow AI agents may be manipulated into unauthorized actionsHow traditional AppSec controls still matter in Agentic AI systemsHow third-party Agentic AI systems should be assessedWhat documentation should be requested from vendorsHow to use STRIDE, MITRE ATLAS, OWASP LLM Top 10, CVE, and CWE for threat enumerationHow to evaluate likelihood, impact, business risk, and compliance riskWhy threat modeling must be continuously updated as architecture and threats changeAkansha also explains that threat modeling Agentic AI is not a simple automated checklist activity.It requires business context, stakeholder interviews, architecture understanding, asset inventory, data flow mapping, trust boundary analysis, risk assessment, guardrail design, logging, monitoring, validation, and continuous review.#AgenticAI #AISecurity #ThreatModeling #AppSec #AIGovernance #OWASP #MITREATLAS #CyberSecurity #GRC #CoffeeWithPrabh
  • The New Frontline: Why Hospitals Are The Biggest Cyber Targets 27.08.2026 1ชม. 1นาที
    Healthcare cybersecurity is not only about protecting networks, servers, applications, or medical devices.Shantanu https://www.linkedin.com/in/shantanushastrish/In this podcast episode, Prabh speaks with Shantanu about healthcare cybersecurity, connected medical devices, hospital security, medical device threat modeling, security by design, cyber resilience, and AI in healthcare.Modern hospitals are now highly interconnected technology ecosystems. Patient monitors, scanners, ultrasound devices, laboratory systems, hospital applications, cloud platforms, networks, and AI-enabled tools exchange information to support faster diagnosis and better treatment decisions.But this connectivity also increases the cybersecurity risk.In healthcare, downtime is not only a business issue.Learn how healthcare cybersecurity protects connected medical devices from threats. Understand the core security measures hospitals use today.Healthcare cybersecurity is becoming a critical priority as hospitals integrate more digital infrastructure. In this discussion, Lead Cybersecurity Engineer Shantanu and CISO Prabh Nair break down the complexities of maintaining medical device security within modern hospital networks. They examine the specific technological advancements currently shaping the industry and the inherent risks that come with them.This conversation is essential for IT professionals and healthcare administrators looking to secure connected medical devices against evolving vulnerabilities. You will gain a clear perspective on the strategies required to implement robust hospital network security, ensuring patient safety remains the top priority. By analyzing these real-world security measures, you will be better equipped to identify potential gaps in your own organizational protocols.Subscribe for weekly cybersecurity breakdowns, and comment below on which healthcare security topic you want us to cover next.
  • AAISM Practice Questions Masterclass | Think Like an AI Security Manager 24.08.2026 1ชม. 3นาที
    AAISM exam preparation is not only about memorizing AI terms.It is about learning how to think like an AI security manager.In this session, I explains AAISM-style practice questions using a practical, manager-focused approach. The focus is on understanding how to choose the best answer when multiple options look correct.The session starts with an AI loan approval case study and connects it with AI governance, AI risk management, AI technologies and controls, enterprise monitoring, and continuous improvement.The key message is simple:AAISM is about governance, risk, controls, evidence, and accountability.In this session, we cover:- How to approach AAISM questions- How to think like an AI security manager- Why governance comes before AI deployment- Why business risk comes before technology- Why AI inventory is required before risk categorization- How AI risk appetite and risk tolerance differ- How to choose controls based on risk- Why data governance is the foundation of AI security- How to handle bias, fairness, transparency, and explainability questions- Why human oversight matters for high-impact AI decisions- How to evaluate vendor AI risk- Why independent assurance matters for third-party AI platforms- How to identify AI exam traps- How to eliminate close distractors- How to connect AI risks with controls, owners, and evidence- How to answer questions on prompt injection, data poisoning, model inversion, model drift, hallucination, and deepfake risk- How to approach AI incident response automation questions- How to understand supervised, unsupervised, and reinforcement learning basics for the examThe most important exam mindset:AAISM Playlisthttps://www.youtube.com/playlist?list=PL0hT6hgexlYwHFcnBpXG2zuM7inotM0z3AAISM Domain 1https://www.youtube.com/watch?v=jb6tQppDPoE&t=2369sAAISM Domain 2https://www.youtube.com/watch?v=hyfIoSQH0vAAAISM Domain 3 https://www.youtube.com/watch?v=260RFZGgwCY&t=1423sDo not choose the most technical answer immediately.Choose the answer that best reduces risk, supports governance, creates accountability, provides evidence, and protects trustworthy AI outcomes.#AAISM #AISecurity #AIGovernance #CyberSecurity #GRC #RiskManagement #AICompliance #PrabhNair
