Sec Guy

Sec Guy

di Sec Guy
Stagione 3

CompTIA Security+ SY0-801: 2.3 Message, Image, Attachment, Browser, and Human Vectors

When the network is breached, a technician reacts with panic, but an executive reacts with a playbook. In this module, Sec Guy breaks down Objective 4.7: Incident Response and Forensics. Using the Salt Typhoon telecommunications breach as a real-world framework, we cover the entire incident response lifecycle. You will learn how to build a Computer Incident Response Team (CIRT), execute tabletop exercises, perform digital forensics using the order of volatility, and navigate the legal minefield of chain of custody and data sovereignty. To map out exactly how to leverage this crisis-management mindset into an executive transition, refer to the SecGuy CompTIA Security+ Career and Certification Strategy Guide. Resources: πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – The Breach, Preparation, and Salt Typhoon 01:50 – Detection, Attribution, and Containment 03:20 – Digital Forensics and the Legal Minefield 05:30 – Lessons Learned and Real-World Application Original Sec Guy video: https://www.youtube.com/watch?v=7i6rLAwrMko

CompTIA Security+ SY0-801: 2.2 Threat Actors & Motivations

In cybersecurity, knowing the exploit is only half the battle. If you do not know the hand behind the keyboard, you are just chasing ghosts.In this module, Sec Guy breaks down Objective 2.2 for the CompTIA Security+ (SY0-801) exam: Threat Actors and Motivations. We move beyond textbook definitions to analyze the actual tradecraft, funding, and motivations of modern adversaries. You will learn how Nation-States use dwell time for espionage, how Organized Crime syndicates operate for financial gain, and why Hacktivists seek disruption. We also uncover the most dangerous, yet overlooked, threat vectors inside your own network: malicious insider threats, negligent employees, and Shadow IT. Resources πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – Knowing the Hand Behind the Keyboard 00:45 – Nation-States: Espionage & Dwell Time (Salt Typhoon) 01:50 – Organized Crime: Extortion & Ransomware (Scattered Spider) 02:40 – Hacktivists: Political Messaging & Disruption 03:30 – Unskilled Attackers (Script Kiddies) 04:15 – The Insider Threat: Malicious vs. Accidental 05:20 – Shadow IT: The Silent Killer of Compliance 06:10 – Threat Actor Attributes: Location, Resources & Sophistication 07:05 – The Interview Trap: Who is the Greatest Day-to-Day Risk? 08:00 – Outro & SecGuy Labs Original Sec Guy video: https://www.youtube.com/watch?v=p1nmkjF_X6o

CompTIA Security+ SY0-801: 2.1 Threat Intelligence & Vulnerability Priority

In enterprise security, you cannot defend against an adversary you do not understand. Today, we begin Domain 2 with Lesson S8-006: From Threat Intelligence to Vulnerability Priority for the CompTIA Security+ (SY0-801). Sec Guy breaks down the definitive difference between a threat (the force that exploits) and a vulnerability (the weakness in the system). You will learn how to consume intelligence across the entire threat lifecycle using Open-Source Intelligence (OSINT), Proprietary Threat Feeds, and Dark Web monitoring to determine an attack's Likelihood and Impact. We also deconstruct the Common Vulnerability Scoring System (CVSS) and explain why relying solely on a Base Score is an operational failure. You will learn how to apply Temporal and Environmental scores to inject actual business context into your patching strategy. Resources πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – The SWAT Analogy: Prioritizing the Enterprise Response 01:00 – Threat vs. Vulnerability: Defining the Incident 01:50 – Intelligence Sources: OSINT, Proprietary Feeds, and the Dark Web 02:45 – The Math of Risk: Likelihood vs. Impact 04:00 – Quantifying Weaknesses: CVEs and CVSS Mechanics 04:50 – Breaking Down CVSS: Base, Temporal, and Environmental Scores 06:30 – The Junior Analyst Trap: Why You Must Apply Business Context 07:45 – LAB-S8-004: The Threat-Priority Board Workshop Original Sec Guy video: https://www.youtube.com/watch?v=FfHfyzz71Sc

