PodcastsTechnologyThe Audit - Cybersecurity Podcast

The Audit - Cybersecurity Podcast

IT Audit Labs
The Audit - Cybersecurity Podcast
Latest episode

91 episodes

  • The Audit - Cybersecurity Podcast

    Inside Email Security: Phishing, Hackers, and Harmony Checkpoint

    04/05/2026 | 32 mins.
    Most organizations think they're protected. They're not. Microsoft Defender sounds solid on paper — but in the real world, it's letting phishing, malware, and business email compromise walk right through the door. In this episode of The Audit, the crew pulls back the curtain on one of the most exploited attack surfaces in any organization: email. 
    Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem are joined by IT Audit Labs' own Cameron Birkland — fresh off three first-place CTF wins in Vegas — for a live walkthrough of Check Point Harmony Email, a tool that plugs directly into your Microsoft 365 environment and shows you exactly what your current setup is missing. 
    🎯 What you'll learn in this episode: 
    Why out-of-the-box Microsoft Defender consistently fails against advanced phishing and BEC attacks — and what "good" email security actually looks like 
    How Check Point Harmony uses machine learning and contextual AI analysis (not just signature matching) to catch threats that bypass traditional filters 
    How threat actors silently set up forwarding rules and inbox monitoring to loot data for weeks — without triggering a single alert 
    IT Audit Labs' new "14 plus one" email security assessment — a 14-day live scan of your Microsoft 365 environment with a full debrief, no disruption required 
    A live demo of the Harmony dashboard: phishing reports, geo-anomaly detection, OneDrive malware scanning, and DLP for exposed sharing links 
    Whether you're securing a 50-person company or advising a 5,000-user enterprise, this episode gives you the practitioner-level insight to finally close the gap in your email defenses. 
    Don't wait until your organization is the next headline. Subscribe for weekly cybersecurity insights from the practitioners actually doing the work. Like, share, and leave us a review on Apple Podcasts if this episode hit home. 
    #emailsecurity #cybersecurity #phishing #businessemailcompromise #Microsoft365 #infosec #checkpoint #harmonyemail
  • The Audit - Cybersecurity Podcast

    Ghost in the Machine: AI Identities & the Spiritual Red Teaming

    20/04/2026 | 40 mins.
    Your organization may have hundreds of AI agents running right now that your security team doesn't know exist. Every single one is an identity. Every identity is an attack surface. 
    In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Madhav Nakar, security researcher on the Phantom Labs team at BeyondTrust, to break down one of the most underexplored threats in enterprise security today: untracked AI agents creating exploitable "ghost identities." Madhav just returned from RSA — where he noticed every booth had an AI angle and a bubble forming — and he's here to cut through the noise with hard-hitting research and practical guidance. 
    🔍 Key Topics Covered: 
    How low-code platforms let non-technical users spawn unvetted AI agents — and why that's a goldmine for attackers 
    Ghost identities: what happens when AI agents run on untracked, over-privileged system identities 
    The AWS sandbox DNS exfiltration proof-of-concept from BSides (BeyondTrust research) 
    Why siloed AWS, Azure, and Okta teams create hidden privilege escalation paths 
    "AI vs. AI" — the emerging defender model where autonomous systems monitor each other 
    Browser extension cross-contamination and prompt injection risk for enterprise Claude deployments 
    The three conditions that make any AI agent dangerous: private data access + untrusted instructions + tool execution 
    Madhav's framework: inventory → least privilege → visibility — the basics that still matter most 
    Bonus: Madhav shares how "spiritually red-teaming yourself" — facing fear, breaking false narratives, and building trust — maps directly to how security professionals should approach zero trust and identity management. Plus: Joshua, Eric, and Nick on conquering stage fright and what that has to do with cybersecurity culture. 
    Don't wait for a ghost identity to become a ghost incident. Subscribe for weekly cybersecurity insights from practitioners, researchers, and the people defending the frontlines. 

    #GhostIdentities, #AIAgentSecurity, #NonHumanIdentity, #ZeroTrust, #TheAuditPodcast
  • The Audit - Cybersecurity Podcast

