Download on the App Store

episodes

  • Spotlight Podcast: RSA President Rohit Ghai warns Digital Transformation is magnifying Enterprise Risk

    In this interview, recorded at the RSA* Charge conference, RSA President Rohit Ghai talks about some of the ways that digital organizations have to adapt to- and address risks introduced by new transformative technologies like machine learning, multi cloud environments and robotics and other “digital transformation” initiatives.











    As a species, humans aren’t good at tackling big, amorphous problems with long time horizons. Take climate change: scientists recognized the growing threat of a warming climate due to human activity more than 40 years ago. Since then, however, countries have been woefully slow to address the threat and have mostly ignored the warnings of the scientific community about the adverse consequences to human society around the world. 



    Rohit Ghai is the President of RSA Security says mega trends like “digital transformation” threaten to accelerate risk in organizations.



    For 21st century businesses, climate change is just one so-called “mega trend” that they must contend with. The other, our guest this week notes, is a phenomenon commonly referred to as ‘digital transformation.’ As we’ve noted before, ‘digital transformation’ is a broad term that encompasses changes brought on by innovations such as machine learning and artificial intelligence, cloud based computing and micro services, DEVOPS methodologies for delivering new applications and features and the use of automation and robotics. 



    [Read: RSA warns Digital Transformation is supercharging Digital Risk]



    While the benefits of digital transformation are easy to grasp, the risks that it introduces are less talked about – even though overlooking the risks brought on by digital transformation can spell disaster. 



    To understand what some of those risks are and how companies can navigate their way through digital transformation, Security Ledger traveled to Orlando recently for RSA Charge, a customer event hosted by RSA Security. There, we caught up with Rohit Ghai, the President of RSA Security on the sidelines of the show. 



    We live in a time where trust is tenuous. While technology is a force for good, there are some things that people are concerned about. In terms of cyber risk in terms of things like the impact of technology on people’s jobs and the societal impact of technology. Our role must be to bolster trust and make sure technology moves forward and drives digital transformation.Rohit Ghai, President of RSA Security



    In this podcast, we’re bringing you the conversation Rohit and I had. We talk about what digital transformation means for RSA’s customers and how digital transformation is accelerating risk and the best way to prepare for the challenges that digital transformation introduce. 



    Check out our full conversation above.







    (*) Disclosure: This podcast and blog post were sponsored by RSA Security for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out our About Security Ledger page on sponsorships and sponsor relations.
    20 min
  • Episode 165: Oh, Canada! Independent Security Researchers Feel the Chill Up North

    In this episode of the podcast (#165), we talk with 19 year-old Noah Clements of University of New Brunswick about the blowback he received after reporting a serious hole in a smart doorbell. Also, staff attorney Tamir Israel from the Canadian Internet Policy and Public Interest Clinic (CIPPIC) joins us to talk about the still evolving legal picture for independent security researchers in Canada.







    As Canada’s young, charismatic Prime Minister Justin Trudeau charged over the finish line to victory in national elections last week, the U.S.’s neighbor to the North seemed on track to retain its reputation as a redoubt of polite and progressive politics in North America. 



    But for independent security researchers, Canada’s reputation as a welcoming and friendly country may ring hollow. In fact, an absence of clear legal precedents risks making Canada a pretty cold and unwelcoming place for independent security researchers, just as their skills are needed the most. 



    In this week’s episode of the podcast we are looking at the issue two ways.



    Ringing the Doh! Bell



    If you want to understand how chilly it can be in Canada for independent security researchers, consider the experience of Noah Clement might be a good person to talk to. The 19 year old undergraduate at the University of New Brunswick took the opportunity to dig into the workings of a smart doorbell his parents had purchased for their home.



    Noah Clements is a student at The University of New Brunswick



    Noah’s discoveries led to the disclosure of serious vulnerability. Among other things, the device, the DB01-S Gen 1 from the Canadian firm dbell allows remote attackers to launch commands with no authentication verification via TCP port 81. That could allow attackers to send arbitrary commands to any doorbell it could connect to remotely or from the same wireless network. And, because the dbell also sports integrations with smart door locks, the flaw could potentially allow an attacker to open the door to the house from the Internet. (Noah posted a video of the “unlock door” attack here.)



