<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[STATUS: SECURE – The Cyber Threat Briefing]]></title><description><![CDATA[<p><b>You cannot be secure if you do not know the threat.</b></p><p>On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy.</p><p>Welcome to <b>Status: Secure</b>, the weekly cyber threat briefing for executives who refuse to operate in the blind.</p><p>Hosted by the <b>WatchUr6</b> collective, this show unites the battlefield with the boardroom. Featuring former <b>Army Special Forces</b> and <b>Naval Special Warfare</b> communications operators alongside an industry-leading CISO nominated for <b>Cybersecurity Woman of the World</b>.</p><p>Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure.</p><p>The enemy is listening. <b>Is your status secure?</b></p>]]></description><link>www.watchur6.com/podcast</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Thu, 28 May 2026 14:28:44 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/2z3crnzL.rss" rel="self" type="application/rss+xml"/><author><![CDATA[WatchUr6 - Cybersecurity]]></author><pubDate>Mon, 26 Jan 2026 21:49:00 GMT</pubDate><copyright><![CDATA[2026 WatchUr6 - Cybersecurity]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Management]]></category><category><![CDATA[Technology]]></category><itunes:author>WatchUr6 - Cybersecurity</itunes:author><itunes:summary>&lt;p&gt;&lt;b&gt;You cannot be secure if you do not know the threat.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On the battlefield, the ability to communicate securely isn&apos;t a &quot;nice to have&quot;—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy.&lt;/p&gt;&lt;p&gt;Welcome to &lt;b&gt;Status: Secure&lt;/b&gt;, the weekly cyber threat briefing for executives who refuse to operate in the blind.&lt;/p&gt;&lt;p&gt;Hosted by the &lt;b&gt;WatchUr6&lt;/b&gt; collective, this show unites the battlefield with the boardroom. Featuring former &lt;b&gt;Army Special Forces&lt;/b&gt; and &lt;b&gt;Naval Special Warfare&lt;/b&gt; communications operators alongside an industry-leading CISO nominated for &lt;b&gt;Cybersecurity Woman of the World&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure.&lt;/p&gt;&lt;p&gt;The enemy is listening. &lt;b&gt;Is your status secure?&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>WatchUr6 - Cybersecurity</itunes:name><itunes:email>swanester@gmail.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"><itunes:category text="Management"/></itunes:category><itunes:category text="Technology"/><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><item><title><![CDATA[016 PE and VC Funds Are Now Liable for Portfolio Cyber Breaches: The PowerSchool Case Study]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If you write the check without verifying what is in the codebase, you lose the fund.</p><p></p><p>In this episode we are analyzing the federal court ruling that rewired cybersecurity due diligence for the entire investment community.</p><p></p><p>On March 18, 2026, a California federal judge allowed class action claims against Bain Capital to proceed for a data breach at PowerSchool that occurred before Bain acquired the company. The acquirer is now legally on the hook for the seller's pre-close cybersecurity failures. Every PE partner, VC general partner, family office principal, and corporate development executive deploying capital in 2026 just got a new precedent. The era of "verify SOC 2 and move on" is over.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li>[00:00] The March 2026 Ruling That Rewired Cyber Diligence: How one federal court decision made the acquirer legally responsible for the seller's pre-acquisition cybersecurity failures.</li><li>[01:39] The PowerSchool Case Walkthrough: 60 million students, 10 million teachers, stolen vendor credentials, and a ShinyHunters ransom demand two months after close.</li><li>[08:26] Why Financial Diligence Is Rigorous and Cyber Diligence Isn't: The double standard inside every investment process, and the Yahoo/Verizon $350 million reference point that should have ended it years ago.</li><li>[12:46] The Five-Point Technical Assessment Every Investor Needs: Secrets in repositories, undocumented data flows, production access sprawl, missing audit trails, and the vendor DPA gap.</li><li>[15:34] The Three Layers of Fiduciary Exposure: Fund-level class action, GP-level LP letter, and personal liability for the partner who championed the deal.</li><li>[18:15] The Three Marching Orders Starting Monday: Upgrade the framework, audit the existing portfolio, build cyber into LP reporting.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/" target="_blank">https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/</a></li><li>Read the Associated Sitrep: The Investor's Cyber Due Diligence Framework — A Four-Stage Playbook for PE and VC Funds After the PowerSchool Ruling: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/" target="_blank">https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/</a></li></ul>]]></description><guid isPermaLink="false">eff358d5-bd6c-40a1-b935-018dd1bd2f3d</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 26 May 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/adc201bd559bee305fee32ed6fe78e15a6228e18bd3375e8b2cc8de884724018/eyJlcGlzb2RlSWQiOiJlZmYzNThkNS1iZDZjLTQwYTEtYjkzNS0wMThkZDFiZDJmM2QiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmEwZjIwNTYxZjA5ZGQxNjc3ZDAwZTBlL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTUtMjFfXzE3LTEwLTE0Lm1wMyJ9.mp3" length="40401754" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/eff358d5-bd6c-40a1-b935-018dd1bd2f3d/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If you write the check without verifying what is in the codebase, you lose the fund.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the federal court ruling that rewired cybersecurity due diligence for the entire investment community.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;On March 18, 2026, a California federal judge allowed class action claims against Bain Capital to proceed for a data breach at PowerSchool that occurred before Bain acquired the company. The acquirer is now legally on the hook for the seller&apos;s pre-close cybersecurity failures. Every PE partner, VC general partner, family office principal, and corporate development executive deploying capital in 2026 just got a new precedent. The era of &quot;verify SOC 2 and move on&quot; is over.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;[00:00] The March 2026 Ruling That Rewired Cyber Diligence: How one federal court decision made the acquirer legally responsible for the seller&apos;s pre-acquisition cybersecurity failures.&lt;/li&gt;&lt;li&gt;[01:39] The PowerSchool Case Walkthrough: 60 million students, 10 million teachers, stolen vendor credentials, and a ShinyHunters ransom demand two months after close.&lt;/li&gt;&lt;li&gt;[08:26] Why Financial Diligence Is Rigorous and Cyber Diligence Isn&apos;t: The double standard inside every investment process, and the Yahoo/Verizon $350 million reference point that should have ended it years ago.&lt;/li&gt;&lt;li&gt;[12:46] The Five-Point Technical Assessment Every Investor Needs: Secrets in repositories, undocumented data flows, production access sprawl, missing audit trails, and the vendor DPA gap.&lt;/li&gt;&lt;li&gt;[15:34] The Three Layers of Fiduciary Exposure: Fund-level class action, GP-level LP letter, and personal liability for the partner who championed the deal.&lt;/li&gt;&lt;li&gt;[18:15] The Three Marching Orders Starting Monday: Upgrade the framework, audit the existing portfolio, build cyber into LP reporting.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/016-pe-vc-funds-liable-portfolio-cyber-breaches-powerschool-case/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: The Investor&apos;s Cyber Due Diligence Framework — A Four-Stage Playbook for PE and VC Funds After the PowerSchool Ruling: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/investor-cyber-due-diligence-framework-powerschool-ruling/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:21:02</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>16</itunes:episode><itunes:title>016 PE and VC Funds Are Now Liable for Portfolio Cyber Breaches: The PowerSchool Case Study</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[015 Inheriting Control Drift: Briefing for New Leaders, CMMC Annual Affirmations &  Phase 2 Deadline]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If you inherit a control library you cannot operationally vouch for, you lose the contract — and possibly your name.</p><p></p><p>In this episode we are analyzing the longest, quietest failure inside the Defense Industrial Base: control drift. There is no breach. No threat actor. No alarm. Just a slow, silent erosion of operational reality — a control library certified clean in 2021 that has decayed by 2026 through cleared workforce attrition, vendor migrations, and "vision-first" leadership making changes before they understand what they inherited.</p><p></p><p>With Phase 2 of the CMMC Final Rule beginning November 10, every incoming CISO, IT Director, and Affirming Official is about to discover the gap between the System Security Plan they inherited and the operational reality they signed for. We break down the four decay patterns, the False Claims Act exposure the annual affirmation creates, and the three marching orders every GovCon executive must execute before the C3PAO walks the floor.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li>[00:00] The Paper Ghost: Why a control library that passed audit in 2021 may no longer exist operationally — and why no alarm fires when it decays.</li><li>[05:49] The Four Decay Patterns: Orphaned custom scripts, vendor migration gaps, SSP rot, and POA&amp;M zombies that have aged into False Claims Act exhibits.</li><li>[13:16] Vision Without Inventory: Why incoming "modernization" leaders create control gaps faster than threat actors do — and the rule that prevents it.</li><li>[15:59] The Annual Affirmation Trap: How a named senior official's signature in SPRS becomes the foundation of a False Claims Act case when the underlying controls have drifted.</li><li>[19:30] The Three Marching Orders: Control Library Walkthrough, Tribal Knowledge Capture, and the Inherited Watch Protocol.