  • Enterprise Risk Management Explained | Building a Risk Program from Scratch 20.08.2026 53นาที
    In this podcast episode, Prabh speaks with David, a cybersecurity risk governance leader, about Enterprise Risk Management, GRC, risk appetite, risk tolerance, executive reporting, AI risk, and how to build a risk management program from scratch.David shares his first experience of building a risk management program in 2004 at a major Australian bank using ISO 17799, and explains why risk professionals must understand business objectives before applying any framework.Many organizations struggle with risk management because different teams use different definitions, different scoring methods, different language, and different assumptions.That is why David emphasizes the importance of building:Common risk languageAgreed definitionsClear governance levelsDecision-making authorityRisk ownershipBusiness-aligned impact and likelihood matricesOne-page executive risk summariesLinkedin Profilehttps://www.linkedin.com/in/vohradsky/In this episode, we discuss:How to build a risk management program from scratchWhy risk management must start with business objectivesWhy common language and agreed definitions matterHow risk appetite and risk tolerance should be explained to business teamsWhy scoping is critical before risk assessmentHow to understand business processes before identifying risksHow to collect relevant data about assets, processes, systems, and peopleHow to design impact and likelihood matrices for different organizational levelsWhy risk assessment should support decision-making, not only documentationHow to present risk to executives in language they understandWhy CFOs care about financial exposureWhy CEOs and boards care about strategic impactHow one-page summaries help executives take clear decisionsWhy accountability and decision points must be visibleWhat first artifacts can help when starting a risk programWhy a charter, risk taxonomy, and control profile are usefulHow AI risk management is changing GRC thinkingWhy cultural adoption is one of the hardest parts of risk managementWhat young GRC professionals should focus on to grow in this fieldDavid also shares an important career lesson for young GRC professionals:Do not remain limited to templates and control checklists.Understand one business process deeply.Work closely with business teams.Learn how they think, how they make decisions, and what uncertainty means for them.The key takeaway from this session is simple:Risk management is not only about documenting risk. It is about helping the business make better decisions in uncertainty.This episode is useful for:AAISM Playlisthttps://www.youtube.com/playlist?list=PL0hT6hgexlYwHFcnBpXG2zuM7inotM0z3GRC Interview Playlisthttps://www.youtube.com/playlist?list=PL0hT6hgexlYxM5P9v7aEYBTJl7iJyK2uKAI Practicalhttps://www.youtube.com/playlist?list=PL0hT6hgexlYwHLdZR_oHvEKN_8IiAMBcUISO 27001 Playlisthttps://www.youtube.com/watch?v=tvd1MUf3aHE&list=PL0hT6hgexlYys_9UWhal1kr9Gkz0ms0sM&pp=sAgC#EnterpriseRiskManagement #GRC #RiskManagement #CyberRisk #CISO #CyberSecurity #Governance #Compliance #AI Governance #CoffeeWithPrabh
  • IT Application Controls Explained with Payroll Case Study | Practical IT Audit Masterclass 17.08.2026 1ชม. 27นาที
