
The Tea on Cybersecurity
Cybersecurity is a term we hear constantly, but many don't truly understand what it involves. This podcast strips away the confusing jargon to explain security and compliance in plain, actionable language. Each episode offers practical insights tailored for SaaS startups and small to medium-sized businesses beginning their cybersecurity journey. Episodes are kept short, typically 15–30 minutes, delivering essential facts without unnecessary filler.
Episodes

Key Takeaways from Season 5 of The Tea on Cybersecurity
On Season 5 of The Tea on Cybersecurity, one thing became clear: security is not a one-and-done deal. It’s a continuous journey.In this episode, host Jara Rowe wraps up the season by highlighting the key takeaways and tackling the biggest myths and misconceptions in cybersecurity and compliance. She also discusses how businesses can future-proof their security posture by focusing on Continuous Thr

Making Continuous Security Work: Inside the CTEM Framework
For SMEs and startups, things are always changing—new projects, growing teams, and evolving products. Amidst this growth, cybersecurity often takes a backseat. However, protecting your business from cyber threats is more important than ever.In this episode, Anh Pham, Director of Penetration Testing and Security at Trava, explains how a robust Continuous Threat Exposure Management (CTEM) framework

Boost Your Cybersecurity with Continuous Threat Exposure Management (CTEM)
Your business is constantly evolving. But how do you know where the weak spots are or which ones actually matter? In a fast-moving environment, understanding your vulnerabilities before attackers do is critical.In this episode, Anh Pham, Director of Penetration Testing and Security at Trava, breaks down why more businesses are moving toward Continuous Threat Exposure Management (CTEM). Anh explain

This is Your Cybersecurity Action Plan to Keep Your Business Safe in 2026
As the new year approaches, now’s the time to refresh your cybersecurity strategy and kick old habits to the curb.In this special episode, Jara Rowe asks Trava experts one simple question: What should businesses focus on in 2026? Tune in for actionable advice that can immediately strengthen your business's security. From implementing essential tools to adopting best practices, these tips can m

Keeping Up with Compliance: The Work That Comes After Certification
Many small and mid-size businesses breathe a sigh of relief once they earn a compliance certification, but the work doesn’t stop there. Certifications like SOC 2, ISO, or CMMC aren’t one-time milestones. They’re ongoing commitments that require fresh evidence, updated controls, and regular monitoring.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, breaks down the reality of

You Bought a Compliance Automation Tool... Now What?
Your compliance tools and automation say you're in the clear. Everything’s marked complete, deadlines are met, and the compliance dashboard is all green.But when it’s time for the audit, you’re still unprepared.In this episode, Kaitlin Zanoni, Security Advisor at Trava Security, breaks down the reality of compliance automation. She explains where these tools add real value, where they fall sho

SOC 2 Without the Stress: What Startups Should Do to Prepare
If your business handles customer data, SOC 2 is not optional.It may not be on your radar today, but it will be soon. And when that time comes, how early you started will make all the difference.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, explains what it takes to prepare for SOC 2 certification. She shares what early prep should look like, how to make the audit less st

SOC 2 Certification in 60 Days? Here’s What They’re Not Telling You
Some companies boast about earning their SOC 2 certification in just two months. While technically possible, that speed usually comes with stress, shortcuts, and costly tradeoffs.In this episode, Marie Joseph, Manager of Compliance Advisory at Trava, explains why true SOC 2 compliance takes more than 60 days. She breaks down the difference between Type 1 and Type 2 reports, outlines what a realist

Introducing Season 5 of The Tea on Cybersecurity
Cybersecurity can feel overwhelming with its many acronyms, shifting rules, and conflicting advice.That’s why Season 5 of The Tea on Cybersecurity is all about separating fact from fiction. Host Jara Rowe kicks things off by identifying the common questions business leaders have about SOC 2 certification, automation tools, and AI policies. This season keeps episodes short and to the point, so you

