
Hashtag Realtalk with Aaron Bregg
Aaron Bregg
Welcome to my little corner of the Internet!
In this channel I give 'real talk' about information security and technologies that impact both your business and personal lives. I try and focus on issues and items that can help you become more 'security curious'. The ultimate goal of help protect your personal and professional well being.
Employer Disclaimer - The opinions and views expressed in the podcast are not necessarily the views of my current employer, Corewell Health.
Legal Disclaimer - All of the security advice that I give is 'as is' and does not constitute real paid professional advice. As with everything security related, please seek second opinions from paid professionals. Photo by
All episodes
Best episodes
Seasons
Top 10 Hashtag Realtalk with Aaron Bregg Episodes
Goodpods has curated a list of the 10 best Hashtag Realtalk with Aaron Bregg episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to Hashtag Realtalk with Aaron Bregg for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite Hashtag Realtalk with Aaron Bregg episode by adding your comments to the episode page.

Episode 106 - CISO Insights - Lessons Learned in My Healthcare Security Journey
Hashtag Realtalk with Aaron Bregg
12/18/24 • 50 min
In this special episode, I finally get a chance to do a virtual fireside chat with my talented and funny CISO Scott Dresen. I actually started working with Scott while he was the Chief Technology Officer for Spectrum Health. It was in this role that Scott down the path to becoming the Chief Information Security Officer for Corewell Health. So you can say he has been here for the entire Information Security program revamp that started back in 2016.
Talking Points:
- Back in 2016 you were the CTO when the Information Security program was 'rebooted'. What were some of your biggest challenges and frustrations back then?
- In 2018 you assumed the dual role of CTO and CISO, what was the hardest thing you had to change/overcome with having that dual role?
- Let's talk to WannaCry incident, what did the high level leadership view look like and what decisions needed to happen?
- In 2019 you had to re-evaluate the state of the security program at the halfway part of the timeline. During that you had to make some hard choice about the direction we needed to go in order to compete things. How did you come up with those decisions?
- You have had the distinct 'pleasure' of being a part of both a small healthcare and large scale acquisitions, what are some valuable lessons learned from each?
- In 2020 you had to pivot from an almost entirely in-person workforce to almost 100% remote, how did you manage to accomplish this in a timely and successful manner?
- In 2023 you had a chance to speak in front of congress around healthcare security, walk me through how that came about, how you felt in the moment and what things would you do differently (in hindsight)
- What has been the hardest part of planning and implementing Artificial Intelligence security?
- Heading into 2025, what advice do you have for other healthcare security leaders as they face the challenges of tighter budgets, smarter threat actors and changing business strategies?
Episode Charities:
- Toys for Tots of Grand Rapids - Presents for less fortunate children
- North Kent Connect - A great foundation that helps families with items that may not be covered by other programs
- YMCA of Greater Grand Rapids - Great organization promoting healthy lifestyles
Episode Sponsor:
Cloud Con - Michigan's premier security and infrastructure conference!

Episode 25 - Let's Talk About Zero Trust
Hashtag Realtalk with Aaron Bregg
11/11/20 • 45 min
In this episode I talk about the concept of 'Zero Trust' with Patrick Tyler. Patrick is a Senior Solutions Engineer for Okta.
Talking Points:
- What is Zero Trust and why should you care?
- What did organizations have to do right away when it comes to Zero Trust?
- Why Zero Trust is important for 'non-traditional' cloud industries like manufacturing to do it?
- While VPN is a powerful tool, it isn't the 'End All Be All' for security.
- What did organizations have to do right away?
This episode is sponsored by Okta. Okta is a Workforce and Customer identity company that is based out of California. Proceeds from this sponsorship will be going towards prizes for the holiday fundraiser event.

Episode 14 - A Casual Conversation on Social Engineering
Hashtag Realtalk with Aaron Bregg
09/02/20 • 41 min
In this episode, myself and my CSA sidekick Matt Nelson, talk with Ken Liao from Abnormal Security about email security and how social engineering is wreaking havoc on businesses.
Topics include:
- The Recent Twitter Hack
- Iran Advancing Their Social Engineering Skills
- The Importance of Good Email Hygiene
- What Does The Future of Email Security Look Like?
A big thanks to Abnormal Security for sponsoring this podcast! A majority of the proceeds will be going to low income students in West Michigan!

