Skip to content
Artwork for Cyber All Day
TechnologyBusinessExplicit

Cyber All Day

Michael VIRGONE

Cybersecurity Podcast

Play
  • 7 episodes
  • weekly
  • Avg 37 min
  • English
  • #6
    Thursday · 40 min

    Helping AI agents understand what secure means for your business #06

    Second part of my conversation with Erlend OFTEDAL - AppSec and AI security researcher. CHAPTERS (01:23) - DORA state report (link below), improved delivery throughput, but also increased delivery stability (05:25) - Planning stage: shifting the focus from attacks to defensive code and security principles (09:03) - Teaching AI agents to write more secure code is sort of the same thing as teaching developers to write more secure code (12:08) - Planning stage: the typing was never the bottleneck. The thinking was (15:45) - With AI writing code, how do you bring security into the development process? (20:29) - Security team being able to ask AI how secure the code is (22:38) - What we need to do right now + AppSec and AI agents (27:21) - Choose the right AI agent for the right purpose (e.g. Claude vs Opengrep) (32:03) - Leverage AI to analyse legacy code to find vulnerabilities, Firefox example, etc. (38:22) - Last words LINK MENTIONED 2025 DORA State of AI-assisted Software Development report: https://cloud.google.com/resources/content/2025-dora-ai-assisted-software-development-report GUEST Erlend OFTEDAL- AppSec and AI security researcher LinkedIn: https://www.linkedin.com/in/erlendoftedal/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • #5
    September 9 · 36 min

    As AI writes more of the code. What about security? #05

    First part of my conversation with Erlend OFTEDAL- AppSec and AI security researcher. CHAPTERS (01:04) - How is the role of the developers changing with the increase of code developed by AI (04:17) - AI gives you more options, makes us more productive + some benefits of AI (building quick app) (06:33) - Example of containing the agents, the two-sided problems to contain the agents (trust vs agency of the AIs) (09:49) - If we have bad practices in the company, AI as an amplifier, would amplify those (14:15) - You can fake competency, Stack Overflow rankings, code on GitHub (18:04) - Automating social engineering, the agents creating GitHub users playing the long game (21:26) - Proprietary code and AI & how it changes the developers’ job developing proprietary code (26:29) - Will we have new open-source frameworks in the future and what will they look like (31:02) - About old languages like COBOL & the bigger picture (34:02) - Another use of AI, finding and fixing low-severity bugs LINK MENTIONED 2025 DORA State of AI-assisted Software Development report: https://cloud.google.com/resources/content/2025-dora-ai-assisted-software-development-report GUEST Erlend OFTEDAL- AppSec and AI security researcher LinkedIn: https://www.linkedin.com/in/erlendoftedal/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • #4
    September 2 · 50 min

    Measuring what matters in a SOC #04

    Second part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment. CHAPTERS (01:28) - Why Dave hates Mean Time to Detect (MTTD) (07:00) - Why SOCs need to measure the quality of their data and signals (13:01) - Confirmation rates + and why the math often doesn't add up (18:00) - It’s very difficult to measure quality, but it’s very valuable + an example (19:29) - Example: how to define the metrics that actually matter to your organisation (23:41) - Mean Time to Respond (MTTR) - and why the number doesn't necessarily inspire confidence (32:06) - Why SOC severity levels need business context (35:28) - Making sure your SOC understands what is actually critical to the business (39:09) - Example of business criticality (41:09) - The importance of having a key operational contact inside the business (43:34) - One of his big measures of quality: how many tickets had to be sent back for validation (47:06) - Not many people understand what a SOC actually is GUEST Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment LinkedIn: https://www.linkedin.com/in/davewmckenzie/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • #3
    August 24 · 49 min