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/" target="_blank">https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/</a></li><li>Read the Associated Sitrep: Building a Living Control Library — The GovCon Playbook for Surviving CMMC Phase 2 and the Annual Affirmation: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/" target="_blank">https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/</a></li></ul>]]></description><guid isPermaLink="false">5d8a5754-3f29-4b26-892f-5fb1b3d4ac17</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 19 May 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/7ebcbd572d584f7f9a066ea42439e19f10fb1ef993450368d4d3c966e0af252f/eyJlcGlzb2RlSWQiOiI1ZDhhNTc1NC0zZjI5LTRiMjYtODkyZi01ZmIxYjNkNGFjMTciLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmEwNzNiYmQzOWUyMGRmZGQzMThkZTUyL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTUtMTVfXzE3LTI5LTEubXAzIn0=.mp3" length="46272409" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/5d8a5754-3f29-4b26-892f-5fb1b3d4ac17/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If you inherit a control library you cannot operationally vouch for, you lose the contract — and possibly your name.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the longest, quietest failure inside the Defense Industrial Base: control drift. There is no breach. No threat actor. No alarm. Just a slow, silent erosion of operational reality — a control library certified clean in 2021 that has decayed by 2026 through cleared workforce attrition, vendor migrations, and &quot;vision-first&quot; leadership making changes before they understand what they inherited.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;With Phase 2 of the CMMC Final Rule beginning November 10, every incoming CISO, IT Director, and Affirming Official is about to discover the gap between the System Security Plan they inherited and the operational reality they signed for. We break down the four decay patterns, the False Claims Act exposure the annual affirmation creates, and the three marching orders every GovCon executive must execute before the C3PAO walks the floor.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;[00:00] The Paper Ghost: Why a control library that passed audit in 2021 may no longer exist operationally — and why no alarm fires when it decays.&lt;/li&gt;&lt;li&gt;[05:49] The Four Decay Patterns: Orphaned custom scripts, vendor migration gaps, SSP rot, and POA&amp;amp;M zombies that have aged into False Claims Act exhibits.&lt;/li&gt;&lt;li&gt;[13:16] Vision Without Inventory: Why incoming &quot;modernization&quot; leaders create control gaps faster than threat actors do — and the rule that prevents it.&lt;/li&gt;&lt;li&gt;[15:59] The Annual Affirmation Trap: How a named senior official&apos;s signature in SPRS becomes the foundation of a False Claims Act case when the underlying controls have drifted.&lt;/li&gt;&lt;li&gt;[19:30] The Three Marching Orders: Control Library Walkthrough, Tribal Knowledge Capture, and the Inherited Watch Protocol.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/015-inheriting-control-drift-cmmc-annual-affirmations-phase-2/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: Building a Living Control Library — The GovCon Playbook for Surviving CMMC Phase 2 and the Annual Affirmation: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/living-control-library-cmmc-phase-2-govcon/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:24:06</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>15</itunes:episode><itunes:title>015 Inheriting Control Drift: Briefing for New Leaders, CMMC Annual Affirmations &amp;  Phase 2 Deadline</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[014 The Transparency Trap: When Hackers Weaponize the SEC Against Banks]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If you lose your compliance timeline, you lose the company.</p><p></p><p>In this episode, we are analyzing the collision between the SEC's new 96-hour breach disclosure mandate and the extortion tactics of modern ransomware cartels.</p><p></p><p>Many financial executives believe the SEC rule is just an administrative burden. The reality? Threat actors are actively weaponizing this mandate, using the threat of federal whistleblower complaints to force ransom payments while your incident response team is still trying to stop the bleeding.</p><p></p><p><b>Intel Declassified in this Briefing:</b> </p><ul><li><b>The Dinner Bell:</b> Why forcing public disclosure during an active breach invites secondary attacks. </li><li><b>The Reporting Dilemma:</b> Why closing the vulnerability must happen before notifying leadership. </li><li><b>The e-Discovery Threat:</b> How claiming "state-of-the-art" security in an SEC filing becomes a massive legal liability post-breach. </li><li><b>The Whistleblower Tactic:</b> How hackers monitor 8-K filings and report you to the SEC if you miss the 96-hour window. </li><li><b>The Caremark Standard:</b> How a technical failure transforms into personal liability for board directors. </li><li><b>Actionable Defense:</b> How to define "materiality" thresholds and conduct board-level tabletop exercises before the fire starts.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks" target="_blank">https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks</a></li><li>Read the Associated Sitrep: How Threat Actors Weaponize the SEC's 96-Hour Rule Against Banks: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/" target="_blank">https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/</a></li></ul>]]></description><guid isPermaLink="false">13ac8aaa-8913-44f0-8a60-54f7ef9990f6</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 12 May 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/8e5f32bd4dbb07d4a6e17268cbd7f3bb930601370214058f009bc951cb65310d/eyJlcGlzb2RlSWQiOiIxM2FjOGFhYS04OTEzLTQ0ZjAtOGE2MC01NGY3ZWY5OTkwZjYiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmY2I1NDEzYjE2YWIxMjhlOTEzNTVlL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTUtN19fMTctNTItMzIubXAzIn0=.mp3" length="36628419" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/13ac8aaa-8913-44f0-8a60-54f7ef9990f6/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If you lose your compliance timeline, you lose the company.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are analyzing the collision between the SEC&apos;s new 96-hour breach disclosure mandate and the extortion tactics of modern ransomware cartels.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Many financial executives believe the SEC rule is just an administrative burden. The reality? Threat actors are actively weaponizing this mandate, using the threat of federal whistleblower complaints to force ransom payments while your incident response team is still trying to stop the bleeding.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;The Dinner Bell:&lt;/b&gt; Why forcing public disclosure during an active breach invites secondary attacks. &lt;/li&gt;&lt;li&gt;&lt;b&gt;The Reporting Dilemma:&lt;/b&gt; Why closing the vulnerability must happen before notifying leadership. &lt;/li&gt;&lt;li&gt;&lt;b&gt;The e-Discovery Threat:&lt;/b&gt; How claiming &quot;state-of-the-art&quot; security in an SEC filing becomes a massive legal liability post-breach. &lt;/li&gt;&lt;li&gt;&lt;b&gt;The Whistleblower Tactic:&lt;/b&gt; How hackers monitor 8-K filings and report you to the SEC if you miss the 96-hour window. &lt;/li&gt;&lt;li&gt;&lt;b&gt;The Caremark Standard:&lt;/b&gt; How a technical failure transforms into personal liability for board directors. &lt;/li&gt;&lt;li&gt;&lt;b&gt;Actionable Defense:&lt;/b&gt; How to define &quot;materiality&quot; thresholds and conduct board-level tabletop exercises before the fire starts.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/014-transparency-trap-sec-96-hour-rule-banks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: How Threat Actors Weaponize the SEC&apos;s 96-Hour Rule Against Banks: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/sec-96-hour-disclosure-rule-cybersecurity-materiality/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:19:05</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>14</itunes:episode><itunes:title>014 The Transparency Trap: When Hackers Weaponize the SEC Against Banks</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[013 The Dispersed Hospital: Securing Telehealth & Remote Patient Monitoring Risks]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If you lose data integrity, you risk patient lives.</p><p></p><p>In this episode, we are analyzing the rapid disappearance of the traditional hospital perimeter. Through the massive expansion of "Hospital-at-Home" programs, clinical care is now being delivered over highly vulnerable residential Wi-Fi networks.</p><p></p><p>Many healthcare executives assume that deploying a clinical tablet into a home is secure simply because the hospital owns the hardware. The reality? Operating a telehealth kit over an unpatched, default-password consumer router turns a life-saving telemetry device into an open backdoor for adversaries.</p><p> </p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:00] The Disappearing Perimeter:</b> Why delivering acute care over unsecured residential Wi-Fi completely invalidates your enterprise firewall.</li><li><b>[01:57] The Trojan Horse Scenario:</b> How threat actors scan cheap smart home IoT devices to pivot directly into hospital-issued telehealth tablets.</li><li><b>[03:50] Kinetic Disruption:</b> The terrifying reality of telemetry spoofing, where manipulated vital signs trigger false medical emergencies and divert hospital resources.</li><li><b>[06:11] The Fiduciary Duty:</b> Why outsourcing patient care to the living room does not outsource your legal liability for data hygiene.</li><li><b>[10:45] Actionable Defense:</b> How to bypass the home network entirely using cellular-first deployments and strict Zero Trust Network Access.</li></ul><p> </p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring" target="_blank">https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring</a></li><li>Read the Associated Sitrep: The Dispersed Hospital: Why Remote Patient Monitoring is a Cybersecurity Minefield: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks" target="_blank">https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks</a></li></ul>]]></description><guid isPermaLink="false">98607229-18f7-4f83-9637-55ee52e7966c</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 05 May 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3928f3f0969b4f79361bd2a762db139563f6073a5409ca40adb100d9df6a33f9/eyJlcGlzb2RlSWQiOiI5ODYwNzIyOS0xOGY3LTRmODMtOTYzNy01NWVlNTJlNzk2NmMiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmMjFlNDZiODNkYzM5NGI0YmUyNTU1L3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTQtMjlfXzE3LTUtNDIubXAzIn0=.mp3" length="26162721" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/98607229-18f7-4f83-9637-55ee52e7966c/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If you lose data integrity, you risk patient lives.