Key Lessons from Season 4 of The Tea on Cybersecurity
If there’s one key takeaway from Season 4 of The Tea on Cybersecurity, it’s that cybersecurity is a shared responsibility. With this in mind, host Jara Rowe wraps up the season by sharing valuable insights that everyone can use. She reflects on the most impactful lessons about compliance, AI, and penetration testing. Key takeaways:The importance of vCISOs and cyber engineersHow to approach penetra

Breaking Down PTaaS: Continuous Security for Modern Companies
Most companies continually push code, launch new features, and update their infrastructure. However, for many businesses, security testing occurs only once a year. That gap leaves systems exposed to risks that go unnoticed.In this episode, Anh Pham, Director of Penetration Testing at Trava, explains the concept of Penetration Testing as a Service (PTaaS). He shares how it works and why it's mo

Understanding Cyber Engineering to Build Stronger Security
Cyber engineering is a broad and often misunderstood field, covering everything from cloud architecture to compliance. But one thing is clear: someone needs to take responsibility for the security of your business’s digital infrastructure.In this episode, host Jara Rowe is joined by Michael Magyar, vCISO at Trava Security, to explore the intersection of cybersecurity, compliance, and engineering.

The Core Pillars of AI Governance
The rapid adoption of AI brings opportunities, yet new risks. Strong governance enables organizations to remain innovative while maintaining trust and protecting data.In this episode, host Jara Rowe welcomes Jim Goldman, Co-Founder of Trava Security, to discuss how clear oversight, board engagement, and high-quality data enable the creation of ethical AI that aligns with business goals.They outlin

Don’t Overtrust the Robots: The Real Tea on AI Compliance
Businesses rely on AI for everything from streamlining communication to managing hiring and forecasting trends. It’s fast, efficient, and deeply embedded in daily operations. But as AI becomes more common, one critical piece is often overlooked: compliance.In this episode, Jara Rowe sits down with Dr. Marwan Omar, Chief AI Officer at Insight Assurance, to talk about the growing need for AI complia

Proving Compliance and Security Effectiveness Through Pen Testing
Many companies start penetration testing to address compliance requirements. However, it can also provide valuable insights beyond just meeting standards.In this episode, host Jara Rowe sits down with Anh Pham and Christina Annechino from Trava to talk about how pen tests uncover hidden risks and strengthen your cybersecurity. They explain compliance frameworks, typical pen test schedules, and com

Getting CMMC Right: Scope, Budget, and Certification Tips
Think compliance is just an IT problem? It’s a revenue problem, too. Without it, some contracts will stay out of reach.In this episode, Jara Rowe talks with Tom Greco, vCISO at Trava Security, about what companies need to know about the Cybersecurity Maturity Model Certification (CMMC). It’s a Department of Defense requirement that verifies whether companies are securely handling Controlled Unclas

Security Leadership Without the Full-Time Price Tag for Small Teams
Is your business one cyberattack away from chaos? Most companies don’t think about cybersecurity until they’re in crisis mode—but by then, the damage is done.In this episode, Jara Rowe talks with Michael Magyar, an experienced virtual Chief Information Security Officer (vCISO). They cover what a vCISO does, why more companies are choosing virtual over full-time, and how to know when it’s time to b

Cybersecurity Lingo Explained: vCISO, PII, and More
Cybersecurity lingo can be overwhelming, but once you get the hang of the essentials, staying secure becomes much easier.In this episode, host Jara Rowe sits down with Marie Joseph, Senior Security Advisor at Trava, to break down key terms like vCISO, PII, and cybersecurity maturity models. They also differentiate between terms like hacker vs. threat actor and firewall vs. antivirus by highlightin

Introducing Season 4 of The Tea on Cybersecurity
Cyber threats are evolving, security rules are tightening, and the idea of a ‘safe network’ is quickly disappearing. So what does that mean for businesses and individuals trying to stay protected?To kick off Season 4, host Jara Rowe revisits key lessons from past seasons and unpacks the biggest cybersecurity trends shaping the industry today. This season will take a deeper look at AI governance, c

