<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2094080.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>The Security Table</title>

  <lastBuildDate>Wed, 01 Jul 2026 09:00:03 -0400</lastBuildDate>
  <link>https://securitytable.buzzsprout.com</link>
  <language>en-us</language>
  <copyright>© 2026 The Security Table</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>c9caf162-7268-5690-beb1-cda9e4955968</podcast:guid>
<podcast:podroll>
    <podcast:remoteItem feedGuid="01ddf729-9e1f-5de2-bcb0-89a7d079eb44" feedUrl="https://feeds.buzzsprout.com/1730684.rss" />
    <podcast:remoteItem feedGuid="ec10c9b5-951a-53d7-a63b-36593f50c6d7" feedUrl="https://feeds.buzzsprout.com/2152378.rss" />
  </podcast:podroll>
  <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>The Security Table is four cybersecurity industry veterans from diverse backgrounds discussing how to build secure software and all the issues that arise!</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:name>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/1mysi67s7rm70u9txeljqcza86yf?.jpg</url>
     <title>The Security Table</title>
     <link>https://securitytable.buzzsprout.com</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/1mysi67s7rm70u9txeljqcza86yf?.jpg" />
  <itunes:category text="Technology" />
  <podcast:person role="co-host" img="https://storage.buzzsprout.com/0s4yre5kt6c56qcs7e0yz5a8a1yc">Chris Romeo</podcast:person>
  <podcast:person role="co-host" img="https://storage.buzzsprout.com/401bn3carhtm4lgjxk0m4aha4hol">Izar Tarandach</podcast:person>
  <podcast:person role="co-host" img="https://storage.buzzsprout.com/70ch2509jejta6ujezvdxph29rnv">Matt Coles</podcast:person>
  <item>
    <itunes:title>Don&#39;t Bury the Model T: Why STRIDE Still Drives in an AI World</itunes:title>
    <title>Don&#39;t Bury the Model T: Why STRIDE Still Drives in an AI World</title>
    <itunes:summary><![CDATA[In this episode, we dig into two things the security community loves to argue about: npm finally doing the right thing and whether STRIDE has any business being called dead. The npm v12 changes gate dangerous install script behavior by default, which is a good step forward and also about a decade overdue. Then we wade into a hot take claiming that STRIDE was built for a world that no longer exists, and we push back hard on the idea that non-deterministic AI systems need an entirely new threat...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we dig into two things the security community loves to argue about: npm finally doing the right thing and whether STRIDE has any business being called dead. The npm v12 changes gate dangerous install script behavior by default, which is a good step forward and also about a decade overdue. Then we wade into a hot take claiming that STRIDE was built for a world that no longer exists, and we push back hard on the idea that non-deterministic AI systems need an entirely new threat-modeling religion rather than a better understanding of the one we already have. Also: wheat, Oregon Trail, and Emacs.</b></p><p><b>🚀 Join the Conversation<br/> If your threat model failed because of an AI hallucination, was that STRIDE&apos;s fault or yours?</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we dig into two things the security community loves to argue about: npm finally doing the right thing and whether STRIDE has any business being called dead. The npm v12 changes gate dangerous install script behavior by default, which is a good step forward and also about a decade overdue. Then we wade into a hot take claiming that STRIDE was built for a world that no longer exists, and we push back hard on the idea that non-deterministic AI systems need an entirely new threat-modeling religion rather than a better understanding of the one we already have. Also: wheat, Oregon Trail, and Emacs.</b></p><p><b>🚀 Join the Conversation<br/> If your threat model failed because of an AI hallucination, was that STRIDE&apos;s fault or yours?</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19356679-don-t-bury-the-model-t-why-stride-still-drives-in-an-ai-world.mp3" length="42546362" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19356679</guid>
    <pubDate>Wed, 01 Jul 2026 09:00:00 -0400</pubDate>
    <itunes:duration>3543</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World</itunes:title>
    <title>Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World</title>
    <itunes:summary><![CDATA[In this episode, we dig into whether DAST is dead, mostly dead, or quietly making a comeback dressed in an AI trench coat. The conversation traces the origins of dynamic application security testing from nmap scans and open source hacker tools to a market now valued at nearly four billion dollars and growing. We debate where DAST ends, and AI pen testing begins, whether AI can find a vulnerability nobody has ever seen before, and what happens when you compound the false positives of rigid rul...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we dig into whether DAST is dead, mostly dead, or quietly making a comeback dressed in an AI trench coat. The conversation traces the origins of dynamic application security testing from nmap scans and open source hacker tools to a market now valued at nearly four billion dollars and growing. We debate where DAST ends, and AI pen testing begins, whether AI can find a vulnerability nobody has ever seen before, and what happens when you compound the false positives of rigid rule-based scanning with the hallucinations of a large language model. Also: cats meowing the Final Countdown.</b></p><p><b>🚀 Join the Conversation<br/> If AI pen testing can already find zero days in open source software, does human pen testing still have a defensible edge — or are we just not ready to admit it doesn&apos;t?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we dig into whether DAST is dead, mostly dead, or quietly making a comeback dressed in an AI trench coat. The conversation traces the origins of dynamic application security testing from nmap scans and open source hacker tools to a market now valued at nearly four billion dollars and growing. We debate where DAST ends, and AI pen testing begins, whether AI can find a vulnerability nobody has ever seen before, and what happens when you compound the false positives of rigid rule-based scanning with the hallucinations of a large language model. Also: cats meowing the Final Countdown.</b></p><p><b>🚀 Join the Conversation<br/> If AI pen testing can already find zero days in open source software, does human pen testing still have a defensible edge — or are we just not ready to admit it doesn&apos;t?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19356650-mostly-dead-or-mostly-back-the-zombie-resurrection-of-dast-in-an-ai-world.mp3" length="30477187" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19356650</guid>
    <pubDate>Wed, 24 Jun 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2537</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Realists At The Table: How To See Through The Hype</itunes:title>
    <title>Realists At The Table: How To See Through The Hype</title>
    <itunes:summary><![CDATA[In this episode, we dig into how the cybersecurity personality has shifted from the ego-driven, hoodie-up archetype to the paycheck-chasing newcomer. The conversation covers hype cycles from mainframes to AI to quantum, whether passion or profit is driving the next generation into the field, and why we think the threat modeling problem is already solved. At the same time, everyone else keeps getting in the way. The discussion takes detours through The Cuckoo's Egg, Sneakers, War Games, and NF...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we dig into how the cybersecurity personality has shifted from the ego-driven, hoodie-up archetype to the paycheck-chasing newcomer. The conversation covers hype cycles from mainframes to AI to quantum, whether passion or profit is driving the next generation into the field, and why we think the threat modeling problem is already solved. At the same time, everyone else keeps getting in the way. The discussion takes detours through </b><b><em>The Cuckoo&apos;s Egg</em></b><b>, </b><b><em>Sneakers</em></b><b>, </b><b><em>War Games</em></b><b>, and NFT apes before landing on a question we couldn&apos;t quite agree on: Does AI actually have a personality, and does it belong in the security community?</b></p><p><b>🚀 Join the Conversation<br/> If you got into cybersecurity for the love of the problem or the paycheck, would you even know the difference anymore?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we dig into how the cybersecurity personality has shifted from the ego-driven, hoodie-up archetype to the paycheck-chasing newcomer. The conversation covers hype cycles from mainframes to AI to quantum, whether passion or profit is driving the next generation into the field, and why we think the threat modeling problem is already solved. At the same time, everyone else keeps getting in the way. The discussion takes detours through </b><b><em>The Cuckoo&apos;s Egg</em></b><b>, </b><b><em>Sneakers</em></b><b>, </b><b><em>War Games</em></b><b>, and NFT apes before landing on a question we couldn&apos;t quite agree on: Does AI actually have a personality, and does it belong in the security community?</b></p><p><b>🚀 Join the Conversation<br/> If you got into cybersecurity for the love of the problem or the paycheck, would you even know the difference anymore?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19356587-realists-at-the-table-how-to-see-through-the-hype.mp3" length="27056561" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19356587</guid>
    <pubDate>Wed, 17 Jun 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2252</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Agentic Access Problem: When AI Becomes Its Own Administrator</itunes:title>
    <title>The Agentic Access Problem: When AI Becomes Its Own Administrator</title>
    <itunes:summary><![CDATA[In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why "because the agent told me to" may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt's un...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why &quot;because the agent told me to&quot; may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt&apos;s unexpected habit of reading both.</b></p><p><b>🚀 Join the Conversation</b></p><p><b>If your AI agent requested administrator access right now, would you know whether it actually needed it?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why &quot;because the agent told me to&quot; may become the next security anti-pattern—before taking a hilarious detour into EULAs, cookie notices, and Matt&apos;s unexpected habit of reading both.</b></p><p><b>🚀 Join the Conversation</b></p><p><b>If your AI agent requested administrator access right now, would you know whether it actually needed it?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19282497-the-agentic-access-problem-when-ai-becomes-its-own-administrator.mp3" length="28918286" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19282497</guid>
    <pubDate>Wed, 03 Jun 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2407</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Tool Creep Problem: When More Security Means Less Security</itunes:title>
    <title>The Tool Creep Problem: When More Security Means Less Security</title>
    <itunes:summary><![CDATA[In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in the gap between what agents are told to do and what they are ac...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in the gap between what agents are told to do and what they are actually capable of. At the end of the day, it comes back to fundamentals: define your agents&apos; boundaries, limit their capabilities to only what they need, and stop confusing tool accumulation with security maturity.</b></p><p><b>🚀 Join the Conversation</b></p><p><b>If your AI agent were compromised today, would you even know it was the agent and not you?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in the gap between what agents are told to do and what they are actually capable of. At the end of the day, it comes back to fundamentals: define your agents&apos; boundaries, limit their capabilities to only what they need, and stop confusing tool accumulation with security maturity.</b></p><p><b>🚀 Join the Conversation</b></p><p><b>If your AI agent were compromised today, would you even know it was the agent and not you?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19143775-the-tool-creep-problem-when-more-security-means-less-security.mp3" length="30403811" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19143775</guid>
    <pubDate>Fri, 08 May 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2531</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Human In The Loop Illusion: Why AI Approvals Are Failing Security</itunes:title>
    <title>The Human In The Loop Illusion: Why AI Approvals Are Failing Security</title>
    <itunes:summary><![CDATA[In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter. 🚀 Join the Conversation  Are we improving security, or just automating bad decisions faster?   FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel T...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter.</b></p><p><b>🚀 Join the Conversation<br/> Are we improving security, or just automating bad decisions faster?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter.</b></p><p><b>🚀 Join the Conversation<br/> Are we improving security, or just automating bad decisions faster?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19100882-the-human-in-the-loop-illusion-why-ai-approvals-are-failing-security.mp3" length="34430967" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19100882</guid>
    <pubDate>Thu, 30 Apr 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2866</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Mythos Problem: When AI Finds Every Vulnerability</itunes:title>
    <title>The Mythos Problem: When AI Finds Every Vulnerability</title>
    <itunes:summary><![CDATA[In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them. We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agents everywhere—and whether fighting AI with more AI actually solves the problem. At the end of the...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them.</b></p><p><b>We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agents everywhere—and whether fighting AI with more AI actually solves the problem.</b></p><p><b>At the end of the day, it comes back to fundamentals: reduce your attack surface, simplify your systems, and focus on what actually matters.</b></p><p><b><br/>🚀 Join the Conversation<br/>Is this a real shift in security—or just faster chaos?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them.</b></p><p><b>We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agents everywhere—and whether fighting AI with more AI actually solves the problem.</b></p><p><b>At the end of the day, it comes back to fundamentals: reduce your attack surface, simplify your systems, and focus on what actually matters.</b></p><p><b><br/>🚀 Join the Conversation<br/>Is this a real shift in security—or just faster chaos?</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/19017903-the-mythos-problem-when-ai-finds-every-vulnerability.mp3" length="34091761" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19017903</guid>
    <pubDate>Wed, 15 Apr 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2838</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What If AI Never Happened? The AppSec Reality Check</itunes:title>
    <title>What If AI Never Happened? The AppSec Reality Check</title>
    <itunes:summary><![CDATA[In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, from “vibe coding” and false confidence in results to the growing gap...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, from “vibe coding” and false confidence in results to the growing gap between finding and fixing vulnerabilities.</b></p><p><b>We also get into the tension between human-driven security practices and AI-assisted workflows, and whether the biggest challenges in AppSec are actually technical at all or still rooted in people and process. Plus, things take a turn as we let AI weigh in…and roast us a bit in the process.</b></p><p><b>Per usual, it’s a mix of thoughtful discussion, strong opinions, and a little chaos.</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, from “vibe coding” and false confidence in results to the growing gap between finding and fixing vulnerabilities.</b></p><p><b>We also get into the tension between human-driven security practices and AI-assisted workflows, and whether the biggest challenges in AppSec are actually technical at all or still rooted in people and process. Plus, things take a turn as we let AI weigh in…and roast us a bit in the process.</b></p><p><b>Per usual, it’s a mix of thoughtful discussion, strong opinions, and a little chaos.</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18978609-what-if-ai-never-happened-the-appsec-reality-check.mp3" length="33970758" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18978609</guid>
    <pubDate>Wed, 08 Apr 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2828</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Evolution Problem: After 100 Episodes, What’s Changed… and What Hasn’t?</itunes:title>
    <title>The Evolution Problem: After 100 Episodes, What’s Changed… and What Hasn’t?</title>
    <itunes:summary><![CDATA[We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never seem to go away. Along the way, we compare where we were then to where things stand now, calling out a few wins,...]]></itunes:summary>
    <description><![CDATA[<p><b>We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never seem to go away. Along the way, we compare where we were then to where things stand now, calling out a few wins, a few misses, and everything in between. After all this time, are we actually any smarter, or just better at explaining the same problems? This episode is part reflection, part reality check, and a look at what 100 episodes have really taught us.</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never seem to go away. Along the way, we compare where we were then to where things stand now, calling out a few wins, a few misses, and everything in between. After all this time, are we actually any smarter, or just better at explaining the same problems? This episode is part reflection, part reality check, and a look at what 100 episodes have really taught us.</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18944876-the-evolution-problem-after-100-episodes-what-s-changed-and-what-hasn-t.mp3" length="35795511" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18944876</guid>
    <pubDate>Wed, 01 Apr 2026 10:00:00 -0400</pubDate>
    <itunes:duration>2980</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Agent Access Problem: When AI Has the Keys, Who’s Really in Control?</itunes:title>
    <title>The Agent Access Problem: When AI Has the Keys, Who’s Really in Control?</title>
    <itunes:summary><![CDATA[In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior driven by prompts, and why “it won’t go rogue” might be missing the point entirely. We also...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior driven by prompts, and why “it won’t go rogue” might be missing the point entirely. We also question the growing hype around AI governance, whether security teams are actually gaining control or just making more lists, and what happens when agents start talking to each other… and running up your bill. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “maybe just add parental controls.”</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior driven by prompts, and why “it won’t go rogue” might be missing the point entirely. We also question the growing hype around AI governance, whether security teams are actually gaining control or just making more lists, and what happens when agents start talking to each other… and running up your bill. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “maybe just add parental controls.”</b></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18902530-the-agent-access-problem-when-ai-has-the-keys-who-s-really-in-control.mp3" length="34856664" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18902530</guid>
    <pubDate>Wed, 25 Mar 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2902</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Invisible Code Problem: When You Can’t See the Attack, Can You Stop It?</itunes:title>
    <title>The Invisible Code Problem: When You Can’t See the Attack, Can You Stop It?</title>
    <itunes:summary><![CDATA[In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whether this is a real emerging threat or just another overhyped security ...]]></itunes:summary>
    <description><![CDATA[<p><b>In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whether this is a real emerging threat or just another overhyped security scare. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “just don’t do it.</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p><b>In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whether this is a real emerging threat or just another overhyped security scare. Per usual, the conversation is filled with sarcasm, skepticism, and a healthy dose of “just don’t do it.</b></p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18872257-the-invisible-code-problem-when-you-can-t-see-the-attack-can-you-stop-it.mp3" length="26364821" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/9tzibweo8fbeqjjswo9k272p7ice?.jpg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18872257</guid>
    <pubDate>Fri, 20 Mar 2026 09:00:00 -0400</pubDate>
    <itunes:duration>2194</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Moltbook Dilemma: What Happens When AI Agents Start Networking</itunes:title>
    <title>The Moltbook Dilemma: What Happens When AI Agents Start Networking</title>
    <itunes:summary><![CDATA[In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the rapid advancements in AI and their impact on society. FOLLOW OUR...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the rapid advancements in AI and their impact on society.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the rapid advancements in AI and their impact on society.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18631442-the-moltbook-dilemma-what-happens-when-ai-agents-start-networking.mp3" length="29619521" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18631442</guid>
    <pubDate>Fri, 06 Feb 2026 08:00:00 -0500</pubDate>
    <itunes:duration>2465</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Walking Dead of Security: When AI Resurrects the Build vs. Buy Debate</itunes:title>
    <title>The Walking Dead of Security: When AI Resurrects the Build vs. Buy Debate</title>
    <itunes:summary><![CDATA[Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and potentially reviving the DIY coding culture of pre-open-source days. We also talk about how developers trained on open source are now leveraging AI built from that same foundation, raising questions about innovation and originality in modern programming....]]></itunes:summary>
    <description><![CDATA[<p>Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and potentially reviving the DIY coding culture of pre-open-source days. We also talk about how developers trained on open source are now leveraging AI built from that same foundation, raising questions about innovation and originality in modern programming.</p><p><a href='https://venturebeat.com/technology/build-vs-buy-is-dead-ai-just-killed-it'>Build vs Buy is Dead - AI Just Killed It </a></p><p><a href='https://thenewstack.io/traditional-code-review-is-dead-what-comes-next/'>Traditional Code Review is Dead</a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and potentially reviving the DIY coding culture of pre-open-source days. We also talk about how developers trained on open source are now leveraging AI built from that same foundation, raising questions about innovation and originality in modern programming.</p><p><a href='https://venturebeat.com/technology/build-vs-buy-is-dead-ai-just-killed-it'>Build vs Buy is Dead - AI Just Killed It </a></p><p><a href='https://thenewstack.io/traditional-code-review-is-dead-what-comes-next/'>Traditional Code Review is Dead</a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18578627-the-walking-dead-of-security-when-ai-resurrects-the-build-vs-buy-debate.mp3" length="29105445" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18578627</guid>
    <pubDate>Wed, 28 Jan 2026 08:00:00 -0500</pubDate>
    <itunes:duration>2422</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Crystal Penguins and AI Chaos: What Could Go Wrong in 2026?</itunes:title>
    <title>Crystal Penguins and AI Chaos: What Could Go Wrong in 2026?</title>
    <itunes:summary><![CDATA[We’re predicting what 2026 has in store for AI and cybersecurity. We explore the wild possibilities of AI integration gone wrong, from people accidentally connecting their AI to sensitive file systems to blaming their AI agents for losing critical data. The conversation takes a thoughtful turn as they debate which jobs might fall to AI automation and if the human touch is still irreplaceable? Examining real examples like the "Y'allbot" weather monitoring system and photorealistic AI actress T...]]></itunes:summary>
    <description><![CDATA[<p>We’re predicting what 2026 has in store for AI and cybersecurity. We explore the wild possibilities of AI integration gone wrong, from people accidentally connecting their AI to sensitive file systems to blaming their AI agents for losing critical data. The conversation takes a thoughtful turn as they debate which jobs might fall to AI automation and if the human touch is still irreplaceable? Examining real examples like the &quot;Y&apos;allbot&quot; weather monitoring system and photorealistic AI actress Tilly Norwood to illustrate how rapidly AI is transforming industries.Tune in and learn how to navigate the AI-powered future responsibly.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re predicting what 2026 has in store for AI and cybersecurity. We explore the wild possibilities of AI integration gone wrong, from people accidentally connecting their AI to sensitive file systems to blaming their AI agents for losing critical data. The conversation takes a thoughtful turn as they debate which jobs might fall to AI automation and if the human touch is still irreplaceable? Examining real examples like the &quot;Y&apos;allbot&quot; weather monitoring system and photorealistic AI actress Tilly Norwood to illustrate how rapidly AI is transforming industries.Tune in and learn how to navigate the AI-powered future responsibly.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18502911-crystal-penguins-and-ai-chaos-what-could-go-wrong-in-2026.mp3" length="28860911" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18502911</guid>
    <pubDate>Wed, 14 Jan 2026 08:00:00 -0500</pubDate>
    <itunes:duration>2402</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Cost of Knowing: How Cybersecurity Professionals View Innovation Differently</itunes:title>
    <title>The Cost of Knowing: How Cybersecurity Professionals View Innovation Differently</title>
    <itunes:summary><![CDATA[We’re pulling back the curtain on the technology industry to reveal what life looks like when you're constantly aware of what can go wrong. From the loss of childlike wonder when encountering new tech to the ethical dilemmas posed by autonomous vehicles, we discuss the unique burden of seeing technology's darker possibilities. We’re examining how years of witnessing security breaches and system failures shape a professional outlook that balances innovation with caution. FOLLOW OUR SOCIAL MEDI...]]></itunes:summary>
    <description><![CDATA[<p>We’re pulling back the curtain on the technology industry to reveal what life looks like when you&apos;re constantly aware of what can go wrong. From the loss of childlike wonder when encountering new tech to the ethical dilemmas posed by autonomous vehicles, we discuss the unique burden of seeing technology&apos;s darker possibilities. We’re examining how years of witnessing security breaches and system failures shape a professional outlook that balances innovation with caution.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re pulling back the curtain on the technology industry to reveal what life looks like when you&apos;re constantly aware of what can go wrong. From the loss of childlike wonder when encountering new tech to the ethical dilemmas posed by autonomous vehicles, we discuss the unique burden of seeing technology&apos;s darker possibilities. We’re examining how years of witnessing security breaches and system failures shape a professional outlook that balances innovation with caution.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18290422-the-cost-of-knowing-how-cybersecurity-professionals-view-innovation-differently.mp3" length="22026693" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18290422</guid>
    <pubDate>Wed, 03 Dec 2025 08:00:00 -0500</pubDate>
    <itunes:duration>1833</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Roller Coaster of Risk: A Threat Modeler&#39;s Perspective</itunes:title>
    <title>The Roller Coaster of Risk: A Threat Modeler&#39;s Perspective</title>
    <itunes:summary><![CDATA[What do roller coasters and threat modeling have in common? More than you'd think. In this episode, we explore how security professionals view risk differently than everyone else—and why that matters. From roller coaster anxiety to the ethics of identifying danger, we dive into the unique mindset that comes with being a threat modeler. Because once you learn to see threats everywhere, there's no going back. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podc...]]></itunes:summary>
    <description><![CDATA[<p>What do roller coasters and threat modeling have in common? More than you&apos;d think. In this episode, we explore how security professionals view risk differently than everyone else—and why that matters. From roller coaster anxiety to the ethics of identifying danger, we dive into the unique mindset that comes with being a threat modeler. Because once you learn to see threats everywhere, there&apos;s no going back.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What do roller coasters and threat modeling have in common? More than you&apos;d think. In this episode, we explore how security professionals view risk differently than everyone else—and why that matters. From roller coaster anxiety to the ethics of identifying danger, we dive into the unique mindset that comes with being a threat modeler. Because once you learn to see threats everywhere, there&apos;s no going back.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18255898-the-roller-coaster-of-risk-a-threat-modeler-s-perspective.mp3" length="32842597" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18255898</guid>
    <pubDate>Wed, 26 Nov 2025 08:00:00 -0500</pubDate>
    <itunes:duration>2734</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Can AI Replace Security Teams? The Software Quality Debate</itunes:title>
    <title>Can AI Replace Security Teams? The Software Quality Debate</title>
    <itunes:summary><![CDATA[Is the cybersecurity industry facing a security problem or a software quality problem? In this episode, we’re tackling the controversial claim that AI advancements could make security teams obsolete—and uncover the deeper issues plaguing software development. The conversation reveals an uncomfortable truth: software companies often transfer the risk of vulnerabilities to customers, creating a system where there's little incentive to invest in security by design. Can AI bridge this gap, or do ...]]></itunes:summary>
    <description><![CDATA[<p>Is the cybersecurity industry facing a security problem or a software quality problem? In this episode, we’re tackling the controversial claim that AI advancements could make security teams obsolete—and uncover the deeper issues plaguing software development. The conversation reveals an uncomfortable truth: software companies often transfer the risk of vulnerabilities to customers, creating a system where there&apos;s little incentive to invest in security by design. Can AI bridge this gap, or do we need fundamental changes in how we approach software development and regulation?</p><p>Article: <a href='https://www.theregister.com/2025/10/27/jen_easterly_ai_cybersecurity/'>Ex-CISA head thinks AI might fix code so fast we won&apos;t need security teams</a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Is the cybersecurity industry facing a security problem or a software quality problem? In this episode, we’re tackling the controversial claim that AI advancements could make security teams obsolete—and uncover the deeper issues plaguing software development. The conversation reveals an uncomfortable truth: software companies often transfer the risk of vulnerabilities to customers, creating a system where there&apos;s little incentive to invest in security by design. Can AI bridge this gap, or do we need fundamental changes in how we approach software development and regulation?</p><p>Article: <a href='https://www.theregister.com/2025/10/27/jen_easterly_ai_cybersecurity/'>Ex-CISA head thinks AI might fix code so fast we won&apos;t need security teams</a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18205842-can-ai-replace-security-teams-the-software-quality-debate.mp3" length="26430267" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18205842</guid>
    <pubDate>Wed, 19 Nov 2025 08:00:00 -0500</pubDate>
    <itunes:duration>2199</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Debate: Is the CIA Triad Truly Dead?</itunes:title>
    <title>The Debate: Is the CIA Triad Truly Dead?</title>
    <itunes:summary><![CDATA[We’re debating an online article claiming that the CIA Triad (Confidentiality, Integrity, Availability) is a relic and needs to be updated for 21st-century threats. The discussion includes whether new properties like authenticity, accountability, and resilience should be incorporated into modern security models. And we delve into the use of analogies, system properties versus values, and the role of ethical considerations in cybersecurity. Listen along to our discussion on whether the foundat...]]></itunes:summary>
    <description><![CDATA[<p>We’re debating an online article claiming that the CIA Triad (Confidentiality, Integrity, Availability) is a relic and needs to be updated for 21st-century threats. The discussion includes whether new properties like authenticity, accountability, and resilience should be incorporated into modern security models. And we delve into the use of analogies, system properties versus values, and the role of ethical considerations in cybersecurity. Listen along to our discussion on whether the foundational elements of security need a refresh.</p><p><a href='https://www.csoonline.com/article/4070548/the-cia-triad-is-dead-stop-using-a-cold-war-relic-to-fight-21st-century-threats.html'>The CIA Triad is Dead </a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re debating an online article claiming that the CIA Triad (Confidentiality, Integrity, Availability) is a relic and needs to be updated for 21st-century threats. The discussion includes whether new properties like authenticity, accountability, and resilience should be incorporated into modern security models. And we delve into the use of analogies, system properties versus values, and the role of ethical considerations in cybersecurity. Listen along to our discussion on whether the foundational elements of security need a refresh.</p><p><a href='https://www.csoonline.com/article/4070548/the-cia-triad-is-dead-stop-using-a-cold-war-relic-to-fight-21st-century-threats.html'>The CIA Triad is Dead </a></p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/18052458-the-debate-is-the-cia-triad-truly-dead.mp3" length="21450770" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18052458</guid>
    <pubDate>Wed, 22 Oct 2025 09:00:00 -0400</pubDate>
    <itunes:duration>1785</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Don’t Forget the Beauty of Simplicity: Exploring Shifts in Software Development</itunes:title>
    <title>Don’t Forget the Beauty of Simplicity: Exploring Shifts in Software Development</title>
    <itunes:summary><![CDATA[We’re debating the concepts of 'Shift Left' and 'Shift Down' in the world of cybersecurity. We explore the intricacies of developer responsibility, the impact of modern AI on code security, and the delicate balance between innovation and secure coding practices. Join us for a thought-provoking discussion that ranges from keeping our digital world secure, efficient and, most importantly, simple.  The Modernization Imperative: Shifting Left is for Suckers. Shift Down Instead.  FOLLOW ...]]></itunes:summary>
    <description><![CDATA[<p>We’re debating the concepts of &apos;Shift Left&apos; and &apos;Shift Down&apos; in the world of cybersecurity. We explore the intricacies of developer responsibility, the impact of modern AI on code security, and the delicate balance between innovation and secure coding practices. Join us for a thought-provoking discussion that ranges from keeping our digital world secure, efficient and, most importantly, simple. </p><p><a href='https://cloud.google.com/blog/products/application-development/richard-seroter-on-shifting-down-vs-shifting-left'>The Modernization Imperative: Shifting Left is for Suckers. Shift Down Instead. </a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re debating the concepts of &apos;Shift Left&apos; and &apos;Shift Down&apos; in the world of cybersecurity. We explore the intricacies of developer responsibility, the impact of modern AI on code security, and the delicate balance between innovation and secure coding practices. Join us for a thought-provoking discussion that ranges from keeping our digital world secure, efficient and, most importantly, simple. </p><p><a href='https://cloud.google.com/blog/products/application-development/richard-seroter-on-shifting-down-vs-shifting-left'>The Modernization Imperative: Shifting Left is for Suckers. Shift Down Instead. </a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17964781-don-t-forget-the-beauty-of-simplicity-exploring-shifts-in-software-development.mp3" length="24315645" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17964781</guid>
