Sec Guy

Sec Guy

di Sec Guy
Stagione 2

CISM Full Course 2026: Supply Chain & Third-Party Risk (The Procurement Lifecycle)

You can build a million-dollar security fortress, but if your HVAC vendor has a weak password, your network is compromised. Welcome back to the CISM/CISO masterclass. In this module, SecGuy breaks down Supply Chain and Third-Party Risk Management (TPRM). We move beyond technical configurations and dive into the executive procurement lifecycle: R-F-Is, R-F-Ps, Proof of Concepts (POC), and why the "Right-to-Audit" clause is the most important sentence in a vendor contract. 🔥 GET JOB READY: Stop memorizing and start executing. Head over to https://SecGuy.org to run our interactive labs. 💬 JOIN THE DISCORD: Connect with senior security leaders navigating these exact vendor negotiations today. Original Sec Guy video: https://www.youtube.com/watch?v=6IYhLODeKbg

CISM Full Course 2026: Incident Management: The Executive Playbook & Tabletop Exercises

A security plan on paper is just a liability waiting to be exposed. In Video 6, we tackle the CISO's ultimate test: Incident Management. Discover the critical differences between an IRP, BCP, and DRP, why technicians fail during a crisis, and how top-tier executives maintain control, legally protect the company, and manage the boardroom narrative during a massive cyber breach. In this video, we cover: • The Crisis Mindset: Why technicians pull cables while executives pull the incident playbook. • The Holy Trinity of Chaos: Distinctly separating Incident Response (stopping the bleeding), Business Continuity (keeping revenue flowing), and Disaster Recovery (rebuilding the tech). • Out-of-Band Communications: The most common failure point during ransomware attacks. • The Tabletop Exercise: Why you must test your C-suite in peacetime to survive wartime. • Post-Incident Review: How to turn a multi-million dollar breach into a strategic budget justification. Passing the exam is just the gate. Dominating the CISO chair is the goal. I am Sec Guy, and the lab is officially open. Stay safe, stay secure. 📚 Resources & Support 🎓 Get Job-Ready: Passing the exam gets you an interview. Our Job Ready Experience Builder gets you hired. Grab your Free or Pro membership and start building a portfolio of real-world executive experience you can showcase to employers: 👉 https://www.secguy.org 💬 Join the Squad: Connect with senior engineers and industry veterans navigating these exact boardroom conversations right now. Tell the squad: Has your organization run a full Tabletop Exercise this year, or are you just hoping for the best? 👉 https://secguy.org/discord 📈 Salary Negotiation: Learn how to leverage your new executive crisis-management mindset for maximum pay using our free resources at SecGuy.org. Original Sec Guy video: https://www.youtube.com/watch?v=-Jd5zbO5MyI

CISM Full Course 2026: Risk Management Engine: Capacity, Appetite, & Tolerance

Stop trying to secure everything and start managing business risk. If you are still trying to patch every single vulnerability without looking at the business impact, you are thinking like a technician, not an executive. In Video 4 of the CISM 2026 series, we explore the core language of the boardroom: Risk Management. Learn how to stop saying "no" to the business and start saying "yes, securely." In this video, we cover: • The Risk Triangle: The critical differences between Risk Capacity, Risk Appetite, and Risk Tolerance (using the "Speed Limit" analogy). • The Math of the Boardroom: How to calculate Single Loss Expectancy (SLE) and Annual Loss Expectancy (ALE) so your CFO actually approves your budget. • Risk Ownership: Why the CISO never owns the risk, and why the Business Unit Leader must sign on the dotted line. • The 4 Executive Choices: How to properly Mitigate, Transfer, Avoid, or Accept enterprise risk. Passing the exam is just the gate. Dominating the CISO chair is the goal. I am Sec Guy, and the lab is officially open. Stay safe, stay secure. 📚 Resources & Support 🎓 Get Job-Ready: Passing the exam gets you an interview. Our Job Ready Experience Builder gets you hired. Grab your Free or Pro membership and start building a portfolio of real-world risk management experience you can showcase to employers: 👉 https://www.secguy.org 💬 Join the Squad: Connect with senior engineers and industry veterans navigating these exact boardroom conversations right now. Tell the squad: In your organization, who actually signs off on accepting risk? Is it the security team, or is it the business owners? 👉 https://secguy.org/discord 📈 Salary Negotiation: Learn how to leverage your new executive risk-management mindset for maximum pay using our free resources at SecGuy.org. Original Sec Guy video: https://www.youtube.com/watch?v=rtcSLvG8FrY

