Cover image of show The Art of Security

The Art of Security

Podcast by Fortra

English

News & politics

Then 99 kr. / month. Cancel anytime.

  • 20 hours of audiobooks / month
  • Podcasts only on Podimo
  • All free podcasts

About The Art of Security

Cybersecurity isn't an exact science. It's where art and science meet, informed by experience, tested in battle and reimagined to tackle evolving adversaries. In The Art of Security, Josh Davies and Tyler Reguly break down how security actually works in practice. From zero-day exploits and emerging threats to rethinking long-standing best practices, they explore what holds up — and what doesn't — in today's rapidly changing landscape. While the science of cybersecurity focuses on what's repeatable, the art of security is about making the right decisions in the moment. Each episode delivers practical insights, informed perspectives, and real-world context to help security professionals and tech enthusiasts stay ahead of evolving threats and build smarter, more resilient defenses.

All episodes

11 episodes

episode Supply Chain Compromise: Trust Is the Target artwork

Supply Chain Compromise: Trust Is the Target

We're told to patch fast, trust updates, and rely on the software ecosystems that power modern business. But what happens when that trust becomes the attack vector itself? In this episode of The Art of Security, Josh Davies and Tyler Reguly dive into the growing world of software supply chain compromise — from malicious open source packages and compromised dependencies to sleeper-agent style attacks that quietly infiltrate trusted projects for years before striking at scale. Josh and Tyler unpack how attackers are weaponizing trust, automation, and AI-assisted development to spread compromise at scale, while exploring practical defenses and why today's "patch immediately" mindset may no longer be enough. When trust is the delivery mechanism, every dependency becomes part of your attack surface. Make sure to subscribe to the podcast!

13 May 2026 - 31 min
episode The Art of Collective Defense artwork

The Art of Collective Defense

When one organization gets breached, attackers don't just win — they get better. In this episode of The Art of Security, we explore a powerful idea: Cybersecurity isn't a solo fight but a shared one. And when defenders collaborate, everyone gets stronger. Josh Davies and Tyler Reguly are joined by Jennifer Quaid and Bob Gordon from the Canadian Cyber Threat Exchange [https://cctx.ca/] (CCTX) to break down what effective collaboration really looks like in practice. From real-world intelligence sharing to cross-industry cooperation, they unpack how organizations can turn threat data into actionable defense and why keeping insights siloed only benefits attackers. You'll learn: * Why "when one wins, we all win" is more than just a slogan * How intelligence sharing improves detection, response, and resilience * The role of trust, community, and diverse perspectives in cybersecurity If you think cybersecurity is just about tools and technology, this conversation will challenge that assumption. Because in today's threat landscape, defense is a team sport. Subscribe for more real-world insights on cybersecurity, threat intelligence, and the decisions that shape effective defense.

29 Apr 2026 - 38 min
episode Stop Patching Everything: Rethinking Vulnerability Management with RSnake artwork

Stop Patching Everything: Rethinking Vulnerability Management with RSnake

In this episode of The Art of Security, Josh Davies and Tyler Reguly take a hard look at vulnerability management (VM) — one of the oldest and most widely adopted practices in cybersecurity — and ask a simple question: are we doing it wrong? Joined by special guest Robert "RSnake" Hansen, we unpack the critical differences between vulnerability management and patch management, and explore why treating them as the same thing may be holding organizations back. From the overwhelming volume of CVEs to the limitations of scoring systems like CVSS, this conversation challenges conventional thinking. Why do so few vulnerabilities actually lead to real-world breaches or business loss? And if that's the case, why are security teams still trying to patch everything? This episode is all about cutting through the noise and focusing on what truly reduces risk. If you've ever felt overwhelmed by vulnerability backlogs or questioned whether your VM program is actually making an impact, this conversation will challenge your assumptions — and give you a new lens to think about security.

15 Apr 2026 - 32 min
episode Trust No One (Especially on April Fools) artwork

Trust No One (Especially on April Fools)

It's April 1st which means nothing can be taken at face value. In this special April Fools' episode of The Art of Security, Josh Davies and Tyler Reguly dive into the long history of pranks in tech and cybersecurity — from spaghetti trees and RFC jokes to Google's legendary gags. But this isn't just a nostalgia trip as Tyler and Josh discuss humor, history, and have a serious conversation about trust, authority, and responsibility in cybersecurity today. This episode blends humor, history, and a serious conversation about trust, authority, and responsibility in cybersecurity today. Whether you're in security, tech, or just love a good prank, this episode will make you think twice before clicking anything on April 1st. Like, subscribe, and share if you enjoy the show!

1 Apr 2026 - 33 min
episode The Art of the Adversary: Scripted Sparrow artwork

The Art of the Adversary: Scripted Sparrow

Business email compromise is getting smarter, and Scripted Sparrow is proving it. Discover how the Scripted Sparrow threat group is running one of the most prolific BEC campaigns targeting organizations worldwide. In this episode of The Art of Security, we're joined by Fortra cybersecurity researcher John Wilson who breaks down how Scripted Sparrow executes highly targeted social engineering attacks that trick organizations into paying fraudulent invoices. Instead of traditional phishing, this group uses spoofed email conversations, fake executive coaching invoices, and carefully crafted tactics to bypass security controls and manipulate employees. Understanding how attackers think is the first step to stopping them. Make sure to subscribe to The Art of Security for more insights on cyber threats, adversary tactics, and real-world security strategies.

18 Mar 2026 - 34 min
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
Rigtig god tjeneste med gode eksklusive podcasts og derudover et kæmpe udvalg af podcasts og lydbøger. Kan varmt anbefales, om ikke andet så udelukkende pga Dårligdommerne, Klovn podcast, Hakkedrengene og Han duo 😁 👍
Podimo er blevet uundværlig! Til lange bilture, hverdagen, rengøringen og i det hele taget, når man trænger til lidt adspredelse.

Choose your subscription

Most popular

Limited Offer

Premium

20 hours of audiobooks

  • Podcasts only on Podimo

  • No ads in Podimo shows

  • Cancel anytime

2 months for 19 kr.
Then 99 kr. / month

Get Started

Premium Plus

Unlimited audiobooks

  • Podcasts only on Podimo

  • No ads in Podimo shows

  • Cancel anytime

Start 7 days free trial
Then 129 kr. / month

Start for free

Only on Podimo

Popular audiobooks

Get Started

2 months for 19 kr. Then 99 kr. / month. Cancel anytime.