Recap on Season 3 - Receipts on The Tea on Cybersecurity
We’ve come to the end of another Season of The Tea on Cybersecurity and you know what that means. Join host Jara Rowe in her ultimate receipts from season 3. She highlights the most important things she has learned from her guests this season including why MFA is key to keeping yourself safe online, how to manage vulnerabilities, what steps you need in preparing for cybersecurity incidents, and ho

Beyond SaaS: What Cybersecurity Looks Like in Healthcare and Banking
"Multi-factor authentication? You better get it today. Don't wait till tomorrow." – Jim GoldmanWe talk a lot about SaaS companies in this show, but today, we’re bringing you something a little different. Jim Goldman, CEO of Trava and one of our favorite cybersecurity experts, joins host Jara Rowe to discuss the complexities of cybersecurity across healthcare and banking, including th

Identifying Third-Party Vendor Risks with Michael Magyar, Trava
"Every business today runs on technology. Every business is a technology business. Right? Even a taco cart uses a little payment thing that you swipe your card in to do that." - Michael MagyarMichael Magyar, a seasoned cybersecurity expert with a decade of experience, joins host Jara Rowe on this episode of The Tea on Cybersecurity to give us the tea on third-party risks. As a penetratio

Cyber Trust and Transparency with John Boomershine, BlackInk IT
“Trust is foundational to both the relationship, interpersonal relationship, B2B relationship. Then also we're having to convey that trust to our customers," - John BoomershineJohn Boomershine– also known as Boomer– sits down with host, Jara Rowe in this episode of The Tea on Cybersecuity to talk about trust and transparency in cybersecurity. As the Vice President of Security and Complian

Defending Your Data Through Cyber Hygiene with Industry Experts Craig Saldanha and Mario Vlieg, Insight Assurance
“Education is by far the most cost-effective tool that you can deploy in your organization before any other types of information, security controls, or complex tools or any additional services. Using the hygiene analogy, you can buy the most expensive toothbrush, and you can buy the fanciest toothpaste. But if you don't teach your child that they need to brush their teeth every night, they'

Mastering Incident Response Plans and Tabletop Exercises with Christina Annechino, Trava
“Especially if this is the first time an organization is creating a plan like this, the focus should really be working on it piece by piece to not be overwhelmed. So, start outsmall. What are the designated roles and responsibilities that you have? Then, determine how the plan can best fit your needs. This can be done by assessing what types of incidents are most detrimental to your organization.”

Navigating Asset Management and Compliance with Marie Joseph, Trava
“Keeping the inventory up to date, make sure that you have all possible points of entry covered and accounted for, similar to a building. When people try to put safeguards for a building, you're doing it, but just like on a network that you can't really physically see if you're missing an asset, that is a hole for an attacker to get into, and we do not want to give them easy access to

Deciphering Risk Management and Compliance with Michael Magyar
“Not only do we need to understand what risks might exist, but we need to understand what impact that might have. That goes into both the chance that they're going to happen and the chance that they're going to be successful in creating damage, and then also the likely damage that's going to happen from them.” - Michael MagyarOn this week’s episode, host Jara Rowe gets the tea on risk

Why Vulnerability Management Matters for Cybersecurity Compliance
“So the concept of vulnerability management in many ways is universal. And so if we think about it in a physical sense, try to keep our homes or our businesses secure from a physical sense. It's one of the vulnerabilities. Leaving your doors unlocked, leaving your windows unlocked, leaving a candle lit, and then leaving the house and going somewhere. Those are vulnerabilities.” - Jim GoldmanJo

Understanding Cybersecurity Frameworks and Certifications with Scott Schlimmer, Trava
“Find a compliance platform, it'll make life a lot easier. Then I would develop the policies and procedures, if you don't already have those, and then collect evidence to justify, to prove everything you're doing that's in the framework. It's going to be important for audits and just internal or external audits.” - Scott SchlimmerIn this episode, host Jara Rowe is once again jo

Cybersecurity Compliance Buzzwords with Marie Joseph and Christina Annechino, Trava
“It's hard to have privacy without security and to have effective security that requires strong protection of personal identifiable information, or PII. So security, privacy, and compliance really must go hand in hand. If one is prioritized over the other, it can have an adverse effect.” - Christina AnnechinoOn this episode, we welcome back both Christina Annechino and Marie Joseph to bring us

