Find partners
Security Cocktail Hour

Security Cocktail Hour

Hosted by Joe Patti and Adam Roth

TechnologyInterviews guests

Episodes

86

Latest episode

Aug 2026

Language

EN-US

About the show

Security veterans Joe Patti and Adam Roth welcome a diverse lineup of cybersecurity and information security experts to share their insights at the virtual bar. From cutting edge topics like AI and Operational Technology (OT) to the realities of careers and mental health, you'll get the inside view of what's happening across the industry and what it's really like to work in these fields, from the people who do it every day. Reach us at feedback@securitycocktailhour.com or @SecCocktailHour on Twitter.

Listen to episodes

60 recent
August 18, 2026Episode 8236 min

Michael Simmons: Raw Vulnerability Scans Are Not Security

Running a vulnerability scan is easy. Deciding what matters, what is noise, and what a business should do next is the real work. Michael Simmons, founder of Elysium Trace, joins Joe Patti and Adam Roth to discuss business-focused vulnerability reporting for MSPs, IT consultants, and smaller security teams. They cover false positives, context, risk acceptance, repeatable reporting, automation, and why human judgment still matters. Michael describes Elysium Trace and its product approach from his own experience. Learn more: https://elysiumtrace.com/

July 22, 2026Episode 8146 min

Gaurav Keerthi: Why Most Companies Can’t Afford Cybersecurity

Cybersecurity was built for enterprises. Gaurav Keerthi explains what that leaves behind for the companies without a cyber team, and why their exposure becomes everyone else’s problem. Gaurav, CEO of StrongKeep and a cybersecurity leader in the public and private sectors, joins Joe Patti and Adam Roth to break down why smaller organizations are still expected to buy, operate, and manage enterprise-style security. They discuss supply-chain risk, the “hopes and prayers” gap, cybersecurity’s IKEA problem, and what a usable baseline could look like for ordinary companies. Episode Takeaways: Most organizations do not have a dedicated cybersecurity professional. Enterprise security programs cannot fully protect an organization when exposed suppliers remain unprotected. Security products need to be simpler, more bundled, and more realistic for companies without specialist teams. Doing something proportionate is better than doing nothing while waiting for a perfect plan. Guest: - Gaurav Keerthi, CEO, StrongKeep - LinkedIn: https://sg.linkedin.com/in/gaurav-keerthi - StrongKeep: https://www.strongkeep.com/ Resources: - CyCon: https://cycon.org/ - NATO Cooperative Cyber Defence Centre of Excellence: https://ccdcoe.org/ Security Cocktail Hour Podcast: - https://securitycocktailhour.com

July 8, 2026Episode 8054 min

Eva Galperin: Stalkerware, Surveillance, and Real-World Harm

Eva Galperin explains how stalkerware, ordinary phone access, coercion, and weak privacy defaults can let someone close create devastating real-world harm. In this episode, we cover: What stalkerware is and why hiding from the user matters Why intimate-partner abuse changes the cybersecurity threat model Privacy as consent and control, not isolation Why end-to-end encryption is not magic if the endpoint is compromised Password managers, VPN myths, patching, and backups What security teams miss when they only focus on exotic adversaries Guest: Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware. Resources: EFF Surveillance Self-Defense: https://ssd.eff.org/ Coalition Against Stalkerware: https://stopstalkerware.org/

June 30, 2026Episode 7949 min

Full Interview: Chad Butler on Drones, AI, and Autonomous Failure

This is the full interview version of our conversation with Chad Butler. Chad previously worked in product security at Amazon and was involved with Prime Air, Amazon's drone delivery program. He joins Joe Patti and Adam Roth to talk about drone delivery, FAA rules, GPS spoofing, detect-and-avoid, ADS-B, autonomous vehicles, AI agents, and the engineering culture needed when software failures can become physical-world safety failures. Topics include: Prime Air and product security commercial drone delivery risk Part 107 and Part 108 beyond visual line of sight operations GPS spoofing and drone capture detect-and-avoid vs right of way ADS-B tradeoffs why pilots may not reliably see drones autonomous vehicles and AI agents adversarial inputs and edge cases public trust after catastrophic failures Challenger, Feynman, and ignored engineering warnings

June 26, 202626 min

Autonomous Systems Have a Security Problem with Chad Butler

Autonomous systems are already moving into the physical world. Drones can fly themselves, robot taxis are carrying passengers, and AI systems are taking more action without direct human control. Chad Butler joins the Security Cocktail Hour to explain why that changes the risk model. The issue is what happens when autonomous systems make real-world decisions from sensor data, routing logic, and AI-driven judgment that may be wrong, spoofed, or manipulated. In this feature version, Chad talks with Joe Patti and Adam Roth about: GPS spoofing and drone capture beyond visual line of sight drone operations trusted and untrusted sensor data AI agents and autonomous vehicles why optimal-environment testing is not enough why "nobody will do that" is not a defense how cyber failures can become safety failures what Challenger and Feynman still teach us about launch pressure and ignored warnings This is a feature cut of the conversation. Th full interview will be released soon.

