Episode
CCT 346: Testing Disaster Recovery Plans and Why BEC Still Works Despite MFA (CISSP Domain 7)
- Published
- May 4, 2026
- Duration seconds
- 1613
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/cissp-cyber-training-podcast-cissp-training-program-6068495/episodes/cct-346-testing-disaster-recovery-plans-and-why-bec-still-works-despite-mfa-cissp-domain-7/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-346-testing-disaster-recovery-plans-and-why-bec-still-works-despite-mfa-cissp-domain-7.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Send us Fan Mail MFA feels like the finish line until you watch a company wire tens of millions of dollars to an attacker without a single password being stolen. We dig into why business email compromise (BEC) still works even in “secure” environments, because the real target is the decision point: trust, timing, urgency, and authority. When attackers can spoof executives or use deepfake voice and video, the authentication layer often never gets challenged in a meaningful way. We break...