CISM Full Course 2026: Governance Engine: Frameworks, Standards, and Strategy

Stop being a hero and start building a machine. If your security program depends on you saving the day, you don't have a program—you have a high-stress hobby. In Video 3 of the CISM 2026 series, we move from the "Mindset" to the "Executive Machine." We break down how top-tier CISOs use frameworks like NIST, ISO, and COBIT to build repeatable security engines that survive global audits and protect the organization's revenue. In this video, we cover: • The Blueprint (NIST CSF): How to translate cyber defense into the 5 core executive functions (Identify, Protect, Detect, Respond, Recover). • The Audit (ISO 27001): Why your CFO and global partners care more about your ISO certificate than your firewall configs. • The Strategy: The critical role of the Security Steering Committee and business alignment (COBIT). • The Documentation Pyramid: The exact hierarchy of Policies (The Law), Standards (The Must), and Procedures (The Manual). • Success Metrics: Stop counting viruses blocked. Start measuring Key Goal Indicators (KGI) and Key Performance Indicators (KPI). Passing the exam is just the gate. Dominating the CISO chair is the goal. I am Sec Guy, and the lab is officially open. Stay safe, stay secure. 📚 Resources & Support 🎓 Get Job-Ready: Passing the exam gets you an interview. Our Job Ready Experience Builder gets you hired. Grab your Free or Pro membership, download the CISO Governance Decision Matrix, and start building your real-world portfolio today: 👉 https://www.secguy.org 💬 Join the Squad: Connect with senior engineers and industry veterans navigating these exact boardroom conversations right now. Tell the squad: Are you a NIST shop or an ISO shop? 👉 https://secguy.org/discord 📈 Salary Negotiation: Learn how to leverage your new executive mindset for maximum pay using our free resources at SecGuy.org. Original Sec Guy video: https://www.youtube.com/watch?v=De422kZnTdc

CISM Full Course 2026: Resource Management & Security ROI

If you want to survive in the CISO chair, you have to stop speaking in vulnerabilities and start speaking in dollars. Here is the exact financial blueprint (CapEx, OpEx, and ROSI) to get your cybersecurity budget approved. Welcome back to the lab. In this module of the CISM/CISO series, Sec Guy breaks down the hardest transition for senior engineers: Resource Management. The Board of Directors doesn't care about the latest zero-day exploit—they care about the balance sheet. We cover Zero-Based Budgeting, Return on Security Investment (ROSI), and how to frame a $2M SOC upgrade as "revenue protection" instead of an IT expense. 📚 Resources & Support 🎓 FREE Interactive Learning Tools Don't just watch—practice. Head over to SecGuy.org to run the Budget Justification Simulation and get hands-on experience. CISM Exam Simulators: https://secguy.org/exam-simulators Governance & Risk Labs: https://secguy.org/python-practice 💬 Join the Squad Connect with senior engineers and industry veterans navigating these exact boardroom conversations right now. Official Discord: https://secguy.org/discord Original Sec Guy video: https://www.youtube.com/watch?v=v99_68sUjLM

CISM Full Course 2026: CISM Mindset Stop Doing, Start Managing

We have seen the technical weeds. Now, let’s look at the boardroom. Welcome to Phase 1: The Executive Baseline. In this video, we switch to the C-Suite mindset. We are breaking down the "Business Alignment" stack, the fundamental shift in responsibility you need to know for the exam, and the critical separation of duties that keeps the organization secure without causing a bankruptcy. In this video, we cover: The CISM Mindset: Why the best technical engineer often fails as a Security Manager. Critical Exam Term: Separation of Duties—The standard for differentiating between IT Operations (The How) and Security Management (The Why). Analysis Tools: Translating technical vulnerabilities like cross-site scripting into Business Impact language (Revenue, Liability, and Reputation). Real-World Scenario: Why an "unbreakable" system that kills revenue is a failure of leadership. Job-Readiness: How to justify security budgets to a CEO who only cares about the bottom line. Timecodes: 0:00 - Intro: Switching to the Blue Team Executive 1:15 - IT Operations vs. Security Management 4:30 - Real-World Scenario: The Cost of Perfect Security 8:00 - Translating Technical Risk to Business Impact 11:30 - What’s Next: Resource Management & Security ROI (Video 2) 📚 Resources & Support 🎓 FREE Interactive Learning Tools Don't just watch—practice. Access our executive simulations to test your leadership skills live. CISM Exam Simulators: https://secguy.org/exam-simulators 💬 Join the Squad Connect with other industry veterans and students in our dedicated C-I-S-M study channel. Official Discord: https://secguy.org/discord #CISM #ISACA #CISO #BlueTeam #SecurityManagement #CyberDefense #ExecutiveMindset #BusinessAlignment #SecGuy #cybersecuritycompany #cso #cism #isaca #ciso #blueteam #securitymanagement #cyberdefense #executivemindset #businessalignment #secguy #cybersecurity #cism2026 #isaca #cismexamprep #certifiedinformationsecuritymanager #cisspvscism #informationsecuritygovernance #examtips #cybercertification #infosecexam #cybersecuritycareer #techniciantoexecutive #securityleadership #careerpivot #cybersecuritymanagement #sixfigurecyber #cybersecuritymentor #directorofsecurity #riskmanagement #cybersecuritystrategy #enterprisesecurity #informationsecurity #boardroomready #cybersecuritytraining #grc #governance #risk #compliance Original Sec Guy video: https://www.youtube.com/watch?v=_I5QT3IQmpY
Stagione 1

