Download on the App Store

episodes

  • Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion

    In this Spotlight edition of the podcast, we’re joined by Brian Trzupek the Senior Vice President of Product at DigiCert. Brian and I take a look at the findings of a recent State of PKI Automation survey and the challenges organizations face as they look to manage a fast-growing population of tens of thousands of PKI certificates.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 







    Twenty years ago, Public Key Infrastructure, or PKI, had a pretty limited remit. Its first applications were securing email and physical access systems in security conscious environments like the military, intelligence community and government. With the explosion of the Internet, PKI became a foundational technology for securing web traffic and authenticating users to applications via technologies like SSL and TLS.



    Brian Trzupek is SVP of Products at DigiCert



    Since then, both the scale and applications of PKI have transformed. Today, PKI and digital certificates are used to sign and secure electronic documents and – increasingly – to secure communications and interactions between billions of connected devices on the Internet of Things.  Moreover, as digital transformation and DEVOPS has taken hold within the enterprise, the demand for PKI to secure critical development and production infrastructure has exploded. 



    Survey: 50,000 Certs on Average



    In fact, a recent survey of PKI use in 400 enterprises worldwide found that the typical enterprise is managing more than 50,000 digital certificates, with most dedicated to securing users, servers, web applications, email and mobile devices. That’s a 43% jump year over year, according to the survey.



    Not surprisingly, IT managers are feeling overwhelmed by the sudden growth in the population of certificates. 61% of those surveyed said they were concerned about the time required to manage certificates in their environment, while 47% reported having encountered “rogue” (or unmanaged) certificates. 



    35 min
  • Episode 228: CISA’s Eric Goldstein on being Everyone’s Friend in Cyber

    In this episode of the podcast (#228) we’re joined by Eric Goldstein, Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA) to talk about how the US government’s lead cybersecurity agency is helping companies and local government to keep hackers at bay. But are organizations ready to ask for help?



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    October is the 18th annual Cybersecurity Awareness Month – a month dedicated to educating the public and the private sector about cyber risks. What better time, then, to check in with our friends at CISA, the Cybersecurity and Infrastructure Security Agency. 



    CISA: A Different Kind of Agency



    Eric Goldstein (CISA)



    As the U.S. government’s newest agency and the tip of the spear for government response to cyber risks and cyber threats, CISA has its hands full. The agency is responsible for coordinating and informing the cybersecurity practices of the federal government, which employs more than 4 million Americans and has a budget of close to $5 trillion. It also is the go-to for cybersecurity intelligence and security services for state and local governments. The agency offers a series of “cyber hygiene services” that local and state governments can use to interrogate their infrastructure. CISA also helps coordinate with the private sector around emerging threats, such as ransomware gangs and the hack of key providers like SolarWinds, Kaseya, the Colonial pipeline and more. 



    CISA executives are quick to point out that the agency is not a regulator nor is it law enforcement. Indeed: CISA is “a different kind of agency:” less bureaucratic, more agile and more willing to embrace technologic change. CISA’s most important objective is to be a friend to the agencies and organizations that it serves: involving itself in cyber incident response not to assign blame or mete out punishment,
    38 min
  • Spotlight: COVID Broke Security. Can We Fix It In 2022?

    In this Spotlight Podcast, Pondurance Founder and Chief Customer Officer Ron Pelletier joins me to discuss his predictions about the security trends that will shape 2022. After a devastating 18 months of COVID – which included a surge in cyber attacks – 2022 offers promises of better times. But maybe not for security teams. Ron says organizations need to go back to the risk management drawing board to prepare for new threats and attacks.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted.



    [MP3]







    The last 18 months has been unlike anything in recent memory. The COVID Pandemic shuttered entire economies, killed millions, sickened hundreds of millions and confined billions of people to their homes. 



    Ron Pelletier is the founder and Chief Customer Officer at Pondurance. 



    Along the way, the pandemic has been a boon for some businesses – think: supermarkets, video streaming services and Amazon.com. And then there are the cyber criminal groups, who have used the disruptions caused by COVID to worm their way onto sensitive networks: exploiting vulnerable remote workers and security teams that were spread thin. 