Cybersecurity in 2024: Trava’s CEO Jim Goldman on What to Expect
“There's a converging of several forces or several trends going on right now that I think are going to potentially cause significant changes in 2024.”@Jim Goldman, CEO of Trava Security, knows a thing or two about cybersecurity. In this episode, Jim and host @Jara Rowe dive into the latest scoop on what's happening in the world of cybersecurity and compliance and what you need to know to k

Introducing Season 3 of The Tea on Cybersecurity
You asked for it, so we’re back for another season of your favorite cybersecurity podcast, The Tea on Cybersecurity. In the last two seasons, host Jara Rowe covered everything from the basics – what is phishing? – to implementation – do I need cyber insurance? This season, we dive deep into compliance but, true to our word, simplify things and cover more basics – a must-listen boost your cybersecu

Spilling The Tea from Season 2 - Receipts from The Tea on Cybersecurity
"Having a really thorough cybersecurity plan is essential. It's honestly what everything comes down to."We’ve reached the end of season 2 of the Tea on Cybersecurity, where we wrap up the season with the most important receipts learned from previous guests.In this episode, we touch on the importance of conducting cyber risk assessments to understand the current risks in your business

Cybersecurity Awareness Training is Not an Option, It’s Essential with Kathy Isaac, VP of Customer Success at Carbide
"Cybersecurity awareness training is not about creating cybersecurity experts. It's about making staff and stakeholders aware of the threats and how to respond to them."In this episode of The Tea on Cybersecurity, VP of Customer Success at Carbide, @Kathy Issac, joins host @Jara Rowe to discuss the ins and outs of cybersecurity awareness training and why every company must partake in

Locking Down Your Virtual Office: Cyber Security for Remote Workers with Anh Pham
"The shift to remote work has transformed the cybersecurity landscape, forcing companies to rethink their approach to protecting their attack surface."In this episode of The Tea on Cybersecurity, @Jara Rowe sits down with Trava Senior Security Engineer @Anh Pham to discuss the blend of remote work and cybersecurity. The shift to remote work has significantly transformed the cybersecurity

The Power of Proactive Protection in Cyber Risk Management and Beyond with Jim Goldman and Ryan Dunn
"Proactive protection is not just about fixing vulnerabilities, it's about implementing a comprehensive security strategy and understanding your system boundaries and actively defending against cyber threats before they can breach your defenses."In the latest episode of The Tea on Cybersecurity, @Jara Rowe talks with @Jim Goldman and @Ryan Dunn to uncover the importance of being proactive in cyber

Cyber Insurance Decoded: A Focus on SaaS Companies with Trava’s Director of Insurance, Ryan Dunn
"Whenever you have a piece of software that has an obligation to perform a duty, like a SaaS company, the intersection of cyber insurance and professional liability is crucial. It's important to transfer the risk with a comprehensive cyber insurance policy to protect against both code failures and potential cyber breaches."In the latest episode of The Tea on Cybersecurity, @Jara Rowe chats with @R

Unveiling Vulnerabilities: The Power of Pen Testing in Cybersecurity with Christina Annechino, Cybersecurity Analyst at Trava
"It's easier to protect your company's assets when you know exactly what your security posture looks like and where your problems are."In the latest episode of The Tea on Cybersecurity, @Jara Rowe chats with @Christina Annechino, Cybersecurity Analyst at Trava, to delve into the world of penetration testing or “pen Testing” and its significance in the realm of cybersecurity.Pen T

Balancing Ethics and Regulations: The Challenge in MarTech's Customer Information with Chris Vannoy, Product and Engineering Leader
"The more data you have, the more painful it's going to be if you mess up your cybersecurity and all that leaks out."On the most recent episode of The Tea on Cybersecurity, host Jara Rowe is joined by Chris Vannoy from The Juice, a renowned MarTech firm, to dive into a discussion about data protection. Chris underscores the significance of SOC2 processes in ensuring data precision an