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are analyzing the rapid disappearance of the traditional hospital perimeter. Through the massive expansion of &quot;Hospital-at-Home&quot; programs, clinical care is now being delivered over highly vulnerable residential Wi-Fi networks.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Many healthcare executives assume that deploying a clinical tablet into a home is secure simply because the hospital owns the hardware. The reality? Operating a telehealth kit over an unpatched, default-password consumer router turns a life-saving telemetry device into an open backdoor for adversaries.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:00] The Disappearing Perimeter:&lt;/b&gt; Why delivering acute care over unsecured residential Wi-Fi completely invalidates your enterprise firewall.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[01:57] The Trojan Horse Scenario:&lt;/b&gt; How threat actors scan cheap smart home IoT devices to pivot directly into hospital-issued telehealth tablets.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[03:50] Kinetic Disruption:&lt;/b&gt; The terrifying reality of telemetry spoofing, where manipulated vital signs trigger false medical emergencies and divert hospital resources.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:11] The Fiduciary Duty:&lt;/b&gt; Why outsourcing patient care to the living room does not outsource your legal liability for data hygiene.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[10:45] Actionable Defense:&lt;/b&gt; How to bypass the home network entirely using cellular-first deployments and strict Zero Trust Network Access.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/013-the-dispersed-hospital-securing-telehealth-remote-patient-monitoring&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: The Dispersed Hospital: Why Remote Patient Monitoring is a Cybersecurity Minefield: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/mission-resilience/remote-patient-monitoring-cybersecurity-telehealth-risks&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:13:38</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>13</itunes:episode><itunes:title>013 The Dispersed Hospital: Securing Telehealth &amp; Remote Patient Monitoring Risks</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[012 The New Insider Threat: Securing Autonomous AI Agents & The BYOD Lesson]]></title><description><![CDATA[<p>If you lose control of your algorithm, you lose control of your company.</p><p></p><p>In this episode of Status: Secure, we are analyzing the sudden, largely unregulated integration of internal AI agents within the Tech Sector. For 20 years, we built our security around the "human firewall," relying on human intuition to catch anomalies. But what happens when you strip the human out of the loop?</p><p></p><p>We break down the recent Meta internal AI misconfiguration, why granting non-human identities read/write access is a ticking time bomb, and why the current AI landscape is a lethal repeat of the Bring Your Own Device (BYOD) era.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:00] The Missing Gut Feeling:</b> Why stripping human intuition out of the loop creates an autonomous insider threat.</li><li><b>[02:54] The BYOD Parallel:</b> How the AI revolution mirrors the chaotic Bring Your Own Device era and the rapid dissolution of the identity perimeter.</li><li><b>[06:08] The Speed of Failure:</b> The devastating difference between a human misplacing a file and an AI recursively altering cloud permissions in milliseconds.</li><li><b>[07:59] Fiduciary Duty:</b> Why you legally own the actions of your AI, and how regulators define "reasonable care."</li><li><b>[10:14] The Command Decision:</b> Two immediate steps—Non-Human Identity Audits and Human-in-the-Loop workflows—to secure your environment tomorrow.</li></ul><p> </p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod" target="_blank">https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod</a></li><li>Read the Associated Sitrep: Non-Human Identity Management: The Lethal Risk of Over-Permissioned AI Agents: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/" target="_blank">https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/</a></li></ul>]]></description><guid isPermaLink="false">7e5e5ac9-3189-4131-b83d-3406f4b16d0d</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3db5919e8b02afb58f3b1f9d55df63e24917183d01db16152e699dabf6adc9a4/eyJlcGlzb2RlSWQiOiI3ZTVlNWFjOS0zMTg5LTQxMzEtYjgzZC0zNDA2ZjRiMTZkMGQiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjllOWY1OTM4YWI3ZmNmOGQ1ZmUyNTUwL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTQtMjNfXzEyLTMzLTU1Lm1wMyJ9.mp3" length="24317849" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/7e5e5ac9-3189-4131-b83d-3406f4b16d0d/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose control of your algorithm, you lose control of your company.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode of Status: Secure, we are analyzing the sudden, largely unregulated integration of internal AI agents within the Tech Sector. For 20 years, we built our security around the &quot;human firewall,&quot; relying on human intuition to catch anomalies. But what happens when you strip the human out of the loop?&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;We break down the recent Meta internal AI misconfiguration, why granting non-human identities read/write access is a ticking time bomb, and why the current AI landscape is a lethal repeat of the Bring Your Own Device (BYOD) era.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:00] The Missing Gut Feeling:&lt;/b&gt; Why stripping human intuition out of the loop creates an autonomous insider threat.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[02:54] The BYOD Parallel:&lt;/b&gt; How the AI revolution mirrors the chaotic Bring Your Own Device era and the rapid dissolution of the identity perimeter.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:08] The Speed of Failure:&lt;/b&gt; The devastating difference between a human misplacing a file and an AI recursively altering cloud permissions in milliseconds.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[07:59] Fiduciary Duty:&lt;/b&gt; Why you legally own the actions of your AI, and how regulators define &quot;reasonable care.&quot;&lt;/li&gt;&lt;li&gt;&lt;b&gt;[10:14] The Command Decision:&lt;/b&gt; Two immediate steps—Non-Human Identity Audits and Human-in-the-Loop workflows—to secure your environment tomorrow.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/012-new-insider-threat-ai-agents-byod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: Non-Human Identity Management: The Lethal Risk of Over-Permissioned AI Agents: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/mission-resilience/non-human-identity-management-ai-security/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:12:40</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>12</itunes:episode><itunes:title>012 The New Insider Threat: Securing Autonomous AI Agents &amp; The BYOD Lesson</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[011 The Compliance Trap: CMMC, The False Claims Act, and the DoD Supply Chain]]></title><description><![CDATA[<p>If you lose your operational integrity, you lose your contracts. If you lose your data, you lose the company.</p><p></p><p>In this episode we are analyzing the soft underbelly of the Defense Industrial Base and the sudden weaponization of cybersecurity compliance.</p><p></p><p>Many GovCon executives believe that uploading a perfect score to SPRS or sticking a System Security Plan in a drawer means their perimeter is secure. The reality? The Department of Justice is actively using the False Claims Act to hunt down contractors who lie about their controls. Treating NIST 800-171 as a mere paperwork exercise is no longer a defense; it is a federal trap.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:00] The Honor System is Dead:</b> Why the DOJ is treating cybersecurity compliance as a kinetic battlefield.</li><li><b>[00:32] Supply Chain Vulnerability:</b> Why nation-state APTs bypass Primes to target Tier 2 and Tier 3 subcontractors for CUI.</li><li><b>[05:50] The Assessment Illusion:</b> Why you need aggressive, adversarial penetration testing to expose the gap between paper and reality.</li><li><b>[09:11] The Whistleblower Threat:</b> How the False Claims Act financially incentivizes your own IT team to report fabricated SPRS scores.</li><li><b>[15:07] Quantifying Cyber Risk:</b> The military "fast rope" analogy for securing necessary cybersecurity budget from the Board of Directors.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/011-cmmc-false-claims-act-dod-supply-chain" target="_blank">https://watchur6.com/podcast/011-cmmc-false-claims-act-dod-supply-chain</a></li><li>Read the Associated Sitrep: The False Claims Act and CMMC: Why Paper Compliance is a Trap for GovCons: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/false-claims-act-cmmc-paper-compliance-trap" target="_blank">https://watchur6.com/sitrep/compliance-protocols/false-claims-act-cmmc-paper-compliance-trap</a></li></ul>]]></description><guid isPermaLink="false">bc30dfca-dfbd-49c5-9419-dfc7633e7a62</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 21 Apr 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0e71e120edcbb3b46aad01936c921c081c10d02124371931c53978d556b10979/eyJlcGlzb2RlSWQiOiJiYzMwZGZjYS1kZmJkLTQ5YzUtOTQxOS1kZmM3NjMzZTdhNjIiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjllMjVhYTExZDU3MjVkMDQyZjQ5MmNhL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTQtMTdfXzE4LTYtNTcubXAzIn0=.mp3" length="29346525" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/bc30dfca-dfbd-49c5-9419-dfc7633e7a62/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose your operational integrity, you lose your contracts. If you lose your data, you lose the company.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the soft underbelly of the Defense Industrial Base and the sudden weaponization of cybersecurity compliance.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Many GovCon executives believe that uploading a perfect score to SPRS or sticking a System Security Plan in a drawer means their perimeter is secure. The reality? The Department of Justice is actively using the False Claims Act to hunt down contractors who lie about their controls. Treating NIST 800-171 as a mere paperwork exercise is no longer a defense; it is a federal trap.