    2021: The End of the Beginning?



    Sure, 2021 has seen a gradual return to normalcy: students are back in the classroom, sports fans have crowded stadiums and workers return to the office. Many hope, that 2022 will bring even happier days, as COVID recedes and the rhythms of life return to normal – even if masks are likely to stay with us for a while. 



    What does the next year have in store? To help us answer that question, we invited Ron Pelletier into the Security Ledger studios. Ron is the founder and Chief Customer Officer at the firm Pondurance. In this conversation, and I talk about what may be in store.



    2022: Turning A Corner



    The tragedies of 2020 aside, Ron says there is plenty of reason for optimism about 2...
    30 min
  • Episode 227: What’s Fueling Cyber Attacks on Agriculture ?

    In this episode of the podcast (#227) we speak with Allan Liska, the head of the CSIRT at the firm Recorded Future. about the spate of attacks in recent months targeting food processing plants, grain cooperatives and other agriculture sector targets. Allan and I talk about the how these attacks are playing out and why, all of a sudden, the agriculture supply chain is under attack.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    There’s trouble on the farm. Recent weeks have seen an increase in attacks on elements of the U.S. food production system. Most famously, there was the meat processor JBS ), which paid $11 million in June to ransomware criminals from the REVil group to regain access to hacked systems and data. 



    Allan Liska runs the CSIRT at Recorded Future



    Then, September brought news of still more attacks on critical food supply chain partners. The New Cooperative, an Iowa grain cooperative with more than 60 locations, was hit by ransomware operated by BlackMatter, a ransomware gang with roots in the DarkSide group, a Russian cybercriminal outfit that was responsible for the attack on the Colonial oil and gas pipeline in the spring. Also in September, the Crystal Valley Cooperative, a Minnesota based farm supply and marketing cooperative was hit with ransomware, knocking the company offline and disrupting business operations.



    Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security



    More Agriculture Supply Chain Attacks on Tap



    That might not be the end. Threat researcher Allan Liska
    23 min
  • Spotlight: Operationalizing MDR with Pondurance CISO Dustin Hutchison

    In this Spotlight Podcast, Pondurance Chief Information Security Officer Dustin Hutchison joins me to talk about the value that managed detection and response (MDR) technology plays in an environment of proliferating threats. Dustin and also talks about how companies can operationalize MDR within their environment.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted.







    Dustin Hutchison is CISO at Pondurance



    Enterprises today have a full plate of challenges when it comes to cyber security. In addition to doing the basic blocking and tackling like software updates and user management, organizations have cloud and third party risks to worry about. The rise of ransomware makes regular on- and off site backups of key systems and data indispensable. 



    And, then there’s the prevalence of sophisticated criminal and nation state adversaries. Organizations today simply can’t count on their ability to keep the bad guys off of their network. That’s why incident response and threat hunting capabilities are in high demand – and low supply. 



    Proliferating Threats: Enter MDR!



    Given the diversity of cybersecurity skills that are now required, its no surprise that managed detection and response (MDR) firms are becoming a staple of enterprise security, as companies look to outsource mission critical cyber security tasks to trained professionals. 



    Spotlight: Is There A Cure For InfoSec’s Headcount Headache?



    But that begs the question of what kinds of firms are likely to benefit the most from contracting with an MDR firm. And, given that your organization can benefit from MDR, what do you need to do first to be in a position to bring one on? And what is involved in the process of integrating that MDR firm into your IT security operations? 



    Operationalizing MDR in the Enterprise



    30 min
  • Spotlight: When Ransomware Comes Calling

    In this Spotlight Podcast, Pondurance Manager of Incident Response Max Henderson joins me to talk about the ongoing ransomware epidemic and some of the emerging trends in ransomware attacks. We also talk about and what companies get right- and wrong in their response. Max gives us some tips about how best to respond to ransomware threats and attacks.



