Byte Sized Security Titelbild

Byte Sized Security

Byte Sized Security

Von: Marc David
Jetzt kostenlos hören, ohne Abo

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.Copyright 2026 Marc David Management & Leadership Politik & Regierungen Ökonomie
  • Ep47: Why AI Risks Are Different
    Sep 19 2026
    Episode Summary:Someone told Marc that AI panic is nothing new — just the printing press or nuclear weapons all over again. He disagreed, and it turns out there was a report to back it up. In this episode he breaks down why AI collapses the cost of dangerous capability in a way the printing press, the internet, and even nuclear weapons never did, what Anthropic's brand-new September 2026 threat intelligence report documents, where his own "$200 expert" framing overstated the case, and the four guardrails that would close the gap.Key Topics Covered:The argument that started this episode — a debate about whether AI panic is history repeating, and the report Marc found three days later making his case for himWhy the printing press comparison breaks down — institutions had a century (and decades, for the internet) to catch up; AI's capability curve moves in monthsWhat's actually different about nuclear weapons — nuclear risk lives behind physical choke points: materials, facilities, expertise. AI risk lives in a skill, and skills can't be fenced offAnthropic's report: the receipts — three disrupted operations, walked through case by case, that turn the argument from speculative to documentedDoes AI make anyone an expert? Not exactly — Marc's own "$200 subscription = expert" line, and the more defensible version of the claimAttackers, defenders, and who adapts faster — the same models cutting attacker costs are cutting defender costs too, and why that race mattersWhat real AI guardrails would look like — four concrete guardrails: pre/post-release capability testing, enforceable standards, international coordination, and risk-scaled accessMain Takeaways:AI doesn't need generations to reach scale like the printing press or the internet did — model capability jumps happen every few months, not every few decadesNuclear risk is contained by physical choke points (fissile material, facilities, expertise); AI risk lives in a skill, and skills don't have a border to fenceAnthropic's September 2026 report documents real, disrupted operations — including a breach that went from one stolen developer token to full cloud admin control in roughly three hours"$200 subscription = expert" overstates it: AI doesn't manufacture expertise, it lowers the skill required to attempt tasks whose consequences the operator isn't trained to handleDefenders get the same acceleration attackers do — the organizations lagging on AI-assisted defense are the ones absorbing the most riskClosing the gap takes four things: pre/post-release capability testing, enforceable (not voluntary) standards, international coordination, and access that scales with risk instead of priceTimestamps:[0:00] The argument behind this episode[1:03] Why the printing press comparison breaks down[1:53] What's different about nuclear weapons[2:55] Anthropic's report: the receipts[4:46] Does AI make anyone an expert? Not exactly[5:45] Attackers, defenders, and who adapts faster[6:16] What real AI guardrails would look likeTools & Resources Mentioned:Anthropic: Detecting and Countering Misuse of AI (September 2026)NIST AI Risk Management FrameworkEU AI Act (European Commission)Full written guide: Why AI Risks Are DifferentAI is fueling the cybersecurity career boomWhy an AI agent shouldn't inherit your permissionsNot legal advice. Figures reflect Anthropic's report as published on September 10, 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Mehr anzeigen Weniger anzeigen
    9 Min.
  • Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited
    Sep 10 2026

    Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.

    In this episode:

    • (00:00) The scan report that isn't as urgent as it looks
    • (01:03) The 98.5% number and the mechanic analogy
    • (02:01) Why the industry defaulted to patch everything
    • (03:00) The 36-hour outage from a perfect-10 patch
    • (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
    • (05:08) What it sounds like when someone understands this in an interview
    • (06:15) Why the industry has no brakes, and the AI-hype myth
    • (07:49) Your homework

    Links:

    • Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing"
    • CISA's Known Exploited Vulnerabilities (KEV) catalog
    • FIRST.org, the CVSS specification
    • Full written breakdown
    • Our cybersecurity career guide
    • Breaking into cybersecurity with no experience
    • Third-party risk and the AI bug-report flood

    Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.

    I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Mehr anzeigen Weniger anzeigen
    10 Min.
  • Ep45: Fired for Failing a Phishing Test? What Binance Actually Does
    Jul 28 2026
    Episode Summary:Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.Key Topics Covered:What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who failsCan you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offenseHow corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)"Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc landsAccountability without a blame culture — four principles for getting Binance's seriousness without the fearThe boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patternsMain Takeaways:You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone ownedPunishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incidentThe metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudlyHumans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the personFair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or reportTimestamps:[0:00] The gotcha that shows up on your performance review[1:03] What Binance's red team is actually doing[2:23] Can you really get fired? Three strikes and the Krebs debate[3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder[5:03] "Weakest link"? The industry split, and where we land[6:55] Accountability without a blame culture: four principles[8:19] The boring middle thing that actually worksTools & Resources Mentioned:Binance runs monthly phishing tests (crypto.news)Repeated failures may lead to dismissal (WEEX)Addressing the repeat phishing offender (IT Brew)"Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)What to do (and not do) when employees click (Hook Security)What's a good phishing failure rate? (Hoxhunt benchmarks)KnowBe4 phishing security testProofpoint phishing simulationMicrosoft Defender attack simulation trainingFull written article: Fired for failing a phishing test?Why modern phishing beats smart peopleWhy employee security awareness training mattersGeneral education, not legal or HR advice. Reporting reflects coverage as of July 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Mehr anzeigen Weniger anzeigen
    11 Min.
adbl_web_anon_alc_button_suppression_t1
Noch keine Rezensionen vorhanden