Sec Guy

Sec Guy

Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether you're fighting off Prompt Injection attacks or just fighting to get your first IT job, the Sec Guy has your back. Join us for deep dives into AI Security, Network Defense, and the future of cyber. Train Hard. Stay Secure.

Episodes

September 17, 2026 4 mins

If you want to survive in the CISO chair, you have to stop speaking in vulnerabilities and start speaking in dollars. Here is the exact financial blueprint (CapEx, OpEx, and ROSI) to get your cybersecurity budget approved.

Welcome back to the lab. In this module of the CISM/CISO series, Sec Guy breaks down the hardest transition for senior engineers: Resource Management. The Board of Directors doesn't care about the latest zero-day ...

Listen
Watch
Mark as Played

Stop being a hero and start building a machine. If your security program depends on you saving the day, you don't have a program—you have a high-stress hobby.

In Video 3 of the CISM 2026 series, we move from the "Mindset" to the "Executive Machine." We break down how top-tier CISOs use frameworks like NIST, ISO, and COBIT to build repeatable security engines that survive global audits and protect the organization's revenue.

In ...

Listen
Watch
Mark as Played

We have seen the technical weeds. Now, let’s look at the boardroom. Welcome to Phase 1: The Executive Baseline. In this video, we switch to the C-Suite mindset.

We are breaking down the "Business Alignment" stack, the fundamental shift in responsibility you need to know for the exam, and the critical separation of duties that keeps the organization secure without causing a bankruptcy.

In this video, we cover:

The CISM Mindset: W...

Listen
Watch
Mark as Played

Stop trying to secure everything and start managing business risk. If you are still trying to patch every single vulnerability without looking at the business impact, you are thinking like a technician, not an executive.

In Video 4 of the CISM 2026 series, we explore the core language of the boardroom: Risk Management. Learn how to stop saying "no" to the business and start saying "yes, securely."

In this video, we cover:

• The Risk T...

Listen
Watch
Mark as Played

You can build a million-dollar security fortress, but if your HVAC vendor has a weak password, your network is compromised. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down Supply Chain and Third-Party Risk Management (TPRM). We move beyond technical configurations and dive into the executive procurement lifecycle: R-F-Is, R-F-Ps, Proof of Concepts (POC), and why the "Right-to-Audit" clause is the most ...

Listen
Watch
Mark as Played

A security plan on paper is just a liability waiting to be exposed. In Video 6, we tackle the CISO's ultimate test: Incident Management. Discover the critical differences between an IRP, BCP, and DRP, why technicians fail during a crisis, and how top-tier executives maintain control, legally protect the company, and manage the boardroom narrative during a massive cyber breach.

In this video, we cover:

• The Crisis Mindset: Why techni...

Listen
Watch
Mark as Played
September 17, 2026 4 mins

You can build a million-dollar network fortress, but if you don't know where your most sensitive data lives, you have already lost. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down Data Governance. We cover the critical legal separation between Data Owners and Data Custodians, how to implement Data Loss Prevention (DLP), and why the CISO should never be the one deciding who gets access to a file.

📘 GET ...

Listen
Watch
Mark as Played

When the CEO asks, "Are we secure?", how do you answer? If you reply with technical metrics like "firewall hits" or "malware blocked," you are thinking like an engineer, not an executive. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down the science of measuring security success. We explain the critical difference between Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and Key Goal Indicat...

Listen
Watch
Mark as Played

You finally got the CISO job. You have the budget, you built the dashboard, and your S.O.C. is fully staffed. But there's one massive problem: You don't actually own the network. The CIO does. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down the brutal reality of boardroom politics. We cover "Influence Without Authority," how to navigate toxic friction between Engineering and Legal, and why forcing the ...

Listen
Watch
Mark as Played

Junior analysts picture major outages as the result of advanced nation-state hackers, but seasoned architects know that a single unvetted internal change can take down a multinational enterprise faster than any DDoS attack.

In this module, Sec Guy breaks down Objective 1.2: Demonstrating the Impact of Change Management Processes on Security. Change management is not bureaucratic red tape; it is an operational governance framework en...

Listen
Watch
Mark as Played

If you are preparing for your CompTIA Security+ SY0-801 certification, throw away the idea of memorizing vocabulary just to pass a test. In the real world, enterprise security is about reasoning through decisions, understanding architectural tradeoffs, and knowing exactly what happens when a control fails.

