

Down the Security Rabbithole Podcast (DtSR)
Rafal (Wh1t3Rabbit) Los
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.On Twitter/X: https://twitter.com/@DtSR_PodcastOn YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqOn LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
Episodes
Mentioned books

Mar 25, 2025 • 36min
DtSR Episode 646 - Ward Pyles on Human Centric Security for Real
Send the hosts a message - try it now!TL;DR: This week Ward Pyles joins Jim Tiller and myself to talk about a relatively unremarkable topic - people-centric security. We've talked about it a bunch but it's not until this episode that something finally clicked in my brain. When Ward talks about the data that security needs - see if you can pick it up too.Also - I'm trying some new bonus content - the "After Show" which is a 2-5 minute post-show bit where we post what's said after the recording (usually) stops. I hope you enjoy it - check that out exclusively on our YouTube channel.YouTube video: https://youtube.com/live/LWzA2czvocQSupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Mar 18, 2025 • 24min
DtSR Episode 645 - Zero Trust Applied in the Real World
Send the hosts a message - try it now!TL;DR: This week's episode is a sit-down in person at Zero Trust World 2025 (sponsored by ThreatLocker) with Ryan Benner. Ryan's the caretaker of "anything that powers up", as he puts it, which means this small organization's security is also his responsibility. So how do you do it with next to no staff, and on a small budget? And how do you even begin to "Zero Trust" your network? Listen in.YouTube Video: https://youtu.be/JUMcWFNsVaASupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Mar 11, 2025 • 44min
DtSR Episode 644 - Inside the Minds of Great Product Managers
Send the hosts a message - try it now!TL;DR: This week's episode shifts the focus from leadership in the enterprise, to leadership in the vendor space. Building security products that innovate, inspire, and meet market and customer demand is far from trivial. Meet two of the best in the business - Arash Marzban and Bryan Lares - and hear what makes the job exciting, and how they make it great.YouTube video: https://youtube.com/live/wA9-vgusyI0Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Mar 4, 2025 • 40min
DtSR Episode 643 - A CISO's Guide to the First 90 Days
Send the hosts a message - try it now!TL;DR: This week's podcast features the wisdom and wit of Merlin Namuth - currently serving as the CISO for the city & county of Denver. Merlin provides insights into how he views the first 90 days of a CISO's role with a new organization, frameworks and processes he goes through to get his bearings and start a successful residency.YouTube Video: https://youtube.com/live/8y7bsKlBBXE?feature=shareSupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Feb 25, 2025 • 24min
DtSR Episode 642 - Chase Cunningham An Epic Zero Trust Keynote
In this engaging discussion featuring Chase Cunningham, a retired Navy chief and cryptologist with a wealth of experience from the NSA, he dismantles outdated security dogmas. Topics include the pressing need for basic security practices amidst complex tech environments and how organizations can effectively implement a zero trust model. Cunningham emphasizes the importance of asset visibility and a red team approach to combat cybersecurity challenges. His insights reveal the necessity of strong leadership and clarity in navigating today's security landscape.

9 snips
Feb 18, 2025 • 39min
DtSR Episode 641 - Kevin Fielder Security Principles and Guard Rails
In this discussion, Kevin Fielder, the Chief Security Officer for NatWest Box and Mettle, shares his expertise in cybersecurity and cloud-native technologies. He highlights the importance of integrating security practices with business goals, advocating for automation in development. The conversation navigates the challenges of vendor relationships and the significance of strategic partnerships in enhancing security. Reflecting on past experiences, Fielder underscores the need for effective communication across teams to bridge gaps and align security measures with organizational objectives.

Feb 11, 2025 • 39min
DtSR Episode 640 - A Practitioner View of Security Automation
Send the hosts a message - try it now!TL;DR: This week is a real treat! Eva Georgieva - a seasoned cybersecurity automation engineer - joins me, James, and Jim to talk about automation in cyber. We talk about challenges, what to automate first, good versus bad automation, and even get a little practical.YouTube: https://youtube.com/live/lA20Mgl3AxESupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Feb 4, 2025 • 49min
DtSR Episode 639 - Richard Bird Famous With 12 People
Send the hosts a message - try it now!TL;DR: This week's episode features a long-time-coming discussion with Richard Bird discussing his book "Famous with 12 people", and the "influencer culture" in cybersecurity. It's an interesting discussion on how our industry works, and who makes it really turn.YouTube: https://youtube.com/live/hk42GbjzDZQ?feature=shareSupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Jan 28, 2025 • 36min
DtSR Episode 638 - Matt Shufeldt Cyber Security's Specialist Problem
Matt Shufeldt, a seasoned cybersecurity expert, dives into the crucial topic of specialization in the field. He discusses the pitfalls of over-specialization and its impact on career trajectories. The conversation highlights the value of flexibility, contrasting super generalists with specialists, and emphasizes the need for adaptable skillsets in a rapidly evolving industry. Shufeldt also touches on the importance of bringing a long-term perspective to security leadership and fostering technological capabilities with an agile mindset.

Jan 21, 2025 • 45min
DtSR Episode 637 - Amanda Berlin Build SMB Tools That Don’t Suck
Send the hosts a message - try it now!TL;DR: On this episode Amanda Berlin, Senior Product manager at Blumira, joins Jim and Rafal to talk about her career, the second edition of her book, and building products for SMBs that "don't suck". The unfortunate fact is that there aren't a lot of products designed for the unique challenges of companies that can't afford an army of security analysts, or consultants.YouTube Video: https://youtube.com/live/rvXqjBU5M4kSupport the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast