
The Department of Know: Astra launches, CISA cuts programs, McKesson breached
About this episode
Read the full stories at CISOSeries.com
This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
A huge thanks to our sponsor, KnowBe4

Get every episode summarized
Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
370 searchable segments. Every word is indexed and playable.
Full transcript
Cybersecurity Headlines — The Department of Know: Astra launches, CISA cuts programs, McKesson breached. Machine-transcribed; use the interactive transcript above to jump the player to any line.
This is Rich Drafalino with the department of, no, we have a fantastic show lined up for you. It's going to start by introducing some of our guests Jonathan Waldrop, C-so over at acoustic. Jonathan, thanks for being here. I got to ask, what has been your priority this week? Well, it's soon to be fall, even though I feel like you're hearing it landed still about 97,000 degrees. But it's almost as pumpkin-sized, pumpkin-spice latte season, which means cyber screen awareness month is right around the corner, so get your plans together. Yes, I love it. I love whenever someone gamifies that in a fun way for cyber security awareness month. It's always a ton of fun. Also, always a ton of fun is when we have Montez Fitzpatrick, the director of information security and global head of cyber security over at Energizer Holdings on the show. Montez, I know you're a busy guy. Both you and Jonathan are, but I got to ask, what has been your priority this week? Well, mostly Jonathan, and I am mostly waiting for the weather to debate. It's been 40 plus degrees C here. That's for our international folks that I know, because
you know me, I'm kind of like Mr. Worldwide, as it were, but kids getting back to school and kind of getting back into the rhythm of things. Putting a global in global CISO, truly, truly appreciated. All right, we now know we're all standing where all our minds are telling we want to just cool down a little bit, but the news is going to stay hot. So let's get into it, got to run the intro. We'll see you on the other side. From the CISO series, it's department of no. Yes indeed, it is the department of no, this is your virtual Friday strategy meeting. Big thanks to our sponsor, Runde, and that is no before for helping us out here and supporting what we're doing here. Remember to get involved on our YouTube chat, live broadcast, effort Friday at 4 p.m. Eastern, or you can shoot us an email, feedback at CISOSeries.com. We love seeing all of those glorious emails, and we deeply appreciate them all. Just a quick reminder here that the opinions expressed by our guests are, in fact, they're our own. In fact, some of the opinions I expressed are going to be my own as well,
not necessarily those of anyone's employer. We've got about 30 minutes, so we're going to dive right in here. We've got one of our favorite segments here, a little something we like to call no or no. This is where we run through some of the stories in the past week. We want your quick take on these. Is this something we want to bring to our security teams? What's the angle here? What really matters here? What is just a fancy headline we will delve into all first up here? You as Senator Ron, why don't you want the NSA to say whether commercial VPNs can withstand sophisticated foreign surveillance, single-hob VPNs route traffic through one provider, an adversary could compel or infiltrate point of failure there, while multi-hob systems add servers, so no one operator can see both the user and the destination. Why don't we want comparisons of things like Apple private relay, Tor, NIM and mix nets, plus clear guidance for government personnel, defense contractors, journalists, and human rights defenders facing advanced threats. Montez, let me start with you. Do these comparisons of capabilities matter to you down the line if and
when these kind of things become published here? Are we going to be asking any commercial VPN to stand up to a state-based actor, just kind of already a little bit ridiculous here? Well, I think you really nailed it, Rich. The commercial VPN against nation-state actor is the absolute wrong calculus, right? The commercial VPN is meant to hide your browsing from your ISP when you're doing naughty watching, right? That's what I heard. That's what I heard. People are saying. This will keep on the streets is what people are saying. This is kind of a calls coming from in the house kind of thing. So when an organization has a wide net cast over all ISPs and all traffic, I mean commercial VPN is really not going to be the thing, right? Jonathan, what about you? Is there any merit to this? A little bit more visibility to at least know, hey, this is, you know, we have some options here. Any argument here?
