From a breach attorney explaining what really happens once ransomware hits your legal team's inbox, to a cybersecurity student explaining why "there's a talent shortage" doesn't match his job search, this stretch of The Art of Security podcast, hosted by Fortra’s Josh Davies and Tyler Reguly, traded some of the co-host banter for outside expertise. Add in a fresh take on why vulnerability names like Heartbleed and Log4Shell spark more hype than help, a hard look at whether your AI governance has any teeth, and a detour into what Hollywood gets right (and hilariously wrong) about hacking, and you've got a run of episodes that's about what's actually happening in courtrooms, classrooms, and security operations centers right now.
Named Vulnerabilities, CVEs & the Problem with Security Hype
Heartbleed. Log4Shell. PrintNightmare. Some vulnerabilities get a name, a logo, and a news cycle, while thousands of other CVEs quietly go unpatched in the background. In this episode, Josh and Tyler debate whether that branding actually helps security teams prioritize or just trains everyone to tune out the next "boy who cried wolf" alert. The conversation covers responsible disclosure, media sensationalism, and what all that hype does to SOC teams, executives, and researchers trying to separate real risk from noise. Listen to the full episode.
Learning Cybersecurity: Education, Experience, and AI
Cybersecurity may be one of the only professions where the learning genuinely never stops. Josh and Tyler sit down with Dr. Mansour Alqarni of Fanshawe College to dig into the skills gap, whether cybersecurity should even be considered an entry-level career, and how AI is reshaping hiring, SOC work, and the classroom all at once. Their conclusion is a debate worth having: Critical thinking and a willingness to keep learning may matter more than any single credential. Listen to the full episode.
What Happens After a Data Breach? Ransomware, Legal Risk, & Recovery
Everyone plans for prevention, fewer plan for what happens the moment prevention fails. Breach lawyer Brent Arnold of INQ Law joins Josh and Tyler to walk through what actually unfolds after ransomware hits, including negotiations, breach reporting obligations, regulatory exposure, and recovery planning. One theme lands hard: process failures often do as much damage as technical ones and knowing where your sensitive data lives before an incident happens is half the battle. Listen to the full episode.
What Canada's Bill C-8 Means for Cybersecurity
A bonus conversation follows the breach episode, and it's a timely one. Bill C-8, Canada's Act Respecting Cyber Security, has received Royal Assent, and Brent Arnold returns to unpack what it actually requires of telecommunications providers, critical infrastructure operators, and vendors selling into Canadian organizations, including minimum cybersecurity requirements and incident preparedness. Listen to the full episode.
Not Curious? Cybersecurity Isn't the Career for You
Is cybersecurity really short on talent, or are organizations just unwilling to develop it? Dema Gorkun, a cybersecurity student at MacEwan University and leader of the Student Ethical Hacking Club, joins Josh and Tyler for a candid, student's-eye view of what cybersecurity education gets right and where it falls short. From vibe-coding pitfalls to a phishing project that triggered an emergency executive meeting, this one's a reminder that curiosity and hands-on labs can matter more than a resume. Listen to the full episode.
AI Governance in Action: How to Secure AI Without Slowing Innovation
Your AI has access, but does it have too much? Josh sits down with Gina Cardelli, Principal Security Strategist at Fortra, to talk through what recent AI security incidents reveal about excessive permissions, shadow AI, and third-party tool risk. The takeaway isn't that governance has to be perfect on day one, it's that organizations need to know how AI is being used, what it can touch, and what happens if something goes wrong. Listen to the full episode.
Hackers in the Movies (Lights, Camera, Cyberattack)
Hollywood rarely gets the technical details of hacking right, but it often captures something true about the human side of security: the curiosity, the social engineering, the trust exploited along the way. This episode is a fun departure that still makes a real point about where movie hacking and real hacking actually overlap. Listen to the full episode.
The Bottom Line
None of these conversations wrap up with a tidy answer, and that's kind of the point. A vulnerability's name doesn't tell you how dangerous it is. A breach doesn't end when the ransomware note disappears. AI governance isn't a policy you write once and forget. Josh, Tyler, and their guests keep landing on the same idea from different angles: security is less about having the right checklist and more about asking the right questions before you need the answers.
If you've made it this far without hitting play, consider this your sign. New episodes drop every two weeks. so subscribe to The Art of Security on Apple Podcasts, Spotify, or YouTube.