Download on the App Store

episodes

  • Episode 209: Fortinet’s Renee Tarun on Scaling InfoSec To Meet Tomorrow’s Challenges

    The information security industry is simultaneously robust and beset by problems and challenges. For one thing: attacks are proliferating and becoming more stealthy and difficult to detect. Updated virus signatures won’t do you much good these days, when attackers are infiltrating software build processes or “living off the land” using administrative tools like Powershell and WMI to do their dirty work.



    Cognitive Bias is the Threat Actor you may never detect



    Renee Tarun is the Deputy CISO and Vice President for Information Security at Fortinet Inc.



    Compounding that there is a talent shortage that measures in the millions of workers globally, and hundreds of thousands of workers just in the U.S. To continue to be effective, in other words, the information security industry needs both better tools to fight adversaries, and more people to do the fighting.



    Fixing InfoSec Demands Scale, Diversity



    Our guest this week has some ideas on how we might square that circle. To wrap up our coverage of women’s history month and as part of our on-going series on Women in Cyber, we sat down with Renee Tarun is the Deputy CISO and VP of Infosec at Fortinet and a veteran of both the NSA where she served as Special Assistant to the Director for Cybersecurity.



    Encore Edition: Veracode CEO Sam King on Infosec’s Leaky Talent Pipeline



    In this interview, Renee talks about her journey to a leadership role in information security and about how the information security can scale up to meet the challenges of the future. That means both embracing technologies like automation and machine learning to help manage the tsunami of data and threats, and broadening the avenues into information security and attracting a range of skills – both hard and soft- to the industry. We also talk about her latest project: a children’s book to educate kids about basic cyber security concepts. 







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    24 min
  • Episode 208: Getting Serious about Hardware Supply Chains with Goldman Sachs’ Michael Mattioli

    In this week’s Security Ledger Podcast, sponsored by Trusted Computing Group, we’re talking about securing the hardware supply chain. We’re joined by Michael Mattioli, a Vice President at Goldman Sachs who heads up that organization’s hardware supply chain security program.







    When we think about cyber threats to the hardware supply chain, we often think about defense contractors making missiles and fighter jets. But these days, hardware supply chain security affects a wide range of companies – not just technology giants like Intel or cloud computing providers like Amazon and Google, but banks and financial services companies, healthcare companies, consumer electronics firms and more. 



    Despite media attention to the problem, the awareness of hardware supply chain risks is still low within companies. Tools and talent to address it are hard to find and expensive. What’s a company to do?



    Hardware Supply Chain Is Everyone’s Problem



    In this episode of the Podcast we welcome Michael Mattioli into the Security Ledger studio. Michael leads the Hardware Engineering team within Goldman Sachs. There, he is responsible for the design and engineering of the firm’s digital experiences and technologies. He is also responsible for the overall strategy and execution of hardware innovation both within the firm and within the broader technology industry.




    Michael Mattioli



    Michael is a Vice President and leads the hardware engineering team at Goldman Sachs.




    “Grandma deserves to know that her iPhone is genuine in the way that a corporation deserves to know if their $30,000 server is genuine.”Michael Mattioli, Goldman Sachs



    Michael is the author of a paper Consumer Exposure to Counterfeit Hardware. In it, he notes that many of the methods used to ensure hardware supply chain integrity are fallible. Visual inspection of installed parts or open source research on sellers don’t scale and are unreliable. He’s trying to sound the alarm about the threat that hardware supply chain insecurity poses to our entire economy.



    TCG Tackles Hardware Supply Chain



    Michael’s part of a new working group at Trusted Computing Group and the GSA that is working to develop standards based technology and tools to enforce hardware integrity at scale. In this interview, Michael and I talk about the growing risk of hardware supply chain risk and the need for coordination throughout the industry to address hardware security threats.Goldman Sachs joined the TCG in February as it looks for partners in securing FinTech, where activities like mobile transactions are growing by leaps and bounds.   



    To start off, I asked Michael to describe the work he does at Goldman Sachs and why a financial services company employs a hardware security expert.




    Download the MP3








    25 min
  • Episode 207: Sarah Tatsis of BlackBerry on finding and Keeping Women in Cyber





    In this week’s episode of the podcast (#207) we speak with Sarah Tatsis of the firm BlackBerry about her 20-year career at the legendary mobile device maker and the myriad challenges attracting women to- and keeping them in the information security field.



