Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by LegitimateCybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by LegitimateCybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Leonardo da Vinci Had Better Wi-Fi: The $100M Louvre Heist #cybersecurity

37:45
 
Share
 

Manage episode 518791194 series 3673385
Content provided by LegitimateCybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by LegitimateCybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

What happens when the most secure museum on Earth has a Wi-Fi password that’s literally “louvre”?

💎 $100 million in jewels disappear, and the world’s best art collection learns what Defense in Dumb really means.

In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer unpack how the Louvre Museum was robbed in broad daylight — not just by thieves, but by bad passwords, unpatched servers, and leadership that never took cybersecurity seriously.

👉 Topics include:

The Windows Server 2003 still guarding priceless art

“Defense in Dumb” vs. real defense in depth

Why pen tests without remediation are a waste of money

How boredom and bureaucracy kill security programs

The Rosetta Stone irony: stolen artifacts complaining about theft

What NIST CSF, GRC, and governance diffusion all have to do with it

Why multi-factor authentication isn’t two French guards and a shrug

And yes — Leonardo da Vinci had better wireless security.

📩 Media & Interview Requests: [email protected]

🎧 Audio listeners: Subscribe on any platform →

https://legitimatecybersecurity.podbean.com/

👇 Comment below: What’s the dumbest password or security setup you’ve seen in the wild?

We might feature your story in a future episode.

Chapters

00:00 – Cold Open: “Imagine robbing the most secure museum on Earth…”

01:00 – Defense in Dumb: Louvre’s password was literally “louvre”

02:10 – British & French museums suddenly hate theft

03:45 – The Cyber Audit That Nobody Fixed

05:30 – Pen Testing vs. Actually Doing the Work

07:00 – Roof access, open windows, and Netflix-level stupidity

09:00 – Boring but critical: why remediation never happens

11:00 – Framework fails: ISO, NIST, GDPR, and no one enforces them

13:30 – Cyber careers, boredom, and the “borification” of information

16:00 – “It really HUMPS your packets”: why GRC isn’t sexy but matters

18:30 – Leadership without packets: Steve Jobs, Woz, and cyber blind spots

20:00 – How the Louvre failed every NIST CSF function

23:00 – MDR myths: detection ≠ protection

25:00 – APTs, insurance loopholes, and cyber blame games

29:00 – Governance diffusion: when everyone assumes someone else did it

31:00 – Legacy tech, no funding, and free open-source fixes

33:00 – PFSense, Security Onion & AI helping broke orgs

35:00 – Final Takeaway: “Leonardo da Vinci had better Wi-Fi security.”

#LegitimateCybersecurity #LouvreHeist #CyberFail

#DataBreach #cybersecurity

#Hackers

#PenTesting

#InfoSec

#NISTCSF

#GRC

#MDR

#APT

#CyberRisk

#MuseumHeist

#DefenseInDumb

#WindowsServer2003

  continue reading

25 episodes

Artwork
iconShare
 
Manage episode 518791194 series 3673385
Content provided by LegitimateCybersecurity. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by LegitimateCybersecurity or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

What happens when the most secure museum on Earth has a Wi-Fi password that’s literally “louvre”?

💎 $100 million in jewels disappear, and the world’s best art collection learns what Defense in Dumb really means.

In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer unpack how the Louvre Museum was robbed in broad daylight — not just by thieves, but by bad passwords, unpatched servers, and leadership that never took cybersecurity seriously.

👉 Topics include:

The Windows Server 2003 still guarding priceless art

“Defense in Dumb” vs. real defense in depth

Why pen tests without remediation are a waste of money

How boredom and bureaucracy kill security programs

The Rosetta Stone irony: stolen artifacts complaining about theft

What NIST CSF, GRC, and governance diffusion all have to do with it

Why multi-factor authentication isn’t two French guards and a shrug

And yes — Leonardo da Vinci had better wireless security.

📩 Media & Interview Requests: [email protected]

🎧 Audio listeners: Subscribe on any platform →

https://legitimatecybersecurity.podbean.com/

👇 Comment below: What’s the dumbest password or security setup you’ve seen in the wild?

We might feature your story in a future episode.

Chapters

00:00 – Cold Open: “Imagine robbing the most secure museum on Earth…”

01:00 – Defense in Dumb: Louvre’s password was literally “louvre”

02:10 – British & French museums suddenly hate theft

03:45 – The Cyber Audit That Nobody Fixed

05:30 – Pen Testing vs. Actually Doing the Work

07:00 – Roof access, open windows, and Netflix-level stupidity

09:00 – Boring but critical: why remediation never happens

11:00 – Framework fails: ISO, NIST, GDPR, and no one enforces them

13:30 – Cyber careers, boredom, and the “borification” of information

16:00 – “It really HUMPS your packets”: why GRC isn’t sexy but matters

18:30 – Leadership without packets: Steve Jobs, Woz, and cyber blind spots

20:00 – How the Louvre failed every NIST CSF function

23:00 – MDR myths: detection ≠ protection

25:00 – APTs, insurance loopholes, and cyber blame games

29:00 – Governance diffusion: when everyone assumes someone else did it

31:00 – Legacy tech, no funding, and free open-source fixes

33:00 – PFSense, Security Onion & AI helping broke orgs

35:00 – Final Takeaway: “Leonardo da Vinci had better Wi-Fi security.”

#LegitimateCybersecurity #LouvreHeist #CyberFail

#DataBreach #cybersecurity

#Hackers

#PenTesting

#InfoSec

#NISTCSF

#GRC

#MDR

#APT

#CyberRisk

#MuseumHeist

#DefenseInDumb

#WindowsServer2003

  continue reading

25 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play