Cybersecurity Business with Fexingo: Security Companies, Breaches, and Enterprise Defense

Cybersecurity Business with Fexingo: Security Companies, Breaches, and Enterprise Defense podcast cover
Fexingo Business & Technology

Cybersecurity Business with Fexingo: Security Companies, Breaches, and Enterprise Defense

Lucas and Luna examine the business of cybersecurity: the companies that build defenses, the breaches that expose weaknesses, and the enterprise strategies that determine who survives a digital siege. Each episode dissects one security vendor's financial filings, contract wins, and R&D spend — CrowdStrike versus Palo Alto Networks, the Okta identity saga, how SentinelOne's AI detection affects its gross margins. They walk through actual breach post-mortems (Colonial Pipeline, SolarWinds, MOVEit) and ask: what did the insurance payout look like, which C-suite roles took the blame, and how did the stock move? Lucas reads directly from SEC filings and earnings call transcripts; Luna presses on competitive moats, customer churn, and the cost of zero-day exploits. The show serves investors tracking the cybersecurity ETF, CISOs benchmarking vendor spend, and product managers who need to understand how boardroom risk appetite translates into line-item budgets. Conversations stay grounded in market caps, contract sizes, and patch-cycle economics — no fear-mongering, no vendor white papers. What does a 30% year-over-year increase in ransomware payouts mean for the next quarter's firewall procurement cycle?

#CybersecurityBusiness#CrowdStrike#PaloAltoNetworks#Okta#SentinelOne#ZeroDay#Ransomware#EnterpriseSecurity#CISO#SOC#BreachPostMortem#SECFiling#CyberInsurance#NetworkTraffic#VendorMoat#Business#FexingoBusiness#Technology

Support Fexingo

Episodes

Latest 50 of 175 episodes

How Shadow IT Is Rewiring Enterprise Security

Sep 2, 2026 · 8:57

We drill into the specific mechanics of shadow IT and why traditional perimeter defense fails when employees bypass IT controls for SaaS tools. Using a concrete example of a mid-market retailer adopting unauthorized collaboration platforms, we explore how data exfiltration happens not through malware but through legitimate user behavior. We discuss the shift from blocking access to monitoring identity, the role of Cloud Access Security Brokers in gaining visibility, and why security teams are…

0:000:00

The Hidden Cost of Shadow IT in Enterprise Security

Sep 1, 2026 · 15:02

Most enterprises don't lose data because their perimeter was breached. They lose it because employees bypassed security controls to get work done faster. In this episode, we examine the specific mechanics of shadow IT — the unauthorized software and cloud services that CISOs can't see and can't protect. We look at why traditional network monitoring fails against encrypted SaaS traffic, how Microsoft and Google are trying to regain visibility with new identity-based controls, and what a…

0:000:00

How AI Security Starts With Data Provenance

Aug 31, 2026 · 8:46

AI models are the new crown jewels for enterprises — and the attack surface is wider than most CISOs think. In episode 173 of Cybersecurity Business with Fexingo, Lucas and Luna drill into the emerging discipline of AI security, focusing on the overlooked foundation: data provenance. They unpack how a poisoned training dataset can corrupt a model's decisions, why supply chain attacks now extend to machine learning pipelines, and how provenance tools like signed manifests and cryptographic…

0:000:00

Why Cyber Insurance Exclusions Are Rewriting Security Budgets

Aug 30, 2026 · 7:46

In this episode of Cybersecurity Business, Lucas and Luna explore a quiet but powerful shift: insurers are starting to exclude coverage for state-backed attacks, and that one policy change is reshaping how enterprises spend on defense. They dig into the recent proposal by a major European insurer, the rise of cyber reinsurance, and how security teams are now mapping budgets to insurer requirements. With specific examples like Lloyd's of London and the 2023 reforms, they unpack the real…

