Cybersecurity Sense

Cybersecurity Sense

Download on the App Store

Cybersecurity Sense episodes

  • New Tools for PCI Compliance

    In this podcast, LBMC Information Security's Bill Dean and John Dorling discuss some of the new tools available to help merchants who are trying to achieve PCI compliance.

    16 min
  • 2018 Was Second-Most Active Year for Data Breaches

    2018 was one of the biggest years for data breaches to date, with more than 6,500 data breaches reported throughout the year. In this podcast, LBMC Information Security's Bill Dean dives deeper into these recent data breach statistics and why it's important to keep investing in the hard work involved with combating cyber-attacks to prevent data breaches in the days to come.

    11 min
  • Targeted Attacks Compared to Opportunistic Attacks

    All companies are subject to opportunistic attacks, but do you know if you are subject to a targeted attack based on the data you generate or maintain? In this podcast, LBMC Information Security's Bill Dean addresses this question while diving deeper into the key differences between targeted attacks and opportunistic attacks.

    9 min
  • Incident Response Should Be Common Sense

    Since incident response issues are no longer just an IT issue and can often involve legal issues, it is important for organizations to develop an incident response team, seek outside expertise, and have an overall action plan in the event of an incident. In this podcast, LBMC Information Security's Bill Dean discusses how a complex situation like incident response can be purely based on common sense.

    8 min
  • Attack Simulation

    In a previous podcast, we discussed purple-teaming as it compares to a conventional penetration test. Let's now build on that approach, starting with the differences between attack simulation and conventional penetration tests. The methodology of attack simulation is the assumption that the network or a system will become compromised and the current controls will not prevent the infection.

    So, how does attack simulation differ from purple-teaming? With purple-teaming, everyone know what controls are being tested and when. The attack simulation is a bit different, asthe focus is the emulation of a specific attacker group and their methods of obtaining sensitive data. In this podcast, LBMC Information Security's Bill Dean discusses attack simulation, or what some people label adversary simulation.

    7 min
  • Purple-Teaming

    Most penetration testers are considered "red team," while most defenders are considered "blue team." Thus, the irony of a conventional penetration test is that these two groups are typically pitted against each other. When the red teams and blue teams are working together, you have what's called a "purple team." While purple-teaming has not always been a thing, it can be a win for both groups.

    Purple-teaming has now become somewhat of a buzzword. However, the effort behind it has great merit and value. In this podcast, LBMC Information Security's Bill Dean helps purple-teaming, as well some of the benefits involved with the practice.

    7 min
  • GDPR and Preparing for DSARs

    The EU's General Data Protection Regulation (GDPR) permits users certain rights (referred to as "data subject access rights" or "DSARs" in the documentation) that organizations will need to be prepared to accommodate if they must comply with GDPR.

    For organizations to be prepared to respond, it's important to have a clear understanding of DSARs before you risk consuming too much time, money, and resources in efforts to remain compliant. In this podcast, LBMC Information Security's Drew Hendrickson shares some considerations for how to prepare and respond when a customer chooses to request action on one of their new rights under GDPR.

    16 min
  • GDPR—How to Prepare

    As organizations determine whether the E.U.'s General Data Protection Regulation (GDPR) is applicable to them, there are several important things to consider when it comes to compliance. Among those things involves preparing for and responding to personal data breaches which is not just a requirement of the GDPR; it's a good business practice in general), data consent, and how you are protecting our data (like data pseudonymisation).

    With GDPR, personal data is defined a bit differently, which means there's potentially much more data for organizations to protect. In this podcast, LBMC Information Security's Drew Hendrickson highlights a list of things to consider when it comes to GDPR compliance.

    17 min
  • Does GDPR Apply to Me?

    As the May 25, 2018 GDPR enforcement date fast approaches, many organizations are asking, "How does the GDPR will apply to my organization?" As the GDPR extends to U.S. organizations that offer services to or monitor behaviors of E.U. citizens, it's important to understand how to classify your organization's data to determine GDPR applicability.

    While the GDPR presents new challenges for organizations storing or processing personal data, maintaining compliance with the proper guidance is essential. In this podcast, LBMC Information Security's Drew Hendrickson explains GDPR, how it can apply to you, and why GDPR compliance matters.

    15 min
  • Why Employees Are Your Number One Risk

    The question is not, "Will your employees will get your company hacked?" but rather "When will your employees get your company hacked?" A recent article from HITECH Answers highlights this sad reality of human-error being the most common reason for a cyber intrusion and data compromise. So, while employee actions can circumvent most every security control you have invested in, security awareness training is critical to prevent your employees from being your number one risk.

    Users are often the last line in your cyber-defense efforts, and there is no patch for people wanting to be helpful or wanting to do the right thing. In this podcast, LBMC Information Security's Bill Dean explains why ongoing employee security training is crucial to ensuring employees know how to spot a hacking attempt, ultimately protecting your organization from a potential cyber-attack.

    Listen, and discover these key takeaways:

    • Reasons why employees often do not realize how important they are to the process
    • How not enabling multi-factor authentication on remote access to email allows hackers to easily access employee email accounts
    • Why 91% of cyberattacks begin with a spear phishing email
    • The importance of having strong passwords for employees
    • Why backing up data is a must for protecting against cyber-attacks
    10 min

About Cybersecurity Sense

From the publisher's feed

Welcome to Cybersecurity Sense, the podcast where real-world security meets practical insights. Hosted by LBMC's Mark Burnette, this show goes beyond compliance checklists to explore the fast-moving…