    Much of what Noah discovered is sadly common in connected or “smart” home devices. The doorbell, which was supposed to be controlled via a mobile app, sported an embedded web server that could be accessed via TCP Port 81 without needing any authentication at all.



    But Clements experience after reporting the hole is one that is becoming less common for researchers in the U.S. and elsewhere.



    Clements discovered a serious security hole in the dbell DB01-S Gen 1 – which has since been discontinued.



    Dbell initially welcomed Noah’s vulnerability report and even offered him a new dbell model at a reduced price in exchange for his help testing it. But the firm quickly became hostile when Noah expressed his desire to go public with his findings. That led to a months-long odyssey between Noah, dbell and dbell’s attorneys, which included everything from gratitude to charges of extortion and threats of legal action.  



    “If you were really genuine and honest to helping others and you had no malicious intention for extortion, you would have accepted the offer for our current product.”email sent to Clements from dBell support team



    For its part,
    31 min
  • Spotlight Podcast: Global Audit Finds Small Firms struggle with Password Hygiene

    In this Spotlight edition of our podcast sponsored by LastPass* we’re joined by LogMeIn Chief Information Security Officer Gerald Beuchelt to talk about LastPass’s third annual Global Password Security Report, which finds password hygiene improving at large companies, but lagging at smaller firms.







    To paraphrase the author F. Scott Fitzgerald: “large companies aren’t like everyone else: they use fewer passwords.”







    That’s one of the unmistakable conclusions from a survey conducted by the firm LastPass (part of LogMeIn) in its latest Global Password Security Report. Among other conclusions, the LastPass analysis showed that employees at small firms typically managed 85 passwords on average – more than three times the number of passwords as workers at larger companies. They also did a worse job managing those extra passwords, with bad hygiene like password reuse far more common. 



    How did we get to this state of password “have and have nots” (or “know and know nots?”) To understand the dynamic a bit better, we invited Gerald Beuchelt, the Chief Information Security Officer at LogMeIn into the Security Ledger studios.  



    Gerald Beuchelt is the CISO at LogMeIn



    Beuchelt is responsible for managing and maintaining the security program across LogMeIn. In this conversation, he and I talk about the continuing challenges of managing passwords and some of the conclusions of the company’s latest Password Security Report. 



    As a provider of password management technology for some 47,000 organizations, the company has a unique perspective on password use.



    Beuchelt is careful to note that LastPass uses “zero knowledge” technology which means it can’t actually “see” its customers passwords. However, it is able to statistically analyze them to assess their security as well as the presence of other security features like multi-factor technology. 



    Companies with the fewest employees had the worst password hygiene, LastPass found. (Image courtesy of LastPass.)



    Beuchelt tells me that password security is a “mixed bag”: with a noticeable uptick in the use of multi factor technology across the board. However, even without knowing the password’s value, it can analyze its complexity (not to mention password re-use) and note the use of other technologies like multi factor authentication and single sign-on. Beuchelt and I talk about how better password hygiene is not being observed universally. Larger firms are getting the message, while smaller firms with 25 or fewer employees lag behind. 



    Its an interesting conversation that you can check out in its entirety!
    26 min
  • Episode 164: Who owns the Data Smart Cars collect? Also: making Passwords work.

    In this episode of Security Ledger Podcast (#164): your car is spying on you. But who owns the data it collects? Also: LastPass’s Dan DeMichele joins us to talk about why password security is still so hard.







    Who owns your Car Data?



    Whether you know it or not, your car is watching you. The same technology that makes it possible for you to load up Spotify or Waze on your drive into work is helping auto manufactures monitor everything about your car: from the performance of your engine to how and where you drive and even whether you’ve gained weight. 



    You create that data – refereed to as “telematics” – using your own vehicle. But is that data yours or the car maker’s? The answer – for now- is buried in the small print of a licensing agreement you probably signed when you purchased the vehicle. In that way, automobiles are starting to look a lot like smart phones, or smart home appliances. 



    The question of who owns the telematic data your car generates isn’t just a brainy legal question. Access to vehicle data is critical to performing maintenance on the car and fixing problems when they arise. But automakers are loath to share the data with owners – let alone independent auto shops that compete with their own dealerships and licensed repair facilities. That has created a battle over telematic data that parallels the fight to create a digital right to repair.



