Full Metal Packet
Ben Lipczynski is the Director of Security and Regulatory Services at Origina and a former British Royal Navy officer with 12 years operating nuclear submarines and global networks. He brings an operator-level perspective on what separates a contained incident from a months-long operational nightmare. In this episode, Ben breaks down why patching is not a silver bullet, why legacy systems are more defensible than most teams assume, and what the submarine service taught him about knowing your critical systems before an attacker finds them for you. He explains: ◼ Why siloed teams and poor system knowledge cause more breaches than sophisticated attacks ever do ◼ Why upgrading to the latest version often introduces more vulnerabilities than it removes ◼ How 700 scan findings came down to 20 real actions after proper contextual analysis ◼ Why the CVE volume problem is about to get significantly worse and what to do about it ◼ Why defense in depth, not patching, is the only strategy that holds up when an attacker gets inside Time Stamps: (0:00) Introduction (0:53) What corporate security teams get wrong vs. the military (2:22) The submarine mindset: 90% training, 10% operations (4:48) Operational clarity in the military: everyone knows the mission and their role (6:59) Military structure vs. corporate agility — opposites or the same need? (10:38) Why Ben left the Navy for cybersecurity (14:32) "Take a marching pace" — thinking before acting in incident response (18:09) The iPad water treatment plant story — OT connectivity creep in the real world (25:30) The myth of N-minus-one: legacy doesn't mean insecure (28:10) Open source dependency risk — 60% of vulnerabilities aren't in the core code (31:01) Slop squatting: attackers pre-registering AI-hallucinated package names (33:00) What to do when you can't patch — contextual risk-based defense in depth (36:26) The patch validation problem — exploits now arrive within hours of a CVE (44:00) Fully patched, still taken down — architecture beats updates (51:26) Log4J case study: why deleting the library beat the patch cycle (55:23) Practical advice for security teams managing legacy systems (1:02:22) The CVE volume crisis — is the current patching model even tenable? (1:07:21) Bold prediction: CVE text itself will become an attack vector for AI agents Connect with the speakers ⬇️: Ben Lipchinski: https://www.linkedin.com/in/benlipczynskisecurity/ [https://www.linkedin.com/in/benlipczynskisecurity/] Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/ [https://www.linkedin.com/in/yegor-sak-725330b2/] Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/ [https://www.linkedin.com/in/alex-paguis-53a21815/] Powered by Control D [https://controld.com/]
10 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Full Metal Packet!