The Defender’s Log Podcast
The Defender’s Log Podcast: Stories from the Cybersecurity FrontlinesThe Defender’s Log is your front-row seat to the real-world battles shaping today’s cybersecurity landscape. Hosted by seasoned professionals, each episode brings you face-to-face with the sharpest minds in digital defense, MSP/MSSP founders, CISOs, threat researchers, and architects, who are redefining what it means to secure our connected world.From zero-trust frameworks to ransomware takedowns, from DNS hardening to incident response in regulated industries, this podcast pulls back the curtain on the strategies, frameworks, and mindsets powering modern cyber resilience. Whether you're a security leader, IT strategist, or tech-savvy executive, you’ll walk away with the tools and stories that move the needle.🔐 Why Listen to The Defender’s Log?Cyber threats are evolving and so must our defenses. This isn’t theory. These are the actual voices of those defending systems under pressure, making real-time decisions that pr...
Episodes

Feb 20, 2026
Feb 20, 2026
58 min
Cybersecurity used to be about perimeter defenses and patch cycles.
Now it’s about decision speed, trust, and restraint—especially when AI is involved.
This conversation with Rafael Ramírez moves through decades of engineering experience, real-world incident response, and the uncomfortable reality that AI is scaling faster than governance, policy, and human intuition.
What stands out isn’t hype—it’s discipline. How leaders think about risk, how zero trust becomes a mindset (not a framework), and why AI security fails most often when it’s rushed instead of designed.
Key Discussion Points
00:00 – Cybersecurity, curiosity, and being “born an engineer”04:30 – Early systems, reverse engineering, and learning by breaking things10:45 – The moment cybersecurity became real: incident response under pressure17:10 – AI security for small and mid-sized organizations (what actually matters)18:40 – Governance, data, hygiene, and why fundamentals still win22:15 – Why AI is moving faster than strategy can keep up25:00 – The danger of shipping AI before it’s ready29:00 – Deterministic vs. non-deterministic systems (and why it matters)33:20 – Zero Trust as a mindset, not a checkbox37:00 – Guardrails, outbound control, and constraining AI behavior41:30 – AI as a double-edged sword47:10 – Local models, cloud swings, and the return of the edge52:00 – Trust is built over time—just like early firewalls54:40 – Technology, trust, and talent: keeping people at the center
If you’re building, defending, or deploying AI inside real organizations, this one will challenge how you think about control, trust, and responsibility.
Join the conversation:
👍 Like this episode to support the channel
🔔 Subscribe for more real‑world security insights
💬 Share your biggest AI takeaway in the comments
🔗 Send this episode to a colleague or friend who works in network security
#CyberSecurity #AISecurity #ZeroTrust #AILeadership #Technology #RiskManagement #AgenticAI #TheDefendersLog #AdamNetworks #SecurityArchitecture #RiskManagement #CloudSecurity #DefensiveSecurity

Feb 6, 2026
Feb 6, 2026
49 min
Attackers are getting smarter—and the protocol they rely on most isn’t what you think.
In this powerful conversation, David Redekop and Johannes Weber break down how modern malware abuses DNS, why attackers prefer DNS tunneling and exfiltration, and the defensive strategies every organization needs in 2026.
Johannes brings decades of hands‑on experience as a network security specialist, consultant, packet analyst, and educator. Together, they trace the full threat landscape around DNS and explore the evolving tools, behaviors, and techniques shaping the defender’s playbook.⏱️ Chapters & Key Moments
00:00 – Why 90% of malware still depends on DNS
01:00 – A fun start: German names, dual identities & cultural overlaps
03:00 – Johannes’ origin story: LAN parties → network engineer → security consultant
06:00 – You don’t need to code to thrive in network security
07:00 – DNS basics: recursive resolvers vs. authoritative servers
08:00 – How attackers abuse DNS “as designed”
10:30 – Lookalike domains & deceptive URL patterns
11:00 – DGAs (Domain Generation Algorithms) explained
12:00 – Newly registered vs. newly observed domains
14:00 – Aging domains & reputation‑based defense
15:00 – DNS exfiltration: how attackers sneak data out
16:00 – Step‑by‑step breakdown of DNS exfiltration
18:00 – DNS tunneling: when attackers turn DNS into a VPN
19:00 – Why signature‑based defenses fail
21:00 – Deep Query Inspection & entropy analysis
22:00 – Where DNS security belongs in your architecture
24:00 – TXT, NULL, A/AAAA abuse & blocking strategies
27:00 – DNS spoofing & cache poisoning
30:00 – DNSSEC: authentication vs. confidentiality
33:00 – DOH/DOT: privacy vs. visibility
36:00 – TLS interception & enterprise tradeoffs
39:00 – Securing roaming users in a VPN‑less world
41:00 – What Pi‑hole solves at home (and what it won’t)
43:00 – Johannes’ favorite tools: DNSViz, DNSDiag, DNSPing
44:30 – The Ultimate PCAP collection (15 years, 90+ protocols)
46:00 – Why Johannes teaches — and the next generation of defenders
48:00 – Closing thoughts & community resources
🛠️ Mentioned Tools & Resources
DNSViz – DNS trust visualization
DNSDiag / DNSPing – Resolver latency + diagnostic toolkit
Iodine / DNScat2 / DNS‑tunnel tools – Examples of DNS tunneling tech
Ultimate PCAP Collection (Johannes’ blog) – 15 years of protocols for Wireshark trainingIf this helped sharpen your defender instincts:
👍 Like this video to support the channel
🔔 Subscribe for more real‑world security insights
💬 Share your biggest DNS takeaway in the comments
🔗 Send this episode to a teammate or friend who works in network security
Together, we make the internet harder to attack — and easier to defend.#CyberSecurity #DNS #DNSSecurity #MalwareAnalysis #DNSExfiltration #DNSTunneling #DNSSEC #DOH #NetworkDefense #PacketAnalysis #Infosec #SecurityPodcast #BlueTeam