Episode 82 - What the Heck is Wrong with Security (Updated)
Hashtag Realtalk with Aaron Bregg
04/05/23 • 44 min
4.6.23 Update:
If you had downloaded this file before 6pm on April 6th you received the wrong episode. This error has been fixed and you have my sincerest apologies for the mess up!
*Disclaimer* While there was no physical harming of bad security vendors in this episode, there is a lot of honest #RealTalk. Opinions in this episode are my own and do not necessarily reflect the views of my leadership or my employer. Additionally, this episode is not sponsored and therefore is not influenced by outside sources.
In this episode I finally had some time to go over to the 'Fresh' Coast of West Michigan and sit down with Matt Nelson to talk about the current state of the cybersecurity industry. Matt is a Senior Solutions Architect for GuidePoint Security and brings a plethora of both useful and useless security knowledge to the conversation!
We kept the conversation focused on several different key areas of information security:
- How NOT to work with a business if you are a security vendor
- How are companies dealing with the rising cost of cybersecurity
- Giving some #RealTalk advice to people looking to break into the information security industry
While this episode went a little bit longer that I would like, it contains a TON of useful advice for not only employees and leaders, but security vendors as well.

Episode 105 - Monsters Under Your Bed: Mapping The Dark Web with Python
Hashtag Realtalk with Aaron Bregg
11/06/24 • 50 min
*Disclaimer* While this episode deals with an incredibly important topic, there are potential dangers in doing this type of work. PLEASE do your homework and be well prepared should you go down this path, as your life can be impacted with a wrong turn.
In this episode, which is the first of a listener requested one around technical topics.
With cybercrime and threat actor activity on the rise, it is more important than ever to understand the dark web and monitor it for potential risks or signs of a breach. There are several tools and intel providers that can do this, but they’re not cheap. So why don’t we just do it ourselves?
Python can handle simple tasks surrounding dark web scanning and offers more customization for complex tasks. Using strictly free open-source libraries and any system you have available, you can set up an automated scanner and detect threats as they arise.
Scan for IP addresses, potentially compromised emails, crypto addresses, and any regex patterns that you desire. Map your findings to the most relevant onion sites and get an understanding of where your adversaries tend to operate. This is just a start. From here, you can go almost anywhere.
Episode Charity:
Proceeds from this episode's sponsorship will be going towards the Baker-Bonsai Friendship Fund. Bruce Baker was a great bonsai tree artist and along with Deal Bull, helped make the art of bonsai be something wonderful that can be shared for future generations at the Frederik Meijer Gardens.
Episode Sponsor:
Cloud Security Alliance of West Michigan
Talking Points:
- Why is it important that you at least have a basic understanding of the Dark Web is you are in the Small and Medium sized Business (SMB) space.
- Pros and Cons of Build vs Buy
- What safeguards do you want when out in the fringes?
- What are the mental health aspects of doing this type of work? How manage those pressures?
- What are Seed URLs?
- How to use Dark Web templates for scanning.
Description credit to GrrCon

Episode 73 - Thinking Differently About Privacy
Hashtag Realtalk with Aaron Bregg
11/23/22 • 38 min
In this episode I sit down with Paul McManus about all things Privacy. Paul is a Senior Information Governance Analyst for Corewell Health Corporate. I have had the distinct pleasure of working with Paul on several different privacy related engagements over the years.
Talking Points:
- What are some of the challenge you are seeing in privacy space right now?
- Integration
- Who watches the watcher?
- As more and more things are outsourced, how do you this with digital assets?
- Do people realize that data that may not be considered 'confidential' now may considered something different in a year or two?
- How are privacy laws changing?
- How is the GDPR different than the US laws?
- Are what point do we 'globalized' healthcare privacy
- Ownership vs Rights
- What are re-selling of de-identified data?
- What about privacy with wearables and driving trackers?
We even had the pleasure of having a quick appearance from a special 'In-House' guest that knows a thing or two about Research Privacy, resident System Architect, Heather Bregg.

Episode 74 - Let's Talk Advanced Email Security
Hashtag Realtalk with Aaron Bregg
11/30/22 • 45 min
In this episode I have a 1 on 1 conversation with the one and only Brian 'Schneebs' Schneble about Advanced Email Security. Brian is a Senior Enterprise Account Executive for Abnormal Security. Brian is not only an active member of the Michigan cybersecurity community but he has extensive knowledge of the automotive industry.
Talking Points:
In a break from the traditional talking points, for this episode we break down a real world use case where a company was hit by a very creative 'double whammy'. Both a compromised email account and a look-a-like domain were used in this attack.
Brian and I walk through what happened, how it could happen and how you can do things to avoid this in your company.
- Compromised Email Accounts
- How Malicious Actors 'Learn' Your Workflows
- Look Alike Domains
- Defensive Domains
- DMARC
This was a highly informative episode and don't mind the state of security talk about the beginning. Listen/View the whole episode, as it will definitely be worth spending your time on!
Podcast Sponsor:
This episode is sponsored by Abnormal Security. Abnormal Security is an Email Security Solutions provider that is known for using Machine Learning to detect non-traditional email attacks. Parts of the proceeds from this sponsorship will be going towards a 2023 InfoSec scholarship at my alma matter Grand Rapids Community College.

