Reimagining Cyber - real world perspectives on cybersecurity · Reimagining Cyber

Luck is not a Strategy- Ep 194

March 25, 2026·22 min
Tyler Moffitt opens the chat with a blunt premise. He and Kelvin Murray spend the conversation arguing that surviving a cyber attack is not a matter of luck, but of preparation and disciplined basics. RDP comes up immediately. Murray says exposed remote desktop is still a serious problem because one compromised login can open the door to servers, domain controllers, and the broader environment. The pair revisit the years when municipalities, schools, and health organizations were getting hammered by simple misconfigurations. It was often basic: default settings, broad exposure, and weak operational hygiene rather than exotic tradecraft. Even now, the same pattern keeps showing up in breach reporting. Murray points out that RDP is less dominant than it was in 2018, but it still appears often enough to remain a standing threat. The discussion turns to criminal economics. He describes how access to compromised machines can be sold cheaply on dark web forums, sometimes for little more than the price of coffee. That is the uncomfortable part. When footholds are that inexpensive, defenders are no longer dealing with a rare anomaly, but with a repeatable business model. The conversation then widens to the kinds of payloads delivered through that access. Ransomware and remote access trojans both come up, along with the broader idea that one successful intrusion can be enough. The hosts keep returning to the same operational point. If attackers only need to be right once, defenders need controls that hold every day. They also push on the human side of the problem. Organizations know the basics, but people still skip them, especially when they think the rules are for someone else. That includes C-suite staff and administrators. The episode then folds in a newer layer of risk. Moffitt and Murray talk about AI agents, bring-your-own-software habits, and employees installing tools on work laptops without fully thinking through the threat. The concern is not just the software itself. It is the assumption that convenience is harmless when it can quietly expand the attack surface. The conversation keeps translating technical details into business stakes. That makes the risks easier to understand for non-specialists. It also keeps the focus on what teams can actually change. Lock down exposure. Remove easy entry points. Treat basic access hygiene as a live control, not a box to check once. The closing note is firm. Luck is a bad security strategy. Preparation, consistency, and a refusal to skip fundamentals are what make the difference.

As heard by us

A blunt reminder that exposed basics, not bad luck, are what usually sink defenders.

This episode treats cyber defense as a matter of preparation, hardening, and follow-through, not luck. Tyler Moffitt and Kelvin Murray make a plain case for why exposed RDP still matters, how one breach can spread to servers and domain controllers, and why ransomware and remote…

Read the full review in PlayNext →

Why you'd press play

If RDP still worries you, this is your straightest reminder to lock it down.

Read the full recommendation in PlayNext →
Listen to the show on