    <pubDate>Wed, 08 Oct 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2023</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>More Cowbell: Security and Speed in Agile</itunes:title>
    <title>More Cowbell: Security and Speed in Agile</title>
    <itunes:summary><![CDATA[We’re diving into the relevance and execution of threat modeling within agile development environments. We dissect the claims, explore the true integration of agile practices with threat modeling, and address the misconceptions and challenges commonly faced. Check out the episode to find out if threat modeling is indeed slowing down agile processes or if it can be seamlessly integrated for better security outcomes. The Problem With Threat Modeling in Application Security: Too Slow, Too Theore...]]></itunes:summary>
    <description><![CDATA[<p>We’re diving into the relevance and execution of threat modeling within agile development environments. We dissect the claims, explore the true integration of agile practices with threat modeling, and address the misconceptions and challenges commonly faced. Check out the episode to find out if threat modeling is indeed slowing down agile processes or if it can be seamlessly integrated for better security outcomes.</p><h1><a href='https://www.linkedin.com/pulse/problem-threat-modeling-application-security-too-slow-martin-cissp-8n5ye'>The Problem With Threat Modeling in Application Security: Too Slow, Too Theoretical, Not Agile</a></h1><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re diving into the relevance and execution of threat modeling within agile development environments. We dissect the claims, explore the true integration of agile practices with threat modeling, and address the misconceptions and challenges commonly faced. Check out the episode to find out if threat modeling is indeed slowing down agile processes or if it can be seamlessly integrated for better security outcomes.</p><h1><a href='https://www.linkedin.com/pulse/problem-threat-modeling-application-security-too-slow-martin-cissp-8n5ye'>The Problem With Threat Modeling in Application Security: Too Slow, Too Theoretical, Not Agile</a></h1><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17927720-more-cowbell-security-and-speed-in-agile.mp3" length="35044088" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17927720</guid>
    <pubDate>Wed, 01 Oct 2025 09:00:00 -0400</pubDate>
    <itunes:duration>2917</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Privateering the Cyber Seas: New Legislation on Cybercrime</itunes:title>
    <title>Privateering the Cyber Seas: New Legislation on Cybercrime</title>
    <itunes:summary><![CDATA[We’re discussing the intriguing world of cyber privateers and the concept of 'hacking back' against cyber criminals. The discussion centers around a proposed bill in the U.S. Congress, H.R. 4988, that aims to authorize private individuals to pursue cyber criminals with the full backing of government-issued letters of marque. We explore the historical context of privateers, the potential legal and ethical implications, and the modern-day ramifications of such measures. And debate whether bring...]]></itunes:summary>
    <description><![CDATA[<p>We’re discussing the intriguing world of cyber privateers and the concept of &apos;hacking back&apos; against cyber criminals. The discussion centers around a proposed bill in the U.S. Congress, H.R. 4988, that aims to authorize private individuals to pursue cyber criminals with the full backing of government-issued letters of marque. We explore the historical context of privateers, the potential legal and ethical implications, and the modern-day ramifications of such measures. And debate whether bringing back this old concept could be a solution to modern cyber threats or if it opens the door to more significant risks and unintended consequences. </p><p><a href='https://cointelegraph.com/news/us-bill-neo-privateers-answer-cybercrime'>US bill proposes 21st-century privateers to take on cybercrime</a></p><p><a href='https://www.congress.gov/bill/119th-congress/house-bill/4988/text'>H.R. 4988 - Scam Farms Marque and Reprisal Authorization Act of 2025</a></p><h1><br/></h1><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re discussing the intriguing world of cyber privateers and the concept of &apos;hacking back&apos; against cyber criminals. The discussion centers around a proposed bill in the U.S. Congress, H.R. 4988, that aims to authorize private individuals to pursue cyber criminals with the full backing of government-issued letters of marque. We explore the historical context of privateers, the potential legal and ethical implications, and the modern-day ramifications of such measures. And debate whether bringing back this old concept could be a solution to modern cyber threats or if it opens the door to more significant risks and unintended consequences. </p><p><a href='https://cointelegraph.com/news/us-bill-neo-privateers-answer-cybercrime'>US bill proposes 21st-century privateers to take on cybercrime</a></p><p><a href='https://www.congress.gov/bill/119th-congress/house-bill/4988/text'>H.R. 4988 - Scam Farms Marque and Reprisal Authorization Act of 2025</a></p><h1><br/></h1><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17893288-privateering-the-cyber-seas-new-legislation-on-cybercrime.mp3" length="25662267" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17893288</guid>
    <pubDate>Wed, 24 Sep 2025 09:00:00 -0400</pubDate>
    <itunes:duration>2135</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Making Privacy Less Cringey</itunes:title>
    <title>Making Privacy Less Cringey</title>
    <itunes:summary><![CDATA[Dr. Kim Wuyts and Avi Douglen join us in today's episode. Both guests are fresh from their training sessions at Black Hat and DEF CON in Las Vegas and share a quick overview of their experiences. We discuss a newly developed privacy awareness card game called 'Context and Cringe,' which aims to educate participants about privacy issues in a fun and interactive way. We also cover an upcoming training session at Global AppSec DC in November, where attendees will learn practical privacy strategi...]]></itunes:summary>
    <description><![CDATA[<p>Dr. Kim Wuyts and Avi Douglen join us in today&apos;s episode. Both guests are fresh from their training sessions at Black Hat and DEF CON in Las Vegas and share a quick overview of their experiences. We discuss a newly developed privacy awareness card game called &apos;Context and Cringe,&apos; which aims to educate participants about privacy issues in a fun and interactive way. We also cover an upcoming training session at Global AppSec DC in November, where attendees will learn practical privacy strategies and get hands-on experience with the card game. Join us as we explore how privacy differs from traditional security concerns in being less precise and more subjective.</p><h1><a href='https://owasp.org/www-project-authoritative-privacy-reference-project/'>OWASP Authoritative Privacy Reference Project</a></h1><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Dr. Kim Wuyts and Avi Douglen join us in today&apos;s episode. Both guests are fresh from their training sessions at Black Hat and DEF CON in Las Vegas and share a quick overview of their experiences. We discuss a newly developed privacy awareness card game called &apos;Context and Cringe,&apos; which aims to educate participants about privacy issues in a fun and interactive way. We also cover an upcoming training session at Global AppSec DC in November, where attendees will learn practical privacy strategies and get hands-on experience with the card game. Join us as we explore how privacy differs from traditional security concerns in being less precise and more subjective.</p><h1><a href='https://owasp.org/www-project-authoritative-privacy-reference-project/'>OWASP Authoritative Privacy Reference Project</a></h1><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17854372-making-privacy-less-cringey.mp3" length="20362378" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17854372</guid>
    <pubDate>Wed, 17 Sep 2025 09:00:00 -0400</pubDate>
    <itunes:duration>1694</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Decoding Mastro: AI Threat Modeling</itunes:title>
    <title>Decoding Mastro: AI Threat Modeling</title>
    <itunes:summary><![CDATA[We’re discussing the article, “Agentic AI Threat Modeling Framework: Maestro published back in February of this year on the Cloud Security Alliance blog. We discuss the various layers, patterns, and threats outlined in the framework, comparing it to existing methodologies like STRIDE and PASTA, and evaluate Maestro's structure, its potential complexity for developers, and its overall practicality and usefulness in the threat modeling arena. Listen along as we unravel the intricacies of the fr...]]></itunes:summary>
    <description><![CDATA[<p>We’re discussing the article, “Agentic AI Threat Modeling Framework: Maestro published back in February of this year on the Cloud Security Alliance blog. We discuss the various layers, patterns, and threats outlined in the framework, comparing it to existing methodologies like STRIDE and PASTA, and evaluate Maestro&apos;s structure, its potential complexity for developers, and its overall practicality and usefulness in the threat modeling arena. Listen along as we unravel the intricacies of the framework and share our candid thoughts on its strengths and weaknesses.</p><p><a href='https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro'>Agentic AI Threat Modeling Framework Maestro</a></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re discussing the article, “Agentic AI Threat Modeling Framework: Maestro published back in February of this year on the Cloud Security Alliance blog. We discuss the various layers, patterns, and threats outlined in the framework, comparing it to existing methodologies like STRIDE and PASTA, and evaluate Maestro&apos;s structure, its potential complexity for developers, and its overall practicality and usefulness in the threat modeling arena. Listen along as we unravel the intricacies of the framework and share our candid thoughts on its strengths and weaknesses.</p><p><a href='https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro'>Agentic AI Threat Modeling Framework Maestro</a></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17816076-decoding-mastro-ai-threat-modeling.mp3" length="35390146" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17816076</guid>
    <pubDate>Wed, 10 Sep 2025 09:00:00 -0400</pubDate>
    <itunes:duration>2946</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Vibe Startups, AI Problems, and Matt’s Precious Computer</itunes:title>
    <title>Vibe Startups, AI Problems, and Matt’s Precious Computer</title>
    <itunes:summary><![CDATA[We’re talking about the rise of "vibe startups" - entrepreneurs hunting for problems to solve rather than building solutions from personal experience. We chat about AI security challenges, questioning whether these are truly new problems or just old security concepts repackaged for the AI era. From prompt injection and guardrails to the scary reality of AI agents acting as humans, we examine whether the industry's obsession with AI is leaving traditional security gaps exposed. FOLLOW OUR SOCI...]]></itunes:summary>
    <description><![CDATA[<p>We’re talking about the rise of &quot;vibe startups&quot; - entrepreneurs hunting for problems to solve rather than building solutions from personal experience. We chat about AI security challenges, questioning whether these are truly new problems or just old security concepts repackaged for the AI era. From prompt injection and guardrails to the scary reality of AI agents acting as humans, we examine whether the industry&apos;s obsession with AI is leaving traditional security gaps exposed.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re talking about the rise of &quot;vibe startups&quot; - entrepreneurs hunting for problems to solve rather than building solutions from personal experience. We chat about AI security challenges, questioning whether these are truly new problems or just old security concepts repackaged for the AI era. From prompt injection and guardrails to the scary reality of AI agents acting as humans, we examine whether the industry&apos;s obsession with AI is leaving traditional security gaps exposed.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17590442-vibe-startups-ai-problems-and-matt-s-precious-computer.mp3" length="30496275" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17590442</guid>
    <pubDate>Wed, 06 Aug 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2538</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>AI, AppSec and the Meaning of Life: The Answer is 42</itunes:title>
    <title>AI, AppSec and the Meaning of Life: The Answer is 42</title>
    <itunes:summary><![CDATA[What are the core competencies that matter most for modern application security teams? Today we discuss understanding code and systems thinking and the crucial ability to assess risk in context - plus why your AppSec team might eventually get absorbed into engineering (and why it could be a good thing). We debate the role of developer mindset in security, the importance of technical depth over tool knowledge, and how to build teams that truly enable rather than gate development.     FOLL...]]></itunes:summary>
    <description><![CDATA[<p>What are the core competencies that matter most for modern application security teams? Today we discuss understanding code and systems thinking and the crucial ability to assess risk in context - plus why your AppSec team might eventually get absorbed into engineering (and why it could be a good thing). We debate the role of developer mindset in security, the importance of technical depth over tool knowledge, and how to build teams that truly enable rather than gate development. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What are the core competencies that matter most for modern application security teams? Today we discuss understanding code and systems thinking and the crucial ability to assess risk in context - plus why your AppSec team might eventually get absorbed into engineering (and why it could be a good thing). We debate the role of developer mindset in security, the importance of technical depth over tool knowledge, and how to build teams that truly enable rather than gate development. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17585675-ai-appsec-and-the-meaning-of-life-the-answer-is-42.mp3" length="32545103" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17585675</guid>
    <pubDate>Wed, 30 Jul 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2709</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Building the World&#39;s Largest Threat Model Library</itunes:title>
    <title>Building the World&#39;s Largest Threat Model Library</title>
    <itunes:summary><![CDATA[Today we’re joined by Petra Vukmirovic. Petra, is the head of information security at Numan and co-leader of the Threat Model Library Project. Petra shares her vision for creating a massive, structured dataset of crowdsourced threat models that could revolutionize how the cybersecurity community learns and shares threat modeling knowledge. We explore the complex challenges of convincing companies to share their threat models publicly, diving into concerns about legal liability, competitive ad...]]></itunes:summary>
    <description><![CDATA[<p>Today we’re joined by Petra Vukmirovic. Petra, is the head of information security at Numan and co-leader of the Threat Model Library Project. Petra shares her vision for creating a massive, structured dataset of crowdsourced threat models that could revolutionize how the cybersecurity community learns and shares threat modeling knowledge. We explore the complex challenges of convincing companies to share their threat models publicly, diving into concerns about legal liability, competitive advantage, and the fundamental tension between transparency and security risk. Listen along to learn more about this exciting project and its potential impact on the cybersecurity field.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Today we’re joined by Petra Vukmirovic. Petra, is the head of information security at Numan and co-leader of the Threat Model Library Project. Petra shares her vision for creating a massive, structured dataset of crowdsourced threat models that could revolutionize how the cybersecurity community learns and shares threat modeling knowledge. We explore the complex challenges of convincing companies to share their threat models publicly, diving into concerns about legal liability, competitive advantage, and the fundamental tension between transparency and security risk. Listen along to learn more about this exciting project and its potential impact on the cybersecurity field.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17471965-building-the-world-s-largest-threat-model-library.mp3" length="35818031" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17471965</guid>
    <pubDate>Wed, 09 Jul 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2982</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Vibe Coding: Can You Put Your Trust in the Machine?</itunes:title>
    <title>Vibe Coding: Can You Put Your Trust in the Machine?</title>
    <itunes:summary><![CDATA[We’re discussing vibe coding again and how AI-generated code is reshaping software development. We discuss the trustworthiness and maintainability of AI-generated code, examining the challenges of reviewing and integrating automated changes at scale. The conversation spans from practical concerns about code quality to broader implications for open-source projects in an AI-augmented world. We talk about identifying telltale patterns in AI-generated code and why context and traceability are bec...]]></itunes:summary>
    <description><![CDATA[<p>We’re discussing vibe coding again and how AI-generated code is reshaping software development. We discuss the trustworthiness and maintainability of AI-generated code, examining the challenges of reviewing and integrating automated changes at scale. The conversation spans from practical concerns about code quality to broader implications for open-source projects in an AI-augmented world. We talk about identifying telltale patterns in AI-generated code and why context and traceability are becoming essential for trusting automated systems.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re discussing vibe coding again and how AI-generated code is reshaping software development. We discuss the trustworthiness and maintainability of AI-generated code, examining the challenges of reviewing and integrating automated changes at scale. The conversation spans from practical concerns about code quality to broader implications for open-source projects in an AI-augmented world. We talk about identifying telltale patterns in AI-generated code and why context and traceability are becoming essential for trusting automated systems.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17437445-vibe-coding-can-you-put-your-trust-in-the-machine.mp3" length="31422282" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17437445</guid>
    <pubDate>Wed, 02 Jul 2025 13:00:00 -0400</pubDate>
    <itunes:duration>2615</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Traversing the Conference Circuit: Highlights and Insights</itunes:title>
    <title>Traversing the Conference Circuit: Highlights and Insights</title>
    <itunes:summary><![CDATA[It’s security conference season and we’re discussing the importance of networking, the value of in-person connections, and sharing insightful tips for delivering effective presentations. From recapping our conference experiences, debating the significance of keynotes, to reminiscing about the impact of classic rock bands like Def Leppard. Listen now to hear about conference experiences, mentoring sessions, and the evolving industry landscape. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcas...]]></itunes:summary>
    <description><![CDATA[<p>It’s security conference season and we’re discussing the importance of networking, the value of in-person connections, and sharing insightful tips for delivering effective presentations. From recapping our conference experiences, debating the significance of keynotes, to reminiscing about the impact of classic rock bands like Def Leppard. Listen now to hear about conference experiences, mentoring sessions, and the evolving industry landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>It’s security conference season and we’re discussing the importance of networking, the value of in-person connections, and sharing insightful tips for delivering effective presentations. From recapping our conference experiences, debating the significance of keynotes, to reminiscing about the impact of classic rock bands like Def Leppard. Listen now to hear about conference experiences, mentoring sessions, and the evolving industry landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17312269-traversing-the-conference-circuit-highlights-and-insights.mp3" length="31357379" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17312269</guid>
    <pubDate>Wed, 11 Jun 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2610</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>MCP…Something Could Go Wrong</itunes:title>
    <title>MCP…Something Could Go Wrong</title>
    <itunes:summary><![CDATA[We’re discussing the complexities of the Model Context Protocol (MCP) and its application in AI systems. Join us for an in-depth discussion about MCP, agent-to-agent communication, and potential security vulnerabilities. We wrap up with a thought-provoking conversation on the future of AI safety and the challenges it presents.  FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening! ]]></itunes:summary>
    <description><![CDATA[<p>We’re discussing the complexities of the Model Context Protocol (MCP) and its application in AI systems. Join us for an in-depth discussion about MCP, agent-to-agent communication, and potential security vulnerabilities. We wrap up with a thought-provoking conversation on the future of AI safety and the challenges it presents. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re discussing the complexities of the Model Context Protocol (MCP) and its application in AI systems. Join us for an in-depth discussion about MCP, agent-to-agent communication, and potential security vulnerabilities. We wrap up with a thought-provoking conversation on the future of AI safety and the challenges it presents. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17269954-mcp-something-could-go-wrong.mp3" length="32976104" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17269954</guid>
    <pubDate>Tue, 03 Jun 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2745</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Threat Modeling or Threat Intelligence, Are they the Same?</itunes:title>
    <title>Threat Modeling or Threat Intelligence, Are they the Same?</title>
    <itunes:summary><![CDATA[Listen in as we debate the differences between threat intelligence and threat modeling. What distinguishes these two concepts in cybersecurity, and how do they inform each other? The conversation explores definitions, real-world examples, and the interconnected relationship between proactive threat modeling and reactive threat intelligence. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening! ]]></itunes:summary>
    <description><![CDATA[<p>Listen in as we debate the differences between threat intelligence and threat modeling. What distinguishes these two concepts in cybersecurity, and how do they inform each other? The conversation explores definitions, real-world examples, and the interconnected relationship between proactive threat modeling and reactive threat intelligence.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Listen in as we debate the differences between threat intelligence and threat modeling. What distinguishes these two concepts in cybersecurity, and how do they inform each other? The conversation explores definitions, real-world examples, and the interconnected relationship between proactive threat modeling and reactive threat intelligence.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17196579-threat-modeling-or-threat-intelligence-are-they-the-same.mp3" length="21556132" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17196579</guid>
    <pubDate>Wed, 21 May 2025 08:00:00 -0400</pubDate>
    <itunes:duration>1793</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Skillset Over Experience: Rethinking Qualifications in Cybersecurity</itunes:title>
    <title>Skillset Over Experience: Rethinking Qualifications in Cybersecurity</title>
    <itunes:summary><![CDATA[Today we delve into the evolving landscape of cybersecurity hiring, debating the merits of prioritizing skills over degrees and experience. From discussing the value of critical thinking and hands-on skills to the potential role of AI in the workforce, the conversation navigates the complexities of hiring practices. We share personal anecdotes, insights from industry articles, and our experiences as hiring managers. Tune in for a humorous and thought-provoking discussion on what really matter...]]></itunes:summary>
    <description><![CDATA[<p>Today we delve into the evolving landscape of cybersecurity hiring, debating the merits of prioritizing skills over degrees and experience. From discussing the value of critical thinking and hands-on skills to the potential role of AI in the workforce, the conversation navigates the complexities of hiring practices. We share personal anecdotes, insights from industry articles, and our experiences as hiring managers. Tune in for a humorous and thought-provoking discussion on what really matters when building a successful cybersecurity team.</p><p><a href='https://www.csoonline.com/article/3963314/cisos-rethink-hiring-to-emphasize-skills-over-degrees-and-experience.html'>CISOs Rethink Hiring to Emphasize Skills Over Degrees and Experience</a> article</p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Today we delve into the evolving landscape of cybersecurity hiring, debating the merits of prioritizing skills over degrees and experience. From discussing the value of critical thinking and hands-on skills to the potential role of AI in the workforce, the conversation navigates the complexities of hiring practices. We share personal anecdotes, insights from industry articles, and our experiences as hiring managers. Tune in for a humorous and thought-provoking discussion on what really matters when building a successful cybersecurity team.</p><p><a href='https://www.csoonline.com/article/3963314/cisos-rethink-hiring-to-emphasize-skills-over-degrees-and-experience.html'>CISOs Rethink Hiring to Emphasize Skills Over Degrees and Experience</a> article</p><p><br/></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/17028842-skillset-over-experience-rethinking-qualifications-in-cybersecurity.mp3" length="28752184" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17028842</guid>
    <pubDate>Wed, 23 Apr 2025 13:00:00 -0400</pubDate>
    <itunes:duration>2393</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Vibe Coding: What Could Possibly Go Wrong?</itunes:title>
    <title>Vibe Coding: What Could Possibly Go Wrong?</title>
    <itunes:summary><![CDATA[Vibe coding, or using AI to generate code by describing what you want. We critically examine the concerns surrounding AI-generated code, including code quality, security risks, and the potential for creating numerous low-quality applications. Our discussion explores whether AI can truly provide foolproof, production-ready code, or if it should be limited to idea generation and prototyping. Catch our candid take on the dangers of relying on AI for software development and the importance of mai...]]></itunes:summary>
    <description><![CDATA[<p>Vibe coding, or using AI to generate code by describing what you want. We critically examine the concerns surrounding AI-generated code, including code quality, security risks, and the potential for creating numerous low-quality applications. Our discussion explores whether AI can truly provide foolproof, production-ready code, or if it should be limited to idea generation and prototyping. Catch our candid take on the dangers of relying on AI for software development and the importance of maintaining human expertise in the coding process.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Vibe coding, or using AI to generate code by describing what you want. We critically examine the concerns surrounding AI-generated code, including code quality, security risks, and the potential for creating numerous low-quality applications. Our discussion explores whether AI can truly provide foolproof, production-ready code, or if it should be limited to idea generation and prototyping. Catch our candid take on the dangers of relying on AI for software development and the importance of maintaining human expertise in the coding process.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16861651-vibe-coding-what-could-possibly-go-wrong.mp3" length="26367855" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16861651</guid>
    <pubDate>Wed, 26 Mar 2025 08:00:00 -0400</pubDate>
    <itunes:duration>2194</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Department of No</itunes:title>
    <title>The Department of No</title>
    <itunes:summary><![CDATA[We’re discussing the complexities of saying 'yes' or 'no' in the context of security decisions in today’s episode and the enduring challenge of integrating security into software development. The conversation swerves into the intriguing idea of a trade-like progression for developers, contrasting it with current knowledge work. The episode culminates in a hit parade of pop culture references, including Star Wars, Star Trek, Firefly, and more. Tune in for a thought-provoking and fun conversati...]]></itunes:summary>
    <description><![CDATA[<p>We’re discussing the complexities of saying &apos;yes&apos; or &apos;no&apos; in the context of security decisions in today’s episode and the enduring challenge of integrating security into software development. The conversation swerves into the intriguing idea of a trade-like progression for developers, contrasting it with current knowledge work. The episode culminates in a hit parade of pop culture references, including Star Wars, Star Trek, Firefly, and more. Tune in for a thought-provoking and fun conversation!</p><p><br/>Article Link:  <a href='https://ramimac.me/saying-no'>How to Say &apos;No&apos; Well</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We’re discussing the complexities of saying &apos;yes&apos; or &apos;no&apos; in the context of security decisions in today’s episode and the enduring challenge of integrating security into software development. The conversation swerves into the intriguing idea of a trade-like progression for developers, contrasting it with current knowledge work. The episode culminates in a hit parade of pop culture references, including Star Wars, Star Trek, Firefly, and more. Tune in for a thought-provoking and fun conversation!</p><p><br/>Article Link:  <a href='https://ramimac.me/saying-no'>How to Say &apos;No&apos; Well</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16609843-the-department-of-no.mp3" length="32581715" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16609843</guid>
    <pubDate>Wed, 12 Feb 2025 10:00:00 -0500</pubDate>
    <itunes:duration>2712</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Cyber Trust Mark Debate</itunes:title>
    <title>The Cyber Trust Mark Debate</title>
    <itunes:summary><![CDATA[The Cyber Trust Mark, a new FCC program aimed at assuring the security of IoT devices is the topic of discussion today. We discuss various aspects of the Cyber Trust Mark, the history of similar initiatives like UL certification, and the challenges faced by consumers in determining the security of their devices. They also debate the merits and drawbacks of regulations like the EU's Cyber Resilience Act, the importance of secure-by-default design, and the limitations of relying solely on consu...]]></itunes:summary>
    <description><![CDATA[<p>The Cyber Trust Mark, a new FCC program aimed at assuring the security of IoT devices is the topic of discussion today. We discuss various aspects of the Cyber Trust Mark, the history of similar initiatives like UL certification, and the challenges faced by consumers in determining the security of their devices. They also debate the merits and drawbacks of regulations like the EU&apos;s Cyber Resilience Act, the importance of secure-by-default design, and the limitations of relying solely on consumers or independent labs to ensure security. Throughout, they explore whether this new mark can genuinely make a difference or if it&apos;s just a rehash of old ideas.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Cyber Trust Mark, a new FCC program aimed at assuring the security of IoT devices is the topic of discussion today. We discuss various aspects of the Cyber Trust Mark, the history of similar initiatives like UL certification, and the challenges faced by consumers in determining the security of their devices. They also debate the merits and drawbacks of regulations like the EU&apos;s Cyber Resilience Act, the importance of secure-by-default design, and the limitations of relying solely on consumers or independent labs to ensure security. Throughout, they explore whether this new mark can genuinely make a difference or if it&apos;s just a rehash of old ideas.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16479093-the-cyber-trust-mark-debate.mp3" length="34025569" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16479093</guid>
    <pubDate>Wed, 22 Jan 2025 09:00:00 -0500</pubDate>
    <itunes:duration>2832</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Hovercrafts and the Evolution of AppSec in 2025</itunes:title>
    <title>Hovercrafts and the Evolution of AppSec in 2025</title>
    <itunes:summary><![CDATA[Hovercrafts and application security in the new year. We revisit last year's predictions on Quantum LLM, SBOMs, and whether DAST tools will make a comeback. With humor and forward-thinking, we explore what the future might hold for application security, the rise of new technologies, and even the outlandish idea of AppSec being dead.  Episode mentioned: AppSec Resolutions - January 9, 2024   FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube...]]></itunes:summary>
    <description><![CDATA[<p>Hovercrafts and application security in the new year. We revisit last year&apos;s predictions on Quantum LLM, SBOMs, and whether DAST tools will make a comeback. With humor and forward-thinking, we explore what the future might hold for application security, the rise of new technologies, and even the outlandish idea of AppSec being dead. </p><p>Episode mentioned:<br/><a href='https://youtu.be/lh532zWuYr4?list=PLTnfXLN6G1SmTN4QKQjVhkM3ISZqGW8w5'>AppSec Resolutions</a> - January 9, 2024</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Hovercrafts and application security in the new year. We revisit last year&apos;s predictions on Quantum LLM, SBOMs, and whether DAST tools will make a comeback. With humor and forward-thinking, we explore what the future might hold for application security, the rise of new technologies, and even the outlandish idea of AppSec being dead. </p><p>Episode mentioned:<br/><a href='https://youtu.be/lh532zWuYr4?list=PLTnfXLN6G1SmTN4QKQjVhkM3ISZqGW8w5'>AppSec Resolutions</a> - January 9, 2024</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16398557-hovercrafts-and-the-evolution-of-appsec-in-2025.mp3" length="25241569" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16398557</guid>
    <pubDate>Wed, 08 Jan 2025 09:00:00 -0500</pubDate>
    <itunes:duration>2100</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Find Your Conferences and watch Die Hard. And the Princess Bride.</itunes:title>
    <title>Find Your Conferences and watch Die Hard. And the Princess Bride.</title>
    <itunes:summary><![CDATA[What makes a conference truly valuable? Is it the unexpected connections and serendipitous meetings of minds, or the chance to break free from the "security echo chamber" by exploring diverse conference experiences? We discuss the considerations that make conferences worth attending and examine whether they are compelling enough to warrant personal investment. Whether large or intimate, each conference provides a distinct journey of learning and interaction.    FOLLOW OUR SOCIAL MEDIA: ➜Twitt...]]></itunes:summary>
    <description><![CDATA[<p>What makes a conference truly valuable? Is it the unexpected connections and serendipitous meetings of minds, or the chance to break free from the &quot;security echo chamber&quot; by exploring diverse conference experiences? We discuss the considerations that make conferences worth attending and examine whether they are compelling enough to warrant personal investment. Whether large or intimate, each conference provides a distinct journey of learning and interaction.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What makes a conference truly valuable? Is it the unexpected connections and serendipitous meetings of minds, or the chance to break free from the &quot;security echo chamber&quot; by exploring diverse conference experiences? We discuss the considerations that make conferences worth attending and examine whether they are compelling enough to warrant personal investment. Whether large or intimate, each conference provides a distinct journey of learning and interaction.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16256340-find-your-conferences-and-watch-die-hard-and-the-princess-bride.mp3" length="21066507" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16256340</guid>
    <pubDate>Wed, 11 Dec 2024 08:00:00 -0500</pubDate>