    Women face many challenges in the workplace and that’s especially true in information security, where women make up less than a quarter of information security professionals. So what does it take to create a workplace that fosters and encourage women?



    Podcast Episode 137 Sponsored by Code42: GirlScouts to the Rescue and Rethinking Enterprise DLP



    We continue our observance of women’s history month by speaking with Sarah Tatsis, who is the Senior Vice President of the Advanced Technology Development Labs at BlackBerry. Sarah is a 20 year veteran of BlackBerry and has held a number of positions within the organization. Today, Sarah and her team of engineers are responsible for taking new technologies from ideation, to incubation, to delivery into BlackBerry products and for helping BlackBerry stay on the cutting edge of security innovation. 



    Sarah Tatsis, who is the Senior Vice President of the Advanced Technology Development Labs at BlackBerry.



    Sarah is also the President of Soroptimist International of Kitchener-Waterloo, a volunteer organization that provides women and girls with access to education and training they need to achieve economic empowerment.



    Episode 205 – Google’s Camille Stewart: InfoSec’s Lack of Diversity is a Cyber Risk



    In this conversation, Sarah and I talk about her path to the information security field and how companies can work to both recruit and keep women on board.



    We discuss the work Sarah and BlackBerry have done with Canada’s Girl Guides (the equivalent of the Girl Scouts in the U.S.) to foster awareness of cybersecurity as a field and discipline. We also talk about the unique challenges that women face in our increasingly technology enabled society and workplaces where threats like deep fake videos, cyber stalking and surveillance disproportionately affect women. 







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email.
    28 min
  • Encore Edition: Veracode CEO Sam King on Infosec’s Leaky Talent Pipeline

    In this encore episode of the podcast, in honor of Women’s History Month, we’re revisiting a 2019 interview with Veracode CEO Sam King to talk about the information security industry’s struggles to attract and retain talented women. This interview originally aired in episode #148.







    The pandemic has been hard on everyone, but it has been especially hard on working women. Women accounted for 55 percent of the 20.5 million jobs lost in April, 2020 at the start of the recession according to the Bureau of Labor Statistics, raising the unemployment rate for adult women to about 15 percent from 3.1 percent in February. That had some people referring to the COVID-induced recession as more of a “shecession.” 



    Sam King is the CEO of Veracode



    But in the information security industry, the “shecession” began long before COVID 19 was a thing. Just over 20 percent of information security pros are women, and the industry has long struggled to find and retain qualified women in information security jobs. Why? Many point to an inhospitable, male dominated culture and a lack of support, within security firms, for female professionals. 



    Episode 203: Don’t Hack The Water and Black Girls Hack Founder Tennisha Martin



    In recognition of Women’s History Month, Security Ledger is running an encore edition of the podcast focused on just this issue. In this conversation recorded at the RSA Conference in 2019, I speak with Sam King, the CEO of the security firm Veracode about infosec’s leaky talent pipeline. King said that often promising information security professionals simply drop out of the field and the workforce because they lack the support of their employer to juggle family and work obligations that are different from those of their male colleagues.







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    16 min
  • Episode 206: What Might A Federal Data Privacy Law Mean In the US?

    In this episode of the podcast (#206): with movement towards passage of a federal data privacy law stronger than ever, we invite two experts in to the Security Ledger studio to talk about what that might mean for U.S. residents and businesses.







    Data theft and misuse has been an acute problem in the United States for years. And, despite the passage of time, little progress has been made in addressing it. Just this week, for example, SITA, an IT provider for the world’s leading airlines said that a breach had exposed data on potentially millions of travelers – just the latest in a steady drumbeat of breach and hacking revelations affecting nearly every industry. 



    In the E.U. the rash of massive data breaches from retail firms, data brokers and more led to the passage of GDPR – the world’s first, comprehensive data privacy regime. In the years since then, other nations have followed suit.



    But in the U.S., despite the passage of a hodgepodge of state data privacy laws, no comprehensive federal law exists. That means there is still no clear federal framework covers critical issues such as data ownership, the disclosure of data breaches, private rights of action to sue negligent firms and so on. 