June 17, 202617 min

Drone-based Hacking Explained with Luke Canfield

This time we’re revisiting our conversation with Luke Canfield and focusing on how drones are becoming a cybersecurity problem. Luke walks through war-flying, drone-mounted Wi-Fi Pineapples, rogue access points, cartel drone operations, prison contraband drops, hybrid warfare, and why most security teams are still thinking too flat. The core takeaway: security exists in three dimensions now, and defenders need to start looking up. Full original episode with Luke Canfield: https://open.spotify.com/episode/18TYWLjiLpqGX995iDmqdL?si=67c757474cc84d33 Security Cocktail Hour: https://securitycocktailhour.com

June 2, 2026Episode 7846 min

Charles Bolden: Why Space Is Not Air-Gapped

Former NASA Administrator and astronaut Charles Bolden joins the Security Cocktail Hour to explain why space is not as isolated as people assume. We cover: Why mission control still sits in the middle Why messages get routed, reviewed, and filtered before reaching a vehicle How consumer devices expand the attack surface in space What cooperation in orbit teaches about security and civics Why he does not buy the hype about easy moon or Mars colonization Organizations mentioned in this episode: Intrepid Museum: https://intrepidmuseum.org/ Astronauts for America: https://www.astronautsforamerica.org/

May 19, 2026Episode 7748 min

Your Stolen Car Can Track Itself

Modern cars are phones with wheels: GPS, telematics, connected apps, and data streams that can expose privacy risks, but also help recover a stolen vehicle before it disappears across jurisdictions. Maria Santos and Eugene Giordani, co-founders of Autoscope, join the Security Cocktail Hour to explain how law enforcement can use consent-based access to connected-car data after a theft. We talk about relay attacks, key cloning, license plate reader limits, built-in GPS, jurisdiction problems, AirTags, immobilizers, Faraday bags, dash cams, and the practical steps car owners can take before something happens. If you care about cybersecurity, connected vehicles, public safety, privacy, or just keeping your car in your driveway, this one is for you. Website: https://securitycocktailhour.com LinkedIn: https://www.linkedin.com/company/security-cocktail-hour Twitter/X: @SecCocktailHour Enjoyed this episode? Follow us and share it with a colleague or friend who owns a connected car.

May 8, 2026Episode 7653 min

Drones Were Just the Beginning. Space Security Is Next.

In this episode, Ché Bolden joins us to talk about drone security, uncrewed systems, satellite security, GPS, autonomy, counter-drone defense, and the growing cyber risks around space-based infrastructure. We get into how drones were originally secured, why unencrypted links were such a problem, how command-and-control attacks can work, and why space is now part of the security conversation. This conversation sits at the intersection of cyber security, drone warfare, satellite security, space security, and the future of connected systems. If you care about drones, satellites, GPS, cyber risk, or the security of critical infrastructure, this episode is worth a listen. Guest Ché Bolden Learn more: bolden.group interastra.institute

April 20, 2026Episode 7553 min

Zero Trust in Orbit: Getting Satellite Security Off the Ground | Joe South

Joe South joins the Security Cocktail Hour to discuss the state of communication satellite security and the doctoral research he is doing to change it. Joe is Director of Cloud & AI Security at Abira Security and hosts the Security Unfiltered podcast, one of the larger independent cybersecurity podcasts. The conversation covers what satellite defense actually looks like today: why most of the security is at the ground station rather than on the satellite itself, what happens when CubeSats stay in orbit for 10 to 12 years without meaningful patching, and how a zero trust framework could be made to work on hardware that operates on less than three watts of power. Joe walks through his proposed approach, which combines TPM-based component authentication with a distributed trust ring across satellite orbits.We also get into cyber warfare and the attribution problem, the strategic implications of a compromised satellite fleet, and Joe's personal story about building self-sufficiency. If you work in cloud, infrastructure, or national security and have never had space in your threat model, this is a good place to start. Guest: Joe South, Director of Cloud & AI Security at Abira Security, host of Security Unfiltered (securityunfiltered.com), doctoral candidate at Capital Technology University.Subscribe to the Security Cocktail Hour newsletter at securitycocktailhour.com for a biweekly read on cybersecurity news and upcoming episodes.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts