The Audit - Cybersecurity Podcast from IT Audit Labs features trusted security experts, industry leaders, and practitioners who unpack the threats, tactics, and trends shaping today’s risk landscape. With 90+ episodes and a top 10% global ranking on Listen Notes, The Audit goes beyond surface-level security talk. Each episode explores real-world threats, attacker techniques, compliance challenges, cyber risk, and the decisions security teams face before, during, and after an incident. IT Audit Labs helps organizations identify risk before attackers exploit it. Through threat assessments, security control reviews, compliance expertise, and a trusted network of partners and specialists, we help teams find their soft spots, strengthen their defenses, and make smarter security decisions. Listen in for sharp conversations, practical insight, and a clearer view of what’s coming next in cybersecurity.
Pitch Analysis
Required Pod Score for this show. PitchCentric checks your profile against host openness, topical fit, and audience signals before you generate a pitch.
Contact path
Verified email
Booking probability
34%
Guest openness
Selective
Verified email on file
80/100
Required Score
Sign up to generate a grounded pitch for The Audit - Cybersecurity Podcast.
Our AI reads these to draft pitches. Use them as grounding for a pitch that cites a real guest and a specific topic.
Episode #97
Cybersecurity News: PaperCut Breach, AGI Hype and Patch Tuesday
Sep 21, 202637 minS1
Nation states are paying top dollar for zero day vulnerabilities, hackers went from an empty lab to domain admin in under four hours, and Nvidia's CEO says we just crossed into AGI. On this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the cybersecurity stories shaping the week and dig into a debate that has no clean answer. The crew opens with news that Eric Brown has a book on the way, built around lessons learned managing technology for clients over the years, before moving into Patch Tuesday, a PaperCut vulnerability that AI agents used to hack hundreds of organizations in seconds, and Nvidia CEO Jensen Huang's claim that artificial intelligence has already crossed into AGI territory. The conversation closes with an ancient parable about a fireman, and what it teaches modern IT teams about the habits they reward. In this episode: Eric Brown's upcoming book workshops potential titles for his book on fixing the managed service provider model. Patch Tuesday and zero days explained, covering what Microsoft's monthly patch cycle fixes and why a zero day can be worth a fortune to a nation state. The PaperCut breach and printer security, where an AI powered attack hit 395 organizations through a PaperCut flaw, echoing printer security nightmares the crew has seen during audits and pen tests. Have we already reached AGI, with Jensen Huang saying yes and Sam Altman calling the term meaningless, as the crew works through the paperclip dilemma and an AI sandbox experiment. The Fireman's Paradox, a centuries old parable about ignoring good advice and what it says about why organizations keep rewarding firefighting instead of prevention. If this episode gave you something to think about, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #PatchTuesday #ZeroDay #Cybersecurity #AGI #PaperCut #ITAudit #InfoSec #AIThreats #Podcast #ITAuditLabs
Building the Future: AI Coding, Agentic Advisors and Custom Tools
Sep 8, 20261h 16mS1
What if your company didn't need a single line of code to build its own CRM, or a board of directors made up entirely of AI agents? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Loren Horsager, founder of Model Mind AI, who has been working in AI since 1993 and now spends his days coaching businesses and CEOs on how to actually put it to work. Loren has helped organizations trade their bloated software stacks, their expensive middleware, and their old habits for AI-driven processes that get built in days instead of quarters. The crew digs into vibe coding, AI councils, and the death of the traditional user interface, then pivots into the harder questions: what happens to developers, where security has to fit into the process, and why voice AI still hasn't earned people's trust. Along the way there's talk of AI trading bots, a QuickBooks security scare, a routing engine that hit 100 percent on-time delivery, and a debate about whether vinyl records and iPods still have a place in an AI-driven world. In this episode: Why vibe coding terrifies developers who ignore it The AI council approach to strategic thinking Why nobody loves their CRM anymore Where security has to sit in AI adoption Why voice AI works for productivity but not yet for trust If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #AI #VibeCoding #Cybersecurity #ITAudit #AIAgents #Automation #BusinessAI #TechLeadership #DigitalTransformation #TheAuditPodcast
Cyber Warfare on Tap: Water Utility Hacks, Nation-State APTs and Secure Browsers
Aug 24, 202648 minS1
What happens when nation-state hackers target the water coming out of your tap? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the recent wave of attacks on water utilities across Minnesota and 27 other states, where threat actors got their hands on administrative passwords to programmable logic controllers. The crew is joined for the first time by Kelly Venzke, Director of Business Operations at IT Audit Labs, who brings a business leadership perspective to a conversation that quickly turns technical. From there, Eric and Nick trace how these attacks echo the Stuxnet playbook used against Iran's nuclear program, explain how threat actors are impersonating help desk staff over Microsoft Teams to gain remote access, and dig into a blockchain-based command and control technique that hides inside paid search ads. The conversation wraps with practical advice on browser security, including why isolating AI browser extensions and ditching saved passwords in the browser matters more than most people realize. In this episode: Nation-state hackers breach US water utilities across 27 states. How Iranian threat actors obtained administrative access to programmable logic controllers and why Minnesota may have been ground zero. The Stuxnet connection. Eric breaks down how the historic attack on Iran's nuclear centrifuges bridged an air-gapped network, and why today's "air-gapped" systems often aren't as isolated as they seem. Help desk impersonation over Microsoft Teams. Why blocking external Teams-to-Teams calls has become a critical defense against social engineering attacks targeting employees. EtherHiding: blockchain-backed command and control. How attackers use paid search ads and blockchain infrastructure to maintain persistent, hard-to-detect access to compromised environments. Practical browser security tips. Kelly, Eric, and Nick talk through password managers, isolating LLM browser extensions, and why saving passwords in your browser is a bad habit worth breaking. Don't wait until your organization is the next headline. Like, share, and subscribe for more conversations on the threats shaping cybersecurity and IT today. #Cybersecurity #InfoSec #NationStateThreat #CriticalInfrastructure #WaterSecurity #APT #EtherHiding #BrowserSecurity #ITAudit #Stuxnet