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:00] The Honor System is Dead:&lt;/b&gt; Why the DOJ is treating cybersecurity compliance as a kinetic battlefield.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[00:32] Supply Chain Vulnerability:&lt;/b&gt; Why nation-state APTs bypass Primes to target Tier 2 and Tier 3 subcontractors for CUI.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[05:50] The Assessment Illusion:&lt;/b&gt; Why you need aggressive, adversarial penetration testing to expose the gap between paper and reality.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:11] The Whistleblower Threat:&lt;/b&gt; How the False Claims Act financially incentivizes your own IT team to report fabricated SPRS scores.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[15:07] Quantifying Cyber Risk:&lt;/b&gt; The military &quot;fast rope&quot; analogy for securing necessary cybersecurity budget from the Board of Directors.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/011-cmmc-false-claims-act-dod-supply-chain&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/011-cmmc-false-claims-act-dod-supply-chain&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: The False Claims Act and CMMC: Why Paper Compliance is a Trap for GovCons: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/false-claims-act-cmmc-paper-compliance-trap&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/false-claims-act-cmmc-paper-compliance-trap&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:20:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>11</itunes:episode><itunes:title>011 The Compliance Trap: CMMC, The False Claims Act, and the DoD Supply Chain</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[010 Securing the Assembly Line: 4 CI/CD Tools Every InfoSec Team Needs]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If your software assembly line is compromised, you lose your customers.</p><p></p><p>In this episode, we are analyzing the high-stakes friction between rapid software development and infrastructure integrity. In the Tech Sector, developers are paid to ship code at breakneck speed, but if InfoSec remains a manual "gate" at the end of the line, the mission fails before it even launches.</p><p></p><p>The reality? The perimeter is no longer your firewall—it’s your CI/CD pipeline. Today, we declassify the "Shift Left" doctrine and the automated arsenal every security team needs to operate "Left of Bang."</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:29] The Velocity Conflict:</b> Why traditional security checkpoints are functionally obsolete in a 50-deploy-a-day environment.</li><li><b>[01:43] Operating Left of Bang:</b> Applying tactical awareness and "military surveillance" to the software development lifecycle.</li><li><b>[03:43] Hardcoded Secrets:</b> The danger of "front door" vulnerabilities and how to deploy automated scanners.</li><li><b>[07:20] Poisoned Wells:</b> Managing the risk of third-party libraries and Software Composition Analysis (SCA).</li><li><b>[11:51] Avoiding the Civil War:</b> Practical strategies for deploying security guardrails without alienating your engineering team.</li></ul><p> </p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/010-securing-cicd-pipeline-infosec-tools" target="_blank">https://watchur6.com/podcast/010-securing-cicd-pipeline-infosec-tools</a></li><li>Read the Associated Sitrep: The Weaponized Pipeline - Why High-Velocity Development Requires a 'Shift-Left' Doctrine: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/mission-resilience/weaponized-pipeline-shift-left-doctrine" target="_blank">https://watchur6.com/sitrep/mission-resilience/weaponized-pipeline-shift-left-doctrine</a></li></ul>]]></description><guid isPermaLink="false">1b1e548b-6f9c-4dfd-a057-00e302cb39da</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 14 Apr 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/65f9e7a1eb4cf5fa3df87578f799761d5c0291cca640723bc15aee9ae9d4057b/eyJlcGlzb2RlSWQiOiIxYjFlNTQ4Yi02ZjljLTRkZmQtYTA1Ny0wMGUzMDJjYjM5ZGEiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlkN2YwOGNhNTI5ZWI5YjBmODQ2ZGVkL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTQtOV9fMjAtMzEtNDAubXAzIn0=.mp3" length="21499132" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/1b1e548b-6f9c-4dfd-a057-00e302cb39da/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If your software assembly line is compromised, you lose your customers.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are analyzing the high-stakes friction between rapid software development and infrastructure integrity. In the Tech Sector, developers are paid to ship code at breakneck speed, but if InfoSec remains a manual &quot;gate&quot; at the end of the line, the mission fails before it even launches.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The reality? The perimeter is no longer your firewall—it’s your CI/CD pipeline. Today, we declassify the &quot;Shift Left&quot; doctrine and the automated arsenal every security team needs to operate &quot;Left of Bang.&quot;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:29] The Velocity Conflict:&lt;/b&gt; Why traditional security checkpoints are functionally obsolete in a 50-deploy-a-day environment.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[01:43] Operating Left of Bang:&lt;/b&gt; Applying tactical awareness and &quot;military surveillance&quot; to the software development lifecycle.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[03:43] Hardcoded Secrets:&lt;/b&gt; The danger of &quot;front door&quot; vulnerabilities and how to deploy automated scanners.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[07:20] Poisoned Wells:&lt;/b&gt; Managing the risk of third-party libraries and Software Composition Analysis (SCA).&lt;/li&gt;&lt;li&gt;&lt;b&gt;[11:51] Avoiding the Civil War:&lt;/b&gt; Practical strategies for deploying security guardrails without alienating your engineering team.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/010-securing-cicd-pipeline-infosec-tools&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/010-securing-cicd-pipeline-infosec-tools&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: The Weaponized Pipeline - Why High-Velocity Development Requires a &apos;Shift-Left&apos; Doctrine: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/mission-resilience/weaponized-pipeline-shift-left-doctrine&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/mission-resilience/weaponized-pipeline-shift-left-doctrine&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:14:56</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>10</itunes:episode><itunes:title>010 Securing the Assembly Line: 4 CI/CD Tools Every InfoSec Team Needs</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[009 Trust No Inbox: The Surging Epidemic of B2B Financial Email Fraud]]></title><description><![CDATA[<p>If you lose comms, you lose the mission. If you trust the inbox blindly, you lose the capital.<br /></p><p>In this episode we are analyzing the new face of financial theft: Business Email Compromise (BEC).</p><p></p><p>Many finance executives assume an email from a known vendor is safe. The reality? High-fidelity phishing attacks have turned convenience into your greatest vulnerability. Adversaries are no longer trying to hack your firewalls; they are hijacking your supply chain communications and becoming the "man-in-the-middle" to reroute hundreds of thousands of dollars before you even realize you've been breached.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:37] The Evolution of Phishing:</b> Why spray-and-pray spam is dead, and how high-fidelity spear-phishing targets your B2B relationships.</li><li><b>[03:20] The Social Engineering Advantage:</b> Why threat actors prefer walking through the front door with a stolen uniform rather than breaking a window.</li><li><b>[06:56] The Man-in-the-Middle:</b> How adversaries use "dwell time" to intercept and alter live invoices seamlessly.</li><li><b>[10:05] The Liability of Convenience:</b> When funds are stolen, who is at fault? Understanding "Reasonable Care" in the eyes of regulators and the courts.</li><li><b>[12:33] Actionable Defense:</b> Why out-of-band verification and shifting email security from IT to InfoSec are non-negotiable for modern fiduciaries.</li></ul><p> </p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/009-trust-no-inbox-b2b-financial-fraud" target="_blank">https://watchur6.com/podcast/009-trust-no-inbox-b2b-financial-fraud</a></li><li>Read the Associated Sitrep: Weaponizing the Inbox: The Surging Epidemic of B2B Financial Email Fraud: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/threat-intelligence/weaponizing-the-inbox-b2b-financial-email-fraud" target="_blank">https://watchur6.com/sitrep/threat-intelligence/weaponizing-the-inbox-b2b-financial-email-fraud</a></li></ul>]]></description><guid isPermaLink="false">d2ee2cf0-6299-4c6f-a16a-b5e5625d01bb</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 07 Apr 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/25bbbf0f6afa1a1e5e9300d7895c8ce5b1c3ee1c8e74227814809acb50ed78f7/eyJlcGlzb2RlSWQiOiJkMmVlMmNmMC02Mjk5LTRjNmYtYTE2YS1iNWU1NjI1ZDAxYmIiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjljZTllNDYyNjkwNTZjYTkxYzM4NzA2L3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTQtMl9fMTgtNTAtMTQubXAzIn0=.mp3" length="22816957" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/d2ee2cf0-6299-4c6f-a16a-b5e5625d01bb/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose comms, you lose the mission. If you trust the inbox blindly, you lose the capital.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the new face of financial theft: Business Email Compromise (BEC).&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Many finance executives assume an email from a known vendor is safe. The reality? High-fidelity phishing attacks have turned convenience into your greatest vulnerability. Adversaries are no longer trying to hack your firewalls; they are hijacking your supply chain communications and becoming the &quot;man-in-the-middle&quot; to reroute hundreds of thousands of dollars before you even realize you&apos;ve been breached.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:37] The Evolution of Phishing:&lt;/b&gt; Why spray-and-pray spam is dead, and how high-fidelity spear-phishing targets your B2B relationships.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[03:20] The Social Engineering Advantage:&lt;/b&gt; Why threat actors prefer walking through the front door with a stolen uniform rather than breaking a window.