    <itunes:duration>1752</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Is it Necessary? Not everything requires an LLM</itunes:title>
    <title>Is it Necessary? Not everything requires an LLM</title>
    <itunes:summary><![CDATA[We debate the necessity and efficiency of LLMs in finding code vulnerabilities in a C library compared to traditional static code analyzers and fuzzing techniques. The conversation explores broader topics in application security testing, including the evolving landscape of Dynamic Application Security Testing (DAST), fuzzing, and the potential of emerging technologies like Application Detection and Response (ADR). FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Tab...]]></itunes:summary>
    <description><![CDATA[<p>We debate the necessity and efficiency of LLMs in finding code vulnerabilities in a C library compared to traditional static code analyzers and fuzzing techniques. The conversation explores broader topics in application security testing, including the evolving landscape of Dynamic Application Security Testing (DAST), fuzzing, and the potential of emerging technologies like Application Detection and Response (ADR).</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We debate the necessity and efficiency of LLMs in finding code vulnerabilities in a C library compared to traditional static code analyzers and fuzzing techniques. The conversation explores broader topics in application security testing, including the evolving landscape of Dynamic Application Security Testing (DAST), fuzzing, and the potential of emerging technologies like Application Detection and Response (ADR).</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16228268-is-it-necessary-not-everything-requires-an-llm.mp3" length="30745465" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16228268</guid>
    <pubDate>Tue, 10 Dec 2024 08:00:00 -0500</pubDate>
    <itunes:duration>2559</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The STRIDE Controversy: Evolution vs. Extinction in Security Models</itunes:title>
    <title>The STRIDE Controversy: Evolution vs. Extinction in Security Models</title>
    <itunes:summary><![CDATA[We discuss a controversial LinkedIn post claiming "Threat Modeling is Dead." While the STRIDE methodology may need updating, it remains a valuable "gateway" tool for teaching security concepts to developers without security backgrounds. We discuss how STRIDE serves as a useful categorization system, emphasize that dogmatic approaches to threat modeling are problematic, and argue that what matters most are results rather than strict adherence to any particular methodology. Our conclusion; STRI...]]></itunes:summary>
    <description><![CDATA[<p>We discuss a controversial LinkedIn post claiming &quot;Threat Modeling is Dead.&quot; While the STRIDE methodology may need updating, it remains a valuable &quot;gateway&quot; tool for teaching security concepts to developers without security backgrounds. We discuss how STRIDE serves as a useful categorization system, emphasize that dogmatic approaches to threat modeling are problematic, and argue that what matters most are results rather than strict adherence to any particular methodology. Our conclusion; STRIDE is still alive and relevant, but it could benefit from an update to demonstrate its continued applicability.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>We discuss a controversial LinkedIn post claiming &quot;Threat Modeling is Dead.&quot; While the STRIDE methodology may need updating, it remains a valuable &quot;gateway&quot; tool for teaching security concepts to developers without security backgrounds. We discuss how STRIDE serves as a useful categorization system, emphasize that dogmatic approaches to threat modeling are problematic, and argue that what matters most are results rather than strict adherence to any particular methodology. Our conclusion; STRIDE is still alive and relevant, but it could benefit from an update to demonstrate its continued applicability.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16096937-the-stride-controversy-evolution-vs-extinction-in-security-models.mp3" length="29687546" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16096937</guid>
    <pubDate>Wed, 13 Nov 2024 08:00:00 -0500</pubDate>
    <itunes:duration>2471</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why 100X Isn&#39;t the Answer</itunes:title>
    <title>Why 100X Isn&#39;t the Answer</title>
    <itunes:summary><![CDATA[A good discussion today covering two different articles, the first covers CISA's list of product security "bad practices", questioning whether it provides real value or is just content marketing. Then the discussion moves onto an article about Shift Left. The group debates whether it is truly more expensive to fix design flaws versus implementation bugs, noting the difficulty of quantifying the cost difference. They argue that the focus should be on providing proper training and incentives fo...]]></itunes:summary>
    <description><![CDATA[<p>A good discussion today covering two different articles, the first covers CISA&apos;s list of product security &quot;bad practices&quot;, questioning whether it provides real value or is just content marketing. Then the discussion moves onto an article about Shift Left. The group debates whether it is truly more expensive to fix design flaws versus implementation bugs, noting the difficulty of quantifying the cost difference. They argue that the focus should be on providing proper training and incentives for developers to build secure software, rather than just adding more security tools. </p><p>Articles discussed in the episode:</p><p><a href='https://www.cisa.gov/resources-tools/resources/product-security-bad-practices'>Product Security Bad Practices</a><br/><br/><a href='https://www.darkreading.com/application-security/shift-left-pushback-triggers-security-soul-searching'>Shift Left Pushback Triggers Security Soul Searching</a></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>A good discussion today covering two different articles, the first covers CISA&apos;s list of product security &quot;bad practices&quot;, questioning whether it provides real value or is just content marketing. Then the discussion moves onto an article about Shift Left. The group debates whether it is truly more expensive to fix design flaws versus implementation bugs, noting the difficulty of quantifying the cost difference. They argue that the focus should be on providing proper training and incentives for developers to build secure software, rather than just adding more security tools. </p><p>Articles discussed in the episode:</p><p><a href='https://www.cisa.gov/resources-tools/resources/product-security-bad-practices'>Product Security Bad Practices</a><br/><br/><a href='https://www.darkreading.com/application-security/shift-left-pushback-triggers-security-soul-searching'>Shift Left Pushback Triggers Security Soul Searching</a></p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/16064983-why-100x-isn-t-the-answer.mp3" length="32364804" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16064983</guid>
    <pubDate>Thu, 07 Nov 2024 10:00:00 -0500</pubDate>
    <itunes:duration>2694</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>We&#39;ll Be Here Until We Become Obsolete</itunes:title>
    <title>We&#39;ll Be Here Until We Become Obsolete</title>
    <itunes:summary><![CDATA[This week we explore the multifaceted concept of obsolescence in technology, detailing its planned, unplanned, and forced forms. We delve into the security implications of outdated or unsupported devices and software, with a spotlight on cloud-connected vehicles and their vulnerabilities. We discuss architectural decisions, regulatory requirements, and real-world incidents like the OnStar hack, reflecting on the need for robust security protocols.     FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @...]]></itunes:summary>
    <description><![CDATA[<p>This week we explore the multifaceted concept of obsolescence in technology, detailing its planned, unplanned, and forced forms. We delve into the security implications of outdated or unsupported devices and software, with a spotlight on cloud-connected vehicles and their vulnerabilities. We discuss architectural decisions, regulatory requirements, and real-world incidents like the OnStar hack, reflecting on the need for robust security protocols. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>This week we explore the multifaceted concept of obsolescence in technology, detailing its planned, unplanned, and forced forms. We delve into the security implications of outdated or unsupported devices and software, with a spotlight on cloud-connected vehicles and their vulnerabilities. We discuss architectural decisions, regulatory requirements, and real-world incidents like the OnStar hack, reflecting on the need for robust security protocols. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15976875-we-ll-be-here-until-we-become-obsolete.mp3" length="20053633" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15976875</guid>
    <pubDate>Wed, 23 Oct 2024 12:00:00 -0400</pubDate>
    <itunes:duration>1668</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>30</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Everything is Boring</itunes:title>
    <title>Everything is Boring</title>
    <itunes:summary><![CDATA[Is everything boring? Chris, Izar and Matt discuss why nothing seems interesting enough lately. Is the excitement of vulnerabilities and ransomware waning? The guys touch on Governance, Risk, and Compliance (GRC) in corporate auditing, the impact of ransomware and the contentious role of cyber insurance, the fading novelty of AI and its influence on security, and examine why essential security tasks might feel mundane yet remain vital. This is a candid conversation you won’t want to miss.&nbs...]]></itunes:summary>
    <description><![CDATA[<p>Is everything boring? Chris, Izar and Matt discuss why nothing seems interesting enough lately. Is the excitement of vulnerabilities and ransomware waning? The guys touch on Governance, Risk, and Compliance (GRC) in corporate auditing, the impact of ransomware and the contentious role of cyber insurance, the fading novelty of AI and its influence on security, and examine why essential security tasks might feel mundane yet remain vital. This is a candid conversation you won’t want to miss. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Is everything boring? Chris, Izar and Matt discuss why nothing seems interesting enough lately. Is the excitement of vulnerabilities and ransomware waning? The guys touch on Governance, Risk, and Compliance (GRC) in corporate auditing, the impact of ransomware and the contentious role of cyber insurance, the fading novelty of AI and its influence on security, and examine why essential security tasks might feel mundane yet remain vital. This is a candid conversation you won’t want to miss. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15930294-everything-is-boring.mp3" length="21620631" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15930294</guid>
    <pubDate>Wed, 16 Oct 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1799</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Experts Want to Excel</itunes:title>
    <title>Experts Want to Excel</title>
    <itunes:summary><![CDATA[What constitutes an expert in the field of threat modeling? Today Matt, Chris and Izar explore cultural references, the intricacies of threat modeling practices, and the criteria that define an expert. The discussion touches on the evolution of threat modeling, the roles of facilitators, and the importance of experience and recognition in the field. The guys humorously debate the challenge of scaling practices in large organizations and share thoughts on how expertise can inspire others. Enjo...]]></itunes:summary>
    <description><![CDATA[<p>What constitutes an expert in the field of threat modeling? Today Matt, Chris and Izar explore cultural references, the intricacies of threat modeling practices, and the criteria that define an expert. The discussion touches on the evolution of threat modeling, the roles of facilitators, and the importance of experience and recognition in the field. The guys humorously debate the challenge of scaling practices in large organizations and share thoughts on how expertise can inspire others. Enjoy this amusing episode complete with tangents on movies, old media technologies, sports analogies, and competitive Excel.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What constitutes an expert in the field of threat modeling? Today Matt, Chris and Izar explore cultural references, the intricacies of threat modeling practices, and the criteria that define an expert. The discussion touches on the evolution of threat modeling, the roles of facilitators, and the importance of experience and recognition in the field. The guys humorously debate the challenge of scaling practices in large organizations and share thoughts on how expertise can inspire others. Enjoy this amusing episode complete with tangents on movies, old media technologies, sports analogies, and competitive Excel.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15893090-experts-want-to-excel.mp3" length="31804940" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15893090</guid>
    <pubDate>Wed, 09 Oct 2024 08:00:00 -0400</pubDate>
    <itunes:duration>2647</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Numb to Data Breaches, and How it Impacts Security of the Average Feature</itunes:title>
    <title>Numb to Data Breaches, and How it Impacts Security of the Average Feature</title>
    <itunes:summary><![CDATA[In this episode of the Security Table with Chris Romeo, Izar Tarandach, and Matt Coles, the team dives into the evolving landscape of modern security approaches. They discuss the shift from strategy to tactics, the impact of data breaches, and why people are becoming numb to such incidents. The episode also touches on the importance of understanding the business side of security and the role of product managers as security champions.  FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the Security Table with Chris Romeo, Izar Tarandach, and Matt Coles, the team dives into the evolving landscape of modern security approaches. They discuss the shift from strategy to tactics, the impact of data breaches, and why people are becoming numb to such incidents. The episode also touches on the importance of understanding the business side of security and the role of product managers as security champions. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the Security Table with Chris Romeo, Izar Tarandach, and Matt Coles, the team dives into the evolving landscape of modern security approaches. They discuss the shift from strategy to tactics, the impact of data breaches, and why people are becoming numb to such incidents. The episode also touches on the importance of understanding the business side of security and the role of product managers as security champions. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15772033-numb-to-data-breaches-and-how-it-impacts-security-of-the-average-feature.mp3" length="23335414" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15772033</guid>
    <pubDate>Wed, 18 Sep 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1942</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Philosophizing Cloud Security</itunes:title>
    <title>Philosophizing Cloud Security</title>
    <itunes:summary><![CDATA[In this episode of the Security Table, our hosts discuss the concept of the 'Shared Fate Model' in cloud security. The conversation explores how this model builds on the shared responsibility model and the implications for cloud service providers and consumers. From robust default security measures to the historical evolution of ISPs, the discussion covers technical and philosophical aspects of cloud infrastructure security. Join us for an informative and engaging session filled with the past...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the Security Table, our hosts discuss the concept of the &apos;Shared Fate Model&apos; in cloud security. The conversation explores how this model builds on the shared responsibility model and the implications for cloud service providers and consumers. From robust default security measures to the historical evolution of ISPs, the discussion covers technical and philosophical aspects of cloud infrastructure security. Join us for an informative and engaging session filled with the past and present of internet connectivity and cloud service security.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the Security Table, our hosts discuss the concept of the &apos;Shared Fate Model&apos; in cloud security. The conversation explores how this model builds on the shared responsibility model and the implications for cloud service providers and consumers. From robust default security measures to the historical evolution of ISPs, the discussion covers technical and philosophical aspects of cloud infrastructure security. Join us for an informative and engaging session filled with the past and present of internet connectivity and cloud service security.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15730714-philosophizing-cloud-security.mp3" length="20674284" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15730714</guid>
    <pubDate>Wed, 11 Sep 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1720</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Innovations in Threat Modeling?</itunes:title>
    <title>Innovations in Threat Modeling?</title>
    <itunes:summary><![CDATA[In this episode of The Security Table, hosts Chris Romeo, Izar Tarandach, and Matt Coles dive into the evolving concept of threat models, stepping beyond traditional boundaries. They explore 'Rethinking Threat Models for the Modern Age,' an article by author Evan Oslick. Focusing on user behavior, alert fatigue, and the role of psychological acceptability, they debate whether broader human factors should integrate into threat modeling.     FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodc...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of The Security Table, hosts Chris Romeo, Izar Tarandach, and Matt Coles dive into the evolving concept of threat models, stepping beyond traditional boundaries. They explore <a href='https://true-positives.com/appsec-blog/rethinking-threat-models-for-the-modern-age#:~:text=If%20your%20current%20threat%20models,%2C%20effective%2C%20and%20secure%20systems.'>&apos;Rethinking Threat Models for the Modern Age</a>,&apos; an article by author Evan Oslick. Focusing on user behavior, alert fatigue, and the role of psychological acceptability, they debate whether broader human factors should integrate into threat modeling. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of The Security Table, hosts Chris Romeo, Izar Tarandach, and Matt Coles dive into the evolving concept of threat models, stepping beyond traditional boundaries. They explore <a href='https://true-positives.com/appsec-blog/rethinking-threat-models-for-the-modern-age#:~:text=If%20your%20current%20threat%20models,%2C%20effective%2C%20and%20secure%20systems.'>&apos;Rethinking Threat Models for the Modern Age</a>,&apos; an article by author Evan Oslick. Focusing on user behavior, alert fatigue, and the role of psychological acceptability, they debate whether broader human factors should integrate into threat modeling. </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15654409-innovations-in-threat-modeling.mp3" length="22782684" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15654409</guid>
    <pubDate>Wed, 28 Aug 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1896</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Illusion of Secure Software</itunes:title>
    <title>The Illusion of Secure Software</title>
    <itunes:summary><![CDATA[In this episode of The Security Table Podcast, hosts ChriS, Izar and Matt dive into the recent statement by CISA's Jen Easterly on the cybersecurity industry's software quality problem. They discuss the implications of her statement, explore the recurring themes in security guidelines, and debate whether the core issue is with people or technology. Join the conversation as they analyze the roles of developers, QA engineers, and emerging AI tools in shaping a secure future, questioning if the ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of The Security Table Podcast, hosts ChriS, Izar and Matt dive into the recent statement by CISA&apos;s Jen Easterly on the cybersecurity industry&apos;s software quality problem. They discuss the implications of her statement, explore the recurring themes in security guidelines, and debate whether the core issue is with people or technology. Join the conversation as they analyze the roles of developers, QA engineers, and emerging AI tools in shaping a secure future, questioning if the industry is on the right path to real change.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of The Security Table Podcast, hosts ChriS, Izar and Matt dive into the recent statement by CISA&apos;s Jen Easterly on the cybersecurity industry&apos;s software quality problem. They discuss the implications of her statement, explore the recurring themes in security guidelines, and debate whether the core issue is with people or technology. Join the conversation as they analyze the roles of developers, QA engineers, and emerging AI tools in shaping a secure future, questioning if the industry is on the right path to real change.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15578228-the-illusion-of-secure-software.mp3" length="29051444" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15578228</guid>
    <pubDate>Wed, 14 Aug 2024 08:00:00 -0400</pubDate>
    <itunes:duration>2418</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>24</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Intersection of Hardware and Software Security</itunes:title>
    <title>The Intersection of Hardware and Software Security</title>
    <itunes:summary><![CDATA[In this episode of The Security Table, Chris, Izar, and Matt discuss an article that discusses threat modeling in the context of hardware. They explore the intersection of hardware and software security, the importance of understanding attack surfaces, and the challenges posed by vulnerabilities in hardware components, such as speculative execution faults and the impact of supply chain security. Join the conversation as they examine the critical points in the ongoing dialogue around hardware ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of The Security Table, Chris, Izar, and Matt discuss an article that discusses threat modeling in the context of hardware. They explore the intersection of hardware and software security, the importance of understanding attack surfaces, and the challenges posed by vulnerabilities in hardware components, such as speculative execution faults and the impact of supply chain security. Join the conversation as they examine the critical points in the ongoing dialogue around hardware and software security integration.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of The Security Table, Chris, Izar, and Matt discuss an article that discusses threat modeling in the context of hardware. They explore the intersection of hardware and software security, the importance of understanding attack surfaces, and the challenges posed by vulnerabilities in hardware components, such as speculative execution faults and the impact of supply chain security. Join the conversation as they examine the critical points in the ongoing dialogue around hardware and software security integration.</p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15543506-the-intersection-of-hardware-and-software-security.mp3" length="21941370" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15543506</guid>
    <pubDate>Wed, 07 Aug 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1825</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Computing Has Trust Issues</itunes:title>
    <title>Computing Has Trust Issues</title>
    <itunes:summary><![CDATA[Join us in this episode of The Security Table as we dive into the world of cybersecurity, starting with a nostalgic discussion about our favorite security-themed movies like 'Sneakers,' 'War Games,' and 'The Matrix.' We then shift gears to explore a critical topic in modern computing: the vulnerabilities and implementation issues of Secure Boot. Discover the intricate details of key management, human errors, and the challenges of maintaining trust in hardware and software systems. The convers...]]></itunes:summary>
    <description><![CDATA[<p>Join us in this episode of The Security Table as we dive into the world of cybersecurity, starting with a nostalgic discussion about our favorite security-themed movies like &apos;Sneakers,&apos; &apos;War Games,&apos; and &apos;The Matrix.&apos; We then shift gears to explore a critical topic in modern computing: the vulnerabilities and implementation issues of Secure Boot. Discover the intricate details of key management, human errors, and the challenges of maintaining trust in hardware and software systems. The conversation extends to the practicalities of password management, passkeys, and the broader implications of securing digital identities. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Join us in this episode of The Security Table as we dive into the world of cybersecurity, starting with a nostalgic discussion about our favorite security-themed movies like &apos;Sneakers,&apos; &apos;War Games,&apos; and &apos;The Matrix.&apos; We then shift gears to explore a critical topic in modern computing: the vulnerabilities and implementation issues of Secure Boot. Discover the intricate details of key management, human errors, and the challenges of maintaining trust in hardware and software systems. The conversation extends to the practicalities of password management, passkeys, and the broader implications of securing digital identities. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15506162-computing-has-trust-issues.mp3" length="33269165" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15506162</guid>
    <pubDate>Wed, 31 Jul 2024 08:00:00 -0400</pubDate>
    <itunes:duration>2769</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Stages of Grief in Incident Response</itunes:title>
    <title>The Stages of Grief in Incident Response</title>
    <itunes:summary><![CDATA[Join Chris, Izar, and Matt as they sit around the Security Table to dissect and discuss the different stages of dealing with security incidents. In this episode, they explore the developer's stages of grief during an incident, and discuss a recent large-scale IT incident. They share insights from their multi-decade experience in security, analyze the fragility of current systems, and discuss the role of luck and probability in security failures.  FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTa...]]></itunes:summary>
    <description><![CDATA[<p>Join Chris, Izar, and Matt as they sit around the Security Table to dissect and discuss the different stages of dealing with security incidents. In this episode, they explore the developer&apos;s stages of grief during an incident, and discuss a recent large-scale IT incident. They share insights from their multi-decade experience in security, analyze the fragility of current systems, and discuss the role of luck and probability in security failures. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Join Chris, Izar, and Matt as they sit around the Security Table to dissect and discuss the different stages of dealing with security incidents. In this episode, they explore the developer&apos;s stages of grief during an incident, and discuss a recent large-scale IT incident. They share insights from their multi-decade experience in security, analyze the fragility of current systems, and discuss the role of luck and probability in security failures. </p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15465490-the-stages-of-grief-in-incident-response.mp3" length="17381938" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15465490</guid>
    <pubDate>Wed, 24 Jul 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1445</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>To SSH or Not?</itunes:title>
    <title>To SSH or Not?</title>
    <itunes:summary><![CDATA[In this episode of 'The Security Table,' we are back from our midsummer break to discuss OpenSSH regression vulnerability. We dig into the nuances of this race condition leading to remote code execution, explore the chain of security updates, and the role of QA in preventing such regressions. We debate the necessity of SSH in modern cloud-native environments and its alternatives. Plus, we answer the critical question of who should catch these vulnerabilities first — QA teams, pentesters, or a...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of &apos;The Security Table,&apos; we are back from our midsummer break to discuss OpenSSH regression vulnerability. We dig into the nuances of this race condition leading to remote code execution, explore the chain of security updates, and the role of QA in preventing such regressions. We debate the necessity of SSH in modern cloud-native environments and its alternatives. Plus, we answer the critical question of who should catch these vulnerabilities first — QA teams, pentesters, or automated tools? </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of &apos;The Security Table,&apos; we are back from our midsummer break to discuss OpenSSH regression vulnerability. We dig into the nuances of this race condition leading to remote code execution, explore the chain of security updates, and the role of QA in preventing such regressions. We debate the necessity of SSH in modern cloud-native environments and its alternatives. Plus, we answer the critical question of who should catch these vulnerabilities first — QA teams, pentesters, or automated tools? </p><p><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15424755-to-ssh-or-not.mp3" length="20295897" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15424755</guid>
    <pubDate>Wed, 17 Jul 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1688</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Rethinking Security Conferences: Engagement and Innovation</itunes:title>
    <title>Rethinking Security Conferences: Engagement and Innovation</title>
    <itunes:summary><![CDATA[In this episode Chris, Matt, and Izar discuss the current state of security conferences and gatherings for professionals in the field. They discuss the value and viability of different types of gatherings, the importance of networking and community-building at events, innovative approaches to conference formats and the need for something more engaging and participatory that caters to both introverts and extroverts. Personal experiences and preferences for conference attendance and speaking en...]]></itunes:summary>
    <description><![CDATA[<p>In this episode Chris, Matt, and Izar discuss the current state of security conferences and gatherings for professionals in the field. They discuss the value and viability of different types of gatherings, the importance of networking and community-building at events, innovative approaches to conference formats and the need for something more engaging and participatory that caters to both introverts and extroverts.</p><p>Personal experiences and preferences for conference attendance and speaking engagements are discussed along with hybrid approaches that combine presentations with facilitated discussions and interactive elements.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode Chris, Matt, and Izar discuss the current state of security conferences and gatherings for professionals in the field. They discuss the value and viability of different types of gatherings, the importance of networking and community-building at events, innovative approaches to conference formats and the need for something more engaging and participatory that caters to both introverts and extroverts.</p><p>Personal experiences and preferences for conference attendance and speaking engagements are discussed along with hybrid approaches that combine presentations with facilitated discussions and interactive elements.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15354254-rethinking-security-conferences-engagement-and-innovation.mp3" length="18798542" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15354254</guid>
    <pubDate>Wed, 03 Jul 2024 08:00:00 -0400</pubDate>
    <itunes:duration>1564</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Privacy vs. Security: Complexity at the Crossroads</itunes:title>
    <title>Privacy vs. Security: Complexity at the Crossroads</title>
    <itunes:summary><![CDATA[In this episode of the Security Table, Chris, Izar, and Matt delve into the evolving landscape of cybersecurity. The episode has a humorous start involving t-shirts and Frogger as a metaphor for the cybersecurity journey, the conversation shifts to the significant topic of cybersecurity being at a crossroads as suggested by a CSO Online article.   They explore the concept of moving from a product-centric to an architectural-centric approach in cybersecurity, discussing the design and integrat...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the Security Table, Chris, Izar, and Matt delve into the evolving landscape of cybersecurity. The episode has a humorous start involving t-shirts and Frogger as a metaphor for the cybersecurity journey, the conversation shifts to the significant topic of cybersecurity being at a crossroads as suggested by a CSO Online article. <br/><br/>They explore the concept of moving from a product-centric to an architectural-centric approach in cybersecurity, discussing the design and integration of inherent capabilities rather than relying on add-on products. The hosts look into the complexities of security and privacy, analyzing their intersections, the challenges of privacy threat modeling, and the importance of understanding the broader ecosystem in which data interacts. The episode concludes with a lively discussion on the evolving nature of security and privacy regulations, the impact of complexity, and the need for continuous threat modeling. <br/><br/>Article mentioned in this episode: <br/><a href='https://www.csoonline.com/article/2126804/cybersecurity-is-at-a-crossroads-its-time-to-shift-to-an-architectural-approach.html'>Cybersecurity at a crossroads: Time to shift to an architectural approach  </a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the Security Table, Chris, Izar, and Matt delve into the evolving landscape of cybersecurity. The episode has a humorous start involving t-shirts and Frogger as a metaphor for the cybersecurity journey, the conversation shifts to the significant topic of cybersecurity being at a crossroads as suggested by a CSO Online article. <br/><br/>They explore the concept of moving from a product-centric to an architectural-centric approach in cybersecurity, discussing the design and integration of inherent capabilities rather than relying on add-on products. The hosts look into the complexities of security and privacy, analyzing their intersections, the challenges of privacy threat modeling, and the importance of understanding the broader ecosystem in which data interacts. The episode concludes with a lively discussion on the evolving nature of security and privacy regulations, the impact of complexity, and the need for continuous threat modeling. <br/><br/>Article mentioned in this episode: <br/><a href='https://www.csoonline.com/article/2126804/cybersecurity-is-at-a-crossroads-its-time-to-shift-to-an-architectural-approach.html'>Cybersecurity at a crossroads: Time to shift to an architectural approach  </a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15271494-privacy-vs-security-complexity-at-the-crossroads.mp3" length="25813971" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15271494</guid>
    <pubDate>Tue, 18 Jun 2024 14:00:00 -0400</pubDate>
    <itunes:duration>2148</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security, Stories, Jazz and Stage Presence with Brook Schoenfield</itunes:title>
    <title>Security, Stories, Jazz and Stage Presence with Brook Schoenfield</title>
    <itunes:summary><![CDATA[In this episode of 'The Security Table,' hosts Chris Romeo, Izar Tarandach, and Matt Coles are joined by Brook Schoenfield, a seasoned security professional, to share insights and stories from his extensive career.  The conversation covers Brook's experience in writing books on security, lessons learned from his 40-year career, and personal anecdotes about his life as a musician, including playing with legends like Bo Diddley and Chuck Berry. Brook highlights the importance of ensemble w...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of &apos;The Security Table,&apos; hosts Chris Romeo, Izar Tarandach, and Matt Coles are joined by Brook Schoenfield, a seasoned security professional, to share insights and stories from his extensive career. </p><p>The conversation covers Brook&apos;s experience in writing books on security, lessons learned from his 40-year career, and personal anecdotes about his life as a musician, including playing with legends like Bo Diddley and Chuck Berry. Brook highlights the importance of ensemble work in both security and music.</p><p><br/></p><p>Books written by Brook Schoenfield:</p><p>Secrets Of A Cyber Security Architect (Auerbach, 2019) <a href='https://brookschoenfield.com/?page_id=331'>https://brookschoenfield.com/?page_id=331</a></p><p>Securing Systems: Applied Security Architecture <a href='https://brookschoenfield.com/?page_id=245'>https://brookschoenfield.com/?page_id=245</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of &apos;The Security Table,&apos; hosts Chris Romeo, Izar Tarandach, and Matt Coles are joined by Brook Schoenfield, a seasoned security professional, to share insights and stories from his extensive career. </p><p>The conversation covers Brook&apos;s experience in writing books on security, lessons learned from his 40-year career, and personal anecdotes about his life as a musician, including playing with legends like Bo Diddley and Chuck Berry. Brook highlights the importance of ensemble work in both security and music.</p><p><br/></p><p>Books written by Brook Schoenfield:</p><p>Secrets Of A Cyber Security Architect (Auerbach, 2019) <a href='https://brookschoenfield.com/?page_id=331'>https://brookschoenfield.com/?page_id=331</a></p><p>Securing Systems: Applied Security Architecture <a href='https://brookschoenfield.com/?page_id=245'>https://brookschoenfield.com/?page_id=245</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15188100-security-stories-jazz-and-stage-presence-with-brook-schoenfield.mp3" length="37529919" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15188100</guid>