Decode Your Team: The Kolbe Index, Conative Strengths and Hiring Smarter
Aug 10, 202644 minS1
What if the way you solve problems has nothing to do with how smart you are or how you feel, and everything to do with instinct? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from SipCyber and guest David Kolbe of Kolbe Corp, whose company built the Kolbe Index to measure the instinctive way people take action. After the whole team takes the assessment live, David breaks down what their scores actually mean and why the crew's mix of Fact Finder, Follow Thru, Quick Start, and Implementor strengths shapes the way they operate under pressure. The conversation moves from the Johari Window and personal blind spots to why teams that clone each other's strengths tend to stall out, and why hiring people unlike yourself is one of the best things a leader can do. David also shares stories from decades of client work, from a CFO who built a physical model of a financing plan to a security engineer who cannot walk past an unsecured cable, before turning to what comes next for Kolbe Corp as they build AI tools around decades of behavioral data while trying to keep that data private and secure. In this episode: What the Kolbe Index actually measures, and why it's different from personality or IQ tests. Conative strengths describe how you instinctively take action, not what you think or how you feel, and they do not change over time. Why balanced teams outperform teams that clone each other. A team full of people with the same instincts feels comfortable right up until deadlines start slipping and nobody notices the blind spot. How opposite strengths cause friction, at work and at home. If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #KolbeIndex #TeamDynamics #Cybersecurity #Leadership #HiringSmart #ITAudit #WorkplacePsychology #TeamBuilding #Podcast #ITAuditLabs
Lock Picking Secrets: Key Cloning, AI Coding and Safe Cracking
Jul 27, 202646 minS1
Can a $35 padlock from a hardware store really keep anyone out? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Eric Osterberg of Grey Duck Locks for a live lock picking demo, a deep dive into how modern car keys get cloned, and a wide-ranging conversation about vibe coding, AI agents, and 3D printing. Eric brings decades of hands-on locksmithing and automotive security experience, along with a builder's instinct that has him constantly shipping his own tools, from a computer-aided dispatch app for emergency management volunteers to a searchable database for ham radio operators. The crew gets into how pin tumbler locks are actually picked, why European vehicles like Audi and Volvo are harder to clone than most domestic trucks, and how devices like the Softdrill can manipulate a safe's dial by listening to its own internal mechanics. From there the conversation turns to AI, covering Eric's use of large language models to streamline his business, the rise of vibe coding for non-programmers, and a heated but even-handed debate over new federal rules pushing automakers toward built-in driver monitoring systems. In this episode: Live lock picking demo and how pin tumbler locks actually work How car key cloning really works, and why some brands resist it better Safe manipulation tools like the Softdrill and TL2000 Vibe coding, AI agents, and building your own tools without a dev team The driver monitoring debate — A new federal mandate pushes automakers toward built-in impairment detection Whether you're curious about lock picking as a hobby or trying to understand how exposed your car key really is, this episode has something for you. Like, share, and subscribe for more conversations at the intersection of security, hardware, and AI. #LockPicking #Locksmith #Cybersecurity #CarKeySecurity #VibeOps #AIAgents #ITAudit #Podcast #3DPrinting #InfoSec
Every question we get asked before someone starts their trial.
If you have a concern about deliverability, AI quality, data privacy, or whether this will actually work for your specific situation, it's probably answered below.
What is the difference between Founder Solo and Founder Pro?
Founder Solo gives you 50 AI pitches per month using the credit model (Standard pitches cost 1 credit, Enriched pitches cost 2). Founder Pro raises that to 200 credits per month and adds full Booking Probability access, unlimited Magic Match, Apollo enrichment credits, and data export capabilities. Both plans use the same credit system, so you can stretch your monthly budget further by using Standard-mode drafting.
How do agency tiers work?
Agency tiers have no base fee. You pay per managed client and per talent profile. Agency Standard is $199 per client per month; Agency Pro is $399 per client per month. Both add $39 per talent profile per month. Your own team's user seats are always free.
What is a talent profile?
A talent profile represents one person (founder, executive, or spokesperson) you are booking onto podcasts. It includes their bio, topics, headshots, and outreach history. Team plans include 5 profiles; agency plans are pay-as-you-go.
Can I switch plans later?
Yes, at any time. Upgrades take effect immediately; downgrades apply at the end of the current billing period. Contact support if you need help migrating between plan families.
Do you offer a free trial?
Every paid plan includes a 15-day free trial. Your card is saved at signup but you will not be charged until day 16. Cancel any time from your dashboard.
What happens if I cancel?
You keep access until the end of your current billing period. No charges after that. Your data is retained for 30 days in case you reactivate.
Is the 20% annual discount automatic?
Yes. Select Annual on the pricing toggle and the discounted price is applied automatically at checkout. The annual price shown is the full year cost.
What if I have more than 50 profiles or 20 clients?
That is our Enterprise tier. Contact our sales team and we will build a custom plan with volume pricing, a dedicated account manager, and SLA guarantees.