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:56] The Man-in-the-Middle:&lt;/b&gt; How adversaries use &quot;dwell time&quot; to intercept and alter live invoices seamlessly.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[10:05] The Liability of Convenience:&lt;/b&gt; When funds are stolen, who is at fault? Understanding &quot;Reasonable Care&quot; in the eyes of regulators and the courts.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[12:33] Actionable Defense:&lt;/b&gt; Why out-of-band verification and shifting email security from IT to InfoSec are non-negotiable for modern fiduciaries.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/009-trust-no-inbox-b2b-financial-fraud&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/009-trust-no-inbox-b2b-financial-fraud&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: Weaponizing the Inbox: The Surging Epidemic of B2B Financial Email Fraud: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/threat-intelligence/weaponizing-the-inbox-b2b-financial-email-fraud&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/threat-intelligence/weaponizing-the-inbox-b2b-financial-email-fraud&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:15:51</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>9</itunes:episode><itunes:title>009 Trust No Inbox: The Surging Epidemic of B2B Financial Email Fraud</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[008 Autopsy of the Stryker Cyber Attack: Wiping 200,000 Endpoints via Intune]]></title><description><![CDATA[<p>If you lose your comms, you lose the mission. If your supply chain loses its endpoints, you lose your patients. </p><p></p><p>In this episode we are analyzing the new standard of mortality risk in the healthcare ecosystem. The recent cyber attack on Stryker—a global medical device giant—didn't rely on zero-day malware. Instead, threat actors weaponized Stryker's own Microsoft Intune administrative controls to remotely wipe 200,000 devices.</p><p></p><p>When a hospital's supply chain collapses, digital negligence translates directly to physical harm. We break down the mechanics of the attack and how healthcare providers must adapt their resilience strategies.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[01:13] The Weaponization of IT:</b> How the Iran-linked group Handala<br />turned a protective tool (Microsoft Intune) into a weapon of mass disruption.</li><li><b>[06:32] The Ripple Effect:</b> Why wiping corporate laptops led to<br />delayed skull implant surgeries for patients globally.</li><li><b>[09:57] Legal Ramifications:</b> When logistics break down and<br />patients are harmed, who holds the liability?</li><li><b>[11:36] PACE Planning:</b> Adopting the military framework for<br />emergency supply chain contingencies.</li><li><b>[14:25] Actionable Defense:</b> Why security teams must enforce<br />"Just-in-Time" (JIT) administrative access immediately.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/008-stryker-cyber-attack-intune-wipe-healthcare" target="_blank">https://watchur6.com/podcast/008-stryker-cyber-attack-intune-wipe-healthcare</a></li><li>Read the Associated Sitrep: <i>Supply Chain Mortality: How the Stryker Hack Weaponized IT<br />Infrastructure</i>: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/threat-intelligence/stryker-cyber-attack-supply-chain-mortality" target="_blank">https://watchur6.com/sitrep/threat-intelligence/stryker-cyber-attack-supply-chain-mortality</a></li></ul>]]></description><guid isPermaLink="false">dfd7b5f0-2555-466a-94ab-6a7dc002a2fd</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 31 Mar 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/7650fd279a36dbe537cb12629558f4ae19b756c7a6a1253eb14eff9b5deb634f/eyJlcGlzb2RlSWQiOiJkZmQ3YjVmMC0yNTU1LTQ2NmEtOTRhYi02YTdkYzAwMmEyZmQiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjljNmFlMmY1NDIwNjFkZThkNDkxMzNmL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTMtMjdfXzE3LTE5LTU5Lm1wMyJ9.mp3" length="25792409" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/dfd7b5f0-2555-466a-94ab-6a7dc002a2fd/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;If you lose your comms, you lose the mission. If your supply chain loses its endpoints, you lose your patients. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the new standard of mortality risk in the healthcare ecosystem. The recent cyber attack on Stryker—a global medical device giant—didn&apos;t rely on zero-day malware. Instead, threat actors weaponized Stryker&apos;s own Microsoft Intune administrative controls to remotely wipe 200,000 devices.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;When a hospital&apos;s supply chain collapses, digital negligence translates directly to physical harm. We break down the mechanics of the attack and how healthcare providers must adapt their resilience strategies.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[01:13] The Weaponization of IT:&lt;/b&gt; How the Iran-linked group Handala&lt;br /&gt;turned a protective tool (Microsoft Intune) into a weapon of mass disruption.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:32] The Ripple Effect:&lt;/b&gt; Why wiping corporate laptops led to&lt;br /&gt;delayed skull implant surgeries for patients globally.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:57] Legal Ramifications:&lt;/b&gt; When logistics break down and&lt;br /&gt;patients are harmed, who holds the liability?&lt;/li&gt;&lt;li&gt;&lt;b&gt;[11:36] PACE Planning:&lt;/b&gt; Adopting the military framework for&lt;br /&gt;emergency supply chain contingencies.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[14:25] Actionable Defense:&lt;/b&gt; Why security teams must enforce&lt;br /&gt;&quot;Just-in-Time&quot; (JIT) administrative access immediately.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/008-stryker-cyber-attack-intune-wipe-healthcare&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/008-stryker-cyber-attack-intune-wipe-healthcare&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: &lt;i&gt;Supply Chain Mortality: How the Stryker Hack Weaponized IT&lt;br /&gt;Infrastructure&lt;/i&gt;: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/threat-intelligence/stryker-cyber-attack-supply-chain-mortality&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/threat-intelligence/stryker-cyber-attack-supply-chain-mortality&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:17:55</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>8</itunes:episode><itunes:title>008 Autopsy of the Stryker Cyber Attack: Wiping 200,000 Endpoints via Intune</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[007 Are You Putting Revenue Before National Security?]]></title><description><![CDATA[<p>For years, the GovCon supply chain lived on the honor system. Ticking compliance boxes (NIST 800-171) was just a "revenue gate"—a criteria needed to win the contract while promising to fix security gaps later through Plans of Action and Milestones (POA&amp;Ms).</p><p></p><p>That era of "Trust" is over. Welcome to Accountability 2.0, where the "Verify" standard of defensive security is now enforced by the DoJ.</p><p></p><p>In this transmission of <i>Status: Secure</i>, we analyze the uncomfortable truth fiduciaries must face: Treating cybersecurity merely as technical debt is now considered fraud against the United States. We break down how simple technical failures (like skipping patches or broken access controls) activate the False Claims Act (FCA), triggering treble damages and incentivizing insiders to become whistleblowers. If you prioritized speed over national security, fiduciaries—including individual Board members—could ultimately lose both.</p><p> </p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:45] The Conventions of Compliance:</b> Why the unverified "honor system" for self-attesting cybersecurity scores is dead.</li><li><b>[03:20] The FCA Activation Matrix:</b> How simple infrastructure rot (unpatched systems) activates federal fraud investigations via the False Claims Act.</li><li><b>[04:40] The Whistleblower’s Math:</b> Breaking down the immense financial incentives (15-30% of settlements) driving insiders to report your unpatched vulnerabilities.</li><li><b>[07:57] Fiduciary Malpractice:</b> Why "the IT team said we were secure" is no longer an acceptable legal defense for individual executives.</li><li><b>[09:31] Marching Orders:</b> Actionable strategic defense (Third-Party Integrity &amp; CUI Enclaves) to align profitability with national security tomorrow.</li></ul><p><b> </b></p><p><b>Mission Links:</b></p><ul><li><b>Verify your Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Want to Hire us:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/007-revenue-vs-national-security-govcon" target="_blank">https://watchur6.com/podcast/007-revenue-vs-national-security-govcon</a></li><li><b>Read the Associated Sitrep: </b><a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/government-cyber-mandate-personal-liability" target="_blank">https://watchur6.com/sitrep/compliance-protocols/government-cyber-mandate-personal-liability</a></li></ul>]]></description><guid isPermaLink="false">f4d06cd4-cda4-4d99-8499-31c26853b181</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 24 Mar 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/ef93e22b4fb82e479fc90900c542bd86c2ad4e45ba38c3d4330371ba49897f7c/eyJlcGlzb2RlSWQiOiJmNGQwNmNkNC1jZGE0LTRkOTktODQ5OS0zMWMyNjg1M2IxODEiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjliYzJiNzMzZWY3OGM3ZmQwMzdhMDJiL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTMtMTlfXzE3LTU5LTMxLm1wMyJ9.mp3" length="18176983" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/f4d06cd4-cda4-4d99-8499-31c26853b181/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;For years, the GovCon supply chain lived on the honor system. Ticking compliance boxes (NIST 800-171) was just a &quot;revenue gate&quot;—a criteria needed to win the contract while promising to fix security gaps later through Plans of Action and Milestones (POA&amp;amp;Ms).&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;That era of &quot;Trust&quot; is over. Welcome to Accountability 2.0, where the &quot;Verify&quot; standard of defensive security is now enforced by the DoJ.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this transmission of &lt;i&gt;Status: Secure&lt;/i&gt;, we analyze the uncomfortable truth fiduciaries must face: Treating cybersecurity merely as technical debt is now considered fraud against the United States. We break down how simple technical failures (like skipping patches or broken access controls) activate the False Claims Act (FCA), triggering treble damages and incentivizing insiders to become whistleblowers. If you prioritized speed over national security, fiduciaries—including individual Board members—could ultimately lose both.