In this module, Sec Guy breaks down Objective 1.1: Security Concepts and Controls. We dismantle the outdated "castle and moat" s...

Listen
Watch
Mark as Played

In enterprise security, you cannot defend against an adversary you do not understand. Today, we begin Domain 2 with Lesson S8-006: From Threat Intelligence to Vulnerability Priority for the CompTIA Security+ (SY0-801).

Sec Guy breaks down the definitive difference between a threat (the force that exploits) and a vulnerability (the weakness in the system). You will learn how to consume intelligence across the entire threat lifecycle ...

Listen
Watch
Mark as Played

Theory without execution is useless in enterprise cybersecurity. In this Domain 1 Mastery Workshop for the CompTIA Security+ (SY0-801), you step into the shoes of the Lead Security Architect for a national healthcare processing network facing a critical Friday morning crisis. When infrastructure engineers submit an emergency Change Advisory Board (CAB) request to overhaul the patient billing portal, junior analysts see a standard b...

Listen
Watch
Mark as Played

In modern enterprise security, cryptography is not an academic math drill; it is the trust engine that enforces identity, proves integrity, and secures multi-cloud environments. In this module, Sec Guy breaks down Objective 1.3: Cryptographic Solutions and the Trust Engine for the CompTIA Security+ (SY0-801). We demystify the difference between one-way integrity (hashing, salting, and rainbow table mitigation) and two-way confiden...

Listen
Watch
Mark as Played

When the network is breached, a technician reacts with panic, but an executive reacts with a playbook.

In this module, Sec Guy breaks down Objective 4.7: Incident Response and Forensics. Using the Salt Typhoon telecommunications breach as a real-world framework, we cover the entire incident response lifecycle. You will learn how to build a Computer Incident Response Team (CIRT), execute tabletop exercises, perform digital forensics ...

Listen
Watch
Mark as Played

In cybersecurity, knowing the exploit is only half the battle. If you do not know the hand behind the keyboard, you are just chasing ghosts.In this module, Sec Guy breaks down Objective 2.2 for the CompTIA Security+ (SY0-801) exam: Threat Actors and Motivations. We move beyond textbook definitions to analyze the actual tradecraft, funding, and motivations of modern adversaries. You will learn how Nation-States use dwell time for es...

Listen
Watch
Mark as Played

When you type a password, the computer knows it's data. But when you talk to an AI, your instructions and your data are the exact same thing—just tokens in a stream. That single flaw is the root of every AI attack. In this video, Sec Guy explains the math behind Universal Adversarial Triggers, reveals how Indirect Prompt Injection can turn a resume into a weapon, and shows why Token Smuggling allows malware to slip right past...

Listen
Watch
Mark as Played
September 17, 2026 4 mins

A password can be stolen, but a temporary token expires. In this video, Sec Guy explains why Long-Term Access Keys are a "security smell" and how to replace them with IAM Roles and the STS (Security Token Service). We break down the critical difference between Identity-Based Policies (What I can do) and Resource-Based Policies (Who can access this bucket), and show you how to use SCPs (Service Control Policies) to create an unbreak...

Listen
Watch
Mark as Played

If your cloud environment is a skyscraper, CSPM is the building inspector checking the foundation, while CASB is the security guard checking everyone who walks through the door. In this video, Sec Guy explains the critical difference between securing infrastructure (IaaS) and securing SaaS applications, breaks down Forward vs. Reverse Proxy deployment modes, and shows how a Zero Trust Policy Decision Point (PDP) can stop an identit...

Listen
Watch
Mark as Played

If your data is breached in the cloud, is it Amazon's fault or yours? In this video, Sec Guy breaks down the Shared Responsibility Model, explaining why Capital One was liable for their massive breach (SSRF) despite using a secure cloud provider. We also cover the evolution from IaaS to Serverless (FaaS) and why Data Sovereignty (Microsoft Ireland Case) means your data is subject to the laws of the physical land it sits on.

New Secu...

Listen
Watch
Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Crime Junkie

    Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by Audiochuck Media Company.

    NFL Daily with Gregg Rosenthal

    Gregg Rosenthal and a rotating crew of NFL Media hosts including Jourdan Rodrigue, Colleen Wolfe, and Nick Shook provide all the NFL news, previews, recaps and analysis you need to be smarter and funnier than your friends.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

    The Clay Travis and Buck Sexton Show

    The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices