• Certified: GCCC and the Practical Side of Critical Security Controls
    Jun 1 2026

    The GIAC Critical Controls Certification (GCCC) is a practical credential for professionals who want to understand how security controls become real defensive work. In this narrated version of my Monday “Certified” feature from Bare Metal Cyber Magazine, we walk through what the certification is, who it is built for, and why the CIS Critical Security Controls matter for security analysts, IT administrators, auditors, risk professionals, consultants, and early-career cybersecurity learners.
    This episode also explains what GCCC really tests, including control purpose, implementation thinking, audit awareness, and the ability to connect security tasks to measurable risk reduction. You will hear how the credential fits into a broader career path and how learners can prepare with a balanced mix of reading, review, practice, and flexible study support through the Bare Metal Cyber Academy.

    Show More Show Less
    16 mins
  • Insight: Making Sense of Static vs Dynamic App Security Testing
    Jun 1 2026

    Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) both promise better application security, but they look at your systems in very different ways. In this audio Insight, we walk through what SAST and DAST actually are, where they sit in your development and delivery stack, and how they turn real code and real traffic into security findings. You will hear a clear, vendor-neutral explanation of how each approach works, from early pipeline scans on source code to live probing of running applications in test or staging environments.

    The narration follows the Tuesday “Insights” feature from Bare Metal Cyber Magazine and focuses on practical use. We explore everyday use cases, quick wins for smaller teams, and more strategic patterns for organizations that want SAST and DAST to support continuous improvement instead of just compliance. You will also hear an honest look at benefits, trade-offs, and limits, plus common failure modes and healthy signals that show these tools are actually reducing risk rather than just adding noise.

    Show More Show Less
    14 mins
  • Insight: Watching What Leaves Your Environment Before It Becomes a Breach
    May 26 2026

    Network egress controls can be the difference between a noisy but contained incident and a quiet data leak that nobody spots until it is too late. In this audio Insight, we walk through what network egress controls are in practical, plain language and where they sit in your security architecture across on-premises and cloud environments. You will hear how they complement identity, endpoint, and application controls instead of trying to replace them, and why treating outbound access as a design decision, not a default setting, is so important for working security and IT teams.

    Show More Show Less
    14 mins
  • Certified: AAISM and the Rise of AI Security Management
    May 25 2026

    This narrated episode walks through ISACA Advanced in AI Security Management (AAISM) in plain English for professionals who want to understand where AI security leadership is heading. Based on my Monday “Certified” feature from Bare Metal Cyber Magazine, it explains what the credential is, who it is really for, and why it is aimed at experienced security managers rather than beginners looking for a first cybersecurity certification.
    The episode also breaks down what AAISM really tests, including AI governance, risk management, control oversight, vendor exposure, and incident readiness. It places the credential into a broader career path so listeners can see what usually comes before it, what kinds of roles it supports, and how the Bare Metal Cyber Academy fits as the broader home for related certification resources.

    Show More Show Less
    14 mins
  • Certified: Is GIAC GSTRT the Right Cyber Leadership Certification for You?
    May 24 2026

    In this episode of my Monday “Certified” feature from Bare Metal Cyber Magazine, we take a clear look at GIAC Strategic Planning, Policy, and Leadership (GSTRT) and what it really represents in a cybersecurity career. This is not a certification centered on tools, commands, or deep technical execution. Instead, it focuses on the leadership side of security work, including planning, policy, communication, program direction, and the ability to connect security priorities to business needs. If you have ever wondered how security professionals grow from doing the work to helping lead the work, this episode walks through that transition in plain English.
    We also explore who GSTRT is really for, what the exam tends to reward, and where it fits in a larger certification path. That includes a practical discussion of how leadership-focused exams differ from technical ones, why experience matters, and how candidates can prepare without overcomplicating the process. As with the rest of this certification’s learning path, the episode fits naturally into the broader Bare Metal Cyber Academy, where the audio course, Study Guide, and Flash Cards work together as flexible resources for busy professionals trying to build confidence and move forward with purpose.

    Show More Show Less
    16 mins
  • Certified: Is CompTIA SecurityX the Advanced Cybersecurity Cert Worth the Climb?
    May 24 2026

    In this episode, we walk through what CompTIA SecurityX (SecurityX) is, why it exists, and who it is really designed for. Rather than treating it like a beginner cert, this narration explains where it fits in the cybersecurity landscape and why it is aimed at people moving into more advanced technical roles. Based on my Monday “Certified” feature from Bare Metal Cyber Magazine, the episode breaks down the certification in plain English so listeners can understand the level, the audience, and the kind of professional growth it is meant to support. It is built for anyone who wants a clearer view of where a serious hands-on cybersecurity path can lead.
    The episode also explores what the exam really tests, including the mix of architecture, engineering, operations, and risk thinking that makes SecurityX different from more foundational certifications. You will hear how the exam fits into a bigger career path, what kinds of jobs it can support, and why it may be a strong future target even if it is not the right next step for everyone today. The Bare Metal Cyber Academy serves as the broader home for the connected resources around this certification, giving busy learners a more flexible way to prepare and build confidence over time.

    Show More Show Less
    13 mins
  • Certified: Is SSCP the Right Next Step for Early-Career Cyber Defenders?
    May 24 2026

    In this episode, we walk through the Systems Security Certified Practitioner (SSCP) in plain English and explain why it matters for early-career cybersecurity and IT professionals who are starting to take on real security responsibility. Based on the Monday “Certified” feature from Bare Metal Cyber Magazine, this narration looks at what SSCP is, who it is really designed for, and why it stands out as a practical certification for people working in systems administration, security operations, support, and related hands-on roles. It is built to help listeners understand where the certification fits before they decide whether it belongs in their own path.
    We also break down what the SSCP exam really tests, including the practical knowledge areas, operational thinking, and real-world judgment the certification is meant to validate. Along the way, the episode explains how SSCP fits into a broader career path, what kinds of jobs it can support, and where it may lead next for someone building toward larger security roles. As part of the broader Bare Metal Cyber Academy, this episode also connects naturally to the free audio course, Study Guide, and Flash Cards resources designed to help busy learners prepare in a flexible way.

    Show More Show Less
    14 mins
  • Certified: CompTIA PenTest+ Is Where Offensive Security Starts Feeling Real
    May 24 2026

    In this episode, we walk through CompTIA PenTest+ (PenTest+) in plain English and explain what it is really designed to validate. Instead of treating it like a flashy hacking badge, we break down how it fits into real cybersecurity work, especially for people moving toward penetration testing, vulnerability assessment, and hands-on security roles. You will hear who this certification is for, why it tends to fit best after some foundational technical experience, and how it can help early-career professionals build a more practical understanding of offensive security.
    This narration is based on the Monday “Certified” feature from Bare Metal Cyber Magazine, and it focuses on what the exam really tests, how to prepare without getting overwhelmed, and where PenTest+ fits in a broader certification path. We also connect the episode to the Bare Metal Cyber Academy as the broader home for the certification resources, including a free audio course developed by Bare Metal Cyber, a Study Guide, and Flash Cards. The goal is to give listeners a clear, beginner-friendly view of whether this certification makes sense for their next move.

    Show More Show Less
    10 mins