    <pubDate>Tue, 04 Jun 2024 08:00:00 -0400</pubDate>
    <itunes:duration>3124</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Debating the CISA Secure by Design Pledge</itunes:title>
    <title>Debating the CISA Secure by Design Pledge</title>
    <itunes:summary><![CDATA[In this episode of 'The Security Table,' hosts Chris Romeo, Matt Coles, and Izar Tarandach discuss the CISA Secure by Design Pledge, a recent initiative where various companies commit to improving software security practices. The hosts critique the pledge, arguing that many of the signatory companies have long been focused on software security, making the pledge redundant for them. They dissect specific goals of the pledge, such as increasing multi-factor authentication (MFA) and reducing def...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of &apos;The Security Table,&apos; hosts Chris Romeo, Matt Coles, and Izar Tarandach discuss the CISA Secure by Design Pledge, a recent initiative where various companies commit to improving software security practices. The hosts critique the pledge, arguing that many of the signatory companies have long been focused on software security, making the pledge redundant for them. They dissect specific goals of the pledge, such as increasing multi-factor authentication (MFA) and reducing default passwords, and express concerns about their actual impact. <br/><br/>Despite their skepticism of the pledge’s effectiveness and measurability, they do acknowledge CISA&apos;s intention behind the pledge is to move the industry forward.<br/><br/>Secure by Design pledge:  https://www.cisa.gov/securebydesign/pledge</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of &apos;The Security Table,&apos; hosts Chris Romeo, Matt Coles, and Izar Tarandach discuss the CISA Secure by Design Pledge, a recent initiative where various companies commit to improving software security practices. The hosts critique the pledge, arguing that many of the signatory companies have long been focused on software security, making the pledge redundant for them. They dissect specific goals of the pledge, such as increasing multi-factor authentication (MFA) and reducing default passwords, and express concerns about their actual impact. <br/><br/>Despite their skepticism of the pledge’s effectiveness and measurability, they do acknowledge CISA&apos;s intention behind the pledge is to move the industry forward.<br/><br/>Secure by Design pledge:  https://www.cisa.gov/securebydesign/pledge</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15172473-debating-the-cisa-secure-by-design-pledge.mp3" length="28604407" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15172473</guid>
    <pubDate>Fri, 31 May 2024 18:00:00 -0400</pubDate>
    <itunes:duration>2381</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why Developers Will Take Charge of Security, Tests in Prod</itunes:title>
    <title>Why Developers Will Take Charge of Security, Tests in Prod</title>
    <itunes:summary><![CDATA[The script delves into a multifaceted discussion encompassing critiques and praises of book-to-movie adaptations like 'Hitchhiker's Guide to the Galaxy', 'Good Omens', and 'The Chronicles of Narnia'. It then transitions to a serious examination of developers' evolving role in security, advocating for 'shift left' and DevSecOps approaches. The conversation navigates through challenges developers encounter in security practices, stressing the necessity of a DevSecOps framework, secure coding la...]]></itunes:summary>
    <description><![CDATA[<p>The script delves into a multifaceted discussion encompassing critiques and praises of book-to-movie adaptations like &apos;Hitchhiker&apos;s Guide to the Galaxy&apos;, &apos;Good Omens&apos;, and &apos;The Chronicles of Narnia&apos;. It then transitions to a serious examination of developers&apos; evolving role in security, advocating for &apos;shift left&apos; and DevSecOps approaches. The conversation navigates through challenges developers encounter in security practices, stressing the necessity of a DevSecOps framework, secure coding languages, and executive support for fostering a robust security culture within organizations.</p><p>Chris, Izar and Matt begin the episode with a lighthearted discussion about books turned into movies, including Hitchhiker&apos;s Guide to the Galaxy and The Chronicles of Narnia series. The main topic of conversation on today’s episode is an article titled &quot;Why Developers Will Take Charge of Security, Tests in Production&quot; by Lorraine Lawson, which interviews Larry Meshrom. The article suggests that developers should take on more responsibility for security, including testing in production environments, as security teams are often perceived as a blocker and don&apos;t understand the day-to-day work of developers. </p><p>The guys question whether developers truly want to take on more security responsibilities, given the constantly evolving nature of security threats and the time it takes to stay up-to-date. They also discuss the role of product managers in driving security and privacy prioritization, and the need for executives to understand the business value of investing in security. The hosts argue that while mature organizations have governance processes in place to enforce security, smaller companies may lack such mechanisms. </p><p>Ultimately, it is concluded that product managers are best positioned to communicate the business value of security to executives, as they are closest to understanding customer needs and revenue drivers. They propose that the industry should focus on educating and empowering product managers to prioritize security and privacy, and to make the case for investing in these areas to executives. This approach could help bridge the gap between security teams and developers, and drive a culture of security within organizations.</p><p>Link to article:  <a href='https://thenewstack.io/why-developers-will-take-charge-of-security-tests-in-prod/'>https://thenewstack.io/why-developers-will-take-charge-of-security-tests-in-prod/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The script delves into a multifaceted discussion encompassing critiques and praises of book-to-movie adaptations like &apos;Hitchhiker&apos;s Guide to the Galaxy&apos;, &apos;Good Omens&apos;, and &apos;The Chronicles of Narnia&apos;. It then transitions to a serious examination of developers&apos; evolving role in security, advocating for &apos;shift left&apos; and DevSecOps approaches. The conversation navigates through challenges developers encounter in security practices, stressing the necessity of a DevSecOps framework, secure coding languages, and executive support for fostering a robust security culture within organizations.</p><p>Chris, Izar and Matt begin the episode with a lighthearted discussion about books turned into movies, including Hitchhiker&apos;s Guide to the Galaxy and The Chronicles of Narnia series. The main topic of conversation on today’s episode is an article titled &quot;Why Developers Will Take Charge of Security, Tests in Production&quot; by Lorraine Lawson, which interviews Larry Meshrom. The article suggests that developers should take on more responsibility for security, including testing in production environments, as security teams are often perceived as a blocker and don&apos;t understand the day-to-day work of developers. </p><p>The guys question whether developers truly want to take on more security responsibilities, given the constantly evolving nature of security threats and the time it takes to stay up-to-date. They also discuss the role of product managers in driving security and privacy prioritization, and the need for executives to understand the business value of investing in security. The hosts argue that while mature organizations have governance processes in place to enforce security, smaller companies may lack such mechanisms. </p><p>Ultimately, it is concluded that product managers are best positioned to communicate the business value of security to executives, as they are closest to understanding customer needs and revenue drivers. They propose that the industry should focus on educating and empowering product managers to prioritize security and privacy, and to make the case for investing in these areas to executives. This approach could help bridge the gap between security teams and developers, and drive a culture of security within organizations.</p><p>Link to article:  <a href='https://thenewstack.io/why-developers-will-take-charge-of-security-tests-in-prod/'>https://thenewstack.io/why-developers-will-take-charge-of-security-tests-in-prod/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15105825-why-developers-will-take-charge-of-security-tests-in-prod.mp3" length="34721846" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15105825</guid>
    <pubDate>Tue, 21 May 2024 09:00:00 -0400</pubDate>
    <itunes:duration>2890</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>12 Factors of Threat Modeling</itunes:title>
    <title>12 Factors of Threat Modeling</title>
    <itunes:summary><![CDATA[Chris, Matt and Izar share their thoughts on an article published by Carnegie Mellon University’s Software Engineering Institute. The list from the article covers various threat modeling methodologies such as STRIDE, PASTA, LinDoN, and OCTAVE methodology for risk management. They emphasize the importance of critical thinking in the field, provide insights into strengths, applications, and limitations of each method, and highlight the significance of annotated threat models for application sec...]]></itunes:summary>
    <description><![CDATA[<p>Chris, Matt and Izar share their thoughts on an article published by Carnegie Mellon University’s Software Engineering Institute. The list from the article covers various threat modeling methodologies such as STRIDE, PASTA, LinDoN, and OCTAVE methodology for risk management. They emphasize the importance of critical thinking in the field, provide insights into strengths, applications, and limitations of each method, and highlight the significance of annotated threat models for application security.</p><p> </p><p>Mentioned in this Episode:<br/>Article: <a href='https://insights.sei.cmu.edu/blog/threat-modeling-12-available-methods/'>https://insights.sei.cmu.edu/blog/threat-modeling-12-available-methods/</a></p><p>Podcast episode: Nobody&apos;s Going to Mess with Our STRIDE <a href='https://www.youtube.com/watch?v=TDFRe_icFmY&amp;pp=ygUSdGhlIHNlY3VyaXR5IHRhYmxl'>https://www.youtube.com/watch?v=TDFRe_icFmY&amp;pp=ygUSdGhlIHNlY3VyaXR5IHRhYmxl</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris, Matt and Izar share their thoughts on an article published by Carnegie Mellon University’s Software Engineering Institute. The list from the article covers various threat modeling methodologies such as STRIDE, PASTA, LinDoN, and OCTAVE methodology for risk management. They emphasize the importance of critical thinking in the field, provide insights into strengths, applications, and limitations of each method, and highlight the significance of annotated threat models for application security.</p><p> </p><p>Mentioned in this Episode:<br/>Article: <a href='https://insights.sei.cmu.edu/blog/threat-modeling-12-available-methods/'>https://insights.sei.cmu.edu/blog/threat-modeling-12-available-methods/</a></p><p>Podcast episode: Nobody&apos;s Going to Mess with Our STRIDE <a href='https://www.youtube.com/watch?v=TDFRe_icFmY&amp;pp=ygUSdGhlIHNlY3VyaXR5IHRhYmxl'>https://www.youtube.com/watch?v=TDFRe_icFmY&amp;pp=ygUSdGhlIHNlY3VyaXR5IHRhYmxl</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/15041565-12-factors-of-threat-modeling.mp3" length="32905547" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15041565</guid>
    <pubDate>Tue, 14 May 2024 08:00:00 -0400</pubDate>
    <itunes:duration>2739</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>XZ and the Trouble with Covert Identities in Open Source</itunes:title>
    <title>XZ and the Trouble with Covert Identities in Open Source</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris delve into the complexities of open source security. They explore the topics of trust, vulnerabilities, and the potential infiltration by malicious actors. They emphasize the importance of proactive security measures, the challenges faced by maintainers, and propose solutions like improved funding models and behavior analysis for enhancing security within the open source ecosystem. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris delve into the complexities of open source security. They explore the topics of trust, vulnerabilities, and the potential infiltration by malicious actors. They emphasize the importance of proactive security measures, the challenges faced by maintainers, and propose solutions like improved funding models and behavior analysis for enhancing security within the open source ecosystem.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris delve into the complexities of open source security. They explore the topics of trust, vulnerabilities, and the potential infiltration by malicious actors. They emphasize the importance of proactive security measures, the challenges faced by maintainers, and propose solutions like improved funding models and behavior analysis for enhancing security within the open source ecosystem.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14997597-xz-and-the-trouble-with-covert-identities-in-open-source.mp3" length="31648275" type="audio/mpeg" />
    <itunes:author>Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14997597</guid>
    <pubDate>Thu, 02 May 2024 11:00:00 -0400</pubDate>
    <itunes:duration>2634</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Nobody&#39;s Going To Mess with Our STRIDE</itunes:title>
    <title>Nobody&#39;s Going To Mess with Our STRIDE</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris take issue with a controversial blog post that criticizes STRIDE as being outdated, time-consuming, and does not help the right people do threat modeling. The post goes on to recommend that LLMs should handle the task. The trio counters these points by highlighting STRIDE's origin, utility, and adaptability. Like any good instrument, it is important to use the right tools in the right context.   They also touch upon the common misconceptions about threat modeling, t...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris take issue with a controversial blog post that criticizes STRIDE as being outdated, time-consuming, and does not help the right people do threat modeling. The post goes on to recommend that LLMs should handle the task. The trio counters these points by highlighting STRIDE&apos;s origin, utility, and adaptability. Like any good instrument, it is important to use the right tools in the right context. <br/><br/>They also touch upon the common misconceptions about threat modeling, the misuse of tools like the Microsoft Threat Modeling Tool, and the benefits of collective threat modeling practices. Throughout, they defend the foundational role of STRIDE in threat modeling, promote the value of including diverse perspectives in the threat modeling process, and encourage looking beyond narrow toolsets to the broader principles of threat analysis.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris take issue with a controversial blog post that criticizes STRIDE as being outdated, time-consuming, and does not help the right people do threat modeling. The post goes on to recommend that LLMs should handle the task. The trio counters these points by highlighting STRIDE&apos;s origin, utility, and adaptability. Like any good instrument, it is important to use the right tools in the right context. <br/><br/>They also touch upon the common misconceptions about threat modeling, the misuse of tools like the Microsoft Threat Modeling Tool, and the benefits of collective threat modeling practices. Throughout, they defend the foundational role of STRIDE in threat modeling, promote the value of including diverse perspectives in the threat modeling process, and encourage looking beyond narrow toolsets to the broader principles of threat analysis.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14853811-nobody-s-going-to-mess-with-our-stride.mp3" length="28495397" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14853811</guid>
    <pubDate>Tue, 09 Apr 2024 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14853811/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14853811/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14853811/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14853811/transcript.vtt" type="text/vtt" />
    <itunes:duration>2371</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>SQLi All Over Again?</itunes:title>
    <title>SQLi All Over Again?</title>
    <itunes:summary><![CDATA[Chris, Matt, and Izar discuss a recent Secure by Design Alert from CISA on eliminating SQL injection (SQLi) vulnerabilities. The trio critiques the alert's lack of actionable guidance for software manufacturers, and they discuss various strategies that could effectively mitigate such vulnerabilities, including ORMs, communicating the why, and the importance of threat modeling. They also explore potential ways to improve the dissemination and impact of such alerts through partnerships with org...]]></itunes:summary>
    <description><![CDATA[<p>Chris, Matt, and Izar discuss a recent Secure by Design Alert from CISA on eliminating SQL injection (SQLi) vulnerabilities. The trio critiques the alert&apos;s lack of actionable guidance for software manufacturers, and they discuss various strategies that could effectively mitigate such vulnerabilities, including ORMs, communicating the why, and the importance of threat modeling. They also explore potential ways to improve the dissemination and impact of such alerts through partnerships with organizations like OWASP, the various PSIRTs, and ISACs, and leveraging threat intelligence effectively within AppSec programs. Ultimately, the trio wants to help CISA maximize its effectiveness in the software security industry.<br/><br/><b>Link to CISA SQLi Alert:<br/></b>Secure by Design Alert: Eliminating SQL Injection Vulnerabilities in Software -- <a href='https://www.cisa.gov/sites/default/files/2024-03/SbD%20Alert%20-%20Eliminating%20SQL%20Injection%20Vulnerabilities%20in%20Software_508c.pdf'>https://www.cisa.gov/sites/default/files/2024-03/SbD%20Alert%20-%20Eliminating%20SQL%20Injection%20Vulnerabilities%20in%20Software_508c.pdf</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris, Matt, and Izar discuss a recent Secure by Design Alert from CISA on eliminating SQL injection (SQLi) vulnerabilities. The trio critiques the alert&apos;s lack of actionable guidance for software manufacturers, and they discuss various strategies that could effectively mitigate such vulnerabilities, including ORMs, communicating the why, and the importance of threat modeling. They also explore potential ways to improve the dissemination and impact of such alerts through partnerships with organizations like OWASP, the various PSIRTs, and ISACs, and leveraging threat intelligence effectively within AppSec programs. Ultimately, the trio wants to help CISA maximize its effectiveness in the software security industry.<br/><br/><b>Link to CISA SQLi Alert:<br/></b>Secure by Design Alert: Eliminating SQL Injection Vulnerabilities in Software -- <a href='https://www.cisa.gov/sites/default/files/2024-03/SbD%20Alert%20-%20Eliminating%20SQL%20Injection%20Vulnerabilities%20in%20Software_508c.pdf'>https://www.cisa.gov/sites/default/files/2024-03/SbD%20Alert%20-%20Eliminating%20SQL%20Injection%20Vulnerabilities%20in%20Software_508c.pdf</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14810473-sqli-all-over-again.mp3" length="27337405" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14810473</guid>
    <pubDate>Tue, 02 Apr 2024 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14810473/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14810473/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14810473/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14810473/transcript.vtt" type="text/vtt" />
    <itunes:duration>2275</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How I Learned to Stop Worrying and Love the AI</itunes:title>
    <title>How I Learned to Stop Worrying and Love the AI</title>
    <itunes:summary><![CDATA[Dive into the contentious world of AI in software development, where artificial intelligence reshapes coding and application security. We spotlight the surge of AI-generated code and the incorporation of copy-pasted snippets from popular forums, focusing on their impact on code quality, security, and maintainability. The conversation critically examines the diminishing role of traditional quality assurance measures versus the growing reliance on automated tools and AI, highlighting potential ...]]></itunes:summary>
    <description><![CDATA[<p>Dive into the contentious world of AI in software development, where artificial intelligence reshapes coding and application security. We spotlight the surge of AI-generated code and the incorporation of copy-pasted snippets from popular forums, focusing on their impact on code quality, security, and maintainability. The conversation critically examines the diminishing role of traditional quality assurance measures versus the growing reliance on automated tools and AI, highlighting potential compromises between development speed and security integrity.<br/><br/>The discussion broadens to consider the future of software security tools in an AI-dominated era, questioning whether AI-generated code could make static application security testing (SAST) tools obsolete or introduce new challenges requiring more human oversight. The debate intensifies around the trustworthiness of AI in handling complex business logic and security policies without introducing vulnerabilities.<br/><br/>The dialogue concludes by reflecting on the balance between innovation and caution in software development. As AI advances, the conversation centers on ensuring it enhances rather than compromises application security, offering insights, anecdotes, and a dose of humor along the way. Stay tuned for more thought-provoking discussions on the intersection of AI and software security.<br/><br/>Helpful Links:<br/>Article: &quot;New study on coding behavior raises questions about impact of AI on software development&quot; at GeekWire -- <a href='https://www.geekwire.com/2024/new-study-on-coding-behavior-raises-questions-about-impact-of-ai-on-software-development/'>https://www.geekwire.com/2024/new-study-on-coding-behavior-raises-questions-about-impact-of-ai-on-software-development/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Dive into the contentious world of AI in software development, where artificial intelligence reshapes coding and application security. We spotlight the surge of AI-generated code and the incorporation of copy-pasted snippets from popular forums, focusing on their impact on code quality, security, and maintainability. The conversation critically examines the diminishing role of traditional quality assurance measures versus the growing reliance on automated tools and AI, highlighting potential compromises between development speed and security integrity.<br/><br/>The discussion broadens to consider the future of software security tools in an AI-dominated era, questioning whether AI-generated code could make static application security testing (SAST) tools obsolete or introduce new challenges requiring more human oversight. The debate intensifies around the trustworthiness of AI in handling complex business logic and security policies without introducing vulnerabilities.<br/><br/>The dialogue concludes by reflecting on the balance between innovation and caution in software development. As AI advances, the conversation centers on ensuring it enhances rather than compromises application security, offering insights, anecdotes, and a dose of humor along the way. Stay tuned for more thought-provoking discussions on the intersection of AI and software security.<br/><br/>Helpful Links:<br/>Article: &quot;New study on coding behavior raises questions about impact of AI on software development&quot; at GeekWire -- <a href='https://www.geekwire.com/2024/new-study-on-coding-behavior-raises-questions-about-impact-of-ai-on-software-development/'>https://www.geekwire.com/2024/new-study-on-coding-behavior-raises-questions-about-impact-of-ai-on-software-development/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14757272-how-i-learned-to-stop-worrying-and-love-the-ai.mp3" length="30512902" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14757272</guid>
    <pubDate>Tue, 26 Mar 2024 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14757272/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14757272/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14757272/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14757272/transcript.vtt" type="text/vtt" />
    <itunes:duration>2539</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Secure by Default in the Developer Toolset and DevEx</itunes:title>
    <title>Secure by Default in the Developer Toolset and DevEx</title>
    <itunes:summary><![CDATA[Matt, Chris, and Izar talk about ensuring security within the developer toolset and the developer experience (DevEx). Prompted by a recent LinkedIn post by Matt Johansen, they explore the concept of "secure by default" tools. The conversation highlights the importance of not solely relying on tools but also considering the developer experience, suggesting that even with secure tools, the ultimate responsibility for security lies with the developers and the organization.  The trio also discuss...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Chris, and Izar talk about ensuring security within the developer toolset and the developer experience (DevEx). Prompted by a recent LinkedIn post by Matt Johansen, they explore the concept of &quot;secure by default&quot; tools. The conversation highlights the importance of not solely relying on tools but also considering the developer experience, suggesting that even with secure tools, the ultimate responsibility for security lies with the developers and the organization.<br/><br/>The trio also discusses the role of DevEx champions in advocating for security within development processes, emphasizing the need for a balance between security and usability to prevent developers from seeking workarounds. They touch upon integrating security into the developer workflow, known as &quot;shifting left,&quot; and the potential downsides of overburdening developers with security responsibilities.<br/><br/>There&apos;s a recurring theme of the complexity and challenges in achieving a &quot;secure by default&quot; stance, acknowledging the difficulty in defining and implementing this concept. The conversation concludes with an acknowledgment that while progress is being made in understanding and implementing security within DevEx, there&apos;s still a long way to go, and the need for further clarification and discussion on these topics is evident.<br/><br/>Matt Johansen&apos;s Original Post:<br/><a href='https://www.linkedin.com/posts/matthewjohansen_i-really-feel-like-a-lot-of-security-problems-activity-7170811256856141825-lKyx'>https://www.linkedin.com/posts/matthewjohansen_i-really-feel-like-a-lot-of-security-problems-activity-7170811256856141825-lKyx</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Chris, and Izar talk about ensuring security within the developer toolset and the developer experience (DevEx). Prompted by a recent LinkedIn post by Matt Johansen, they explore the concept of &quot;secure by default&quot; tools. The conversation highlights the importance of not solely relying on tools but also considering the developer experience, suggesting that even with secure tools, the ultimate responsibility for security lies with the developers and the organization.<br/><br/>The trio also discusses the role of DevEx champions in advocating for security within development processes, emphasizing the need for a balance between security and usability to prevent developers from seeking workarounds. They touch upon integrating security into the developer workflow, known as &quot;shifting left,&quot; and the potential downsides of overburdening developers with security responsibilities.<br/><br/>There&apos;s a recurring theme of the complexity and challenges in achieving a &quot;secure by default&quot; stance, acknowledging the difficulty in defining and implementing this concept. The conversation concludes with an acknowledgment that while progress is being made in understanding and implementing security within DevEx, there&apos;s still a long way to go, and the need for further clarification and discussion on these topics is evident.<br/><br/>Matt Johansen&apos;s Original Post:<br/><a href='https://www.linkedin.com/posts/matthewjohansen_i-really-feel-like-a-lot-of-security-problems-activity-7170811256856141825-lKyx'>https://www.linkedin.com/posts/matthewjohansen_i-really-feel-like-a-lot-of-security-problems-activity-7170811256856141825-lKyx</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14716301-secure-by-default-in-the-developer-toolset-and-devex.mp3" length="31555199" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14716301</guid>
    <pubDate>Tue, 19 Mar 2024 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14716301/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14716301/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14716301/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14716301/transcript.vtt" type="text/vtt" />
    <itunes:duration>2626</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Debating the Priority and Value of Memory Safety</itunes:title>
    <title>Debating the Priority and Value of Memory Safety</title>
    <itunes:summary><![CDATA[Chris, Izar, and Matt tackle the first point of the recent White House report, "Back to the Building Blocks: a Path toward Secure and Measurable Software." They discuss the importance of memory safety in software development, particularly in the context of critical infrastructure. They also explore what memory safety means, citing examples like the dangers of using C over safer alternatives such as Java, Rust, or Go.  The debate covers the effectiveness of government recommendations on softwa...]]></itunes:summary>
    <description><![CDATA[<p>Chris, Izar, and Matt tackle the first point of the recent White House report, &quot;Back to the Building Blocks: a Path toward Secure and Measurable Software.&quot; They discuss the importance of memory safety in software development, particularly in the context of critical infrastructure. They also explore what memory safety means, citing examples like the dangers of using C over safer alternatives such as Java, Rust, or Go.<br/><br/>The debate covers the effectiveness of government recommendations on software development practices, the role of memory safety in preventing security vulnerabilities, and the potential impact on industry sectors reliant on low-level programming languages like C and C++. The dialogue highlights different perspectives on the intersection of government policy, software development, and cybersecurity, providing valuable insights into the challenges and importance of adopting memory-safe programming practices.<br/><br/><b>Helpful Links:<br/><br/></b>BACK TO THE BUILDING BLOCKS: A PATH TOWARD SECURE AND MEASURABLE SOFTWARE - <a href='https://www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf'>https://www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf</a><br/><br/>Dance Your PhD 2024 winner, WELI, Kangaroo Time: <a href='https://youtu.be/RoSYO3fApEc'>https://youtu.be/RoSYO3fApEc</a><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris, Izar, and Matt tackle the first point of the recent White House report, &quot;Back to the Building Blocks: a Path toward Secure and Measurable Software.&quot; They discuss the importance of memory safety in software development, particularly in the context of critical infrastructure. They also explore what memory safety means, citing examples like the dangers of using C over safer alternatives such as Java, Rust, or Go.<br/><br/>The debate covers the effectiveness of government recommendations on software development practices, the role of memory safety in preventing security vulnerabilities, and the potential impact on industry sectors reliant on low-level programming languages like C and C++. The dialogue highlights different perspectives on the intersection of government policy, software development, and cybersecurity, providing valuable insights into the challenges and importance of adopting memory-safe programming practices.<br/><br/><b>Helpful Links:<br/><br/></b>BACK TO THE BUILDING BLOCKS: A PATH TOWARD SECURE AND MEASURABLE SOFTWARE - <a href='https://www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf'>https://www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf</a><br/><br/>Dance Your PhD 2024 winner, WELI, Kangaroo Time: <a href='https://youtu.be/RoSYO3fApEc'>https://youtu.be/RoSYO3fApEc</a><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14668394-debating-the-priority-and-value-of-memory-safety.mp3" length="25218094" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14668394</guid>
    <pubDate>Tue, 12 Mar 2024 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14668394/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14668394/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14668394/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14668394/transcript.vtt" type="text/vtt" />
    <itunes:duration>2098</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Selling Fear, Uncertainty, and Doubt</itunes:title>
    <title>Selling Fear, Uncertainty, and Doubt</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris discuss the impact of fear, uncertainty, and doubt (FUD) within cybersecurity. FUD is a double-edged sword - while it may drive awareness among consumers, it also leads to decision paralysis or misguided actions due to information overload. The saturation of breach reports and security threats also desensitizes users and blurs the line between vigilant security practices and unnecessary panic. Fear-based security strategies do not foster a secure environment.  The prolif...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris discuss the impact of fear, uncertainty, and doubt (FUD) within cybersecurity. FUD is a double-edged sword - while it may drive awareness among consumers, it also leads to decision paralysis or misguided actions due to information overload. The saturation of breach reports and security threats also desensitizes users and blurs the line between vigilant security practices and unnecessary panic. Fear-based security strategies do not foster a secure environment.<br/><br/>The proliferation of smart devices and the internet of things (IoT) make many everyday objects potential targets for cyber-attacks. However, media sensationalism surrounds these vulnerabilities, and there is a lack of follow-through in educating consumers about realistic risks and protective measures. This gap underscores the need for reliable sources of cybersecurity info that can cut through the FUD, offering actionable insights rather than contributing to fear.<br/><br/>They also explore the practice of weaponizing security in competitive markets. Some companies leverage security breaches, or the lack thereof, to differentiate themselves in the marketplace. These marketing strategies highlight &quot;superior&quot; security features while pointing out competitors&apos; breaches. While such tactics might draw attention to security considerations, they also risk confusing what constitutes meaningful cybersecurity practices. The industry needs to balance competitive advantage with ethical responsibility and consumer education. Who will fill the gap?</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris discuss the impact of fear, uncertainty, and doubt (FUD) within cybersecurity. FUD is a double-edged sword - while it may drive awareness among consumers, it also leads to decision paralysis or misguided actions due to information overload. The saturation of breach reports and security threats also desensitizes users and blurs the line between vigilant security practices and unnecessary panic. Fear-based security strategies do not foster a secure environment.<br/><br/>The proliferation of smart devices and the internet of things (IoT) make many everyday objects potential targets for cyber-attacks. However, media sensationalism surrounds these vulnerabilities, and there is a lack of follow-through in educating consumers about realistic risks and protective measures. This gap underscores the need for reliable sources of cybersecurity info that can cut through the FUD, offering actionable insights rather than contributing to fear.<br/><br/>They also explore the practice of weaponizing security in competitive markets. Some companies leverage security breaches, or the lack thereof, to differentiate themselves in the marketplace. These marketing strategies highlight &quot;superior&quot; security features while pointing out competitors&apos; breaches. While such tactics might draw attention to security considerations, they also risk confusing what constitutes meaningful cybersecurity practices. The industry needs to balance competitive advantage with ethical responsibility and consumer education. Who will fill the gap?</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14580857-selling-fear-uncertainty-and-doubt.mp3" length="29667455" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14580857</guid>