0:000:00

How Security Teams Turn Breach Intel Into Boardroom Strategy

Aug 29, 2026 · 9:05

In this episode of Cybersecurity Business, Lucas and Luna dig into the surprisingly fuzzy line between 'security' and 'business' in the modern CISO role. With data from the latest IBM Cost of a Data Breach report — now averaging $4.9 million per incident — they explore how forward-looking security leaders are moving beyond technical fixes to translate breach intelligence into the language of risk, revenue, and resilience. The conversation centers on a specific case: a mid-sized healthcare…

0:000:00

How Cyber Insurers Are Quietly Reshaping Enterprise Defense

Aug 28, 2026 · 11:04

Enterprise security teams are used to thinking about attackers, patches, and controls. But in 2026, the real pressure to change behavior is coming from an unlikely source: the cyber insurance underwriter. In Episode 170 of Cybersecurity Business, Lucas and Luna unpack how insurers are moving beyond premiums and starting to dictate security architecture itself. They drill into the rise of 'pre-binding' requirements—minimum controls that must be in place before a policy is even quoted—and how one…

0:000:00

How CISOs Are Building Cyber Resilience Teams

Aug 27, 2026 · 7:55

In this episode of Cybersecurity Business, Lucas and Luna explore the rise of dedicated cyber resilience teams inside enterprises. They break down how companies like JPMorgan and Maersk have shifted from pure prevention to recovery-focused planning, and the new CISO-level roles emerging to lead these efforts. The conversation drills into the concept of resilience exercises, the hard numbers around mean time to recover, and how boards are now asking tougher questions about incident response. If…

0:000:00

How Cyber Insurance Is Reshaping the Ransomware Decision

Aug 26, 2026 · 8:56

In this episode, Lucas and Luna explore how the escalating cost of cyber insurance is changing the calculus for enterprises facing ransomware demands. They break down the 'ransomware dilemma': whether to pay or not, and how insurers' evolving policies—like refusing to cover ransom payments or capping payouts—are pushing companies toward more proactive defense. With a recent case where a company's insurer balked at covering the ransom, they examine the tension between paying to restore…

0:000:00

How Cyber Insurance Is Rethinking the Ransomware Decision

Aug 25, 2026 · 9:45

In episode 167 of Cybersecurity Business, Lucas and Luna dive into the hidden calculus behind ransom payments. When a breach hits, the decision to pay or not isn't just a security call — it's a financial one, shaped by insurance terms, stock-market reactions, and the cost of downtime. They unpack how the 2023 Change Healthcare attack changed the conversation, why some companies quietly build ransom capacity into their risk budgets, and the rise of 'pay-and-chase' strategies where firms pay up…

0:000:00

How Cloud Security Posture Management Stops Cloud Misconfigurations

Aug 24, 2026 · 9:44

Cloud misconfigurations remain a leading cause of data breaches, yet many security teams still struggle to identify and fix them before attackers strike. In this episode, Lucas and Luna explore Cloud Security Posture Management (CSPM) and how it helps enterprises automate the detection and remediation of risky cloud settings. They anchor the conversation around the Capital One breach, where a misconfigured web application firewall led to the exposure of over 100 million customer records. They…

0:000:00

The Price of Ransomware: Payouts and Negotiation Tactics

Aug 23, 2026 · 10:17

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna examine the high-stakes world of ransomware negotiations. They break down the evolving tactics of cybercriminals, the role of professional negotiators, and the ethical and financial dilemmas faced by companies that decide to pay or not. Using the real-world example of a mid-sized logistics firm that faced a seven-figure demand, they explore the hidden costs of a breach, the psychology of extortion, and the long-term…

0:000:00

How Quantum-Safe Encryption Is Becoming an Enterprise Imperative

Aug 22, 2026 · 10:37

As quantum computers edge closer to breaking today's encryption, forward-looking CISOs are already migrating to post-quantum cryptography. In this episode, Lucas and Luna drill into the real-world logistics of that shift: the National Institute of Standards and Technology's finalized post-quantum standards, the hard problem of upgrading PKI and TLS at scale, and the specific industries that face the highest 'harvest now, decrypt later' risk. They discuss why a bank's decade-old data is still…

