Down the Security Rabbithole Podcast (DtSR)

Down the Security Rabbithole Podcast (DtSR)

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

Episodes

October 14, 2025 46 mins

TL;DR: If you've ever wondered what goes through the mind of a top-tier CISO, wonder no longer. This week's episode features Trey Ford talking a little nostalgia, and a little of what's on his mind as a CISO. Fantastic episode, shout out to BugCrowd for the episode.

Youtube video: https://youtube.com/live/uFl45Tb93gY?feature=share

Have something to say? Let's hear it.

Support the show

>>> Please consider cli...

Mark as Played

TL;DR:  Let's talk, err, lament, Third Party Risk programs. Who has time for these, and is there any real value in identifying 3rd party risks? Or is it just all theater for the lawyers? Paul Farley joins Jim, James and Rafal to chop it up.

Dive in with us, and see what you think.

YouTube Video: https://youtube.com/live/Le23nkaybfE

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the ...

Mark as Played
September 30, 2025 43 mins

TL;DR:  This week's episode is what happens when I go on vacation and have a little time to think. So here we go - let's talk about this Jaguar Land Rover was compromised and ransomware spread. The damage has been 'extensive' to the point where they stopped everything... are there any lessons here?

Links

  • https://www.theguardian.com/business/2025/sep/20/jaguar-land-rover-hack-factories-cybersecurity-jlr
  • https://...
Mark as Played
September 23, 2025 39 mins

TL;DR: This podcast features our friend Bo Birdwell who sits down with us to explain the ins and outs of the new DFARS CMMS update. Jim and Bo cover a lot of ground, and James and I are along for the ride asking questions.

Great episode if you're in the space, worrying about what this latest update means to you.

YouTube Video: https://youtube.com/live/0cl1S4f3g8E

Have something to say? Let's hear it.

Support the show

>>&g...

Mark as Played

TL;DR: This week's returning guest is Doug Cavit, but this time he's here to talk about the Internet apocalypse. Partly driven by AI, but mostly we discuss automated content generation, bots, and consumption as we reach the conclusion that it's all coming crashing down... sooner than we'd like.

YouTube Video: https://youtube.com/live/tUJgdrh3ws8

Have something to say? Let's hear it.

Support the show

>>>...

Mark as Played

TL;DR: Michael Reichstein joins the pod this week to talk about "rock star CISOs" and those who trade equity for their souls. It's an interesting discussion but this one comes with a warning label: If you're easily offended, do not listen to this.

Michael's post that started this conversation: https://www.linkedin.com/posts/mreichstein_cybersecurity-leadership-businessethics-activity-7361753110983135233-YSct

...

Mark as Played
September 2, 2025 43 mins

TL;DR: This week's pod features our favorite former analyst Anton Chuvakin, and an AppSec OG Jeff Williams as we tackle the subject of AppSec's favorite new acronym - ADR. What is it? Why is it? Should it be? We answer all these questions and more, and laugh along the way a bit too.

YouTube Video: https://youtube.com/live/69xeGDoDYbU

Links

Mark as Played

TL;DR: This week's returning guest is the man, the myth, the Alpaca farmer, Philippe Humeau of CrowdSec. Life comes at you fast, threats come at you faster. The good news is - defenses can keep up. Listen in, then go check out CrowdSec!

YouTube video: https://youtube.com/live/7Xc99bXCfwQ

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=...

Mark as Played

TL;DR: This week's guest is Dr Sam Liles - who's been CISO'ing since most of us have been in the industry. Sam gets it, and he has some perspective on what's going on with all this market consolidation. What is it good for? He's got some things to say, and he's not shy about it.

YouTube: https://youtube.com/live/ROEA6z5Q-sk

Have something to say? Let's hear it.

Support the show

>>> Please cons...

Mark as Played

TL;DR: This week's show is a testament to surviving a week of Hacker Summer Camp out in Las Vegas. I have an interview with Ray Canzanese, Jr. (again, because y'all love him) and a bit of my take-away / rant from the week I spent out in the desert.

  Enjoy, I hope you made it home safe and learned something. Good God it was hot.

YouTube Video: ( standby, waiting on me to edit )

Thanks again to my friends at Netskope!

Have som...

Mark as Played

** Early release, due to Black Hat Conference and RaffCon XVIII.

TL;DR: This episode is all about #RaffCon. Ever wanted to know what the heck it is? Well, Raffael Marty and I break it down, give you a little history, and reminisce. As we got into Black Hat week, this is the perfect precursor to #RaffCon XVIII.


