Skip to content

Prabh Nair

Prabh Nair
Prabh Nair
Latest episode

157 episodes

  • Prabh Nair

    How to Prepare for CGRC Certification in 2026

    14/09/2026 | 42 mins.
    Many professionals come from ISO 27001, audit, compliance, or traditional cybersecurity backgrounds. But CGRC is strongly aligned with NIST publications, system authorization, security and privacy control assessment, and the Risk Management Framework lifecycle.In this podcast episode, Prabh speaks with Aamir about his CGRC preparation journey, the difference between ISO-based GRC thinking and NIST-based GRC thinking, and why CGRC is useful for professionals working in governance, risk, compliance, security authorization, FedRAMP, control assessment, and AI governance.
    In this episode, we discuss:What CGRC certification isWhy CGRC requires NIST-based thinkingDifference between ISO-based GRC and NIST-based GRCWhy NIST RMF is central to CGRC preparationHow CGRC is different from CISSP, CCSP, CISA, CRISC and ISO 27001Why system authorization boundaries matterWhy control implementation and assessment are importantHow compliance becomes a lifecycle processWhy POA&M is important in risk assessment and remediationHow FISMA, FedRAMP, NIST, COBIT and ISO connect in GRC thinkingWhy CGRC is relevant for security and privacy integrationHow CGRC connects with AI governance and algorithmic riskKey NIST publications for CGRC preparationHow to prepare using the CBK and structured training materialsWhy candidates must think like a risk governance advisorAamir also explains that CGRC professionals should be able to support the full security lifecycle:Define authorization boundariesIdentify and categorize systemsSelect and implement controlsAssess control effectivenessSupport authorization decisionsMaintain continuous monitoringTrack remediation through POA&MAlign compliance with business and mission risk
  • Prabh Nair

    Inside the Ransomware War Room | Human Side of Cybercrime with Jon DiMaggio

    10/09/2026 | 41 mins.
    Ransomware is not only a technical problem.Behind every ransomware attack, there are people — operators, affiliates, initial access brokers, negotiators, developers, money launderers, and criminal leaders making decisions under pressure.In this podcast episode, Prabh speaks with Jon DiMaggio, cybercrime investigator, founder and principal researcher at Arkham Cyber, and author of The Art of Cyber Warfare, about the human side of ransomware operations.Jon explains why organizations make a major mistake when they treat ransomware only as malware, encryption, indicators of compromise, backups, and recovery.The real adversary is human.To defend better, security teams must understand attacker motivation, fear, ego, trust, negotiation behavior, relationships, mistakes, and internal conflicts.In this episode, we discuss:Why ransomware is not only a technical problemWhy understanding the human adversary mattersHow ransomware groups operate behind the scenesThe role of initial access brokersHow affiliate teams work inside ransomware-as-a-service ecosystemsHow ransomware operators manage extortion and negotiation pressureWhy human intelligence matters in cybercrime investigationHow dark web research helps reveal attacker behaviorHow Jon investigated the LockBit ransomware groupWhy attacker psychology, ego, trust, and internal conflict matterHow technical intelligence and human intelligence work togetherHow MITRE ATT&CK, Cyber Kill Chain, and Diamond Model help defendersWhy technical indicators alone are not enoughHow ransomware negotiation patterns can manipulate victimsHow law enforcement and private-sector intelligence can support disruptionHow AI may increase the speed, scale, and automation of ransomware attacksWhy defenders must combine telemetry, threat intelligence, and human behavior analysisLinkedin Profilehttps://www.linkedin.com/in/jondimaggio/https://www.amazon.in/Art-Cyberwarfare-Investigators-Ransomware-Cybercrime-ebook/dp/B09BKLRH8P#Ransomware #ThreatIntelligence #CyberCrime #DarkWeb #LockBit #IncidentResponse #SOC #CISO #CyberSecurity #HumanIntelligence
  • Prabh Nair

    How to Crack JEE: AIR 59 Shares Study Routine, Mistakes and College Advice

    07/09/2026 | 33 mins.
    JEE preparation is not only about studying for long hours.

    It is about discipline, consistency, the right strategy, emotional control, mock test analysis, and making smart decisions during the final phase of preparation.
    In this podcast, Prabh speaks with Ishaan Singh, who achieved All India Rank 59 in JEE, about his preparation journey, study routine, coaching experience, final-week strategy, college selection, and the skills students should build beyond academics.

    Ishaan shares practical advice for JEE aspirants and parents who are trying to understand what really matters during preparation and after results.
    In this episode, we discuss:Ishaan’s JEE preparation journeyHow he built a disciplined study routineHow to manage school, coaching, self-study and personal activitiesWhy focused study blocks and regular breaks matterWhy avoiding social media helped him stay focusedHow to analyze mock tests and identify weak areasWhat to revise in the final week before JEEWhy previous year questions are importantWhy students should avoid difficult new problems just before the examWhy handwritten notes can improve learningRole of coaching in structure, testing and peer supportWhy students should not constantly compare themselves with othersHow to handle setbacks during preparationHow to choose a good engineering college beyond rankingsWhy students should speak with current students and alumni before choosing a collegeImportance of curriculum quality, peer group, internships, research exposure and campus cultureGap between college education and industry skillsWhy skills matter beyond college tagsHow students from non-CSE branches can still build careers in software and technologyHow AI tools can support learning when used correctlyOne of the strongest takeaways from this session:#JEE #JEEPreparation #Engineering #IIT #StudentLife #CareerGuidance #CollegeSelection #Education #Parents #CoffeeWithPrabh
  • Prabh Nair

