Cybersecurity Sense

Cybersecurity Sense

Download on the App Store

Cybersecurity Sense episodes

  • Phishing Emails with 100% Click Rate

    In a recent report from Wombat Security Technologies based on data from millions of simulated phishing attacks, it was found that 76% of organizations said they experienced phishing attacks in 2017, and nearly half of information security professionals said that the rate of attacks increased from 2016 to 2017. F-Secure also recently released research data indicating that over one-third of security incidents start with phishing emails or malicious attachments sent to company employees.

    In this podcast, LBMC Information Security's Bill Dean digs into these research findings and shares some reasons why training employees to spot phishing emails, messages, and pre-texting calls can't be done just once or once a year.

    Listen, and discover these key takeaways:

    • Fascinating new research findings about phishing attacks
    • Reasons for training employees about phishing attacks on an ongoing basis
    • Why it only takes one user to follow the link in a phishing email for your network to be compromised
    • New approaches that may be implemented into our menu of phishing schemes
    7 min
  • IIA Knoxville—Implementing Cloud-Managed Security

    When cloud-managed security was first introduced, there was some concern about the levels of security as compared to the security of data on an organization's premises. Today, security professionals have implemented the appropriate controls to help could-based data management be safe and effective. As many organizations are now embracing and migrating to the cloud, it is important to know the risks and proper controls associated with the movement.

    In this podcast from the Institute of Internal Audit meeting in Knoxville, LBMC Information Security's Bill Dean and Sese Bennett discuss the effectiveness and concerns surrounding migrating to cloud-managed security measures and what organizations today should know.

    Listen, and discover these key takeaways:

    • Why you should evaluate your current security frameworks and compare with cloud-managed controls
    • A brief explanation of FedRAMP and FISMA
    • Reasons to consider moving to cloud-managed security
    • The potential risks associated with cloud frameworks if not implemented properly
    • Why not to stop at the assessment phase
    8 min
  • IIA Knoxville—Risky Business

    No matter the industry—government, healthcare, financial, or even smaller, mom-and-pop businesses—each deal with some type of sensitive customer information, and each has decisions to make when it comes to managing risk. Most security and audit frameworks (HIPAA, ISO, PCI, NIST, SOC 2, etc.) have requirements for risk assessment, making them one of the first things auditors or regulators ask for. Many companies are still using spreadsheets when it comes to performing risk assessments, which can be ineffective and insecure. Such a lack of functionality can keep a company from moving beyond assessment and into true risk management.

    In this podcast from the Institute of Internal Audit meeting in Knoxville, LBMC Information Security's Bill Dean and Mark Fulford discuss the importance of risk management, including the effectiveness of risk assessments and how BALLAST can help organizations automate the risk assessment process.

    Listen, and discover these key takeaways:

    • Understanding what's important to your organization when it comes to managing risks
    • Reasons to consider more targeted risk assessments
    • Why you shouldn't just do gap assessments
    • How to automate the risk assessment process
    • Why not to stop at the assessment phase
    8 min
  • IIA Knoxville—Dear President Trump: How to Secure the United States & Demonstrate That Your Company Is

    In the information security world, we all wish we had more access to senior executives. Following that logic, if you're responsible for security at your organization, and you are lucky enough to ride on the same elevator with a senior executive from your company, you should be prepared with your "elevator pitch" on what to say about improving the cybersecurity posture of the organization. When asked, you want to have your message fine-tuned and be able to communicate it clearly and succinctly (before the elevator reaches the parking garage).

    In this podcast, LBMC Information Security's Mark Burnette discusses his elevator pitch to President Donald Trump with podcast host Bill Dean. While Mark hasn't ridden on an elevator with the President, he doesn't let that stop him from finding a way to articulate what the President should be doing to address cybersecurity issues at the federal level.

    Listen, and discover these key takeaways:

    • Reasons cybersecurity initiatives at the federal government level are important
    • Former and current administration actions on cybersecurity
    • Reasons for establishing a national cybersecurity advisory committee
    • The need for enforcing existing cybersecurity laws
    • Why the ease and proliferation of cyber-attacks is too much to ignore
    8 min
  • IIA Knoxville—SOC for Cybersecurity

    The AICPA Cybersecurity Working Group brought to life a new type of cybersecurity examination report in 2017 known as SOC (System and Organization Control) for Cybersecurity. These reports are intended to provide a consistent approach for evaluating and reporting on an entity's cybersecurity risk management program and give management the ability to consistently describe its cybersecurity risk management program. Additionally, the flexibility of the reports allows management to use any recognized security framework as a baseline while enabling a CPA to provide independent assurance on the effectiveness of the program's design.

    In this podcast from the Institute of Internal Audit meeting in Knoxville, LBMC Information Security's Bill Dean and Drew Hendrickson discuss SOC for Cybersecurity reports and what organizations and IT professionals should know about this new report and how it could help their organizations.