    In this podcast, Prabh speaks with Chinmay, who has tested more than 100 automated controls, to explain IT Application Controls using a practical payroll process case study.https://www.linkedin.com/in/chinmaykulkarni22/https://chinmaykulkarni22.substack.com/Chinmay explains that application controls are automated actions within systems that help prevent or detect errors without manual intervention. Unlike IT General Controls, which are more standardized across applications, IT Application Controls are specific to a business process, system logic, workflow, configuration, and transaction flow.The biggest lesson from this session is simple:Do not start with a checklist. Start with the business risk.In this episode, we discuss:What IT Application Controls areDifference between ITGC and IT Application ControlsWhy application controls are specific to business processesHow payroll risks translate into application controlsInput validation controlsCalculation and processing controlsInterface controlsOutput controlsAuthorization workflow controlsData validation controlsITGC dependency for application controlsHow SOC reports support third-party control relianceHow to test automated controlsWhy production screenshots and configuration evidence matterWhen one sample may be enough for fully automated controlsHow to prepare a lead sheet for application control testingWhy auditors must understand risk before testing controlsPlaylisthttps://www.youtube.com/watch?v=gaClcfhfWFM&list=PL0hT6hgexlYyNWBcGYfabwumCr0GKmLWv&pp=sAgChttps://www.youtube.com/watch?v=mq_vSLHm4r0&list=PL0hT6hgexlYztA41j1bceTfVagP9mtq28&pp=sAgCChinmay also walks through a practical lead sheet structure covering risk statements, walkthrough details, automated control descriptions, trigger types, reference data, attributes, configuration inspection, and testing scenarios.#ITAudit #ITGC #ApplicationControls #GRC #SOX #Audit #CyberSecurity #Big4 #CoffeeWithPrabh
  • Auditing AI Systems in Critical Sectors 13.08.2026 57นาที
    AI is moving from simple human-to-system interaction to agentic AI, where machines interact with other machines, take actions, exchange data, and influence business decisions.This creates a major challenge for cybersecurity, GRC, audit, compliance, and assurance professionals:Priyank Sonihttps://www.linkedin.com/in/priyank-soni-iima/How do you audit an AI system when you cannot fully see the model, logic, architecture, or internal decision-making process?In this podcast, Prabh speaks with Priyank Soni, a cybersecurity, AI/ML, digital trust, governance, and assurance leader, about auditing AI systems in critical sectors.Priyank explains why traditional audit approaches are not enough when AI systems become black boxes, especially in sectors where trust, safety, compliance, and accountability matter.In this episode, we discuss:Why AI audit is becoming important in critical sectorsHow AI is moving toward agentic and machine-to-machine interactionsWhy zero-trust architecture must evolve for AI agentsWhy AI systems require stronger documentation and evidenceHow ISO/IEC 42001 is shaping AI governance and audit expectationsWhy auditors must understand data flow, model behavior, and system boundariesHow to audit black box AI systemsWhy AI audits should start with inventory and classificationWhy data mapping is critical for AI assuranceHow to assess AI vendor and supply chain riskWhy SBOM and ABOM may become important for AI system auditsHow to handle trade secret challenges when vendors do not share model detailsWhy auditor, vendor, and internal team collaboration is requiredWhat performance metrics auditors should reviewHow to test bias, fairness, and reliabilityWhy adversarial input testing mattersWhy human oversight must be validated, not just mentioned in policyWhy AI systems need continuous monitoring after deploymentWhy AI audits may need to happen more frequently than traditional IT auditsPriyank also explains that AI auditing is still in an early maturity phase. Many organizations, vendors, and auditors are learning together. That makes documentation, risk assessment, monitoring, and evidence collection even more important.#AIAudit #AIGovernance #ISO42001 #AISecurity #CyberSecurity #GRC #DigitalTrust #ResponsibleAI #CriticalInfrastructure #VendorRiskManagement #CoffeeWithPrabh
  • CISO Masterclass: Building Security Programs for the AI Era 10.08.2026 1ชม. 10นาที
    AI adoption is accelerating across enterprises, but most security programs were not designed for the speed, scale, and complexity of AI-driven threats.In this CISO Masterclass episode, Prabh speaks with Agnidapta Sarkar, a seasoned cybersecurity evangelist and digital resilience strategist, about how CISOs must evolve their security programs for the AI era.Agni explains why organizations must first understand their digital assets, business impact, material risk, and enterprise architecture before rushing into AI adoption or AI security controls.The discussion goes deep into why traditional visibility-focused security is no longer enough. Modern attackers increasingly use valid credentials, legitimate tools, automation, and faster attack paths. With AI, the challenge becomes even more serious because attacks can happen with