Jan 23, 2026
Jan 23, 2026
40 min
The odds remain badly stacked against the defender. As we hurtle toward a digital ecosystem populated by a trillion AI agents, the Universal Threat Ecosystem (UTE) is expanding at an asymmetric rate. The traditional security stack—obsessed with detection and response—is fundamentally broken because it requires a "Patient Zero." It waits for the compromise to occur before it rings the alarm.In this episode of The Defender’s Log, David Redekop sits down with Francois, CISO and partner at ADAMnetworks, to dismantle the "Whack-a-mole" approach to cybersecurity. From the high-stakes world of film production and technical diving to the front lines of cyber warfare, Francois shares how a life spent mitigating physical risk informed a "Default Deny-all" posture.The Asymmetric ChallengeWe are currently witnessing the rise of Generative Adversarial Networks (GANs) in the hands of the adversary. Initial Access Brokers (IAB) and Ransomware-as-a-Service (RaaS) operators are using the defender’s own AI tools to train malware to be invisible. If your strategy relies on identifying "known bad," you have already lost.Why "True Proactive" Defense is Mandatory:Neutralize Egress: If the malware cannot "call home" to its Command & Control (C2), the ATTACK IS DISRUPTED.Eliminate the Patient Zero Requirement: By moving the security boundary to the DNS layer with a Zero Trust Resolver, we stop connections to unknown and unverified entities.Sovereign Capability: Reclaim control over your network’s connectivity. Stop letting the internet happen to you and start shaping it.Detection is a post-mortem. Prevention is sovereignty.Francois and David explore the human element of the "Sheepdog mentality" and why the next generation of Blue Teamers must move beyond the application layer (Layer 7) and harden the foundation of connectivity itself.Key Technical Concepts Discussed:Zero Trust Connectivity (ZTC): Moving beyond identity to strict connection control.OT & IoT Vulnerabilities: Why agentless protection is the only path forward for critical infrastructure.Preemptive Defense: Cutting off the attacker's resources before the infrastructure is even fully deployed.In a world of a trillion AI agents, where the adversary uses your own defenses to train their attacks, can you afford to maintain a "Detect and Respond" posture? At what point does the convenience of an "open" network become an existential liability for your organization?

Jan 9, 2026
Jan 9, 2026
55 min
Defending the Internet, One Domain at a TimeIn this episode of The Defender’s Log, host David Redekop sits down with Peter Lowe, the creator and maintainer of one of the internet’s most widely used blocklists, a resource quietly protecting users for over 27 years.What started as a personal effort to block intrusive ads has evolved into a critical layer of modern cybersecurity infrastructure. Peter shares the technical, ethical, and human realities of maintaining a blocklist at internet scale, from DNS-based blocking and privacy challenges to dealing with criticism, threats, and constant technological change.The conversation also explores unexpected territory: how language, culture, and communication shape security, why defaults in operating systems matter more than most users realize, and how Apple, Microsoft, and modern platforms influence privacy at scale.This episode isn’t just about blocking domains; it’s about trust, responsibility, and defending the open internet without owning it.