SecAi+ Domain 4.1: AI CoE, Responsible AI, and AI RIsk

From the server room to the boardroom: Mastering AI GRC for the SecAI+ Exam. This episode covers Domain 4: AI Governance, Risk, and Compliance. We explore the AI Center of Excellence (CoE), identify the Builders, Defenders, and Watchers on an AI team, and deep-dive into the dangers of Shadow AI. Learn the essential Responsible AI Principles—Fairness, Transparency, and Accountability—needed to pass objective 4.1. 🎓 Join the Mission: Get free practice tests and the Python for Security module at: secguy.org 📍 Timestamps (Chapters): 00:00 – Introduction to AI GRC (Domain 4) 00:28 – The AI Center of Excellence (CoE) 00:50 – Team Roles: Builders vs. Defenders 01:23 – Team Roles: The Watchers (Auditors & Analysts) 01:40 – Shadow AI vs. Shadow IT 02:17 – Beyond Data: Safety & Reputational Risk 02:35 – Responsible AI Principles: Fairness & Transparency 02:50 – Accountability = Human (Avoiding Bias) 03:13 – Coming Up: EU AI Act & Regulatory Frameworks #AI #Governance #SecAI #CompTIA #RiskManagement #SecGuy

SecAI+ Domain 3.3: The AI Analyst (Blue Team Tools, MCP & Co-Pilot)

We have seen the weapons (Video 10). Now, let’s look at the shields. Welcome to Domain 3: AI-Assisted Security. In this video (Objective 3.3), we switch to the Blue Team. We are breaking down the "AI Co-Pilot" stack, the new hardware you need to know for the exam, and the critical standard that connects AI to your internal data without causing a leak. In this video, we cover: The AI Co-Pilot: IDE vs. CLI Plugins (GitHub Copilot vs. Terminal Assistants). Critical Exam Term: Model Context Protocol (MCP)—The standard for connecting AI to secure internal servers. Analysis Tools: Vulnerability Analysis, Anomaly Detection, Summarization, and Real-Time Translation. Hardware: NVIDIA Jetson Nano Orin (Edge AI) and Vector Databases. Privacy: Using Ollama to run local LLMs and prevent data leaks. Timecodes: 0:00 - Intro: Switching to the Blue Team 0:25 - The AI Co-Pilot (IDE vs. CLI Plugins) 1:00 - CRITICAL TERM: Model Context Protocol (MCP) 1:30 - Analysis Tools: Vuln Scans & Translation 2:15 - Anomaly Detection & Vector Databases 2:38 - Edge AI Hardware: NVIDIA Jetson Nano Orin 3:02 - Threat Hunting with Neo4j Graph Database 3:22 - Privacy Tools: Ollama & Local LLMs 3:45 - What’s Next: Automation & SOAR (Video 12) ​📚 Resources & Support ​🎓 FREE Interactive Learning Tools Don't just watch—practice. Access our new browser-based tools to test your skills live. ​AI-Powered Exam Simulators: https://secguy.org/exam-simulators ​Python for Security Labs: https://secguy.org/python-practice ​Mock Interview Board: https://secguy.org/mock-interview 💬 Join the Squad Connect with other industry veterans and students in our new dedicated study group. ​Official Discord: https://secguy.org/discord-chat ​📚 Download Course Materials Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy. ​Access Here: https://secguy.org/courses #SecAI #CompTIA #BlueTeam #CyberDefense #MCP #ModelContextProtocol #Ollama #JetsonNano #CoPilot #Cybersecurity

SecAI+ Domain 3.1: The AI Analyst (Blue Team Tools, MCP & Co-Pilot)

