Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Speed, Flexibility, and AI: The Case for Migrating from Legacy SOAR Systems - Whitney Young - ESW #376

    In this episode, we explore some compelling reasons for transitioning from traditional SOAR tools to next-generation SOAR platforms. Discover how workflow automation and orchestration offers unparalleled speed and flexibility, allowing organizations to stay ahead of evolving security threats. We also delve into how advancements in AI are driving this shift, making new platforms more adaptable and responsive to current market demands.

    Segment Resources:

    • Learn more about using Tines for Security
    • Peruse the Tines library of 'Stories' built by Tines partners and customers
    • Learn how to integrate AI tooling into Tines stories and workflows

    This segment is sponsored by Tines. Visit https://securityweekly.com/tines to learn more about them!

    Show Notes: https://securityweekly.com/esw-376

    34 min
  • Do phishing tests do more harm than good? - Wolfgang Goerlich - ESW #376

    A month ago, my friend Wolfgang Goerlich posted a hot take on LinkedIn that is less and less of a hot take these days.

    He posted, "our industry needs to kill the phish test",and I knew we needed to have a chat, ideally captured here on the podcast.

    I've been on the fence when it comes to phishing simulation, partly because I used to phish people as a penetration tester. It always succeeded, and always would succeed, as long as it's part of someone's job to open emails and read them. Did that make phishing simulation a Sisyphean task? Was there any value in making some of the employees more 'phishing resistant'?

    And who is in charge of these simulations? Who looks at a fake end-of-quarter bonus email and says, "yeah, that's cool, send that out."

    Segment Resources:

    • Phishing in Organizations: Findings from a Large-Scale and Long-Term Study
    • The GoDaddy Phishing Awareness Test
    • The Chicago Tribune - How a Phishing Awareness Test Went Very Wrong
    • University of California Santa Cruz - This uni thought it would be a good idea to do a phishing test with a fake Ebola scare

    Show Notes: https://securityweekly.com/esw-376

    35 min
  • Cybersecurity at the speed of Formula One - Darren Guccione, Harry Wilson - ESW #375

    Ever wondered what it's like to be responsible for the cybersecurity of a sports team? How about when that sports team is one of the world's most successful Formula One teams? I can't describe how excited we are to share this interview. This interview is basically two huge F1 nerds who happen to also be cybersecurity veterans asking everything they've always wanted to know about what it takes to secure an F1 team.

    For the folks out there that aren't familiar with this sport, Formula One is arguably the fastest, most watched, and most international automotive racing sport today. In the 2024 season, the racing series will feature ten teams traveling to 24 race tracks located in 21 different countries. Also, did you know that only two countries get more than one race? Italy gets to host two Grand Prix, and the United States gets to host three.

    A HUGE thanks to Keeper Security and Darren Guccione for making this interview possible. This isn't a sponsored interview, but it was Keeper's PR team that pitched the idea for this interview to us, and as F1 fans, we're super grateful they did!

    Segment Resources:

    • Keeper Press Release on the Partnership
    • Williams Press Release on the Partnership
    • Some more details from Keeper on why they chose to sponsor automotive racing

    Show Notes: https://securityweekly.com/esw-375

    40 min
  • Oktane 2024 and the Current State of Identity Security - Harish Peri - ESW #375

    We are a month away from Oktane -- the biggest identity event of the year. Okta is bringing thousands of identity industry thought leaders, IT and security executives, and other tech leaders together on October 15-17 to discuss the changing landscape for security and identity, how organizations are putting identity first, new Okta products, and more. Harish Peri, Senior Vice President of Product Marketing, joins Enterprise Security Weekly to discuss what people should expect from Oktane this year, the conversations that will take place at the event and why it's important for security professionals to attend/tune in.

    This segment is sponsored by Oktane. Visit https://securityweekly.com/oktane2024 and use discount code OKTNSC24 to pay only $100 for your full conference pass!

    Show Notes: https://securityweekly.com/esw-375

    42 min
  • Cybersecurity has too many distractions and can the White House fix BGP? - ESW #375

    This week, in the enterprise security news,

    1. Cribl, Zafran, and US states raise funding
    2. Cisco, Check Point, Salesforce, and Absolute Software acquire cybersecurity startups
    3. AI Security products are picking up steam
    4. You probably shouldn't be too worried about Yubikey cloning
    5. Instead, you should be more worried about malicious npm packages!
    6. The White House wants to fix BGP
    7. SolarWinds has shady stuff in its source code, AGAIN
    8. The challenge of bringing security to small business
    9. Scams are getting quicker and more effective
    10. how not to run a phishing test
    11. and AI assistants rickroll paying customers!

    Show Notes: https://securityweekly.com/esw-375

    1 hr 11 min
  • How to Make the World Quantum Safe - Vadim Lyubashevsky - ESW Vault

    Check out this episode from the ESW Vault, hand picked by main host Adrian Sanabria! This episode was initially published on April 21 2023.

    Quantum computers are scaling rapidly. Soon, they will be powerful enough to solve previously unsolvable problems. But they come with a global challenge: fully-realized quantum computers will be able to break some of the most widely-used security protocols in the world. Dr. Vadim Lyubashevsky will discuss how quantum-safe cryptography protects against this potential future.

