Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Chasing Entropy Episode 004: From Student to Leader – A Conversation with Matt Johansen

37:21
 
Share
 

Manage episode 483840586 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

In this episode of Chasing Entropy, host Dave Lewis welcomes longtime friend and cybersecurity thought leader Matt Johansen. What unfolds is a deeply insightful, often personal discussion that spans the evolution of an entire career—from a student in a literal church pew to a key voice shaping cybersecurity narratives today.

From Dorm Room to Industry Leader

Matt shares the serendipitous moment that ignited his cybersecurity career: a last-semester class taught by a university CISO, a DVD of James Arlen’s “Black Hat to Black Suit,” and the early encouragement to engage on Twitter and LinkedIn. That first year of digital networking proved foundational—every boss Matt's had, he met during that stretch.

Big Banks and Shadow IT

Matt contrasts his experience building security programs at a scrappy fintech startup with the tightly controlled environment at Goldman Sachs post-acquisition. He discusses how rigid controls can reduce risk but stifle innovation, and unpacks how shadow IT thrives even in the most controlled environments. The lesson? Security postures must match organizational realities.

Mental Health, Burnout & the Myth of the Security Superhero

One of the episode's most powerful threads is Matt’s advocacy for mental health awareness in cybersecurity. He critiques "superhero culture," where the same individuals are always relied on in crises. Instead, he calls for real structural changes—proper rotations, mandatory time off, and leadership accountability. As he puts it, you can’t yoga your way out of burnout.

Identity is the New Malware

Matt and Dave explore how the attack surface has shifted. With SaaS proliferation and stolen credentials replacing malware as the primary attack vector, identity management has become paramount. Highlighting attacks like the TeleMessage breach and the phishing incident involving Troy Hunt, they emphasize that security must make “clicking links” safe—not shame users for doing it.

Vulnerable U & Making Security Accessible

Matt now runs Vulnerable U—a cybersecurity media company delivering digestible infosec news via newsletters, YouTube, TikTok, and Instagram. He reflects on how his early work curating news for Liquid Matrix evolved into a full-time passion for communicating security in a human, relatable way.

Advice for Aspiring Professionals

Matt’s number one tip for newcomers? Create content. Even if you’re still learning, share your process. Blog your breakthroughs, record your thought process, and contribute to the dialogue. That transparency and authenticity open doors.

Mentioned in the Episode:

“Clicking links should be safe. What do we have to do to make clicking links safe?” — Matt Johansen

Be sure to subscribe, share, and join us as we continue to chase entropy across the loading construct.

  continue reading

4 episodes

Artwork
iconShare
 
Manage episode 483840586 series 3662462
Content provided by Dave Lewis, 1Password and Dave Lewis. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Lewis, 1Password and Dave Lewis or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

In this episode of Chasing Entropy, host Dave Lewis welcomes longtime friend and cybersecurity thought leader Matt Johansen. What unfolds is a deeply insightful, often personal discussion that spans the evolution of an entire career—from a student in a literal church pew to a key voice shaping cybersecurity narratives today.

From Dorm Room to Industry Leader

Matt shares the serendipitous moment that ignited his cybersecurity career: a last-semester class taught by a university CISO, a DVD of James Arlen’s “Black Hat to Black Suit,” and the early encouragement to engage on Twitter and LinkedIn. That first year of digital networking proved foundational—every boss Matt's had, he met during that stretch.

Big Banks and Shadow IT

Matt contrasts his experience building security programs at a scrappy fintech startup with the tightly controlled environment at Goldman Sachs post-acquisition. He discusses how rigid controls can reduce risk but stifle innovation, and unpacks how shadow IT thrives even in the most controlled environments. The lesson? Security postures must match organizational realities.

Mental Health, Burnout & the Myth of the Security Superhero

One of the episode's most powerful threads is Matt’s advocacy for mental health awareness in cybersecurity. He critiques "superhero culture," where the same individuals are always relied on in crises. Instead, he calls for real structural changes—proper rotations, mandatory time off, and leadership accountability. As he puts it, you can’t yoga your way out of burnout.

Identity is the New Malware

Matt and Dave explore how the attack surface has shifted. With SaaS proliferation and stolen credentials replacing malware as the primary attack vector, identity management has become paramount. Highlighting attacks like the TeleMessage breach and the phishing incident involving Troy Hunt, they emphasize that security must make “clicking links” safe—not shame users for doing it.

Vulnerable U & Making Security Accessible

Matt now runs Vulnerable U—a cybersecurity media company delivering digestible infosec news via newsletters, YouTube, TikTok, and Instagram. He reflects on how his early work curating news for Liquid Matrix evolved into a full-time passion for communicating security in a human, relatable way.

Advice for Aspiring Professionals

Matt’s number one tip for newcomers? Create content. Even if you’re still learning, share your process. Blog your breakthroughs, record your thought process, and contribute to the dialogue. That transparency and authenticity open doors.

Mentioned in the Episode:

“Clicking links should be safe. What do we have to do to make clicking links safe?” — Matt Johansen

Be sure to subscribe, share, and join us as we continue to chase entropy across the loading construct.

  continue reading

4 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play