Cultivating Security

Cultivating Security

Cultivating Security

Episodes 18
Avg. Duration 21m
Activity Highly Active
Since Dec 2025
Latest Episode Mar 2026

Publishing Details

Schedule
Weekly
Format
Episodic
Consistency
72%
Hosting
cultivatingsecurity.com

Contact & Outreach

About This Podcast

Deep examinations of industry incidents, vendor risk, and operational security decisions from 25+ years in the field. AI-narrated episodes transform written analysis into practical insights for security professionals who need to understand what really happens when security meets operational reality. No certifications required, just real-world experience.

Podcasting 2.0 Features

funding license medium podping txt updateFrequency

Explore Statistics

Recent Episodes

Week 12: Incident Response Is Half Politics

Mar 24, 2026 21m

You’ve planned for incidents. You have a documented incident response plan. You’ve done tabletop exercises. Your team knows their roles. You have runbooks for common scenarios. Then an actual…

Week 11: When ‘Best Practices’ Don’t Apply

Mar 17, 2026 19m

Every security framework, every certification course, every vendor white paper tells you what you should do. Implement least privilege. Segment your network. Patch within 30 days. Enforce MFA…

Week 10: Compliance Is Not Security (But You Still Have to Care)

Mar 10, 2026 17m

Every security person eventually has this realization: passing the audit doesn’t mean you’re secure. You can check every box in the compliance framework. You can get your SOC 2 certification. You…

Week 9: Reading the Room: What Your CISO Actually Cares About

Mar 03, 2026 17m

If you’re trying to get security work done, you need to understand what your leadership cares about. And I mean actually cares about, not what they say in all-hands meetings or what’s in the security…

Week 8: Why Security Projects Fail (And It’s Usually Not Technical)

Feb 24, 2026 20m

You’ve probably seen this: a security initiative that makes perfect technical sense, that addresses real risk, that has clear value—and it dies anyway. Not because the technology doesn’t work. Not…

Week 7: Reporting to IT: How to Build Security When You’re Not in Charge

Feb 17, 2026 25m

A lot of security people find themselves in this position: you’re the security person, or the security team, reporting up through IT leadership that didn’t come up through security. Maybe your…

Week 6: Vendor Relationships Aren’t Partnerships (No Matter What the Sales Deck Says)

Feb 10, 2026 28m

Every vendor will tell you they’re committed to security. They take it very seriously. They’re a trusted partner in your security journey. They understand your challenges and they’re here to…

Week 5: The Identity Sprawl Problem

Feb 03, 2026 31m

Identity used to be simple. Users had accounts. Accounts had passwords. You managed them in Active Directory or LDAP. Authentication happened at the perimeter, and once you were inside, you were…

Why Chat-Based AI Tools Fail in Operational Security: Building Capability vs. Productivity

Jan 28, 2026 29m

AI as Capability, Not Conversation: Why Chat-Based Tools Fail Operational Security Work In the last 18 months, every vendor has suddenly “integrated AI” into their products. Your SIEM has AI now.…

Week 4: The Logging and Visibility Problem No One Mentions

Jan 27, 2026 22m

You probably think you can see more than you actually can. That’s not a criticism—it’s just how modern environments work. The assumptions we built our mental models on (servers you own, networks…

Week 3: Fort Knox Isn’t the Goal: Learning to Live with Imperfect Security

Jan 20, 2026 19m

Here’s something nobody tells you when you’re starting out: your job is not to eliminate risk. I know that sounds wrong. You got into security because you care about protecting things. You see the…

Week 2: Understanding Your Environment Before You Try to Secure It

Jan 13, 2026 19m

You can’t protect what you don’t know exists. That should be obvious. But based on how most security programs operate, it apparently isn’t. People want to jump straight to the interesting work.…

Week 1: Introduction: Foundations That Nobody Teaches

Jan 06, 2026 8m

There’s a gap in how people learn security work. Not a small one. You can get certified six ways from Sunday. You can read every framework document NIST ever published. You can know the OWASP Top…

When Your Vendor Drops a Security Layer (And Doesn’t Tell You)

Dec 24, 2025 19m

Back in November, there was a piece on KrebsOnSecurity about the Cloudflare outage — particularly companies that chose to bypass Cloudflare entirely to get their services back online. I wrote an…

Security Third: Why “Security First” Makes Organizations Less Secure

Dec 13, 2025 44m

I heard something on a podcast the other day that’s been rattling around in my head ever since. The hosts were talking about Mike Rowe’s “Safety Third” concept — the idea that safety matters, sure,…

The Marquis Breach: What Happens When Your Vendor’s Security is Worse Than You Think

Dec 08, 2025 37m

I was winding down my workday last week when one of my analysts posted a link in our team chat—another BleepingComputer article about a data breach. This one was different, though. Marquis Software…

Willful Ignorance as a Security Vulnerability

Dec 03, 2025 15m

Saturday evening. Long day of side projects and farm work. The corporate work week was done, but I’d been grinding through accounting, blog writing, development work—all the side-business stuff that…

Why Now? What 15 Years of Security Work Taught Me

Dec 02, 2025 15m

Why I’m Writing This For the past few months, I’ve been writing more formal internal analysis pieces – breaking down incidents I see in threat intel feeds, public breach notifications, security…

Frequently Asked Questions

How many episodes does Cultivating Security have?

Cultivating Security has published 18 episodes since December 2025, covering topics in Business, Management.

Is Cultivating Security still active?

Cultivating Security is currently highly active with new episodes weekly. Average episode length is 21m.

How do I contact Cultivating Security for sponsorship or guest appearances?

Sign up on Grep.FM to access contact details for Cultivating Security, including email and social media links.

Similar Podcasts