
Hosted by Hunter Strategy · EN

Most of us don’t realize just how deeply embedded systems and firmware influence our daily lives — from medical devices to cars, factories, and even space tech. But as these critical systems become more interconnected and complex, so do the security risks. In this episode, cybersecurity veterans Jake Williams and Mick Douglas unpack the real-world challenges of secure firmware development and why it can’t be an afterthought anymore.Episode Chapters: 00:00 Introduction to Secure Firmware Development02:26 Defining Firmware and Embedded Systems03:52 Challenges in Firmware Security08:03 Industry-Specific Trade-offs in Firmware Development13:56 Building Security into Firmware from the Ground Up22:24 Secure Firmware Updates and Supply Chain Risks23:11 Understanding Firmware Updates in IoT Devices31:14 Security Standards for Embedded Devices40:52 The Future of Liability and Standards in Embedded Systems

On this episode of This is Fine, host Matt Triner sits down with guests John Czaika, VP, Strategic Initiatives of Hunter Strategy, and Kevin Belanga, Chief Growth Officer of Hunter Strategy, to break down the fundamentals of government contract types. John walks through how risk shifts across fixed-price, time-and-materials, and cost-reimbursement contracts, while Kevin brings the industry-side perspective on bidding, compliance, and common misconceptions. Together they trace the policy pendulum from Better Buying Power 1.0 through 3.0 and why the government increasingly favors firm fixed price. They close with practical advice for smaller companies entering the space, most notably to build strategic partnerships early and get comfortable understanding your own costs.Episode Chapters: 00:00 Introduction to Government Contracting Fundamentals02:26 Types of Government Contracts05:28 Understanding Risk in Contracting08:20 Business Development and Contract Types11:04 Government's Perspective on Risk13:56 Common Misconceptions in Government Contracting24:06 Navigating Government Contracting Challenges25:10 Misconceptions in Government-Industry Communication27:39 The Role of Market Research in Contract Types37:10 Advice for Small Businesses in Government Contracting

This episode explores why purple teaming is becoming a smarter security strategy, with host, Matt Triner, speaking alongside guests Jordan Lazo, Gabriel Abdalawad, and Jake Williams from Hunter Strategy. They break down the difference between red, blue, and purple teams, and explain how collaboration helps organizations improve detections and reduce blind spots. The conversation also covers why purple teaming is especially valuable for less mature organizations that need to build stronger security foundations. Overall, the guests argue that sharing tactics, testing detections, and closing gaps creates more practical security than working in silos.Episode Chapters: 00:00 Introduction to Cybersecurity Teams01:00 Defining Blue, Red, and Purple Teams03:19 The Philosophy of Purple Teaming07:57 Real-World Examples of Detection and Exploitation12:55 Building a Purple Team in Less Mature Organizations18:39 The Importance of Detection Engineering23:49 Understanding Decay and AI Solutions29:53 Cloud Security: Risks and Responsibilities31:17 Documentation Challenges in Cloud Implementations37:54 The Case for Purple Teams44:24 Strategies for Implementing Purple Teams

Cyber warfare is often misunderstood and this episode explains why it’s usually a supporting act rather than the main event in modern conflict. Jake Williams and Bryson Bort break down how cyber operations differ from kinetic warfare, why attribution and battle damage assessment are so difficult, and why political and strategic limits often matter more than the technology itself. You’ll also hear how adversaries use low-cost, scalable cyber campaigns to create disruption without triggering direct escalation. Overall, it’s a sharp look at how cyber tactics are reshaping future warfare and global security.Episode Chapters: 00:00 Introduction to Cyber Warfare05:16 The Role of Cyber in Modern Warfare07:51 Stuxnet: A Case Study in Cyber Warfare10:52 Legal Definitions and Warfare16:17 The Complexity of Cyber Operations17:50 Investment in Cyber Capabilities22:10 The Future of Cyber Warfare27:06 Ethics and Cyber Warfare33:51 Predictions for Future Conflicts41:30 Educating on Cyber Warfare

Cybersecurity Challenges in Internet of Things (IoT) DevicesIoT isn't just smart bulbs and garage door openers, it's the badge scanner at your office door, the sensors on a wind turbine, the x-ray machine at your hospital, and the PLC system running a manufacturing floor. The attack surface is enormous, and most of it was never built with security in mind.In this episode, host Matt Triner sits down with Adeel Chohan, Head of Data & AI at Provectus, to unpack why IoT security is so hard to get right and why it keeps getting harder. They dig into device procurement gaps, firmware vulnerabilities, the challenges of securing brownfield infrastructure, and why security is almost always the last conversation in an IoT deployment, not the first.From power grids to hospital networks to factory floors, Adeel and Matt explore what it actually takes to secure environments where connected devices outnumber the people managing them - and why legacy perimeter defenses aren't built for this reality.You can't protect what you can't see.Episode Chapters:00:00 Introduction to IoT Device Security02:47 The Broad Scope of IoT Devices05:35 Unique Considerations for Securing IoT Devices09:56 Challenges in Implementing Security Measures for IoT Devices23:27 The Role of Cloud Providers in Enabling and Securing IoT Devices26:49 The Challenge of IoT Cybersecurity and the Need for Standardization27:42 From Point-to-Point Solutions to Standardized Device Management31:05 The Trade-Offs Between Proprietary and Standardized Protocols42:01 The Role of Regulation in Ensuring IoT Security44:27 The Impact of Decreasing Sensor Costs on IoT Security46:33 The Mindset Shift Towards Prioritizing IoT Security49:06 The Future of IoT Security: Regulations, Collaboration, and AI