    Changes In D.C. Bring Data Privacy Into Focus



    But that may be about to change. In a closely divided Washington D.C. data privacy is the rare issue that has bipartisan support. And now, with Democrats in control of Congress and the Whitehouse, the push is on to pass pro-consumer privacy legislation into law. 



    Stacey Gray, who is a Senior Counsel at the Future of Privacy Forum



    In this episode of the podcast, we invited two experts on data privacy legislation and policy into the Security Ledger studios to talk. In our first segment, we’re joined by Stacey Gray, who is a Senior Counsel at the Future of Privacy Forum to talk about progress towards a federal data privacy law in the U.S. and what that might mean for businesses and consumers. 



    I started out by asking Stacey about the recent movement on privacy legislation, including during the Trump administration, and what 2021 may have in store. 



    How Security Boosts Privacy – and Vice Versa



    Data privacy and data security are often spoken of in the same breath, but they’re actually discrete topics and discrete problems for organizations. If you want proof of that, look to the healthcare sector in the U.S. Healthcare firms must comply with HIPAA, one of the most stringent data privacy laws in the world. But that hasn’t saved them from a rash of devastating security breaches as hackers preyed on insecure and poorly maintained IP infrastructure to steal sensitive health information on hundreds of millions of Americans. 



    Rehan Jalil is the CEO of Securiti.ai.



    In our second segment, we invited Rehan Jalil, the CEO of Securiti.ai into the studio to dig deep on the security vs. privacy question. Securiti.ai is a firm that sells privacy management and compliance services.  



    In this conversation, Rehan and I talk about the evolving thinking on data privacy and security and about the impact on IT  the EU’s GDPR and state laws like CCPA are having on how businesses manage their data. Rehan and I also talk about whether technology might provide a way to bridge the gap between security and privacy: allowing ...
    55 min
  • Episode 205 – Google’s Camille Stewart: InfoSec’s Lack of Diversity is a Cyber Risk

    Here’s the deal with the information security industry in the United States: our country doesn’t have nearly the number of information security professionals that it needs. According to an estimate from Cybersecurity Ventures, the shortage of US cyber security workers could reach 500,000 people in 2021. The other point worth noting is that the information security professionals we do have are overwhelmingly white and male.  ISC2 data show that just 24% of cybersecurity workers are women. Just 9% of workers self-identified as African American or Black, compared with 13%of the population at large. Just 4% identified as Hispanic, compared with 18% of the overall population. 



    Camille Stewart is the Head of Security Policy for Google Play and Android at Google



    We know that the shortage of infosec pros poses a cybersecurity risk. Companies across industries struggle to find and then retain information security professionals to staff security operations centers (SOCs) and manage the security of networks in sectors like government, healthcare and retail. 



    Episode 148: Joseph Menn on Cult of the Dead Cow also Veracode CEO Sam King on InfoSec’s Leaky Talent Pipeline



    But what about the lack of diversity? Do infosec’s racial and gender imbalances create their own kind of security risks? Does a homogenous population of security pros potentially blind the organizations they work for  – and our society – to cyber risks? Does it shut off exploration of potentially beneficial programs, solutions or avenues of inquiry that might help solve the epidemic of cyber security threats and attacks plaguing our society? 



    You and your teams are not as effective and as able to address the threat without a diverse lens. Camille Stewart, Google



    Episode 85: Supply Chain Attacks and Hacking Diversity with Leon Johnson



    According to our guest this week: it just might. Camille Stewart is the Head of Security Policy for Google Play and Android at Google. She is also a Cyber Fellow at Harvard University’s Belfer Center for Science and International Affairs. Camille is the author of the essay “Systemic Racism is a Cybersecurity Threat” which ran on the Council of Foreign Relations website back in June of 2020.



    In it, Camille argues that understanding how systemic racism influences cyber security is integral to protecting the American people and defending the country from cyber adversaries. 



    In this conversation, Camille and I talk about her own journey to information security as a black woman and about the barriers that men and women of color face as they seek to enter information security.



