Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • The end of the road for some cyber startups & making detection actually work! - ESW #373

    This week, in the enterprise security news,

    1. A funding that looks like an acquisition
    2. And two for-sure acquisitions
    3. Rumors that there are funding problems for early stage cyber startups, and we'll see a lot more acquisitions before the end of the year
    4. Speaking of rumors, Crowdstrike did NOT like last week's Action1 acquisition rumor!
    5. Shortening detection engineering feedback loops
    6. HoneyAgents
    7. More reflections on Black Hat 2024
    8. The attacker does NOT just have to get it right once
    9. and the defender does NOT have to get it right every time
    10. Remember BEC scams? Yeah, they're still enterprise enemy #1

    All that and more, in the news this week on Enterprise Security Weekly!

    Show Notes: https://securityweekly.com/esw-373

    1 hr 18 min
  • Secure Web Gateways Have Failed Us & Using AI to Prevent the Next CrowdStrike Outage - Vivek Ramachandran, Vivek Bhandari - ESW #373
    SquareX

    With employees spending most of their working hours on the browser, web attacks are one of the biggest attack vectors today. Yet, both enterprises and security vendors today aren't focused on securing the browser – a huge risk given that attackers can easily bypass Secure Web Gateways, SASE and SSE solutions.

    This segment will demonstrate the importance of a browser-native solution, discuss the limitations of current solutions and how enterprises can better protect their employees from web attacks.

    Segment Resources:

    • DEF CON talk abstract
    • Enterprise use cases for SquareX
    • Data Sheet
    • Why Browser Native Solutions are better than Cloud Based Proxies
    • Blog on the Many Failures of Secure Web Gateways

    This segment is sponsored by Square X. Visit https://securityweekly.com/squarexbh to learn how SquareX can protect your employees from web attacks!

    Tanium

    The recent CrowdStrike outage and subsequent disruption tested organizations' resiliency and confidence as the world went offline. It served as a reminder that in an increasingly technology-dependent world, things will go wrong – but security leaders can plan accordingly and leverage emerging technologies to help minimize the damage.

    In this interview, Tanium's Vice President of Product Marketing Vivek Bhandari explains how AI and automation can help with remediation and even prevent similar outages from happening in the future, and breaks down the future of Autonomous Endpoint Management (AEM) as the solution for continuous cyber resilience in the face of disruption.

    Segment Resources:

    • The Future of Converged Endpoint Management is Autonomous Endpoint Management (AEM)

    This segment is sponsored by Tanium. Visit https://securityweekly.com/taniumbh to learn more about them!

    Show Notes: https://securityweekly.com/esw-373

    37 min
  • Operational Resilience in Healthcare & Zscaler Uncovers Record-Breaking Ransom - Marty Momdjian, Brett Stone-Gross - ESW #372

    Many cybersecurity experts are calling recent attacks on healthcare more sophisticated than ever. One attack disrupted prescription drug orders for over a third of the U.S. and has cost $1.5 billion in incident response and recovery services. Separately, an operator of over 140 hospitals and senior care facilities in the U.S. was also victimized. These attacks are becoming all too common. Disruptions can lead to life-and-death situations with massive impacts on patient care. All industries, especially healthcare, have to better prepare for ransomware attacks. Are you ready to turn the tables on threat actors? Marty Momdjian, Semperis EVP and General Manager provides advice on how hospitals can regain the upper hand.

    This segment is sponsored by Semperis. Visit https://securityweekly.com/semperisbh to learn more about them!

    The annual report details the latest ransomware attack trends and targets, ransomware families, and effective defense strategies. Findings in the report uncovered an 18% overall increase in ransomware attacks year-over-year, as well as a record-breaking ransom payment of US$75 million – nearly double the highest publicly known ransomware payout – to the Dark Angels ransomware group.

    Segment Resources: For a deeper dive into best practices for protecting your organization and the full findings, download the Zscaler ThreatLabz 2024 Ransomware Report Link below - https://zscaler.com/campaign/threatlabz-ransomware-report

    This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them!

    Show Notes: https://securityweekly.com/esw-372

    33 min
  • Devo Launches New Capabilities & Revolutionizing Cyber Resilience - Rakesh Nair, Rekha Shenoy - ESW #372

    Devo, the security analytics company, recently launched data orchestration, a data analytics cloud, and security operations center (SOC) workflow enhancements. Enterprise security teams are struggling with growing data volumes—and they're also up against headcount and budget constraints. These solutions offer security teams data control, cost optimizations, and efficient automation for better security outcomes.

    Segment Resources: https://www.devo.com/defend-everything/

    This segment is sponsored by Devo. Visit https://securityweekly.com/devobh to learn more about how Devo's new solutions can streamline your security operations.