    MSSP SOC reporting has a metrics problem #03

    First part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment. CHAPTERS (00:00) - In this episode & intro (01:20) - Dave’s introduction (04:34) - Dave jokes that he “tortures” vendors for a living (07:47) - The story behind his talk at Security BSides London, “You Scored 46” - and why SOC metrics matter (12:34) - For the purposes of his talk, he went to AI and asked for a monthly service delivery report + scope + inventory (15:57) - AI averages the internet, vendor claims & pure filler slides (17:00) - The industry doesn't know how to measure SOC performance: MSSP economics & honesty (24:30) - Those monthly service delivery meetings should be more about what is happening rather than the stats (30:29) - Goodhart’s Law: when metrics create the behaviour you want to avoid (33:28) - The MSSP value paradox: they want to bring value, but it's good to have “boring customers” too (38:59) - Why we need to keep clarifying the terminology: alerts, incidents & events (42:52) - What is even an incident? It depends who you ask: security vs data incidents GUEST Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment LinkedIn: https://www.linkedin.com/in/davewmckenzie/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • #2
    August 17 · 38 min

    What is wrong with cybersecurity marketing #02

    Second part of my conversation with Samantha SWIFT, Chief Marketing Officer at Cyberr and Heelr, Conference Organizer of multiple BSides events, with a background in global threat response. CHAPTERS (02:24) - A lot of teams in cybersecurity marketing hire great marketing people who know absolutely bugger all about cybersecurity (04:29) - The problems with absolutes (09:08) - Product claims and their limitations (what works on paper vs. what actually works) (11:25) - Sam's thoughts: “I think authentic is the word I always want to go with” (14:12) - Being honest about where a product isn't strong enough (including walking away from a deal) (18:24) - The balance between what you say you do, what you actually do and what somebody actually needs (21:25) - Building products with a finite amount of engineering resources (customer requests, roadmaps and validating ideas) (24:42) - The information candidates give away during interviews (CVs, LinkedIn, background and what they reveal) (27:13) - Speaking to people on the ground (customers, Gong transcripts and cybersecurity events) (28:09) - The value of cybersecurity events for marketing, product and sales (B-Sides, grassroots events vs. RSA and Black Hat) (30:00) - Talking to people outside your product bubble (red team, offensive security, SOC, etc.) (31:44) - Fake companies and fake jobs (35:58) - Sam's 2020 example: when she halted a product release because it wasn't ready (37:13) - The importance of speaking to people more (getting outside the vendor bubble) (37:59) - The message to remember: stop saying absolutes, don't scare people, authenticity matters GUEST Samantha SWIFT, Chief Marketing Officer at Cyberr and Heelr LinkedIn: https://www.linkedin.com/in/safesecs/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • #1
    August 17 · 38 min

    A real-world deepfake job applicant #01

    First part of my conversation with Samantha SWIFT, Chief Marketing Officer at Cyberr and Heelr, Conference Organizer of multiple BSides events, with a background in global threat response. CHAPTERS (03:06) - Real-life example: the deepfake job applicant. What happened during the interview (05:21) - Why a deepfake may be used for a job interview (salary differences, subcontracting, etc.) (07:47) - This candidate looked great on paper (CV, LinkedIn, job description, covering email) (08:36) - The red flags that started to add up (new LinkedIn profile, Romania, skills and experience) (10:32) - The Romanian language odd situation. The candidate didn't want to switch languages (15:15) - Deepfakes getting better and cheaper (16:30) - How attackers can prepare for interviews with AI (research, LinkedIn, prompts) (19:03) - In this particular situation, the technology wasn't the problem, it was the preparation (21:19) - How to mitigate the risk (job descriptions, identity verification, etc.) (26:02) - The information candidates give away (CVs, LinkedIn, previous employers, etc.) (31:44) - Fake companies and fake jobs (35:31) - Sam's message, and as the technology gets better: what can companies actually do GUEST Samantha SWIFT, Chief Marketing Officer at Cyberr and Heelr LinkedIn: https://www.linkedin.com/in/safesecs/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

  • August 13 · 6 min

    Welcome to Cyber All Day #00

    A short introduction to Cyber All Day: who I am, what the podcast is about, why I created it, and why I follow a two-conversation format. CHAPTERS (00:00) - Introduction to Cyber All Day (00:27) - About me and how I approach the podcast (01:51) - What is Cyber All Day about? (02:26) - The two-episode format and how I approach conversations (04:30) - The vibe, where to find the podcast, and timestamps (05:54) - Outro GUEST None - Episode 0 HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.

Showing 1–7 of 7 episodes