0:000:00

How CISOs Are Using Cyber Reinsurance to Cap Catastrophic Loss

Aug 21, 2026 · 11:43

When a single ransomware event can cost an enterprise tens of millions, traditional cyber insurance leaves gaps. In this episode, Lucas and Luna explore how CISOs are turning to cyber reinsurance — insurance for insurers — to cap catastrophic losses. They unpack the mechanics of how a primary carrier's exposure gets transferred to reinsurers, the role of the Federal Insurance Office's 2026 report on the growing market, and why parametric triggers like 'pay on declared ransomware event' are…

0:000:00

Supply Chain Security Feeds on the Shared Responsibility Model

Aug 20, 2026 · 8:09

In this episode, Lucas and Luna dive into the shared responsibility model in cloud security, focusing on how CISOs and security teams are navigating the blurred lines between cloud providers and enterprises in 2026. With the rise of complex multi-cloud environments and serverless computing, the episode explores a real-world case study of a company that thought its cloud provider was securing its data, only to discover the gap was theirs. They discuss the concrete steps security teams are…

0:000:00

How CISOs Prioritize Vulnerabilities with Exposure Management

Aug 19, 2026 · 8:35

Episode 161 of Cybersecurity Business digs into exposure management, the discipline replacing patch-everything security. Lucas and Luna break down why the average enterprise juggles tens of thousands of open vulnerabilities but can only fix a fraction, and how CISOs now focus on 'exploitability' first. They walk through a concrete example: a critical-rated flaw in a less-accessed system versus a medium-rated bug in an internet-facing edge device, and why attackers force the latter. The episode…

0:000:00

How CISOs Are Using Attack Path Management

Aug 18, 2026 · 10:12

In episode 160 of Cybersecurity Business with Fexingo, Lucas and Luna dig into attack path management — the practice of mapping how an attacker could move from initial compromise to crown-jewel data. They explore a 2025 report showing that 74 percent of breach paths used known, unpatched vulnerabilities, and walk through how a mid-sized healthcare firm used graph-based analysis to cut its exposure by half. The conversation covers why traditional patch management fails, how CISOs are shifting to…

0:000:00

How CISOs Buy Cyber Insurance for Cloud Native Stacks

Aug 17, 2026 · 12:25

As enterprises move workloads to the cloud, cyber insurance underwriting is struggling to keep up. In this episode, Lucas and Luna explore how cloud-native architectures are forcing insurers to rethink risk models, and how CISOs are adapting their buying strategies. They break down the rise of cloud-specific insurance products, the role of automated security assessments, and the growing gap between traditional policies and modern infrastructure. With real-world examples like the Capital One…

0:000:00

How Security Teams Are Adopting Passwordless Authentication

Aug 16, 2026 · 9:04

Passwords are the weakest link in enterprise security, yet most firms still rely on them. In this episode, Lucas and Luna explore the shift to passwordless authentication—why it's gaining traction, how it works, and what it means for security teams. They break down the move from passwords to passkeys, the role of standards like FIDO2, and the challenges of rolling out passwordless across a large organization. With practical examples and real-world considerations, they explain how this approach…

0:000:00

How Cyber Insurance Is Priced After a Breach

Aug 15, 2026 · 10:13

In this episode of Cybersecurity Business, Lucas and Luna dive into the hidden mechanics of how cyber insurance premiums are set after a breach. They break down the role of loss-run reports, the shift from per-incident to aggregate coverage, and why a single breach can double your premium even if your security posture improves. They also explore how insurers are now using real-time threat telemetry and AI to price risk, and what CISOs can do to avoid being blindsided at renewal. With a sharp…

0:000:00

How Breach Disclosure Timelines Shape Cyber Insurance Payouts

Aug 14, 2026 · 10:03

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore how the speed and accuracy of breach disclosure can influence cyber insurance payouts, using the 2024 Change Healthcare ransomware attack as a case study. They unpack the insurer's perspective, the role of forensic investigators, and the delicate dance between legal obligations and policy requirements. With cyber premiums up an average of 15% in 2026, understanding the disclosure timeline is more critical than ever.…

