86 episodes
- Running a vulnerability scan is easy. Deciding what matters, what is noise, and what a business should do next is the real work.
Michael Simmons, founder of Elysium Trace, joins Joe Patti and Adam Roth to discuss business-focused vulnerability reporting for MSPs, IT consultants, and smaller security teams. They cover false positives, context, risk acceptance, repeatable reporting, automation, and why human judgment still matters.
Michael describes Elysium Trace and its product approach from his own experience. Learn more: https://elysiumtrace.com/ - Cybersecurity was built for enterprises. Gaurav Keerthi explains what that leaves behind for the companies without a cyber team, and why their exposure becomes everyone else’s problem.
Gaurav, CEO of StrongKeep and a cybersecurity leader in the public and private sectors, joins Joe Patti and Adam Roth to break down why smaller organizations are still expected to buy, operate, and manage enterprise-style security. They discuss supply-chain risk, the “hopes and prayers” gap, cybersecurity’s IKEA problem, and what a usable baseline could look like for ordinary companies.
Episode Takeaways:
Most organizations do not have a dedicated cybersecurity professional.
Enterprise security programs cannot fully protect an organization when exposed suppliers remain unprotected.
Security products need to be simpler, more bundled, and more realistic for companies without specialist teams.
Doing something proportionate is better than doing nothing while waiting for a perfect plan.
Guest:
- Gaurav Keerthi, CEO, StrongKeep
- LinkedIn: https://sg.linkedin.com/in/gaurav-keerthi
- StrongKeep: https://www.strongkeep.com/
Resources:
- CyCon: https://cycon.org/
- NATO Cooperative Cyber Defence Centre of Excellence: https://ccdcoe.org/
Security Cocktail Hour Podcast:
- https://securitycocktailhour.com - Eva Galperin explains how stalkerware, ordinary phone access, coercion, and weak privacy defaults can let someone close create devastating real-world harm.
In this episode, we cover:
What stalkerware is and why hiding from the user matters
Why intimate-partner abuse changes the cybersecurity threat model
Privacy as consent and control, not isolation
Why end-to-end encryption is not magic if the endpoint is compromised
Password managers, VPN myths, patching, and backups
What security teams miss when they only focus on exotic adversaries
Guest: Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware.
Resources:
EFF Surveillance Self-Defense: https://ssd.eff.org/
Coalition Against Stalkerware: https://stopstalkerware.org/ - This is the full interview version of our conversation with Chad Butler.
Chad previously worked in product security at Amazon and was involved with Prime Air, Amazon's drone delivery program. He joins Joe Patti and Adam Roth to talk about drone delivery, FAA rules, GPS spoofing, detect-and-avoid, ADS-B, autonomous vehicles, AI agents, and the engineering culture needed when software failures can become physical-world safety failures.
Topics include:
Prime Air and product security
commercial drone delivery risk
Part 107 and Part 108
beyond visual line of sight operations
GPS spoofing and drone capture
detect-and-avoid vs right of way
ADS-B tradeoffs
why pilots may not reliably see drones
autonomous vehicles and AI agents
adversarial inputs and edge cases
public trust after catastrophic failures
Challenger, Feynman, and ignored engineering warnings - Autonomous systems are already moving into the physical world. Drones can fly themselves, robot taxis are carrying passengers, and AI systems are taking more action without direct human control.
Chad Butler joins the Security Cocktail Hour to explain why that changes the risk model.
The issue is what happens when autonomous systems make real-world decisions from sensor data, routing logic, and AI-driven judgment that may be wrong, spoofed, or manipulated.
In this feature version, Chad talks with Joe Patti and Adam Roth about:
GPS spoofing and drone capture
beyond visual line of sight drone operations
trusted and untrusted sensor data
AI agents and autonomous vehicles
why optimal-environment testing is not enough
why "nobody will do that" is not a defense
how cyber failures can become safety failures
what Challenger and Feynman still teach us about launch pressure and ignored warnings
This is a feature cut of the conversation. Th full interview will be released soon.
More Technology podcasts
Trending Technology podcasts
About Security Cocktail Hour
Security veterans Joe Patti and Adam Roth welcome a diverse lineup of cybersecurity and information security experts to share their insights at the virtual bar. From cutting edge topics like AI and Operational Technology (OT) to the realities of careers and mental health, you'll get the inside view of what's happening across the industry and what it's really like to work in these fields, from the people who do it every day.Reach us at feedback@securitycocktailhour.com or @SecCocktailHour on Twitter.
Podcast websiteListen to Security Cocktail Hour, Deep Questions with Cal Newport and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Security Cocktail Hour
Scan code,
download the app,
start listening.
download the app,
start listening.































