Imagen de portada del programa STATUS: SECURE – The Cyber Threat Briefing

STATUS: SECURE – The Cyber Threat Briefing

Podcast de WatchUr6 - Cybersecurity

inglés

Negocios

Empieza 7 días de prueba

$99 / mes después de la prueba.Cancela cuando quieras.

  • 20 horas de audiolibros al mes
  • Podcasts solo en Podimo
  • Podcast gratuitos
Prueba gratis

Acerca de STATUS: SECURE – The Cyber Threat Briefing

You cannot be secure if you do not know the threat.On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy.Welcome to Status: Secure, the weekly cyber threat briefing for executives who refuse to operate in the blind.Hosted by the WatchUr6 collective, this show unites the battlefield with the boardroom. Featuring former Army Special Forces and Naval Special Warfare communications operators alongside an industry-leading CISO nominated for Cybersecurity Woman of the World.Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure.The enemy is listening. Is your status secure?

Todos los episodios

16 episodios

episode 016 PE and VC Funds Are Now Liable for Portfolio Cyber Breaches: The PowerSchool Case Study artwork

016 PE and VC Funds Are Now Liable for Portfolio Cyber Breaches: The PowerSchool Case Study

If you lose comms, you lose the mission. If you write the check without verifying what is in the codebase, you lose the fund. In this episode we are analyzing the federal court ruling that rewired cybersecurity due diligence for the entire investment community. On March 18, 2026, a California federal judge allowed class action claims against Bain Capital to proceed for a data breach at PowerSchool that occurred before Bain acquired the company. The acquirer is now legally on the hook for the seller's pre-close cybersecurity failures. Every PE partner, VC general partner, family office principal, and corporate development executive deploying capital in 2026 just got a new precedent. The era of "verify SOC 2 and move on" is over. Intel Declassified in this Briefing: * [00:00] The March 2026 Ruling That Rewired Cyber Diligence: How one federal court decision made the acquirer legally responsible for the seller's pre-acquisition cybersecurity failures. * [01:39] The PowerSchool Case Walkthrough: 60 million students, 10 million teachers, stolen vendor credentials, and a ShinyHunters ransom demand two months after close. * [08:26] Why Financial Diligence Is Rigorous and Cyber Diligence Isn't: The double standard inside every investment process, and the Yahoo/Verizon $350 million reference point that should have ended it years ago. * [12:46] The Five-Point Technical Assessment Every Investor Needs: Secrets in repositories, undocumented data flows, production access sprawl, missing audit trails, and the vendor DPA gap. * [15:34] The Three Layers of Fiduciary Exposure: Fund-level class action, GP-level LP letter, and personal liability for the partner who championed the deal. * [18:15] The Three Marching Orders Starting Monday: Upgrade the framework, audit the existing portfolio, build cyber into LP reporting. Mission Links: * Verify your Security Posture: https://watchur6.com/secure [https://watchur6.com/secure] * Want to Hire us: https://watchur6.com/contact/ [https://watchur6.com/contact/] * View the Show Notes: https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/ [https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/] * Read the Associated Sitrep: The Investor's Cyber Due Diligence Framework — A Four-Stage Playbook for PE and VC Funds After the PowerSchool Ruling: https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/ [https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/]

26 de may de 2026 - 21 min
episode 015 Inheriting Control Drift: Briefing for New Leaders, CMMC Annual Affirmations & Phase 2 Deadline artwork

