Home Podcasts The Art of Security
The Art of Security

The Art of Security

Fortra 16 Episodes Jul 22, 2026

Cybersecurity isn't an exact science. It's where art and science meet, informed by experience, tested in battle and reimagined to tackle evolving adversaries. In The Art of Security, Josh Davies and Tyler Reguly break down how security actually works in practice. From zero-day exploits and emerging threats to rethinking long-standing best practices, they explore what holds up — and what doesn't — in today's rapidly changing landscape. Each episode delivers practical insights, informed perspectives, and real-world context to help security professionals and tech enthusiasts stay ahead of evolving threats and build smarter, more resilient defenses.

Episodes

AI Governance in Action: How to Secure AI Without Slowing Innovation
AI Governance in Action: How to Secure AI Without Slowing Innovation Jul 22, 2026 35:25 Your AI has access. But does It have too much? AI can help organizations move faster, automate work, and unlock new opportunities. But when AI systems can access sensitive data, connect to business tools, or take actions on a user's behalf, governance becomes an operational security priority. In this episode of The Art of Security, co-host Josh Davies speaks with Gina Cardelli, Principal Security
Not Curious? Cybersecurity Isn't the Career for You — A Student's Honest Take
Not Curious? Cybersecurity Isn't the Career for You — A Student's Honest Take Jul 8, 2026 47:26 Is cybersecurity really facing a skills shortage or are businesses just unwilling to train the next generation? In episode 10 of The Art of Security, Josh Davies and Tyler Reguly are joined by Dema Gorkun, cybersecurity student at MacEwan University, leader of the Student Ethical Hacking Club, and OWASP collaborator. Dema shares a candid student's-eye view of what today's cybersecurity education g
What Canada's Bill C-8 Means for Cybersecurity
What Canada's Bill C-8 Means for Cybersecurity Jul 1, 2026 04:51 Canada's Bill C-8 has received Royal Assent. But what does that actually mean for cybersecurity teams, critical infrastructure operators, telecommunications providers, and vendors selling into Canadian organizations? In this bonus episode of The Art of Security, Brent Arnold of INQ Law about the impact of Bill C-8, also known as An Act Respecting Cyber Security. They discuss the law's focus on tel
After the Breach: Ransomware, Data Loss, and the Legal Fallout
After the Breach: Ransomware, Data Loss, and the Legal Fallout Jun 24, 2026 45:54 What really happens after a data breach? In this episode of The Art of Security, hosts Josh Davies and Tyler Reguly are joined by Brent Arnold of INQ Law to unpack the legal, operational, and business fallout that follows a breach. From ransomware negotiations and breach reporting obligations to data loss, regulatory risk, and recovery planning, Brent shares what organizations need to know when a
Learning Cybersecurity: Education, Experience, and AI
Learning Cybersecurity: Education, Experience, and AI Jun 10, 2026 44:14 Cybersecurity is one of the few professions where the learning never stops. New technologies, evolving threats, and the rapid rise of AI constantly reshape what security professionals need to know. In this episode of The Art of Security, Josh Davies and Tyler Reguly sit down with Dr. Mansour Alqarni of Fanshawe College to explore the current state of cybersecurity education and what it takes to bu
Named Vulnerabilities, CVEs & the Problem With Security Hype
Named Vulnerabilities, CVEs & the Problem With Security Hype May 27, 2026 37:22 Why do vulnerabilities like Heartbleed, PrintNightmare, and Log4Shell get memorable names while thousands of other CVEs go unnoticed? In this episode of The Art of Security, Josh Davies and Tyler Reguly debate whether named vulnerabilities help cybersecurity awareness or create dangerous hype cycles. From CVE identifiers and responsible disclosure to media sensationalism and "boy who cried wolf" f
Supply Chain Compromise: Trust Is the Target
Supply Chain Compromise: Trust Is the Target May 13, 2026 31:38 We're told to patch fast, trust updates, and rely on the software ecosystems that power modern business. But what happens when that trust becomes the attack vector itself? In this episode of The Art of Security, Josh Davies and Tyler Reguly dive into the growing world of software supply chain compromise — from malicious open source packages and compromised dependencies to sleeper-agent style attac
The Art of Collective Defense
The Art of Collective Defense Apr 29, 2026 38:05 When one organization gets breached, attackers don't just win — they get better. In this episode of The Art of Security, we explore a powerful idea: Cybersecurity isn't a solo fight but a shared one. And when defenders collaborate, everyone gets stronger. Josh Davies and Tyler Reguly are joined by Jennifer Quaid and Bob Gordon from the Canadian Cyber Threat Exchange (CCTX) to break down what effec
Stop Patching Everything: Rethinking Vulnerability Management with RSnake
Stop Patching Everything: Rethinking Vulnerability Management with RSnake Apr 15, 2026 32:29 In this episode of The Art of Security, Josh Davies and Tyler Reguly take a hard look at vulnerability management (VM) — one of the oldest and most widely adopted practices in cybersecurity — and ask a simple question: are we doing it wrong? Joined by special guest Robert "RSnake" Hansen, we unpack the critical differences between vulnerability management and patch management, and explore why trea
Trust No One (Especially on April Fools)
Trust No One (Especially on April Fools) Apr 1, 2026 33:41 It's April 1st which means nothing can be taken at face value. In this special April Fools' episode of The Art of Security, Josh Davies and Tyler Reguly dive into the long history of pranks in tech and cybersecurity — from spaghetti trees and RFC jokes to Google's legendary gags. But this isn't just a nostalgia trip as Tyler and Josh discuss humor, history, and have a serious conversation about tr
The Art of the Adversary: Scripted Sparrow
The Art of the Adversary: Scripted Sparrow Mar 18, 2026 34:38 Business email compromise is getting smarter, and Scripted Sparrow is proving it. Discover how the Scripted Sparrow threat group is running one of the most prolific BEC campaigns targeting organizations worldwide. In this episode of The Art of Security, we're joined by Fortra cybersecurity researcher John Wilson who breaks down how Scripted Sparrow executes highly targeted social engineering attac
Who Watches the Watchman?
Who Watches the Watchman? Mar 4, 2026 31:25 In this episode, Tyler Reguly and Josh Davies dig into a tough but necessary question: Who's keeping an eye on the people who keep us secure? They break it down across three fronts — security vendors, internal security teams, and third-party providers — exploring what happens when the protectors themselves become the risk. From vendor breaches that ripple across customers to insider threat cases i

Recommended