Skip to content
Artwork for The Cybersecurity Podcast
TechnologyEducationCourses

The Cybersecurity Podcast

EC-Council

Welcome to The Cybersecurity Podcast by EC-Council, where those shaping the future of cybersecurity take the center stage. 

Created to raise awareness & spark meaningful dialogue about cybersecurity, this podcast dives into the stories, behaviors, and first-hand experiences that shape our digital world. 

Hosted by EC-Council Group President Jay Bavisi, each episode unpacks not just what’s happening in cybersecurity, but why it matters to all of us. 

From ethical hacking to social engineering, cyber policy to personal journeys, this podcast brings together leaders, practitioners, and individuals shaping the industry for conversations that are bold, insightful, & impossible to ignore.  

Get fresh and exclusive perspectives, insights, and stories straight from the experts shaping cybersecurity today.   

Whether you're a practitioner, a policymaker, or just cyber-curious, this is your front-row seat to real talk from those on the frontlines. 

Play
  • 6 episodes
  • monthly
  • Avg 34 min
  • English
  • September 24 · 37 min

    She Convinced the Pentagon to Get Hacked: Katie Moussouris on Bug Bounties in the AI Era

    For more than 20 years, organizations have argued about whether to let hackers into their systems. Katie Moussouris helped settle that argument. In Episode 17 of The Cybersecurity Podcast, host Jay Bavisi talks with Katie Moussouris, founder and CEO of Luta Security. She created Microsoft's first bug bounty program, convinced the Pentagon to launch Hack the Pentagon, and helped develop the ISO standards for vulnerability disclosure. Katie explains how she sold Microsoft on paying hackers. She also tells the inside story of how Hack the Pentagon launched with a total budget of about $150K. Then she looks at how AI is changing vulnerability research. It is flooding bug bounty programs with "AI slop" and duplicate reports, and it makes elite researchers even more effective. She also warns about government "buggy banks," makes the case for open-weight models as defensive tools, and says why organizations still need to hire interns even when AI can do their jobs.

    • Transcript
  • August 19 · 50 min

    The Man Who Invented the SBOM: Allan Friedman on Software Transparency

    Every candy bar comes with a list of ingredients. Most software doesn't — and that gap is quietly one of the biggest risks in cybersecurity. Jay Bavisi sits down with Dr. Allan Friedman, senior advisor at CISA, professor at Indiana University, and the man widely credited as the father of the Software Bill of Materials (SBOM), to unpack why software transparency has become a global compliance issue almost overnight. They cover why SolarWinds — the attack that put supply chain security on the map — actually wouldn't have been stopped by an SBOM, the WannaCry story that exposed how little hospitals knew about their own medical devices, how the EU's Cyber Resilience Act and PCI DSS are forcing vendors to disclose what's in their code, VEX and the difference between "vulnerable" and "exploitable," and what happens to software risk once AI starts writing most of the code. A candid, wide-ranging conversation on trust, transparency, and the messy politics of getting an entire industry to agree on what "secure software" actually means.

    • Transcript
  • July 13 · 39 min

    Truth, Transparency, and a Subpoena: Inside TikTok's Security Crisis with Roland Cloutier

    Roland Cloutier spent years as ByteDance/TikTok's Chief Security Officer during one of the most scrutinized periods any security leader has faced — congressional hearings, Senate testimony, and an international ban, all while protecting a platform used by over 3 billion people. In this conversation with host Jay Bavisi, Roland traces his path from military combat security and federal law enforcement into cybersecurity, and unpacks what it actually takes to lead through that kind of pressure. The conversation covers the mindset shift CISOs need to stop absorbing blame and start operating as business leaders; his "command staff" approach to building resilient, cross-trained security teams; and a breakdown of the three distinct jobs a CISO now holds in the AI era, enabling the business to use AI, defending against AI-driven attacks, and using AI to run security operations better. Roland also gets candid about what it was really like preparing for and sitting through Senate and congressional testimony, how he separated geopolitics from genuine security concerns, the personal toll, sleep, health, a full year of sustained pressure — and the one career decision he'd take back.