    Aaron Lowe is a Senior Vice President for Government Affairs at The Auto Care Association. 



    To understand the issue a bit better and get caught up on where things stand, we invited Aaron Lowe, the Senior Vice President for Government Affairs at the Auto Care Association into our studio. ACA has launched a new program called Your Car Your Data Your Choice.



    In this conversation, Aaron and I talk about the competitive as well as privacy and security implications of the automakers harvesting and even reselling reams of telematic data from their customers. We also talk about the national public awareness campaign that Auto Care Association has launched: Your Car, Your Data, Your Choice which is trying to raise awareness about the privacy and data ownership issues surrounding smart cars.



    Why Companies struggle with Passwords



    In our second segment: the latest State of the Password Report by LastPass has some good news: use of two factor authentication is increasing rapidly.: up more than 10% over last year. 



    But not all the news is good: less than 50% of businesses are employing a single sign on solution, LastPass found. And employees at businesses large and small still struggle to stay on top of their passwords and keep their accounts secure.



    Dan DeMichele is the Vice President of product for the IAM BU at  LogMeIn



    Also: a severe password gap exists as well: at small businesses, employees may have up to 85 separate passwords per employee. But at larger firms that number could be a third the size: just 25 passwords per employee. 



    To understand why and how companies struggle with pas...
    37 min
  • Episode 163: Cyber Risk has a Dunning-Kruger Problem also: Bad Password Habits start at Home

    In this episode of Security Ledger Podcast (#163) sponsored by LastPass: Kevin Richards of the insurer Marsh joins us to talk about that company’s Cyber Risk Perceptions Survey. Also Yaser Masoudnia of LastPass* joins us to talk about the blurry line between personal and professional is complicating enterprise security.







    We all know about the Dunning-Kruger Effect: that sneaky cognitive bias that convinces people of low ability that they’re actually the bomb, simply because their ignorance prevents them from apprehending how much they don’t know. No doubt you’ve worked with someone imprisoned by Dunning-Kruger. And, indeed, in a culture that rewards swagger and big talk, its easy to see this particular bias at work all around us.



    A Dunning-Kruger Effect with IT Risk?



    Dunning-Kruger is interesting. We tend to focus on one aspect of it, namely: that low ability people consistently overestimate their aptitude. But the research by Dunning and Kruger revealed a consistent pattern: as individuals become more competent, their confidence in their own abilities falls, creating a kind of competency trough. Confidence recovers as actual mastery of the topic at hand increases, creating a distinctive “U” shaped graph. As they achieve true mastery, individuals confidence in their ability recovers, though typically not to the same high level they exhibited when they had absolutely no idea what they were talking about.



    Kevin Richards is the Global Lead for Cyber Risk Consulting at Marsh



    But can Dunning-Kruger cloud organizational thinking in the same way that it clouds individuals’ perceptions? On this topic, a recent survey by the insurer Marsh and Microsoft caught our eye. The 2nd annual Cyber Risk Perception Survey asked 1,500 executives and IT professionals at companies of all sizes across the globe about the state of cyber risk perceptions and risk management.



    One interesting finding of the survey: industry analysts, corporate leaders and IT pros said their organization were never more concerned about cyber risk and were spending more than ever before to address that risk. Despite that, their confidence in their cyber risk preparedness fell by 6%: with just 23% “highly confident” in their readiness to defend against cyber attacks. That means corporate leaders were less optimistic than in years past – when they were admittedly less concerned about- and spending less money on cyber defense.



    “We’ve never spent more. Its my top concern. And the confidence in our ability to defend actually went down.” Kevin Richards, Global Lead for Cyber Risk Consulting at Marsh



    Why? To understand what may be bubbling in the minds of corporate executives and risk professionals, we sat down with Kevin Richards, the global lead for cyber risk consulting at Marsh, which is the world’s largest insurance and cyber risk insurance brokerage. 