Protect Sensitive Data: Understanding Privacy and Security Certifications with Marie Joseph, Senior Security Solutions Engineer at Trava
"Security is all about the protection of your data. While privacy is determining how your data is being used."On this episode of The Tea on Cybersecurity, join host Jara Rowe as she delves into the world of privacy and security certificates with expert guest @Marie Joseph, Senior Security Solutions Engineer at Trava.Protecting sensitive data has become more important than ever. But with

Audits Vs. Assessments: What's the Difference and Which Is Right For You? With Jim Goldman and Ben Phillips
"The thing about security also is the threats are always changing. So you can't just keep doing what you've been doing and think you're going to be fine. You have to adapt to the changing threat landscape."In the world of Cybersecurity, things are everchanging. This week Cybersecurity expert and CEO & Co-Founder of Trava Security Jim Goldman and Ben Phillips CPA and Direc

A Crash Course in the Benefits of ISO 27001 Certification with Anh Pham and Marie Joseph
“When a customer compares between vendors, the one with an ISO certification is going to have an edge.”We’ve covered the concept of compliance frameworks in previous episodes, but now we’re taking a deep dive into what it takes to obtain a specific certification: ISO 27001.If you’ve ever wondered about the benefits of ISO compliance and the potential challenges you may face during the certificatio

SOC2, ISO, and Beyond: Navigating Privacy Compliance Frameworks with Marie Joseph, Senior Security Solutions Engineer at Trava
“Compliance isn’t something that happens overnight.”If the phrase ‘compliance frameworks’ makes you want to run for the hills, hang in there – we've got you covered. In this conversation, Marie Joseph, Senior Security Solutions Engineer at Trava, unpacks the different compliance frameworks and explains which certifications you need to meet your business goals. While compliance frameworks aren’

Cyber Risk Assessments: Uncovering Your Security Vulnerabilities with Jim Goldman, CEO and Co-Founder of Trava
“A cyber risk assessment is nothing more than a diagnosis.”As a small or medium business, you may assume you’re not a primary target for cyber attacks. Cybersecurity expert and CEO & Co-Founder of Trava Security Jim Goldman reveals that small and medium businesses are actually more likely targets than large enterprise customers. Whether you’re a Fortune 500 company or a brand-new startup, it&#

Introducing Season 2 of The Tea on Cybersecurity
We’re back for the second season of your favorite cybersecurity podcast, The Tea on Cybersecurity. In season one, host Jara Rowe covered the basics of cybersecurity for SaaS companies, and season two will take a deeper dive into newer topics, such as cyber risk assessments, compliance frameworks, and security certifications. The podcast is a must-listen for decision-makers with cybersecurity tasks

Recap of Season 1 - Receipts from The Tea on Cybersecurity
We did it! We made it to the end of season 1 of The Tea on Cybersecurity.So we’ve spilled the tea on a lot of cybersecurity in Season 1, but now it’s time for some mega receipts. Podcast host, Jara Rowe, breaks down what past guests have shared with listeners that are essential to keep in mind - what cybersecurity truly means, why it’s important, how it should be implemented, and when you should t

Implementing Cyber Security and Why You Should do it NOW with Jake Miller
“It’s so important to build your security programs early on because there's an expectation in the market, especially for enterprise grade SaaS companies, that you have at least started to take those programs seriously.”Jake Miller, the Chief Executive Officer of the Engineered Innovation Group, has a long background in software and product development and focuses on helping companies to design

Cyber Insurance: When, How, and Why You Need It with Limit’s Shea McNamara
“Because people don’t fully understand technology, hackers and criminals find this as an opportunity to attack and get an edge. This is why cybersecurity is so important.”Shea McNamara, the Co-Founder and Head of Sales at Limit, focuses on melding technology and risk management for people and businesses around the world so they can achieve their aspirations. Due to the increasing amounts of cyber

Starting a Security Program by Choice or by Force with Trava’s Marie Joseph
“Two-thirds of small, medium-sized businesses are the ones that are most attacked. Hackers specifically look for these!”Marie Joseph, the Security Solutions Engineer at Trava, specializes in helping companies start their security program, and/or help mature it. With the rise in attacks of cyber security in businesses, Marie talks all about when the appropriate time to start a security program to a

