C-Suite Cyber Podcast
What are most organizations still getting wrong with security? In this episode, we sit down with Spencer (@techspence), a penetration tester who’s tested over 150 organizations, to break down the real-world gaps attackers are still exploiting every day. We start with a surprising truth: some of the most effective attacks today aren’t new. Simple issues like local admin password reuse are still everywhere, and they’re often all an attacker needs to take over an environment. From there, we dig into how the shift to cloud and hybrid environments is changing the game. Moving to Microsoft 365 and Entra doesn’t eliminate risk, it reshapes it. Identity has become the new battleground, and misconfigurations, over-permissioned users, and weak access controls are opening doors most teams don’t even realize exist. We also get into: * Why “secure” is a myth and resilience is what actually matters * How attackers bypass EDR and why detection is still lagging behind * The hidden risks in SaaS, SSO, and vendor trust * Why context matters more than vulnerability severity scores * How to communicate security findings in a way the business actually understands Plus, we explore what’s coming next. AI, agent-based workflows, and the rise of supply chain risk are creating entirely new attack surfaces, and most organizations aren’t ready. Spencer shares why AI won’t replace pentesters anytime soon, but will force everyone in the industry to level up. This episode is packed with real-world insights from the front lines of offensive security, along with lessons for defenders, leaders, and anyone responsible for protecting a business. If you want to understand what actually matters in security right now, this is the conversation to listen to. ___________________________________ Connect with Spencer: https://www.linkedin.com/in/spenceralessi/ https://spenceralessi.com/ https://x.com/techspence https://www.youtube.com/@cyberthreatpov ___________________________________ Connect with C-Suite Cyber: LinkedIn [https://www.linkedin.com/company/c-suite-cyber-podcast] [https://x.com/suite_cybe82537] X [https://x.com/suite_cybe82537] Instagram [https://www.instagram.com/csuitecyberpodcast/] [https://www.tiktok.com/@c_suite_cyber_podcast] TikTok [https://www.tiktok.com/@c_suite_cyber_podcast]
24 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de C-Suite Cyber Podcast!