0:000:00

How CISOs Use AI to Triage Alerts and Beat Alert Fatigue

Aug 13, 2026 · 9:08

Security teams drown in alerts—some estimates put the volume at thousands per day. In this episode, Lucas and Luna explore how CISOs are using AI-powered triage to separate real threats from noise. They dig into the math behind false positives, why traditional rules-based systems are failing, and what it means for security analysts' jobs. With a concrete example from a mid-sized fintech, they show how AI cut alert volume by 70 percent while catching a sophisticated credential-stuffing attack…

0:000:00

How Cyber Insurance Premiums Are Priced After a Breach

Aug 12, 2026 · 9:38

In this episode of Cybersecurity Business, Lucas and Luna dive into the gritty mechanics of how cyber insurance premiums are calculated after a company suffers a breach. They explore the role of security questionnaires, loss history, and remediation efforts, using a concrete example of a mid-sized logistics firm that saw its premium double after a ransomware incident. The conversation unpacks how insurers differentiate between a single event and a pattern of poor security hygiene, and why a…

0:000:00

How Zero-Knowledge Proofs Can Prove a Breach Without Revealing Secrets

Aug 11, 2026 · 9:14

Enterprises have long struggled to prove to auditors, regulators, and business partners that they've been breached without exposing the very vulnerabilities that allowed it. Zero-knowledge proofs, a cryptographic technique that lets one party prove a fact without revealing the underlying data, are emerging as a practical solution. In this episode, Lucas and Luna explore how firms are using zero-knowledge proofs to verify breach notifications, share threat intelligence without leaking sensitive…

0:000:00

Why Security Teams Are Switching to On-Prem SIEM

Aug 10, 2026 · 8:35

In this episode of Cybersecurity Business, Lucas and Luna look at a quiet but significant shift in enterprise security: on-premise security information and event management, or SIEM. After more than a decade of 'cloud first' messaging, a growing number of security teams are pulling their log data back in-house. Lucas walks through the math that's driving the change—data ingestion costs, egress fees, and the trade-offs between cloud scalability and on-prem control—and cites a concrete case: a…

0:000:00

How Security Teams Use Threat Hunting to Find Hidden Attackers

Aug 9, 2026 · 10:00

Episode 151 of Cybersecurity Business with Fexingo looks inside the world of proactive threat hunting. Lucas and Luna examine how enterprise security teams move beyond automated alerts to actively search for signs of intrusion that slipped past their defenses. They break down the difference between reactive monitoring and hunting, the role of the MITRE ATT&CK framework as a roadmap, and the human intuition that still matters when machines miss the subtle clues. Using the example of a stealthy…

0:000:00

How Zero Trust Is Rewriting Network Security

Aug 8, 2026 · 7:32

In this special 150th episode, Lucas and Luna explore how the zero trust model is fundamentally changing enterprise network security. They trace the shift from perimeter-based defenses to a verify-everything approach, using the 2023 Okta breach as a case study to show how even identity providers can fall victim to credential theft. The conversation covers the rise of identity-centric security, the practical challenges of implementing zero trust, and the uncomfortable truth that perimeters no…

0:000:00

How CISOs Are Using Threat Intelligence Sharing to Stop Attacks

Aug 7, 2026 · 9:04

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore the rise of threat intelligence sharing among enterprises. They dive into how companies are moving from siloed security to collaborative defense, using platforms like the Cyber Threat Alliance and industry-specific ISACs. The conversation centers on a concrete example: the 2021 Kaseya supply-chain attack, where shared indicators of compromise helped organizations respond faster. Lucas breaks down the economics of…

