

8th Layer Insights
Perry Carpenter | N2K Networks
Get ready for a deep dive into what cybersecurity professionals often refer to as the "8th Layer" of security: HUMANS. Welcome to 8th Layer Insights (8Li). This podcast is a multidisciplinary exploration into how the complexities of human nature affect security and risk. Author, security researcher, and behavior science enthusiast Perry Carpenter taps experts for their insights and illumination. Topics include cybersecurity, psychology, behavior science, communication, leadership, and more.
Episodes
Mentioned books

Mar 19, 2024 • 55min
How AI Can Deceive and be Deceived
On this episode Perry sits down with Dr. Matthew Canham to explore ways in which AI can be weaponized against us, and how age old social engineering tactics can be used to trick large language models.
Guest:Dr. Matthew Canham (LinkedIn) (Website)Books and References (Books are Amazon Associate Links and help support the show):
Cognitive Security Institute YouTube Channel
Cognitive Security Institute website
YouTube video: BlackHat Presentation -- Me and My Evil Digital Twin: The Psychology of Human Exploitation by AI Assistants
YouTube video: NEW AI Jailbreak Method SHATTERS GPT4, Claude, Gemini, LLaMA
Not with a Bug, But with a Sticker: Attacks on Machine Learning Systems and What To Do About Them, by Ram Shankar Siva Kumar & Hyrum Anderson
Six Thinking Hats, the de Bono Group
Six Thinking Hats: Looking at Decision in Different Ways, MindTools
AI + Six Thinking Hats, LifeArchitect.ai
8Li Season 4, episode 10: Artificial Intelligence Insights & Oddities
Perry's Books (Amazon Associate Links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Feb 27, 2024 • 40min
Frame the Future: The Art of Becoming a Futurist
On this episode Perry sits down with Jeremy Treadwell, a people-first technologist and futurist, to get the lowdown on how a futurist approaches the world.
Guest:Jeremy Treadwell (LinkedIn) (Twitter)Books and References (Books are Amazon Associate Links and help support the show):
YouTube Video: What UX/UI Taught Me about Improving Security Awareness [SANS Security Awareness Summit 2022], Jeremy Treadwell
YouTube Video: Reimagine the Future of Data, Privacy + Security with Technologist Jeremy Treadwell
The Institute for the Future website
Four Questions to Turn Everyone in Your Company Into a Futurist, FastCompany article
How Does a Futurist See the Future, LinkedIn Article by Jacob Morgan
The Black Swan: Second Edition: The Impact of the Highly Improbable: With a new section: "On Robustness and Fragility", by Nassim Nicholas Taleb
The Gray Rhino: How to Recognize and Act on the Obvious Dangers We Ignore, by Michele Wucker
William Gibson’s Future Is Now, Pagan Kennedy, the New York Times
8Li Season 1, episode 8: The Risk Episode: Black Swans, Grey Rhinos, Angels & Demons
Perry's Books (Amazon Associate Links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Feb 13, 2024 • 56min
How to Scam a Romance Scammer
Welcome to season 5 of 8th Layer Insights!To celebrate Valentine's Day, Perry sits down with Emmy winning reporter Kerry Tomlinson to talk about the time she turned the tables on a romance scammer.
Guest:Kerry Tomlinson (LinkedIn) (Website) (YouTube)Books and References:
YouTube video: Inside a romance scam: how to make a catfisher sing
YouTube video: Scammers are stealing people's faces for live video calls
National Cybersecurity Alliance : Online Romance and Dating Scams
National Cybersecurity Alliance : Romance Scams Resource Kit
Federal Trade Commission: Romance scammers’ favorite lies exposed
Know Your Meme: On the Internet, Nobody Knows You're A Dog
‘NOBODY KNOWS YOU’RE A DOG’: As iconic Internet cartoon turns 20, creator Peter Steiner knows the joke rings as relevant as ever
Wikipedia: On the Internet, nobody knows you're a dog
Perry's Books (Amazon Associate Links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Nov 30, 2023 • 1h 6min
Artificial Intelligence: Insights & Oddities
On this episode, Perry celebrates the one year birthday of ChatGPT by taking a look at AI from technological, philosophical, and folkloric perspectives. We see how AI was formed based on human words and works, and how it can now shape the future of human legend and belief.Guests:
Brandon Karpf, Vice President at N2K Networks (LinkedIn) (Website)
Dr. Lynne S. McNeill, Associate Professor at Utah State University (LinkedIn) (Twitter)
Dr. John Laudun, Professor at University of Louisiana at Lafayette (LinkedIn) (Twitter) (Website)
Lev Gorelov, Research Director at Handshake Consulting (LinkedIn) (Twitter) (Website)
Resources
Interview with the AI, part one, by the Brandon Karpf / the CyberWire
'Hard Fork': An Interview With Sam Altman, by The New York Times