Dec 26, 2025
Dec 26, 2025
59 min
The internet is a collision of legacy protocols and modern asymmetric threats. In this episode of The Defenders Log, I sit down with the man who built the foundation: Dr. Paul Mockapetris, the inventor of the Domain Name System (DNS).We don't just reminisce about the 1980s; we dissect how the Universal Threat Ecosystem (UTE) has weaponized the very decentralization that made the internet possible. The failure today does not come from gross negligence, but the imperfect application of the current stack. The odds remain badly stacked against the defender. While generic tools focus on detection, which is fundamentally too late, this conversation pivots toward Zero Trust Connectivity (ZTC).Strategic Deep Dive:The "Whack-a-Mole" Reality: Why chasing RaaS and IABs through traditional feeds is a losing game.Default Deny-All: Dr. Mockapetris explains his "day job"—making sure DNS doesn't work when you don't want it to.The DoH/DoT Trap: How hyperscalers are centralizing authority and eroding Sovereign Capabilities.Agentic AI: Preparing for a world with trillions of automated agents jabbering across your infrastructure.If you want to survive the next evolution of cyber warfare, you must shut down egress to the attacker. It is time to move beyond simple resolution and toward a hardened state of prevention.#CyberSecurity #ZeroTrust #DNS #ZTC #ThreatIntelligence #ADAMnetworks #InfoSec #CyberWarfare #PaulMockapetris #SovereignCapability #DefaultDeny

Dec 12, 2025
Dec 12, 2025
57 min
In this episode of The Defender’s Log, host David Redekop sits down with DNS and DDI expert Andreas Taudte, who brings more than 16 years of experience in network security, DNS architecture, and threat mitigation.Together, they unpack the real challenges organizations face with DNS, from evasion techniques and tunneling threats to the growing complexity of legacy systems and hybrid networks. Andreas explains why DNS predictability is essential, how DDI (DNS, DHCP, IPAM) has evolved, and what enterprises must do to build resilient, zero-trust-aligned network foundations.This conversation is packed with real-world stories, practical insights, and actionable strategies for anyone responsible for securing modern infrastructures. If you touch networking, cybersecurity, or cloud architecture; this deep dive is for you.Timestamps - 00:00 Introduction to DNS and DDI 01:20 Meet Andreas: A Deep Dive into DNS 06:22 The Journey into DNS and DDI 06:49 Understanding DDI: DNS, DHCP, and IPAM 09:53 Challenges and Stories from the Field 22:21 Security and Management in DNS and DDI 28:13 External Audits and DNS Management 30:16 Infrastructure as Code and Network Configuration 31:15 Building a Strong Foundation for Networks 31:30 The Reality of Temporary Solutions 32:00 Buzzwords and IT Management 33:34 Zero Trust and Default Deny All 34:25 DNS Threats and Exploits 44:22 Complex DNS Evasion Techniques 46:49 Combining Security Layers for Better Defense 52:03 Predictable DNS Resolution 54:17 Final Thoughts and Advice #DNS #DNSSecurity #DDI #Cybersecurity #NetworkSecurity #ZeroTrust #ITInfrastructure #CyberThreats #IPAM #DHCP #SecurityArchitecture #BlueTeam #NetworkEngineering

Nov 28, 2025
Nov 28, 2025
41 min
In this powerful episode, host David Redekop sits down with Joshua Domagalski, Chief Information Security Officer and former offensive operator, to explore the real complexities of modern cyber defense.Joshua opens up about his journey from the military to cybersecurity leadership, the shift from attacking systems to protecting them, and why defending is far more challenging than breaking in.This conversation goes far beyond tools and tactics, it uncovers the human, strategic, and geopolitical layers that shape cybersecurity today.You’ll learn about:Why offensive skills are essential for strong defenseThe truth about AI adoption in security operationsHow insider threats actually workRansomware strategy (not just response)Why experience matters more than certificationsThe real job of a CISO in 2025The importance of humility, discipline, and continuous learningHow geopolitics fuels cyber conflictWhy most breaches originate from human behaviorIf you're a SOC analyst, aspiring CISO, blue team operator, or cybersecurity enthusiast — this episode will reshape how you see the defender’s role.Timestamps - 00:00 Introduction and Early Interests01:00 Welcome to The Defender's Log01:16 Joshua Domagalski's Journey into Cybersecurity02:38 Challenges in Cyber Defense04:19 The Importance of Offensive Skills for Defense05:08 Balancing Proactive and Reactive Defense06:42 AI Adoption and Cybersecurity09:46 The Role of Experience vs. Certification11:39 Joshua's Path to Becoming a CISO14:16 Human Elements in Cybersecurity22:09 Strategies for Insider Threats and Ransomware36:17 Geopolitical Challenges in Cybersecurity39:40 Final Thoughts and Advice40:35 Conclusion and Call to Action#Cybersecurity #CISO #CyberDefense #Infosec #BlueTeam #Ransomware #AIinSecurity #OffensiveSecurity #SecurityLeadership #TheDefendersLog

