Legitimate Cybersecurity Podcasts

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.
Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.
Episodes
Episodes



Apr 10, 2026
Why Is LinkedIn Spying on Your Browser?
Apr 10, 2026
Apr 10, 2026
28 min
A new lawsuit alleges LinkedIn may have been collecting data from inside users’ browsers in ways most people never expected.If that is true, this is not just normal tracking. It is a much more invasive look into how websites can profile you behind the scenes.In this episode of Legitimate Cybersecurity, Frank Downs and Dustin Brewer break down the class-action allegations against LinkedIn, explain browser extension detection in plain English, and talk about why so many people are fed up with paying for platforms that still treat their identity like a product. They also walk through what this kind of tracking could reveal about you, why regulation keeps falling behind, and what everyday users can do right now to limit exposure online.📩 Media/interview: admin@legitimatecybersecurity.com🎧 Audio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 LinkedIn is spying on you?00:37 What this new lawsuit actually alleges01:34 Why this one feels different03:32 Why people are so fed up with LinkedIn06:04 What websites can already learn about you08:23 How browser extension detection works10:13 Why this feels so invasive14:51 What you can do to protect yourself18:11 Browser vs app: which gives companies more access?20:46 Consent, ethics, and hidden tracking26:56 Will regulation ever catch up?28:15 Final thoughts#linkedin #privacy #BrowserTracking #cybersecurity #dataprivacy #onlinetracking #surveillance #digitalprivacy #technews #legitimatecybersecurity
Apr 10, 2026
28 min



Apr 4, 2026
What’s Inside the White House App?
Apr 4, 2026
Apr 4, 2026
38 min
You expect a government app to inform you. You probably do not expect tracking capability, mystery dependencies, and sloppy security decisions.This episode breaks down why the White House app is a warning sign for anyone who installs “official” software without asking what it can really do.Frank Downs and Dustin Brewer dig into the White House app as a real-world case study in mobile privacy, dormant GPS functionality, third-party code dependencies, digital supply-chain risk, and the uncomfortable question of who is actually accountable when insecure software gets released.This is not just about one app. It is about the broader problem with modern software: hidden permissions, weak development practices, and the false assumption that “official” means secure.If you use apps from governments, brands, schools, banks, or anyone else you assume you can trust, this episode will make you think twice about what is really happening in the background.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Hosted by Frank Downs and Dustin Brewer on Legitimate Cybersecurity.Chapters:00:00 – Why this app matters00:50 – The White House app and dormant GPS capability02:47 – Why “it’s off for now” is not reassuring07:47 – Real-world GPS tracking through everyday apps10:06 – Why taxpayers should care about this one11:35 – Random dependencies and supply-chain risk14:05 – How software supply-chain attacks really happen18:35 – Incompetence vs malicious intent24:47 – Leftover dev tools, WordPress, and security basics27:46 – Who is actually accountable?32:49 – Cybersecurity is a mindset, not a checkbox36:18 – Which frameworks help and which get gamed39:34 – Listener shout-outs and close#cybersecurity #appsecurity #dataprivacy #mobilesecurity #supplychainsecurity #privacy #WhiteHouseApp #infosec #LegitimateCybersecurity
Apr 4, 2026
38 min



Apr 1, 2026
Apr 1, 2026
45 min
AI is being forced into the tools you use every day before most companies have written real rules.That matters because one careless prompt can become a privacy, compliance, or job-risk problem fast.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Walter Haydock to break down what happens when AI shows up in Word, email, HR systems, search, and business workflows before organizations are actually ready for it.They unpack where companies get AI adoption wrong, why “just use it” is dangerous guidance, what accountability should look like, and how frameworks like ISO 42001 and the NIST AI RMF help organizations build rules before the damage is done. They also dig into AI hiring risks, shadow AI, risky models, and why some AI features feel more like forced adoption than useful innovation.If you’ve ever wondered whether AI is helping your company or quietly creating legal, privacy, and security risk, this episode is for you.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Subscribe for more conversations with Frank Downs and Dustin Brewer as they translate the hidden systems shaping everyday technology.Chapters:00:00 AI is suddenly in your tools01:14 Meet Walter Haydock02:41 Every company needs AI rules04:42 Why gray areas become risk05:38 Advice for less technical businesses09:44 ISO 42001 vs. NIST AI RMF12:44 Who should own AI accountability?14:24 AI in hiring and HR20:50 Why bias never fully disappears27:29 Will the U.S. regulate AI?30:27 Where AI is being overused38:27 Shadow AI and risky models43:10 What StackAware does44:23 Walter’s best advice#artificialintelligence #aigovernance #cybersecurity #privacy #compliance #shadowai #iso42001 #nist #techrisks #legitimatecybersecurity
Apr 1, 2026
45 min



