Folgen

  • Hack Responsibly Episode 07: From IT Support to Red Team Lead
    Jun 24 2026

    In this episode of Hack Responsibly, host Karl Fosaaen sits down with Giles Inkson, Director of Red Team Operations NetSPI, for a candid conversation about the winding path into offensive security, and what it actually looks like to do this work at a high level today.

    Giles covers a lot of ground: getting started in security, exploring AI use cases for red teaming, and navigating an industry that's shifted dramatically from stronger EDR, federated identity, SaaS sprawl, to a security culture that's finally starting to catch up.

    In this episode:

    • How curiosity (and some questionable game cheats) led to a career in red teaming
    • Building and experimenting with AI-assisted offense
    • Living off the land: why built-in OS tools still win
    • The engagement that went from default credentials to domain admin
    • Favorite tools, books, cons, and why sleep is a non-negotiable
    Mehr anzeigen Weniger anzeigen
    43 Min.
  • Hack Responsibly Episode 06: Testing at the Speed of Attackers
    May 20 2026

    In this episode of Hack Responsibly, Karl Fossen talks to James Albany, NetSPI’s Senior Director of Network Pentesting, about his path from a SOC analyst to a penetration testing leader. They cover how AI and continuous testing are reshaping the security industry, what common gaps still show up in assessments, and what James is up to outside of work.

    What’s discussed:

    • Advice for newcomers: understand the fundamentals so you can gut-check what AI is doing well versus poorly
    • The shift from point-in-time assessments to continuous testing programs and why clients are increasingly asking for it
    • AI's role in security testing, including generating Nuclei templates and accelerating vulnerability discovery, and when traditional automation is still the better choice
    • The "fire hose effect" of AI tools like Mythos compressing timelines for vulnerability discovery, proof-of-concept development, and remediation
    • Underrepresented topics in security: SCCM/deployment server risks, Linux and Kubernetes environments, and supply chain security
    • Common gaps still showing up in assessments, including Active Directory and application-level vulnerabilities that network scanners miss
    • TFTP and PXE booting as surprisingly persistent and effective attack vectors
    Mehr anzeigen Weniger anzeigen
    35 Min.
  • Hack Responsibly Episode 05: Proactive Cloud Security: Mitigate Real Risks
    Mar 20 2026

    In this episode of Hack Responsibly, Karl Fossen chats with Thomas Elling, NetSPI’s Director of Cloud Pentesting, about today’s cloud security challenges. They dive into cloud pentesting tips and common misconfigurations, discussing how attackers take advantage of these gaps. Thomas also shares his own path into cybersecurity. Listen to practical advice for newcomers, and a look at why staying curious and adaptable matters for anyone tackling today’s evolving threats.

    We dive into:

    • Strategic cloud adoption and layered security
    • Mitigating high-impact cloud vulnerabilities
    • The threat of attack chaining
    • Cultivating a resilience security culture
    Mehr anzeigen Weniger anzeigen
    30 Min.
  • Hack Responsibly Episode 04: From Blue Team to Pentesting - Tools, Tales, and Techniques
    Feb 23 2026

    In this episode, host Karl Fosaaen sits down with Paul Ryan, Senior Director of Application Security at NetSPI, to explore his journey in cybersecurity and his leadership in application pentesting. Paul shares how his career evolved from IT and blue team roles to becoming a key figure in application security at NetSPI.

    We dive into:

    • The evolution of application pentesting, including the rise of APIs and AI in security testing.
    • Paul’s favorite tools and techniques, including the importance of checklists for consistency and quality.
    • Advice for aspiring cybersecurity professionals: "Follow your passions."
    • Memorable pentesting engagements, from formula injection debates to creative vulnerability discoveries.
    • Paul’s love for hacker culture, including his favorite movie, Sneakers, and his passion for tinkering with old tech.
    Mehr anzeigen Weniger anzeigen
    30 Min.
  • Hack Responsibly Episode 03: The Hidden Risk in Legacy Infrastructure
    Jan 7 2026

    For many enterprise organizations (particularly in financial services and healthcare) mainframes remain the backbone of daily operations. Yet, these critical legacy systems often operate under a false assumption of "security by obscurity." Overlooking the security of these core assets represents a significant, often unaddressed, operational risk.

    In this episode of the Hack Responsibly podcast, NetSPI VP of Research Karl Fosaaen connects with Phil Young, NetSPI Director of Mainframe Pentesting. Known in the industry as "Soldier of Fortran," Phil is a leading authority on mainframe security. Together, they dismantle the myth that legacy infrastructure is immune to modern threats and discuss why specialized testing is essential for business continuity.

    Mehr anzeigen Weniger anzeigen
    38 Min.
  • Hack Responsibly Episode 02: Securing the AI Frontier
    Jan 7 2026

    The adoption of artificial intelligence and large language models (LLMs) presents a significant opportunity for business innovation, but also introduces a new and complex attack surfaces. Balancing the drive for AI integration with robust security measures is essential for long-term strategic success and risk mitigation.

    In this episode of the Hack Responsibly podcast, NetSPI VP of Research Karl Fosaaen speaks with Kim Wiles, Director of AI Penetration Testing, about the unique security challenges posed by emerging AI technologies.

    Mehr anzeigen Weniger anzeigen
    27 Min.
  • Hack Responsibly Episode 01: Inside the Mind of a Social Engineer
    Jan 7 2026

    A single human error can compromise even the most robust technical infrastructure. For executives and security leaders, understanding the psychology behind these breaches is critical to protecting organizational assets.

    In the first episode of the Hack Responsibly podcast, host and NetSPI VP of Research Karl Fosaaen talked with Patrick Sayler about dissecting the evolving landscape of social engineering. This discussion moves beyond simple phishing definitions to explore the sophisticated tactics threat actors use to bypass advanced security controls, from multi-factor authentication (MFA) fatigue to AI-driven deception.

    This episode offers high-level insights into how social engineering impacts your risk posture and what proactive measures you can take to align your security initiatives with business continuity goals.

    Mehr anzeigen Weniger anzeigen
    47 Min.