So first off, Montez nailed it, right? This is something you can buy off the shelf or something you download for free is not like the top tier, whatever. Now, that said that the fact that Congresspeople, senators, elected officials are talking about VPN and how do we improve security? Great. That's good. We do need to have these conversations. But I'm, yeah, I mean, I'm going to go go download opera and everything's going to be fine. So we'll be good. Yes, Mike. My Apple private really labeled definitely help when North Korea decides to be with some fake job operas. Absolutely. All right here. Let's go across the pond here. UK reaches for the tech vendor eject button. Ladies and gentlemen, to the UK's December security and resilience bill, would let ministers restrict high risk tech suppliers from energy, water, transportation, healthcare, and data infrastructure. China can't, oh, sorry,
I had something in my throat here. I don't know what that's all about. Officials could demand stronger safeguards, order a phase withdrawal or just flat out band purchases in very serious cases. The bill is third, the House of Commons that is now in the House of Lords because British legislatures have adorable names. Jonathan, the UK seems to be trying to shake up its cybersecurity policy responses. We've seen this over. I want to say the last year and a half. We've seen them kind of do their big reset here. Is this kind of ability to do a policy rug pull from a vendor perspective meaningful? Or is this just something to keep over the heads of? Let's just say China out there to keep them under best behavior. This is, hey, we have this card in our back pocket. We could do the unilateral ban. We saw the US kind of do something with this with a lot of our networking infrastructure a couple of years ago now. But I'm curious what are your thoughts here? Yeah, I don't think that I think this is just sitting in the signal, hey, you're going to have to be sneakier to get past us. Honestly, I think the key here is this feels like a reactive control. We talk about reactive kind of detection controls and security and we talk about proactive
controls and security. I think we need more proactive controls and security. The fact that, hey, you had a breach bed on you. We're going to pull you out. We're going to put you on the bad boy list or bad girl list, whatever. That's not going to help prevent this from happening next month, next year, next decade. I think the key here is we've had to talk about prevention. People always love pointing fingers and whose fault was it at the end of things? At some level, we do have to do that. We've got to figure out what happened, get to the ground truth. But honestly, I think we need to spend our time thinking about good strategies to prevent this, rather, prevent and detect, than whose fault was it? How can I down their company? Mind you what about for you? Are you a fan of the closed barn doors after horse leaves kind of approach? I think Jonathan nailed it. The state-based SP and Ajak was when they heard about this, I'm sure they were just biting their nails. They're like, what will we do now?
No. No. I think. They don't necessarily know the best of dates. When we begin to think about the operational reality, what it costs to prevent replace, especially when it comes to our operation technology, that is all predicated on the fact that your Ajak button, the ejection seat clears the plane, which it most certainly will not in this case. Yeah. We saw that when they wanted to rip out all that Huawei infrastructure, especially from a lot of rural ISPs, they're just weren't cost-competitive solutions out there that, again, unless this policy comes with, and we've allotted this budget to allow us to do that in the event that we actually need to do this, it becomes a lot more academic, I think, at that point. Just a quick shout out to Dave Beave, the truth in our chat, finally making it to the live show. Appreciate you having here. David, make sure you get in there, let us know what you think about the stories. I see CCL in there and April as well. So happy to have some people in our chat. Have fun there. Next story here on No Were No, AI powered vulnerability
reports, drive down bug bounty prices. Dark reading recently looked at the impact of the Lone Poc ellipse on bug bounty programs. The LLM has uncovered a mass of bug reports and an increase in vulnerability discovery, platforms and companies that run much of the bug bounty industry have faced increased triage and payout times. The issue is also being compounded by low quality AI generated slot reports from those looking to make a quick buck. You know, Montez, we've got two stories kind of back to back here and No Were No that kind of deal with the changing economics of security, particularly when it comes to AI. Here, the knock on AI bug bounty specifically is that slot never looks at exploitability, at least that's kind of been the narrative that I've seen out there. I'm curious from your perspective, will the economics of bug bounties kind of ever go back to where they were kind of make sense again? Like, it doesn't this come down to, hey, the actual bug bounty value here is doing that human triage, doing that legwork ahead of time before you hit submission. I'm curious, where do you see this kind of going?