    <pubDate>Tue, 27 Feb 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14580857/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14580857/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14580857/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14580857/transcript.vtt" type="text/vtt" />
    <itunes:duration>2469</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Prioritizing AppSec: A Conversation Between a VP of Eng, a Product Manager, and a Security &quot;Pro&quot;</itunes:title>
    <title>Prioritizing AppSec: A Conversation Between a VP of Eng, a Product Manager, and a Security &quot;Pro&quot;</title>
    <itunes:summary><![CDATA[Prompted by fan mail, Chris, Izar, and Matt engage in a role-playing scenario as a VP of engineering, a security person, and a product manager. They explore some of the challenges and competing perspectives involved in prioritizing application security. They highlight the importance of empathy, understanding business needs and language, and building relationships within an organization while dealing with security threats and solutions. They end with insights into the role of AI in AppSec, its...]]></itunes:summary>
    <description><![CDATA[<p>Prompted by fan mail, Chris, Izar, and Matt engage in a role-playing scenario as a VP of engineering, a security person, and a product manager. They explore some of the challenges and competing perspectives involved in prioritizing application security. They highlight the importance of empathy, understanding business needs and language, and building relationships within an organization while dealing with security threats and solutions. They end with insights into the role of AI in AppSec, its prioritization, and its limitations.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Prompted by fan mail, Chris, Izar, and Matt engage in a role-playing scenario as a VP of engineering, a security person, and a product manager. They explore some of the challenges and competing perspectives involved in prioritizing application security. They highlight the importance of empathy, understanding business needs and language, and building relationships within an organization while dealing with security threats and solutions. They end with insights into the role of AI in AppSec, its prioritization, and its limitations.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14533236-prioritizing-appsec-a-conversation-between-a-vp-of-eng-a-product-manager-and-a-security-pro.mp3" length="26791577" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14533236</guid>
    <pubDate>Tue, 20 Feb 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14533236/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14533236/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14533236/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14533236/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2094080/14533236/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Prioritizing AppSec: A Conversation Between a VP of Eng, a Product Manager, and a Security &quot;Pro&quot;" />
  <psc:chapter start="1:30" title="Simulation: Prioritizing AppSec in an Organization" />
  <psc:chapter start="23:04" title="Reflections: The Importance of Empathy, Relationships, and Terminology" />
</psc:chapters>
    <itunes:duration>2229</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Villainy, Open Source, and the Software Supply Chain</itunes:title>
    <title>Villainy, Open Source, and the Software Supply Chain</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris have a lively discussion about how security experts perceive open-source software. Referencing a post that described open source as a 'hive of scum and villainy,' the team dissects the misconceptions about open source software and challenges the narrative around its security. They explore the complexities of the software supply chain, the notion of 'inheritance' when it comes to security vulnerabilities, and the impact of transitive dependencies. They also discuss reputa...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris have a lively discussion about how security experts perceive open-source software. Referencing a post that described open source as a &apos;hive of scum and villainy,&apos; the team dissects the misconceptions about open source software and challenges the narrative around its security. They explore the complexities of the software supply chain, the notion of &apos;inheritance&apos; when it comes to security vulnerabilities, and the impact of transitive dependencies. They also discuss reputation systems, dependency injection, and the reality of accepting responsibility for incorporated software packages and their security issues. Tune in for these and other thoughtful insights about the interplay between open source solutions and security aspects in software development.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris have a lively discussion about how security experts perceive open-source software. Referencing a post that described open source as a &apos;hive of scum and villainy,&apos; the team dissects the misconceptions about open source software and challenges the narrative around its security. They explore the complexities of the software supply chain, the notion of &apos;inheritance&apos; when it comes to security vulnerabilities, and the impact of transitive dependencies. They also discuss reputation systems, dependency injection, and the reality of accepting responsibility for incorporated software packages and their security issues. Tune in for these and other thoughtful insights about the interplay between open source solutions and security aspects in software development.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14478663-villainy-open-source-and-the-software-supply-chain.mp3" length="23109707" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14478663</guid>
    <pubDate>Tue, 13 Feb 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14478663/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14478663/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14478663/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14478663/transcript.vtt" type="text/vtt" />
    <itunes:duration>1922</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Adam Shostack -- Thinking like an Attacker and Risk Management in the Capabilities</itunes:title>
    <title>Adam Shostack -- Thinking like an Attacker and Risk Management in the Capabilities</title>
    <itunes:summary><![CDATA[Threat modeling expert Adam Shostack joins Chris, Izar, and Matt in this episode of the Security Table. They look into threat actors and their place in threat modeling. There's a lively discussion on risk management, drawing the line between 'thinking like an attacker' and using current attacker data to inform a threat model. Adam also suggests that we must evaluate if risk assessments serve us well and how they impact organizations on various levels. The recurring theme is the constant need ...]]></itunes:summary>
    <description><![CDATA[<p>Threat modeling expert Adam Shostack joins Chris, Izar, and Matt in this episode of the Security Table. They look into threat actors and their place in threat modeling. There&apos;s a lively discussion on risk management, drawing the line between &apos;thinking like an attacker&apos; and using current attacker data to inform a threat model. Adam also suggests that we must evaluate if risk assessments serve us well and how they impact organizations on various levels. The recurring theme is the constant need for evolution and adaptation in threat modeling and risk management processes. You can tune in to get a rich perspective on these key cybersecurity topics.<br/><br/><b>Link<br/></b>Threat Modeling Manifesto: https://www.threatmodelingmanifesto.org/<br/>Threat Modeling Capabilities: https://www.threatmodelingmanifesto.org/capabilities/<br/><br/><em>Threats: What Every Engineer Should Learn From Star Wars</em> by Adam Shostack - https://threatsbook.com/</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Threat modeling expert Adam Shostack joins Chris, Izar, and Matt in this episode of the Security Table. They look into threat actors and their place in threat modeling. There&apos;s a lively discussion on risk management, drawing the line between &apos;thinking like an attacker&apos; and using current attacker data to inform a threat model. Adam also suggests that we must evaluate if risk assessments serve us well and how they impact organizations on various levels. The recurring theme is the constant need for evolution and adaptation in threat modeling and risk management processes. You can tune in to get a rich perspective on these key cybersecurity topics.<br/><br/><b>Link<br/></b>Threat Modeling Manifesto: https://www.threatmodelingmanifesto.org/<br/>Threat Modeling Capabilities: https://www.threatmodelingmanifesto.org/capabilities/<br/><br/><em>Threats: What Every Engineer Should Learn From Star Wars</em> by Adam Shostack - https://threatsbook.com/</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14448690-adam-shostack-thinking-like-an-attacker-and-risk-management-in-the-capabilities.mp3" length="33430747" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14448690</guid>
    <pubDate>Tue, 06 Feb 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14448690/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14448690/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14448690/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14448690/transcript.vtt" type="text/vtt" />
    <itunes:duration>2783</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Bug Bounty Theater and Responsible Bug Bounty</itunes:title>
    <title>Bug Bounty Theater and Responsible Bug Bounty</title>
    <itunes:summary><![CDATA[Izar, Matt, and Chris discuss the effectiveness of bug bounty programs and delve into topics such as scoping challenges, the ethical considerations of selling exploits, and whether it is all just bug bounty theater. The hosts share their insights and opinions on the subject, providing a thought-provoking discussion on the current state of bug bounties in the security industry. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Tabl...]]></itunes:summary>
    <description><![CDATA[<p>Izar, Matt, and Chris discuss the effectiveness of bug bounty programs and delve into topics such as scoping challenges, the ethical considerations of selling exploits, and whether it is all just bug bounty theater. The hosts share their insights and opinions on the subject, providing a thought-provoking discussion on the current state of bug bounties in the security industry.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Izar, Matt, and Chris discuss the effectiveness of bug bounty programs and delve into topics such as scoping challenges, the ethical considerations of selling exploits, and whether it is all just bug bounty theater. The hosts share their insights and opinions on the subject, providing a thought-provoking discussion on the current state of bug bounties in the security industry.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14389128-bug-bounty-theater-and-responsible-bug-bounty.mp3" length="19630810" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14389128</guid>
    <pubDate>Tue, 30 Jan 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14389128/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14389128/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14389128/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14389128/transcript.vtt" type="text/vtt" />
    <itunes:duration>1633</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Threat Modeling Capabilities</itunes:title>
    <title>Threat Modeling Capabilities</title>
    <itunes:summary><![CDATA[This week around the Security Table Matt, Izar and Chris discuss the recently-published Threat Modeling Capabilities document. They explore how capabilities serve as measurable goals that organizations either possess or lack, contrasting the binary nature of capabilities with the continuum of maturity. The team shares insights on the careful definition and measurement of each capability, highlighting the creative debates and diverse perspectives that enriched the document.  They also emphasiz...]]></itunes:summary>
    <description><![CDATA[<p>This week around the Security Table Matt, Izar and Chris discuss the recently-published Threat Modeling Capabilities document. They explore how capabilities serve as measurable goals that organizations either possess or lack, contrasting the binary nature of capabilities with the continuum of maturity. The team shares insights on the careful definition and measurement of each capability, highlighting the creative debates and diverse perspectives that enriched the document.<br/><br/>They also emphasize the collaborative effort behind the document&apos;s creation. The process mirrors the successful teamwork from the Threat Modeling Manifesto, showcasing the enjoyment and effectiveness of their work together.<br/><br/>Finally, the team reflects on their journey from the project&apos;s start to the release of the Threat Modeling Capabilities document. They share personal stories and the collaborative spirit that led to the project&apos;s success, inviting feedback from the community to refine and improve the document further.<br/><br/><b>Links<br/></b>Threat Modeling Manifesto: https://www.threatmodelingmanifesto.org/<br/>Threat Modeling Capabilities: https://www.threatmodelingmanifesto.org/capabilities/</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>This week around the Security Table Matt, Izar and Chris discuss the recently-published Threat Modeling Capabilities document. They explore how capabilities serve as measurable goals that organizations either possess or lack, contrasting the binary nature of capabilities with the continuum of maturity. The team shares insights on the careful definition and measurement of each capability, highlighting the creative debates and diverse perspectives that enriched the document.<br/><br/>They also emphasize the collaborative effort behind the document&apos;s creation. The process mirrors the successful teamwork from the Threat Modeling Manifesto, showcasing the enjoyment and effectiveness of their work together.<br/><br/>Finally, the team reflects on their journey from the project&apos;s start to the release of the Threat Modeling Capabilities document. They share personal stories and the collaborative spirit that led to the project&apos;s success, inviting feedback from the community to refine and improve the document further.<br/><br/><b>Links<br/></b>Threat Modeling Manifesto: https://www.threatmodelingmanifesto.org/<br/>Threat Modeling Capabilities: https://www.threatmodelingmanifesto.org/capabilities/</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14349694-threat-modeling-capabilities.mp3" length="30247357" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14349694</guid>
    <pubDate>Tue, 23 Jan 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14349694/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14349694/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14349694/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14349694/transcript.vtt" type="text/vtt" />
    <itunes:duration>2517</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Open Source Puppies and Beer</itunes:title>
    <title>Open Source Puppies and Beer</title>
    <itunes:summary><![CDATA[Chris, Izar, and Matt address the complexities of open-source component usage, vulnerability patches, civic responsibility, and licensing issues in this Security Table roundtable. Sparked by a LinkedIn post from Bob Lord, Senior Technical Advisor at CISA, they discuss whether software companies have a civic duty to distribute fixes for vulnerabilities they discover in open-source components. They also examine if there is a need to threat model every third-party component and consider the impl...]]></itunes:summary>
    <description><![CDATA[<p>Chris, Izar, and Matt address the complexities of open-source component usage, vulnerability patches, civic responsibility, and licensing issues in this Security Table roundtable. Sparked by a LinkedIn post from Bob Lord, Senior Technical Advisor at CISA, they discuss whether software companies have a civic duty to distribute fixes for vulnerabilities they discover in open-source components. They also examine if there is a need to threat model every third-party component and consider the implications of certain licenses for security patches. This is a discussion that needs to be had by anyone using open-source components in their code. Listen in and engage as we learn and think through this important issue together!</p><p><br/></p><p>Links:</p><p>Bob Lord’s post about Open Source Responsibility:<br/><a href='https://www.linkedin.com/posts/lordbob_just-a-quick-thought-on-open-source-if-you-activity-7146137722095558657-z_RI'>https://www.linkedin.com/posts/lordbob_just-a-quick-thought-on-open-source-if-you-activity-7146137722095558657-z_RI</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris, Izar, and Matt address the complexities of open-source component usage, vulnerability patches, civic responsibility, and licensing issues in this Security Table roundtable. Sparked by a LinkedIn post from Bob Lord, Senior Technical Advisor at CISA, they discuss whether software companies have a civic duty to distribute fixes for vulnerabilities they discover in open-source components. They also examine if there is a need to threat model every third-party component and consider the implications of certain licenses for security patches. This is a discussion that needs to be had by anyone using open-source components in their code. Listen in and engage as we learn and think through this important issue together!</p><p><br/></p><p>Links:</p><p>Bob Lord’s post about Open Source Responsibility:<br/><a href='https://www.linkedin.com/posts/lordbob_just-a-quick-thought-on-open-source-if-you-activity-7146137722095558657-z_RI'>https://www.linkedin.com/posts/lordbob_just-a-quick-thought-on-open-source-if-you-activity-7146137722095558657-z_RI</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14303706-open-source-puppies-and-beer.mp3" length="29245822" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14303706</guid>
    <pubDate>Tue, 16 Jan 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14303706/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14303706/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14303706/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14303706/transcript.vtt" type="text/vtt" />
    <itunes:duration>2434</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>AppSec Resolutions</itunes:title>
    <title>AppSec Resolutions</title>
    <itunes:summary><![CDATA[Join us for the final episode of The Security Table for 2023. Chris, Izar, and Matt answer fan mail, make fun predictions for the upcoming year, discuss their resolutions for improving cybersecurity, and make a call to action to global listeners. Highlights include the reach of the podcast, explaining Large Language Models (LLMs), Quantum LLMs, Software Bill of Materials (SBOM), and the importance of teaching secure coding from high school level up. Chris, Izar, and Matt share their passion f...]]></itunes:summary>
    <description><![CDATA[<p>Join us for the final episode of The Security Table for 2023. Chris, Izar, and Matt answer fan mail, make fun predictions for the upcoming year, discuss their resolutions for improving cybersecurity, and make a call to action to global listeners. Highlights include the reach of the podcast, explaining Large Language Models (LLMs), Quantum LLMs, Software Bill of Materials (SBOM), and the importance of teaching secure coding from high school level up. Chris, Izar, and Matt share their passion for making cybersecurity more accessible, practical, and effective through critical discussions and innovative ideas.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Join us for the final episode of The Security Table for 2023. Chris, Izar, and Matt answer fan mail, make fun predictions for the upcoming year, discuss their resolutions for improving cybersecurity, and make a call to action to global listeners. Highlights include the reach of the podcast, explaining Large Language Models (LLMs), Quantum LLMs, Software Bill of Materials (SBOM), and the importance of teaching secure coding from high school level up. Chris, Izar, and Matt share their passion for making cybersecurity more accessible, practical, and effective through critical discussions and innovative ideas.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14275063-appsec-resolutions.mp3" length="34412091" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14275063</guid>
    <pubDate>Tue, 09 Jan 2024 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14275063/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14275063/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14275063/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14275063/transcript.vtt" type="text/vtt" />
    <itunes:duration>2864</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>39</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Impact of Prompt Injection and HackAPrompt_AI in the Age of Security</itunes:title>
    <title>The Impact of Prompt Injection and HackAPrompt_AI in the Age of Security</title>
    <itunes:summary><![CDATA[Sander Schulhoff of Learn Prompting joins us at The Security Table to discuss prompt injection and AI security. Prompt injection is a technique that manipulates AI models such as ChatGPT to produce undesired or harmful outputs, such as instructions for building a bomb or rewarding refunds on false claims. Sander provides a helpful introduction to this concept and a basic overview of how AIs are structured and trained. Sander's perspective from AI research and practice balances our security qu...]]></itunes:summary>
    <description><![CDATA[<p>Sander Schulhoff of Learn Prompting joins us at The Security Table to discuss prompt injection and AI security. Prompt injection is a technique that manipulates AI models such as ChatGPT to produce undesired or harmful outputs, such as instructions for building a bomb or rewarding refunds on false claims. Sander provides a helpful introduction to this concept and a basic overview of how AIs are structured and trained. Sander&apos;s perspective from AI research and practice balances our security questions as we uncover where the real security threats lie and propose appropriate security responses.<br/><br/>Sander explains the HackAPrompt competition that challenged participants to trick AI models into saying &quot;I have been pwned.&quot; This task proved surprisingly difficult due to AI models&apos; resistance to specific phrases and provided an excellent framework for understanding the complexities of AI manipulation. Participants employed various creative techniques, including crafting massive input prompts to exploit the physical limitations of AI models. These insights shed light on the need to apply basic security principles to AI, ensuring that these systems are robust against manipulation and misuse.<br/><br/>Our discussion then shifts to more practical aspects, with Sander sharing valuable resources for those interested in becoming adept at prompt injection. We explore the ethical and security implications of AI in decision-making scenarios, such as military applications and self-driving cars, underscoring the importance of human oversight in AI operations. The episode culminates with a call to integrate lessons learned from traditional security practices into the development and deployment of AI systems, a crucial step towards ensuring the responsible use of this transformative technology.<br/><br/><b>Links:</b></p><ul><li>Learn Prompting: https://learnprompting.org/</li><li>HackAPrompt: https://www.hackaprompt.com/</li><li>Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition: https://paper.hackaprompt.com/</li></ul><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Sander Schulhoff of Learn Prompting joins us at The Security Table to discuss prompt injection and AI security. Prompt injection is a technique that manipulates AI models such as ChatGPT to produce undesired or harmful outputs, such as instructions for building a bomb or rewarding refunds on false claims. Sander provides a helpful introduction to this concept and a basic overview of how AIs are structured and trained. Sander&apos;s perspective from AI research and practice balances our security questions as we uncover where the real security threats lie and propose appropriate security responses.<br/><br/>Sander explains the HackAPrompt competition that challenged participants to trick AI models into saying &quot;I have been pwned.&quot; This task proved surprisingly difficult due to AI models&apos; resistance to specific phrases and provided an excellent framework for understanding the complexities of AI manipulation. Participants employed various creative techniques, including crafting massive input prompts to exploit the physical limitations of AI models. These insights shed light on the need to apply basic security principles to AI, ensuring that these systems are robust against manipulation and misuse.<br/><br/>Our discussion then shifts to more practical aspects, with Sander sharing valuable resources for those interested in becoming adept at prompt injection. We explore the ethical and security implications of AI in decision-making scenarios, such as military applications and self-driving cars, underscoring the importance of human oversight in AI operations. The episode culminates with a call to integrate lessons learned from traditional security practices into the development and deployment of AI systems, a crucial step towards ensuring the responsible use of this transformative technology.<br/><br/><b>Links:</b></p><ul><li>Learn Prompting: https://learnprompting.org/</li><li>HackAPrompt: https://www.hackaprompt.com/</li><li>Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition: https://paper.hackaprompt.com/</li></ul><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14169822-the-impact-of-prompt-injection-and-hackaprompt_ai-in-the-age-of-security.mp3" length="46576065" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14169822</guid>
    <pubDate>Tue, 19 Dec 2023 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14169822/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14169822/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14169822/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14169822/transcript.vtt" type="text/vtt" />
    <itunes:duration>3878</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>38</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Looking Back, Looking Forward</itunes:title>
    <title>Looking Back, Looking Forward</title>
    <itunes:summary><![CDATA[Join Izar, Matt, and Chris in a broad discussion covering the dynamics of the security community, the evolving role of technology, and the profound impact of social media on our lives. As the trio considers what they are most thankful for in security, they navigate a series of topics that blend professional insights with personal experiences, offering a unique perspective on how these elements intersect in the modern world.  Chris begins by highlighting the importance of collaboration and lea...]]></itunes:summary>
    <description><![CDATA[<p>Join Izar, Matt, and Chris in a broad discussion covering the dynamics of the security community, the evolving role of technology, and the profound impact of social media on our lives. As the trio considers what they are most thankful for in security, they navigate a series of topics that blend professional insights with personal experiences, offering a unique perspective on how these elements intersect in the modern world.<br/><br/>Chris begins by highlighting the importance of collaboration and learning within the ever-expanding security community. Shifting to broader security concerns, Izar emphasizes the value of mentoring and the potential for institutionalizing it through platforms like OWASP. Matt critiques over-relying on AI. He advocates for tool-assisted solutions rather than tool-performed ones and stresses the importance of accurately representing AI&apos;s capabilities.<br/><br/>In a particularly engaging segment, the panelists explore the influence of social media and technology on personal well-being. They share anecdotes and observations on the pursuit of simplicity in a tech-driven world, discussing the concept of &apos;social media sobriety&apos; and social media&apos;s impact on happiness. They conclude with a collective call to action, urging viewers to engage in positive change through volunteering, mentoring, and contributing to open-source projects. This discussion is a must-watch for anyone interested in the intersection of technology, security, and societal trends.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Join Izar, Matt, and Chris in a broad discussion covering the dynamics of the security community, the evolving role of technology, and the profound impact of social media on our lives. As the trio considers what they are most thankful for in security, they navigate a series of topics that blend professional insights with personal experiences, offering a unique perspective on how these elements intersect in the modern world.<br/><br/>Chris begins by highlighting the importance of collaboration and learning within the ever-expanding security community. Shifting to broader security concerns, Izar emphasizes the value of mentoring and the potential for institutionalizing it through platforms like OWASP. Matt critiques over-relying on AI. He advocates for tool-assisted solutions rather than tool-performed ones and stresses the importance of accurately representing AI&apos;s capabilities.<br/><br/>In a particularly engaging segment, the panelists explore the influence of social media and technology on personal well-being. They share anecdotes and observations on the pursuit of simplicity in a tech-driven world, discussing the concept of &apos;social media sobriety&apos; and social media&apos;s impact on happiness. They conclude with a collective call to action, urging viewers to engage in positive change through volunteering, mentoring, and contributing to open-source projects. This discussion is a must-watch for anyone interested in the intersection of technology, security, and societal trends.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14046472-looking-back-looking-forward.mp3" length="33327196" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14046472</guid>
    <pubDate>Tue, 28 Nov 2023 22:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14046472/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14046472/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14046472/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14046472/transcript.vtt" type="text/vtt" />
    <itunes:duration>2774</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>37</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CVSS 4.0 Unleashed with Patrick Garrity</itunes:title>
    <title>CVSS 4.0 Unleashed with Patrick Garrity</title>
    <itunes:summary><![CDATA[Patrick Garrity joins the Security Table to unpack CVSS 4.0, its impact on your program, and whether or not it will change the game, the rules of how the game is played, or maybe the entire game. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening! ]]></itunes:summary>
    <description><![CDATA[<p>Patrick Garrity joins the Security Table to unpack CVSS 4.0, its impact on your program, and whether or not it will change the game, the rules of how the game is played, or maybe the entire game.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Patrick Garrity joins the Security Table to unpack CVSS 4.0, its impact on your program, and whether or not it will change the game, the rules of how the game is played, or maybe the entire game.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/14001576-cvss-4-0-unleashed-with-patrick-garrity.mp3" length="42112195" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14001576</guid>
    <pubDate>Tue, 21 Nov 2023 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14001576/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14001576/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14001576/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/14001576/transcript.vtt" type="text/vtt" />
    <itunes:duration>3506</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>36</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>An SBOM Lifecycle</itunes:title>
    <title>An SBOM Lifecycle</title>
    <itunes:summary><![CDATA[Aditi Sharma joins Matt, Izar, and Chris around the Security Table to discuss Software Bill of Materials (SBOMs). The team discusses potential advantages as well as challenges of SBOMs in different contexts such as SaaS solutions, physical products, and internal procedures. The episode also explores the importance of knowing what software components a company is consuming and the significance of SBOM for vulnerability management and risk posture. The team concludes by stressing that while SBO...]]></itunes:summary>
    <description><![CDATA[<p>Aditi Sharma joins Matt, Izar, and Chris around the Security Table to discuss Software Bill of Materials (SBOMs). The team discusses potential advantages as well as challenges of SBOMs in different contexts such as SaaS solutions, physical products, and internal procedures. The episode also explores the importance of knowing what software components a company is consuming and the significance of SBOM for vulnerability management and risk posture. The team concludes by stressing that while SBOM has great potential value, the value realization is still a work in progress.<br/><br/><b>Links:<br/></b>Chris&apos; LinkedIn post about the SBOM cycle: <a href='https://www.linkedin.com/posts/securityjourney_where-is-the-part-where-the-vulnerabilities-activity-7128757968740777986-0PQV'>https://www.linkedin.com/posts/securityjourney_where-is-the-part-where-the-vulnerabilities-activity-7128757968740777986-0PQV</a><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Aditi Sharma joins Matt, Izar, and Chris around the Security Table to discuss Software Bill of Materials (SBOMs). The team discusses potential advantages as well as challenges of SBOMs in different contexts such as SaaS solutions, physical products, and internal procedures. The episode also explores the importance of knowing what software components a company is consuming and the significance of SBOM for vulnerability management and risk posture. The team concludes by stressing that while SBOM has great potential value, the value realization is still a work in progress.<br/><br/><b>Links:<br/></b>Chris&apos; LinkedIn post about the SBOM cycle: <a href='https://www.linkedin.com/posts/securityjourney_where-is-the-part-where-the-vulnerabilities-activity-7128757968740777986-0PQV'>https://www.linkedin.com/posts/securityjourney_where-is-the-part-where-the-vulnerabilities-activity-7128757968740777986-0PQV</a><br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13967067-an-sbom-lifecycle.mp3" length="32905555" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13967067</guid>
    <pubDate>Tue, 14 Nov 2023 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13967067/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13967067/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13967067/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13967067/transcript.vtt" type="text/vtt" />
    <itunes:duration>2739</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>35</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>An SBOM Fable</itunes:title>
    <title>An SBOM Fable</title>
    <itunes:summary><![CDATA[Join Chris, Matt, and Izar for a lively conversation about an article that offers 20 points of "essential details" to look for in a Software Bill of Materials (SBOM). They dissect and debate various points raised in the article, including generating SBOMs, the necessary components, and how to gauge the quality of this digital inventory. Their critique is both insightful and humorously candid, and they will offer you a tour through the often complex world of software documentation.  Hear about...]]></itunes:summary>
    <description><![CDATA[<p>Join Chris, Matt, and Izar for a lively conversation about an article that offers 20 points of &quot;essential details&quot; to look for in a Software Bill of Materials (SBOM). They dissect and debate various points raised in the article, including generating SBOMs, the necessary components, and how to gauge the quality of this digital inventory. Their critique is both insightful and humorously candid, and they will offer you a tour through the often complex world of software documentation.<br/><br/>Hear about topics ranging from open source dependency tree, the necessity – or not – of manual SBOM generation, and the importance of a Vulnerability Exploitability Exchange (VEX) document alongside an SBOM. You will hear why they think an SBOM with a VEX can transform and simplify risk assessment procedures by providing clear and actionable insights for threat management. <br/><br/><b>Links:<br/><br/></b><a href='https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/'>Forbes: 20 Tech Experts Share Essential Details To Look For In An SBOM</a><br/><a href='https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/'>https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Join Chris, Matt, and Izar for a lively conversation about an article that offers 20 points of &quot;essential details&quot; to look for in a Software Bill of Materials (SBOM). They dissect and debate various points raised in the article, including generating SBOMs, the necessary components, and how to gauge the quality of this digital inventory. Their critique is both insightful and humorously candid, and they will offer you a tour through the often complex world of software documentation.<br/><br/>Hear about topics ranging from open source dependency tree, the necessity – or not – of manual SBOM generation, and the importance of a Vulnerability Exploitability Exchange (VEX) document alongside an SBOM. You will hear why they think an SBOM with a VEX can transform and simplify risk assessment procedures by providing clear and actionable insights for threat management. <br/><br/><b>Links:<br/><br/></b><a href='https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/'>Forbes: 20 Tech Experts Share Essential Details To Look For In An SBOM</a><br/><a href='https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/'>https://www.forbes.com/sites/forbestechcouncil/2023/10/09/20-tech-experts-share-essential-details-to-look-for-in-an-sbom/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13930339-an-sbom-fable.mp3" length="26886713" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13930339</guid>
