エピソード

  • QA and Automated Testing
    2026/09/17

    Everyone claims their testing tool does AI now, and Jay Newlin (Director of Quality Assurance) has the flooded inbox to prove it. He and Greg Vanore (Director of Software Engineering) join host Matt Triner to talk about cutting through that noise, why customers still don't believe automation is worth paying for, and the readable, declarative test frameworks that actually change their minds. Then things get personal with the two worst legacy code handoff stories you'll hear this year, one on burned CDs, one on three-ring binders of printed source code, and what disciplined test automation looks like when you inherit either one.Episode Chapters:

    00:00 Introduction

    00:07 Automated Quality Assurance Testing in Software Development

    01:22 Challenges in Assessing Tools for Automation Testing

    02:42 The Importance of Automation in Testing

    03:50 Educating Customers on the Value of Automation Testing

    04:41 Expanding Testing Techniques Beyond Traditional Methods

    05:48 Customer Perception of Automated Testing

    07:09 The Future of Automated Testing

    15:57 Balancing Rapid Deployment and Quality

    16:58 The Importance of Unit Test Coverage

    17:56 Maintaining Test Automation During Rapid Deployment

    20:41 The Role of Tooling in Government Environments

    22:56 Deliverables and Documentation in Government Contracts

    25:12 Testing Legacy Systems

    27:56 Considerations for Legacy Systems in Test Automation

    34:43 The Future State of Automated Testing

    続きを読む 一部表示
    43 分
  • Applied Cyber Threat Intelligence
    2026/09/10

    Ask 5 people to define threat intelligence and you'll get 5 different answers, and that's exactly where this episode starts. Will Elchert (Senior CTI Analyst, Hunter Strategy) and Jake Williams (VP of R&D, Hunter Strategy) join host Matt Triner alongside two clients living this from the buyer's side: Keith McCartney, SVP of Security and IT at DNA Nexus, and Billy Martin, CTSO at Vigor. Together, they break down what separates a threat intel program that actually drives decisions from one that's just, as Jake puts it, "cyber story time with the CTI team." The conversation covers where AI genuinely helps in CTI workflows and where it falls flat, how red and blue teams each get value out of the same intelligence, and what metrics actually prove a security program's worth to leadership.

    Episode Chapters:

    00:00 Introduction to Cyber Threat Intelligence

    02:51 Defining Threat Intelligence

    05:41 Stakeholder Engagement in Cybersecurity

    08:34 Risk Management and Cyber Threat Intelligence

    11:36 Industry-Specific Approaches to Threat Intelligence

    14:25 The Importance of Context in Threat Intelligence

    17:07 Integrating Cybersecurity Functions

    19:51 Actionability of Threat Intelligence

    25:24 The Evolution of Cyber Threat Intelligence

    28:58 AI's Role in Cybersecurity

    32:19 Data Analysis and AI Integration

    37:14 Challenges and Opportunities with AI

    41:27 Human Element in Cyber Threat Intelligence

    49:57 Red Team vs Blue Team Dynamics

    52:28 Red Team vs Blue Team: Who Leverages CTI Better?

    55:02 Funding and Capability Development in Cybersecurity

    58:11 The Importance of Communication and Collaboration

    01:01:14 Metrics for Measuring Threat Intelligence Effectiveness

    01:09:45 Building a Cybersecurity Program from Scratch

    続きを読む 一部表示
    1 時間 21 分
  • Threat Modeling Techniques in Defense Cybersecurity
    2026/09/03

    Threat modeling is one of cybersecurity's most valuable practices, and one of the most skipped. Xander Keele (Director of Solution Architecture) and Greg Vanore (Director of Software Engineering) join host Matt Triner to break down frameworks like STRIDE and PASTA, why developers push back on it, and how to get buy-in without falling into pure theory. They also dig into how AI is changing the pace of both attacks and defenses.

    Episode Chapters:

    00:00 Introduction to Threat Modeling in Cybersecurity

    02:12 Defining Threat Modeling and Its Overlooked Nature

    07:13 The Role of Risk Assessment in Threat Modeling

    12:09 Social Skills in Threat Modeling and Development

    22:06 Higher-Level Threat Modeling and Industry Context

    24:45 Real-World Applications of Threat Modeling Techniques

    31:49 Enhancing Threat Models with Market Insights

    34:10 The Role of Market Share in Risk Assessment

    36:36 Contractual Implications of Threat Modeling

    41:34 Integrating Threat Modeling into Development Culture

    52:02 Adapting Threat Modeling for Emerging Technologies

    続きを読む 一部表示
    55 分
  • Opensource Software Security in the DoD
    2026/08/27

    Open source software promises cost savings and faster innovation, but the Department of Defense's approach to it is messier than most people realize. Host Matt Triner sits down with Hunter Strategy's Greg Vanore (Director of Software Engineering) and Nate Kingsley (CIO) to unpack the real risks: contributor license agreements that can sign away government-funded code, foreign ownership questions that don't always get consistent answers, and a supply chain that's only as trustworthy as its weakest link. They also dig into what's actually fixing the problem, from CI/CD pipelines to continuous ATO. This one gets spicy.Episode Chapters:

    00:00 Introduction and Overview

    01:59 Defining Open Source Software

    03:49 Contributor License Agreements and Licensing Issues

    06:08 The Challenges of Open Source Software in the DoD

    08:39 The Need for Clear Policies

    11:25 The Financial Challenges of Open Source Software

    17:19 The Risk of Support and Lack of Governance

    20:12 The Permissiveness of Open Source Software in the DoD

    24:02 Supply Chain Risk and Software Sourcing

    30:11 Improving the Use of Open Source Software

    35:16 The Role of S-BOMs and Information Sharing

    37:49 Conclusion and Call to Action

    続きを読む 一部表示
    38 分
  • The Most Useless NPM Repos
    2026/08/20

    TIL: npm has a package called "none." It does exactly what it sounds like: nothing. It still gets 300 downloads a week. There's also "is-even," which calls out to an AI model to check whether a number is even, with about 80% accuracy, because apparently modulo operators were too much work. Matt Triner sits down with Matt D'vertola, Greg Vanore, and Jeff Segal to laugh at npm's most absurd packages and then get serious about what they expose: arbitrary code execution on install, a transitive dependency system that snowballs trust across thousands of hands, and why typosquatting a familiar package name still works embarrassingly well. The jokes are the hook. The supply chain risk is the point.


    Episode Chapters:

    00:00 Introduction to NPM and Its Impact

    06:45 The Dark Side of NPM: Security Risks

    11:49 Micro Packages: A Double-Edged Sword

    14:45 Cultural Reflections on Node.js and NPM

    19:41 The Evolution of UI and UX Development

    24:24 Cultural Divide in Application Development

    28:47 The Rise of JavaScript and Node.js

    33:47 The Importance of Software Engineering Fundamentals

    35:30 Best Practices for NPM Security

    続きを読む 一部表示
    46 分
  • Team Death Spiral
    2026/08/13

    Your product is getting worse, not better, and everyone's too busy bailing water to notice the boat isn't even the problem. Hunter Strategy's Greg Vanore, Scott Hiland, and Jeff Segal break down the Team Death Spiral: the slow, often invisible slide from a healthy team into one buried in tech debt, low morale, and busted trust. They get into why "tech debt" is the wrong word to bring into a leadership conversation, what it actually means when a team isn't allowed to lead, and why more money or headcount rarely saves a struggling team. Spoiler: the fix usually has nothing to do with the budget.Episode Chapters:

    00:00 Understanding the Team Death Spiral

    03:30 Identifying Warning Signs

    07:18 The Role of Leadership in Preventing the Spiral

    13:36 Communication and Team Dynamics

    18:03 Tech Debt: A Deeper Dive

    21:50 The Necessity of Automation in Agile Development

    22:49 Challenges in Team Automation and Ownership

    25:14 Leadership's Role in Preventing Team Death Spirals

    27:11 Effective Communication and Empathy in Leadership

    29:31 Balancing Fun and Seriousness in Team Dynamics

    30:11 Empathy Towards Non-Human Factors

    34:54 Navigating Difficult Conversations with Stakeholders

    37:18 Understanding Profitability and Team Efficiency

    39:09 The Importance of Maintenance Over Replacement

    48:02 Agency and Resource Allocation in High-Performing Teams

    54:48 The Impact of Resources on Team Performance

    続きを読む 一部表示
    55 分
  • Security Clearance Processes
    2026/08/06

    Security clearances are confusing enough on their own - facility clearances, personnel clearances, safeguarding, network access - and the rules rarely work the way people assume. In this episode, Matt Triner talks with Sean Blackman, co-founder and CEO of Nooks, about the real bottlenecks holding companies back from classified work, including the "chicken and egg" problem of needing a clearance to win a contract and a contract to justify a clearance. They dig into why building your own SCIF can take two years before a network is even touched, and why "go get a prime to sponsor you" is too often the only advice small businesses get.

    Sean explains what Nooks is actually solving: shared, subscription-based access to secure facilities around the country, and why he sees this as a national scaling problem, not just a paperwork one. If you're a founder, contractor, or engineer weighing whether classified work is worth pursuing, this conversation lays out what to expect and where to start.

    Episode Chapters:

    00:00 Introduction and Overview

    05:01 Introducing Nooks: Classified Infrastructure as a Service

    08:01 The Challenges of Scaling in the Classified Marketplace

    11:57 The Role of Nooks in Solving the Access Problem

    19:56 Solving the Dual Use Problem: Defense and Intelligence

    22:52 The Timeframe for Security Clearances and Network Access

    28:42 The Role of Commercial Solutions for Classified

    33:57 Challenges and Opportunities in the Classified Marketplace

    39:52 Advice for Companies Entering the Classified Space

    続きを読む 一部表示
    42 分
  • How to Determine Materiality in a DFIR Situation
    2026/07/30

    What actually makes a cybersecurity incident "material" - and who gets to decide? In this episode of This Is Fine, host Matt Triner sits down with Lee Kim (IANS Faculty and Practicing Law Institute member) and Jake Williams (VP of R&D, Hunter Strategy) to break down materiality in digital forensics and incident response. They cover the legal definition of materiality, the SEC's share-price test from TSC Industries v. Northway, and why the call should sit with counsel rather than the forensics firm. The conversation also digs into practical guardrails: documenting decisions in real time to avoid hindsight bias, building scenario-based frameworks before an incident hits, and where large language models do (and very much don't) belong in forensic work. A grounded, occasionally profane look at a topic every incident responder eventually has to wrestle with.

    Episode Chapters:

    00:00 Introduction to Digital Forensics and Materiality

    04:12 Understanding Materiality

    10:45 Regulatory Frameworks and Materiality

    15:32 Establishing Materiality in Incident Response

    23:20 Understanding Materiality in Forensics

    28:13 The Role of Stakeholders in Defining Materiality

    35:37 The Future of Materiality and Regulatory Changes

    41:09 AI's Role in Forensics and Materiality

    続きを読む 一部表示
    46 分