You know, I think this is not a simple question and I'm not known for brevity. I will try, though, I will try. And one thing, I am nostalgic and sometimes about things and I think this is one of them, we can say like the maybe the bronze age of bug bounty, I believe we'll come back, but the targets will become more complicated, like across surfaces, across systems being, you know, put together and, you know, much more complicated. So the, the water, the bar, I think, has been lowered or is maybe completely gone in a lot of regards, but I think is going to come back in that way there. Jonathan, yeah, I'm sorry, I'm not that Dominican. No, no, no, no, no, I say, hey, I did it. You know, that was well great for me. I keep it a nice and lucid and tight. I like it. Jonathan, I got to ask, are we, is it a, you know, as Montez said, you know, we've exited the bronze
age of reentering in the, I guess we've jumped to the steam age of it feels like a build a tail. Yeah, yeah, for the, the, oh, I like that, the gilded, the gilded, the gilded, where, where are we at with, bug bounty these days? Maybe this makes it more accessible to companies. I mean, really, I think that the difficult part of bug bounty programs is not necessarily the cost, but the, the get it right, although the kind of legal protections that you got to go through. Honestly, you know, maybe, maybe this helps some, I think we talk about democratizing security across organizations, across people, across leaders. And maybe this kind of helps with different models, the, like we've got all this things, all the AI models to help identify vulnerabilities. We also have AI models to help fix them too, right? So, you know, I think it's where, where we focus our time and where we focus our energy on. So, but garbage and garbage out, that that's, that's never going to, never going to go away. Yeah, I think to your point, it used to be, oh, they have a bug bounty program, they're doing this the right way, right? They're
creating the incentives right to like, to get this report. And I think that's maybe the, like, this is no, that is no longer an indicator of anything, right? Because everybody's doing this all the time. Our last story and nowhere know here, the cost of porting PLC exploits, researchers at 4 Scout published research on the cost and time it takes to port exploits developed for specific PLCs to related hardware. They looked at two, two kind of different exploits on a single PLC and they found that having a skilled researcher guide the LLM model was far more efficient for quickly porting the vulnerability than lending the model operate in isolation. In one case, Sonnet 4.6, I guess completely stalled out to crash out trying to get there, while Opus 4.6 to eight hours, Deportive Vulnerability, at the cost of around $500, it tokens, which feels like what I use on just a monthly basis whenever I accidentally switch over to Opus. The report found that a human researcher can parallelize this work, but AI has the potential to reduce the marginal cost of doing so across many related targets
at once. Jonathan, is this, and this one, I'm curious, are you surprised at the time and cost finding here? Does that follow along with your expectations or is it just helpful to have kind of a baseline to kind of measure against? I don't know about the cost and time. What really I thought about was this is proof that one AI is not here to take over yet. We're not going to all find ourselves jobless, but if you put a smart brain behind LLM, that's way better than somebody who doesn't code and doesn't know about, can't do computers and try to write an app to solve World Hunger, I don't know. But honestly, I think we put smart people behind it, and it can used in the right way. This can absolutely become a force multiplier, but we can't just take people that don't know anything about it, give them an LLM and expect them to solve all the problems fast and cheap. Yeah, that was kind of the weird thing about this report. I would have thought they would have doubled down on me. This can make human, like this greatly increase the
efficiency of a skilled human versus, oh, they're a guide. Did anything strike you when this research? No, 500 dollars were tokens of something that I would imagine would be this complex is an absolute fire sell. Because what does this type of research cost in the, on the prior to this in open market there, I think it's like five or six hundred dollars an hour for a researcher or something that's specialized nature like this and agree again with Jonathan. That's why I know that I like them because I do it's a multi-level even smoking. I like it. Is that the reality is that with even my own things that I do, the leveraging the LLMs in general, they are, it's not that is doing things that I can't do, but it's really on the at least an order of magnitude more efficient with the things that I've created and is just that's what I think is where we're really