015 Inheriting Control Drift: Briefing for New Leaders, CMMC Annual Affirmations & Phase 2 Deadline

If you lose comms, you lose the mission. If you inherit a control library you cannot operationally vouch for, you lose the contract — and possibly your name. In this episode we are analyzing the longest, quietest failure inside the Defense Industrial Base: control drift. There is no breach. No threat actor. No alarm. Just a slow, silent erosion of operational reality — a control library certified clean in 2021 that has decayed by 2026 through cleared workforce attrition, vendor migrations, and "vision-first" leadership making changes before they understand what they inherited. With Phase 2 of the CMMC Final Rule beginning November 10, every incoming CISO, IT Director, and Affirming Official is about to discover the gap between the System Security Plan they inherited and the operational reality they signed for. We break down the four decay patterns, the False Claims Act exposure the annual affirmation creates, and the three marching orders every GovCon executive must execute before the C3PAO walks the floor. Intel Declassified in this Briefing: * [00:00] The Paper Ghost: Why a control library that passed audit in 2021 may no longer exist operationally — and why no alarm fires when it decays. * [05:49] The Four Decay Patterns: Orphaned custom scripts, vendor migration gaps, SSP rot, and POA&M zombies that have aged into False Claims Act exhibits. * [13:16] Vision Without Inventory: Why incoming "modernization" leaders create control gaps faster than threat actors do — and the rule that prevents it. * [15:59] The Annual Affirmation Trap: How a named senior official's signature in SPRS becomes the foundation of a False Claims Act case when the underlying controls have drifted. * [19:30] The Three Marching Orders: Control Library Walkthrough, Tribal Knowledge Capture, and the Inherited Watch Protocol. Mission Links: * Verify your Security Posture: https://watchur6.com/secure [https://watchur6.com/secure] * Want to Hire us: https://watchur6.com/contact/ [https://watchur6.com/contact/] * View the Show Notes: https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/ [https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/] * Read the Associated Sitrep: Building a Living Control Library — The GovCon Playbook for Surviving CMMC Phase 2 and the Annual Affirmation: https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/ [https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/]

19 de may de 2026 - 24 min
episode 014 The Transparency Trap: When Hackers Weaponize the SEC Against Banks artwork

014 The Transparency Trap: When Hackers Weaponize the SEC Against Banks

If you lose comms, you lose the mission. If you lose your compliance timeline, you lose the company. In this episode, we are analyzing the collision between the SEC's new 96-hour breach disclosure mandate and the extortion tactics of modern ransomware cartels. Many financial executives believe the SEC rule is just an administrative burden. The reality? Threat actors are actively weaponizing this mandate, using the threat of federal whistleblower complaints to force ransom payments while your incident response team is still trying to stop the bleeding. Intel Declassified in this Briefing: * The Dinner Bell: Why forcing public disclosure during an active breach invites secondary attacks. * The Reporting Dilemma: Why closing the vulnerability must happen before notifying leadership. * The e-Discovery Threat: How claiming "state-of-the-art" security in an SEC filing becomes a massive legal liability post-breach. * The Whistleblower Tactic: How hackers monitor 8-K filings and report you to the SEC if you miss the 96-hour window. * The Caremark Standard: How a technical failure transforms into personal liability for board directors. * Actionable Defense: How to define "materiality" thresholds and conduct board-level tabletop exercises before the fire starts. Mission Links: * Verify your Security Posture: https://watchur6.com/secure [https://watchur6.com/secure] * Want to Hire us: https://watchur6.com/contact/ [https://watchur6.com/contact/] * View the Show Notes: https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks [https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks] * Read the Associated Sitrep: How Threat Actors Weaponize the SEC's 96-Hour Rule Against Banks: https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/ [https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/]

12 de may de 2026 - 19 min
episode 013 The Dispersed Hospital: Securing Telehealth & Remote Patient Monitoring Risks artwork

