Podcast · Tech & Cybersécurité
Random but Memorable
Matt Davey co-hosts an award-winning security podcast recognized by Signal and the Webby Awards for making complex cybersecurity topics accessible and actionable for business audiences.
⏱ 7 min read · Readable by ChatGPT, Gemini, Claude
Random but Memorable delivers award-winning security education through expert interviews, real-world breach analysis, and lighthearted security games that make cybersecurity concepts stick. The podcast covers emerging threats like shadow AI, prompt injection attacks, identity security failures, and the human factors driving modern breaches. Every other Tuesday, hosts Matt Davey, Michael "Roo" Fey, Anna Eastick, and Sara Teare break down how AI models detect (and fail to fix) vulnerabilities, why always-on access creates hidden risks, and what to do when your organization gets hacked.
- Signal and Webby award-winning podcast recognized for making cybersecurity accessible and actionable for business professionals
- Features in-depth interviews with industry experts on AI security, identity management, prompt injection, and emerging threat vectors
- Combines practical security advice with breach case studies, ensuring listeners understand both theory and real-world impact
- Published every other Tuesday by a four-person expert team experienced in threat analysis, incident response, and security culture
Explore the full episode archive of Random but Memorable to discover how these security principles apply to your organization.
What this podcast really covers
Random but Memorable systematically maps the security threats that keep enterprise leaders awake: the silent expansion of AI tools across organizations, the gap between vulnerability detection and actual remediation, and the identity-based attacks that exploit "always-on" access models. Recent episodes reveal a core tension in modern security—teams invest heavily in detection systems yet struggle with response when models identify vulnerabilities they cannot automatically fix.
The podcast goes deeper into psychology and compliance. Episodes on prompt injection attacks expose how adversaries manipulate AI systems through carefully crafted input, while segments on traveling professionals show that security isn't just a technical problem but a behavioral one. Interviews with guest experts like Rom Carmel (identity security), Keith Hoodlet (AI vulnerability analysis), and Glenn Wilkinson (breach response) ground abstract concepts in executable strategies.
Who this podcast is essential for
Chief Information Security Officers and Security Team Leads benefit immediately from the breach case studies and expert interviews, gaining language and frameworks to communicate risk to board members and implement identity controls that reduce always-on access exposure.
Enterprise Technology Leaders and IT Managers
Risk, Compliance, and Legal Professionals
What the episodes really reveal
The episode titles expose a systematic shift in threat sophistication. Early seasons addressed perimeter defense and data breach mechanics; recent episodes focus on the human and operational layer—vibe coding security, traveler risk, identity-based attacks, and the limits of AI as a security tool. This progression reflects reality: as technical defenses mature, adversaries move upstream to exploit identity, process, and human judgment.
Recurring themes emerge: AI is neither savior nor threat, but a tool that amplifies existing security gaps. Always-on access creates unnecessary risk surface. Breach response speed and transparency matter more than perfect prevention. Security culture—from coding practices to travel habits—shapes organizational resilience far more than infrastructure alone.
What this changes in practice
Organizations that apply insights from Random but Memorable typically shift three things: first, they implement time-bound access policies that require regular re-authentication rather than granting perpetual privileges. Second, they audit and govern AI tool adoption explicitly, treating shadow AI as a compliance risk equivalent to unsanctioned cloud services. Third, they invest in breach response playbooks and notification protocols before an incident occurs, recognizing that speed and transparency reduce customer churn and regulatory penalties far more effectively than investing another dollar in prevention systems.
Listen to Random but Memorable episodes on identity security and breach response to develop your security strategy with expert guidance.
Start listening to the latest security insights from Random but Memorable today.
The podcast answers these questions
What security risks do AI habits pose to businesses?
Uncontrolled AI usage patterns—what security professionals call "tokenmaxxing"—expose organizations to data leakage, prompt injection vulnerabilities, and unauthorized access to sensitive models. Employees who adopt AI tools without security oversight inadvertently create shadow AI environments that bypass standard compliance frameworks and increase breach surface area significantly.
Can AI models detect and fix security vulnerabilities automatically?
AI models excel at identifying vulnerabilities through pattern recognition and static analysis, but remediation remains a human responsibility. These models flag weaknesses accurately yet lack the contextual business logic and security architecture knowledge required to implement safe fixes without introducing new risks or breaking functionality.
Why is always-on access considered a hidden security risk?
Perpetual access privileges—whether for employees, contractors, or systems—create prolonged exposure windows for insider threats and lateral movement attacks. Organizations that maintain continuous identity access without regular re-authentication or privilege review compound the damage window when credentials are compromised, turning minor breaches into major incidents.
What should businesses do immediately after a security breach?
First, isolate affected systems to prevent further spread, then notify your incident response team and preserve forensic evidence without disturbing logs. Simultaneously activate your communication plan to inform stakeholders according to legal and regulatory timelines—speed of disclosure now determines compliance penalties, regulatory relationships, and customer retention far more than the breach itself.