YouTube video: https://youtube.com/live/jwArV_EwuZc

Have something to say? Let's hear it.

Support the show

>>>...

Mark as Played

TL;DR: This is one of the most important episodes we've done on this podcast. The CISO and CIO have a complicated, dynamic, and often ugly relationship - but what should it be like? How can the two work together and evolve their roles together, for the benefit of everyone in the business? Larry Whiteside, Jr. ( Co-Founder and President at Confide) and Dennis McDonald ( Chief Information & Security Officer at Jack Henry ) l...

Mark as Played

TL;DR: This week's conversation is all about the Customer Success team featuring Nick Puetz and Steve Dakhe. These guys have significant seat time building, operating, and perfecting the CSM role - and we're here to talk about it. What is a CSM? Why do they exist? And what is their role in customer engagement? Listen in, find out!

YouTube: https://youtube.com/live/lCen-1Vt_K8

Have something to say? Let's hear it.

Support...

Mark as Played

TL;DR: This week we took a sit-down with serial entrepreneur, Will Gragido. Will has been a part of several innovative start-ups, and is now onto his next one. He's a product innovator with a pragmatic sense of what customers need, and he's here to give you the run-down of what drives him, what got him here, and things you should think about if you're thinking of setting off on your own.

YouTube video: https://youtube...

Mark as Played
July 8, 2025 39 mins

TL;DR: Did you miss us? Yes, we're back with Sam Masiello and we're talking about whatever is on his mind. Well ...there's geopolitics and Iranian hackers and frankly we need to talk about what it means for your security program.

Thanks for joining us, Sam!

YouTube Video: https://youtube.com/live/H-4ZktBIUDE

Have something to say? Let's hear it.

Show Sponsor: ThreatLocker
Allow what you need, block everything else...

Mark as Played

TL;DR:  This week's episode came from my (Rafal) brain. I've been reading far too much LinkedIn, and the "influencer" postings have been making me crazy. So, here we are. We talk through some of these posts, many of which are AI generated I think, and have a little fun with it. Call it...therapy.

YouTube Video: https://youtube.com/live/uZVfkge8bQE

Have something to say? Let's hear it.

Support the show

>>&g...

Mark as Played

TL;DR: On this episode, part 4 of our AI series, we are once again joined by Raja Mukerji, Jeff Collins, and John Dickson to discuss what it means to think about security for AI. Is it something completely different? Is it something same-'ol? Or - is it a bit of both. And what aren't we thinking about when it comes to securing AI?

YouTube video: https://youtube.com/live/vUJIOrX0kHc

Have something to say? Let's hear it.

S...

Mark as Played

TL;DR: This week I bring John Dickson back to join Jeff Collins and Raja Mukerji as we talk through the following:

  1. What can AI do, for cyber security, that we can't do with current tools?
  2. What is the model for incorporating AI into cybersecurity - are we replacing people? augmenting people? both? neither?
  3. Where is AI the strongest in these use-cases today, and where is the promise for 12 - 36 months out?
  4. What are the LIMITATIO...
Mark as Played

TL;DR: This week John Dickson returns to go deeper down the AI rabbit hole with special guest Erik Bloch as we dive into a more technical explanation of AI, how this innovation differs from other similar concepts, previous tech innovations, and some of the commercial vs consumer use-cases where AI is best suited. It's a deeper discussion, and we will for sure have a part 3, and likely 4 coming soon.

YouTube video: https://youtu...

Mark as Played

TL;DR: So - Artificial Intelligence (AI)...incomprehensible good, or catastrophic evil? Both? And what does that depend on? This episode is the start of a series wherein we explore the potential good or bad of AI, what the dependencies are. and what kinds of branches of discussion there could be. Join us as we discuss a generational topic, with some of our best guests starting with John Dickson.

Required listening: Episode 654 w/Sou...

Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Dateline NBC

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    CrimeLess: Hillbilly Heist

    It’s 1996 in rural North Carolina, and an oddball crew makes history when they pull off America’s third largest cash heist. But it’s all downhill from there. Join host Johnny Knoxville as he unspools a wild and woolly tale about a group of regular ‘ol folks who risked it all for a chance at a better life. CrimeLess: Hillbilly Heist answers the question: what would you do with 17.3 million dollars? The answer includes diamond rings, mansions, velvet Elvis paintings, plus a run for the border, murder-for-hire-plots, and FBI busts.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

    Crime Junkie

    Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by audiochuck Media Company.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.