Unlock the future of cybersecurity in the Department of Defense with insights on the latest tools, frameworks, and strategies transforming network monitoring. Most agencies are still relying on outdated processes—are you prepared for the shift toward automated, real-time risk assessments? In this episode, Dan Beller, Director of Cloud Solutions at Hunter Strategy, and Chris Sowards, GRC expert, reveal how cutting-edge innovations like OSCAL, cloud-native integrations, and advanced vulnerability scanning are revolutionizing continuous monitoring for defense networks.Episode Chapters: 00:00 Introduction to Continuous Monitoring and Risk Assessment02:05 Continuous Monitoring and the ATO Process03:23 Continuous Monitoring and System Modifications06:15 Evolution of Continuous Monitoring08:45 Assessment and Compliance in Continuous Monitoring12:44 Tooling and Automation in Continuous Monitoring16:04 Future Trends in Continuous Monitoring19:04 Building Trust and Relationships19:43 Challenges in Generating Artifacts20:29 Automating ATO Process22:48 GRC as a Gateway into Cybersecurity24:00 The Value of GRC Professionals24:29 The Importance of GRC in Software Development25:51 The Need for Improved Tooling27:08 The Role of OSCAL in Trusting Tooling28:31 Tools for Managing Disparate Scanning Results29:52 The Challenge of Limited Authorizations30:51 Collaboration and Human Readability in OSCAL34:07 The Need for Connected Governance36:27 Measuring the Success of Continuous Monitoring

Most organizations overlook the secret ingredient to cybersecurity success: culture. In this eye-opening episode, cybersecurity veterans Russell Eubanks and AJ King reveal how building a strong security culture isn’t just good practice, it's essential. They share powerful stories demonstrating what a thriving security culture looks like and how it can prevent costly breaches. Discover why aligning mindsets and fostering collaboration across teams can transform security from a challenge into a strategic advantage. Perfect for leaders eager to embed security into their organization's DNA, this conversation offers proven strategies to transform your mindset—and your defenses.00:00 Introduction to Security Culture02:27 The Importance of Culture in Cybersecurity05:19 Examples of Good and Bad Security Culture11:01 Comparing Security Cultures Across Organizations18:35 Common Pitfalls in Enhancing Security Culture21:58 Integrating Security into Organizational Culture23:45 The Role of Non-Security Management26:35 Empowering All Employees in Security29:28 Phishing Exercises: A Double-Edged Sword38:25 Key Takeaways for Executives and Non-Executives

In this episode of "This is Fine," AJ King, Alex Sharpe, and Jake Williams delve into the complexities of the Zero Trust framework and its overlay against NIST 800-53 R5. They explore the philosophical and practical aspects of Zero Trust, emphasizing its role in modern cybersecurity. The discussion highlights the challenges and strategies for implementing Zero Trust, particularly in government and commercial sectors. The episode concludes with insights on how organizations can approach Zero Trust as an evolving mindset rather than a fixed goal.Episode Chapters: 00:00 Introduction to Zero Trust and NIST 800-5305:37 Challenges in Implementing Zero Trust11:18 The Role of Identity in Zero Trust17:11 The Evolution of Zero Trust22:29 Final Thoughts on Zero Trust Implementation

In this episode of This is Fine, cybersecurity experts AJ King, Joshua Marpet, and Jake Williams dive into the complexities of pen testing. They explore why standardization is crucial for effective testing and how misconceptions can lead to security gaps. Discover the importance of proper scoping to focus on high-impact areas and why a pen test should simulate real attack scenarios. This discussion is essential for security leaders aiming to enhance their testing programs and communicate value across teams. Learn how to turn pen testing into a strategic security pillar and make smarter cybersecurity investments.00:00 Introduction to Pen Testing and Cybersecurity Experts02:02 Common Misconceptions About Pen Testing07:35 The Need for Standardization in Pen Testing10:49 Defining Pen Testing: Dimensions and Attributes16:51 The Role of Compliance in Pen Testing21:57 The Impact of Breaches on Shareholder Value23:15 The Impact of Cyber Insurance on Business Operations25:59 Understanding the Role of CISOs in Cybersecurity27:34 Challenges in Scoping Penetration Tests30:38 The Importance of Standards in Cybersecurity33:33 Regulatory Environment and Its Influence on Cybersecurity36:23 The Role of Regulation in Cybersecurity Standards39:14 Defining Objectives for Effective Penetration Testing41:31 Maximizing Value from Penetration Testing Budgets

Most organizations dramatically underestimate how quickly offensive cyber techniques evolve—and how crucial stealth and rapid detection truly are. In this episode, Jake Williams, a cybersecurity veteran, joins Hunter Strategy’s AJ King and Jordan Lazo to expose the real tactics behind cyber warfare—and how your organization can keep pace. Discover why the myth of complex, Hollywood-style attacks is just that, and why most breaches happen through simple social engineering or widespread credential theft. Tune in now to master the art of cyber resilience in a hostile digital landscape—because in cyber warfare, the winners are those who adapt first.Episode Chapters: 00:00 Introduction to Cybersecurity and Nation-State Threats04:46 The Rise of Zero-Day Exploits12:23 Common Misconceptions in Offensive Cyber Operations18:15 The Reality of Cyber Attacks25:33 Public-Private Collaboration in Cybersecurity30:15 Staying Ahead in Offensive Operations