    <pubDate>Wed, 08 Nov 2023 05:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13930339/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13930339/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13930339/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13930339/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2094080/13930339/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="An SBOM Fable" />
  <psc:chapter start="2:06" title="1. An Open-Source Dependency Tree" />
  <psc:chapter start="4:55" title="2. A Library with Version Numbers" />
  <psc:chapter start="9:50" title="3 &amp; 4. Details on Updates and A List of Third-Party Components" />
  <psc:chapter start="13:14" title="8. Whether the SBOM is Generated Dynamically or Manually" />
  <psc:chapter start="20:02" title="9. The Encryption Protocol and Library" />
  <psc:chapter start="23:32" title="10. Data Residency" />
  <psc:chapter start="25:46" title="16. How Many and Which Functions Are Enabled" />
  <psc:chapter start="27:23" title="13. How Long It Takes To Receive the SBOM" />
  <psc:chapter start="30:22" title="18. The Delivery Address" />
  <psc:chapter start="32:37" title="20. The Final Price" />
  <psc:chapter start="34:17" title="19. A VEX Document" />
</psc:chapters>
    <itunes:duration>2237</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</itunes:title>
    <title>NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</title>
    <itunes:summary><![CDATA[Matt, Chris, and Izar discuss the recently published "NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations." They review each point and critically analyze the document's content, pointing out areas where the terminology might be misleading or where the emphasis should be shifted. As they work through the top ten list, several trends and larger conversations appear out of the individual points.   The trio delves into the nuances of system configurations, emphasizing th...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Chris, and Izar discuss the recently published &quot;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations.&quot; They review each point and critically analyze the document&apos;s content, pointing out areas where the terminology might be misleading or where the emphasis should be shifted. As they work through the top ten list, several trends and larger conversations appear out of the individual points. <br/><br/>The trio delves into the nuances of system configurations, emphasizing the risks associated with default settings that expose insecure protocols. Systems should not provide options that are inherently insecure! They also touch upon the challenges of network segmentation in the era of software-defined networking and the implications of poor patch management. They highlight the importance of understanding the difference between configuration problems and design flaws, particularly in password management and storage. <br/><br/>The discussion provides insights into the complexities of cybersecurity and the challenges of ensuring that systems are both user-friendly and secure. The dynamic exchange underscores the importance of continuous learning and adaptation in the ever-evolving field of cybersecurity.<br/><br/><b>Helpful Links:<br/><br/></b><a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a'>NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</a><br/>     https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Chris, and Izar discuss the recently published &quot;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations.&quot; They review each point and critically analyze the document&apos;s content, pointing out areas where the terminology might be misleading or where the emphasis should be shifted. As they work through the top ten list, several trends and larger conversations appear out of the individual points. <br/><br/>The trio delves into the nuances of system configurations, emphasizing the risks associated with default settings that expose insecure protocols. Systems should not provide options that are inherently insecure! They also touch upon the challenges of network segmentation in the era of software-defined networking and the implications of poor patch management. They highlight the importance of understanding the difference between configuration problems and design flaws, particularly in password management and storage. <br/><br/>The discussion provides insights into the complexities of cybersecurity and the challenges of ensuring that systems are both user-friendly and secure. The dynamic exchange underscores the importance of continuous learning and adaptation in the ever-evolving field of cybersecurity.<br/><br/><b>Helpful Links:<br/><br/></b><a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a'>NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</a><br/>     https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13818143-nsa-and-cisa-red-and-blue-teams-share-top-ten-cybersecurity-misconfigurations.mp3" length="14552356" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13818143</guid>
    <pubDate>Tue, 24 Oct 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13818143/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13818143/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13818143/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13818143/transcript.vtt" type="text/vtt" />
    <itunes:duration>1209</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Future Role of Security and Shifting off the Table</itunes:title>
    <title>The Future Role of Security and Shifting off the Table</title>
    <itunes:summary><![CDATA[The Security Table gathers to discuss the evolving landscape of application security and its potential integration with development. Chris posits that application or product security will eventually be absorbed by the development sector, eliminating the need for separate teams. One hindrance to this vision is the friction between security and engineering teams in many organizations.  Many people think that security incidents have negative implications on brand reputation and value. Izar point...]]></itunes:summary>
    <description><![CDATA[<p>The Security Table gathers to discuss the evolving landscape of application security and its potential integration with development. Chris posits that application or product security will eventually be absorbed by the development sector, eliminating the need for separate teams. One hindrance to this vision is the friction between security and engineering teams in many organizations.<br/><br/>Many people think that security incidents have negative implications on brand reputation and value. Izar points out that, contrary to popular belief, major security breaches, such as those experienced by Sony and MGM, do not have a lasting impact on stock prices. Chris counters this by highlighting the potential for upcoming privacy legislation in the U.S., which could shift the focus and importance of security in the corporate world.<br/><br/>Chris envisions a future where the security team is dissolved and its functions are absorbed across various business units. This would lead to better alignment, reduced infighting, and more efficient budget allocation. Security functions need to be placed where they can have the most significant impact, without the potential conflicts that currently exist between security teams and other business units.<br/><br/>The second topic of discussion is the &quot;shift left&quot; movement in the realm of application security. There is ambiguity and potential misuse of the term. What exactly is being shifted and from where does the shift start? The term &quot;shift left&quot; suggests moving security considerations earlier in the development process. However, the hosts point out that the phrase has been co-opted and weaponized for marketing purposes, often without a clear understanding of its implications. For instance, they highlight that while it&apos;s easy to claim that a product or process &quot;shifts left,&quot; it&apos;s essential to define what is being shifted, how much, and the tangible benefits of such a shift.<br/><br/>Matt emphasizes the idea of not just shifting left but starting left, meaning that security considerations should begin from the requirements phase of a project. Chris mentions that the concept of shifting left isn&apos;t new and cites Joe Jarzombek&apos;s late 90s initiative called &quot;Building Security In&quot; as a precursor to the current shift left movement. The hosts also humorously liken the shift left movement to a game of Frogger, suggesting that if one shifts too much to the left, they might miss the mark entirely. The discussion underscores the need for clarity and purpose when adopting the shift left philosophy, rather than just using it as a buzzword.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Security Table gathers to discuss the evolving landscape of application security and its potential integration with development. Chris posits that application or product security will eventually be absorbed by the development sector, eliminating the need for separate teams. One hindrance to this vision is the friction between security and engineering teams in many organizations.<br/><br/>Many people think that security incidents have negative implications on brand reputation and value. Izar points out that, contrary to popular belief, major security breaches, such as those experienced by Sony and MGM, do not have a lasting impact on stock prices. Chris counters this by highlighting the potential for upcoming privacy legislation in the U.S., which could shift the focus and importance of security in the corporate world.<br/><br/>Chris envisions a future where the security team is dissolved and its functions are absorbed across various business units. This would lead to better alignment, reduced infighting, and more efficient budget allocation. Security functions need to be placed where they can have the most significant impact, without the potential conflicts that currently exist between security teams and other business units.<br/><br/>The second topic of discussion is the &quot;shift left&quot; movement in the realm of application security. There is ambiguity and potential misuse of the term. What exactly is being shifted and from where does the shift start? The term &quot;shift left&quot; suggests moving security considerations earlier in the development process. However, the hosts point out that the phrase has been co-opted and weaponized for marketing purposes, often without a clear understanding of its implications. For instance, they highlight that while it&apos;s easy to claim that a product or process &quot;shifts left,&quot; it&apos;s essential to define what is being shifted, how much, and the tangible benefits of such a shift.<br/><br/>Matt emphasizes the idea of not just shifting left but starting left, meaning that security considerations should begin from the requirements phase of a project. Chris mentions that the concept of shifting left isn&apos;t new and cites Joe Jarzombek&apos;s late 90s initiative called &quot;Building Security In&quot; as a precursor to the current shift left movement. The hosts also humorously liken the shift left movement to a game of Frogger, suggesting that if one shifts too much to the left, they might miss the mark entirely. The discussion underscores the need for clarity and purpose when adopting the shift left philosophy, rather than just using it as a buzzword.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13785721-the-future-role-of-security-and-shifting-off-the-table.mp3" length="39622025" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13785721</guid>
    <pubDate>Tue, 17 Oct 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13785721/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13785721/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13785721/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13785721/transcript.vtt" type="text/vtt" />
    <itunes:duration>3298</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Show About Nothing that Turned into Something</itunes:title>
    <title>A Show About Nothing that Turned into Something</title>
    <itunes:summary><![CDATA[The Security Table gathers this week to discuss expectations about tooling in the Application Security industry. Matt emphasizes that tools should essentially automate tasks that humans can perform but in a faster and more efficient manner. The conversation then shifts to the overwhelming nature of communication platforms like Slack. Izar highlights the challenges of managing attention spans and context-switching when one is part of numerous Slack channels, likening it to being in a room with...]]></itunes:summary>
    <description><![CDATA[<p>The Security Table gathers this week to discuss expectations about tooling in the Application Security industry. Matt emphasizes that tools should essentially automate tasks that humans can perform but in a faster and more efficient manner. The conversation then shifts to the overwhelming nature of communication platforms like Slack. Izar highlights the challenges of managing attention spans and context-switching when one is part of numerous Slack channels, likening it to being in a room with a hundred simultaneous conversations.<br/><br/>The hosts further discuss the integration of tools and the importance of contextualization. Current tools provide too many results, lack context, and therefore fail to recommend effective solutions. They touch upon the idea of startups building their own suite of tools to ensure seamless communication between them, even if they aren&apos;t the best in their individual categories. <br/><br/>The episode concludes with a thought-provoking statement from Chris, who envisions a future where AppSec might become obsolete, and development could potentially absorb the security team. He teases this topic for the next episode, urging listeners and co-hosts to ponder this radical idea.<br/><br/>Overall, the episode provides a look into the current state of security tooling, the challenges faced by professionals, and the potential future of the AppSec landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Security Table gathers this week to discuss expectations about tooling in the Application Security industry. Matt emphasizes that tools should essentially automate tasks that humans can perform but in a faster and more efficient manner. The conversation then shifts to the overwhelming nature of communication platforms like Slack. Izar highlights the challenges of managing attention spans and context-switching when one is part of numerous Slack channels, likening it to being in a room with a hundred simultaneous conversations.<br/><br/>The hosts further discuss the integration of tools and the importance of contextualization. Current tools provide too many results, lack context, and therefore fail to recommend effective solutions. They touch upon the idea of startups building their own suite of tools to ensure seamless communication between them, even if they aren&apos;t the best in their individual categories. <br/><br/>The episode concludes with a thought-provoking statement from Chris, who envisions a future where AppSec might become obsolete, and development could potentially absorb the security team. He teases this topic for the next episode, urging listeners and co-hosts to ponder this radical idea.<br/><br/>Overall, the episode provides a look into the current state of security tooling, the challenges faced by professionals, and the potential future of the AppSec landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13734109-a-show-about-nothing-that-turned-into-something.mp3" length="24179568" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13734109</guid>
    <pubDate>Tue, 10 Oct 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13734109/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13734109/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13734109/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13734109/transcript.vtt" type="text/vtt" />
    <itunes:duration>2012</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Hamster Wheel of Scan and Fix</itunes:title>
    <title>The Hamster Wheel of Scan and Fix</title>
    <itunes:summary><![CDATA[Matt and Izar join in a debate with Chris Romeo as he challenges the paradigm of "scan and fix" in application security. Chris references a LinkedIn post he made, which sparked significant reactions, emphasizing the repetitive nature of the scan and fix process. His post critiqued the tools used in this process, noting that they often produce extensive lists of potential vulnerabilities, many of which might be false positives or not appropriately prioritized. He underscores the need for innov...]]></itunes:summary>
    <description><![CDATA[<p>Matt and Izar join in a debate with Chris Romeo as he challenges the paradigm of &quot;scan and fix&quot; in application security. Chris references a LinkedIn post he made, which sparked significant reactions, emphasizing the repetitive nature of the scan and fix process. His post critiqued the tools used in this process, noting that they often produce extensive lists of potential vulnerabilities, many of which might be false positives or not appropriately prioritized. He underscores the need for innovation in this domain, urging for a departure from the traditional methods. <br/><br/>Izar gives some helpful historical context at the beginning of his response. The discussion emphasizes the significance of contextualizing results. Merely scanning and obtaining scores isn&apos;t sufficient; there&apos;s a pressing need for tools to offer actionable, valid outcomes and to understand the context in which vulnerabilities arise. The role of AI in this domain is touched upon, humorously envisioning an AI-based scanning tool analyzing AI-written code, leading to a unique &quot;Turing test&quot; scenario.<br/><br/>Addressing the human factor, Izar notes that while tools can evolve, human errors remain constant. Matt suggests setting developmental guardrails, especially when selecting open-source projects, to ensure enhanced security. The episode concludes with a unanimous call for improved tools that reduce noise, prioritize results, and provide actionable insights, aiming for a more streamlined approach to application security.<br/><br/>Chris encourages listeners, especially those newer to the industry, to think outside the box and not just accept established practices. He expresses a desire for a world where scan-and-fix is replaced by something more efficient and effective. While he acknowledges the importance of contextualizing results, he firmly believes that there must be a better way than the current scan-and-fix pattern.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt and Izar join in a debate with Chris Romeo as he challenges the paradigm of &quot;scan and fix&quot; in application security. Chris references a LinkedIn post he made, which sparked significant reactions, emphasizing the repetitive nature of the scan and fix process. His post critiqued the tools used in this process, noting that they often produce extensive lists of potential vulnerabilities, many of which might be false positives or not appropriately prioritized. He underscores the need for innovation in this domain, urging for a departure from the traditional methods. <br/><br/>Izar gives some helpful historical context at the beginning of his response. The discussion emphasizes the significance of contextualizing results. Merely scanning and obtaining scores isn&apos;t sufficient; there&apos;s a pressing need for tools to offer actionable, valid outcomes and to understand the context in which vulnerabilities arise. The role of AI in this domain is touched upon, humorously envisioning an AI-based scanning tool analyzing AI-written code, leading to a unique &quot;Turing test&quot; scenario.<br/><br/>Addressing the human factor, Izar notes that while tools can evolve, human errors remain constant. Matt suggests setting developmental guardrails, especially when selecting open-source projects, to ensure enhanced security. The episode concludes with a unanimous call for improved tools that reduce noise, prioritize results, and provide actionable insights, aiming for a more streamlined approach to application security.<br/><br/>Chris encourages listeners, especially those newer to the industry, to think outside the box and not just accept established practices. He expresses a desire for a world where scan-and-fix is replaced by something more efficient and effective. While he acknowledges the importance of contextualizing results, he firmly believes that there must be a better way than the current scan-and-fix pattern.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13659947-the-hamster-wheel-of-scan-and-fix.mp3" length="40694675" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13659947</guid>
    <pubDate>Tue, 26 Sep 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13659947/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13659947/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13659947/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13659947/transcript.vtt" type="text/vtt" />
    <itunes:duration>3388</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>30</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Threat Modeling Conference</itunes:title>
    <title>Threat Modeling Conference</title>
    <itunes:summary><![CDATA[The Security Table gathers to discuss the upcoming ThreatModCon 2023 (https://www.threatmodelingconnect.com), the inaugural and only conference dedicated entirely to threat modeling.   ThreatModCon 2023  Sunday, October 29, 2023 Marriott Marquis Washington, DC   The Threat Modeling Conference will cover various aspects of threat modeling, from AI integration to privacy concerns, from a brief history of threat modeling to hands-on workshops. The sessions will emphasize learning, interacti...]]></itunes:summary>
    <description><![CDATA[<p>The Security Table gathers to discuss the upcoming ThreatModCon 2023 (<a href='https://www.threatmodelingconnect.com/'>https://www.threatmodelingconnect.com</a>), the inaugural and <em>only</em> conference dedicated entirely to threat modeling.<br/><br/></p><p>ThreatModCon 2023 </p><p>Sunday, October 29, 2023</p><p>Marriott Marquis Washington, DC<br/><br/></p><p>The Threat Modeling Conference will cover various aspects of threat modeling, from AI integration to privacy concerns, from a brief history of threat modeling to hands-on workshops. The sessions will emphasize learning, interaction, and applying knowledge in real-world scenarios. <br/><br/></p><p>~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-</p><p>From threatmodelingconnect.com:<br/><br/></p><p>Join us for the inaugural Threat Modeling Conference — the first annual meetup of our community — on October 29th to learn, share, and discuss how to make threat modeling approachable to everyone.<br/><br/></p><p>Come away with the latest trends, tools, and strategies in threat modeling, helping you stay ahead of the curve as you navigate the constantly-changing cybersecurity landscape<br/><br/></p><p><b>Meet the Speakers</b><br/><b>Welcome / Closing: </b>Chris Romeo<br/><b>Keynote:</b> Matthew Coles, Seba Deleersnyder, Robert Hurlbut, Tanya Janka, Brook Schoenfield, John Taylor<br/><b>Workshop Leaders: </b>Robert Hurlbut, Jonathan (Jono) Sosulska<br/><b>Speakers:</b> Michael Bernhardt, James Berthoty, Lisa Cook, Avi Douglen, Tyson Garrett, Geoff Hill, Wael Ghandour, Brenna Leath, Dr. Michael Loadenthal, Edouard Stoka, Dr. Kim Wuyts<br/><br/></p><p><b>I’m new to threat modeling, Is this conference for me?</b><br/>At the heart of this inaugural threat modeling conference is our belief that “threat modeling is for everyone.” Whether you’ve heard about threat modeling for the first time or have been on this journey for decades, we believe you’ll benefit from the insightful talks, dynamic workshops, and plenty of hallway conversations. You’ll come away with the knowledge, skills, and connections needed to take your security career to new heights.</p><p>~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-</p><p><br/></p><p>Listen in to hear what excites Chris, Matt, and Izar about ThreatModCon, and sign up to attend yourself!</p><p><br/></p><p>Threat Modeling is for Everyone!</p><p><br/></p><p><a href='https://www.threatmodelingconnect.com/'>https://www.threatmodelingconnect.com/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Security Table gathers to discuss the upcoming ThreatModCon 2023 (<a href='https://www.threatmodelingconnect.com/'>https://www.threatmodelingconnect.com</a>), the inaugural and <em>only</em> conference dedicated entirely to threat modeling.<br/><br/></p><p>ThreatModCon 2023 </p><p>Sunday, October 29, 2023</p><p>Marriott Marquis Washington, DC<br/><br/></p><p>The Threat Modeling Conference will cover various aspects of threat modeling, from AI integration to privacy concerns, from a brief history of threat modeling to hands-on workshops. The sessions will emphasize learning, interaction, and applying knowledge in real-world scenarios. <br/><br/></p><p>~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-</p><p>From threatmodelingconnect.com:<br/><br/></p><p>Join us for the inaugural Threat Modeling Conference — the first annual meetup of our community — on October 29th to learn, share, and discuss how to make threat modeling approachable to everyone.<br/><br/></p><p>Come away with the latest trends, tools, and strategies in threat modeling, helping you stay ahead of the curve as you navigate the constantly-changing cybersecurity landscape<br/><br/></p><p><b>Meet the Speakers</b><br/><b>Welcome / Closing: </b>Chris Romeo<br/><b>Keynote:</b> Matthew Coles, Seba Deleersnyder, Robert Hurlbut, Tanya Janka, Brook Schoenfield, John Taylor<br/><b>Workshop Leaders: </b>Robert Hurlbut, Jonathan (Jono) Sosulska<br/><b>Speakers:</b> Michael Bernhardt, James Berthoty, Lisa Cook, Avi Douglen, Tyson Garrett, Geoff Hill, Wael Ghandour, Brenna Leath, Dr. Michael Loadenthal, Edouard Stoka, Dr. Kim Wuyts<br/><br/></p><p><b>I’m new to threat modeling, Is this conference for me?</b><br/>At the heart of this inaugural threat modeling conference is our belief that “threat modeling is for everyone.” Whether you’ve heard about threat modeling for the first time or have been on this journey for decades, we believe you’ll benefit from the insightful talks, dynamic workshops, and plenty of hallway conversations. You’ll come away with the knowledge, skills, and connections needed to take your security career to new heights.</p><p>~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-~-</p><p><br/></p><p>Listen in to hear what excites Chris, Matt, and Izar about ThreatModCon, and sign up to attend yourself!</p><p><br/></p><p>Threat Modeling is for Everyone!</p><p><br/></p><p><a href='https://www.threatmodelingconnect.com/'>https://www.threatmodelingconnect.com/</a></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13603265-threat-modeling-conference.mp3" length="23295258" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13603265</guid>
    <pubDate>Tue, 19 Sep 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13603265/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13603265/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13603265/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13603265/transcript.vtt" type="text/vtt" />
    <itunes:duration>1938</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>AppSec vs. ProdSec</itunes:title>
    <title>AppSec vs. ProdSec</title>
    <itunes:summary><![CDATA[Chris Romeo, Matt Coles, and Izar Tarandach attempt to demystify the concepts of Application Security (AppSec) and Product Security (ProdSec). They find that even defining and differentiating both concepts is challenging. Various articles exist about AppSec and ProdSec, but the industry is generally confused about these terms.   Discussing the role of hardware in product security initiates an animated debate. Questions arise about whether the presence of hardware makes something more of ...]]></itunes:summary>
    <description><![CDATA[<p>Chris Romeo, Matt Coles, and Izar Tarandach attempt to demystify the concepts of Application Security (AppSec) and Product Security (ProdSec). They find that even defining and differentiating both concepts is challenging. Various articles exist about AppSec and ProdSec, but the industry is generally confused about these terms. <br/><br/>Discussing the role of hardware in product security initiates an animated debate. Questions arise about whether the presence of hardware makes something more of a &quot;product&quot; and how software-only products differ from those with hardware components. Supply chain challenges, the significance of hardware in security considerations, and the potential overlap between AppSec and ProdSec become central themes of their conversation.<br/><br/>They make progress during this spirited discussion, but the hosts conclude without arriving at a definitive answer. They humorously acknowledge their collective confusion and agree to revisit the topic in future episodes. This conversation deserves a part two, emphasizing their commitment to understanding and clarifying the nuances of AppSec and ProdSec.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris Romeo, Matt Coles, and Izar Tarandach attempt to demystify the concepts of Application Security (AppSec) and Product Security (ProdSec). They find that even defining and differentiating both concepts is challenging. Various articles exist about AppSec and ProdSec, but the industry is generally confused about these terms. <br/><br/>Discussing the role of hardware in product security initiates an animated debate. Questions arise about whether the presence of hardware makes something more of a &quot;product&quot; and how software-only products differ from those with hardware components. Supply chain challenges, the significance of hardware in security considerations, and the potential overlap between AppSec and ProdSec become central themes of their conversation.<br/><br/>They make progress during this spirited discussion, but the hosts conclude without arriving at a definitive answer. They humorously acknowledge their collective confusion and agree to revisit the topic in future episodes. This conversation deserves a part two, emphasizing their commitment to understanding and clarifying the nuances of AppSec and ProdSec.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13559984-appsec-vs-prodsec.mp3" length="26749646" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13559984</guid>
    <pubDate>Tue, 12 Sep 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13559984/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13559984/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13559984/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13559984/transcript.vtt" type="text/vtt" />
    <itunes:duration>2226</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Imposter Syndrome</itunes:title>
    <title>Imposter Syndrome</title>
    <itunes:summary><![CDATA[Imposter Syndrome is when a person feels inadequate despite their accomplishments. Not unique to the field of cybersecurity or even software development, imposter syndrome can affect any professional as they advance and grow in their area of expertise. Matt and Izar, both seasoned security professionals, openly discuss the dichotomy between their intellectual achievements and the emotional weight of feeling like they don't belong. They touch upon the challenges of presenting at conferences, w...]]></itunes:summary>
    <description><![CDATA[<p>Imposter Syndrome is when a person feels inadequate despite their accomplishments. Not unique to the field of cybersecurity or even software development, imposter syndrome can affect any professional as they advance and grow in their area of expertise.</p><p>Matt and Izar, both seasoned security professionals, openly discuss the dichotomy between their intellectual achievements and the emotional weight of feeling like they don&apos;t belong. They touch upon the challenges of presenting at conferences, where the internal dialogue of self-doubt might be at its loudest, yet they&apos;ve learned to project confidence. </p><p>The conversation also highlights the importance of understanding one&apos;s worth, emphasizing that it doesn&apos;t stem from external validation or the opinions of others. The hosts each share personal anecdotes, such as moments when they felt most vulnerable on stage, and how they&apos;ve learned to navigate these feelings over time. </p><p>This podcast serves as a candid exploration of the imposter syndrome, offering insights and encouragement to professionals from any field who might feel the same way.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Imposter Syndrome is when a person feels inadequate despite their accomplishments. Not unique to the field of cybersecurity or even software development, imposter syndrome can affect any professional as they advance and grow in their area of expertise.</p><p>Matt and Izar, both seasoned security professionals, openly discuss the dichotomy between their intellectual achievements and the emotional weight of feeling like they don&apos;t belong. They touch upon the challenges of presenting at conferences, where the internal dialogue of self-doubt might be at its loudest, yet they&apos;ve learned to project confidence. </p><p>The conversation also highlights the importance of understanding one&apos;s worth, emphasizing that it doesn&apos;t stem from external validation or the opinions of others. The hosts each share personal anecdotes, such as moments when they felt most vulnerable on stage, and how they&apos;ve learned to navigate these feelings over time. </p><p>This podcast serves as a candid exploration of the imposter syndrome, offering insights and encouragement to professionals from any field who might feel the same way.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13527425-imposter-syndrome.mp3" length="24969906" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13527425</guid>
    <pubDate>Tue, 05 Sep 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13527425/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13527425/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13527425/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13527425/transcript.vtt" type="text/vtt" />
    <itunes:duration>2077</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Return on Investment of Threat Modeling</itunes:title>
    <title>The Return on Investment of Threat Modeling</title>
    <itunes:summary><![CDATA[The Security Table team dialogues about the importance of data and metrics in understanding and communicating risk. After Matt defines ROI, Izar emphasizes that while data is crucial, it doesn't always come in numerical form. Instead, risk can be expressed in various ways, such as trends, and doesn't necessarily need to be quantified in traditional terms. Chris stresses that executives need tangible metrics and data to make informed decisions, especially when communicating with legal teams an...]]></itunes:summary>
    <description><![CDATA[<p>The Security Table team dialogues about the importance of data and metrics in understanding and communicating risk. After Matt defines ROI, Izar emphasizes that while data is crucial, it doesn&apos;t always come in numerical form. Instead, risk can be expressed in various ways, such as trends, and doesn&apos;t necessarily need to be quantified in traditional terms. Chris stresses that executives need tangible metrics and data to make informed decisions, especially when communicating with legal teams and other stakeholders.<br/><br/>They then talk about visibility and understanding the attack surface. Izar explains that the attack surface represents an organization&apos;s exposure to potential threats. The goal is to provide a comprehensive picture of the organization&apos;s vulnerabilities and the measures taken to address them. Instead of inundating executives with technical reports, Izar suggests telling a story that conveys the essence of the risks and the steps taken to mitigate them. Chris, however, emphasizes the importance of concrete data and the challenges executives can face in understanding technical nuances.<br/><br/>Lastly, the dialogue touches upon the real-world implications of threat modeling and its ROI. Matt Coles highlights the potential legal and business repercussions if things go awry. The discussion underscores the evolutionary nature of threat modeling, with Izar noting that while one might start with limited expertise, continuous learning and adaptation lead to improvement over time. The overarching theme is the balance between technical details and business-oriented communication, ensuring that executives understand the value and impact of threat modeling initiatives.<br/><br/><b>Links referenced:</b></p><ul><li>US Executive Order 14028 on cybersecurity - https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity</li><li>CISA, Secure by Design, Secure by Default - https://www.cisa.gov/securebydesign</li><li>Secure Software Development Framework (SSDF) from NIST - https://csrc.nist.gov/Projects/ssdf</li></ul><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Security Table team dialogues about the importance of data and metrics in understanding and communicating risk. After Matt defines ROI, Izar emphasizes that while data is crucial, it doesn&apos;t always come in numerical form. Instead, risk can be expressed in various ways, such as trends, and doesn&apos;t necessarily need to be quantified in traditional terms. Chris stresses that executives need tangible metrics and data to make informed decisions, especially when communicating with legal teams and other stakeholders.<br/><br/>They then talk about visibility and understanding the attack surface. Izar explains that the attack surface represents an organization&apos;s exposure to potential threats. The goal is to provide a comprehensive picture of the organization&apos;s vulnerabilities and the measures taken to address them. Instead of inundating executives with technical reports, Izar suggests telling a story that conveys the essence of the risks and the steps taken to mitigate them. Chris, however, emphasizes the importance of concrete data and the challenges executives can face in understanding technical nuances.<br/><br/>Lastly, the dialogue touches upon the real-world implications of threat modeling and its ROI. Matt Coles highlights the potential legal and business repercussions if things go awry. The discussion underscores the evolutionary nature of threat modeling, with Izar noting that while one might start with limited expertise, continuous learning and adaptation lead to improvement over time. The overarching theme is the balance between technical details and business-oriented communication, ensuring that executives understand the value and impact of threat modeling initiatives.<br/><br/><b>Links referenced:</b></p><ul><li>US Executive Order 14028 on cybersecurity - https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity</li><li>CISA, Secure by Design, Secure by Default - https://www.cisa.gov/securebydesign</li><li>Secure Software Development Framework (SSDF) from NIST - https://csrc.nist.gov/Projects/ssdf</li></ul><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13479149-the-return-on-investment-of-threat-modeling.mp3" length="24385651" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13479149</guid>