    • Transcript
  • June 11 · 29 min

    The Business of Ransomware: How Attacks Are Planned and Negotiated- Part 1

    What really happens after a ransomware attack? In this episode of The Cybersecurity Podcast by EC-Council, host Jay Bavisi is joined by  Kurtis Minder, a ransomware negotiator and cyber intelligence expert who works deep within the ransomware ecosystem. After spending years studying and engaging with ransomware groups, building #human intelligence #networks, and supporting organizations during live ransomware incidents, he shares how ransomware actually works beyond headlines, assumptions, and surface-level narratives. This episode covers: How ransomware groups are structured and why they operate like businesses What negotiation conversations with attackers actually look like Why ransomware negotiations often take weeks, not hours The growing role of automation and ai in ransomware operations Double extortion, data leaks, and scenarios where negotiations break down Learn more about the firsthand stories from Kurtis’s early negotiations, cases that went wrong, and why understanding attacker motivation plays a critical role in effective cyber defense. This episode offers a practical, experience-led perspective on ransomware shaped by real incidents, real decisions, and real consequences faced by organizations under attack.

    • Transcript
  • June 11 · 29 min

    The Business of Ransomware: How Attacks Are Planned and Negotiated- Part 2

    What really unfolds once a ransomware attack hits? In this episode of The Cybersecurity podcast by EC-Council, host Jay Bavisi sits down with Kurtis Minder — a ransomware negotiator and cyber intelligence specialist who operates inside the ransomware underground. With years of experience observing, engaging, and negotiating with ransomware #groups, building human intelligence networks, and guiding organizations through active attacks, Kurtis reveals how ransomware truly works. This episode explores: - How ransomware gangs are organized and why they run like companies - What real ransom negotiations sound like behind closed doors - Why these talks often last weeks instead of hours - How automation and #ai are reshaping ransomware campaigns - What happens when double extortion and data leaks come into play - You’ll also hear stories from Kurtis’s earliest negotiations, incidents that went off track, and why understanding attacker psychology is essential to defending against cybercrime. This episode delivers an insider’s view of ransomware, built on real-world incidents, hard decisions, and the realities organizations face under pressure.

    • Transcript
  • June 8 · 19 min

    Jay Bavisi on AI, Cybersecurity, and the HUGE Talent Gap (RSA 2026)

    Artificial intelligence is evolving at an unprecedented pace—but is cybersecurity keeping up? In this exclusive interview from RSA 2026, Amber Pedroncelli sits down with Jay Bavisi (CEO of EC-Council) to break down the biggest challenges facing cybersecurity leaders today. From AI adoption to governance gaps, the conversation reveals why organizations may be moving faster than they can securely manage. 💡 𝗞𝗲𝘆 𝗶𝗻𝘀𝗶𝗴𝗵𝘁𝘀 𝗳𝗿𝗼𝗺 𝘁𝗵𝗶𝘀 𝗶𝗻𝘁𝗲𝗿𝘃𝗶𝗲𝘄: • Why AI is outpacing cybersecurity frameworks • The shocking stat: only 18% of major companies have AI governance in place • How CISOs are being “steamrolled” by rapid AI adoption • The growing AI cybersecurity talent gap • Why some jobs will disappear—but many new roles will be created • The biggest risks: prompt injection, data poisoning, and AI attacks • Introducing the ADG Framework: Adopt, Defend, Govern 🚀 As AI reshapes industries, cybersecurity professionals must adapt quickly—or risk falling behind. This discussion explores what organizations must do now to secure the future of AI. 👤 𝗔𝗯𝗼𝘂𝘁 𝘁𝗵𝗲 𝗦𝗽𝗲𝗮𝗸𝗲𝗿 Jay Bavisi is the CEO of EC-Council and a global leader in cybersecurity education and workforce development.

    • Transcript
Showing 1–6 of 6 episodes