013 The Dispersed Hospital: Securing Telehealth & Remote Patient Monitoring Risks

If you lose comms, you lose the mission. If you lose data integrity, you risk patient lives. In this episode, we are analyzing the rapid disappearance of the traditional hospital perimeter. Through the massive expansion of "Hospital-at-Home" programs, clinical care is now being delivered over highly vulnerable residential Wi-Fi networks. Many healthcare executives assume that deploying a clinical tablet into a home is secure simply because the hospital owns the hardware. The reality? Operating a telehealth kit over an unpatched, default-password consumer router turns a life-saving telemetry device into an open backdoor for adversaries.   Intel Declassified in this Briefing: * [00:00] The Disappearing Perimeter: Why delivering acute care over unsecured residential Wi-Fi completely invalidates your enterprise firewall. * [01:57] The Trojan Horse Scenario: How threat actors scan cheap smart home IoT devices to pivot directly into hospital-issued telehealth tablets. * [03:50] Kinetic Disruption: The terrifying reality of telemetry spoofing, where manipulated vital signs trigger false medical emergencies and divert hospital resources. * [06:11] The Fiduciary Duty: Why outsourcing patient care to the living room does not outsource your legal liability for data hygiene. * [10:45] Actionable Defense: How to bypass the home network entirely using cellular-first deployments and strict Zero Trust Network Access.   Mission Links: * Verify your Security Posture: https://watchur6.com/secure [https://watchur6.com/secure] * Want to Hire us: https://watchur6.com/contact/ [https://watchur6.com/contact/] * View the Show Notes: https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring [https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring] * Read the Associated Sitrep: The Dispersed Hospital: Why Remote Patient Monitoring is a Cybersecurity Minefield: https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks [https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks]

5 de may de 2026 - 13 min
episode 012 The New Insider Threat: Securing Autonomous AI Agents & The BYOD Lesson artwork

012 The New Insider Threat: Securing Autonomous AI Agents & The BYOD Lesson

If you lose control of your algorithm, you lose control of your company. In this episode of Status: Secure, we are analyzing the sudden, largely unregulated integration of internal AI agents within the Tech Sector. For 20 years, we built our security around the "human firewall," relying on human intuition to catch anomalies. But what happens when you strip the human out of the loop? We break down the recent Meta internal AI misconfiguration, why granting non-human identities read/write access is a ticking time bomb, and why the current AI landscape is a lethal repeat of the Bring Your Own Device (BYOD) era. Intel Declassified in this Briefing: * [00:00] The Missing Gut Feeling: Why stripping human intuition out of the loop creates an autonomous insider threat. * [02:54] The BYOD Parallel: How the AI revolution mirrors the chaotic Bring Your Own Device era and the rapid dissolution of the identity perimeter. * [06:08] The Speed of Failure: The devastating difference between a human misplacing a file and an AI recursively altering cloud permissions in milliseconds. * [07:59] Fiduciary Duty: Why you legally own the actions of your AI, and how regulators define "reasonable care." * [10:14] The Command Decision: Two immediate steps—Non-Human Identity Audits and Human-in-the-Loop workflows—to secure your environment tomorrow.   Mission Links: * Verify your Security Posture: https://watchur6.com/secure [https://watchur6.com/secure] * Want to Hire us: https://watchur6.com/contact/ [https://watchur6.com/contact/] * View the Show Notes: https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod [https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod] * Read the Associated Sitrep: Non-Human Identity Management: The Lethal Risk of Over-Permissioned AI Agents: https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/ [https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/]

28 de abr de 2026 - 12 min
Muy buenos Podcasts , entretenido y con historias educativas y divertidas depende de lo que cada uno busque. Yo lo suelo usar en el trabajo ya que estoy muchas horas y necesito cancelar el ruido de al rededor , Auriculares y a disfrutar ..!!
Muy buenos Podcasts , entretenido y con historias educativas y divertidas depende de lo que cada uno busque. Yo lo suelo usar en el trabajo ya que estoy muchas horas y necesito cancelar el ruido de al rededor , Auriculares y a disfrutar ..!!
Fantástica aplicación. Yo solo uso los podcast. Por un precio módico los tienes variados y cada vez más.
Me encanta la app, concentra los mejores podcast y bueno ya era ora de pagarles a todos estos creadores de contenido

Elige tu suscripción

Más populares

Premium

20 horas de audiolibros

  • Podcasts solo en Podimo

  • Disfruta los shows de Podimo sin anuncios

  • Cancela cuando quieras

Empieza 7 días de prueba
Después $99 / mes

Prueba gratis

Sólo en Podimo

Audiolibros populares

Preguntas frecuentes

Más preguntas y respuestas
Prueba gratis

Empieza 7 días de prueba. $99 / mes después de la prueba. Cancela cuando quieras.