    Privacy Ops Masterclass | Building Trust Across Product, AI and Security

    03/09/2026 | 51 mins.
    Privacy does not fail only because organizations do not have policies.Many times, privacy fails because it comes too late.After the product is designed.After the code is written.After the vendor is onboarded.After the data flow is already live.After the AI use case has already started using personal data.In this podcast/session, Prabh discusses the practical meaning of Operationalising Privacy across Product, AI and Security.This session focuses on how privacy can move from paperwork to real execution inside organizations.We discuss why privacy by design fails when privacy is reviewed only after design is complete, and why privacy must be embedded into product development, engineering workflows, AI programs, security reviews, data-flow mapping, risk scoring, and day-to-day business decisions.https://www.linkedin.com/in/devika-subbaiah-infosec/In this session, we cover:- Why privacy should not appear only at the end of product design- Why privacy by design must be embedded before code is written- What Privacy Operations really means- Difference between privacy policy and privacy operations- Why DPO oversight and Privacy Ops execution are not the same role- How product, security, legal, business and privacy teams should work together- Why data flow diagrams should be living maps, not one-time documents- How vendor changes, retention changes and subprocessors affect privacy risk- Why privacy risk should not be viewed only through a legal lens- Why privacy risk and security risk must both be assessed- How dual-axis risk scoring can help evaluate organizational risk and individual harm- How an Activity-First Data Model can reduce repeated privacy documentation- How RoPA, DPIA, TIA, LIA and consent records can be generated from a common activity record- Why privacy must scale across products, functions and AI programs- Why every privacy framework field ultimately represents a real person and a real riskThe key message is simple:Privacy that only works on the day it was checked is not privacy.Organizations need privacy systems that are operational, scalable, evidence-driven, and embedded into daily decision-making.Watch the full session and comment below:What is the biggest privacy challenge in your organization — product design, AI usage, vendor risk, data mapping, privacy operations, or DPO execution?#PrivacyOps #DataProtection #PrivacyByDesign #AIGovernance #CyberSecurity #GRC #DPDP #GDPR #ProductSecurity #PrivacyEngineering #CoffeeWithPrabh
  • Prabh Nair

    Threat Modeling for Agentic AI: Stop Treating Agents Like APIs

    31/08/2026 | 53 mins.
    Agentic AI is changing the way applications are designed, tested, deployed, and secured.Traditional application security focuses on APIs, authentication, authorization, databases, code, sessions, and technical attack surfaces.But Agentic AI introduces a different challenge.A user may not need technical knowledge to influence the system.A simple natural language prompt can make an AI agent classify intent, call a tool, retrieve data, generate a response, trigger a workflow, or influence a business decision.In this podcast episode, Prabh speaks with Akansha about Threat Modeling for Agentic AI Systems, using a practical customer support chatbot architecture as the case study.The architecture discussed includes:Classifier agentResponder agentQA reviewer agentHuman approval processRetrieval databaseTool integrationsLogging and monitoringRefund workflowThird-party integrationsThe session explains how a customer request flows through different agents, how intent is classified, how responses are generated, how refund requests are reviewed, and why human approval is important for high-risk financial actions.Content Reference https://github.com/smartdevil09/AI-Security-Professional-Roadmap/blob/main/AI%20security%20concepts/Threat%20Modelling%20Agentic%20Architecture.pdfLinkedin Profilehttps://www.linkedin.com/in/akesharwani/In this episode, we discuss:How Agentic AI differs from traditional application securityWhy prompts and natural language interactions create new risksWhy threat modeling should happen before production deploymentWhy stakeholder engagement is criticalHow to understand the business problem before identifying threatsHow to create an asset inventory for AI systemsHow to identify business assets and AI assetsHow to prepare data flow diagrams for multi-agent systemsHow to define trust boundaries between users, agents, tools, databases, and third partiesWhy refund workflows need stronger approval controlsWhy human approval is required for critical financial transactionsWhy logging and monitoring must be carefully designedHow to avoid logging sensitive PII dataHow attackers may exploit AI agents using prompt injectionHow AI agents may be manipulated into unauthorized actionsHow traditional AppSec controls still matter in Agentic AI systemsHow third-party Agentic AI systems should be assessedWhat documentation should be requested from vendorsHow to use STRIDE, MITRE ATLAS, OWASP LLM Top 10, CVE, and CWE for threat enumerationHow to evaluate likelihood, impact, business risk, and compliance riskWhy threat modeling must be continuously updated as architecture and threats changeAkansha also explains that threat modeling Agentic AI is not a simple automated checklist activity.It requires business context, stakeholder interviews, architecture understanding, asset inventory, data flow mapping, trust boundary analysis, risk assessment, guardrail design, logging, monitoring, validation, and continuous review.#AgenticAI #AISecurity #ThreatModeling #AppSec #AIGovernance #OWASP #MITREATLAS #CyberSecurity #GRC #CoffeeWithPrabh
More Technology podcasts
About Prabh Nair
Prabh Nair is a cybersecurity podcaster covering cyber risk, ransomware, incident response, SOC operations, GRC, AI security, threat intelligence, digital forensics, ISO 27001, CISSP, CISM, and security leadership. Built for SOC analysts, auditors, cybersecurity professionals, students, and business leaders, each episode delivers simple explanations, practical lessons, and real-world examples to help you stay ahead in the fast-changing cyber world. #CyberSecurity #InformationSecurity #CyberRisk #GRC #SOC #IncidentResponse #Ransomware #ThreatIntelligence #AISecurity #DigitalForensics
Podcast website

Listen to Prabh Nair, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features