Cybersecurity Podcasts for Students: A 12-Week Listening Plan
A week-by-week security podcast plan for university, bootcamp and self-taught students: one short daily news show, two or three named episodes a week, and a phase on identity, MFA and passkeys. Mapped to Security+, CySA+ and the CISSP.

The best security podcasts for students mix one short daily news show with a few chosen episodes each week, in an order that builds from stories to concepts to defensive work. This 12-week plan does that at 2 to 4 hours a week, with every episode named and linked, for university, bootcamp and self-taught students.
Verified as of 1 October 2026 against each show's own feed.
I founded LoginRadius in 2013 and scaled it to over a billion users. I also run Start with Identity, the non-profit identity community I founded for IAM and security professionals, and I curate the security podcast directory on this site. Every show below has a review page there.
Why a Plan Beats a "Best Podcasts" List
Most student lists name 20 shows and stop. A plan tells you which episode to play, in an order where each one makes the next easier, and caps the time so listening supports your course instead of replacing it.
Four phases of three weeks: how attacks happen, core concepts, identity, then defenders and careers. For the short version, read the listening path for security students, which this plan expands.
Phase 1, Weeks 1 to 3: How Attacks Happen
Start with stories. A narrated hack gives you the sequence of an attack before you know the vocabulary, so later definitions have a picture to hang on.
The daily habit for Weeks 1 to 6 is Cybersecurity Headlines: three stories in seven or eight minutes every weekday.
Week 1: Meet the attackers
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 2.5 hours.
- Darknet Diaries: 6: The Beirut Bank Job (29 min). A physical penetration test of a bank.
- Darknet Diaries: 54: NotPetya (57 min). How one attack on Ukraine spilled into companies worldwide.
- Malicious Life: The Morris Worm Pt. 1 (27 min). The 1988 incident that created incident response. A finished archive, run by Cybereason.
- Take away: Attacks are chains of small steps, and the damage often lands far from the original target.
Week 2: Ransomware and scams as businesses
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 3.2 hours.
- Click Here: Knights of Old and a ransomware joust (25 min). One Akira attack that ended a 150-year-old company. Run by Recorded Future, a threat intelligence vendor.
- Darknet Diaries: 126: REvil (64 min). How a ransomware-as-a-service operation was organised.
- Smashing Security: How to scam someone in seven days (61 min). A real romance-scam script walked through day by day.
- Take away: Online crime is organised like a company, with roles, suppliers and scripts.
Week 3: Scope, impact and the law
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 3.3 hours.
- Darknet Diaries: 59: The Courthouse (86 min). Two testers jailed during an authorised test.
- Darknet Diaries: 159: Vastaamo (51 min). A breach where the patients themselves were extorted.
- Click Here: How China’s Volt Typhoon hacked a small-town utility (23 min). Nation-state prepositioning told through one small utility.
- Take away: Written authorisation is not a formality, and a breach is measured by what happens to people, not by the number of records.
Phase 2, Weeks 4 to 6: Core Concepts
Now name what you heard. Each definition comes with a real case.
Week 4: The models every course starts with
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 2.2 hours.
- The CompTIA Security+ Audio Course: CIA and AAA: The Core Security Models (1.1) (13 min). The core models, in a free Security+ lesson.
- The Azure Security Podcast: Episode 125: Origins of MITRE ATT&CK (35 min). Blake Strom on how MITRE ATT&CK was built.
- Threat Vector by Palo Alto Networks: Inside 750 Breaches with Unit 42 (42 min). Where breaches start, from Palo Alto Networks' Unit 42 responders.
- Take away: Name which part of the CIA triad each Phase 1 attack broke, and which ATT&CK steps it used.
Week 5: Software and the supply chain
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 2.5 hours.
- Crying Out Cloud: CROC News - XZ Utils backdoor explained (13 min). The famous open source backdoor. From Wiz, now part of Google Cloud.
- Malicious Life: NotPetya Part 1 (33 min). Week 1's attack, retold as a poisoned software update.
- Absolute AppSec: Episode 303 - w/Prof. Brian Glas - OWASP Top 10 2025 (62 min). An OWASP Top 10 maintainer on how the 2025 list was built.
- Take away: Supply chain attacks abuse trust in code you did not write.
Week 6: Cloud and vulnerabilities
Daily: Cybersecurity Headlines, 8 minutes a weekday. Week total: about 2.3 hours.
- Cloud Security Podcast by Google: EP193 Inherited a Cloud? Now What? How Do I Secure It? (31 min). Securing a cloud someone else built. Google Cloud's show ended in August 2026.