Episode 76 - Why Your Business Needs Data Visualization
Hashtag Realtalk with Aaron Bregg
01/18/23 • 30 min
In this episode I had a chance to talk to Lisa Jones-Huff about the importance of data visualization and how it can help both security AND the business. Lisa is the Senior Director of Global Security Specialists for Elastic.
Talking Points:
Some basic steps for understanding how to interpret your data:
- What is the very first thing you should do on your data visualization journey?
- What type of data do you have?
- What is the value of that data?
- What types of use cases provide the most 'Combined Value'?
- How can Graph can help tell the story in a detail that a 'regular' person can understand?
Episode Sponsor:
This episode is sponsored by Elastic. Elastic is a multi-faceted business and security solutions company based out of Mountain View California. Part of the sponsor ship fee will be going to raise money for the Autism Alliance of Michigan.

Episode 101 - Talking AI Threat Intelligence Insights from the IBM X-Force Report
Hashtag Realtalk with Aaron Bregg
03/01/24 • 47 min
In this episode I had a chance to have a candid conversation with Charles Henderson. Charles is a global managing partner at IBM and also happens to be the head of the X-Force team. IBM recently released the X-Force Threat Intelligence Index report for 2024.
While the report is delves into many different areas of Threat Intelligence, we concentrated on several key areas focused primarily on artificial intelligence:
- Pronounced increase in Identity attacks
- Understanding how more 'business-like' malicious actors are becoming
- Upcoming universal AI attack surface
- How much do you think this will get wors? For example, I reached out to a couple of CISOs from some prominent local companies and one of their worries was and I quote, "Longer term I think we will have to worry about attackers trying to attack and leverage AI technologies that are being utilized by organizations."
- 50% is the expected market share threshold likely to trigger attacks against AI platforms.
- Evolution of malware delivery mechanisms. AI's part in Business Email Compromise. Another area of concern when I polled my CISO contacts was AI's ability to, and I quote again, "Easier to perfect grammar and templates for phishing and other social engineering attempts.". How do you think companies like IBM can start helping people combat these types of attacks?)
- Thoughts on OpenAI's Sora and its potential impact on security
Episode Charity:
The Corewell Health's involvement in the Blue Envelope Suicide Prevention Program. The School Blue Envelope Suicide Prevention Program trains middle and high school faculty and staff so that every school employee—from teachers to coaches and bus drivers—would know how to respond to a student who may express thoughts of suicide. The “Blue Envelope” protocol for crisis management was developed internally to quickly activate patient safety responses by communicating the code words "Blue Envelope."
Every person within a physician’s office became proficient in how to respond at a moment’s notice to a patient who may have thoughts of suicide. Through previous grant and foundation dollars, this program has been able to successfully train over 8,500 middle, high, and elementary school personnel across 156 schools within 53 different school districts. This training has resulted in over 2,000 interventions for students in crisis.
Episode Sponsor:
This episode is sponsored by IBM, who recently celebrated their 100th birthday! IBM is a computer solution company based out of Armonk, New York.

Episode 75 - Where are My Logs at? Rethinking Loggin in 2023
Hashtag Realtalk with Aaron Bregg
12/21/22 • 49 min
In this the 3rd annual holiday fundraiser podcast episode, I talk with Kam Amir and Brenden Morgenthaler about what enterprise logging will look like in 2023. Kam is the Director of Technical Alliances for Cribl. Brenden is an Enterprise Architect for CDW.
Talking Points:
Kam has developed a formula for getting the most value from your setup using the three 'Vs':
- Variety
- Value
- Velocity
This allows for you to get more freedom to get valuable data into your platform.
Brenden talks to real life uses cases like:
- Grouping Meta Data for things like charge back,
- How do you setup threshold rules to help with crashing clusters
- Auditing Kerberos events issue
Podcast Sponsors:
This holiday event raised funds for 3 great causes:
Many thanks to Cribl, CDW and Custom Business Solutions for helping us raise over $1,000 for charity!
Show more best episodes

Show more best episodes
FAQ
How many episodes does Hashtag Realtalk with Aaron Bregg have?
Hashtag Realtalk with Aaron Bregg currently has 107 episodes available.
What topics does Hashtag Realtalk with Aaron Bregg cover?
The podcast is about Information Security, Podcasts, Technology, Science and Cybersecurity.
What is the most popular episode on Hashtag Realtalk with Aaron Bregg?
The episode title 'Episode 71 - Looking at Vulnerability Management' is the most popular.
What is the average episode length on Hashtag Realtalk with Aaron Bregg?
The average episode length on Hashtag Realtalk with Aaron Bregg is 45 minutes.
How often are episodes of Hashtag Realtalk with Aaron Bregg released?
Episodes of Hashtag Realtalk with Aaron Bregg are typically released every 14 days.
When was the first episode of Hashtag Realtalk with Aaron Bregg?
The first episode of Hashtag Realtalk with Aaron Bregg was released on Dec 30, 2019.
Show more FAQ

Show more FAQ