    <pubDate>Tue, 29 Aug 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13479149/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13479149/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13479149/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13479149/transcript.vtt" type="text/vtt" />
    <itunes:duration>2029</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Jim Manico ❤️ Threat Modeling: The Untold Story</itunes:title>
    <title>Jim Manico ❤️ Threat Modeling: The Untold Story</title>
    <itunes:summary><![CDATA[Jim Manico joins Chris, Matt, and Izar at the Security Table for a rousing discussion on his Threat Modeling journey. They also learn about each other's thoughts about DAST, SAST, SCA, Security in AI, and several other topics. Jim is an educator at heart, and you learn quickly that he loves application security. Jim is not afraid to drop a few controversial opinions and even a rap!  Jim discusses the importance of static application security testing (SAST) and how it is becoming increasingly ...]]></itunes:summary>
    <description><![CDATA[<p>Jim Manico joins Chris, Matt, and Izar at the Security Table for a rousing discussion on his Threat Modeling journey. They also learn about each other&apos;s thoughts about DAST, SAST, SCA, Security in AI, and several other topics. Jim is an educator at heart, and you learn quickly that he loves application security. Jim is not afraid to drop a few controversial opinions and even a rap!<br/><br/>Jim discusses the importance of static application security testing (SAST) and how it is becoming increasingly important in application security. He argues that SAST is a powerful tool for detecting vulnerabilities in software and that modern SAST tools can work at DevOps speed. He makes his case for why he believes SAST will be the ultimate security tool in the future.<br/><br/>Jim also talks about the potential of AI in the field of software security, particularly in the area of auto-remediation for SAST findings. He believes that with good data and models, AI-powered remediation engines could revolutionize the industry.<br/><br/>The episode also delves into threat modeling and its role in software development. The participants discuss the importance of identifying security issues early in the development process and the return on investment (ROI) of threat modeling. Jim emphasizes that threat modeling should focus on identifying issues that static analysis tools cannot easily detect, such as access control vulnerabilities. <br/><br/>They conclude with a discussion on the &quot;shift left&quot; movement in software security and its potential benefits and challenges.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Jim Manico joins Chris, Matt, and Izar at the Security Table for a rousing discussion on his Threat Modeling journey. They also learn about each other&apos;s thoughts about DAST, SAST, SCA, Security in AI, and several other topics. Jim is an educator at heart, and you learn quickly that he loves application security. Jim is not afraid to drop a few controversial opinions and even a rap!<br/><br/>Jim discusses the importance of static application security testing (SAST) and how it is becoming increasingly important in application security. He argues that SAST is a powerful tool for detecting vulnerabilities in software and that modern SAST tools can work at DevOps speed. He makes his case for why he believes SAST will be the ultimate security tool in the future.<br/><br/>Jim also talks about the potential of AI in the field of software security, particularly in the area of auto-remediation for SAST findings. He believes that with good data and models, AI-powered remediation engines could revolutionize the industry.<br/><br/>The episode also delves into threat modeling and its role in software development. The participants discuss the importance of identifying security issues early in the development process and the return on investment (ROI) of threat modeling. Jim emphasizes that threat modeling should focus on identifying issues that static analysis tools cannot easily detect, such as access control vulnerabilities. <br/><br/>They conclude with a discussion on the &quot;shift left&quot; movement in software security and its potential benefits and challenges.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13448546-jim-manico-threat-modeling-the-untold-story.mp3" length="40589518" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13448546</guid>
    <pubDate>Tue, 22 Aug 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13448546/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13448546/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13448546/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13448546/transcript.vtt" type="text/vtt" />
    <itunes:duration>3379</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>25</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Secure by Design</itunes:title>
    <title>Secure by Design</title>
    <itunes:summary><![CDATA["Secure by Design" has garnered attention with the release of a document by CISA. What does it mean? How does it fit with Threat Modeling? And do you know if Secure by Design will answer our need for secure software?  "Secure by Design" means a system is designed with secure principles. The system should come pre-hardened and pre-secured, ensuring users don't have to configure it for security after installation. On the other hand, "Secure by Default" means that the system is configured correc...]]></itunes:summary>
    <description><![CDATA[<p>&quot;Secure by Design&quot; has garnered attention with the release of a document by CISA. What does it mean? How does it fit with Threat Modeling? And do you know if Secure by Design will answer our need for secure software?<br/><br/>&quot;Secure by Design&quot; means a system is designed with secure principles. The system should come pre-hardened and pre-secured, ensuring users don&apos;t have to configure it for security after installation. On the other hand, &quot;Secure by Default&quot; means that the system is configured correctly for security right out of the box.<br/><br/>The hosts explore what it means to be secure by design. Systems can be implemented with security principles rather than relying on users to configure settings post-installation. Matt raises the concept of &quot;de-hardening&quot; guides for compatibility and other situations. But Chris Romeo strongly opposes the idea, fearing it might provide a roadmap for undoing the security measures put in place.<br/><br/>They also discuss how Threat Modeling fits with Secure by Design as a guide at the beginning and in the verification process. The episode concludes with the hosts emphasizing the importance of continuous threat modeling and the need to stay updated with the evolving security landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>&quot;Secure by Design&quot; has garnered attention with the release of a document by CISA. What does it mean? How does it fit with Threat Modeling? And do you know if Secure by Design will answer our need for secure software?<br/><br/>&quot;Secure by Design&quot; means a system is designed with secure principles. The system should come pre-hardened and pre-secured, ensuring users don&apos;t have to configure it for security after installation. On the other hand, &quot;Secure by Default&quot; means that the system is configured correctly for security right out of the box.<br/><br/>The hosts explore what it means to be secure by design. Systems can be implemented with security principles rather than relying on users to configure settings post-installation. Matt raises the concept of &quot;de-hardening&quot; guides for compatibility and other situations. But Chris Romeo strongly opposes the idea, fearing it might provide a roadmap for undoing the security measures put in place.<br/><br/>They also discuss how Threat Modeling fits with Secure by Design as a guide at the beginning and in the verification process. The episode concludes with the hosts emphasizing the importance of continuous threat modeling and the need to stay updated with the evolving security landscape.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13407700-secure-by-design.mp3" length="28447220" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13407700</guid>
    <pubDate>Tue, 15 Aug 2023 00:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13407700/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13407700/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13407700/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13407700/transcript.vtt" type="text/vtt" />
    <itunes:duration>2367</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Champions as the Answer to Engineering Hating Security</itunes:title>
    <title>Security Champions as the Answer to Engineering Hating Security</title>
    <itunes:summary><![CDATA[What happens when engineers transform into security champions? Is this beneficial, and what are the implications of this transformation? Izar reveals his transition from a naysayer to a supporter of security champions, and Chris and Matt seek to understand his current position. They explore the position of Security Champion and discuss the components of a good security champion program.  Matt defines security champions as developers with influence who can be a bridge between security and engi...]]></itunes:summary>
    <description><![CDATA[<p>What happens when engineers transform into security champions? Is this beneficial, and what are the implications of this transformation? Izar reveals his transition from a naysayer to a supporter of security champions, and Chris and Matt seek to understand his current position. They explore the position of Security Champion and discuss the components of a good security champion program.<br/><br/>Matt defines security champions as developers with influence who can be a bridge between security and engineering. They receive advanced training and bring resources to their team to lead them to effective threat modeling. While security champion programs may have potential pitfalls, such as overloading team members, good security champion programs should benefit the individual and the business. Chris emphasizes the importance of providing opportunities for growth, learning, and networking to make the program appealing to potential champions.<br/><br/>With the potential issue of champions leaving an organization, they highlight the need for companies to keep up with salary expectations as champions grow in their roles. They also touch on the challenge of preventing security champions from being disliked by their team once they transition from being developers.<br/><br/>There are several resources for those interested in building a Champions program, including Dustin Lehr&apos;s Security Champion Success Guide and Chris Romeo&apos;s Security Champion Framework available on GitHub.<br/><br/>The episode concludes with a call for listener feedback and input, emphasizing the hosts&apos; desire for an interactive and engaging conversation with their audience.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What happens when engineers transform into security champions? Is this beneficial, and what are the implications of this transformation? Izar reveals his transition from a naysayer to a supporter of security champions, and Chris and Matt seek to understand his current position. They explore the position of Security Champion and discuss the components of a good security champion program.<br/><br/>Matt defines security champions as developers with influence who can be a bridge between security and engineering. They receive advanced training and bring resources to their team to lead them to effective threat modeling. While security champion programs may have potential pitfalls, such as overloading team members, good security champion programs should benefit the individual and the business. Chris emphasizes the importance of providing opportunities for growth, learning, and networking to make the program appealing to potential champions.<br/><br/>With the potential issue of champions leaving an organization, they highlight the need for companies to keep up with salary expectations as champions grow in their roles. They also touch on the challenge of preventing security champions from being disliked by their team once they transition from being developers.<br/><br/>There are several resources for those interested in building a Champions program, including Dustin Lehr&apos;s Security Champion Success Guide and Chris Romeo&apos;s Security Champion Framework available on GitHub.<br/><br/>The episode concludes with a call for listener feedback and input, emphasizing the hosts&apos; desire for an interactive and engaging conversation with their audience.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13326936-security-champions-as-the-answer-to-engineering-hating-security.mp3" length="31647523" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13326936</guid>
    <pubDate>Tue, 01 Aug 2023 12:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13326936/transcript" type="text/html" />
    <itunes:duration>2634</itunes:duration>
    <itunes:keywords>#SecurityChampions</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why Do Engineers Hate Security?</itunes:title>
    <title>Why Do Engineers Hate Security?</title>
    <itunes:summary><![CDATA[There is a relationship between security professionals and engineers. Explore the possibility of engineers disliking security personnel and how security professionals can improve their relationship with engineers.  Security professionals need to be empathetic, have strong soft skills, and be able to influence and embed themselves within the engineering team. Resource management is essential, and avoiding engineers feeling like security is always giving them an over-the-shoulder look.   B...]]></itunes:summary>
    <description><![CDATA[<p>There is a relationship between security professionals and engineers. Explore the possibility of engineers disliking security personnel and how security professionals can improve their relationship with engineers.<br/><br/>Security professionals need to be empathetic, have strong soft skills, and be able to influence and embed themselves within the engineering team. Resource management is essential, and avoiding engineers feeling like security is always giving them an over-the-shoulder look. <br/><br/>Being part of the engineering team and understanding their world is vital to being a security professional that engineers don&apos;t hate. It is challenging to sell security as insurance to engineering leaders who may not see the value in investing time and resources.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>There is a relationship between security professionals and engineers. Explore the possibility of engineers disliking security personnel and how security professionals can improve their relationship with engineers.<br/><br/>Security professionals need to be empathetic, have strong soft skills, and be able to influence and embed themselves within the engineering team. Resource management is essential, and avoiding engineers feeling like security is always giving them an over-the-shoulder look. <br/><br/>Being part of the engineering team and understanding their world is vital to being a security professional that engineers don&apos;t hate. It is challenging to sell security as insurance to engineering leaders who may not see the value in investing time and resources.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13296708-why-do-engineers-hate-security.mp3" length="35662688" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13296708</guid>
    <pubDate>Wed, 26 Jul 2023 17:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13296708/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13296708/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13296708/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13296708/transcript.vtt" type="text/vtt" />
    <itunes:duration>2968</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Posture is a Thing</itunes:title>
    <title>Security Posture is a Thing</title>
    <itunes:summary><![CDATA[What is security posture? Izar was at a conference in Amsterdam, where he was asked to define security posture and how to measure it. Is security posture qualitative or quantitative, and can it be compared across teams, organizations, and departments? This led us down this rabbit hole; what is security posture, and is it even possible to measure? Security posture is multi-dimensional, differentiating between organizational and system security postures. Security activities that are reasonable ...]]></itunes:summary>
    <description><![CDATA[<p>What is security posture? Izar was at a conference in Amsterdam, where he was asked to define security posture and how to measure it. Is security posture qualitative or quantitative, and can it be compared across teams, organizations, and departments? This led us down this rabbit hole; what is security posture, and is it even possible to measure?</p><p>Security posture is multi-dimensional, differentiating between organizational and system security postures. Security activities that are reasonable to a company&apos;s level of risk acceptance are essential. Leadership changes could impact security posture; the departure of a CISO, for example, doesn&apos;t immediately affect the security posture as the policies and experiences built up over time remain.<br/><br/>Tools and processes assess security posture. An organization&apos;s security posture doesn&apos;t necessarily reflect the system&apos;s security posture. You must understand where a design is starting regarding security and where it is now.<br/><br/>The episode concludes with a call to listeners to share their thoughts on security posture and contribute to the ongoing discussion. The hosts express their interest in learning from different perspectives and experiences in security.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What is security posture? Izar was at a conference in Amsterdam, where he was asked to define security posture and how to measure it. Is security posture qualitative or quantitative, and can it be compared across teams, organizations, and departments? This led us down this rabbit hole; what is security posture, and is it even possible to measure?</p><p>Security posture is multi-dimensional, differentiating between organizational and system security postures. Security activities that are reasonable to a company&apos;s level of risk acceptance are essential. Leadership changes could impact security posture; the departure of a CISO, for example, doesn&apos;t immediately affect the security posture as the policies and experiences built up over time remain.<br/><br/>Tools and processes assess security posture. An organization&apos;s security posture doesn&apos;t necessarily reflect the system&apos;s security posture. You must understand where a design is starting regarding security and where it is now.<br/><br/>The episode concludes with a call to listeners to share their thoughts on security posture and contribute to the ongoing discussion. The hosts express their interest in learning from different perspectives and experiences in security.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13241760-security-posture-is-a-thing.mp3" length="32365704" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13241760</guid>
    <pubDate>Mon, 17 Jul 2023 21:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13241760/transcript" type="text/html" />
    <itunes:duration>2694</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Should #AppSec be Part of the Development Team?</itunes:title>
    <title>Should #AppSec be Part of the Development Team?</title>
    <itunes:summary><![CDATA[The big question is if it's possible to lose the application security team and move all the functions directly into development.  What are developers' roles in application security (AppSec), and what challenges do they face?  We delve into developers' responsibility in ensuring security, despite not always having the necessary tools or training to do so effectively.  We discuss "shifting everything left," which refers to integrating security earlier in the development process. We ex...]]></itunes:summary>
    <description><![CDATA[<p>The big question is if it&apos;s possible to lose the application security team and move all the functions directly into development.<br/><br/>What are developers&apos; roles in application security (AppSec), and what challenges do they face?  We delve into developers&apos; responsibility in ensuring security, despite not always having the necessary tools or training to do so effectively. </p><p>We discuss &quot;shifting everything left,&quot; which refers to integrating security earlier in the development process. We express concern that developers are being burdened with increasing responsibility without being given the power or resources to handle it effectively. This is referred to as the &quot;inverse Spider-Man thing&quot; - with great responsibility should come great power, but this isn&apos;t always the case in AppSec.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The big question is if it&apos;s possible to lose the application security team and move all the functions directly into development.<br/><br/>What are developers&apos; roles in application security (AppSec), and what challenges do they face?  We delve into developers&apos; responsibility in ensuring security, despite not always having the necessary tools or training to do so effectively. </p><p>We discuss &quot;shifting everything left,&quot; which refers to integrating security earlier in the development process. We express concern that developers are being burdened with increasing responsibility without being given the power or resources to handle it effectively. This is referred to as the &quot;inverse Spider-Man thing&quot; - with great responsibility should come great power, but this isn&apos;t always the case in AppSec.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13191308-should-appsec-be-part-of-the-development-team.mp3" length="26738873" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13191308</guid>
    <pubDate>Sun, 09 Jul 2023 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13191308/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13191308/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13191308/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13191308/transcript.vtt" type="text/vtt" />
    <itunes:duration>2225</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Lack of Reasonable, or Everything That Is Wrong with Security Requirements</itunes:title>
    <title>Lack of Reasonable, or Everything That Is Wrong with Security Requirements</title>
    <itunes:summary><![CDATA[How do you determine what constitutes "reasonable security" when evaluating vendors? Is “reasonable” a measure of compliance to a set standard? Is it reasonable to expect mature threat modeling practices? Some expectations are too high to be reasonable, but the minimum standard that both parties agree upon doesn’t seem like enough. Join the hosts of the Security Table as they discuss the importance of a reasonable security standard, one that both a vendor and the buyer can agree upon. Izar be...]]></itunes:summary>
    <description><![CDATA[<p>How do you determine what constitutes &quot;reasonable security&quot; when evaluating vendors? Is “reasonable” a measure of compliance to a set standard? Is it reasonable to expect mature threat modeling practices? Some expectations are too high to be reasonable, but the minimum standard that both parties agree upon doesn’t seem like enough.</p><p>Join the hosts of the Security Table as they discuss the importance of a reasonable security standard, one that both a vendor and the buyer can agree upon.</p><p>Izar bemoans the vetting process for software vendors that can be overburdened with paperwork and checkboxes, but still lack confidence in a product’s security. Can we do better? He asks Matt and Chris what information or assurances vendors can reasonably provide to convince buyers that they truly understand and prioritize security.</p><p>Chris proposes evaluating people, process, tools, and governance as a starting point. Matt raises concerns about needing to satisfy the concerns of the end customer and internal teams and leadership. Threat modeling is proposed as a basic starting point. But, is threat modeling just a bare minimum, or is it the reasonable standard both sides of the discussion can be happy with?</p><p>The team discusses the importance of seeing the pipeline of any product being considered. </p><p>What is reasonable? A threat model, documentation of that model, and an invitation to read and ask questions about the described process. The threat model needs to cover what and how software is built, as well as deployment into production. That is enough. That&apos;s reasonable. Is the team’s conclusion reasonable? Listen along, and watch for the upcoming discussion on LinkedIn.</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>How do you determine what constitutes &quot;reasonable security&quot; when evaluating vendors? Is “reasonable” a measure of compliance to a set standard? Is it reasonable to expect mature threat modeling practices? Some expectations are too high to be reasonable, but the minimum standard that both parties agree upon doesn’t seem like enough.</p><p>Join the hosts of the Security Table as they discuss the importance of a reasonable security standard, one that both a vendor and the buyer can agree upon.</p><p>Izar bemoans the vetting process for software vendors that can be overburdened with paperwork and checkboxes, but still lack confidence in a product’s security. Can we do better? He asks Matt and Chris what information or assurances vendors can reasonably provide to convince buyers that they truly understand and prioritize security.</p><p>Chris proposes evaluating people, process, tools, and governance as a starting point. Matt raises concerns about needing to satisfy the concerns of the end customer and internal teams and leadership. Threat modeling is proposed as a basic starting point. But, is threat modeling just a bare minimum, or is it the reasonable standard both sides of the discussion can be happy with?</p><p>The team discusses the importance of seeing the pipeline of any product being considered. </p><p>What is reasonable? A threat model, documentation of that model, and an invitation to read and ask questions about the described process. The threat model needs to cover what and how software is built, as well as deployment into production. That is enough. That&apos;s reasonable. Is the team’s conclusion reasonable? Listen along, and watch for the upcoming discussion on LinkedIn.</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13095743-lack-of-reasonable-or-everything-that-is-wrong-with-security-requirements.mp3" length="24698672" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13095743</guid>
    <pubDate>Thu, 29 Jun 2023 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13095743/transcript" type="text/html" />
    <podcast:soundbite startTime="114.0" duration="42.0" />
    <itunes:duration>2055</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>We Don&#39;t Know What We Don&#39;t Know</itunes:title>
    <title>We Don&#39;t Know What We Don&#39;t Know</title>
    <itunes:summary><![CDATA[Certificate pinning is a security measure used in computer networking and something Chris candidly admits to his lack of understanding. Matt and Izar explain certificate pinning, a client-side operation that adds an extra layer of security to the Transport Layer Security (TLS) protocol and ensures that the client application checks the server's certificate against a known copy of that certificate.  The discussion leads to a reflection on the vast amount of knowledge required in cybersecurity,...]]></itunes:summary>
    <description><![CDATA[<p>Certificate pinning is a security measure used in computer networking and something Chris candidly admits to his lack of understanding.</p><p>Matt and Izar explain certificate pinning, a client-side operation that adds an extra layer of security to the Transport Layer Security (TLS) protocol and ensures that the client application checks the server&apos;s certificate against a known copy of that certificate.<br/><br/>The discussion leads to a reflection on the vast amount of knowledge required in cybersecurity, emphasizing the importance of continuous learning and the willingness to admit and fill gaps in one&apos;s understanding. Engage in further research and discussion, and realize cybersecurity is a &quot;never stop learning&quot; discipline.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Certificate pinning is a security measure used in computer networking and something Chris candidly admits to his lack of understanding.</p><p>Matt and Izar explain certificate pinning, a client-side operation that adds an extra layer of security to the Transport Layer Security (TLS) protocol and ensures that the client application checks the server&apos;s certificate against a known copy of that certificate.<br/><br/>The discussion leads to a reflection on the vast amount of knowledge required in cybersecurity, emphasizing the importance of continuous learning and the willingness to admit and fill gaps in one&apos;s understanding. Engage in further research and discussion, and realize cybersecurity is a &quot;never stop learning&quot; discipline.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13075919-we-don-t-know-what-we-don-t-know.mp3" length="16243065" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13075919</guid>
    <pubDate>Tue, 20 Jun 2023 14:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13075919/transcript" type="text/html" />
    <itunes:duration>1350</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Privacy and the creepiness factor of collecting data</itunes:title>
    <title>Privacy and the creepiness factor of collecting data</title>
    <itunes:summary><![CDATA[What is privacy, and how does it intersect with security? We are joined by our first guest, Ally O'Leary, a privacy compliance expert. Ally works for a consumer electronics company, ensuring compliance with global privacy laws and acting as a data protection officer. The episode delves into the intersection of privacy and security, with Ally explaining how these two areas often go hand in hand. She emphasizes the importance of understanding the definition of personal information and being awa...]]></itunes:summary>
    <description><![CDATA[<p>What is privacy, and how does it intersect with security? We are joined by our first guest, Ally O&apos;Leary, a privacy compliance expert. Ally works for a consumer electronics company, ensuring compliance with global privacy laws and acting as a data protection officer.</p><p>The episode delves into the intersection of privacy and security, with Ally explaining how these two areas often go hand in hand. She emphasizes the importance of understanding the definition of personal information and being aware of where such data is stored within a company&apos;s systems.</p><p>A significant part of the discussion revolves around why security and privacy are two different functions within a company. Ally explains that privacy is a relatively new concept for most companies, often triggered by regulations like the GDPR. She also mentions that privacy often becomes part of the legal function due to the close work with attorneys to interpret laws.</p><p>The conversation also touches on the challenges of data governance and the importance of proper data ownership on the business side. Ally highlights the need for regular reviews of data flows and audits to stay on top of data governance.</p><p>Towards the end of the episode, Ally advises security professionals on when to involve privacy experts in their processes, especially during the development life cycle. She encourages security professionals to notify their privacy colleagues about any projects or initiatives that might impact systems containing personal data.</p><p>Overall, the episode provides valuable insights into the world of privacy compliance, the relationship between privacy and security, and the role of data governance in protecting personal information.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>What is privacy, and how does it intersect with security? We are joined by our first guest, Ally O&apos;Leary, a privacy compliance expert. Ally works for a consumer electronics company, ensuring compliance with global privacy laws and acting as a data protection officer.</p><p>The episode delves into the intersection of privacy and security, with Ally explaining how these two areas often go hand in hand. She emphasizes the importance of understanding the definition of personal information and being aware of where such data is stored within a company&apos;s systems.</p><p>A significant part of the discussion revolves around why security and privacy are two different functions within a company. Ally explains that privacy is a relatively new concept for most companies, often triggered by regulations like the GDPR. She also mentions that privacy often becomes part of the legal function due to the close work with attorneys to interpret laws.</p><p>The conversation also touches on the challenges of data governance and the importance of proper data ownership on the business side. Ally highlights the need for regular reviews of data flows and audits to stay on top of data governance.</p><p>Towards the end of the episode, Ally advises security professionals on when to involve privacy experts in their processes, especially during the development life cycle. She encourages security professionals to notify their privacy colleagues about any projects or initiatives that might impact systems containing personal data.</p><p>Overall, the episode provides valuable insights into the world of privacy compliance, the relationship between privacy and security, and the role of data governance in protecting personal information.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/13025006-privacy-and-the-creepiness-factor-of-collecting-data.mp3" length="34242831" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13025006</guid>
    <pubDate>Mon, 12 Jun 2023 13:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/13025006/transcript" type="text/html" />
    <podcast:soundbite startTime="705.0" duration="60.0" />
    <itunes:duration>2850</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Guardrails and Paved Roads</itunes:title>
    <title>Security Guardrails and Paved Roads</title>
    <itunes:summary><![CDATA[Guard rails and paved roads -- how do they fit together in application security?  Guardrails are security tools in the pipeline that help ensure the software doesn't drift too far from established standards. These guardrails allow developers to maintain their creativity and flexibility while building features that ultimately go to the customer. Paved roads are platforms that developers can build on top of without having to worry about aspects like identity and access management. Paved ro...]]></itunes:summary>
    <description><![CDATA[<p>Guard rails and paved roads -- how do they fit together in application security?  Guardrails are security tools in the pipeline that help ensure the software doesn&apos;t drift too far from established standards. These guardrails allow developers to maintain their creativity and flexibility while building features that ultimately go to the customer.</p><p>Paved roads are platforms that developers can build on top of without having to worry about aspects like identity and access management. Paved roads and guardrails funnel developer activity without breaking their freedom to do what they need to do<br/><br/>Automation is critical in maintaining guardrails and paved roads. Automation allows for the creation of new structures and ensures that existing structures function as expected.<br/><br/>The episode concludes with the hosts expressing their commitment to driving down the paved roads, building more security guardrails, and making everything secure by default.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Guard rails and paved roads -- how do they fit together in application security?  Guardrails are security tools in the pipeline that help ensure the software doesn&apos;t drift too far from established standards. These guardrails allow developers to maintain their creativity and flexibility while building features that ultimately go to the customer.</p><p>Paved roads are platforms that developers can build on top of without having to worry about aspects like identity and access management. Paved roads and guardrails funnel developer activity without breaking their freedom to do what they need to do<br/><br/>Automation is critical in maintaining guardrails and paved roads. Automation allows for the creation of new structures and ensures that existing structures function as expected.<br/><br/>The episode concludes with the hosts expressing their commitment to driving down the paved roads, building more security guardrails, and making everything secure by default.<br/><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12983239-security-guardrails-and-paved-roads.mp3" length="30720851" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12983239</guid>