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:45] The Conventions of Compliance:&lt;/b&gt; Why the unverified &quot;honor system&quot; for self-attesting cybersecurity scores is dead.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[03:20] The FCA Activation Matrix:&lt;/b&gt; How simple infrastructure rot (unpatched systems) activates federal fraud investigations via the False Claims Act.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[04:40] The Whistleblower’s Math:&lt;/b&gt; Breaking down the immense financial incentives (15-30% of settlements) driving insiders to report your unpatched vulnerabilities.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[07:57] Fiduciary Malpractice:&lt;/b&gt; Why &quot;the IT team said we were secure&quot; is no longer an acceptable legal defense for individual executives.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:31] Marching Orders:&lt;/b&gt; Actionable strategic defense (Third-Party Integrity &amp;amp; CUI Enclaves) to align profitability with national security tomorrow.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Want to Hire us:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/007-revenue-vs-national-security-govcon&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/007-revenue-vs-national-security-govcon&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated Sitrep: &lt;/b&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/government-cyber-mandate-personal-liability&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/government-cyber-mandate-personal-liability&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:12:37</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>7</itunes:episode><itunes:title>007 Are You Putting Revenue Before National Security?</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[006 Slow is Smooth & Smooth is Fast - Security in the Agentic Ecosystem]]></title><description><![CDATA[<p>The perimeter hasn't just moved; it has dissolved. You are only as secure as the weakest link in your digital supply chain.</p><p></p><p>In this episode we are analyzing the "Trojan Agent"—how supply chain poisoning has evolved from simple software updates to the hijacking of your autonomous ecosystem.</p><p></p><p>Most modern tech startups consist of 20% original code and 80% third-party integrations. What happens when your AI<br />support agent is manipulated into exfiltrating your database because you gave it the keys to the kingdom? "Ease of use" is the new vulnerability.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:41] The 80/20 Reality:</b> Why original code is shrinking and<br />third-party AI agents are the new primary attack surface.</li><li><b>[02:31] Agentic Poisoning:</b> How indirect prompt injections turn<br />customer success bots into authorized data thieves.</li><li><b>[10:38] The Unpredictable AI:</b> A real-world case study of a<br />forward-facing AI gone rogue and the resulting reputational damage.</li><li><b>[16:49] Boardroom Liability:</b> Why "Vendor Negligence" is<br />legally and practically becoming "Founder Negligence."</li><li><b>[21:29] Marching Orders:</b> Tactical steps to vet your AI<br />vendors, audit your contracts, and enforce Human-in-the-Loop (HITL) guardrails.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li><b>Verify your Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Want to Hire us:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/006-security-in-the-agentic-ecosystem" target="_blank">https://watchur6.com/podcast/006-security-in-the-agentic-ecosystem</a></li><li><b>Read the Associated Sitrep (Tactical Deep Dive):</b> Agentic Poisoning: The New Frontier<br />of Supply Chain Attacks in the Tech Sector: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/threat-intelligence/agentic-poisoning-saas-supply-chain-risk/" target="_blank">https://watchur6.com/sitrep/threat-intelligence/agentic-poisoning-saas-supply-chain-risk/</a></li></ul>]]></description><guid isPermaLink="false">cd9e5336-2ab9-4b9a-ab28-ca7a94fe6acc</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 17 Mar 2026 08:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/30218dc5f62a1c802b7c3e15aa70e86b3e032e84eaf683fefef8d1c6b407d736/eyJlcGlzb2RlSWQiOiJjZDllNTMzNi0yYWI5LTRiOWEtYWIyOC1jYTdhOTRmZTZhY2MiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjliNDM0OTdiNGNlZjBjZDFkYmIzZGIzL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTMtMTNfXzE3LTAtMjMubXAzIn0=.mp3" length="35447266" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/cd9e5336-2ab9-4b9a-ab28-ca7a94fe6acc/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;The perimeter hasn&apos;t just moved; it has dissolved. You are only as secure as the weakest link in your digital supply chain.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode we are analyzing the &quot;Trojan Agent&quot;—how supply chain poisoning has evolved from simple software updates to the hijacking of your autonomous ecosystem.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Most modern tech startups consist of 20% original code and 80% third-party integrations. What happens when your AI&lt;br /&gt;support agent is manipulated into exfiltrating your database because you gave it the keys to the kingdom? &quot;Ease of use&quot; is the new vulnerability.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:41] The 80/20 Reality:&lt;/b&gt; Why original code is shrinking and&lt;br /&gt;third-party AI agents are the new primary attack surface.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[02:31] Agentic Poisoning:&lt;/b&gt; How indirect prompt injections turn&lt;br /&gt;customer success bots into authorized data thieves.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[10:38] The Unpredictable AI:&lt;/b&gt; A real-world case study of a&lt;br /&gt;forward-facing AI gone rogue and the resulting reputational damage.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[16:49] Boardroom Liability:&lt;/b&gt; Why &quot;Vendor Negligence&quot; is&lt;br /&gt;legally and practically becoming &quot;Founder Negligence.&quot;&lt;/li&gt;&lt;li&gt;&lt;b&gt;[21:29] Marching Orders:&lt;/b&gt; Tactical steps to vet your AI&lt;br /&gt;vendors, audit your contracts, and enforce Human-in-the-Loop (HITL) guardrails.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Want to Hire us:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/006-security-in-the-agentic-ecosystem&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/006-security-in-the-agentic-ecosystem&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated Sitrep (Tactical Deep Dive):&lt;/b&gt; Agentic Poisoning: The New Frontier&lt;br /&gt;of Supply Chain Attacks in the Tech Sector: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/threat-intelligence/agentic-poisoning-saas-supply-chain-risk/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/threat-intelligence/agentic-poisoning-saas-supply-chain-risk/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:24:37</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>6</itunes:episode><itunes:title>006 Slow is Smooth &amp; Smooth is Fast - Security in the Agentic Ecosystem</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[005 Triaging the Invisible Risks in Your Clinical Supply Chain]]></title><description><![CDATA[<p>When the doctor’s hand is networked, the doctor’s responsibility is networked.</p><p></p><p>In this episode, we are triaging the "invisible risks" buried within the clinical supply chain.</p><p></p><p>Fifteen years ago, an IV pump or a pacemaker was a standalone machine. Today, it is a computer node on your network—capable of pulling data, receiving remote instructions, and, if compromised, delivering lethal doses. As the Internet of Medical Things (IoMT) scales, the perimeter of healthcare has shifted from the server room to the patient’s bedside.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:00] The Networked Hand:</b> How medical devices transitioned from machines to high-risk network endpoints.</li><li><b>[01:35] Targeted Sabotage:</b> Why unpatched firmware and generic passwords are no longer just "IT issues"—they are assassination vectors.</li><li><b>[04:57] The FDA Lag:</b> Why life-saving devices are often deployed with seven-year-old, unsupported software.</li><li><b>[09:31] Legal Malpractice 2.0:</b> Why the definition of "reasonable care" now includes your network segmentation strategy.</li><li><b>[12:42] The Triage Framework:</b> Immediate marching orders for CISOs: Inventory, Segmentation, and Procurement Overhaul.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li><b>Verify your Clinical Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Want to Hire us:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>Read the Associated SITREP (Deeper Tactical Dive):</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/iomt-clinical-supply-chain-risk-triage" target="_blank">https://watchur6.com/sitrep/iomt-clinical-supply-chain-risk-triage</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/005-triaging-invisible-risks-clinical-supply-chain" target="_blank">https://watchur6.com/podcast/005-triaging-invisible-risks-clinical-supply-chain</a></li></ul>]]></description><guid isPermaLink="false">05d15845-f5a9-4b31-9bc7-ea91808aed6d</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 10 Mar 2026 18:30:39 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/7015a168c7b35e480000b1cf0f7ad992fe0ef3b1a8865d3df9109f62efada2aa/eyJlcGlzb2RlSWQiOiIwNWQxNTg0NS1mNWE5LTRiMzEtOWJjNy1lYTkxODA4YWVkNmQiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjliMDY2N2E4NjlkZTdhMDg5MTVlYTg0L3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTMtMTBfXzE5LTQ0LTkubXAzIn0=.mp3" length="36787661" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/episodes/05d15845-f5a9-4b31-9bc7-ea91808aed6d/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;When the doctor’s hand is networked, the doctor’s responsibility is networked.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are triaging the &quot;invisible risks&quot; buried within the clinical supply chain.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Fifteen years ago, an IV pump or a pacemaker was a standalone machine. Today, it is a computer node on your network—capable of pulling data, receiving remote instructions, and, if compromised, delivering lethal doses. As the Internet of Medical Things (IoMT) scales, the perimeter of healthcare has shifted from the server room to the patient’s bedside.