going to see the true power. Thanks to GC Johnson and the chat there for let me know. I was on my AirPods right here. So thank you for letting me know. I'm now on the good mic. So it is now better. And much like going back to the conversation though, the, what is interesting here is that I don't usually like the saying like this is the this is the worst AI is ever going to be. But I think in this case, like they were using Opus 4.6, which is, you know, we were on like two versions more of that, fabled what we're going to talk about, you know, fabled and Mithos 5.1. These days, I don't know what percentage they are better, but I would imagine over time, maybe if it's even just using something like fabled or something like that to help, you know, be the moderator for a cheaper model or something like that. Even if you don't have that skilled research to be able to, you know, and it does end up jacking up your token costs, you know, to your point, it used to be $500 an hour and dot, dot, dot, who knows how long it's going to take if it's even feasible. Just feels like a complete,
I do think we're at that point of this is the longest and the most expensive this potentially could be in terms of like, you know, just commodifying that whole process of porting these over. So a very, a very interesting situation. Another very interesting situation is who's supporting us this week as our sponsor. And that is of course, no before. Your employees have always been the target, but the threats they face are evolving. AI empowers cyber criminals to clone a co-workers voice, fake a video call with your CEO or personalize a fishing email using details scraped from your own website. No before is AI Native security awareness training fights back with 12 autonomous defense agents that allow you to deliver personalized relevant and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations. Trust no before worldwide. Find out why at nobefore.com. All right, let's get into some of our deep dives. We've got
some big meaty topics here. First up, I alluded to it just a second ago new AI models and new AI rules. All right, I'm going to try and blast this as quick as I can. So in response to all of the model X escapes out there and Thropic has announced new safety rules for agents. This includes creating a new real-time classifier to detect and block agent escapes, strengthening isolation of high risk sandboxes and having more red teaming on those high risk sandboxes. Sandboxes must now default to no internet access when being to evaluate by third parties with verification required before every run. And these sandboxes need to be pressure tested before running any evaluations. I don't know what AI sandbox pressure testing looks like, but it sounds very impressive. The company also released meathos and Fable 5.1. As I mentioned, headline feature here, Fables, Guardrails will now allow it to identify software vulnerabilities for defensive use. Fable 5.0's Guardrails were very restrictive on cyber security use cases. So kind of loosening that up. Open AI meanwhile, launched its astramodel claiming it's the first mile to reach a critical cyber security threshold dot dot
company is pursuing an IPO and will be going public. A caveat's aside, meaning it can now find unknown flaws and build exploits, excuse me, and build exploits across well-defendant systems without step-by-step human help. Maybe for like a PLC porting, an exploit porting, who knows? The advanced server capabilities will only start with a small test group. They are still slower, rolling all of this. And finally, a group of about 100 firms, this includes a lot of big names, Google, Microsoft, and Thropic, open AI. Capital One, MasterCard, Visa, Adobe, Oracle, and IBM signed an open letter calling on countries and organizations around the world to beef up their cyber defenses before AI grows powerful enough to override them. That sounds encouraging. All right, Montez. Okay, I think everyone agrees, you know, beefing up defenses, AI, something that should be called for or at least re-evaluating where we are with defenses in the age of AI here. But also, we have new models that can do even more cybersecurity stuff. Is there anything in that announcement that caught your eyes as the bigger,
the bigger deal, you know, guardrails, we got increased guardrails and safety considerations, new models, open letter that says, hey, fix the stuff. What stood out to you? Well, the open letter will absolutely work. That's first, right? You know, that will absolutely work. We're all letting it onboard is just that easy. Yeah, we fixed it. Kind of one of those things that I think it has to be done and it should have been done, you know, there's really no not being on the wrong side of that. You know, when you say guardrails, it sort of reminds me of fences and we all know that fences keep honest people honest. And so, if we want to read into that, I think that, you know, our dishonest folks, people who are aiming to break bad will absolutely find ways, you know, around the fence. And I think, you know, there are opportunities with the non-fronture models as they get more
