Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português

Info icon Announcement: 2026 KuppingerCole PAM Leadership Compass: BeyondTrust recognized as an Overall Leader and top Product Leader among 36 evaluated vendors. Access the Report

  • Home
  • Resources
  • Podcast
  • Ep. 82 – Security Tools Are Failing: Lessons from the 2025 Microsoft Vulnerability Report current page
Link copied

Ep. 82 – Security Tools Are Failing: Lessons from the 2025 Microsoft Vulnerability Report

Your Host:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Guests:
Paula Januszkiewicz headshot
Paula Januszkiewicz
CEO and Founder of CQURE, Microsoft MVP and RD, Cybersecurity expert
Sami Laiho Bio Pic Bw 200X200
Sami Laiho
Windows OS & Security Expert, Senior Technical Fellow
Kip Boyle Use this one 300x300
Kip Boyle
CISO, Cyber Risk Opportunities LLC
Charles Henderson Headshot retouched 26
Charles Henderson
VP of Cyber Security Services, Coalfire
Podcast default

Listen on your favorite platform:

Spotify Apple Podcasts Youtube Pocket Casts Castro

About This Episode

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

BeyondTrust's 2025 Microsoft Vulnerability Report dropped—and it’s a wake-up call. With 1,360 new vulnerabilities and elevation of privilege attacks dominating the landscape, even insurance companies are backing away from covering privileged service accounts. In this special episode, cybersecurity veterans James Maude, Paula Januszkiewicz, Sami Laiho, Kip Boyle, and Charles Henderson dig into what the data from the 2025 report really means. Forget the fearmongering—this is about clear-headed, field-tested advice.

You’ll hear why flashy security tools often sit unused, how simple controls could prevent 60% of attacks, and why "secure by default" still hasn’t delivered. From AI-driven vulnerability discovery to cloud missteps that could sink your stack, this isn’t your usual “patch faster” sermon—it’s a blueprint for getting real results. If you’re overwhelmed by alerts, underwhelmed by your security stack, or just tired of doing more with less, this episode is your lifeline.

About Our Guests

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Paula Januszkiewicz headshot
Paula Januszkiewicz
CEO and Founder of CQURE, Microsoft MVP and RD, Cybersecurity expert

Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, which she established back in 2008. She is also an Enterprise Security MVP, honorable Microsoft Regional Director, and a world-class cybersecurity expert, consulting Customers worldwide. In 2017, Paula graduated from Harvard Business School. She delivers keynotes and sessions at the biggest world conferences such as RSA, Black Hat, Microsoft Ignite, SecTor Canada, Australian Cyber Conference, GISEC, GITEX, LEAP, and many others. She is often a top-rated speaker, including being chosen the No. 1 Speaker at Microsoft Ignite (among 1,100 speakers at a conference with 26,000 attendees) and at Black Hat Asia 2019. At the RSA Conference, two of her sessions were among the top 5 best rated. Paula is known for her unique stage presence that is always well-received among diverse audiences, often gathering thousands of people!


Paula has over 19 years of experience in the cybersecurity field, performing penetration tests, architecture consulting, trainings, and seminars. Every year, she takes over 200 flights to provide cybersecurity services for CQURE’s Customers. Paula and her Team also design security awareness programs for various organizations, including awareness sessions for top management. Together, they create various security tools (CQTools) supporting penetration tests, incident response, and forensics, which are shared with the community. Paula is a member of the Technical Advisory Board at the Royal Bank of Scotland/Natwest. And to top it all off, she has access to the source code of Windows!

Sami Laiho Bio Pic Bw 200X200
Sami Laiho
Windows OS & Security Expert, Senior Technical Fellow

Sami Laiho is one of the world’s leading professionals in the Windows OS and Security. Sami has been working with and teaching OS troubleshooting, management, and security since 1996. In 2019 Sami was chosen by TiVi-magazine as one of the top 100 influencers in IT in Finland. He is the 11th most followed person in his field in Finland.


At Ignite 2018, Sami’s “Behind the Scenes: How to build a conference winning session” and “Sami Laiho: 45 Life Hacks of Windows OS in 45 minutes” sessions were ranked as #1 and #2 out of 1708 sessions!! This was the first time in the history of the conference that anyone has been able to do this. Before that, at Ignite 2017, the world’s biggest Microsoft event, Sami was evaluated as the Best External Speaker! Also, Sami’s sessions were evaluated as the Best session in TechEd North America, Europe and Australia in 2014, and Nordic Infrastructure Conference in 2016, 2017 and 2019.

