Efani Features Podcast
Efani Features Podcast
Podcast Description
Cybersecurity. Privacy. Blockchain. Unfiltered.The Efani Features Podcast is your trusted guide to the evolving world of digital security. Hosted by Mark Kreitzman of Efani, each episode dives deep into the critical issues shaping our digital future - from SIM swap threats and mobile privacy to crypto security and blockchain innovation.Join leading experts, ethical hackers, founders, and privacy advocates as we unpack real-world threats, explore cutting-edge solutions, and share practical strategies to protect your data in an increasingly connected world.What you'll hear:Insider takes on the latest cybersecurity trendsThe truth about SIM swaps, spyware, and mobile hacksDeep dives into crypto and blockchain securityHow to take back control of your digital privacyWhether you're a crypto holder, startup founder, or just privacy-curious, this podcast delivers clear, actionable insights in every episode.Stay informed. Stay secure.Subscribe to Efani Features Podcast - where privacy isn't optional, it's essential.
Podcast Insights
Content Themes
This podcast covers a wide array of topics including cybersecurity trends, mobile privacy, and blockchain security. Episodes feature deep dives into critical issues like SIM swap threats, the vulnerabilities of mobile devices, and practical steps for enhancing personal data security. Noteworthy episodes may include discussions on ransomware prevention strategies and the importance of using de-Googled phones for enhanced privacy.

Cybersecurity. Privacy. Blockchain. Unfiltered.
The Efani Features Podcast is your trusted guide to the evolving world of digital security. Hosted by Mark Kreitzman of Efani, each episode dives deep into the critical issues shaping our digital future – from SIM swap threats and mobile privacy to crypto security and blockchain innovation.
Join leading experts, ethical hackers, founders, and privacy advocates as we unpack real-world threats, explore cutting-edge solutions, and share practical strategies to protect your data in an increasingly connected world.
What you’ll hear:
- Insider takes on the latest cybersecurity trends
- The truth about SIM swaps, spyware, and mobile hacks
- Deep dives into crypto and blockchain security
- How to take back control of your digital privacy
Whether you’re a crypto holder, startup founder, or just privacy-curious, this podcast delivers clear, actionable insights in every episode.
Stay informed. Stay secure.
Subscribe to Efani Features Podcast – where privacy isn’t optional, it’s essential.
What if the biggest flaw in cybersecurity is that we wait for something bad to be identified before we block it?
In Episode 32 of the Efani Features Podcast, host Mark Kreitzman sits down with David Redekop, Founder and CEO of ADAMnetworks, to explore a very different approach to network security: default denial, egress control, DNS as a root of trust, and preemptive defense.
David explains why traditional cybersecurity is often reactive. Security teams identify threats, detect suspicious activity, and then respond. But by the time that process finishes, the attacker may already have moved laterally, connected to external infrastructure, or begun exfiltrating data.
ADAMnetworks approaches the problem from the opposite direction:
Block everything by default, then only allow what is known, necessary, and trusted.
🔐 In This Episode:
Mark and David discuss:
- Why traditional detect-and-block cybersecurity can be too reactive
- The importance of controlling outbound network traffic
- Why egress is one of the most overlooked parts of enterprise security
- How attackers abuse legitimate internet infrastructure
- Why IP-based blocklists are becoming less effective
- How DNS can be used as a root of trust
- The concept of “default deny”
- Why known-good destinations can be safer than chasing known-bad infrastructure
- How zero-trust connectivity applies to outbound connections
- Why legacy, IoT, and OT environments create unique security problems
- How organizations can reduce the impact of compromised devices without replacing everything
- Why preemptive defense may become a much larger part of cybersecurity strategy
🚪 The Problem With an Internet Designed to Route Around Blocks
David explains that one of the internet’s greatest strengths is also one of its biggest security weaknesses.
The internet was designed to route around failures and maintain connectivity.
That resilience is what made the modern internet possible, but attackers can take advantage of the same flexibility.
Once malware or a compromised device is inside a network, the attacker often has significant freedom to communicate outward.
That outbound access is where ADAMnetworks focuses much of its attention.
Instead of only asking:
“How do we stop an attacker from getting in?”
David argues that organizations also need to ask:
“If something is already compromised, what is it actually allowed to talk to?”
🛡️ Default Deny: Flipping the Traditional Cybersecurity Model
A central idea in the episode is default denial.
Traditional cybersecurity often works by allowing normal activity and trying to identify what is malicious.
ADAMnetworks flips that model.
Rather than blocking only known-bad destinations, the system can restrict connections to destinations that have already been identified as legitimate and necessary.