and more sophisticated that this may not even be. So we could be looking at the wrong thing, as maybe what I'm saying, although it's very impressive. Jonathan, the one thing that stood out to me and I love to keep track of who signs what open letters of the week, right? It seems like every company that handles payments is on every open letter and they're extraordinarily worried about all of this, which makes me feel like this isn't just, I'm more nearly very skeptical of anytime someone's about to go public and they need to sell more of their own thing that they are advocating for that thing. But like, MasterCard and Visa are signing on to everything about figuring out open source supply chain. Well, warning about AI and railing advances here, like, so that's, to me, stood out, what for you stood out in this kind of trio of announcements here? I think, honestly, a couple things that I think about when reading articles like this, one, my first thought is, okay, how do I apply it to my organization? And articles about mythos and fable and like all the different model, how cool they are and
how great they are at finding vulnerabilities. If you got unpatched systems, quit fiddling with mythos and fable and go fix those unpatched systems, right? So one, focus on priorities. That said, there's plenty of people that are doing research and all this kind of stuff. It's very valuable. We need that. For the 100 companies and obviously all the big names here that you would expect, I think we'll talk about it in a little bit. But like, hey, let's go write emails to all these governments and tell them they need to help. Okay. And then what? Like, what's the plan? And I think these companies are in the best position to provide some support on what that might look like. Partnerships across organizations, particularly companies that are almost competitors, like when we look at the ISAC space, that's an organization that has really helped move security forward and help level the playing field and kind of that thought of the rising tide raises all
boats type of thing. And so I think this is really how, you know, if this is going to help us come together, align behind a couple of common objectives and hey, let's get a, let's get a foundational level for X. Yes, but some on Tesla's point. Yeah, I put a fence up. Okay. It's four feet tall. I could top over that. I could even hop over that. And I'm, you know, however, our new AI powered stills will enable us. Yes. Yes. All right. Next up here, one of them are interesting kind of dual stories that I just kind of saw a link to here. So we have critical infrastructure security shifting from public to private, maybe. So first up, we have CISA saying they're going to scale back six free assessments. The agency had been offering to critical infrastructure organizations. And they're citing essentially we don't have enough people to do them all with names like several resilience reviews and ransomware readiness assessments. These actions involved CISA regional advisors, meeting with infrastructure operators, asking them questions and help them to use the agency's cybersecurity evaluation tool or C sets to generate reports with recommended
security improvements. Should be noted C set is like an open source standard. So like these are available, you can still go find the old tooling out there and tactically run them yourself, but still kind of a bummer here. But at the same time, the US government launched project watershed 250. This is a six month Texas pilot pairing water utilities with private sector cybersecurity and AI companies, the office of the national cyber director and Texas cyber command will oversee the effort with about a dozen companies volunteering expertise and tools. The point here is to test what actually improves utility defenses before the model is expanded elsewhere, basically saying is this a viable model. Jonathan C set retreating just as the administration is launching a pilot for a public private critical infrastructure initiative seems like curious timing here. Do you think something like this kind of public private partnership has a better chance of reaching more critical infrastructure providers? We'd see that there was a lot of goodwill kind of coming out of the gen. Easterly CISA administration there with building out these kind of free tooling sets or would you rather this be a yes and rather than a no but kind of situation?
