Byte Sized Security Titelbild

Byte Sized Security

Byte Sized Security

Von: Marc David
Jetzt kostenlos hören, ohne Abo

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.Copyright 2026 Marc David Management & Leadership Politik & Regierungen Ökonomie
  • Ep45: Fired for Failing a Phishing Test? What Binance Actually Does
    Jul 28 2026
    Episode Summary:Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.Key Topics Covered:What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who failsCan you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offenseHow corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)"Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc landsAccountability without a blame culture — four principles for getting Binance's seriousness without the fearThe boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patternsMain Takeaways:You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone ownedPunishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incidentThe metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudlyHumans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the personFair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or reportTimestamps:[0:00] The gotcha that shows up on your performance review[1:03] What Binance's red team is actually doing[2:23] Can you really get fired? Three strikes and the Krebs debate[3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder[5:03] "Weakest link"? The industry split, and where we land[6:55] Accountability without a blame culture: four principles[8:19] The boring middle thing that actually worksTools & Resources Mentioned:Binance runs monthly phishing tests (crypto.news)Repeated failures may lead to dismissal (WEEX)Addressing the repeat phishing offender (IT Brew)"Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)What to do (and not do) when employees click (Hook Security)What's a good phishing failure rate? (Hoxhunt benchmarks)KnowBe4 phishing security testProofpoint phishing simulationMicrosoft Defender attack simulation trainingFull written article: Fired for failing a phishing test?Why modern phishing beats smart peopleWhy employee security awareness training mattersGeneral education, not legal or HR advice. Reporting reflects coverage as of July 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Mehr anzeigen Weniger anzeigen
    11 Min.
  • Ep44: California's DROP Tool: Delete Yourself From Data Brokers in One Free Request
    Jul 22 2026
    Episode Summary:California just made deleting yourself from data brokers a single free request. In this episode Marc breaks down the state's new DROP tool: what it deletes, how to file it in a few minutes, why August 1, 2026 is the date that matters, and the three things it won't fix. If you're a California resident, this is a free privacy win you shouldn't skip. If you're not, he covers what to do instead.Key Topics Covered:What DROP is — California's Delete Request and Opt-out Platform, and where the 614 data broker number comes fromHow it works — one free request, and what it actually deletes across registered brokersFiling it step by step — a few minutes of work, plus the scam to watch out forThe August 1, 2026 deadline — why that's the date brokers have to start honoring requestsThe honest limits — what DROP won't fix: Google, Meta, and brokers that re-collect your dataNot in California? — the moves that get you similar protection without DROPMain Takeaways:DROP lets California residents delete themselves from every registered data broker (614 and counting) with a single free request — no per-broker opt-outsAugust 1, 2026 is the date that matters: that's when brokers must start honoring DROP deletion requestsIt's not a silver bullet — it won't remove you from Google or Meta, and brokers can re-collect your data over time, so treat it as maintenance, not a one-and-doneWatch for the scam: the only official place to file is the state's own site — don't pay a third party to do what's freeNot a California resident? Freeze your credit and use manual opt-outs or a removal service to get similar coverageTimestamps:[0:00] The 12-broker breaking point[1:10] What DROP is and where the 614 number comes from[2:05] How it works and what it actually deletes[3:40] Filing it step by step, plus the scam to avoid[4:46] Why August 1, 2026 is the deadline[5:19] The honest limits: Google, Meta, and recurring brokers[6:51] Not in California? Do this insteadTools & Resources Mentioned:File a DROP request (official)California Privacy Protection AgencyCalifornia Delete Act (SB 362)EFF: What You Need to Know About California's DROP ToolFull written guide: California's DROP tool & data broker opt-outHow consent laundering moves your dataRemove your personal info from the internetCredit freezes & identity protectionNot legal advice. Details reflect the tool as of July 2026; enforcement begins August 1, 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Mehr anzeigen Weniger anzeigen
    10 Min.
  • Ep43: The Best Personality Traits for Working in Cybersecurity
    Jun 1 2026

    Episode Summary:

    A Reddit thread on r/cybersecurity asked a simple question: what's the best personality trait for working in cyber? The answers — with hundreds of upvotes — weren't about hacking or certifications. They were about curiosity, patience, humility, staying calm under pressure, and empathy. Marc walks through each trait with personal stories from 8+ years of building teams, hiring, and working incidents at 2 AM.

    Key Topics Covered:

    • Curiosity — the #1 answer by a wide margin; the trait that makes you dig into a log line everyone else shrugs off
    • Patience — explaining technical risk to non-technical people without making them feel stupid, because if you do, they stop reporting incidents
    • Humility — saying "I don't know, but I'll figure it out" beats bluffing every time; ego is the worst trait in the field
    • Calm under pressure — incident response at 2 AM, zero-days on Friday afternoons, breaches that keep growing; staying focused when everything is on fire matters more than any cert
    • Empathy and kindness — cybersecurity is a people problem wrapped in a technology problem; being technically right doesn't matter if nobody wants to work with you
    • The uncomfortable truth — ADHD, burnout, trauma-induced hypervigilance; the always-on mindset is a strength until it isn't

    Main Takeaways:

    • Technical skills are trainable — tools, frameworks, scripting languages, detection logic are all learnable, especially with AI
    • Soft traits like curiosity, patience, and empathy are harder to develop and are what separate people everyone wants on their team from people nobody wants to work with
    • If you're thinking about getting into cybersecurity, don't ask "am I technical enough?" — ask "am I curious enough to keep learning?"
    • The best cybersecurity professionals aren't the ones who sprint the hardest — they're the ones still there in five years

    Timestamps:

    • [0:00] Introduction — the Reddit thread that started it all
    • [0:58] Curiosity — the #1 answer and why it matters
    • [2:41] Patience — the art of explaining things without condescension
    • [3:58] Humility — why "I don't know" is a superpower
    • [5:15] Calm under pressure — the difference between a skill and a warning sign
    • [6:28] Empathy and kindness — the most surprising and important trait
    • [7:49] The uncomfortable part — burnout, ADHD, and mental health in cyber
    • [9:11] Final thoughts — what really separates the best from the rest

    Tools & Resources Mentioned:

    • Reddit Thread: Best Personality Type/Traits for Working in Cyber

    ---

    I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Mehr anzeigen Weniger anzeigen
    12 Min.
adbl_web_anon_alc_button_suppression_t1
Noch keine Rezensionen vorhanden