Security Confidential S15 E7 Nick Espinosa

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Nick Espinosa. Nick Espinosa is a cybersecurity expert with over 25 years of experience in the field. He founded Windy City Networks, later acquired in 2013, and went on to create Security Fanatics in 2015, specializing in custom cyber defense strategies for medium to enterprise-level corporations. Nick is a board member, advisor, and contributor to several cybersecurity organizations and initiatives, including Roosevelt University, the COVID-19 Cyber Threat Coalition, and the Cyber Peace Institute. He’s also an award-winning co-author, TEDx speaker, and host of the nationally syndicated radio show “The Deep Dive.”

00:00 Intro

01:20 Our Guest

02:07 Growing up around technology

06:42 What can’t companies do right?

14:40 Nerd to English translation

21:07 The 5 laws of Cybersecurity

35:21 Innovating around Systems

49:24 More about Nick

Transcript

Manoj Tandon: Hello everyone, this is your host, Manoj Tandon. Welcome to Dark Rhiino Security’s Security Confidential. We have a fantastic guest today, but before I introduce him, please show us a little love—smash the like and subscribe buttons, leave a comment, and help us keep bringing you great conversations.

Nick Espinosa: Happy to be here and looking forward to the conversation.

Manoj Tandon: Let’s start with your origin story. How did you get here? Were you a computer scientist by training, or how did this all begin?

Nick Espinosa: Well, when I landed on this planet—no, seriously—it started when I was five. My dad bought me my first computer, and the next day, while he was at work, I took it apart—screw by screw. When he got home and realized what I’d done, he wasn’t happy at first, but I put it back together and it turned on. That’s when my dad realized I had a knack for this.

By age seven, I was building my own computers. By nine, I could program in 12 languages. At 12 or 13, I started earning certifications, and by 14, I was hacking my first systems. At 19, I founded Windy City Networks, and here we are. Technology isn’t just in my blood—it’s in my DNA. I love what I do.

Manoj Tandon: For parents with young kids who want to spark that same interest, was there a secret?

Nick Espinosa: Honestly, I was just fascinated by how things worked. Once I got that first computer running again, I wanted to understand everything—how it worked, how to make it talk to other systems, and eventually, how to break it. I spent all my free time either in school, playing soccer, or on a computer.

Parents today have so many more resources—coding camps, build-your-own computer kits like Kano, online classes. We’re raising a generation of digital creators, and that’s a great thing. Technology drives the global economy, so getting kids involved early is invaluable.

Manoj Tandon: What was your first computer?

Nick Espinosa: An IBM PC Junior, back in 1984. It had no hard drive, just a five-and-a-quarter floppy and cartridges, with a mighty 256K of memory. My first operating system was Microsoft BASIC 1.0, which I still have on cartridge somewhere at my mom’s house.

Manoj Tandon: Who—or what—was your first hack?

Nick Espinosa: For legal reasons, I can’t say, but let’s just say it was a government entity.

Manoj Tandon: Fair enough! Were you a fan of WarGames growing up?

Nick Espinosa: Absolutely. WarGames, Hackers, Sneakers—all of them. I’ve been a lifelong nerd and proud of it.

Manoj Tandon: You’ve created some cybersecurity laws I want to discuss later, but first—why can’t companies seem to get cybersecurity right?

Nick Espinosa: That’s a loaded question. One major issue is burnout. We’ve got a global talent shortage, CISOs without budgets, and people leaving the field because it’s relentless. Many decide it’s easier to run a doggy daycare than be a CISO.

The other side is the human element. Humans trust—too much. People fall for phishing every day, often executives. Awareness training helps, but trust and complacency are our biggest vulnerabilities.

Manoj Tandon: Is that trust or ignorance?

Nick Espinosa: Both. Trust often stems from ignorance or overconfidence. The Dunning-Kruger effect is real—people think they’re too smart to get hacked, which makes them easy targets. Older generations, in particular, grew up trusting authority and consistency. Today, misinformation and manipulation make it harder to know what’s real.

Manoj Tandon: So why don’t more companies build a true culture of cybersecurity instead of just training sessions?

Nick Espinosa: Exactly. Cybersecurity shouldn’t be a bolt-on; it should be built into the organization’s DNA—from the top down. The CEO and C-suite need to champion it. If leadership doesn’t walk the talk, employees won’t either.

And when policies are ignored or “shadow IT” creeps in, it erodes discipline. Change management and accountability are key. Everyone—from interns to executives—should be empowered to call out inefficiencies or security issues.

Manoj Tandon: That’s a great point. What about leadership blind spots? Many CFOs see cybersecurity as just a tech problem, and CISOs often struggle to communicate risk in business terms.

Nick Espinosa: That’s one of our biggest challenges. CISOs need to learn to speak “nerd to English.” Cybersecurity is about risk management, not just tools. When you show the CFO the potential financial loss versus the cost of prevention, things click.

I tell executives: IT is the engine of your economy, and cybersecurity is the shield protecting that engine. If CISOs can’t express value in those terms, they won’t get buy-in—or budget.

Manoj Tandon: Agreed. And the reporting structure doesn’t help when CISOs report to CIOs.

Nick Espinosa: Exactly. It’s a conflict of interest. The CISO should report directly to the board. When cybersecurity sits under IT, the fox is guarding the henhouse.

Manoj Tandon: And then there’s the “not my job” attitude among general staff.