    We also discuss her theory on how the information security industry’s struggles to diversify might increase cyber security risks. Camille notes that the country’s history of systemic racism and the different lived experiences of black an...
    35 min
  • Episode 204: Josh Corman of CISA on securing the Vaccine Supply Chain

    In this episode of the podcast (#204) we’re joined by Josh Corman of CISA, the Cybersecurity and Infrastructure Security Agency, to talk about how that agency is working to secure the healthcare sector, in particular vaccine supply chains that have come under attack by nations like Russia, China and North Korea.







    Incidents like the Solar Winds hack have focused our attention on the threat posed by nation states like Russia and China, as they look to steal sensitive government and private sector secrets. But in the vital healthcare sector, nation state actors are just one among many threats to the safety and security of networks, data, employees and patients.



    Joshua Corman is the Chief Strategist for Healthcare and COVID on the CISA COVID Task Force.



    In recent years, China has made a habit of targeting large health insurers and healthcare providers as it seeks to build what some have described as a “data lake” of U.S. residents that it can mine for intelligence. Criminal ransomware groups have released their malicious wares on the networks of hospitals, crippling their ability to deliver vital services to patients and – more recently – nation state actors like North Korea, China and Russia have gone phishing – with a “ph” – for information on cutting edge vaccine research related to COVID 19.



    How is the U.S. government responding to this array of threats? In this episode of the podcast, we’re bringing you an exclusive interview with Josh Corman, the Chief Strategist for Healthcare and COVID for the COVID Task Force at CISA, Cybersecurity and Infrastructure Security Agency.



    Cryptocurrency Exchanges, Students Targets of North Korea Hackers



    In this interview, Josh and I talk about the scramble within CISA to secure a global vaccine supply chain in the midst of a global pandemic. Among other things, Josh talks about the work CISA has done in the last year to identify and shore up the cyber security of vital vaccine supply chain partners – from small biotech firms that produce discrete but vital components needed to produce vaccines to dry ice manufacturers whose product is needed to transport and store vaccines.



    Episode 194: What Happened To All The Election Hacks?



    To start off I asked Josh to talk about CISA’s unique role in securing vaccines and how the Federal Government’s newest agency works with other stake holders from the FBI to the FDA to address widespread cyber threats.











    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, 
    33 min
  • Episode 203: Don’t Hack The Water and Black Girls Hack Founder Tennisha Martin

    In this episode of the Security Ledger Podcast (#203) we talk about the apparent hack of a water treatment plant in Oldsmar Florida with Frank Downs of the firm BlueVoyant. In our second segment: is infosec’s lack of diversity a bug or a feature? Tennisha Martin of Black Girls Hack joins us to talk about the many obstacles that black women face as they try to enter the information security field.







    Part 1: Don’t Hack the Water!



    An obscure water treatment facility in Oldsmar Florida became ground zero for the United States concerns about foreign adversaries ability to access and control critical infrastructure last week, after local officials revealed in a news conference that an unknown assailant had remotely accessed the facility’s SCADA system and attempted to raise levels of the poisonous chemical sodium hydroxide in the drinking water by a factor of more than 100. 



    Frank Downs is the Director of Proactive Services at Bluevoyant.



    The attack failed after a worker at the treatment plant saw it play out on his terminal in real time, and adjusted the sodium hydroxide levels back to normal. Nor would it have worked, officials assured a worried public: sensors elsewhere in the water distribution system would almost certainly have caught the abrupt increase in the dangerous chemical. 



    But closies do count when it comes to critical infrastructure hacks, and the Oldsmar incident set off a federal investigations and a flurry of warnings and editorial hand-wringing about the risks facing critical infrastructure systems. That’s especially true with so many workers accessing them remotely during the pandemic, leaving sensitive systems exposed. 



    Episode 202: The Byte Stops Here – Biden’s Cyber Agenda



    In our first segment this week, Frank Downs of the firm BlueVoyant joins us in the Security Ledger studio to discuss the water system hack and why critical infrastructure firms continue to struggle to protect their environments. 



    Can Infosec Walk the Talk on Diversity?



    For years professionals have decried the lack of diversity in the information security field which, even more than high tech in general, is dominated by white men. At infosec conferences, concerted effort has been made giving more visibility and voice to women and minorities. The dreaded “MANels” – panels made up entirely of men – have been targeted and, in many cases, banished. But down in the trenches – where information hiring takes place and information work is done – there is little evidence of change. 