Nov 14, 2025
Nov 14, 2025
51 min
In this episode of The Defender’s Log, host David Redekop sits down with Tim Adams, DNS threat intelligence expert and founder of ScoutDNS, to uncover the evolving world of DNS security. From his early days running a wireless network integrator to building a resilient DNS resolver service, Tim shares lessons in innovation, resilience, and the art of staying ahead of cyber threats. They discuss everything from DNS over HTTPS (DOH) and threat intelligence to balancing privacy, compliance, and encryption in a rapidly changing digital landscape. Whether you're a cybersecurity professional, MSP, or privacy advocate, this conversation offers an unfiltered look into the next frontier of internet defense.#Cybersecurity #DNS #ThreatIntelligence #DataPrivacy #InternetSecurity #NetworkSecurity #TechInnovation #Encryption #DOH #DOT #ScoutDNS #MSP #CyberDefense #TheDefendersLog #Podcast #Technology #Infosec #DigitalPrivacy #CyberThreats #TechLeadership

Oct 31, 2025
Oct 31, 2025
43 min
In this gripping episode of The Defender’s Log, host David Redekop sits down with Alexander Rau, Partner in Cybersecurity at KPMG, to explore the intense world of cyber incident response.From ransomware attacks and business email compromises to AI-driven ransom negotiations, Alexander shares firsthand experiences from the cyber frontlines, revealing what really happens when organizations are under digital siege.They discuss the psychological toll of defending under pressure, the ethical dilemmas in paying ransom, and why small and medium businesses remain top targets. Rau also explains how threat intelligence sharing, proactive defense, and human resilience can make the difference between recovery and collapse.This episode is a must-listen for cybersecurity professionals, executives, and anyone curious about how real digital warfare unfolds, and how to stay ahead of it.Timestamps - 00:00 Introduction 01:13 Meet the Guest: Alexander Rau 02:05 The Reality of Cybersecurity Threats 04:32 The Importance of Threat Intelligence Sharing 17:47 Challenges in Cybersecurity for Small and Medium Businesses 23:16 Standardized Unwinding Procedures 24:46 The Human Factor in Incident Response 26:32 Memorable Incidents and Threat Actors 27:13 Ransom Negotiations and AI Involvement 30:31 Ethical Dilemmas in Ransom Payments 33:40 The Evolution of Cybersecurity Practices 41:25 Final Thoughts and Advice

Oct 16, 2025
Oct 16, 2025
49 min
In this episode of The Defender’s Log, host David Redekop sits down with Sami Khoury, the Head of the Canadian Centre for Cyber Security, for an inside look at the battle to protect national infrastructure from unseen digital threats.From his beginnings as a research engineer in 1992 to leading one of Canada’s most critical cybersecurity agencies, Sami shares lessons from three decades of defense — from combating ransomware to promoting “secure-by-design” innovation.Discover how public-private collaboration, education, and technology are shaping the next frontier of digital security. Whether you’re a cybersecurity professional, policymaker, or tech enthusiast, this episode will leave you with a new appreciation for the people protecting the digital realm.🧠 Key Takeaways:Ransomware and the evolution of modern cyber threatsWhy “secure-by-design” is the foundation of cyber resilienceThe power of collaboration between government and private sectorsBuilding a cybersecurity culture through awareness and innovationInsights into the mindset of a lifelong defender of the digital realmTimestamps / Chapters00:00 — The Original Spark: Passion for Problem-Solving 01:01 — Welcome to The Defender’s Log 01:17 — Meet Sami Khoury: Canada’s Cybersecurity Leader 03:34 — The Journey from Engineer to Cyber Chief 06:34 — A Day in the Life of a National Cyber Defender 08:55 — Cyber Policy and the Power of Innovation 12:19 — Inside the Cyber Center: Strategy and Collaboration 28:50 — Ransomware: The Evolving Threat Landscape 34:19 — Building a Culture of Cyber Resilience 40:59 — Recognitions, Reflections, and Lessons Learned 44:42 — A Call to Action: The Future of Cyber Defense