- Cloud Security Podcast by Google: EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant (30 min). Five cloud mistakes Mandiant keeps finding.
- Open Source Security: Vulnerability disclosure with Casey Ellis (38 min). Why reporting bugs is hard.
- Take away: Cloud breaches usually start with misconfiguration and excess access, not exotic exploits.
Phase 3, Weeks 7 to 9: Identity, Where Attackers Get In
Identity is where I have spent my career, and it is where responders on these shows keep finding the way in: stolen passwords, phished MFA codes and hijacked sessions. Understanding it helps in SOC, cloud and IAM interviews alike.
From Week 7, switch the daily habit to SANS Stormcast: five to eight technical minutes from the SANS Internet Storm Center handlers. SANS also sells training.
Use the Start with Identity podcast directory (more than 20 identity podcasts) and the Start with Identity glossary. Look up each term when an episode first uses it: MFA, phishing-resistant MFA, passkey, SIM swap, account takeover and SSO.
Week 7: Why MFA is not the end of the story
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 2.5 hours.
- Hacking Humans: Identity theft gets a raise. (57 min). Account takeover tactics, for the people targeted.
- Malicious Life: You Should Be Afraid of SIM Swaps (33 min). Why a phone number is a weak identity anchor.
- The Defender's Advantage Podcast: How Threat Actors Bypass Multi-Factor Authentication (27 min). The bypasses Mandiant keeps finding. Run by Google's Mandiant team.
- Take away: Ask not "is MFA on?" but "can this factor be phished?"
Week 8: Passkeys and phishing resistance
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 2.7 hours.
- Click Here: Evilginx’s good intentions (13 min). The toolkit built to prove MFA was not foolproof.
- Blueprint: Build the Best in Cyber Defense: How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud (54 min). Why FIDO2 and passkeys stop credential phishing. From SANS.
- Identity at the Center: #373 - Going Passkey Phishing with Nishant Kaushik (58 min). FIDO Alliance's CTO answers objections to passkeys.
- Take away: A passkey is bound to the real website, so a lookalike page gets nothing. Then read the passkeys and FIDO learn guide.
Week 9: Account takeover, SSO and how IAM teams work
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 3.3 hours.
- Smashing Security: This clever scam nearly hijacked a tech CEO's Apple ID (55 min). MFA fatigue and a fake support call.
- Research Saturday: nOAuth-ing to see here. (24 min). Account takeover through an OAuth flaw. From N2K, and harder, so replay it.
- Identity at the Center: #450 - New to Identity with Alexis Bernthal (84 min). A newcomer's route into IAM.
- Take away: With SSO, one stolen session can open every connected app. Then read the OAuth and OIDC learn guide.
Identity at the Center is worth keeping after Week 9: two working IAM consultants on a weekly trade podcast for IAM practitioners, leaning toward enterprise workforce identity. Its Start with Identity profile lists more episodes.
Bookmark two more learn guides: privileged access management and non-human identity. The identity attacks episode list has 12 more picks, and the CIAM Compass glossary covers the customer identity side.
Phase 4, Weeks 10 to 12: How Defenders Work, and Careers
The last phase moves to the people who stop attacks, and how they got hired.
Week 10: Inside a SOC
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 3.0 hours.
- Security Unfiltered: Episode 50 - Thomas Kinsella - Life Of A SOC Analyst (64 min). The most common first security job.
- Blueprint: Build the Best in Cyber Defense: 11 Strategies of a World-Class Security Operations Center: Fundamentals (55 min). What a SOC is for. From SANS.
- Detection at Scale: SANS's John Hubbard on Future-Proofing SOC Analysts in the Age of AI (29 min). Analyst skills that still matter with AI. Run by Panther Labs, a SIEM vendor.
- Take away: A SOC is a triage system: most work is deciding what not to chase.
Week 11: Incident response
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 2.4 hours.
- The Defender's Advantage Podcast: The Art of Remediation in Incident Response (41 min). Evicting the attacker for good.
- Hacker Valley Studio: Leading Cybersecurity Incidents as Incident Commander and Responding to a Cyber Crisis (37 min). What an incident commander actually does.
- Dark Reading Confidential: Hoff’s Rules: People First (33 min). Leading a team through a major breach.
- Take away: Response is a people process as much as a technical one.
Week 12: Getting hired
Daily: SANS Stormcast, 7 minutes a weekday. Week total: about 2.6 hours.