I do think some of the programs that came out of CISA in years past were on target, right? It's making security accessible to a lot of different types of companies and organizations that may or may not have a budget. Hey, there's still things you can do to help configure to get to a baseline that don't involve going to buy a fancy new tool. And that's the case around security in general. I do like some of the public private partnerships just because we all have skin in the game. And we do look to our elected officials to provide for the common defense whether that's whatever that means. In this case in a cyber security context, there are any number of ways that this could help. Is it the end of the answer? No, absolutely not. But hopefully this provides some footing that we can launch from. Where are you sitting at? Kind of looking at these two stories
hand in hand. I think of other efforts like Craig Newmark I recall has kind of been very passionate about doing kind of staging in a civil defense effectively, right? Kind of not quite as explicit public private partnerships, but is that the way this has to go as threats become, you know, more sophisticated? It's easier to be more sophisticated, I guess, for a variety of actors when it comes to critical infrastructure. Yeah, where am I sitting? I am very happy that Jonathan would first want this question. And so, but if I were to be in you know, Rich, you told me that I had to be optimistic for one question and here it is. Please. My optimism is that so in the reality, even with when we have, you know, a public initiative, you know, that always tends to start even still with like, you know, private parties that are experts in that realm, right? And so you could argue potentially that this is more or less short circling that and still in and bringing maybe some of
those private parties who would then be advising to something that would become like a public initiative directly to, you know, private. That's if we were to be optimistic. And so hopefully that is the case. And do I see how this could work? Absolutely. As long as we keep, you know, our wallets and our pockets, right? But as soon as the wall comes out, then I think there are other things that happen. Yeah. What I am encouraged with is it's not just we're doing this everywhere, right? Like it seems reasonable to this and a relatively small scale pilot, although, you know, Texas A not inconsiderate, a lot of critical infrastructure there as we have found out with various weather disasters or the last couple of years here. I think the idea of if the idea of this is, let's honestly see what works, right? Let's see what the cost is. Can we convince private companies that, right? You know, it turns out maintaining critical infrastructure that your business depends on is like actually in your, you know, your business self interest to kind of be motivated to be proactive about.
That idea seems like it could have some merit. Again, I am, I think guarded optimism is too optimistic my take on this. But I don't think there's obviously no one solution to this, right? Even if CESA was fully staffed and we were giving this away, we're trying to lift, you know, raise everybody up to the cybersecurity poverty line and we're, you know, doing all this, we're telling that is not the answer in and of itself alone, right? So the more things we can throw at this, it makes me sad when we are losing resources, even as we are, you know, potentially trying some interesting new stuff. So that's, I will, I will sit in the middle. Thank you for taking the optimistic as was you were contractually obligated. That's right. Yeah, it's in my country. All right. And our last story for today, we got a bad breach trifecta. So basically, I need just make the case for which one is the worst breach here. First up, we have the US healthcare giant McKesson confirming that the company suffered a cybersecurity incident involving unauthorized access to third party applications and data theft. Shining hundreds, extortion group has publicly
claimed that they stole 284 million patient records, which last in my check is a lot. A dark web service called Nexus, meanwhile claims it's selling scans of more than 153 million US and Canadian drivers licenses, plus over 10 million other ID cards. The images appear tied to the Louisiana based ID scan not.net, which provides identity verification to retailers, rental call companies and others, 153 million less than 284 million last time I checked. And finally, we have Thompson Reuters disclosing a cybersecurity incident impacting its court management software, which resulted in a breach of sensitive case data across 11 US states and the US Virgin Islands, as well as several Ontario courts. This leaked confidential, redacted or sealed information affecting various courts. We kind of don't know the scale or scope of that being very cagey, obviously. Although this incident did happen in March, so they probably, I hope they have figured out what exactly has been lost in that case. This one, that one was the most notable for the delay here. My test, I'm going to start with you here, not a great day for being a third party service provider.
Patient data IDs or court data, which one, which one do you got worse? We'll reach you know that I worked in healthcare security for quite a while. And so I'm going to have to go with court data on this one. And here's why. And here's why. So it's, I wanted to go with patient data because of the long live-inness of it. But when I really got to thinking about with the court data, I don't have any, you know, any foreknowledge of this. But potentially when you're talking about cases that haven't been adjudicated yet, and you know, that getting out into the public domain, you know, somewhere are or another. And so then, you know, unfairly biasing someone who is of course innocent until proven guilty. I think that's where I sit there. Jonathan, what about you? Are you going court docs or make the case? Come on, make the case. Let's go. As I was thinking about this, I'm, this is a real world scenario of what's worse from the flagship show, right? Yes.