    Max Henderson is the Manager of Incident Response at Pondurance



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 







    Ransomware attacks have become a mainstay of the cyber threat landscape -and among the most dreaded forms of cyber crime. While exact numbers are hard to come by, large scale studies of companies found that more than a third had been hit by ransomware in the past year, with the retail, government and education sectors particularly hard hit.



    With the attention given to the threats posed by ransomware, why do organizations still fall victim to these attacks? There are many contributing factors, but one of the most important is the shortage of cyber security talent in the trenches of modern organizations. Without properly trained personnel, organizations are missing the early signs of a compromise that might otherwise allow them to cut short a malicious campaign. And even when internal teams do get wind of a cyber attack in process, a lack of experience can hamper their response: tipping off attackers in ways that worsen the damage and disruption they cause or allow them to cover their tracks, denying victims a full understanding of the scope of the incident.



    Getting Incident Response Right



    So what should companies worried about ransomware do? In this episode of the podcast we’re joined by Max Henderson, the Manager of Incident Response at the endpoint detection and response firm Pondurance. Max is a seasoned cyber security and incident response professional who has led hundreds of investigations including complete network, cloud, and Active Directory compromises of entities with annual revenues in the multi-billion dollar range. Hiss investigations and presentations have been featured on CBS 60 Minutes, National Infragard, and International ISSA conferences.



    In this conversation, Max and I talk about some of the root causes of the ransomware pandemic, and why it is that companies so often miss the telltale signs of growing compromises in their environments.
    27 min
  • Spotlight: Is There A Cure For InfoSec’s Headcount Headache?

    In this Spotlight Podcast, Pondurance Chief Strategy Officer Lyndon Brown joins me to talk about how changes in both the threat landscape and the workplace are driving demand for managed detection and response services, in which companies hire outside security talent to help keep sophisticated cyber adversaries at bay.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    Change is the one constant in the information security field, where the bad guys set the tone and whose hunger for profits drive rapid evolution in both threats and attacks. 



    These days, the plague du jour is ransomware, in which cyber criminal gangs infiltrate companies, encrypt sensitive information and systems and – increasingly – offer threaten to leak stolen data to increase the leverage on their victims. 





    Unfortunately, the “fix” for  the ransomware problem isn’t straight forward. Enterprise perimeters had already deteriorated well before the COVID pandemic and the rapid shift to remote work battered down what was left of them. Phishing attacks, credential stuffing and application layer attacks like SQL injection reliably provide access to corporate environments. Perimeter based detections and blocking offer little in the way of protection against these risks. 



    Lyndon Brown is the Chief Strategy Officer at Pondurance



    Increasingly the solution for organizations is to bring in security experts to help keep hackers at bay. But that runs up against another urgent problem: a severe shortage of cyber security workers, especially in sectors like healthcare and government. In July, for example, the Department of Homeland Security announced that it had completed its most successful cybersecurity hiring drive ever and that it still had more than 1,800 vacancies for cyber security workers.



    One answer to the cybersecurity talent shortage is
    31 min
  • Episode 226: The Cyber Consequences Of Our Throw Away Culture

    In this episode of the podcast (#226) we speak with John Shegerian, the Chairman and CEO of Electronics Recycling International (ERI) about his new book: “The Insecurity of Everything.” John and I talk about the world’s growing electronic waste problem and how foreign actors are believed to be harvesting sensitive data from laptops, phones and other electronics discarded by the U.S. and other nations.



    A note: we have free copies of John’s book available for Security Ledger podcast listeners. If you’d like one use the button below to sign up and receive your copy!



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 







    On Tuesday, Apple introduced the iPhone 13. It one of several device announcements made during a virtual event at its headquarters in Cupertino, California including a revamped iPad, and iPad Mini, as well as a new Apple Watch Series 7.



    After the upgrade: tons of e-waste



    That’s great news for Apple fans, but bad news for the environment. New devices, after all, mean a wave of upgrades as users jettison perfectly usable hardware for the latest and greatest. That old hardware may find a new owner in the secondary market. But much of it will become a part of the world’s massive river of eWaste along with television sets, video game consoles, home appliances and more. 



