Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Alice and Bob Learn Secure Coding - Tanya Janca - ESW #396

    We get a visit from Tanya Janca to discuss her latest book, Alice and Bob Learn Secure Coding!

    Segment Resources:

    • Tanya's latest book on Amazon
    • Tanya's previous book, Alice and Bob Learn Application Security on Amazon
    • Tanya's website, She Hacks Purple

    Show Notes: https://securityweekly.com/esw-396

    35 min
  • First Do No Harm - Security Challenges in Healthcare - Ed Gaudet - ESW #396

    In 2011, Marc Andreessen predicted that software would eat the world. Specifically, the prediction was that software companies would take over the economy and disrupt all industries. The economic prediction has mostly come true, with 9 out of 10 of the most highly valued companies being tech companies. The industry disruption didn't materialize in some cases, and outright failed in others.

    Healthcare seems to be one of these 'disruption-resistant' areas. Ed joins us today to discuss why that might be, and what the paths towards securing the healthcare industry might look like.

    Segment Resources: Ed's podcast, Risk Never Sleeps

    Show Notes: https://securityweekly.com/esw-396

    23 min
  • AI Security Concerns: Real Threats or Distractions? Also - unhinged security teams! - ESW #395

    In the enterprise security news,

    1. Change Healthcare's HIPAA fine is vanishingly small
    2. How worried should we be about the threat of AI models?
    3. What about the threat of DeepSeek?
    4. And the threat of employees entering sensitive data into GenAI prompts?
    5. The myth of trillion-dollar cybercrime losses are alive and well!
    6. Kagi Privacy Pass gives you the best of both worlds: high quality web searches AND privacy/anonymity
    7. Thanks to the UK for letting everyone know about end-to-end encryption for iCloud!
    8. What is the most UNHINGED thing you've ever seen a security team push on employees?

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-395

    56 min
  • Is Shift Left Just Starting to Catch On? And Other AppSec Trends & Insights - Jenn Gile - ESW #395

    'Shift Left' feels like a cliché at this point, but it's often difficult to track tech and security movements if you aren't interacting with practitioners on a regular basis. Some areas of tech have a longer tail when it comes to late adopters and laggards, and application security appears to be one of these areas. In this interview, Jenn Gile catches us up on AppSec trends.

    Segment Resources:

    • Microsoft Defender for Cloud Natively Integrates with Endor Labs
    • 2024 Dependency Management Report
    • How to pick the right SAST tool

    Show Notes: https://securityweekly.com/esw-395

    32 min
  • The Future of Cyber Regulation in the New Administration - Ilona Cohen - ESW #395

    In this interview, we're excited to have Ilona Cohen to help us understand what changes this new US administration might bring, in terms of cybersecurity regulation. Ilona's insights come partially from her own experiences working from within the White House. Before she was the Chief Legal Officer of HackerOne, she was a senior lawyer to President Obama and served as General Counsel of the White House Office of Management and Budget (OMB).

    In this hyper-partisan environment, it's easy to get hung up on particular events. Do many of us lack cross-administration historical perspective? Probably. Should we be outraged by the disillusion of the CSRB, or was this a fairly ordinary occurrence when a new administration comes in? These are the kinds of questions I'll be posing to Ilona in this conversation.

    • How the Change Healthcare breach can prompt real cybersecurity change

    Show Notes: https://securityweekly.com/esw-395

    33 min
  • The dark side of security leadership, will agentic be a thing, OWASP AI resources - ESW #394

    In this week's enterprise security news, we've got

    1. 5 acquisitions
    2. Tines gets funding
    3. new tools and DFIR reports to check out
    4. A legal precedent that could hurt AI companies
    5. AI garbage is in your code repos
    6. the dark side of security leadership
    7. HIPAA fines are broken
    8. Salt Typhoon is having a great time
    9. Don't use ChatGPT for legal advice!!!!!

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-394

    52 min
  • A SecOps Medley: we talk automation, AI, data management, and EDR evaluations - Allie Mellen - ESW #394

    We couldn't decide what to talk to Allie about, so we're going with a bit of everything. Don't worry - it's all related and ties together nicely.

    • First, we'll discuss AI and automation in the SOC - Allie is covering this trend closely, and we want to know if she's seeing any results yet here.
    • Next, we'll discover SecOps data management - the blood that delivers oxygen to the SOC muscles.
    • Finally, we'll discuss MITRE's recent EDR evaluations - there was some contention around some vendors claiming to ace the test and we're going to get the tea on what's really going on here!

    For each of these three topics, these are the blog posts they correspond with if you want to learn more:

    1. Generative AI Will Not Fulfill Your Autonomous SOC Hopes (Or Even Your Demo Dreams)
    2. If You're Not Using Data Pipeline Management For Security And IT, You Need To
    3. Go Beyond The MITRE ATT&CK Evaluation To The True Cost Of Alert Volumes

    Show Notes: https://securityweekly.com/esw-394

    33 min
  • Evolving the SOC: Automating Manual Work while Maintaining Quality at Scale - Tim MalcomVetter - ESW #394

    We've got a few compelling topics to discuss within SecOps today. First, Tim insists it's possible to automate a large amount of SecOps work, without the use of generative AI. Not only that, but he intends to back it up by tracking the quality of this automated work with an ISO standard unknown to cybersecurity.

    I've often found useful lessons and wisdom outside security, so I get excited when someone borrows from another, more mature industry to help solve problems in cyber. In this case, we'll be talking about Acceptable Quality Limits (AQL), an ISO standard quality assurance framework that's never been used in cyber.

    Segment Resources:

    • Introducing AQL for cyber.
    • AQL - How we do it
    • An AQL 'calculator' you can play around with

    Show Notes: https://securityweekly.com/esw-394

    32 min
  • Breach details need to be transparent and kids need cybersecurity education - ESW #393

    This week, in the enterprise security news,

    1. Semgrep raises a lotta money
    2. CYE acquires Solvo
    3. Sophos completes the Secureworks acquisition
    4. SailPoint prepares for IPO
    5. Summarizing the 2024 cybersecurity market
    6. Lawyers that specialize in keeping breach details secret
    7. Scientists torture AI
    8. Make sure to offboard your S3 buckets
    9. extinguish fires with bass

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-393

    49 min
  • Inside look and lessons from a Recent APT Attack on a U.S. Aerospace Company - John Dwyer - ESW #393

    Listeners of the show are probably aware (possibly painfully aware) that I spend a lot of time analyzing breaches to understand how failures occurred. Every breach story contains lessons organizations can learn from to avoid suffering the same fate. A few details make today's breach story particularly interesting:

    • It was a Chinese APT
    • Maybe the B or C team? They seemed to be having a hard time
    • Their target was a blind spot for both the defender AND the attacker

    Segment Resources:

    • https://www.binarydefense.com/resources/blog/shining-a-light-in-the-dark-how-binary-defense-uncovered-an-apt-lurking-in-shadows-of-it/
    • https://www.theregister.com/2024/09/18/chinesespiesfoundonushqfirm_network/

    Show Notes: https://securityweekly.com/esw-393

    32 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…