- Simply Cyber's Daily Cyber Threat Brief: Want to Know What Matters to the CISO When Hiring Junior Cyber Staff? (45 min). Hiring criteria from a CISO. Simply Cyber also sells courses.
- Hacker Valley Studio: I Failed Over 300 Times Trying To Get Into Security ft. Joe South (40 min). A long road through rejection.
- CISO Tradecraft: #288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael) (39 min). Entering security through GRC.
- Take away: SOC, GRC, AppSec, cloud and IAM all hire juniors. Start with the area whose phase you enjoyed most.
Weekly totals run 2.2 to 3.3 hours at normal speed, less at faster playback.
Listening Alongside Security+, CySA+ and the CISSP
Podcasts are a companion to certification study, not a substitute. They give repetition and context.
Security+. SY0-701 is the current exam. SY0-801 launches on 17 November 2026, and SY0-701 retires on 11 June 2027 in English. The Security+ audio course is a free, ad-free course in short lessons by Dr. Jason Edwards. The feed holds both SY0-801 and older SY0-701 lessons, so check objective numbers. Start with SY0-801 at a Glance: What Changed from Security+ 701 (Intro) (13 min), and pair it with a question bank.
CySA+ (CS0-004). The directory has no dedicated course. Weeks 10 and 11 are the closest match; then follow the listening path for SOC work.
CISSP. The CISSP requires years of work experience, so most students are planning ahead. CISSP Cyber Training Podcast by Shon Gerber teaches one objective per episode. Two identity lessons fit Phase 3: CCT 280: Mastering Identity Lifecycle Management (Domain 5.5) (35 min) and CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6) (33 min). Know what it is: a free funnel for Gerber's paid courses, plugged in every episode.
The security student path has the full certification guide.
How to Listen So It Sticks
- Speed up the easy material. News and story shows hold up well at 1.5x to 1.6x. I listen at 1.6x myself. Drop back to normal speed for research episodes and certification lessons.
- Keep one line of notes per episode. Write the attack, the weakness it used and the control that would have stopped it.
- Replay anything you lost. A second pass after looking up two glossary terms is often when it clicks.
- Connect each episode to your course. Play the matching week after a lecture on the topic.
- Skip without guilt. If an episode is not working by the 15-minute mark, move on.
Where to Go After Week 12
- The 25 security podcast episodes every beginner should hear.
- The path for people switching into security, for career changers.
- The podcast topics index, with pages for SOC and blue team, AppSec, cloud security and GRC and privacy.
- The episode lists, including ransomware, supply chain attacks and incident response.
- The Start with Identity learn guides, for more identity study.
Frequently Asked Questions
What is the best security podcast for students?
For a daily habit, Cybersecurity Headlines is the easiest: three stories in about eight minutes. For motivation, Darknet Diaries tells real hacking stories. For exam study, the Security+ audio course gives free lessons labelled by objective.
How many hours a week should a student spend on security podcasts?
Two to four hours is enough, and this plan stays in that range. That works out to a short daily news show plus two or three chosen episodes. More usually means listening is replacing hands-on practice.
Can podcasts help me pass Security+?
They help with repetition, not with practice questions. The Security+ audio course covers the objectives in short lessons, but it has no questions in the audio. Use it beside a practice-test bank, and check whether each lesson targets SY0-701 or SY0-801.
Are cybersecurity podcasts good for complete beginners?
Yes, if you start with story shows. Darknet Diaries, Malicious Life and Click Here need no background. Technical shows make more sense after a few weeks.
Which podcast should I use to learn identity and access management?
There is no single right show. Identity at the Center (episode #450 is aimed at newcomers), The ID Talk Podcast and A Digital Identity Digest are all good places to begin, and the Start with Identity podcast directory profiles more than 20 identity shows.
More like this
All Scams & Cybersecurity- Scams & CybersecurityThe 12 Cybersecurity and B2B SaaS Podcasts I Listen to Weekly (and the 6 I Quit)Most best-podcasts lists are SEO-driven, not editorial. Here are the 12 cybersecurity and B2B SaaS podcasts I listen to weekly, plus the…
- Scams & CybersecurityThe Top Cybersecurity YouTube Channels to Learn From in 2026A categorised, founder-curated list of 44 cybersecurity YouTube channels organised by what you actually want to learn: offense, defence,…
- Why Podcast Discovery Is Broken in 2026 (And the Editorial Fix)Apple Podcasts and Spotify recommend the same 10 shows to everyone. The "best tech podcasts" lists are SEO chaff. Here is why discovery…
Get new Scams & Cybersecurity writing
Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.