    John Shegerian is the CEO of ERI



    Globally, an estimated  59 million tons of used electronics end up in landfills each year. In the last 20 years, electronics waste (e-waste) has become one of the fastest growing waste stream in the world. What’s worse: e-waste is both difficult to recycle and exceptionally harmful to the environment. It accounts for less than 2 percent of the world’s waste stream by volume. But it causes over 70 percent of the waste stream’s harmful and toxic environmental effects, according to US PIRG. 



    Sensitive data dragged to the curb



    But there’s another, less talked about consequence of our e-waste problem: data lea...
    28 min
  • Spotlight: Securing COVID’s New Normal with Cathy Spence of Intel

    In this Spotlight Podcast, Intel Senior Principle Engineer Cathy Spence joins me to talk about how COVID 19 has forged a new normal and shifted enterprise security battle lines.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    The world is more than 18 months into the COVID pandemic and one thing is for certain: business and life itself are not going “back to normal” any time soon – if ever.



    The changes forced on organizations by COVID are simply too substantial. They range from the shift to remote work and the (permanent?) end of office culture, to a whole hearted embrace of digital transformation and cloud computing. Sure, these things started out as temporary responses to a mortal threat. A year and a half later, however, they’re deeply entrenched – the building blocks of a new, post-pandemic “normal” for the business world.



    Remote Work Poses Security Challenge



    But securing that new normal won’t be easy – as incidents in the last year have shown us. The shift to remote work has  pushed the enterprise perimeter out to thousands or tens of thousands of vulnerable home networks. It has increased reliance on VPNs and other remote access technology, and cybercriminals have taken note. The compromise  of the colonial pipeline, after all, came by way of a vulnerable VPN concentrator that Colonial’s internal security assessments and “red teams” overlooked. 



    And then there’s the problem of all those investments organizations made before COVID. Just because workers have gone remote, doesn’t mean that organizations don’t still rely on legacy infrastructure and code that is old enough to drive – if not drink. 



    Fifty Shades of Hybrid



    What will it mean to secure this new normal? In this spotlight edition of the podcast,
    28 min
  • Episode 225: Unpacking the Azure CHAOS DB Flaw with Nir Ohfeld of Wiz

    In this episode of the podcast (#225) we’re joined by Nir Ohfeld, a Senior Security Researcher at the firm Wiz. Nir helped discover the recent CHAOS DB flaw in COSMOS DB, the flagship database for Microsoft’s Azure cloud platform. Nir and I discuss the implications of the flaw, what steps organizations should take to limit their exposure and the larger issue of cloud insecurity.



    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 



    [MP3]







    A flight to the cloud is one of the most salient technology trends of the last decade. With each passing month, more and more organizations are swapping out on premises applications and platforms for their cloud based alternatives: GSuite or Office 365 for Office, Azure AD for Active Directory, Workday and Salesforce for SAP and Oracle…and on and on. 



    But there are security trade offs that go along with cloud migration. And the past week made that abundantly clear, after Microsoft and security researchers from the firm Wiz revealed a critical flaw in COSMOS DB,  Microsoft’s Azure flagship database, which Wiz named “CHAOS DB.” 



    Episode 152: What the Silex Malware says about IoT Insecurity and Cloud Security CEO Steve Mullaney on Amazon ReInforce



    Nir Ohfeld is a Senior Security Researcher at Wiz.



    CHAOS DB: The Crown Jewel of Hacks



    According to a report by researchers from Wiz, a flaw in the Jupyter Notebook, a common component of COSMOS DB,  opened thousands of Microsoft Azure customers to a “trivial” remote compromise that could have provided remote attackers with full administrative access (read, write, delete) to other customers Cosmos DB instances without authorization. The vulnerability  impacts thousands of organizations, including numerous Fortune 500 companies, Wiz reported. That prompted a warning by Microsoft, who also disabled the Jupyter Notebook feature on COSMOS DB just days after receiving the Wiz report...
    23 min