If you're a security student
A listening order for students: a short daily news habit, one story-driven show for motivation, one technical show, one career show, and an exam companion. Each step is free and none assumes a security job.
- 01
Daily news habit, 5 to 10 minutes
Three headlines a day in seven or eight minutes. After a month the names in your textbook start showing up in the news.
Cybersecurity Headlines
Rich Stroffolino · Sarah Lane · Steve Prentice
Three security stories in about seven minutes, every weekday, plus a Friday live discussion with CISOs.
Listen if you want the day's security news in under ten minutes.
mixeddaily<30m - 02
One story for motivation
Long-form stories about real hacks. This is the show that makes the subject feel worth the study hours.
Darknet Diaries
PickJack Rhysider
Narrative true-crime stories from the cybersecurity world.
Listen if you you like long-form narrative non-fiction, think This American Life for hacking.
narrativebiweekly30–60m - 03
One technical show
About 25 minutes a week with the researcher behind one real finding, usually from the vendor that published it. Short enough to replay when a term goes over your head.
Research Saturday
Dave Bittner
One fresh threat research report a week, explained by the researcher who wrote it, in about 25 minutes.
Listen if you work in a SOC or CTI role and want the week's notable malware and campaign research.
interviewweekly<30m - 04
One career show
A daily live news brief that stops on each story to say what an analyst should take from it, with a big career community around it. Episodes run 90 minutes, so listen while you work.
Daily Cyber Threat Brief
Gerald Auger
A live weekday news stream that explains why each story matters, with a career community attached.
Listen if you are a student or junior analyst who wants news explained, not just reported.
mixeddaily60m+ - 05
Exam companion
Short Security+ lessons for the commute, from a feed covering both SY0-701 and SY0-801. Use it next to your study guide, not instead of it.
Certified: The CompTIA Security+ Audio Course
Dr. Jason Edwards
A free, ad-free Security+ course in 12 to 20 minute audio lessons, now rebuilt for SY0-801.
Listen if you are studying for Security+ and want objective-by-objective audio review.
soloirregular<30m
Listening while you study for a certification
Podcasts do not follow an exam syllabus, so treat these as companions to your study guide, not substitutes. Each episode below is useful background for the domain it sits under. Domain names and weights are from the exam owner's page, checked 2026-09-30.
CompTIA Security+ (SY0-701)retires 2027-06-11
Domain 1: General Security Concepts (12%)
Domain 2: Threats, Vulnerabilities, and Mitigations (22%)
Domain 3: Security Architecture (18%)
- Prioritizing Cloud Security: How to Decide What to Protect First · Cloud Security Podcast · 41 min
- EP193 Inherited a Cloud? Now What? How Do I Secure It? · Cloud Security Podcast by Google · 31 min
- Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401 · Application Security Weekly · 60 min
Domain 4: Security Operations (28%)
Domain 5: Security Program Management and Oversight (20%)
Official outline: www.comptia.org
CompTIA Security+ (SY0-801)from 2026-11-17
Domain 1: General Security Concepts (16%)
Domain 2: Threats, Vulnerabilities, and Attacks (24%)
Domain 3: Security Architecture (19%)
- Prioritizing Cloud Security: How to Decide What to Protect First · Cloud Security Podcast · 41 min
- EP193 Inherited a Cloud? Now What? How Do I Secure It? · Cloud Security Podcast by Google · 31 min
- Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401 · Application Security Weekly · 60 min
Domain 4: Security Operations (27%)
Domain 5: Security Program Management and Oversight (14%)
Official outline: www.comptia.org
CompTIA CySA+ (CS0-004)
Domain 1: Security Operations (34%)
Domain 2: Vulnerability Management (26%)
Domain 3: Incident Response and Management (24%)
Domain 4: Reporting and Communication (16%)
Official outline: www.comptia.org
ISC2 CISSP (2024 outline)
Domain 1: Security and Risk Management (16%)
Domain 2: Asset Security (10%)
Domain 3: Security Architecture and Engineering (13%)
- CIA and AAA: The Core Security Models (1.1) · Certified: The CompTIA Security+ Audio Course · 13 min
- EP193 Inherited a Cloud? Now What? How Do I Secure It? · Cloud Security Podcast by Google · 31 min
- Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401 · Application Security Weekly · 60 min
Domain 4: Communication and Network Security (13%)
Domain 5: Identity and Access Management (IAM) (13%)
Domain 6: Security Assessment and Testing (12%)
- Iron Maiden and cloud security · Cloud Security Today · 46 min
- Pen Test Arrest: 5 Years Later · Dark Reading Confidential · 42 min
- 59: The Courthouse · Darknet Diaries · 86 min
Domain 7: Security Operations (13%)
Domain 8: Software Development Security (10%)
Official outline: www.isc2.org