greater speed, scale, and depth.In this episode, we discuss:* How CISOs should evolve their security programs for AI threats* Why architecture must come before governance* Why organizations must map digital assets to business impact* How AI changes the speed, scale, and complexity of attacks* Why identity is becoming one of the biggest attack targets* Why Zero Trust needs practical implementation, not just discussion* The role of enhanced identity governance* How micro-segmentation reduces blast radius* Why software-defined perimeters matter in modern defense* Why AI agents need the same access controls as human users* Why proactive governance must monitor ongoing access, not only initial approval* How CISOs should think about resilience before a breach happens* Why incident learnings must feed back into architecture and governance improvementAgni also explains why many organizations struggle with AI security because they do not fully understand their business problems, data flows, access paths, and architectural weaknesses.This episode is highly useful for CISOs, security leaders, enterprise architects, GRC professionals, cyber risk managers, IAM professionals, SOC leaders, AI governance teams, and board-level cybersecurity stakeholders.The key message from this conversation is simple:Before AI governance can succeed, enterprise architecture must be understood, controlled, and resilient.Watch the full episode and comment below:What should CISOs fix first in the AI era — architecture, identity, governance, or resilience?Subscribe for more CISO Masterclass episodes, AI security discussions, cybersecurity leadership insights, GRC content, and practical enterprise security conversations.#aisecurity #ciso #infose #aigovernance
  • Practical OT Risk Assessment Using 06.08.2026 56นาที
    In many organizations, OT security is still discussed at a very high level. But when we go into the real world, the challenge is different:How do we actually assess cyber risk in an OT environment where safety, uptime, legacy systems, plant operations, and business impact all come together?In this session, Sajath walked through a very practical approach to OT cybersecurity risk assessment — not just theory, but how to think through:OT asset identificationBusiness and operational impactThreat scenariosVulnerability and exposureLikelihood and impact scoringRisk matrix creationSafety and reputational impactControl prioritizationPractical documentation for decision-makingWhat I really liked about this discussion was the focus on practical risk thinking.OT cybersecurity is not only about firewalls, segmentation, or compliance checklists. It is about understanding what can stop operations, affect safety, damage reputation, or create real business disruption.A big thank you to Sajath Sathar for sharing his experience and making the session highly practical for learners and professionals Shivhttps://www.youtube.com/watch?v=qjJvK7nB3VI&t=1047s&pp=ygURT1QgU0VDVVJJVFkgUFJBQkg%3DOT Security Program with Manjunathhttps://www.youtube.com/watch?v=nSyAmYgtWeg&t=340s&pp=ygURT1QgU0VDVVJJVFkgUFJBQkg%3DHow to Build OT Security https://www.youtube.com/watch?v=XDA0QGC1W_s&t=3s&pp=ygURT1QgU0VDVVJJVFkgUFJBQkg%3D#OTSecurity #ICSSecurity #CyberSecurity #RiskAssessment #IEC62443 #GRC #IndustrialCyberSecurity #Podcast #PrabhNair #InfosecTrain
  • Real-World Red Teaming: From Reconnaissance to System Access 03.08.2026 1ชม. 2นาที
    In this special cybersecurity podcast episode, Prabh interviews Sarang, a seasoned cybersecurity expert popularly known as “Cyber Insane,” to discuss practical red teaming, enterprise attack simulations, web application security, and real-world attack kill chain thinking.https://www.linkedin.com/in/sarang-tumne-cyber-insane-a1681827/https://m.youtube.com/@redteamgarage-rtg?ra=m📚 RTG – Practical Red Teaming Book copies are now available!✅ Physical Book: ₹899 (Free delivery across India)✅ PDF Copy: ₹499 (Instant download)🎁 Special for Prabh’s community: Get 15% OFF using coupon code: RTG15📩 DM for physical and PDF copies at +91 9137495772📖 Amazon Kindle Edition (₹499):https://amzn.in/d/0bvHeFaM📖 Google Books Edition (₹499):https://books.google.co.in/books/about/Practical_Red_Teaming_Field_Tested_Strat.html?id=4L_rEAAAQBAJ&redir_esc=y⚠️ Coupon code is applicable only for physical/PDF copies and not for Kindle or Google Books editionsThis session goes beyond theory. Sarang explains how red teamers think, how enterprise attacks are planned, and why organizations must go beyond basic vulnerability scanning and traditional penetration testing.