    Kevin noted that a steady stream of news about mega breeches weighs on the minds of corporate executives. Beyond that, cyber security might simply be harder than companies and their leaders anticipated. Increased attention to- and spending on cyber risk efforts helps address th...
    37 min
  • Spotlight Podcast: Breaking Bad Password Habits to Fight Advanced Threats

    In this Spotlight edition of the Security Ledger podcast, Rachael Stockton of LastPass * joins us to discuss the myriad of challenges facing companies trying to secure users’ online activities, and simple solutions for busting insecure user behaviors to address threats like phishing, account takeover and more.







    Twenty years ago, if you ran a business, user authentication was a pretty straight forward prospect: tools like Active Directory (or a predecessor) stored user identities that were used to access local endpoints (desktop or laptop computers) and gain access to shared network resources: application servers, file servers, email and so on.







    This was all pretty straight forward. From your perspective: your team owned the network and the IT assets that those applications ran on. A perimeter protected your business from the Internet and your workers worked – for the most part – at the office. 



    The world has changed tremendously since then, as has authentication. A firms standing up an IT operation in 2019 will likely own few IT assets aside from the systems its employees use. Most every application employees use to do their job will be delivered as a service and – likely – run off of cloud services operated by a third party provider.



    Rachael Stockton is the director of product strategy at LastPass. 



    Employees also will work from everywhere. Home, remote offices, coffee shops and cars- and do so using laptops, mobile devices and more. Personal and professional activities intermingle seamlessly -often just a browser tab away from each other.  Hackers and other malicious actors have taken notice: leveraging stolen credentials from consumer sites to compromise corporate networks and setting up “watering hole” attacks to harvest  sensitive logon information from employees.



    All that makes once straight forward questions about authentication much, much more difficult, while human behavior remains just as hard to change. Rachael Stockton of LastPass notes that authentication technology has to adapt to the new ways that people work and the threats that companies face. “Every employee is a potential entry point (for hackers),” Stockton told me.



    I think there’s a difference between the password going away – so not having a password – and us not caring that we have a password anymore. – Rachael Stockton, LastPass



    What is the best way for companies to address authentication and identity challenges? Stronger authentication is a good first step. Added layers of security such as two factor authentication can radically reduce or even eliminate whole categories of online attacks.



    Still, users are reluctant to change (or break) bad habits, even when they know they’re insecure. In this spotlight podcast, we invited Rachael back into the Security ledger studio to talk about why insecure practices persist in enterprises and how best to break users of their bad habits.



    Rachael and I also talk about practical steps that organizations can take to improve your employees online security including better user education, incentives and gamification to more streamlined authentication and single sign on tools.  







    (*) Disclosure: This podcast was sponsored by 
    26 min
  • Episode 162: Have We missed Electric Grid Cyber Attacks for Years? Also: Breaking Bad Security Habits

    In this episode of the podcast #162: according to the non profit that oversees it, the first disruptive hack of the U.S. grid happened in March of this year. Our guest, Joe Weiss, said it really happened more than a decade ago and that hundreds more like it have been overlooked or mis-classified. Also: Rachael Stockton of the firm LastPass* joins us to talk about changing users troublesome password behavior to make companies more secure.







    If you believe the headlines, the first known disruptive cyber attack against  the U.S. grid happened on March 5, 2019 when an unidentified actor attacked firewalls at an undisclosed utility that was part of the power grid in California, Utah and Wyoming. The incident cause “brief” outages of internet-facing firewalls that controlled communications between the control center and multiple remote generation sites and between equipment on these sites, according to a report (PDF) released by NERC, the North American Electric Reliability Corporation.







    That incident made news in April after the utility reported it to the U.S. Department of Energy and was called “unprecedented.” “A cyberattack is not known to have ever disrupted the flow of electricity anywhere in the United States,” E&E News, an electricity industry publication noted.



    But what if the first successful attack on the grid didn’t happen in March 2019, but 15 years ago, in 2004? And what if hundreds of similar cyber incidents -both malicious and inadvertent – had occurred since the turn of the Millennium, but were never labeled as such?



    Joe Weiss, Applied Control Solutions



    Our next guest, Joe Weiss of  of Applied Control Solutions has been making the case that cyber attacks on North America’s expansive grid are neither new nor are they rare. According to Weiss, there have been hundreds of cyber incidents (he counts more than 300) going back decades.