    As security monitoring has gotten more mature over the years, remediating security vulnerabilities is still stuck in the dark ages requiring mountains of CVE reports and thousands of manual tasks to be done by network engineers at the wee hours of the nights and weekends. Cyber resilience requires a more continuous approach to remediation, one that does not depend on manual work but also one that can be trusted not to cause outages.

    This segment is sponsored by BackBox. Visit https://securityweekly.com/backboxbh to learn more about them!

    Show Notes: https://securityweekly.com/esw-372

    32 min
  • Highlights from BlackHat/DefCon, Vulnerabilities, and Cyber Marketing Challenges - ESW #372

    In this conversation, the hosts discuss patchless patching, vulnerabilities in the Windows TCP/IP stack, and the trustworthiness of Microsoft. They highlight the challenges of marketing in the cybersecurity industry and the importance of building trust with customers. The conversation also touches on the need for vendors to prioritize security and code quality over rushing products to market. Overall, the hosts express concerns about the frequency of security vulnerabilities and the potential impact on customer trust. Other topics of discussion include the Innovators and Investors Summit at Black Hat, the potential sale of Trend Micro, layoffs in the industry, and the controversy surrounding room searches at DEF CON. They also touch on the concept of time on the moon and its implications for future lunar missions.

    Show Notes: https://securityweekly.com/esw-372

    1 hr 6 min
  • More AI funding, Crowdstrike ripples continue, GPT yourself - ESW #371

    , in the enterprise security news,

    1. AI is still getting a ton of funding!
    2. Netwrix acquires PingCastle
    3. Tenable looks for a buyer
    4. SentinelOne hires Alex Stamos as their new CISO
    5. Crowdstrike doesn't appreciate satire when it's at their expense
    6. Intel begins one of the biggest layoffs we've ever seen in tech
    7. Windows Downdate
    8. RAG poisoning
    9. GPT yourself
    10. The Xerox Hypothesis

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-371

    1 hr 3 min
  • Interviewing Black Hat Startup Spotlight Winner, Knostic - Sounil Yu - ESW #371

    We chat with Sounil Yu, co-founder of LLM access control startup, Knostic. We discuss both the experience of participating in Black Hat's startup competition, and what his company, Knostic, is all about. Knostic was one of four finalists for Black Hat's Startup Spotlight competition and was announced as the winner on August 6th.

    References

    • DarkReading: Knostic Wins 2024 Black Hat Startup Spotlight Competition
    • Knostic's Website

    Show Notes: https://securityweekly.com/esw-371

    35 min
  • AI Red Teaming and AI Safety - Amanda Minnich - ESW #371

    In this interview we explore the new and sometimes strange world of redteaming AI. I have SO many questions, like what is AI safety?

    We'll discuss her presence at Black Hat, where she delivered two days of training and participated on an AI safety panel.

    We'll also discuss the process of pentesting an AI. Will pentesters just have giant cheatsheets or text files full of adversarial prompts? How can we automate this? Will an AI generate adversarial prompts you can use against another AI? And finally, what do we do with the results?

    Resources:

    • PyRIT AI redteaming tool
    • Microsoft's AI redteaming guide

    Show Notes: https://securityweekly.com/esw-371

    42 min
  • Funding, Cato, Code42, DoS Robots, and Blackhat Prep - ESW #370

    This week, in the enterprise security news,

    1. over half a billion in funding, as everyone gets their pre-Blackhat announcements out!
    2. Mimecast picks up Code42
    3. Will Cato Networks IPO?
    4. Canarytokens update
    5. We still have some crowdstrike fallout to discuss
    6. CISO responses to SEC rules
    7. Making things secure without security tools
    8. tips for going SOCLess
    9. denial of service robots

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-370

    52 min
  • 10 Security Researcher Qualities Marketers Should Adopt - Dani Woolf - ESW #370

    There's plenty of content out there detailing how vendors fall short:

    • scummy, aggressive sales tactics
    • overuse of jargon and buzzwords
    • sneaky sales tactics
    • dumping on competitors
    • products that fall far short of claims
    • ambulance chasing

    So what should they doing? In this episode, we chat with Dani Wolff, about how marketers can adopt the skills and mindsets of security researchers to improve GTM strategies, without resorting to awful tactics. Drawing from extensive experience in qualitative interviews and collaborations with enterprise security executives and researchers, Dani will uncover how the innate curiosity and analytical prowess of researchers can dismantle unhealthy habits within vendor organizations.

    We'll also discuss Dani's various projects, including the WTF Did I Just Read podcast, CyberNest, and CyberSynapse. Dani will explain how these are all designed to address the gap between vendors and buyers in the cybersecurity industry.

    Show Notes: https://securityweekly.com/esw-370

    51 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…