    <pubDate>Mon, 05 Jun 2023 15:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12983239/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12983239/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12983239/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12983239/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="1200.0" duration="60.0" />
    <itunes:duration>2556</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Capture the Flag or NOT?</itunes:title>
    <title>Capture the Flag or NOT?</title>
    <itunes:summary><![CDATA[There is an overemphasis on Capture The Flag in the security world. Instead, the industry should focus more on the 'builder' perspective to develop robust systems rather than the 'breaker' mindset typically associated with penetration testing and CTF competitions. In addition, we must shift the industry's reward and recognition structures to incentivize building secure-by-design systems.  A CTF is a type of cybersecurity competition where participants solve security-related challenges to find...]]></itunes:summary>
    <description><![CDATA[<p>There is an overemphasis on Capture The Flag in the security world. Instead, the industry should focus more on the &apos;builder&apos; perspective to develop robust systems rather than the &apos;breaker&apos; mindset typically associated with penetration testing and CTF competitions. In addition, we must shift the industry&apos;s reward and recognition structures to incentivize building secure-by-design systems.<br/><br/>A CTF is a type of cybersecurity competition where participants solve security-related challenges to find flags representing vulnerabilities or secrets within a system. A CTF and bug bounty are similar, as both test cybersecurity skills but have different goals and outcomes.</p><p>Red teaming is not just about penetration testing but also about testing the operations of the people who manage defenses. <br/><br/>Finally, the discussion ends with pondering the question of &quot;winning&quot; in cybersecurity and agreeing that providing a system free of defects and ensuring security assurance should be the ultimate goal.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>There is an overemphasis on Capture The Flag in the security world. Instead, the industry should focus more on the &apos;builder&apos; perspective to develop robust systems rather than the &apos;breaker&apos; mindset typically associated with penetration testing and CTF competitions. In addition, we must shift the industry&apos;s reward and recognition structures to incentivize building secure-by-design systems.<br/><br/>A CTF is a type of cybersecurity competition where participants solve security-related challenges to find flags representing vulnerabilities or secrets within a system. A CTF and bug bounty are similar, as both test cybersecurity skills but have different goals and outcomes.</p><p>Red teaming is not just about penetration testing but also about testing the operations of the people who manage defenses. <br/><br/>Finally, the discussion ends with pondering the question of &quot;winning&quot; in cybersecurity and agreeing that providing a system free of defects and ensuring security assurance should be the ultimate goal.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12931268-capture-the-flag-or-not.mp3" length="29827755" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12931268</guid>
    <pubDate>Sat, 27 May 2023 18:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12931268/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12931268/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12931268/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12931268/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="1163.0" duration="60.0" />
    <itunes:duration>2482</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Simple Product Security Requirements</itunes:title>
    <title>Simple Product Security Requirements</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris discuss the United Kingdom's new minimum security standards for all Internet-connected consumer products. They highlight three key aspects of these new standards:  Banning of Universal Default and Easily Guessable Passwords: The hosts agree this is a long-overdue measure, as universal default passwords present a significant security risk. They also touch on challenges such as vendor services requiring default passwords and potential ways to address this, like physical sw...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris discuss the United Kingdom&apos;s new minimum security standards for all Internet-connected consumer products. They highlight three key aspects of these new standards:<br/><br/>Banning of Universal Default and Easily Guessable Passwords: The hosts agree this is a long-overdue measure, as universal default passwords present a significant security risk. They also touch on challenges such as vendor services requiring default passwords and potential ways to address this, like physical switches for privileged access.<br/><br/>Transparency about Security Updates: The hosts discuss the requirement for manufacturers to be clear about how long products will receive security updates. This provision aims to help consumers make better purchasing decisions. In addition, they discuss the challenges it may pose for smaller manufacturers and the potential impact on product pricing.<br/><br/>Vulnerability Reports: The hosts discuss a requirement for manufacturers to respond to bug bounty reports within a reasonable timeframe. They note that many companies need help managing this process effectively and express skepticism about whether this requirement will significantly improve the situation.<br/><br/>While they acknowledge that some of these requirements may challenge smaller companies, the hosts generally see them as a positive step towards better consumer product security.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris discuss the United Kingdom&apos;s new minimum security standards for all Internet-connected consumer products. They highlight three key aspects of these new standards:<br/><br/>Banning of Universal Default and Easily Guessable Passwords: The hosts agree this is a long-overdue measure, as universal default passwords present a significant security risk. They also touch on challenges such as vendor services requiring default passwords and potential ways to address this, like physical switches for privileged access.<br/><br/>Transparency about Security Updates: The hosts discuss the requirement for manufacturers to be clear about how long products will receive security updates. This provision aims to help consumers make better purchasing decisions. In addition, they discuss the challenges it may pose for smaller manufacturers and the potential impact on product pricing.<br/><br/>Vulnerability Reports: The hosts discuss a requirement for manufacturers to respond to bug bounty reports within a reasonable timeframe. They note that many companies need help managing this process effectively and express skepticism about whether this requirement will significantly improve the situation.<br/><br/>While they acknowledge that some of these requirements may challenge smaller companies, the hosts generally see them as a positive step towards better consumer product security.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12878250-simple-product-security-requirements.mp3" length="27462339" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12878250</guid>
    <pubDate>Thu, 18 May 2023 22:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12878250/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12878250/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12878250/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12878250/transcript.vtt" type="text/vtt" />
    <itunes:duration>2285</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Reasonable Software Security: Do We Really Need DAST?</itunes:title>
    <title>Reasonable Software Security: Do We Really Need DAST?</title>
    <itunes:summary><![CDATA[In this episode of the Security Table, the gang discusses reasonable software security. They explore whether current application security tooling, such as dynamic application security testing (DAST), provides a decent return on investment. The group acknowledges that the value of security tools depends on the organization's context and specific needs. They also touch on the importance of understanding a company's risk appetite and how this can inform what is considered reasonable security. Th...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the Security Table, the gang discusses reasonable software security. They explore whether current application security tooling, such as dynamic application security testing (DAST), provides a decent return on investment. The group acknowledges that the value of security tools depends on the organization&apos;s context and specific needs. They also touch on the importance of understanding a company&apos;s risk appetite and how this can inform what is considered reasonable security. The conversation concludes with the idea that reasonable security is not constant but a function with various arguments.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the Security Table, the gang discusses reasonable software security. They explore whether current application security tooling, such as dynamic application security testing (DAST), provides a decent return on investment. The group acknowledges that the value of security tools depends on the organization&apos;s context and specific needs. They also touch on the importance of understanding a company&apos;s risk appetite and how this can inform what is considered reasonable security. The conversation concludes with the idea that reasonable security is not constant but a function with various arguments.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12748343-reasonable-software-security-do-we-really-need-dast.mp3" length="26622588" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12748343</guid>
    <pubDate>Thu, 04 May 2023 08:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12748343/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12748343/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12748343/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12748343/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="120.0" duration="60.0" />
    <itunes:duration>2215</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Final Take on the National Cybersecurity Strategy: Software Liability And Privacy</itunes:title>
    <title>The Final Take on the National Cybersecurity Strategy: Software Liability And Privacy</title>
    <itunes:summary><![CDATA[Chris Romeo, Izar Tarandach, and Matt Coles discuss the national cybersecurity strategy, focusing on pillar three, which aims to shape market forces to drive security and resilience. They explore the idea of liability and the goal of shifting the consequences of poor cybersecurity away from the most vulnerable. The trio also considers the influence of GDPR and its impact on the US, comparing it to the European Union's experience. The podcast hosts discuss the need for better security in IoT d...]]></itunes:summary>
    <description><![CDATA[<p>Chris Romeo, Izar Tarandach, and Matt Coles discuss the national cybersecurity strategy, focusing on pillar three, which aims to shape market forces to drive security and resilience. They explore the idea of liability and the goal of shifting the consequences of poor cybersecurity away from the most vulnerable. The trio also considers the influence of GDPR and its impact on the US, comparing it to the European Union&apos;s experience.</p><p>The podcast hosts discuss the need for better security in IoT devices and the potential impact of the policy on the rest of the world, including China. In addition, they express concern about the potential for a tedious and complex liability process similar to the medical industry, which may not ultimately benefit users.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Chris Romeo, Izar Tarandach, and Matt Coles discuss the national cybersecurity strategy, focusing on pillar three, which aims to shape market forces to drive security and resilience. They explore the idea of liability and the goal of shifting the consequences of poor cybersecurity away from the most vulnerable. The trio also considers the influence of GDPR and its impact on the US, comparing it to the European Union&apos;s experience.</p><p>The podcast hosts discuss the need for better security in IoT devices and the potential impact of the policy on the rest of the world, including China. In addition, they express concern about the potential for a tedious and complex liability process similar to the medical industry, which may not ultimately benefit users.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12733109-the-final-take-on-the-national-cybersecurity-strategy-software-liability-and-privacy.mp3" length="37495651" type="audio/mpeg" />
    <itunes:author>Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12733109</guid>
    <pubDate>Wed, 26 Apr 2023 23:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12733109/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12733109/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12733109/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2094080/12733109/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="503.267" duration="30.0" />
    <itunes:duration>3121</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Convergence of AI in the World of Cybersecurity</itunes:title>
    <title>A Convergence of AI in the World of Cybersecurity</title>
    <itunes:summary><![CDATA[Izar, Matt, and Chris scour the Interwebs for an article to discuss, only to find that each person has chosen an article related to the convergence of AI and cybersecurity. We discuss whether ChatGPT can replace humans with threat modeling, Microsoft's Security Copilot, and the open letter to freeze AI development for six months. AI is the future, and it will significantly impact the security professional's role. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Tabl...]]></itunes:summary>
    <description><![CDATA[<p>Izar, Matt, and Chris scour the Interwebs for an article to discuss, only to find that each person has chosen an article related to the convergence of AI and cybersecurity. We discuss whether ChatGPT can replace humans with threat modeling, Microsoft&apos;s Security Copilot, and the open letter to freeze AI development for six months. AI is the future, and it will significantly impact the security professional&apos;s role.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Izar, Matt, and Chris scour the Interwebs for an article to discuss, only to find that each person has chosen an article related to the convergence of AI and cybersecurity. We discuss whether ChatGPT can replace humans with threat modeling, Microsoft&apos;s Security Copilot, and the open letter to freeze AI development for six months. AI is the future, and it will significantly impact the security professional&apos;s role.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12578087-a-convergence-of-ai-in-the-world-of-cybersecurity.mp3" length="33159207" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12578087</guid>
    <pubDate>Mon, 03 Apr 2023 10:00:00 -0400</pubDate>
    <podcast:soundbite startTime="260.0" duration="60.0" />
    <itunes:duration>2760</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The US National Cybersecurity Strategy -- Pillars One and Two</itunes:title>
    <title>The US National Cybersecurity Strategy -- Pillars One and Two</title>
    <itunes:summary><![CDATA[The Security Table gang continues our discussion about the United States National Cybersecurity Strategy, released in 2023. We cover pillars one and two, defend critical infrastructure, and disrupt and dismantle threat actors.  We talk about the importance of defining critical infrastructure and the responsibility of both the private and public sectors in protecting it. We also mention cybersecurity requirements to support national security and public safety and the challenge of getting vario...]]></itunes:summary>
    <description><![CDATA[<p>The Security Table gang continues our discussion about the United States National Cybersecurity Strategy, released in 2023. We cover pillars one and two, defend critical infrastructure, and disrupt and dismantle threat actors.<br/><br/>We talk about the importance of defining critical infrastructure and the responsibility of both the private and public sectors in protecting it. We also mention cybersecurity requirements to support national security and public safety and the challenge of getting various agencies and organizations to work together. Finally, the hosts ponder whether social media platforms could be considered critical infrastructure, and they conclude that critical infrastructure comes down to safety, security, and public welfare.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The Security Table gang continues our discussion about the United States National Cybersecurity Strategy, released in 2023. We cover pillars one and two, defend critical infrastructure, and disrupt and dismantle threat actors.<br/><br/>We talk about the importance of defining critical infrastructure and the responsibility of both the private and public sectors in protecting it. We also mention cybersecurity requirements to support national security and public safety and the challenge of getting various agencies and organizations to work together. Finally, the hosts ponder whether social media platforms could be considered critical infrastructure, and they conclude that critical infrastructure comes down to safety, security, and public welfare.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12473850-the-us-national-cybersecurity-strategy-pillars-one-and-two.mp3" length="50808786" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12473850</guid>
    <pubDate>Mon, 20 Mar 2023 00:00:00 -0400</pubDate>
    <podcast:soundbite startTime="2431.25" duration="60.0" />
    <itunes:duration>4232</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The US National Cybersecurity Strategy - Introduction - Part One</itunes:title>
    <title>The US National Cybersecurity Strategy - Introduction - Part One</title>
    <itunes:summary><![CDATA[The United States released a new National Cybersecurity Strategy. The gang gathers to discuss the new strategy and look at it from a practitioner's perspective.   We discuss the impact and depth of the malicious actor section, with an increased emphasis on the nation-state and the details shared about nation-state adversaries.  We also get into a debate about a statement made regarding the dependence and need to be placed on the system instead of the end user to make security decisi...]]></itunes:summary>
    <description><![CDATA[<p>The United States released a new National Cybersecurity Strategy. The gang gathers to discuss the new strategy and look at it from a practitioner&apos;s perspective. <br/><br/>We discuss the impact and depth of the malicious actor section, with an increased emphasis on the nation-state and the details shared about nation-state adversaries.  We also get into a debate about a statement made regarding the dependence and need to be placed on the system instead of the end user to make security decisions. Is this strategy a call for big brother disguised as security improvements?<br/><br/>Is the US Government truly responsible for securing the Internet? Discussion and debate ensue.<br/><br/>We vowed to discuss the whole thing, and with this first episode, we got through the introduction. We will continue with additional episodes until we unpack the entire strategy.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The United States released a new National Cybersecurity Strategy. The gang gathers to discuss the new strategy and look at it from a practitioner&apos;s perspective. <br/><br/>We discuss the impact and depth of the malicious actor section, with an increased emphasis on the nation-state and the details shared about nation-state adversaries.  We also get into a debate about a statement made regarding the dependence and need to be placed on the system instead of the end user to make security decisions. Is this strategy a call for big brother disguised as security improvements?<br/><br/>Is the US Government truly responsible for securing the Internet? Discussion and debate ensue.<br/><br/>We vowed to discuss the whole thing, and with this first episode, we got through the introduction. We will continue with additional episodes until we unpack the entire strategy.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12429311-the-us-national-cybersecurity-strategy-introduction-part-one.mp3" length="33236638" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12429311</guid>
    <pubDate>Mon, 13 Mar 2023 09:00:00 -0400</pubDate>
    <itunes:duration>2767</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Application Security, Product Security, and what do we call this thing we do</itunes:title>
    <title>Application Security, Product Security, and what do we call this thing we do</title>
    <itunes:summary><![CDATA[The gang is back to debate and discuss the definition of application security. We start by figuring out what an application is and then layer security on top of it. We branched into how product security fits against application security and eventually concluded that system security is all-encompassing, but it's an old term. We also learn that Izar is uncomfortable speaking about cybersecurity at cocktail parties. Enjoy! FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Securi...]]></itunes:summary>
    <description><![CDATA[<p>The gang is back to debate and discuss the definition of application security. We start by figuring out what an application is and then layer security on top of it. We branched into how product security fits against application security and eventually concluded that system security is all-encompassing, but it&apos;s an old term. We also learn that Izar is uncomfortable speaking about cybersecurity at cocktail parties. Enjoy!</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang is back to debate and discuss the definition of application security. We start by figuring out what an application is and then layer security on top of it. We branched into how product security fits against application security and eventually concluded that system security is all-encompassing, but it&apos;s an old term. We also learn that Izar is uncomfortable speaking about cybersecurity at cocktail parties. Enjoy!</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12378520-application-security-product-security-and-what-do-we-call-this-thing-we-do.mp3" length="37078230" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12378520</guid>
    <pubDate>Sun, 05 Mar 2023 15:00:00 -0500</pubDate>
    <itunes:duration>3087</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Acronyms, Abbreviations, and a slide into Application Security</itunes:title>
    <title>Acronyms, Abbreviations, and a slide into Application Security</title>
    <itunes:summary><![CDATA[Matt, Izar, and Chris started the conversation by discussing all the acronyms and abbreviations we use in security and then morphed into a discussion of what application security is. While they only scratched the surface of what application security is, this episode will make you think about all the acronyms we use in our industry and how they are received by those that are new and outsiders. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: T...]]></itunes:summary>
    <description><![CDATA[<p>Matt, Izar, and Chris started the conversation by discussing all the acronyms and abbreviations we use in security and then morphed into a discussion of what application security is. While they only scratched the surface of what application security is, this episode will make you think about all the acronyms we use in our industry and how they are received by those that are new and outsiders.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>Matt, Izar, and Chris started the conversation by discussing all the acronyms and abbreviations we use in security and then morphed into a discussion of what application security is. While they only scratched the surface of what application security is, this episode will make you think about all the acronyms we use in our industry and how they are received by those that are new and outsiders.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12337896-acronyms-abbreviations-and-a-slide-into-application-security.mp3" length="29588164" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12337896</guid>
    <pubDate>Mon, 27 Feb 2023 12:00:00 -0500</pubDate>
    <itunes:duration>2463</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security talent conclusion, from the candidates viewpoint</itunes:title>
    <title>Security talent conclusion, from the candidates viewpoint</title>
    <itunes:summary><![CDATA[The gang continues our discussion and debate around the security talent shortage. We consider the issue from the candidate's viewpoint this time, thinking about all the different things candidates have to deal with in being hired, from years of experience, certification, and depth of the interview process. We try to draw some actionable conclusions for hiring managers because, without action, we are just part of the problem. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The S...]]></itunes:summary>
    <description><![CDATA[<p>The gang continues our discussion and debate around the security talent shortage. We consider the issue from the candidate&apos;s viewpoint this time, thinking about all the different things candidates have to deal with in being hired, from years of experience, certification, and depth of the interview process. We try to draw some actionable conclusions for hiring managers because, without action, we are just part of the problem.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang continues our discussion and debate around the security talent shortage. We consider the issue from the candidate&apos;s viewpoint this time, thinking about all the different things candidates have to deal with in being hired, from years of experience, certification, and depth of the interview process. We try to draw some actionable conclusions for hiring managers because, without action, we are just part of the problem.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12250197-security-talent-conclusion-from-the-candidates-viewpoint.mp3" length="29385892" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12250197</guid>
    <pubDate>Tue, 14 Feb 2023 09:00:00 -0500</pubDate>
    <itunes:duration>2446</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security talent shortage — fact or fiction</itunes:title>
    <title>Security talent shortage — fact or fiction</title>
    <itunes:summary><![CDATA[The gang considers whether the security talent shortage is fact or fiction. We've all hired people for security roles at different places and have heard about this "shortage" for years. We discuss the role of the business in building strong apprenticeship programs and the efforts of academia to prepare people for these roles. We don't resolve everything that needs resolution, so we'll be back with part two next week on this same topic.  Show notes: https://www.prnewswire.com/news-releases/des...]]></itunes:summary>
    <description><![CDATA[<p>The gang considers whether the security talent shortage is fact or fiction. We&apos;ve all hired people for security roles at different places and have heard about this &quot;shortage&quot; for years. We discuss the role of the business in building strong apprenticeship programs and the efforts of academia to prepare people for these roles. We don&apos;t resolve everything that needs resolution, so we&apos;ll be back with part two next week on this same topic.<br/><br/>Show notes:</p><ul><li>https://www.prnewswire.com/news-releases/despite-slowing-economy-demand-for-cybersecurity-workers-remains-strong-301730414.html</li><li><a href='https://accesscyber.co/blog/10000-cybersecurity-jobs'>https://accesscyber.co/blog/10000-cybersecurity-jobs</a></li></ul><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang considers whether the security talent shortage is fact or fiction. We&apos;ve all hired people for security roles at different places and have heard about this &quot;shortage&quot; for years. We discuss the role of the business in building strong apprenticeship programs and the efforts of academia to prepare people for these roles. We don&apos;t resolve everything that needs resolution, so we&apos;ll be back with part two next week on this same topic.<br/><br/>Show notes:</p><ul><li>https://www.prnewswire.com/news-releases/despite-slowing-economy-demand-for-cybersecurity-workers-remains-strong-301730414.html</li><li><a href='https://accesscyber.co/blog/10000-cybersecurity-jobs'>https://accesscyber.co/blog/10000-cybersecurity-jobs</a></li></ul><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12203404-security-talent-shortage-fact-or-fiction.mp3" length="30547019" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12203404</guid>
    <pubDate>Tue, 07 Feb 2023 12:00:00 -0500</pubDate>
    <itunes:duration>2543</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Lastpass and the Security of Security Products</itunes:title>
    <title>Lastpass and the Security of Security Products</title>
    <itunes:summary><![CDATA[The gang discusses the Lastpass breach and the need for the security of utility-style security providers. We discuss Lastpass from a different angle - the responsibility of "hard security" providers.   As security practitioners, we have been telling users to "just use a password manager." So what do we do now? How do password managers impact the way we give advice? Lastpass is as "hard security" service as it can be - are security people taking things as seriously as they should? Are we ...]]></itunes:summary>
    <description><![CDATA[<p>The gang discusses the Lastpass breach and the need for the security of utility-style security providers. We discuss Lastpass from a different angle - the responsibility of &quot;hard security&quot; providers. <br/><br/>As security practitioners, we have been telling users to &quot;just use a password manager.&quot; So what do we do now? How do password managers impact the way we give advice?</p><p>Lastpass is as &quot;hard security&quot; service as it can be - are security people taking things as seriously as they should? Are we too &quot;here&apos;s your two months of credit policing, thank you very much&quot; accommodated? We explore and reach some conclusions.</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang discusses the Lastpass breach and the need for the security of utility-style security providers. We discuss Lastpass from a different angle - the responsibility of &quot;hard security&quot; providers. <br/><br/>As security practitioners, we have been telling users to &quot;just use a password manager.&quot; So what do we do now? How do password managers impact the way we give advice?</p><p>Lastpass is as &quot;hard security&quot; service as it can be - are security people taking things as seriously as they should? Are we too &quot;here&apos;s your two months of credit policing, thank you very much&quot; accommodated? We explore and reach some conclusions.</p><p><br/></p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/12041838-lastpass-and-the-security-of-security-products.mp3" length="42887063" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12041838</guid>
    <pubDate>Sat, 14 Jan 2023 09:00:00 -0500</pubDate>
    <podcast:soundbite startTime="1620.0" duration="60.0" />
    <itunes:duration>3572</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Software bill of materials -- what is it good for?</itunes:title>
    <title>Software bill of materials -- what is it good for?</title>
    <itunes:summary><![CDATA[The gang considers the software bill of materials (SBOM) approach and asks hard questions about what SBOM is for and whether it improves security. Note the gang believes in SBOM. We ask the hard questions to help us all expand our minds and truly understand the value propositions. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening! ]]></itunes:summary>
    <description><![CDATA[<p>The gang considers the software bill of materials (SBOM) approach and asks hard questions about what SBOM is for and whether it improves security. Note the gang believes in SBOM. We ask the hard questions to help us all expand our minds and truly understand the value propositions.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang considers the software bill of materials (SBOM) approach and asks hard questions about what SBOM is for and whether it improves security. Note the gang believes in SBOM. We ask the hard questions to help us all expand our minds and truly understand the value propositions.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/11966085-software-bill-of-materials-what-is-it-good-for.mp3" length="38010114" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11966085</guid>
    <pubDate>Mon, 02 Jan 2023 14:00:00 -0500</pubDate>
    <itunes:duration>3165</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Should security give up on developers?</itunes:title>
    <title>Should security give up on developers?</title>
    <itunes:summary><![CDATA[The gang discusses whether security should or could give up on developers. We explore what the development world would look like if security did all the security, and the developer's responsibility ended when they committed a PR. Conclusions are eventually reached. FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for Listening! ]]></itunes:summary>
    <description><![CDATA[<p>The gang discusses whether security should or could give up on developers. We explore what the development world would look like if security did all the security, and the developer&apos;s responsibility ended when they committed a PR. Conclusions are eventually reached.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>The gang discusses whether security should or could give up on developers. We explore what the development world would look like if security did all the security, and the developer&apos;s responsibility ended when they committed a PR. Conclusions are eventually reached.</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/11885088-should-security-give-up-on-developers.mp3" length="35178521" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11885088</guid>
    <pubDate>Fri, 16 Dec 2022 12:00:00 -0500</pubDate>
    <itunes:duration>2929</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security tools and the companies that make them</itunes:title>
    <title>Security tools and the companies that make them</title>
    <itunes:summary><![CDATA[In the inaugural episode of the Security Table, the gang discusses Mark Curphey's article, "A Security Tools Crash Is Coming." We consider the four conditions Mark describes, and then we riff on what it means for the security world in 2023. We also uncover several debates that will resurface in upcoming episodes, such as SBOM: what is it really for? FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @SecTablePodcast ➜LinkedIn: The Security Table Podcast ➜YouTube: The Security Table YouTube Channel Thanks for...]]></itunes:summary>
    <description><![CDATA[<p>In the inaugural episode of the Security Table, the gang discusses Mark Curphey&apos;s article, &quot;<a href='https://www.linkedin.com/pulse/security-tools-crash-coming-mark-curphey/'>A Security Tools Crash Is Coming</a>.&quot; We consider the four conditions Mark describes, and then we riff on what it means for the security world in 2023. We also uncover several debates that will resurface in upcoming episodes, such as SBOM: what is it really for?</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></description>
    <content:encoded><![CDATA[<p>In the inaugural episode of the Security Table, the gang discusses Mark Curphey&apos;s article, &quot;<a href='https://www.linkedin.com/pulse/security-tools-crash-coming-mark-curphey/'>A Security Tools Crash Is Coming</a>.&quot; We consider the four conditions Mark describes, and then we riff on what it means for the security world in 2023. We also uncover several debates that will resurface in upcoming episodes, such as SBOM: what is it really for?</p><p>FOLLOW OUR SOCIAL MEDIA:</p><p>➜Twitter: <a href='https://twitter.com/SecTablePodcast'>@SecTablePodcast</a><br/>➜LinkedIn:<a href='https://www.linkedin.com/showcase/83990241'> </a><a href='https://www.linkedin.com/company/the-security-table-podcast/'>The Security Table Podcast</a><br/>➜YouTube: <a href='https://www.youtube.com/channel/UCLodR5gtnVo0e8PAtwcr4Lg'>The Security Table YouTube Channel</a></p><p>Thanks for Listening!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2094080/episodes/11850580-security-tools-and-the-companies-that-make-them.mp3" length="38177501" type="audio/mpeg" />
    <itunes:author>Tania Ward, Izar Tarandach, Matt Coles, and Chris Romeo</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11850580</guid>
    <pubDate>Sun, 11 Dec 2022 10:00:00 -0500</pubDate>
    <itunes:duration>3179</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