    Listen, and discover these key takeaways:

    • A brief introduction to SOC for Cybersecurity
    • Elements found within an SOC for Cybersecurity report
    • The role of CPA firms in cybersecurity
    • Differences in SOC 2 versus SOC for Cybersecurity
    • An explanation of who needs SOC for Cybersecurity
    6 min
  • 5 Reasons Why Organizations Don't Detect a Cyber Breach

    Incident response consultants are often contacted by clients who are in complete shock that their systems or networks have been compromised. Many times, these clients are hoping our analysis will ultimately prove that the incident was just a "flesh wound" to their systems and that they didn't experience an actual data breach. It's quite common for organizations to assume that data breaches won't happen to them, and consequently, they typically don't have an incident response plan.

    Not only do organizations need an incident response plan, but they also need to test it via incident response tabletop exercises. In this podcast, LBMC Information Security's Bill Dean shares five key reasons why organizations don't detect cyber breaches, as well as some helpful tips for being prepared in the event of a cyber-attack.

    Listen, and discover these key takeaways:

    • Reasons why organizations need to plan for a data breach and test the plan
    • Understanding why it's important for organizations to know where its sensitive data lives
    • The importance of enlisting the assistance of skilled information security professionals
    • The case in support of quality penetration testing
    10 min
  • 2017 Year-End Healthcare Breach Review

    In comparison to previous years, 2017 was a good year as the number of healthcare records compromised was significantly down. As of December 30, there had been 341 breaches reported, affecting a little less than 5 million individuals. This compares to 327 breach reports in 2016 but with 16.6 million individuals affected. When this information is contrasted with 2015 statistics, fewer breaches (268) were reported, however more than 113 million patients were affected.

    So, why the significant drop in affected individuals? In this podcast, LBMC Information Security's Mark Fulford offers some leading theories for these statistics, as well as a quick rundown of the top five healthcare data breaches from 2017.

    Listen, and discover these key takeaways:

    • Out of the top five healthcare data breaches, the largest one was a result of insider activity—specifically, unauthorized access through stolen media by a now-former employee, while the remaining four were all related to ransomware.
    • Health providers were responsible for most of 2017's data breach reports.
    • As compared to Payers and Business Associates, far more records were compromised at provider organizations in 2017.
    12 min
  • Law Firms are Cybersecurity Targets

    A recent report from cybersecurity firm, FireEye revealed that Chinese hackers have been actively targeting a shortlist of multinational law firms since at least June of 2017. This was an apparent effort to spy on lawyers and steal confidential information, proving that not only are law firms targets of nation states, but attackers are also keeping up with current news, using well-designed phishing campaigns that contain references to pertinent, high-profile U.S. news stories. Although law firm data breaches are not often in the news, they are happening at an alarming rate, and cybersecurity professionals need to be aware and equipped for knowing how to appropriately address such breaches.

    In this podcast, LBMC Information Security's Bill Dean highlights some specific examples of law firm data breaches and why law firms are such large targets for cyber-thieves.

    Listen, and discover these key takeaways:

    • Recent examples of law firm data breaches
    • The efforts of hackers to use U.S. news stories and scandals in hacking
    • Why law firms are cybersecurity targets
    • Reasons law firms need to be prepared for potential data breaches
    8 min
  • SOC for Cybersecurity

    Since business leaders and board members are not often technically-inclined, they tend to have many questions about cybersecurity. Because of this, the AICPA recently recognized the need for a new type of cybersecurity examination report and put together a task force to bring to life what's now known as SOC (System and Organization Control) for Cybersecurity. These reports will be beneficial in giving business leaders and board members an independent assurance and solid understanding of risk management and working with third-party cybersecurity professionals.

    In this podcast, LBMC Information Security's Mark Burnette and Drew Hendrickson discuss SOC for Cybersecurity reports and what organizations and IT professionals should know about this new report and how it could help their organizations.

    Listen, and discover these key takeaways:

    • Why SOC for Cybersecurity reports were created
    • Key elements found within an SOC for Cybersecurity report
    • Differences in SOC 2 and SOC for Cybersecurity reports
    • Ways organizations benefit from SOC for Cybersecurity reports
    • Differences in SOC for Cybersecurity and Risk Assessments
    24 min
  • Information Security Questions for SMBs

    A key observation that can be made within the information security industry today is that cybersecurity is not extremely difficult, it is just hard and requires long-term dedication, focus, and commitment. Considering this observation, a key question all cybersecurity professionals must ask is, "If you don't know where you are, how do you know where you need to improve?" Knowing the answer to this question is essential for beginning or enhancing an organization's cybersecurity program.

    In this podcast, LBMC Information Security's Bill Dean discusses some information security basics that many organizations are overlooking. Bill also walks through a series of basic questions that are good to ask when beginning or strengthening a cybersecurity program.

    Listen, and discover these key takeaways:

    • Information about getting started and improving a cybersecurity program
    • Reasons that cybersecurity is not about the latest product, but rather about people, processes, and technology
    • Why products can't help you avoid the hard work of cybersecurity basics
    11 min

About Cybersecurity Sense

From the publisher's feed

Welcome to Cybersecurity Sense, the podcast where real-world security meets practical insights. Hosted by LBMC's Mark Burnette, this show goes beyond compliance checklists to explore the fast-moving…