0:000:00

How CISOs Use Tabletop Exercises to Stress Test Their Plans

Aug 6, 2026 · 9:17

Episode 148 of Cybersecurity Business with Fexingo looks at how CISOs use tabletop exercises to stress-test their incident response plans before a real breach hits. Lucas and Luna walk through a realistic ransomware scenario, showing how a well-run exercise can expose gaps in communication, decision-making, and technical readiness. They discuss why many exercises fail because they're too scripted, how red teams and purple teams add realism, and what CISOs can learn from the military's use of…

0:000:00

How Cyber Insurance is Reshaping Enterprise Defense Strategies

Aug 5, 2026 · 7:56

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna dive into the evolving role of cyber insurance in enterprise security. With premiums rising sharply and carriers demanding stronger security controls, insurers are becoming de facto regulators of corporate cybersecurity. Lucas breaks down how underwriting now involves technical assessments, how policy terms are tightening around ransomware and business email compromise, and why some companies are self-insuring while others…

0:000:00

How AI Agents Are Reshaping Enterprise Security Operations

Aug 4, 2026 · 7:43

In this episode, Lucas and Luna dive into how AI agents are transforming security operations centers. They explore a real-world example: a major financial institution that deployed autonomous agents to triage thousands of daily alerts, cutting response times by 60 percent. The conversation covers what AI agents actually do, where they still struggle, and how human analysts are shifting from firefighters to supervisors. They also discuss the risk of 'agent sprawl' and why some CISOs are pushing…

0:000:00

How CISOs Are Using Cyber Range Training to Prepare for Real Attacks

Aug 3, 2026 · 11:06

Cyber ranges are the flight simulators of the cybersecurity world, letting security teams rehearse their response to a live attack in a simulated environment. In this episode, Lucas and Luna explore how leading enterprises are using cyber ranges to move beyond tabletop exercises and build hands-on muscle memory for incident response. They break down the anatomy of a typical range exercise, from realistic network ladders to the 'injects' that force teams to make decisions under pressure. The…

0:000:00

How Security Teams Use Cyber Deception to Trap Attackers

Aug 2, 2026 · 11:57

In this episode, Lucas and Luna explore how enterprises are deploying cyber deception—honeypots, decoys, and fake credentials—to outsmart attackers. They dive into a real case involving a financial services firm that used a fake database to catch a persistent intruder, and discuss the shift from passive detection to active engagement. With insights on realistic honeypots, the role of deception in threat intelligence, and how even smaller companies can adopt these strategies, this episode offers…

0:000:00

How CISOs Turn Incident Postmortems Into Strategic Assets

Aug 1, 2026 · 9:31

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore how enterprises are transforming incident postmortems from after-the-fact reports into strategic assets that reshape security programs. The discussion centers on a 2025 study showing that companies with structured post-incident review processes cut repeat incidents by 40 percent. They break down why traditional postmortems often fail, how forward-looking teams use them to drive process improvements and tooling…

0:000:00

Why CISOs Are Cutting Their Security Vendor Count

Jul 30, 2026 · 6:51

Episode 142 of Cybersecurity Business with Fexingo dives into the growing trend of security vendor consolidation. Lucas and Luna unpack why the average enterprise now juggles over 45 security tools—and why many CISOs are aggressively cutting that number. They explore the business case for consolidation, from reducing alert fatigue to lowering total cost of ownership, and cite examples like Palo Alto Networks' Cortex XSIAM and CrowdStrike's Falcon platform. The hosts also discuss the risks of…

0:000:00

How Bug Bounty Programs Find Vulnerabilities Before Attackers

Jul 30, 2026 · 8:07

Bug bounty programs have become a cornerstone of enterprise security. In 2025 alone, HackerOne's community reported over 100,000 unique vulnerabilities. This episode explores how companies like Google and Microsoft leverage crowd-sourced testing to catch flaws internal teams miss. We break down the economics: payouts versus breach costs, the choice between running an in-house program or using a platform like Bugcrowd, and why private programs are growing for sensitive assets. Lucas and Luna…

