Download on the App Store

episodes

  • Spotlight Podcast: How AI Is Reshaping The Cyber Threat Landscape

    Host Paul Roberts speaks with Jim Broome, the CTO and President of DirectDefense about the evolution of cybersecurity threats and how technologies like AI are reshaping the cybersecurity landscape and the work of defenders and Managed Security Service Providers (MSSPs).

    The post Spotlight Podcast: How AI Is Reshaping The Cyber Threat Landscape appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk
    • Episode 256: Recursive Pollution? Data Feudalism? Gary McGraw On LLM Insecurity
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    38 min
  • Episode 257: Securing Software on Wheels with Dennis Kengo Oka of Synopsys

    In this episode of The Security Ledger Podcast (#257) Paul speaks with Dennis Kengo Oka, a senior principal automotive security strategist at the firm Synopsys about the growing cyber risks to automobiles as connected vehicle features proliferate in the absence of strong cybersecurity protections.

    The post Episode 257: Securing Software on Wheels with Dennis Kengo Oka of Synopsys appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Episode 257: Securing Software on Wheels with
    • Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    35 min
  • Episode 256: Recursive Pollution? Data Feudalism? Gary McGraw On LLM Insecurity

    Paul speaks with Gary McGraw of the Berryville Institute of Machine Learning (BIML), about the risks facing large language model machine learning and artificial intelligence, and how organizations looking to leverage artificial intelligence and LLMs can insulate themselves from those risks.

    The post Episode 256: Recursive Pollution? Data Feudalism? Gary McGraw On LLM Insecurity appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk
    • Spotlight Podcast: How AI Is Reshaping The Cyber Threat Landscape
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    33 min
  • Episode 255: EDM, Meet CDM – Cyber Dance Music with Niels Provos

    In this episode of The Security Ledger Podcast (#255) host Paul Roberts interviews Niels Provos of Lacework about his mission to use EDM to teach people about cybersecurity.

    The post Episode 255: EDM, Meet CDM – Cyber Dance Music with Niels Provos appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    • Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk
    • Episode 258: Broken Brokers – Optery’s Fight To Claw Back Your Personal Data
    30 min
  • Episode 254: Dennis Giese’s Revolutionary Robot Vacuum Liberation Movement

    Security researcher and IoT hacker Dennis Giese talks about his mission to liberate robot vacuums from the control of their manufacturers, letting owners tinker with their own devices and - importantly - control the data they collect about our most intimate surroundings.

    The post Episode 254: Dennis Giese’s Revolutionary Robot Vacuum Liberation Movement appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • A Digital Lock Maker Tried To Squash A DEF CON Talk. It Happened Anyway. Here’s Why.
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    • Spotlight Podcast: OT Is Under Attack. Now What?
    37 min
  • Spotlight Podcast: Chris Petersen CEO Of RADICL On Protecting Defense Industry SMBs Spotlight Podcast: RADICL Is Coming To The Rescue Of Defense SMBs

    In this Spotlight Security Ledger podcast, Chris Petersen, the CEO and founder of RADICL, talks about his company's mission to protect small and midsized businesses serving the defense industrial base, which are increasingly in the cross-hairs of sophisticated, nation-state actors.

    The post Spotlight Podcast: RADICL Is Coming To The Rescue Of Defense SMBs appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk
    • Report Finds Lack of Talent, Tools Frustrates Cyber Investigations
    • Spotlight Podcast: How AI Is Reshaping The Cyber Threat Landscape
    28 min
  • Episode 253: DevSecOps Worst Practices With Tanya Janca of We Hack Purple

    Tanya Janca of the group We Hack Purple, talks with Security Ledger host Paul Roberts about the biggest security mistakes that DevSecOps teams make, and application development’s “tragedy of the commons,” as more and more development teams lean on open source code.

    The post Episode 253: DevSecOps Worst Practices With Tanya Janca of We Hack Purple appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Sickened by Software? Changing The Way We Talk About 0Days
    • GitGuardian’s HasMySecretLeaked Is HaveIBeenPwned for DevOps
    • State of Modern Application Security: 6 Key Takeaways For 2022
    33 min
  • Episode 252: Colin O’Flynn On Hacking An Oven To Make It Stop Lying

    In this episode of the podcast, host Paul Roberts speaks with Colin O'Flynn, CTO and founder of the firm NewAE about his work to patch shoddy software on his home's electric oven - and the bigger questions about owners rights to fix, tinker with or replace the software that powers their connected stuff.

    The post Episode 252: Colin O’Flynn On Hacking An Oven To Make It Stop Lying appeared first on The Security Ledger with Paul F. Roberts.

    Click the icon below to listen.
    Related Stories
    • Episode 254: Dennis Giese’s Revolutionary Robot Vacuum Liberation Movement
    • Security Teams Lean Into AI As Cyber Worker Shortage Persists
    • Malicious Python Packages Target Crypto Wallet Recovery Passwords
    43 min
  • Spotlight Podcast: Are you ready for Threat Reconnaissance?