    Segment Resources:

    IBM Quantum Safe: https://www.ibm.com/quantum/quantum-safe IBM scientists help develop NIST's quantum-safe standards: https://research.ibm.com/blog/nist-quantum-safe-protocols Government and industry experts recommend moving to quantum-safe cryptography: https://research.ibm.com/blog/economist-quantum-safe-replay

    Show Notes: https://securityweekly.com/vault-esw-16

    47 min
  • SaaS Security Beyond Just Misconfiguration & Expert Insights on Cybersecurity Ethics - Ed Skoudis, Maor Bin - ESW #374

    In this interview, Maor Bin, CEO and Co-Founder of Adaptive Shield, discusses the evolving landscape of SaaS Security. He highlights the challenges posed by the security gap resulting from the rapid adoption of SaaS applications and why SaaS security is beyond just misconfiguration management.

    Segment Resources: https://www.adaptive-shield.com/landing-page/the-annual-saas-security-survey-report-2025-ciso-plans-and-priorities/

    This segment is sponsored by Adaptive Shield. Visit https://securityweekly.com/adaptiveshieldbh to download the Annual SaaS Security Survey Report!

    Cybersecurity professionals are often confronted with ethical dilemmas that need to be carefully navigated. In 25 years of teaching incident handling and penetration testing, Ed has often been asked by his students for help in ethical decision-making. Ed will share some of their questions and his recommended approaches for addressing them. Ed also has a new book out, The Code of Honor, about cybersecurity ethics. All proceeds go to scholarships for college students.

    Segment Resources: 1) Ed's book, published June 18, 2024: https://www.amazon.com/Code-Honor-Embracing-Ethics-Cybersecurity/dp/1394275862/ref=sr11?crid=1DSHPCXDIQ1VT&dib=eyJ2IjoiMSJ9.rmZX2-3mj1nI74iKkjbKkQSNKCuRjjn-QQ8qrzVy21tMRAXuKu5Qr5rPgtszkVd7zJMV7oVTuImUZIxMQfecnaRlNRfAVI5G7azyWi8lY.WHOujvlsQXPTJaHuEafwRC2WVKZe474eVXHn46kLiEY&dib_tag=se&keywords=skoudis&qid=1722767581&sprefix=skoudis%2Caps%2C90&sr=8-1

    2) Holiday Hack Challenge - sans.org/holidayhack

    Show Notes: https://securityweekly.com/esw-374

    33 min
  • Interview with ThreatLocker: Is Application Allowlisting Making a Comeback? - Danny Jenkins - ESW #374

    I often say that it isn't the concepts or ideas in cybersecurity that are bad, but the implementations of them. Sometimes the market timing is just wrong and the industry isn't ready for a particular technology (e.g. enterprise browsers). Other times, the technology just isn't ready yet (e.g. SIEMs needed better database technology and faster storage). Since the ideas are solid, we see these concepts return after a few years.

    Application allowlisting is one of these product categories. Threatlocker has been around since 2017 and is now a late stage startup that has achieved market fit. We chat with the company's CEO and founder, Danny Jenkins to find out how they learned from the mistakes made before them, and differentiate from the technology some of us remember from the late 2000s and early 2010s.

    Segment Resources:

    • Threat Locker Solutions

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Show Notes: https://securityweekly.com/esw-374

    34 min
  • What asset management (ITAM) looks like outside cybersecurity - Jeremy Boerger - ESW #374

    The top priority on the CIS Critical Security Controls list has never changed: inventory and control of enterprise assets. Yet it remains one of the most challenging controls to implement, much less master. The refrain, "you can't secure what you don't know about" is as old as information security itself.

    Complicating this task is the fact that improving asset management isn't an aspiration unique to the security team. IT, finance, facilities, and other groups within large enterprises are concerned with this as well. This often leads to challenges: should all these groups attempt to standardize on one common asset database or CMDB? Or should security go their own way, and purchase their own asset management tool?

    Answering these questions would be a lot easier if we had someone with an IT asset management (ITAM) perspective, and fortunately, we do! Jeremy Boerger of Boerger Consulting joins us to help us understand the IT perspective, so we can understand if there are opportunities for security and IT to help each other out, or at least find some common ground!

    Boerger Consulting Resources:

    • Email newsletter
    • LinkedIn newsletter
    • Book page
    • Amazon book page

    Show Notes: https://securityweekly.com/esw-374

    38 min
  • Let's Get Real About Where AI can Help SecOps & AI, Automation & Low-Code - Mike Lyborg, Brandon Potter - ESW #373
    Swimlane and GenAI

    Join Swimlane CISO, Mike Lyborg and Security Weekly's Mandy Logan as they cut through the AI peanut butter! While Generative AI is the not-so-new hot topic, it's also not the first time the cybersecurity industry has embraced emerging technology that can mimic human actions. Security automation and its ability to take action on behalf of humans have paved the way for generative AI to be trusted (within reason). The convergence and maturity of these technologies now have the potential to revolutionize how SecOps functions while force-multiplying SOC teams.

    This segment is sponsored by Swimlane. Visit https://securityweekly.com/swimlanebh to learn more about them!

    Swimlane and ProCircular

    ProCircular, is a security automaton power-user and AI early adopter. Hear from Swimlane customer, Brandon Potter, CTO at ProCircular, about how use of Swimlane, has helped his organization increase efficiency, improve security metrics and ultimately grow their customer base without increasing headcount.

    Segment Resources:

    • ProCircular Case Study
    • ProCircular Web Site

    This segment is sponsored by Swimlane. Visit https://securityweekly.com/swimlanebh to learn more about them!

    Show Notes: https://securityweekly.com/esw-373

    33 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…