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:00] The Networked Hand:&lt;/b&gt; How medical devices transitioned from machines to high-risk network endpoints.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[01:35] Targeted Sabotage:&lt;/b&gt; Why unpatched firmware and generic passwords are no longer just &quot;IT issues&quot;—they are assassination vectors.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[04:57] The FDA Lag:&lt;/b&gt; Why life-saving devices are often deployed with seven-year-old, unsupported software.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:31] Legal Malpractice 2.0:&lt;/b&gt; Why the definition of &quot;reasonable care&quot; now includes your network segmentation strategy.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[12:42] The Triage Framework:&lt;/b&gt; Immediate marching orders for CISOs: Inventory, Segmentation, and Procurement Overhaul.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Clinical Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Want to Hire us:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated SITREP (Deeper Tactical Dive):&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/iomt-clinical-supply-chain-risk-triage&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/iomt-clinical-supply-chain-risk-triage&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/005-triaging-invisible-risks-clinical-supply-chain&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/005-triaging-invisible-risks-clinical-supply-chain&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:25:33</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>5</itunes:episode><itunes:title>005 Triaging the Invisible Risks in Your Clinical Supply Chain</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[004 Weaponized AI - How Deepfake Phone Calls are Draining Bank Accounts]]></title><description><![CDATA[<p>If you can’t verify the identity of the person on the other end of the line, you don't have security—you have an open vault.</p><p></p><p>In this episode, we are analyzing a bank heist where no one wears a mask and no one holds a weapon. Instead, the thief uses the exact voice of your most loyal customer.</p><p></p><p>In 2026, AI isn't just writing code; it's cloning identities. We break down how threat actors use as little as three seconds of audio from social media to bypass call center security and why traditional "secret questions" are now a systemic liability for the finance sector.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[01:06] The 3-Second Clone:</b> How LinkedIn and TikTok provide the "source code" for your identity.</li><li><b>[03:58] The Death of KBA:</b> Why "Security Questions" are now a low-cost commodity on the Dark Web.</li><li><b>[05:40] Regulatory Fallout:</b> Why the CFPB views outdated security as "Negligence," not just a breach.</li><li><b>[07:12] Defensive AI:</b> Moving authentication off the voice channel and onto cryptographically secure hardware.</li><li><b>[09:00] Marching Orders:</b> Tactical steps for VPs of Fraud to stress-test their call centers today.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li><b>Verify your Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Want to Hire us:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>Read the Associated Sitrep (Deep Dive on MFA):</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/mission-resilience/phishing-resistant-mfa-banking-deepfakes/" target="_blank">https://watchur6.com/sitrep/mission-resilience/phishing-resistant-mfa-banking-deepfakes/</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/004-weaponized-ai-deepfake-voice-banking-fraud" target="_blank">https://watchur6.com/podcast/004-weaponized-ai-deepfake-voice-banking-fraud</a></li></ul>]]></description><guid isPermaLink="false">c6b046c3-42a3-46bb-abfb-cdc0ce6c8557</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/327e2f3858960811422dda31fa42b7114c83061a144fe8b8732754bb85f55d38/eyJlcGlzb2RlSWQiOiJjNmIwNDZjMy00MmEzLTQ2YmItYWJmYi1jZGMwY2U2Yzg1NTciLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlhNjBmNmVjNmMzYTAxMDBiZWJmN2EzL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTMtMl9fMjMtMzAtNi5tcDMifQ==.mp3" length="18358169" type="audio/mpeg"/><itunes:summary>&lt;p&gt;If you can’t verify the identity of the person on the other end of the line, you don&apos;t have security—you have an open vault.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are analyzing a bank heist where no one wears a mask and no one holds a weapon. Instead, the thief uses the exact voice of your most loyal customer.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In 2026, AI isn&apos;t just writing code; it&apos;s cloning identities. We break down how threat actors use as little as three seconds of audio from social media to bypass call center security and why traditional &quot;secret questions&quot; are now a systemic liability for the finance sector.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[01:06] The 3-Second Clone:&lt;/b&gt; How LinkedIn and TikTok provide the &quot;source code&quot; for your identity.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[03:58] The Death of KBA:&lt;/b&gt; Why &quot;Security Questions&quot; are now a low-cost commodity on the Dark Web.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[05:40] Regulatory Fallout:&lt;/b&gt; Why the CFPB views outdated security as &quot;Negligence,&quot; not just a breach.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[07:12] Defensive AI:&lt;/b&gt; Moving authentication off the voice channel and onto cryptographically secure hardware.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:00] Marching Orders:&lt;/b&gt; Tactical steps for VPs of Fraud to stress-test their call centers today.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Want to Hire us:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated Sitrep (Deep Dive on MFA):&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/mission-resilience/phishing-resistant-mfa-banking-deepfakes/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/mission-resilience/phishing-resistant-mfa-banking-deepfakes/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/004-weaponized-ai-deepfake-voice-banking-fraud&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/004-weaponized-ai-deepfake-voice-banking-fraud&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:12:45</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>4</itunes:episode><itunes:title>004 Weaponized AI - How Deepfake Phone Calls are Draining Bank Accounts</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[003 Velocity vs Security: Is "Move Fast and Break Things" Costing You Enterprise Deals?]]></title><description><![CDATA[<p>In the tech sector, speed is life. But if you’re a startup trying to land Fortune 500 clients, shipping code without security isn't "moving fast"—it's building catastrophic security debt.</p><p></p><p>In this episode, we are talking to the disruptors, the coders, and the startup founders who need to balance development velocity with enterprise-grade security. We break down why the old "Wild West" era of coding is dead, how AI is changing the game, and why waiting until an enterprise client asks for a SOC 2 report is a $50,000 mistake.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li>[01:36] Security Debt: Why patching vulnerabilities later is like building a 50-story skyscraper on a cracked foundation.</li><li>[05:57] Shifting Left: How to stop using security as a "gate" and start using it as a "guardrail" to actually speed up your deployment cycles.</li><li>[08:34] The Enterprise Gatekeeper: Why security is no longer just a backend issue, but a mandatory product feature required to close major revenue deals.</li><li>[11:43] The Venture Capital Rule: Why you must treat SOC 2 compliance exactly like raising capital—get it before you need it.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li>Verify your Security Posture: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li>Want to Hire us: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li>View the Show Notes: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/003-velocity-vs-security" target="_blank">https://watchur6.com/podcast/003-velocity-vs-security</a></li><li>Read the Associated Sitrep: SOC 2 Compliance: The Ultimate Gatekeeper to Enterprise Tech Deals - <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/compliance-protocols/soc-2-compliance-enterprise-tech-deals/" target="_blank">https://watchur6.com/sitrep/compliance-protocols/soc-2-compliance-enterprise-tech-deals/</a></li></ul>]]></description><guid isPermaLink="false">d44c5965-5653-4ed0-bc98-fcc237fbd09f</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 24 Feb 2026 15:48:22 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/00472298a3494fd18099cfab1f03fe948a7b312c08742057457da244e341e310/eyJlcGlzb2RlSWQiOiJkNDRjNTk2NS01NjUzLTRlZDAtYmM5OC1mY2MyMzdmYmQwOWYiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk5ZGM4NDc0NDI1MGNkZmM5MTMwODMxL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTItMjRfXzE2LTQ4LTIzLm1wMyJ9.mp3" length="21380641" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In the tech sector, speed is life. But if you’re a startup trying to land Fortune 500 clients, shipping code without security isn&apos;t &quot;moving fast&quot;—it&apos;s building catastrophic security debt.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, we are talking to the disruptors, the coders, and the startup founders who need to balance development velocity with enterprise-grade security. We break down why the old &quot;Wild West&quot; era of coding is dead, how AI is changing the game, and why waiting until an enterprise client asks for a SOC 2 report is a $50,000 mistake.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;[01:36] Security Debt: Why patching vulnerabilities later is like building a 50-story skyscraper on a cracked foundation.&lt;/li&gt;&lt;li&gt;[05:57] Shifting Left: How to stop using security as a &quot;gate&quot; and start using it as a &quot;guardrail&quot; to actually speed up your deployment cycles.&lt;/li&gt;&lt;li&gt;[08:34] The Enterprise Gatekeeper: Why security is no longer just a backend issue, but a mandatory product feature required to close major revenue deals.&lt;/li&gt;&lt;li&gt;[11:43] The Venture Capital Rule: Why you must treat SOC 2 compliance exactly like raising capital—get it before you need it.