    Cyber News: Iran Attacks, Greyware, and Backdoor Code

    06/04/2026 | 34 mins.
    What if the tools protecting your organization were the ones compromising it? In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem — joined by IT Audit Labs team member Samuel Cala live in the St. Paul studio — unpack a wave of cybersecurity stories that all converge on one unsettling theme: trust is being exploited at every layer of the stack. 
    From an Iranian-linked APT group targeting U.S. healthcare infrastructure, to a sophisticated GitHub Actions supply chain attack that backdoored an AI coding library used by thousands of developers — the crew breaks down exactly how threat actors are weaponizing the tools, platforms, and third-party services organizations depend on daily. 
    They also dive into a disturbing revelation about AI-powered audit certifications: one company allegedly fabricated compliance evidence to hand out ISO 27001 and SOC 2 certifications at a fraction of the cost — raising serious questions about what those credentials are actually worth. 
    In this episode: 
    🇮🇷 Iran's escalation from cyber espionage to active disruption — what signals to watch for 
    🔗 The GitHub Actions / LiteLLM supply chain attack explained step by step 
    🧾 How an AI certification firm allegedly faked audit evidence — and what it means for your vendor trust 
    📡 FCC bans on foreign-made routers and the gray market hardware problem hiding in plain sight 
    🤖 OpenAI kills Sora — what it signals about where AI is actually headed 
    Whether you're a CISO trying to defend against nation-state threats or a developer trusting open-source libraries, this episode delivers the context — and the hard questions — you need to stay ahead. 
    Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions! 
    #cybersecurity #supplychainattack #infosec #threatintelligence #ISO27001 #SOC2 #githubsecurity #irancyberattack #aicybersecurity #itauditlabs
  • The Audit - Cybersecurity Podcast

    Cognitive Surrender: How AI Weaponizes Human Psychology

    23/03/2026 | 43 mins.
    A $25 million wire transfer. A fake CFO. An entire executive team that didn't exist. This is what modern cybercrime looks like — and your firewall won't stop it. 
    In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum sit down with James McDowell — forensic psychology expert, cybercrime researcher, and adjunct professor at American Military University — to explore the chilling intersection of AI, human psychology, and cybercrime. James introduces the concept of "cognitive surrender": the slow, dangerous transfer of our thinking to AI tools, and how threat actors are exploiting it at scale. 
    What You'll Learn: 
    What "cognitive surrender" is and why it's cybercrime's greatest accelerant 
    How a $25M deepfake scam bypassed every red flag a trained employee had 
    The psychology behind System 1 vs. System 2 thinking — and why attackers time their strikes around your lunch break 
    Why voice passwords and family code phrases are becoming critical security tools 
    How FraudGPT and dark-web AI models are lowering the barrier for cybercriminals 
    What James's wave theory reveals about how we trust — and how that trust gets exploited 
    📖 Guest: James McDowell Forensic psychologist, cybercrime researcher, and author of Forensic Psychology and the Human Side of Cybercrime. James teaches at American Military University and leads research at [Research Institute] focused on the psychology of cyber offenders and victims. 
    📚 Book available on Amazon and Routledge. Search: Forensic Psychology and the Human Side of Cybercrime 
    Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers the psychological intelligence to help protect your business. Like, share, and subscribe for more in-depth security discussions! 
    #cybersecurity #cybercrime #socialengineering #deepfake #AIthreats #infosec #phishing #cyberpsychology #ethicalhacking #CISO
  • The Audit - Cybersecurity Podcast

    Surviving a Cardiac Event: Biometric Data and the Risks Nobody Talks About

    09/03/2026 | 36 mins.
    What if the device keeping you alive was also a cybersecurity vulnerability? That's not a hypothetical — it's Victor Barge's reality. 
    In this episode of The Audit, IT Audit Labs' Global Delivery Director Victor Barge shares the story of his sudden cardiac event and the life-saving defibrillator now implanted in his chest and the eye-opening security questions that followed. Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum connect Victor's story to the real-world cyber risks organizations ignore every single day. 
    What you'll learn in this episode: 
    How modern pacemakers and defibrillators transmit biometric data 24/7 — and what happens if that data is compromised 
    Why the 2017 Abbott pacemaker recall of 500,000 devices is a warning the industry hasn't fully heeded 
    The parallel between reactive healthcare and reactive cybersecurity — and why waiting costs you more 
    Why billion-dollar organizations are still storing passwords in spreadsheets in 2026 
    What continuous monitoring in IT security can learn from real-time cardiac telemetry 
    Whether you're a CISO, IT auditor, or just someone wearing a smartwatch, this episode will make you rethink what "sensitive data" really means.

More Technology podcasts

About The Audit - Cybersecurity Podcast

Brought to you by IT Audit Labs. Trusted cyber security experts and their guests discuss common security threats, threat actor techniques and other industry topics. IT Audit Labs provides organizations with the leverage of a network of partners and specialists suited for your needs.​We are experts at assessing security risk and compliance, while providing administrative and technical controls to improve our clients’ data security. Our threat assessments find the soft spots before the bad guys do, identifying likelihood and impact, while our security control assessments rank the level of maturity relative to the size of the organization.
Podcast website

Listen to The Audit - Cybersecurity Podcast, Acquired and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features

The Audit - Cybersecurity Podcast: Podcasts in Family