    So how come we haven’t heard about them? Weiss argues that much of the problem is due to how cyber incidents are classified by the NERC, which oversees users, owners, and operators of the North American bulk power system, which serves more than 334 million people. Despite ample evidence of malicious and inadvertent “cyber” incidents that cause power disruptions, NERC and FERC, the federal regulators that oversee it, have a “see no evil” mentality.



    Weiss worries that the unwillingness to confront cyber risk is allowing grid operators to ignore mounting evidence that our electric grid is highly vulnerable to cyber attack and manipulation. In our first segment, we welcome Joe back to our podcast to talk about how and why cyber incidents affecting grid operation and reliability are being overlooked. 



    Patching Flaws at Layer 8



    Security pros like to joke about compromises at “Layer 8” – a reference to the seven layer OSI model. Its a nerdy and amusing way to talk about the “users” -the homo sapiens who are increasingly the targets of malicious actors.



    But what is the role of users in ensuring the security of modern organizations? And can even the best trained users be counted on to not become victims?



    Rachael Stockton is the director of product strategy...
    33 min
  • Spotlight Podcast: Security Automation is (and isn’t) the Future of Infosec

    In this Spotlight Podcast, we speak with David Brumley, the Chief Executive Officer at the security firm ForAllSecure* and a professor of Computer Science at Carnegie Mellon University. Brumley is a noted expert on the use of machine learning and automation to cyber security problems. In this podcast, we talk about the growing demand for security automation tools and how the chronic cyber security talent shortage in North America and elsewhere is driving investment in automation. You can also check out a transcript of our conversation below.







    Every so often, a technology comes along that seems to perfectly capture the zeitgeist: representing all that is both promising and troubling about the future.



    In the 1960s, you think of plastic, which was a pillar of a massively expanding consumer culture in the United States that put “convenience” above all else. That’s the joke behind the now-famous “advice” given to Dustin Hoffman’s Benjamin Braddock in the 1967 movie “The Graduate” by the older Mr. McGuire: “I’ve got just one word for you Benjamin…’plastics.'”



    McGuire was on to something: the use of plastic did indeed mushroom in the decades that followed. Advances in the use of polymers revolutionized everything from food packaging to electronics, telecommunication and medicine. That’s undoubtedly been a benefit to billions of people on the planet. It has also made some smaller number of those people fantastically rich. But there is a downside to plastics and the throw-away culture they engendered, as we now know. Plastic trash now clogs our rivers and streams and micro plastics seep into our water and food and, borne on the winds, make their way to the earth’s most remote places.



    That same L.A. pool party in 2019 might have young Benjamin being advised to look into “AI” – artificial intelligence. Like plastics in the 1960s, AI and machine learning are already big and getting bigger. Machine learning algorithms are already being used in transportation to ease road congestion, in healthcare to spot medical errors and improve patient care and in retail to improve the customer shopping experience. The technology is poised to change just about everything else …at least eventually. By 2030 AI could deliver additional global economic output of $13 trillion per year to the global economy according to McKinsey Global Institute research. 



    One industry where there is plenty of speculation about the potential applications and benefits of machine learning and artificial intelligence is information security, where high demand and an acute shortage of talent have executives, entrepreneurs and industry analysts argue that the adoption of machine learning and AI is unavoidable, especially if companies hope to stay on top of multiplying and fast-evolving cyber threats without breaking the bank. 



    But how exactly will artificial intelligence help bridge the information security skills gap? And even with the help of machine learning algorithms, what kinds of security work is still best left to humans?



    For our latest Security Ledger Spotlight podcast, we sat down with someone who is uniquely positioned to answ...
    25 min
  • Spotlight Podcast: Rethinking Your Third Party Cyber Risk Strategy

    Third party cyber risk is growing. Despite that, most companies are unprepared to address it in a systematic way. In this Spotlight Podcast, a companion to our new eBook, Rethinking Third Party Cyber Risk Management, we go deep on the topic of building a mature third party cyber risk program with Dave Stapleton the Director of Assessment Operations at the firm CyberGRX* and Jon Ehret, the President & Co-Founder of Third Party Risk Association. 