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Verify your Security Posture: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Want to Hire us: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;View the Show Notes: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/003-velocity-vs-security&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/003-velocity-vs-security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the Associated Sitrep: SOC 2 Compliance: The Ultimate Gatekeeper to Enterprise Tech Deals - &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/compliance-protocols/soc-2-compliance-enterprise-tech-deals/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/compliance-protocols/soc-2-compliance-enterprise-tech-deals/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:14:51</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>3</itunes:episode><itunes:title>003 Velocity vs Security: Is &quot;Move Fast and Break Things&quot; Costing You Enterprise Deals?</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[002 Technical Debt: The High Cost of Legacy Systems]]></title><description><![CDATA[<p>In this briefing, we strip away the "If it ain't broke, don't fix it" mentality that plagues the GovCon sector. We analyze the collision between aging government infrastructure and modern adversary capabilities.</p><p></p><p>Many contractors believe they can hide their legacy tech behind a firewall and pass a CMMC assessment. The reality? If you can’t patch it, you can’t certify it.</p><p></p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:46] The Patching Gap:</b> Why End-of-Life (EOL) software is the ultimate playground for hackers.</li><li><b>[02:23] The Compliance Wall:</b> Why legacy systems trigger an automatic failure under NIST 800-171 (Control 3.14.1).</li><li><b>[04:14] The "Assessment Tax":</b> Why you will waste $50k on an assessor just to be told your hardware is obsolete.</li><li><b>[06:15] Tactical Remediation:</b> The "Inventory &amp; Isolate" strategy for systems you cannot afford to replace yet.</li><li><b>[09:39] The Time Machine:</b> Contrasting Silicon Valley speed with the "archaeology" of DOD IT systems.</li></ul><p></p><p><b>Mission Links:</b></p><ul><li><b>Verify your Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Establish a Secure Line:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/002-technical-debt-legacy-systems-govcon/" target="_blank">https://watchur6.com/podcast/002-technical-debt-legacy-systems-govcon/</a></li><li><b>Read the Associated Sitrep:</b> Infrastructure Rot - Why Aging Hardware Fails the Mission: <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/mission-resilience/infrastructure-rot-aging-hardware-threats/" target="_blank">https://watchur6.com/sitrep/mission-resilience/infrastructure-rot-aging-hardware-threats/</a></li></ul>]]></description><guid isPermaLink="false">f63e0ace-6ea7-414d-84fd-a65765c877ff</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0e74ac596a6e65eb85bf24471a6a673cc844d673c2933915c17ef5449dde578e/eyJlcGlzb2RlSWQiOiJmNjNlMGFjZS02ZWE3LTQxNGQtODRmZC1hNjU3NjVjODc3ZmYiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk5MzhmYmNkNjhkZDVhZDczNTg5YzJlL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTItMTZfXzIyLTQ0LTI4Lm1wMyJ9.mp3" length="24259543" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this briefing, we strip away the &quot;If it ain&apos;t broke, don&apos;t fix it&quot; mentality that plagues the GovCon sector. We analyze the collision between aging government infrastructure and modern adversary capabilities.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Many contractors believe they can hide their legacy tech behind a firewall and pass a CMMC assessment. The reality? If you can’t patch it, you can’t certify it.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:46] The Patching Gap:&lt;/b&gt; Why End-of-Life (EOL) software is the ultimate playground for hackers.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[02:23] The Compliance Wall:&lt;/b&gt; Why legacy systems trigger an automatic failure under NIST 800-171 (Control 3.14.1).&lt;/li&gt;&lt;li&gt;&lt;b&gt;[04:14] The &quot;Assessment Tax&quot;:&lt;/b&gt; Why you will waste $50k on an assessor just to be told your hardware is obsolete.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:15] Tactical Remediation:&lt;/b&gt; The &quot;Inventory &amp;amp; Isolate&quot; strategy for systems you cannot afford to replace yet.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:39] The Time Machine:&lt;/b&gt; Contrasting Silicon Valley speed with the &quot;archaeology&quot; of DOD IT systems.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Establish a Secure Line:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/002-technical-debt-legacy-systems-govcon/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/002-technical-debt-legacy-systems-govcon/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated Sitrep:&lt;/b&gt; Infrastructure Rot - Why Aging Hardware Fails the Mission: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/mission-resilience/infrastructure-rot-aging-hardware-threats/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/mission-resilience/infrastructure-rot-aging-hardware-threats/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:16:51</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>2</itunes:episode><itunes:title>002 Technical Debt: The High Cost of Legacy Systems</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[001 HIPAA Compliance vs Dark Web Economics]]></title><description><![CDATA[<p>Welcome to the first transmission of <i>Status: Secure</i>. Today, we are analyzing the collision between regulatory compliance and the profit models of the Dark Web.</p><p>Many healthcare executives believe passing a HIPAA audit means their perimeter is secure. The reality? A compliance certificate is just a driver’s license—it doesn’t mean you know how to drive defensively when a threat actor runs you off the road.</p><p><b>Intel Declassified in this Briefing:</b></p><ul><li><b>[00:00] The Valuation Gap:</b> Why hackers pay 200x more for patient data than credit cards.</li><li><b>[01:53] The Compliance Fallacy:</b> Why checking the "HIPAA Box" leaves your doors wide open.</li><li><b>[06:36] The "Lock" Theory:</b> Are you keeping honest people honest, or stopping an adversary?</li><li><b>[09:33] Kinetic Cyber:</b> When a network breach becomes a mortality risk (NICU &amp; Pacemakers).</li><li><b>[11:41] Actionable Defense:</b> Two immediate steps (Segmentation &amp; Immutable Backups) to secure your infrastructure today.</li></ul><p><b>Mission Links:</b></p><ul><li><b>Verify your Security Posture:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/secure" target="_blank">https://watchur6.com/secure</a></li><li><b>Want to Hire us:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/contact/" target="_blank">https://watchur6.com/contact/</a></li><li><b>View the Show Notes:</b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/podcast/001-hipaa-compliance-vs-dark-web-economics/" target="_blank">https://watchur6.com/podcast/001-hipaa-compliance-vs-dark-web-economics/</a></li><li><b>Read the Associated Sitrep: The Anatomy of a Medical Breach (Why Ransomware Loves Healthcare) </b> <a rel="noopener noreferrer nofollow" href="https://watchur6.com/sitrep/threat-intelligence/anatomy-medical-breach-hipaa/" target="_blank">https://watchur6.com/sitrep/threat-intelligence/anatomy-medical-breach-hipaa/</a></li></ul>]]></description><guid isPermaLink="false">607b54a6-c44e-47da-939b-a4f7636ba038</guid><dc:creator><![CDATA[WatchUr6 - Cybersecurity]]></dc:creator><pubDate>Sat, 14 Feb 2026 03:02:52 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/bf64933946b9a3017814686d3836b475142e9a9f35eb6ef85dd493be20e89d8a/eyJlcGlzb2RlSWQiOiI2MDdiNTRhNi1jNDRlLTQ3ZGEtOTM5Yi1hNGY3NjM2YmEwMzgiLCJwb2RjYXN0SWQiOiIyN2U5ZmMyYS1kMWVkLTRhMjMtYTBlNC04YzA5NDZkNmMxMDMiLCJhY2NvdW50SWQiOiI2ODJjYzM4MjJiYzZiMzI4MWM0MTdhZDEiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk4ZmU3MjcxNGI1YzdiYTA1ZTY4ODBjL3RpbS1zd2FuZXlzLXN0dWRpby1jb21wb3Nlci0yMDI2LTItMTRfXzQtOC0yMy5tcDMifQ==.mp3" length="22090335" type="audio/mpeg"/><itunes:summary>&lt;p&gt;Welcome to the first transmission of &lt;i&gt;Status: Secure&lt;/i&gt;. Today, we are analyzing the collision between regulatory compliance and the profit models of the Dark Web.&lt;/p&gt;&lt;p&gt;Many healthcare executives believe passing a HIPAA audit means their perimeter is secure. The reality? A compliance certificate is just a driver’s license—it doesn’t mean you know how to drive defensively when a threat actor runs you off the road.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Intel Declassified in this Briefing:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;[00:00] The Valuation Gap:&lt;/b&gt; Why hackers pay 200x more for patient data than credit cards.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[01:53] The Compliance Fallacy:&lt;/b&gt; Why checking the &quot;HIPAA Box&quot; leaves your doors wide open.&lt;/li&gt;&lt;li&gt;&lt;b&gt;[06:36] The &quot;Lock&quot; Theory:&lt;/b&gt; Are you keeping honest people honest, or stopping an adversary?&lt;/li&gt;&lt;li&gt;&lt;b&gt;[09:33] Kinetic Cyber:&lt;/b&gt; When a network breach becomes a mortality risk (NICU &amp;amp; Pacemakers).&lt;/li&gt;&lt;li&gt;&lt;b&gt;[11:41] Actionable Defense:&lt;/b&gt; Two immediate steps (Segmentation &amp;amp; Immutable Backups) to secure your infrastructure today.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Mission Links:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verify your Security Posture:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/secure&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/secure&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Want to Hire us:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/contact/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/contact/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;View the Show Notes:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/podcast/001-hipaa-compliance-vs-dark-web-economics/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/podcast/001-hipaa-compliance-vs-dark-web-economics/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Read the Associated Sitrep: The Anatomy of a Medical Breach (Why Ransomware Loves Healthcare) &lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://watchur6.com/sitrep/threat-intelligence/anatomy-medical-breach-hipaa/&quot; target=&quot;_blank&quot;&gt;https://watchur6.com/sitrep/threat-intelligence/anatomy-medical-breach-hipaa/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:15:20</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/27e9fc2a-d1ed-4a23-a0e4-8c0946d6c103/logos/7bc56604-3569-4b38-ac0b-e77a879de2b2.png"/><itunes:episode>1</itunes:episode><itunes:title>001 HIPAA Compliance vs Dark Web Economics</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>