  • Bug Bounty Hunting Roadmap: From Zero to First Bounty 30.07.2026 1ชม. 13นาที
    Are you interested in bug bounty hunting but confused about where to start?In this podcast session, Prabh speaks with Monish about the real beginner roadmap for learning bug bounty, web security, XSS, SQL injection, Burp Suite, vulnerability reporting, and practical web application testing.This session is designed for beginners who want to learn bug bounty the right way. Instead of directly jumping into advanced tools and random payloads, Monish explains why every beginner must first understand how websites actually work.Before you start hunting bugs, you need to understand the basics of HTML, CSS, JavaScript, HTTP requests and responses, cookies, browser developer tools, frontend logic, backend logic, databases, authentication, sessions, and website technology stacks.Monish explains how these foundations help you understand real vulnerabilities like Cross-Site Scripting XSS, SQL Injection, misconfigurations, broken access control, and other common web security issues.The discussion also covers how beginners can use platforms like W3Schools, Juice Shop, OWASP practice labs, PortSwigger Web Security Academy, TryHackMe, Hack The Box, HackTricks, and Burp Suite to build practical skills in a safe and legal way.One of the most important parts of this episode is the discussion on why many bug bounty reports get rejected. Monish explains common mistakes such as submitting duplicate vulnerabilities, depending only on automated scanners, using AI without understanding the finding, missing business impact, weak proof of concept, and losing patience too early.This video is useful for cybersecurity beginners, bug bounty learners, web security students, ethical hacking aspirants, penetration testing beginners, college students interested in cybersecurity, and anyone who wants to learn bug bounty legally and practically.Bug bounty is not about randomly running tools. It is about understanding applications, finding real security impact, documenting evidence properly, and reporting vulnerabilities responsibly.Watch the full session and comment below with the next bug bounty topic you want Monish and Prabh to cover.Subscribe for more practical cybersecurity podcasts, bug bounty learning, ethical hacking guidance, web security training, SOC content, GRC insights, and real-world career advice#BugBounty #EthicalHacking #WebSecurity #CyberSecurity #PenetrationTesting
  • CISSP 2026 AI Topics Questions Master Class 27.07.2026 1ชม. 24นาที
    Are you preparing for CISSP 2026 and wondering how AI security, AI governance, responsible AI, privacy, and model attacks can be tested in the exam?In this video, we break down important CISSP-style AI questions in a practical and exam-focused way. Instead of memorizing definitions, you will learn how to think like a CISSP candidate when facing scenario-based questions on AI systems, governance, risk management, security controls, privacy, and third-party AI platforms.AI is no longer just a technology topic. For CISSP candidates, AI connects directly with Security and Risk Management, Asset Security, Security Architecture, Security Operations, Identity and Access Management, Software Development Security, and Third-Party Risk Management.In this session, we cover AI governance, responsible AI, ethical AI, shadow AI, model poisoning, model inversion, membership inference, prompt injection, differential privacy, AI-SBOM, model cards, AI vendor risk, AI monitoring, risk appetite, risk tolerance, SOC, SIEM, SOAR, and AI security control selection. This video is useful for CISSP 2026 candidates, cybersecurity professionals, GRC professionals, SOC analysts, security managers, risk managers, and AI governance learners who want to understand how AI-related security topics may appear in scenario-based CISSP questions.Watch the full video and try answering each question before checking the explanation. That is how you build CISSP-level judgment.Subscribe for more CISSP exam preparation, cybersecurity concepts, AI security topics, and practical scenario-based questions.CISSP 2026 Coffee Shotshttps://www.youtube.com/watch?v=1krYtSQbMWc&list=PL0hT6hgexlYxKzBmiCD6SXW0qO5ucFO-J&pp=sAgCCISSP Spotify Podcast Domain 1 to Domain 7Domain 1 : https://open.spotify.com/episode/6fggB2lwYA5kzmdmz7BsCh?si=ff488838799b4baeDomain 2 = https://open.spotify.com/episode/4RkQIHgpTUC87TR3UqmkHd?si=ca4f12aea1dc473aDomain 3 = https://open.spotify.com/episode/1b59qRq9vk0hvfa0UiqRm1?si=5f9da0b4cf6545d6Domain 3 Part 2 = https://open.spotify.com/episode/4ncdZBhZEtPCZQYzbLi03m?si=041114030f904c21Domain 3 Part 3 = https://open.spotify.com/episode/3F1S1M8PzVdWMt4egBKFR2?si=dfcdb502cc8049afDomain 4 Part 1 = https://open.spotify.com/episode/6yRGRfpK51II7Od438imNA?si=f94c058f77854f5eDomain 4 Part 2 = https://open.spotify.com/episode/2b3Z8hFII1ypWcVMjqBQlC?si=a16dfb96da6a4addDomain 5 : https://open.spotify.com/episode/1ouhqFPycKwBqMYAF9v4rO?si=u-I7VHQ7Q0CjGmOPfelnSwDomain 6 https://open.spotify.com/episode/0SjIzz6eWO1YKvMg5MVpVK?si=b6980db1afce41a2Domain 7 : https://open.spotify.com/episode/2Ov3RXtw8XMq5R1jJL3o5X?si=2e1bb4ce50fa4516#cisspexam #cissp2026 #CISSP #CISSP2026 #AISecurity #Cybersecurity #aigovernance