Mar 20, 2026
AI Is Replacing Tech Jobs With Insecure Code
Mar 20, 2026
Mar 20, 2026
44 min
AI is starting to replace parts of white-collar work faster than most people realize.The bigger problem is that it may also flood the market with insecure code, weaker judgment, and fewer real entry-level paths.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down Anthropic’s latest report on the jobs most exposed to AI and explain what the headlines are getting wrong.They dig into the difference between AI exposure and actual job loss, why the data may be skewed toward technical users, and why roles like programmers, analysts, support specialists, and customer service reps are being hit first. They also tackle the deeper issue: if AI keeps making it easier for inexperienced people to ship software, are we about to create a massive wave of insecure code?This is not just a conversation about automation. It is a conversation about who still needs human judgment, where experience still matters, and why “efficiency” can quietly become a security problem.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/#cybersecurity #artificialintelligence #techjobs #softwaredevelopment #jobmarket #anthropic #automation #infosec #legitimatecybersecurity
Mar 20, 2026
44 min



Mar 13, 2026
Your TV Is Recording What You Watch
Mar 13, 2026
Mar 13, 2026
30 min
Your smart TV may be taking snapshots of what you watch, even when you think you bypassed the built-in apps.That data can be used to identify shows, measure advertisements, and help build a profile of behavior inside your home.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer explain how Automatic Content Recognition (ACR) works, why HDMI devices like Apple TV or gaming consoles may not stop it, and how companies correlate TV viewing with other data sources.They also break down why opting out can be difficult, how these systems are used for ad measurement and profiling, and what steps viewers can take right now to reduce the tracking.If you own a smart TV, streaming device, or connected home system, this episode explains what is actually happening behind the screen.📩 Media and interview inquiries:admin@legitimatecybersecurity.com🎧 Listen to the audio podcast:https://legitimatecybersecurity.podbean.com/Chapters:00:00 — Your TV Is Watching You Back00:45 — What Automatic Content Recognition Actually Is01:25 — How TVs Identify What You Watch02:13 — Why HDMI Devices Do Not Stop It05:25 — How Viewing Data Gets Linked to Your Phone09:59 — Why Opting Out Is So Difficult11:37 — Cameras, Microphones, and Smart Device Monitoring18:51 — What You Can Do to Reduce Tracking20:22 — VPNs, DNS Blocking, and Practical Limits26:33 — The Real Takeaway: Every Screen Collects Data#cybersecurity#privacy#smarttv#dataprivacy#surveillance#smarthome#technology#streaming#legitimatecybersecurity
Mar 13, 2026
30 min



Mar 7, 2026
After the Breach, the Legal Crisis Begins
Mar 7, 2026
Mar 7, 2026
45 min
A cyber incident is not just a technical problem. The legal response can shape what happens next, what gets disclosed, and how much worse the damage becomes.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Kate Hanniford, cybersecurity and data privacy partner at Alston & Bird, to unpack the part of cyber incidents most people overlook: the legal side.Kate explains what really happens when the phone rings after a breach, how executives think under pressure, where regulators draw the line between bad luck and negligence, and why data retention can quietly become one of the biggest risks in an investigation. They also dig into SEC disclosure rules, outdated regulations, AI adoption risk, and the growing sophistication of state and federal regulators.This is a grounded look at what actually breaks after a cyber incident — and why the legal response matters just as much as the technical one.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/#cybersecurity #dataprivacy #incidentresponse #breachresponse #compliance #aigovernance #riskmanagement #legitimatecybersecurityChapters:00:00 Cyber incidents are legal incidents too00:36 Meet Kate Hanniford01:12 How Kate got into cybersecurity law05:30 How lawyers specialize in cyber08:34 What the first breach call feels like12:32 How technical a cyber lawyer has to be14:45 Which regulators worry companies most18:47 Bad luck vs negligence in cybersecurity19:57 Why data retention becomes a legal problem22:17 The SEC four-day disclosure rule27:43 Are cyber regulations outdated?32:43 Which frameworks actually inspire confidence?35:28 Does AI create more legal risk?39:20 The fast question round44:36 Kate’s best life advice#Cybersecurity#DataPrivacy#IncidentResponse#BreachResponse#Compliance#SEC#AIGovernance#RiskManagement#PrivacyLaw
Mar 7, 2026
45 min