CompTIA Security+ SY0-801: Domain 1 Mastery Workshop

Theory without execution is useless in enterprise cybersecurity. In this Domain 1 Mastery Workshop for the CompTIA Security+ (SY0-801), you step into the shoes of the Lead Security Architect for a national healthcare processing network facing a critical Friday morning crisis. When infrastructure engineers submit an emergency Change Advisory Board (CAB) request to overhaul the patient billing portal, junior analysts see a standard business request, but an experienced architect spots an architectural minefield. Sec Guy guides you through dissecting the proposal’s catastrophic failures: missing impact analyses, absent backout plans, bypassed inspection proxies, deprecated MD5 hashing without salt, self-signed wildcard certificates, and unencrypted internal synchronization tunnels. You will learn not only how to reject a reckless deployment, but how to re-engineer the entire system using Enterprise PKI, mutual TLS 1.3, tokenization, Zero Trust identity, and automated rollback triggers, concluding with an executive briefing that proves business value to the CIO and CRO. Resources πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – Domain 1: From Theory to Execution 00:25 – The Scenario: Lead Security Architect 00:30 – The Emergency Change Request: Three Hidden Risks 01:00 – Don't Approve the Ticket: Analyze the Risk 01:20 – No Impact Analysis, No Approval: Managerial Control Failures 01:43 – Backout Protects Availability: The Missing Rollback Plan 02:11 – No Inspection Means No Visibility: Eliminating Detective Controls 02:41 – Internal Does Not Mean Trusted: Violating Defense in Depth 03:02 – Reject the Risk, Rewrite the Plan 03:17 – Open the Design Packet: Follow the Failure Path 03:32 – One Wildcard Key: Cluster-Wide Risk 03:43 – Never Disable Certificate Validation: On-Path Vulnerabilities 04:15 – Limit the Key's Blast Radius: Enforcing Least Privilege 04:37 – MD5 + No Salt = Credential Failure 05:11 – Slow KDF & Unique Salting Architecture 05:33 – Encrypt Internal Traffic: TLS 1.3 & Forward Secrecy 06:20 – Shared Admin Means No Accountability: AAA Breakdown 06:55 – Repair the Architecture: The Remediated Blueprint 07:13 – One Service, One Certificate: Enterprise PKI & OCSP Stapling 07:33 – Zero Trust Identity: Phishing-Resistant MFA & Jump Hosts 08:05 – Layered Data Protection: AES-256 & Tokenization 08:38 – Governed Pipeline: Test, Snapshot, Verify, Rollback 09:13 – Executive Briefing: Translating Security to the CIO & CRO 10:05 – Outro & Preparing for Domain 2 Original Sec Guy video: https://www.youtube.com/watch?v=twkmTT7nq9U

CompTIA Security+ SY0-801: 1.3 Cryptographic Solutions & Trust Engine

In modern enterprise security, cryptography is not an academic math drill; it is the trust engine that enforces identity, proves integrity, and secures multi-cloud environments. In this module, Sec Guy breaks down Objective 1.3: Cryptographic Solutions and the Trust Engine for the CompTIA Security+ (SY0-801). We demystify the difference between one-way integrity (hashing, salting, and rainbow table mitigation) and two-way confidentiality (symmetric vs. asymmetric encryption). You will master how Transport Layer Security (TLS) combines the speed of AES with the key-exchange power of RSA and ECC, how digital signatures mathematically enforce non-repudiation, and how enterprise Public Key Infrastructure (PKI) maintains the root of trust across Certificate Authorities (CAs), CRLs, and OCSP stapling. We also detail dedicated hardware root of trust implementations including TPMs, HSMs, and secure enclaves. Resources πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – Hashing vs. Encryption: Integrity vs. Confidentiality 02:10 – Collision Attacks, SHA-256 & Salting Passwords 04:15 – Obfuscation Techniques: Steganography, Tokenization & Masking 06:40 – Symmetric vs. Asymmetric: AES, RSA, and Elliptic Curve Cryptography (ECC) 09:20 – Hybrid Encryption & The TLS Handshake 11:35 – Public Key Infrastructure (PKI), Root CAs & Certificate Lifecycles 13:50 – Certificate Revocation: CRLs vs. OCSP Stapling 15:40 – Digital Signatures & Non-Repudiation Architecture Original Sec Guy video: https://www.youtube.com/watch?v=tV1AnMYSBbw

CompTIA Security+ SY0-801: 1.2 Change Management

Junior analysts picture major outages as the result of advanced nation-state hackers, but seasoned architects know that a single unvetted internal change can take down a multinational enterprise faster than any DDoS attack. In this module, Sec Guy breaks down Objective 1.2: Demonstrating the Impact of Change Management Processes on Security. Change management is not bureaucratic red tape; it is an operational governance framework ensuring that changes are documented, rigorously tested, authorized, and auditable. You will learn how the Change Advisory Board (CAB) operates, the necessity of formal impact analysis and backout plans, and the technical implications of downtime, legacy dependencies, and allow/deny lists. We also cover the critical importance of updating diagrams, policies, and utilizing version control to prevent cascading systemic failures. Resources: πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord In this episode: 00:00 – The Greatest Threat to Uptime & The Change Advisory Board (CAB) 02:15 – The Approval Process: Ownership, Stakeholders & Impact Analysis 04:30 – Backout Planning vs. Failing Forward 06:10 – Technical Implications: Allow Lists, Downtime & Legacy Dependencies 08:45 – Closing the Loop: Documentation, Diagrams & Version Control Original Sec Guy video: https://www.youtube.com/watch?v=Xk7S3o1tzA8

