# Security Debt: The Risk Nobody is Reporting Page: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/security-debt-the-risk-nobody-is-reporting Text version: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/security-debt-the-risk-nobody-is-reporting.md Podcast: [Cyberside Chats: Cybersecurity Insights from the Experts](https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591) Published: 2026-04-28T10:30:00+00:00 Episode link: https://www.chatcyberside.com/e/security-debt-the-risk-nobody-is-reporting/ Audio file: https://mcdn.podbean.com/mf/web/t7vprbgvncgcv4br/EP70_Security_Debt_Audio_Only_v3btr9d.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/security-debt-the-risk-nobody-is-reporting Duration seconds: 1749 ## Resource In this live episode of Cyberside Chats, we dig into security debt and why it continues to sit behind so many major incidents. This is the risk that builds quietly over time when controls are available but never turned on, systems aren’t fully decommissioned, or ownership is unclear. Using recent examples like Stryker, along with Change Healthcare and Colonial Pipeline, we walk through how attackers don’t always need sophisticated techniques. In many cases, they just take advantage of gaps that have been sitting there for years. We also introduce a simple framework to think about security debt across identity, lifecycle, architecture, governance, and operations, and why most real-world incidents cut across more than one of these areas. We close with a look at how things are changing. With AI accelerating exploit development, the window to fix these issues is getting smaller. What used to be a manageable delay is quickly becoming real exposure. Audience takeaways Require dual approval for destructive admin actions. Any system where one administrator can wipe, delete, or lock out at scale — Intune, Entra, identity providers, backup consoles, remote management tools — should require a second administrator to approve the action before it executes. Microsoft's Multi Admin Approval does this for Intune. Most identity and backup platforms have an equivalent. Turn it on. Stryker is the case study for what happens when you don't. (Addresses: Governance debt primarily; reduces Identity and Architecture debt blast radius.) Enforce phishing-resistant MFA on every administrator and every remote-access path. Not "available," not "recommended" — enforced, with no exceptions. Every admin account. Every VPN. Every Citrix or similar remote portal. Change Healthcare is the case study for… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/security-debt-the-risk-nobody-is-reporting/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/security-debt-the-risk-nobody-is-reporting.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.