The Exciting, Perilous Journey Toward AGI, Ilya Sutskever TED Talk
Ilya: the AI scientist shaping the world, by The Guardian
Meet Loab, the AI Art Woman Haunting the Internet: Is she a demon? A Cryptid? Or nothing at all..., the Guardian
In 2016, Microsoft’s Racist Chatbot Revealed the Dangers of Online Conversation The bot learned language from people on Twitter—but it also learned values, IEEE Spectrum
Perry's Digital Folklore episode about AI
Handshake's Generative AI Masterclass on Maven
Perry's Books (Amazon Associate links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Be sure to check out Perry's other show, Digital Folklore. It's all about the oddities and importance of online culture. Head over to the show's website (https://digitalfolklore.fm/) to see our custom artwork, subscribe to the newsletter, shop for merch, support the show on Patreon, and more. Want to check out what others are saying? Here's some recent press about the show: https://digitalfolklore.fm/in-the-news.Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, Storyblocks, & EpidemicSound.8Li cover art by Chris Machowski @ https://www.RansomWear.net/.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Oct 24, 2023 • 52min
Technology and the Law of Unintended Consequences (Encore)
Let's face it. Most of us have a love/hate relationship with technology and technological advances. We dream about the new thing... but when it arrives, we are usually a little disappointed. Many of us also lament the constant erosion of privacy, the changes in social norms, and more. And, little-by-little, we allow those aspects of new technology to make us numb. We accept the cognitive dissonance of not totally being happy with the trade-offs; yet we still make the trade.In this episode, we explore a few of the positives and some of the unintended consequences associated with recent technological advancements. We'll hear from Dr. Lydia, Kostopoulos, Dr. Charles Chaffin, Andra Zaharia, and Aaron Barr.Guests:
Dr. Lydia Kostopoulos (LinkedIn) (Website)
Dr. Charles Chaffin (LinkedIn) (Website)
Andra Zaharia (LinkedIn) (Website)
Aaron Barr (LinkedIn) (Website)
Books and Resources:
IEEE Article: Decoupling Human Characteristics from Algorithmic Capabilities by Dr. Lydia Kostopoulos
Numb: How the Information Age Dulls Our Senses and How We Can Get them Back by Dr. Charles Chaffin (Amazon Associate Links)
The Numb Podcast by Dr. Charles Chaffin
The Cyber Empathy Podcast by Andra Zaharia
Reminder: Your 'smart AI' often involves a low-paid contractor surveilling you
How creepy is your smart speaker?
Newton's Laws of Motion
Unintended Consequences
Elon Musk's warning regarding AI
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter (Amazon Associate Link)
Everything is Alive podcast by PRX and Radiotopia
Production Credits:Additional voice talent provided by Kristina Leigh.Additional research by Nyla Gennaoui.Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: hello [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Oct 10, 2023 • 41min
Cybersecurity First Principles w/Rick Howard
In this episode, Perry sits down with cybersecurity expert Rick Howard to delve into the concept of 'First Principles' in cybersecurity. They discuss the importance of risk decision-making, threat modeling, and tabletop exercises, as well as the use of Bayes algorithm in cybersecurity risk forecasting. The chapter also highlights the Cybersecurity Canon Project and emphasizes the need for organizations to maximize existing technology before considering new investments.

Sep 26, 2023 • 34min
OSINT, Curiosity, Creativity, & Career Pivots: A Conversation with Rae Baker
If you’ve been listening to this show for a while, you’ll know that we’ve touched on the topic of Open Source Intelligence (otherwise known as OSINT) several times. It is an area of information security that penetration testing that’s been getting quite a bit of attention over the past several years. When you think about the digital world we live in, where we have a proliferation of personal, organizational, and governmental data on the internet...and the simple fact that data likes to leak…we can safely predict that OSINT investigation techniques will continue to be in demand.On this episode, Perry sits down with Rae Baker. Rae is the author of the book Deep Dive: Exploring the Real-world Value of Open Source Intelligence, which was released in April of this year from Wiley publishing. In this discussion with Rae, you’ll hear a bit about her career pivot to OSINT specialist from being a graphic designer, how creativity fuels her job, advice for aspiring cybersecurity and OSINT professionals, and a lot more.