Kip Boyle Use this one 300x300
Kip Boyle
CISO, Cyber Risk Opportunities LLC

Kip Boyle is the Chief Information Security Officer (CISO) for several companies. He's the co-host of the "Cyber Risk Management Podcast" at https://cr-map.com/podcast. He helps senior decision-makers manage unlimited cyber risks through rigorous prioritization. He's served as a Captain with the F-22 program in the US Air Force. In the private sectors he was a CISO for an insurance company, credit card processor, bank, credit union, and IT Managed Service Provider. He lives in Seattle with his wife and six kids. 

Charles Henderson Headshot retouched 26
Charles Henderson
VP of Cyber Security Services, Coalfire

Charles Henderson, Coalfire’s Executive Vice President of Cyber Security Services, is a seasoned executive who specializes in leading teams that test, monitor, respond to, and secure organizations around the world. Throughout his career, Charles and the teams he has managed have specialized in threat intelligence, incident response, penetration testing, adversary simulation, vulnerability management, and vulnerability research. Formerly leading IBM X-Force and Trustwave SpiderLabs, his teams' clients range from governments, to the largest on the Fortune lists, to small and midsized companies interested in improving their security posture or in need of assistance handling a security incident.

Charles is also an enthusiastic member of the information security community and an advocate of vulnerability research. He serves on the BlackHat review board, has been a featured speaker at various conferences around the world on various subjects relating to security testing and incident response - including Black Hat, DEFCON, RSA, and SXSW. He has also appeared on or in CBS Evening News, NBC Nightly News, The Today Show, CNN, BBC, The Wall Street Journal, The New York Times, Forbes, USA Today, The Register, SC Magazine, Engadget, eWeek, Reuters, Car & Driver, and various other media outlets.

Share this episode
Open in Player
Spotify Apple Podcasts Youtube Pocket Casts Castro
Podcast Play Button An icon representing a play button for a podcast player.
Share this Podcast
  • Link
Signup for Podcast notifications
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Latest Episodes

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
1600279708 Robert Siciliano Headshot
Podcast default
Ep. 102 - Lions, Gazelles, and Pig Butchering // Robert Siciliano
Robert Siciliano
May 22, 2026
01:02:00
Jeffrey Wheatman
Podcast default
Ep. 101 – Cyber Security and the Art of Story Telling // Jeffrey Wheatman
Jeffrey Wheatman
May 08, 2026
00:57:41
James Maude Headshot 2024 Marc Maiffret1
100th episode square website
Ep. 100 - 100th Episode Celebration!!
James Maude | Marc Maiffret
Apr 17, 2026
01:08:58
Rob black headshot
Podcast default
Ep. 99 – Breaches, Births and Battling BS // Rob Black
Rob Black
Apr 03, 2026
00:51:55
Dahvid Schloss square
Podcast default
Ep. 98 – From Special Ops to Mob Boss // Dahvid Schloss
Dahvid Schloss
Mar 20, 2026
00:58:59

Related to Cybersecurity

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Field Chief Technology Officer
Podcast default
Ep. 87 - Code Crashes and Vinyl Scratches // Kevin Greene
James Maude
Sep 12, 2025
00:55:41
Field Chief Technology Officer
Podcast default
Ep. 77 - Bugs in the System: When Moths Hack Power Plants // Lesley Carhart
James Maude
Apr 25, 2025
00:52:16
100th episode square website
Ep. 100 - 100th Episode Celebration!!
Apr 17, 2026
01:08:58
Field Chief Technology Officer Chief Technology Officer
Podcast default
Ep. 66 - Hook, Line, and AI: The New Age of Phishing Attacks // Brooke Denney
James Maude | Marc Maiffret
Nov 22, 2024
00:48:03

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.
MS Vulns Report 2026 orange background 1

New: 2026 Microsoft Vulnerabilities Report

Access the report for expert analysis of Microsoft's vulnerability and security landscape, breaking down key trends, security shifts, emerging risks—and what it all means for you.

Get the Report

New: 2026 Microsoft Vulnerabilities Report: Access the report for expert analysis of Microsoft's vulnerability and security landscape, breaking down key trends, security shifts, emerging risks—and what it all means for you.

Get the Report