Nick Espinosa: That’s a tough one. You can’t force people to care, but you can help them understand the consequences. I’ve seen employees in tears after realizing their mistake cost their company millions. No one wants to be the weak link. Accountability and empathy both matter.

Manoj Tandon: Let’s talk about your first law of cybersecurity.

Nick Espinosa: Law #1: If there’s a vulnerability, it will be exploited—no exceptions.

Every piece of software is released with known or unknown flaws. Developers ship under deadlines knowing they’ll patch later. The key is prioritizing risk. Fix the most critical vulnerabilities first—the ones that could cripple you. That requires risk assessment frameworks like NIST or ISO.

Manoj Tandon: Most companies don’t even know all their assets.

Nick Espinosa: Exactly. Asset management is step one. If you don’t know what you have, you can’t protect it. And manual lists in Excel don’t cut it. Automate it. It’s a living system, not a one-time exercise.

Manoj Tandon: You mentioned finding a toaster on a client’s network once.

Nick Espinosa: True story. It was an internet-connected toaster that could print images on bread. It was running Linux 0.1, totally insecure, and we used it to exfiltrate part of their database. The IT team had no idea it existed—a salesperson brought it back from China as a novelty. That’s how easy it is for IoT to create exposure.

Manoj Tandon: Which brings us to OT—what about all these connected devices in offices?

Nick Espinosa: Segmentation is critical. Keep internal, operational, and guest networks completely separate. Enforce strict BYOD policies or, better yet, don’t allow personal devices at all. The cost of issuing corporate hardware is nothing compared to the cost of a breach.

Manoj Tandon: What about process vulnerabilities—social engineering and human habits?

Nick Espinosa: That ties into Law #3: Humans trust even when they shouldn’t.

Attackers exploit trust. Deepfakes are the latest example—one company lost $30 million after a fake Zoom call with a cloned CFO. Another case at Ferrari involved a voice clone of the CEO. The best defense is verification—ask something only the real person would know.

Phishing simulations should never be “gotcha” moments—they should build teamwork. Anyone, from janitors to CEOs, can be phished.

Manoj Tandon: Some say that fostering distrust could harm company culture.

Nick Espinosa: It’s about healthy skepticism, not paranoia. A culture of verification protects everyone. Trust, but verify.

Manoj Tandon: What’s the second law?

Nick Espinosa: Law #2: Everything is vulnerable in some way. Even if we don’t see it yet. Nothing is bulletproof. Supply chains, cloud services, even pacemakers have been exploited. Every innovation introduces new attack surfaces.

Manoj Tandon: Which leads to law number four.

Nick Espinosa: Law #4: With innovation comes opportunity for exploitation. Every great invention—phones, operating systems, social media—creates both progress and risk. We must bake security into innovation from day one.

Manoj Tandon: And finally, law number five?

Nick Espinosa: Law #5: When in doubt, see law number one. Because at the end of the day, human trust is a vulnerability too. If there’s a flaw—technical or human—it will be exploited.

Manoj Tandon: Perfectly said. Before we wrap up, tell us what’s next for you.

Nick Espinosa: I’ll be speaking at Compliance Week in Boston this October alongside leaders like FTC Chair Lina Khan. I’m also working on my next book, though I owe my editor an email about that! You can catch my radio show The Deep Dive on NPR Pacific affiliates or find me online at @NickAESP on X and YouTube.

Manoj Tandon: That’s fantastic. We’ve only scratched the surface today, so we’ll have to have you back. Nick, thank you so much for your insights.

Nick Espinosa: My pleasure—thanks for having me.

Manoj Tandon: And thank you to our listeners for tuning in to Security Confidential. Stay curious, stay safe, and remember—trust, but verify.

Nick’s Linkedin

Kiteworks enables organizations to effectively manage risk in every send, share, receive, and save of sensitive content. To this end, they have created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content moving within, into, and out of their organization, significantly improving risk management while ensuring regulatory compliance on all sensitive content communications.

Check out the other episodes in Season 15:

Ep.0 Robert Kerbeck – Fame, Fortune, and Corporate Espionage

Ep. 1 Stephen Kowski – Inside the mind of a Field CTO

Ep. 2 Vivek Ramachandran – Inside Email Security: Breaking Through Gmail and Outlook’s Defenses

Ep. 3 Dr. Eric Daimler – AI’s Future: More Than Just Machine Learning

Ep. 4 Purandar Das – Data is the New Oil

Ep. 5 Aaron Painter – Understanding Deepfakes

Ep. 6 Jake Moshenko – Navigating Open Source and Distributed Systems

Ep. 7 Nick Espinosa – Why CISOs Must Master Nerd to English Translation

Ep. 8 Dan Lohrmann – AI, Fraud, and the Future of Cybersecurity

Ep. 9 Greg Schaffer – How the Role of a vCISO is changing

Ep. 10 Sanjay Chopra – AI Innovations and the Future of Automation

Nick Espinosa is a cybersecurity expert with over 25 years of experience in the field.

He founded Windy City Networks, later acquired in 2013, and went on to create Security Fanatics in 2015, specializing in custom cyber defense strategies for medium to enterprise-level corporations.

Nick is a board member, advisor, and contributor to several cybersecurity organizations and initiatives, including Roosevelt University, the COVID-19 Cyber Threat Coalition, and the Cyber Peace Institute.

He’s also an award-winning co-author, TEDx speaker, and host of the nationally syndicated radio show “The Deep Dive.”

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top