CompTIA Security+ SY0-801: 1.1 Security Concepts and Controls

If you are preparing for your CompTIA Security+ SY0-801 certification, throw away the idea of memorizing vocabulary just to pass a test. In the real world, enterprise security is about reasoning through decisions, understanding architectural tradeoffs, and knowing exactly what happens when a control fails. In this module, Sec Guy breaks down Objective 1.1: Security Concepts and Controls. We dismantle the outdated "castle and moat" strategy and build a modern Defense in Depth architecture. You will learn how to apply the CIA Triad, govern access with the AAA Framework, implement Zero Trust principles, and deploy the exact categories and types of security controls required to defend a modern enterprise. Rersources: πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord πŸ’» Practice Test: https://secguy.org In this episode: 00:00 – Introduction: The Perimeter is Dead & Defense in Depth 01:32 – The CIA Triad: Confidentiality, Integrity, and Availability 03:38 – Governing Access: The AAA Framework (Authentication, Authorization, Accounting) 05:53 – Limiting the Blast Radius: Least Privilege & Zero Trust Architecture 07:11 – Security Controls: The 4 Categories (Technical, Managerial, Operational, Physical) 09:01 – Security Controls: The 6 Types (Preventive, Deterring, Detective, Corrective, Compensating, Directive) Original Sec Guy video: https://www.youtube.com/watch?v=sEKQuOfkKpk
Stagione 2

CISM Full Course: Data Governance for CISOs

You can build a million-dollar network fortress, but if you don't know where your most sensitive data lives, you have already lost. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down Data Governance. We cover the critical legal separation between Data Owners and Data Custodians, how to implement Data Loss Prevention (DLP), and why the CISO should never be the one deciding who gets access to a file. πŸ“˜ GET THE BOOK: Ready to bridge the gap from analyst to executive? Grab your copy of the new book, The Cyber Blueprint: Ascending to CISO, here: https://www.secguy.org/books-guides-more πŸ”₯ GET JOB READY: Stop studying theory and start governing the enterprise. Head over to https://SecGuy.org to run our Data Governance Simulators. πŸ’¬ JOIN THE DISCORD: Connect with senior security leaders who are building data classification policies today: https://www.secguy.org/discord Original Sec Guy video: https://www.youtube.com/watch?v=MWU3WQeQsUU

CISM Full Course 2026: Managing C-Suite Conflict & Risk Acceptance

You finally got the CISO job. You have the budget, you built the dashboard, and your S.O.C. is fully staffed. But there's one massive problem: You don't actually own the network. The CIO does. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down the brutal reality of boardroom politics. We cover "Influence Without Authority," how to navigate toxic friction between Engineering and Legal, and why forcing the business to sign a Risk Acceptance form is your ultimate superpower. πŸ“˜ GET THE BOOK: Ready to bridge the gap from analyst to executive? Grab your copy of the new book, The Cyber Blueprint: Ascending to CISO, here: https://www.secguy.org/books-guides-more πŸ”₯ GET JOB READY: Stop fighting the business and start enabling it. Head over to https://SecGuy.org to run our Executive Conflict Simulators. πŸ’¬ JOIN THE DISCORD: Connect with senior security leaders who are navigating C-Suite politics today: https://www.secguy.org/discord Tags: Original Sec Guy video: https://www.youtube.com/watch?v=zFmVT777Z2w

CISM Full Course 2026: Cybersecurity Metrics: KRIs vs. KPIs vs. KGIs

When the CEO asks, "Are we secure?", how do you answer? If you reply with technical metrics like "firewall hits" or "malware blocked," you are thinking like an engineer, not an executive. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down the science of measuring security success. We explain the critical difference between Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and Key Goal Indicators (KGIs), and how to build a dashboard that actually secures your budget. πŸ”₯ GET JOB READY: Stop guessing at metrics. Head over to https://SecGuy.org to run the Executive Dashboard Lab and build a live KRI spreadsheet. πŸ’¬ JOIN THE DISCORD: Connect with senior security leaders who are tracking enterprise metrics today: https://www.secguy.org/discord GET THE BOOK: The Cyber Blueprint: Ascending to CISO: https://www.secguy.org/books-guides-more Original Sec Guy video: https://www.youtube.com/watch?v=ktxHc9p7lBQ
4 di 7