    Tennisha Martin is the Executive Director of Black Girls Hack.



    The lack of progress, despite a crushing shortage of infosec workers and the stated intentions of infosec leaders and executives, might get you wondering whether cyber’s lack of diversity is a bug or a feature of the system. 



    57 min
  • Episode 202: The Byte Stops Here – Biden’s Cyber Agenda

    In this episode of the Security Ledger Podcast (#202) we do a deep dive on President Biden’s cyber agenda with three experts on federal cyber policy and the challenges facing the new administration.







    Well, it almost didn’t happen, but on January 20, Joseph Robinette Biden Jr. was sworn in as the 46th President of the United States. More than any president since Franklin Roosevelt, Biden inherited a country in the throws of a crisis. By the time of his inauguration, the COVID virus had killed upwards of 400,000 U.S. residents and tanked the  national economy. As the incidents of January 6 indicated, right wing militant groups are stirring and threatening to topple democratic institutions.



    Enter Solar Storm



    And, as if that wasn’t enough, the weeks between the November Election and Biden’s January inauguration brought to light evidence of what is perhaps the biggest cyber intrusion by a foreign adversary into US government networks, the so called Solar Storm hack, which has been widely attributed to the government of Russia. 



    Even before Solar Storm, Biden made clear as a candidate that a cyber security reset was needed and that cyber would be a top priority of his administration. The wide ranging hack of the US Treasury, Departments, of State, Justice, Defense and Homeland Security – among others – just added fuel to the roaring dumpster fire of Federal IT security. 



    But what will that reset look like? To understand a bit better what might be in store in the months ahead we devoted this episode of the podcast to interviewing three experts on federal IT security and cyber defense. 



    Rebuilding Blocks



    But first, before you can do a reset you need to understand what went wrong the first time around. In the case of federal cyber security, that’s not a short list.



    Spotlight Podcast: Taking a Risk-Based Approach to Election Security



    In our fist segment, we’re joined by two experts on cyber policy about the US governments struggles to get cyber security right, culminating with the problems seen during the Trump administration.







    Lauren Zabierek is the Executive Director of Cyber Project at Belfer Center For Science and International Affairs at Harvard’s Kennedy School of Government. She’s joined by Paul Kolbe, the Director of the Intelligence Project at Belfer Center. The two joined me in the Security Ledger studios to talk about how the Biden Administration might rebuild the US government’s cyber function and who might populate key positions in the new administration. 



    Spotlight Podcast: QOMPLX CISO Andy Jaquith on COVID, Ransomware and Resilience



    To start off, I asked them what the biggest challenges are out of the gate for the new administration. 



    The Byte Stops Here: What Cyber Leadership Looks Like



    As Harry Truman famously said: the “Buck stops” at the President’s desk.
    42 min
  • Episode 201: Bug Hunting with Sick Codes

    In the past 20 years, bug hunting has transformed from a hobby (or maybe even a felony) to a full-time profession for tens of thousands of talented software engineers around the globe. Thanks to the growth in private and public bug bounty programs, men and women with the talent can earn a good living by sniffing out flaws in the code for applications and – increasingly -physical devices that power the 21st century global economy. 



    Asus ShadowHammer suggests Supply Chain Hacks are the New Normal



    Bug Hunting Smart TVs To Supply Chain



    What does that work look like and what platforms and technologies are drawing the attention of cutting edge vulnerability researchers? To find out we sat down with the independent researcher known as Sick Codes (@sickcodes). In recent months, he has gotten attention for a string of important discoveries. Among other things, he discovered flaws in Android smart television sets manufactured by the Chinese firm TCL and was part of the team, along with last week’s guest John Jackson, that worked to fix a serious server side request forgery flaw in a popular open source security module, NPM Private IP. 



    Spotlight Podcast: How Machine Learning is revolutionizing Application Fuzzing



    In this interview, Sick Codes and I talk about his path to becoming a vulnerability researcher, the paid and unpaid research he conducts looking for software flaws in common software and internet of things devices, some of the challenges and impediments that still exist in reporting vulnerabilities to corporations and what’s in the pipeline for 2021. 







    As always,  you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and check us out on SoundCloud, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. 
    34 min