Mar 3, 2026
Mar 3, 2026
50 min
America’s cyber “first responder” isn’t the FBI anymore—it’s private companies.That shift changes what gets prioritized during a breach: mission vs. margin, attribution vs. recovery, and who gets help first.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Milan Patel (Global Head of MDR at BlueVoyant, former FBI) to unpack what breaks when cyber defense gets outsourced—because it already has. Milan shares how the FBI actually works in real incidents, why private-sector response dominates, and the recurring failures that keep breaches happening “the same way, with a different cut of sushi.”You’ll learn:Why the private sector responds first ~95% of the time—and what the FBI really does when they arriveThe 3 root causes Milan sees behind most breaches (and why they don’t go away)The hidden risk of “unknown, unprotected” network branches and configuration driftWhat AI will (and won’t) replace in MDR, SOC work, and incident responseThe real looming problem: training the next generation when Level 1 work gets automatedWhy AI agents inside your environment force a rethink of identity + data access controlsMedia / interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/If you want weekly breakdowns of the hidden systems shaping security (and the incentives nobody admits out loud), subscribe and join the conversation in the comments.Chapters:0:00 Cold open: “The FBI used to be the frontline…”0:55 Meet Milan Patel: FBI → private sector MDR2:30 “How do I get into cyber?” Milan’s origin story6:50 The FBI hiring gauntlet (and why honesty wins)11:35 Quantico + the “blind monkey” field office lottery14:05 “Too bad, you’re going cyber” (how cyber squads really looked back then)17:35 The big shift: who responds first during breaches (and why)20:10 Why companies don’t care about “catching the bad guy” mid-crisis22:55 The same breaches keep happening—what people aren’t learning23:30 Milan’s “3 causes” of most breaches: culture, funding, configuration26:10 The generational gap in clicking, trust, and risk behavior29:10 “What security do I even need?” (coverage vs. cost reality check)31:15 The brutal truth: validating what’s actually deployed vs. what you think is deployed33:00 AI in cybersecurity: what’s real vs. hype34:35 “Don’t make me talk to a robot” — the last-mile human requirement36:10 The coming SOC shift: fewer Level 1s, more “all Level 3” teams37:25 The pipeline problem: how do juniors learn when grunt work is automated?38:40 Vibe coding + security: why Milan’s confidence is rising (with guardrails)44:10 AI arms race: faster attackers, same fundamentals46:05 AI agents in your network = identity + data access crisis49:00 Milan’s one life rule: “Focus on your sphere of influence”49:40 Outro + “keep on cyberin’”#cybersecurity #incidentresponse #fbi #manageddetectionandresponse #ransomware #cybercrime #aisecurity #SOC #cyberrisk #infosec #legitimatecybersecurity
Mar 3, 2026
50 min



Feb 23, 2026
AI Is Rewriting Compliance (GRC)
Feb 23, 2026
Feb 23, 2026
36 min
Compliance isn’t “paperwork”—it’s the last line between your customers and the next Equifax-level mess.But GRC teams are stuck chasing screenshots and questionnaires instead of reducing real risk—and AI is about to change that.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Richa Kaul, CEO & Founder of Compliance (an AI-native enterprise GRC platform), right after her company’s $20M raise led by Google Ventures.We dig into:Why GRC gets hated (and how to stop being the “business blocker”)What real AI in compliance looks like vs. “LLM sticker on legacy software”The uncomfortable truth: audits shouldn’t disappear—and why incentives matterHow to reduce hallucination risk with tight inputs/outputs + guardrailsThird-party risk management (TPRM): the questionnaire nightmare… and the path outMedia/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 – Compliance is the job (and also… you wanted to be an astronaut)01:20 – Meet Richa Kaul + the “privacy nut” origin story02:11 – $20M from Google Ventures: why GRC is getting real investment02:52 – Quick GRC explainer (governance, risk, compliance)03:35 – “Compliance is broken”: why everyone hates the process04:49 – The real pain: chasing evidence vs. reducing risk07:00 – What “AI-powered” actually means (and why most vendors are faking it)09:31 – Force multipliers: where AI should increase capability, not just save time11:25 – Completeness problem: you can’t protect what you don’t know exists13:09 – Example: encryption checks → automation + AI completeness/accuracy criteria15:58 – The future: continuous monitoring, audits, and what should change17:24 – Why audits shouldn’t go away (incentives + independence)20:07 – Gatekeeping, CMMC, and “audit industry” friction23:58 – TPRM hell: questionnaires, insurance, and repetitive evidence requests27:05 – Why Richa cares: privacy, consumer harm, and the mission behind GRC28:46 – Equifax as the “spark” (without breach-shaming)31:52 – Hallucinations: how to build AI you can trust in compliance workflows35:24 – “Do you use compliance to ensure compliance?” (dogfooding)36:00 – Outro: “Keep on cyberin’”#GRC #Compliance #Cybersecurity #AI #RiskManagement #Audit #ThirdPartyRisk #DataPrivacy #Governance #securityculture #legitimatecybersecurity
Feb 23, 2026
36 min