0:000:00

How Software Bill of Materials Improves Supply Chain Security

Jul 29, 2026 · 6:25

In episode 140 of Cybersecurity Business, Lucas and Luna dive into how enterprises are adopting Software Bill of Materials (SBOM) to manage supply chain risk. Starting with the Log4j vulnerability as a cautionary tale, they explain what an SBOM is—an ingredient list for software—and how it helps organizations know exactly what components are in their code. They discuss adoption drivers like the 2021 Executive Order and CISA's guidance, tools such as Anchore and Snyk, and real-world case studies…

0:000:00

How Cloud Misconfigurations Cause Most Breaches

Jul 29, 2026 · 9:00

Episode 139 dives into cloud security posture management (CSPM). Lucas and Luna break down a shocking stat: over 60% of cloud breaches stem from customer misconfigurations, citing Azure's latest report. They explore how tools like CSPM automatically discover and remediate risky settings, share a case study of a Fortune 500 retailer that closed 90% of critical gaps in three months, and debate whether CSPM is becoming table stakes for cloud adoption. A practical look at why 'the cloud is secure'…

0:000:00

How XDR Is Reshaping Enterprise Incident Response

Jul 28, 2026 · 6:42

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore how Extended Detection and Response (XDR) platforms are changing the way security teams investigate and respond to threats. They break down how XDR aggregates telemetry from endpoints, networks, and cloud workloads to reduce alert fatigue and accelerate containment. Lucas cites an IDC survey showing nearly 40% of large enterprises have adopted XDR by mid-2026, and contrasts it with traditional SIEM approaches. The…

0:000:00

How CISOs Fight Deepfake Social Engineering Threats

Jul 28, 2026 · 9:51

In 2025, a deepfake voice clone of a CEO tricked a multinational firm into wiring $25 million. As generative AI tools make voice and video synthesis cheap and convincing, enterprises are scrambling to update their social engineering defenses. This episode drills into how security teams verify identity on calls, the state-of-the-art in liveness detection, and why old-school callback protocols are making a comeback. We look at real-world incidents, the detection arms race between security vendors…

0:000:00

How SEC Disclosure Rules Are Reshaping Incident Response Plans

Jul 27, 2026 · 6:16

On July 27, 2026, a mid-sized healthcare company suffered a ransomware attack and filed an SEC 8-K within 48 hours. Lucas and Luna explore how the SEC's cybersecurity disclosure rule, effective since late 2023, has fundamentally changed how enterprises prepare for and respond to breaches. They discuss the pressure on CISOs to assess materiality quickly, the rise of disclosure committees, and why tabletop exercises now include mock filings. Plus: how the rule is forcing firms to rethink the…

0:000:00

How Enterprises Outsource Threat Detection to MDR Providers

Jul 27, 2026 · 8:30

Episode 135 of Cybersecurity Business with Fexingo dives into the rapid adoption of Managed Detection and Response (MDR) services. Lucas and Luna explore why over 60% of organizations now outsource threat hunting to providers like CrowdStrike and Arctic Wolf, citing a severe shortage of cybersecurity analysts and the need for 24/7 coverage. They break down the economics: a typical in-house SOC costs upwards of $1.5 million annually, while MDR subscriptions can start at $50,000 per year for…

0:000:00

How Companies Use Security Ratings to Vet Third-Party Vendors

Jul 26, 2026 · 7:12

In this episode, Lucas and Luna explore the rise of security rating platforms like BitSight and SecurityScorecard, which are replacing traditional vendor questionnaires. They discuss how a typical Fortune 500 company with over 1,300 third-party vendors uses continuous monitoring to assess risk, referencing the Verizon DBIR statistic that one in five breaches traces back to a third party. The hosts examine the methodology behind these ratings, including external scanning and breach data, and…

0:000:00

How Enterprises Use Identity Threat Detection and Response to Stop Credential Attacks

Jul 26, 2026 · 10:00

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore how enterprises are adopting Identity Threat Detection and Response (ITDR) to combat rising credential-based attacks. Using the 2023 Okta breach as a case study, they explain how ITDR fills gaps between traditional IAM and EDR, and why Gartner predicts that by 2026, 75% of enterprises will deploy ITDR. Lucas breaks down the difference between ITDR and other tools, citing vendors like Silverfort and CrowdStrike. The…

