Daily Cyber with Brandon

Daily Cyber with Brandon

🎙 Brandon Krieger 👥 38K 📅 November 20, 2025 ⏱ 76 min 👁 68 📄 expert opinion 🧭 2026-08-18
Available in: English (current) Français

Keywords

cybersecurityvendor riskshared responsibilityshadow ITTPRM

Summary

In this episode of Daily Cyber, host Brandon Krieger interviews Joshua Scott, VP of Security at Hydrolix, about the evolution of cybersecurity over the past three decades. They discuss how the expansion of cloud services and SaaS platforms has increased the attack surface, leading to a rise in shadow IT and third-party risks. Scott emphasizes the importance of shared responsibility models, where cloud providers handle infrastructure security but customers must secure their own configurations and data. They delve into the challenges of vendor risk management (TPRM), including the need to assess fourth-party risks and the importance of balancing security with business needs. Scott advises that security professionals should support business objectives while maintaining defensible risk decisions, and that saying ’no’ to a vendor should be based on clear criteria and executive backing. The conversation highlights the need for pragmatic security approaches that avoid overly restrictive gates, which can drive users to shadow IT. Overall, the episode provides practical insights for CISOs, MSPs, and security leaders on managing vendor risk and aligning security with business goals.

175 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights from a seasoned security professional on practical aspects of vendor risk management and shared responsibility. The argumentation is based on real-world experience, with concrete examples such as discovering 2,000 cloud solutions at a previous company and the importance of understanding fourth-party risks. The discussion is coherent and well-structured, covering the evolution of security, the explosion of attack surfaces, and the need for pragmatic security decisions. The value lies in the actionable advice for security leaders, such as making vendor onboarding processes smoother and ensuring executive support for risk decisions. The argumentation is solid, though it relies on anecdotal evidence rather than empirical data, which limits its scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The video does not cite specific sources or studies, relying instead on the speaker’s professional experience. The quality of sources is therefore limited to the credibility of the guest, who has nearly three decades in the field. The title ‘Daily Cyber with Brandon’ is generic and does not reflect the specific topic, but the content aligns with the channel’s focus. The discussion is consistent with common industry knowledge, but the lack of formal references reduces its scientific rigor. No comments were provided for analysis.

212 words

Title / Content Match

The title 'Daily Cyber with Brandon' is generic and does not convey the specific topic of the episode, but the content aligns with the channel's focus on cybersecurity discussions.

Quality & Reliability

7/10

The video features an experienced cybersecurity professional (Joshua Scott) sharing practical insights on vendor risk management, shared responsibility, and security strategy. The discussion is grounded in real-world experience but lacks formal citations or references to specific studies or reports. The information is generally reliable and aligns with common industry knowledge, but the lack of verifiable sources and the conversational format limit its scientific rigor.

Key Moments

Cited Sources

  • DailyCyber.ca — Mentioned in the video description as a resource for more information and to become a guest.

Concurring Sources

  • NIST Cybersecurity Framework — Provides a framework for managing cybersecurity risks, aligning with the video's emphasis on risk-based decisions.

Contribution & Novelties

The video offers a practical perspective on vendor risk management and shared responsibility, emphasizing the need for a balanced approach that supports business goals. It highlights the often-overlooked issue of fourth-party risks and the importance of making security processes efficient to avoid shadow IT. The discussion provides actionable advice for security leaders, such as ensuring executive backing for risk decisions and creating a clear framework for vendor onboarding.

Pour aller plus loin :

  • Shared responsibility model — Explains the division of security responsibilities between cloud providers and customers.
  • Third-party risk management — Overview of the discipline and its importance in cybersecurity.
  • Shadow IT — Definition and implications of unauthorized technology use within organizations.

113 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the expert's experience. The technical level is moderate, suitable for a professional audience, and the overall reliability is good due to the guest's credibility, though the lack of formal sources prevents a higher score.

Reliability 7/10