    In this Spotlight episode of the Security Ledger podcast, I interview David Monnier, the CIO and Chief Evangelist at the firm Team Cymru (pron. kum–ree) about the evolution of the threat intelligence space and the growing need for what Team Cymru calls “Threat Reconnaissance,” a process for leveraging organization-specific threat intel to help root out and neutralize malicious campaigns targeting an organization.



    [MP3] [Video] [Transcript]







    “Cyber threat intelligence” is a phrase that refers to data compiled on the activities, tools and capabilities of malicious cyber actors. And it’s a big business. By one estimate, the global threat intelligence market was valued at USD $4.24 billion in 2022 and is projected to grow to $18.11 billion by 2030. 



    These days, most security teams consume multiple threat intelligence feeds to help them make sense of the threat landscape and spot risks to their organization – IT assets, networks, data. But making threat intelligence actionable is another matter. After all, knowing that a ransomware group or state sponsored actor is targeting your industry is different from knowing that they’re targeting your company specifically. And, absent specific information about threats to your organization and the ability to act on that information, threat intelligence feeds can simply add noise to an already noisy SOC. 



    A better approach is what our next guest calls “threat reconnaissance” – the application of threat intelligence to hunt down and neutralize looming or active threats that target your organization. But how does a security team move from simply consuming threat intelligence, to operationalizing it and conducting threat reconnaissance?



    In this Spotlight Edition of the podcast, I’m joined by David Monnier, the CIO and Chief Evangelist at the firm Team Cymru to talk about his company’s work to evolve threat intelligence from merely curated feeds relevant to a specific industry or sector, to tailored feeds that highlight active or evolving threats specific to an organization.



    The key, Monnier explained, is to gather threat intelligence that is actionable and then leverage it to expose the workings of cyber adversaries targeting your organization – the command and control (C2) infrastructure they rely on, the employees they target, and so on.



    “A hotel chain doesn’t have the same adversaries pursuing it as someone at home nor as say a defense contractor. They all have different adversaries. And really, you need to have intelligence that’s catered,” Monnier told me.



    In this conversation, David and I talk about the drive towards threat reconnaissance and the evolution in threats and threat actors – in particular the economics driving and explosion in cyber crime and what Monnier calls “miscreancy” over the past three decades.



    To start off our conversation, I asked David to fill us in on his long tenure in the cyber security community, which stretches back to the mid 1990s and the more recent work he’s focused on at Team Cymru.



    Video Interview
    38 min
  • Episode 251: Kry10 CEO Boyd Multerer on building a secure OS for the IoT

    In this episode of the podcast, host Paul Roberts speaks with Boyd Multerer, CEO of the firm Kry10 about the firm’s technology: a secure operating system for the Internet of Things and about how the challenges of managing modern, connected devices demands new tools and platforms for securing those devices.



    [Video Podcast] | [MP3] | [Transcript]







    The Internet of Things is growing – and fast. Data from the firm IoT Analytics  shows that the number of global IoT connections grew by 18% in 2022 to 14.3 billion active IoT endpoints.  By 2027, there will likely be more than 29 billion IoT connections, the firm says. 



    Unfortunately for consumers, businesses and governments alike: all those billions of devices sit on a shaky foundation. A study of the security of IoT devices by Phosphorus Labs, a cybersecurity company, found that 68% of devices studied contained high-risk or critical software vulnerabilities. That’s consistent with a 2020 study by Palo Alto Networks that found that 57% of IoT devices are vulnerable to medium- or high-severity attacks. 



    Boyd Multerer is the CEO of Kry10


    And, as software and always on Internet connectivity extend to a greater range of endpoints, the stakes are getting higher. Sophisticated, cyber physical devices running on general purpose operating systems like Linux create untold opportunities for mischief. As an example, there are the recent revelations of remotely exploitable flaws in vehicle telematics software which raise the specter of cyber physical attacks in which software based attacks cause damage to persons and property. 



    This growing population of smart, connected and cyber physical devices demands a new and more secure platform from which to operate – one designed with next generation, smart cyber physical devices in mind. And that’s what our guest today says he’s developed. Boyd Multerer is the CEO and founder of Kry10 (pronounced “Cry Ten”), a company that has developed a highly secure operating system for smart, connected devices in mission critical settings. The Kry10 platform is billed as a zero trust architecture that is capable of limiting the code that can run in privileged mode and isolate  non-core capabilities as possible.



    In this conversation, I talk with Boyd about Kry10’s technology and the challenge of securing the modern IoT and how the challenges of managing modern, connected devices demands new tools and platforms for securing those devices. To start off, I asked Boyd to talk about his journey through cybersecurity and how his work in the early 2000s as an engineer at Microsoft tasked with developing the company’s massively popular XBOX  and XBOX Live gaming platform informed his current work about secur...
    39 min