  • Kudankulam Data Leak Explained | Critical Infrastructure, Vendor Risk & Dark Web Intelligence 23.07.2026 49นาที
    Critical infrastructure may not always be directly attacked.Sometimes, the real risk comes from vendors, contractors, suppliers, hosting providers, exposed credentials, weak access controls, and data leaked through third-party ecosystems.In this podcast episode, Prabh speaks with Rakesh Krishnan, a threat intelligence researcher, about the Kudankulam Nuclear Power Plant-related data exposure discovered on a dark web data leak site operated by the ransomware group World Leaks.00:00 - 01:04 – Highlights01:04 - 02:54 - Introduction, Guest welcome, his credentials and Agenda02:54 – 04:29 - Discovery of the Breach04:29 – 11:16 - Research Motivation and Initial Investigation11:16 – 13:13 - Risk Assessment of Sensitive Data Leaks13:13 – 15:38 - Technical Analysis and Breach Patterns15:38 – 18:26 - Adversary Attack Life Cycles18:26 – 21:47 - Global Threat Landscape and APT Rankings21:47 – 23:10 - Identifying Nationally Sensitive Data23:10 – 28:06 - Geopolitical Data Logic and Intelligence28:06 – 30:35 - Vendor Security and Leadership Lessons30:35 – 35:45 - Offensive Perspective on Data Classification35:45 – 39:12 - Evolution of Ransomware Tactics39:12 – 44:42 - CISO Incident Response and Negotiation44:42 – 48:06 - Technical Rapid Fire48:06 – 49:40 - End of the conversation by thanking Rakesh Krishnan and looking forward to doing more Podcast.The discussion explains that this was not described as a direct attack on Kudankulam Nuclear Power Plant. Instead, sensitive KKNP-related documents were discovered inside a leaked dataset connected to One of the MNC infrastructure data hosted through a third-party data center.This case is important for every CISO, SOC analyst, threat intelligence team, GRC professional, vendor risk manager, and critical infrastructure stakeholder.Why?Because attackers do not always need to breach the main organization directly.They can study leaked vendor records, engineering drawings, supplier layouts, technical specifications, financial documents, and email records to understand the ecosystem around critical infrastructure.Twitter https://x.com/RakeshKrish12Linkedin Profilehttps://www.linkedin.com/in/rakesh-krishnan-6179a94b/Detailed Bloghttps://theravenfile.com/2026/07/17/kudankulam-nuclear-power-plant-leak-an-accidental-disclosure/In this episode, we discuss:- What was discovered in the Kudankulam-related data exposure- Why the incident points toward third-party and vendor ecosystem risk- How ransomware data leak sites operate- How double extortion works- Why exposed engineering drawings and technical records are dangerous- Why compliance does not always mean security- Why critical infrastructure defenders must monitor dark web leak sites- How attackers weaponize leaked supplier and vendor information- Why no data should be considered useless- How data classification must include business, regulated, and operational data- Why CISOs must investigate exposed VPN, RDP, credential, and access patterns- Why ransomware and data-extortion-only cases must be separated during investigation- How insider threat and credential compromise affect critical infrastructure security- What SOC teams should monitor after dark web exposure- Why vendor vetting must go beyond reputation and compliance certificates- What India’s critical infrastructure ecosystem can learn from this caseWhat should organizations improve first — dark web monitoring, vendor risk assessment, data classification, or SOC detection?#kudankulam #Kudankulamdatabreach #Kudankulamsec
  • How to Implement ISO 27701 in the Real World 23.07.2026 1ชม. 39นาที