Guest:Rae Baker (LinkedIn) (Twitter) (Website)Books and References:
Deep Dive: Exploring the Real-world Value of Open Source Intelligence, by Rae Baker (Amazon Associate link)
Kase Scenarios: https://kasescenarios.com/
The OSINT Curious project
TraceLabs
YouTube Playlist from the 2022 SANS OSINT Summit
YouTube video by The Cyber Mentor: Learn OSINT in 4.5 Hours
Lockheed Martin Cyber Kill-Chain: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Perry's Books (Amazon Associate Links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Sep 12, 2023 • 57min
Conversational Security Awareness: Putting Humanity into Your Human Risk Management Program
Listen in as Perry Carpenter & Dr. Jessica Barker present their joint session, "Conversational Security Awareness" at the SANS Managing Human Risk Summit. ... and stay tuned after the presentation for a quick conversation between Perry, Jessica, and Lance Spitzner (SANS) as they discuss themes from this year's event.Guests:
Dr. Jessica Barker (LinkedIn) (Twitter)
Jeremy Treadwell (LinkedIn) (Twitter)
Lance Spitzner (LinkedIn) (Twitter)
Additional Resources:
Jessica Barker's great blog post summarizing this session
Jessica Barker's 2020 RSA Keynote
Related 8Li Episodes:
8Li S1 E9: Security ABCs Part 1: Make Awareness Transformational
8Li S1 E10: Security ABCs Part 2: 8th Layer Insights and the Quest for Security Culture
8Li S2 E10: The Next Evolution of Security Awareness
8Li S4 E3: Carrots, Sticks, and Culture: The Art and Science of Social Signaling
8Li S4 E5: We are the Champions
8Li S4 E6: Blending Awareness, Social Engineering, and Physical Penetration Testing -- A Conversation with Jayson E. Street
Relevant Books (Amazon Associate Links)
Confident Cyber Security: How to Get Started in Cyber Security and Futureproof Your Career, by Jessica Barker
Cybersecurity ABCs: Delivering awareness, behaviours and culture change by Jessica Barker, Adrian Davis, Bruce Hallas, & Ciarán Mc Mahon
Mixed Signals: How Incentives Really Work, by Uri Gneezy
Security Awareness Program Builder: Practical guidelines for building your Information Security Awareness Program & prep guide for the Security Awareness and Culture Professional (SACP)™ by Mark Majewski
Perry's Books (Amazon Associate Links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: hello [at] 8thLayerInsights [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 29, 2023 • 1h 6min
Blending Awareness, Social Engineering, and Physical Penetration Testing -- A Conversation with Jayson E. Street
On today's show, Perry sits down with Jayson E. Street to discuss his unique blend of social engineering, physical penetration testing, and security awareness. Jayson refers to this as being trained by a simulated adversary. At the heart of Jayson's method is intense boldness in his approach to social engineering and penetration testing coupled with an equally intense passion for helping his clients and their employees improve their overall security posture and mindsets. It's about education rather than exploitation.Guest: Jayson E. Street (LinkedIn) (Twitter) (Website)YouTube videos of Jayson
2022 Saintcon: Hacker Striptease
Tomorrow Unlocked: Penetration tester Jayson E. Street helps banks by hacking them
Risks & Reels: Who's a Hacker?
Jasyon's book (Amazon Associate link) Dissecting the Hack: The V3rb0t3n NetworkPerry's Books (Amazon Associate links)
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Be sure to check out Perry's other show, Digital Folklore. It's all about the oddities and importance of online culture. Head over to the show's website (https://digitalfolklore.fm/) to see our custom artwork, subscribe to the newsletter, shop for merch, support the show on Patreon, and more. Want to check out what others are saying? Here's some recent press about the show: https://digitalfolklore.fm/in-the-news. Season 2 starts September 4, 2023.Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, Storyblocks, & EpidemicSound.8Li cover art by Chris Machowski @ https://www.RansomWear.net/.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: perry [at] 8thLayerMedia [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 8, 2023 • 1h 5min
How to Fool the White House (Encore)
Hey all! I'm at BlackHat and Defcon this week. If you're there, track me down. I'd love to meet you!This week's episode is an encore of one of my favorites. My interview with James Linton (a.k.a. The Email Prankster). In 2017, James went on a virtual joyride exploiting the ways that people interact with emails. One of the most interesting things about James' story is that his exploits didn't rely on any type of highly technical method(s); they were simple display name deceptions. But that didn't stop him from fooling CEOs from some of the worlds largest banks, celebrities, and high ranking staff members in the White House.James' success using these simple methods serves as a warning for us all. We don't fall for scams because they are technically sophisticated or because we are stupid. We fall for scams because we are human.Guest: James Linton (LinkedIn) (Website)Books and Resources:
Anatomy Of An Email Impersonation Spree: Who Got Pranked And Why
An email prankster is hitting the CEOs of the world's biggest banks
How to Prank the Rich and Powerful Without Really Trying
Morgan Stanley CEO James Gorman falls for email prank
This Man Pranked Eric Trump And Harvey Weinstein — Now He Just Wants A Job
Media Coverage YouTube Playlist
James Linton -- Wikipedia Entry
The Journal of Best Practices: A Memoir of Marriage, Asperger Syndrome, and One Man's Quest to Be a Better Husband by David Finch
Perry -- Interview on Springbrook's Converge Autism Radio
Perry -- Security Weekly Interview
Perry Carpenter - The Aspies Guide to Social Engineering - DEF CON 27 Social Engineering Village
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors, by Perry Carpenter
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer by Perry Carpenter & Kai Roer
Production Credits:Music and Sound Effects by Blue Dot Sessions, Envato Elements, & Storyblocks.Artwork by Chris Machowski @ https://www.RansomWear.net/ and Mia Rune @ https://www.MiaRune.com.8th Layer Insights theme music composed and performed by Marcos Moscat @ https://www.GameMusicTown.com/Want to get in touch with Perry? Here's how:
LinkedIn
Twitter
Instagram
Email: hello [at] 8thLayerInsights [dot] com
Learn more about your ad choices. Visit megaphone.fm/adchoices