The Blame Game: Trava’s Scott Schlimmer Talks Who’s at Fault in a Security Breach
"Make sure you stay up to date on the latest trends and technologies - it's the key to success!"As a Cyber Risk Specialist at Trava, Scott Schlimmer is in charge of evaluating a company’s security posture and creating a plan on how to best strengthen security and reduce risk. But the question he is answering today is WHO’S TO BLAME?? Cybersecurity risk can be a scary subject for any company, and o

What will 2023 Bring in Cybersecurity? Predictions with Jim Goldman, CEO and Co-Founder of Trava Security
"You don't have to be perfectly secure. You just have to be more secure than the next business."Jim Goldman has been in the cybersecurity sector for over 30 years—he’s seen some things. Which made him the perfect person for Jara to speak with about what will be on the horizon in the world of cybersecurity in 2023. In this episode, Jim warns of potentially dangerous trends around AI and cyber-warfa

Explain SOC 2 to Me Like I’m a Child: with Marie Joseph, Senior Security Solutions Engineer at Trava
Marie Joseph knows a thing or two about security compliance. As a Senior Security Solutions Engineer at Trava Security, Marie helps clients through the process of becoming SOC 2 certified…. but what is SOC 2?In this episode, Marie helps us get to the bottom of what SOC 2 certification is and why it’s important for companies to attain. Listen in for the 101 on SOC 2, ISO 27001 and GDPR (that’s a lo

Getting Risky: Cybersecurity & Compliance with Casted CPO, Adam Patarino
“In order to make sure that we are trusted and our customers feel safe uploading and managing their content with us, we have to show that we take compliance seriously.”Successes compliance strategies aren’t always easy, but boy are they necessary. In this episode of The Tea on Cybersecurity, host Jara Rowe speaks with Adam Patarino, CPO and Co-Founder of Casted, a podcast and video content marketi

You Are the Weakest Link! (In Cybersecurity) with Trava Security CTO, Rob Beeler
Everything in the world revolves around people, including cybersecurity.We all know people are complex, unique, and full of surprises, making it hard to guess what they will do. This unpredictability causes a headache for companies when it comes to cybersecurity.In this episode of The Tea on Cybersecurity, host Jara Rowe dives into the human element of protecting yourself with Trava’s CTO and Co-F

The Importance of Cybersecurity Strategies in Small Businesses with Trava Security CEO, Jim Goldman
If the check engine light came on in your car, would you go to an auto parts store and grab random items to fix the problem? Unlikely. So why do business owners take that hap-hazard approach to protecting themselves against cyberattacks? In this episode of The Tea on Cybersecurity, Jim Goldman, CEO and Co-founder of Trava Security, shares why having a risk management plan and creating a cybersecur

Phishing you say? Like with a pole? Cybersecurity Terms with Trava Security CTO, Rob Beeler
If you ignore cybersecurity threats, it’s only worse in the end since hackers are smart, and it’s a never-ending web of attacks and breaches. Understanding what those threats are is the first step.In this episode of The Tea on Cybersecurity, host Jara Rowe dives into the complicated world of cybersecurity terminology with Trava’s CTO and Co-Founder, Rob Beeler. They discuss common terms like phish

Cybersecurity 101 with Jim Goldman, CEO and Co-Founder of Trava
Jim Goldman began his career as a Professor of Network Engineering at Purdue University back when the world was only starting to understand the internet. As times have changed, so has Jim, and today he’s the CEO and Co-Founder of Trava Security. Network security, now called cybersecurity, has expanded exponentially, touching everything with a microchip and more.In this episode of The Tea on Cybers

Introducing the Tea on Cybersecurity
Cybersecurity—a word we hear all the time. Show of hands for those that actually understand what it means.The Tea on Cybersecurity is here to help educate the newbs on what cybersecurity is, why it is important, and everything in between. The Tea on Cybersecurity is for everyone, but especially those small and medium sized businesses that are starting their journey in building a cyber risk managem