​🛡️ Domain 3: AI-Assisted Security (Objective 3.1) ​We’ve analyzed the weapons in Domain 2—now it’s time to deploy the shields. Welcome to the Blue Team. ​In this video, we break down the "AI Co-Pilot" stack and the defensive tools you need to master for the SecAI+ exam. From the hardware powering Edge AI to the critical protocols that secure internal data, this is your crash course in AI-assisted defense. ​🚀 What We Cover in This Video: ​The AI Co-Pilot Stack: Understanding the difference between IDE plugins (GitHub Copilot) and CLI Terminal Assistants. ​CRITICAL Exam Concept: The Model Context Protocol (MCP)—the industry standard for connecting AI models to secure internal servers without risking data leaks. ​Defensive Analysis: leveraging AI for vulnerability scanning, anomaly detection, automated summarization, and real-time translation. ​Hardware & Architecture: A look at NVIDIA Jetson Nano Orin (Edge AI) and how Vector Databases power modern security tools. ​Threat Hunting: visualizing threats with Neo4j Graph Databases. ​Data Privacy: How to use Ollama to run local LLMs, ensuring your sensitive data never leaves the network. ​⏱️ Timecodes ​0:00 - Intro: Switching to the Blue Team ​0:25 - The AI Co-Pilot (IDE vs. CLI Plugins) ​1:00 - CRITICAL TERM: Model Context Protocol (MCP) ​1:30 - Analysis Tools: Vuln Scans & Translation ​2:15 - Anomaly Detection & Vector Databases ​2:38 - Edge AI Hardware: NVIDIA Jetson Nano Orin ​3:02 - Threat Hunting with Neo4j Graph Database ​3:22 - Privacy Tools: Ollama & Local LLMs ​3:45 - What’s Next: Automation & SOAR (Video 12) ​📚 Resources & Support ​🎓 FREE Interactive Learning Tools Don't just watch—practice. Access our new browser-based tools to test your skills live. ​AI-Powered Exam Simulators: https://secguy.org/exam-simulators ​Python for Security Labs: https://secguy.org/python-practice ​Mock Interview Board: https://secguy.org/mock-interview ​💬 Join the Squad Connect with other industry veterans and students in our new dedicated study group. ​Official Discord: https://secguy.org/discord-chat ​📚 Download Course Materials Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy. ​Access Here: https://secguy.org/courses ​Next Up: Domain 3.3: The AI Automator (SOAR & Agents) ​#SecAI #CompTIA #BlueTeam #CyberDefense #MCP #ModelContextProtocol #Ollama #JetsonNano #CoPilot #Cybersecurity

Domain 3.2: The AI Offensive (Red Team, Deepfakes & Malware)

We have talked about how to hack an AI. Now, let’s talk about when the AI becomes the hacker. Welcome to Domain 3: AI-Assisted Security. In this video (Objective 3.2), we switch to the Red Team. We are breaking down exactly how attackers weaponize LLMs to scale social engineering, clone voices for "Vishing," and generate polymorphic malware that evades traditional antivirus. In this video, we cover: Identity Attacks: Deepfakes, Impersonation, and Social Engineering at Scale. Infrastructure Attacks: Automated Reconnaissance, Attack Vector Discovery, and AI-Enhanced DDoS. Payloads: Polymorphic Code, Obfuscation, and Adversarial Malware Generation. Hardware: Why GPUs are required for Password Cracking (PassGAN). Timecodes: 0:00 - Intro: The AI Offensive (Domain 3) 0:42 - Social Engineering & Personalized Phishing 1:05 - Voice Cloning & Vishing (The 3-Second Rule) 1:38 - Automated Recon & Attack Vector Discovery 2:05 - AI-Enhanced DDoS (Traffic Shaping) 2:28 - Writing Malware & Polymorphic Code (Obfuscation) 3:05 - Hardware: GPUs & Password Cracking (PassGAN) 3:35 - What’s Next: The Blue Team (Video 11) ​📚 Resources & Support ​🎓 FREE Interactive Learning Tools Don't just watch—practice. Access our new browser-based tools to test your skills live. ​AI-Powered Exam Simulators: https://secguy.org/exam-simulators ​Python for Security Labs: https://secguy.org/python-practice ​Mock Interview Board: https://secguy.org/mock-interview ​💬 Join the Squad Connect with other industry veterans and students in our new dedicated study group. ​Official Discord: https://secguy.org/discord-chat ​📚 Download Course Materials Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy. ​Access Here: https://secguy.org/courses Next Video: Domain 3.1: The AI Analyst (Blue Team Defense) #SecAI #CompTIA #Cybersecurity #RedTeam #Deepfakes #Malware #EthicalHacking #PassGAN #AIsecurity
5 di 7