0:000:00

How Companies Use Ransomware Negotiation Firms to Manage Breach Fallout

Jul 25, 2026 · 7:29

When ransomware strikes, many enterprises now hire third-party negotiation firms to handle the attacker directly. This episode explores the rise of professional ransomware negotiators — often staffed by former FBI agents and crisis psychologists — who step in as intermediaries between victims and criminal groups. We discuss how these firms assess attackers' credibility, drive down ransom demands (by an average of 38% according to Coveware), and coordinate with legal and insurance teams in real…

0:000:00

How CISOs Use Cyber Deception to Trap Attackers

Jul 24, 2026 · 12:56

Episode 131 of Cybersecurity Business with Fexingo explores the emerging practice of cyber deception technology. Lucas and Luna break down how companies like a major European bank deployed fake assets—decoy databases, credentials, and network shares—to detect and study attackers in real time. They discuss a real case where a deception layer caught a ransomware group within hours of initial access, before any actual data was encrypted. Lucas explains the three types of lures: breadcrumbs…

0:000:00

How Enterprises Use Cyber Exposure Management

Jul 23, 2026 · 8:45

Episode 130 of Cybersecurity Business with Fexingo dives into cyber exposure management — the practice of continuously quantifying and prioritizing cyber risk across an organization's entire attack surface. Lucas and Luna explore how this approach goes beyond traditional vulnerability management by factoring in business context, asset criticality, and threat intelligence. They discuss the rise of exposure management platforms like Tenable's Exposure360 and Qualys TotalCloud, and how companies…

0:000:00

How Zero-Trust Network Access Is Replacing VPNs

Jul 23, 2026 · 11:28

Episode 129 of Cybersecurity Business explores how enterprises are migrating from traditional VPNs to zero-trust network access (ZTNA). Lucas and Luna discuss the CrowdStrike outage in July 2024 that accelerated the shift, the specific security weaknesses of VPNs — including lateral movement risks and credential theft — and how ZTNA architectures enforce least-privilege access. They break down the differences between ZTNA and VPNs, using Zscaler as a key example, and examine why the zero-trust…

0:000:00

How Security Teams Use Cyber Threat Intelligence Platforms

Jul 22, 2026 · 10:30

In this episode of Cybersecurity Business with Fexingo, Lucas and Luna explore how enterprises are operationalizing cyber threat intelligence platforms. They dive into a specific case: how a mid-sized financial services firm used an open-source CTI platform to reduce incident response time by 40 percent. Lucas explains the difference between strategic, tactical, and operational intelligence, and why many companies still fail to connect intelligence to actual detection rules. Luna challenges…

0:000:00

Why Enterprises Are Adopting Cyber Insurance Alternatives

Jul 22, 2026 · 11:35

Cyber insurance premiums have surged 300% since 2021, and coverage exclusions for nation-state attacks and silent ransomware are leaving companies exposed. In this episode, Lucas and Luna explore the rise of parametric cyber insurance and captive insurance structures as alternatives. They walk through a concrete case: a mid-size logistics firm that used a 144A catastrophe bond structure to create a $50 million cyber-specific captive, cutting its premium cost by 40% while gaining coverage for…

0:000:00

How Security Teams Use Digital Twins to Simulate Attacks

Jul 21, 2026 · 9:29

In this episode, Lucas and Luna explore how enterprises are deploying digital twins—virtual replicas of their production networks—to run attack simulations without risking real systems. They break down a specific case: a mid-sized financial services firm that built a twin of its trading infrastructure to test ransomware response. The hosts discuss the cost savings, the fidelity challenge, and why CISOs are treating digital twins as a core part of their cyber range exercises. Listeners will…

0:000:00

Showing the latest 50 episodes. The full archive of 175 is on Apple Podcasts, Spotify and every major podcast app — or via the RSS feed above.