    Want to understand how to implement ISO 27701 properly and turn privacy compliance into a working system? In this podcast, we break down the practical implementation of ISO 27701, explain how it relates to ISO 27001, and show how organizations can build a real Privacy Information Management System (PIMS) instead of treating privacy as a one-time compliance exercise.This session covers the structure of ISO 27701, the role of privacy principles, the difference between controllers and processors, and the real steps involved in operationalizing privacy controls across people, process, and technology. It also explores key implementation areas such as data processing assessments, records of processing activity, consent management, privacy impact assessments, vendor risk assessments, cross-border data transfers, training, privacy champions, and continuous monitoring.In this video, you’ll learn:What ISO 27701 is and why it mattersHow ISO 27701 extends ISO 27001 for privacy risk managementThe difference between data controllers and data processorsHow to start a practical PIMS implementationWhy records of processing activity are essentialHow to map privacy controls to regulations like GDPR and DPDPAHow to handle privacy impact assessments and vendor riskWhy privacy implementation takes months, not weeksHow privacy champions, training, and continuous monitoring support long-term complianceThis episode is useful for:privacy professionalsDPOsCISOscompliance leadersGRC teamsISO 27001 practitionersconsultants implementing privacy frameworksWhether you are starting an ISO 27701 implementation, improving your privacy governance model, or trying to align privacy operations with ISO 27001, this discussion gives you a practical roadmap.Data Privacy Professional Videohttps://www.youtube.com/watch?v=76fcelayw00&t=1734s&pp=ygUSZGF0YSBwcml2YWN5IHByYWJo0gcJCQQLAYcqIYzvInterview Serieshttps://www.youtube.com/watch?v=ugHmTNup-ys&list=PL0hT6hgexlYynj0FOvrGCPfiWZFRkMJx4&pp=sAgCGDPR Implementationhttps://www.youtube.com/watch?v=Pf_qQxeubIg&pp=ygUKZ2RwciBwcmFiaA%3D%3DPDPL Implementationhttps://www.youtube.com/watch?v=SgvOkRZgrd0&t=1338s&pp=ygUSZGF0YSBwcml2YWN5IHByYWJoSubscribe for more content on ISO 27701, privacy management, GDPR, data protection, information security governance, and compliance implementation#dataprivacy #iso27701 #cybersecurity #dataprivacyday
  • How to Pentest LLMs Like a Security Researcher Cybersecurity 20.07.2026 1ชม. 43นาที
    Are LLMs and AI apps really secure? In this podcast, we break down LLM security, prompt injection, LLM penetration testing, and the real vulnerabilities attackers look for when testing AI systems. From reconnaissance and enumeration to payload manipulation and lab-based exploitation, this session shows how traditional web application security testing differs from LLM security testing in real-world environments.Youtube : https://m.youtube.com/@darshanhackzInstagram : https://www.instagram.com/darshanhackzX : https://x.com/darshanhackzSecurity researcher Darshan Naik joins the discussion to explain common LLM vulnerabilities such as prompt injection, hallucinations, excessive agency, information disclosure, insecure integrations, and API misuse. The session also explores how weak validation, poor segmentation, and insecure AI workflows can expose sensitive data or create paths to unauthorized access. Practical examples and lab walkthroughs make the concepts easy to understand for both security professionals and learners.In this video, you’ll learn:How LLM penetration testing is different from traditional web app pentestingHow attackers identify whether a target is using a real LLM or static AIWhat prompt injection looks like in practiceWhy hallucinations, insecure permissions, and excessive agency create riskHow API integrations and AI agents can increase the attack surfaceWhy validation, segmentation, and secure implementation matterHow to use labs and practical exercises to improve AI security testing skillsWhat defenders should do to reduce LLM security vulnerabilitiesThis episode is useful for:penetration testersbug bounty huntersAI security researchersAppSec professionalsred teamersdevelopers building LLM applicationssecurity leaders exploring AI riskWhether you are testing AI chatbots, reviewing LLM security posture, or learning how modern attackers abuse AI systems, this conversation gives you a practical starting point.Subscribe for more content on AI security, LLM hacking, prompt injection, penetration testing, AppSec, and cybersecurity research.GEN AI Securityhttps://www.youtube.com/watch?v=aTJPKifa1VM&t=489s&pp=ygUPZ2VuIGFpIHNlY3VyaXR5#LLMSecurity #PromptInjection #AISecurity #Pentesting #CyberSecurity

ยอดนิยมใน

พอดแคสต์นี้ปรากฏในชาร์ตพอดแคสต์ของประเทศเหล่านี้ด้วย