And so, so Montez, I hear you on some court cases that have yet to be adjudicated. And that's an angle that I honestly hadn't thought of until you mentioned that. So that's valid. Think of through Nexus claims of 150 million ID cards. Like that feels like, okay, yep, another big one. Yeah, it's a lot of people, but not too spicy of that data. And I mean, don't don't undersell it, obviously. But for me, 284 million, that is a lot of people. And when you're talking about patient outcomes, that somebody's health is on the line. And we are as people as humans, we're no more vulnerable than we are in the hospital. And that gives attackers a huge angle on social engineering to pose as a hospital bill or some provider bill in all that kind of stuff. So for me, the worst case here is sadly, McKesson. So thoughts and prayers and hug ops to all the
folks that are responding to these incidents. But man, McKesson is, that's hard. Can I just say it is a weird world that we live in when like 153 million drivers licensing just come out? And I'm just like, okay, yeah, like I just feel like like 10 years ago, we'd be like, this is a privacy outrage. Something needs to be done. Yeah. Yeah. Exactly. And now we're just like, you could deep fake them anyway. Who cares? Yeah. I will say to me, like the court data provides a more unique social engineering opportunity. If you got your hands on what people considered sealed court data. So yes, the pure volume and just the, again, like all of these are our degrees of horrible, like getting health data out there. I just, again, like my kids, like, just power school data got leaked. And I was like, I was upset by the breach of their privacy. Who cares if they got a C in gym or whatever. But like, health data that is so incredibly personal, so incredibly, again, the medical system is so obtuse when it comes to billing and or opaque when it comes to that.
All of those, I could see some potential for some real damage there. So just, it seemed like just, big bad breaches were abounding. And we had to give, we had to give the run out here. Absolutely. DC Johnson legitimately wants to know how many more drivers licenses are there than 153 million. What point can we say all of them got that is extremely valid point because that we got to be pretty close. Yeah. Most people at that point. Shout out to that service, though, for having a big data set customer base. So who knows how many of those were expired, though, as well. That could be part of the reason. So big. All right. That just about brings us to the end of the show. I want to give a huge, huge thank you to both Jonathan Wall Drop the C-Soo over at acoustic and Montez Fitzpatrick director of information security and global head of cybersecurity over at Energizer Holdings for being here. We'll have links to both of your show notes. Thank you. So so much for being here. Always a pleasure. We will have to have you both back on before too long. Thank you. Thanks very much. And thanks also to our sponsor. No before for sponsoring
the show today. Remember you can send us your feedback anytime feedback at CisoSeries.com. A huge thank you to everybody in our chat helping us have some fun here. We had DC Johnson, David Murray. We had Brown Coyotes and Hello World. I know how to do that in Python. That's the extent of my coding skill before Claude was invented. So there we have that. So thanks to everybody that was hanging out April as well in the chat. Having some fun with us. Make sure to invite a friend next time. Tell them to join us every single Friday at 4 p.m. Eastern for the show. We always have a fun time. Thanks so much for being here for our Friday stand up. Have a great week. Stay secure out there and for myself for the Big Boss man David Spark for the entire Ciso Series team and for in fact for Montez and for Jonathan. Here's wishing you and yours to have a super sparkly day. Cybersecurity headlines are available every weekday. Head to CisoSeries.com for the full stories behind the headlines.
More episodes
More from Cybersecurity Headlines

MikroTik routers hijacked, Russian data center threats, UK cybercrime losses sur...
Cybersecurity Headlines

Court records breach, Breeze Comet hits Brazil, Aesto records breach
Cybersecurity Headlines

153M licenses for sale, Anthropic reverses course, Astra enters the red zone
Cybersecurity Headlines

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability
Cybersecurity Headlines