David describes this as moving protection to the front of the process.
The philosophy is simple:
- Don't allow everything and hunt for threats afterward
- Allow what is known and required
- Deny everything else by default
The idea itself is not new, but applying it broadly to modern network egress is where David believes the industry is now beginning to shift.
🌐 Why DNS Matters
DNS plays a central role in ADAMnetworks' approach.
Instead of relying only on IP reputation, the platform looks at the domain name a device is attempting to reach and whether that destination is known, expected, and permitted.
David explains why IP-based defenses are becoming increasingly difficult.
Attackers can quickly spin up infrastructure in major cloud environments, use it briefly, and tear it down before traditional reputation systems have time to respond.
With IPv6 and rapidly changing cloud infrastructure, that challenge becomes even greater.
DNS provides another layer of context:
What destination did this device actually intend to reach, and should it be allowed to reach it?
🏭 Protecting Legacy & Industrial Systems
One of the strongest use cases discussed is environments containing legacy equipment.
Manufacturing facilities, industrial environments, and operational technology systems may still depend on devices running decades-old software.
Replacing that equipment is often not realistic.
David gives the example of an organization still operating Windows XP-based PLC controllers because replacing the underlying industrial systems would require a major capital investment.
Instead of assuming every legacy device can simply be upgraded, organizations need ways to constrain what those devices are allowed to do.
By limiting a vulnerable device to only the systems it genuinely needs, businesses can reduce the potential blast radius if that device is compromised.
💡 IoT Devices: Assume They Will Be Compromised
The same principle applies to IoT.
A thermostat, smart light bulb, camera, sensor, or industrial controller may never receive meaningful security updates after deployment.
Those devices can become attractive targets for attackers looking for lateral movement inside a network.
David's approach is not to assume those devices will remain perfectly secure forever.
Instead:
Assume compromise is possible, then limit what the device can communicate with.
A smart light bulb may need to talk to a local controller.
A thermostat may need to communicate with its management platform.
That does not mean either device should have unrestricted access to the entire internet.
🧱 “Don't Talk to Strangers”
David also discusses a core ADAMnetworks concept called “Don't Talk to Strangers.”
The idea is that a destination must first be resolved through an allowed DNS request before a connection to that destination is permitted.
That creates a relationship between DNS resolution and actual network connectivity.
If software attempts to bypass that trusted path or communicate with an unexpected destination, the connection can be blocked.
This is designed to make it significantly harder for malicious software to simply call out to attacker-controlled infrastructure.
🤖 AI & Preemptive Defense
The conversation also looks at where cybersecurity may be heading next.
David argues that artificial intelligence can be used not only to detect malicious behavior, but also to better understand what normal, necessary activity should look like.
Instead of asking AI to identify every possible threat, another approach is to understand the known-good environment:
- Which applications are actually required?
- Which domains do they legitimately need?
- Which devices should communicate with which services?
- What network behavior is truly necessary?
Everything outside that expected behavior can then be treated with greater skepticism.
This shifts cybersecurity from constantly chasing attackers toward reducing the opportunities they have in the first place.
🎯 Who Should Listen?
This episode is particularly relevant for:
- CISOs and security leaders
- Network security professionals
- IT teams
- Manufacturing organizations
- Industrial and OT environments
- Businesses with legacy infrastructure
- Organizations deploying IoT devices
- Companies protecting intellectual property
- Security teams exploring zero-trust architecture
- Anyone interested in preemptive cyber defense
The larger message is straightforward:
Attackers will eventually find a way in. The real question is what they are allowed to do once they get there.
🌐 Learn more about ADAMnetworks:https://adamnet.works
📱 Learn more about Efani:https://www.efani.com/
🎙 Hosted by Mark Kreitzman from Efani
#EfaniFeatures #ADAMnetworks #DavidRedekop #Cybersecurity #ZeroTrust #DNSecurity #NetworkSecurity #PreemptiveDefense #DefaultDeny #EgressControl #IoTSecurity #OTSecurity #CISO #EnterpriseSecurity #Efani

Disclaimer
This podcast’s information is provided for general reference and was obtained from publicly accessible sources. The Podcast Collaborative neither produces nor verifies the content, accuracy, or suitability of this podcast. Views and opinions belong solely to the podcast creators and guests.
For a complete disclaimer, please see our Full Disclaimer on the archive page. The Podcast Collaborative bears no responsibility for the podcast’s themes, language, or overall content. Listener discretion is advised. Read our Terms of Use and Privacy Policy for more details.