    Third party cyber exposure is a growing cost center for organizations. There are lots of reasons for this. Consider the emergence of strict data privacy and security regulations in recent years including the European Union’s General Data Privacy Regulation (GDPR) and like-minded laws like the California Consumer Privacy Act and the New York State Information Security Breach and Notification Act.



    In recent years, these laws and others have imposed substantial fines on companies found mishandling sensitive data. That means that, for companies holding onto personally identifiable information, the cost of ignoring third party risk is growing. 



    Jon Ehret is the CEO and founder of the Third Party Cyber Risk Association



    In just one example, the hotel chain Marriott was fined £99 million ($123 million) in 2019 under GDPR for a 2014 breach of a reservation system at the hotel chain Starwood that affected 339 million customers. (Marriott acquired Starwood in 2016.) In a statement accompanying the fine, UK Information Commissioner Elizabeth Denham said that GDPR’s protections for personal data mean that companies must “carr(y) out proper due diligence when making a corporate acquisition, and pu(t) in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected.”



    Marriott is hardly the only company (or even the only hospitality company) to suffer from a third party breach. Absent robust tools to manage their third-party relationships, organizations of all kinds struggle to scale inefficient processes to meet the new demands of regulators and business partners for third party risk assessments. A survey of 600 IT professionals by The Ponemon Institute found that companies spend an average of $2.1 million annually vetting third parties. Still, more than two thirds of those IT pros said the processes they use to do so are only somewhat effective or not effective at all. 



    Download our new ebook: Rethinking Third-Party Cyber Risk Management



    For our new ebook: Rethinking Third Party Cyber Risk Management, Security Ledger interviewed IT risk professionals across industries. They told us that high costs and limited scale characterize third-party cyber risk management programs in their sector. As a result, many have languished, even as the need for them has grown.  



    In conversations with leading risk and security professionals about their third-party cyber risk practices, many described legacy programs focused on regulatory compliance and questionnaires – whether paper-based or online.  “Ten or 15 years ago (third-party risk management) was basically a Word document with questions tha...
    35 min
  • Episode 161: 3 Years after Mirai, IoT DDoS Problem may get Worse

    Three years after the Mirai botnet launched some of the biggest denial of service attacks ever seen, DDoS is a bigger problem and ever. Even worse: we stand on the made up of webcams and other Internet of things as technologies like 5G bring greater bandwidth to connected endpoints. In this podcast, we speak with Hardik Modi, the senior director of threat intelligence at the firm NetScout Systems* about the lessons from his company’s latest threat intelligence report.







    August marked the three year anniversary of the discovery of the Mirai botnet. This month and next mark anniversaries of that botnet’s most notable attack, including the 2016 attack on the website of security journalist Brian Krebs’ website and the takedown of DYN, a managed DNS hosting firm in October 2016. 







    Mirai was notable for its use of Internet of Things devices like digital video recorders and webcams to carry out massive denial of service attacks. The attack, which caused ripple effects on services like Amazon.com and Twitter, raised awareness of the threat posed by Internet connected “stuff.”



    Mirai Creators Cooperate with Feds to Avoid Prison



    Three years later, however, all that awareness has done little to stem the tide of DDoS attacks. The most recent Threat Intelligence Report released by NetScout, in fact, observed 4 million DDoS attacks in just the first six months of 2019. That was a 34% jump from the same period in 2018. 



    Hardik Modi, is the Senior Director of Threat Intelligence at NetScout.



    What’s going on? To find out we invited Hardik Modi, the senior director of threat intelligence at the security firm NetScout into the Security Ledger studios to talk.



    One thing that he points to as a contributing factor in the growth of denial of service attacks is the “democratization” of DDoS technology. Push button DDoS tools and outsourced services now make even large scale attacks available to unskilled actors, Modi told me. 



    Do Cities deserve Federal Disaster Aid after Cyber Attacks?



    In this conversation, Hardik and I talk about the factors contributing to the growth in DDoS attacks in the last six months and why very large DDoS attacks seem to be waning. We also discuss the impact that emerging technologies like 5G wireless technology will have on the Internet threat landscape. 
     







    (*) Disclosure: This podcast was sponsored by NetScout Systems for more information on how Security Ledger works with its sponsors and sponsored content on Security Ledger, check out 
    29 min