EP09 - How to Build Security That Actually Works | ft. Jeff Man (Consultant, Advisor & Podcaster)
In this episode, I speak with Jeff Man, a cybersecurity veteran with over 40 years of experience across NSA, red teaming, PCI, consulting, and industry leadership. Jeff shares a rare, ground-level view of what “security” actually means and why most organizations continue to get it wrong.
We discuss his journey from solving puzzles to joining NSA, building the agency’s first red team, working on early cryptographic systems, and spending two decades teaching companies how to think about risk, data, and process.
Jeff explains the critical difference between securing (technology, patching, fixing) and security (monitoring, process, diligence) and why the industry consistently overinvests in tools while underinvesting in thinking.
This episode is a deep, practical, honest conversation about how security really works, and why mindset matters more than any product.
Ideal for professionals across offensive, defensive, governance, and leadership roles who want to build long-lasting security programs.
What You Will Learn (Key Takeaways):
* Why most companies fix technology but ignore process
* How the cybersecurity mindset has shifted (and where it’s stuck)
* Stories from NSA, early crypto systems, and building the first red team
* Why PCI is misunderstood but extremely useful
* The difference between "securing" and "security"
* Why availability (not confidentiality) is today’s biggest problem
* The importance of curiosity and the “hacker mindset”
* Why marketing shapes cybersecurity more than we admit
* How to think, not just follow tools or trends
* What keeps Jeff going after decades in the field
Timestamps:
* 00:00 – Intro
* 00:59 – Welcoming Jeff Man
* 01:30 – Jeff’s journey from puzzles to NSA
* 06:30 – Early cryptographic work & first software crypto system
* 10:50 – Building NSA's first red team
* 15:30 – Why companies don’t fix security even after pen tests
* 17:30 – What organizations are getting wrong today
* 20:10 – Why focusing only on technology never works
* 22:30 – CIA triad misconceptions
* 25:30 – Vulnerability overload & why “fix everything” is impossible
* 28:30 – Securing vs. Security (monitoring, process, diligence)
* 31:50 – Why process, not people, is the real failure point
* 34:30 – Rethinking patching, compliance, and risk
* 38:20 – How Jeff keeps himself informed today
* 41:20 – Lessons from 900+ podcast episodes
* 43:00 – The hacker mindset: curiosity, questioning, thinking
* 49:20 – Why he continues speaking, podcasting, and mentoring
* 51:21 – Closing thoughts