Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Cybersecurity's Love Affair with Distractions - Fred Wilmot - ESW #370

    Remember 20 years ago? When we were certain SIEMs would grant our cybersecurity teams superpowers? Or 10 years ago, when we were sure that NGAV would put an end to malware as we knew it? Or 15 years ago, when we were sure that application control would put an end to malware as we knew it? Or 18 years ago, when NAC would put an end to unauthorized network access?

    Why do we keep thinking that the next vendor offering is going to solve all our problems? In this interview, we talk with Fred Wilmot about the hard work of building effective processes and resilient architectures that will actually yield reductions in risk and detection/response capabilities that actually work.

    We'll discuss shifts in thinking that can move us past the latest distractions, and keep security teams focused on work that moves the needle. Fred may also mention his past transgressions against the industry and what he's doing to "wipe out the red from his ledger".

    Show Notes: https://securityweekly.com/esw-370

    37 min
  • AI Ruining the Internet, Crowdstrike Post Mortem, Wiz Walks - ESW #369

    This week, on Enterprise Security Weekly, we've got:

    1. Identity Security gets more funding
    2. Wiz walks away
    3. BlackHat Announces Startup Spotlight Finalists
    4. Crowdstrike post mortem
    5. Simple Security Tricks are the Best Security Tricks
    6. Splitting the CISO role
    7. Web scraping for AI is out of control
    8. SEC vs Solarwinds
    9. Vaping the Internet

    Show Notes: https://securityweekly.com/esw-369

    54 min
  • Can the latest wave of AI innovation deliver for security operations teams? - ESW #369

    Edward Wu thinks so! Understandably so, as his startup, Dropzone.ai is making a big bet on generative AI to change the face (and pace) of security operations.

    We'll talk about what has changed here, and I have so many questions:

    • after many generations of AI/ML technology in security, is the current gen really that dramatically different?
    • Dropzone is far from the only startup with the same idea here, how will they differentiate?
    • Is the problem that we need more help than we can possibly hire, or are we fundamentally doing something wrong in security operations?
    • Specifically, what is this tech doing to help?

    Finally, we'll wrap by talking about where this tech goes next, and can we get there with current technology, or are we dependent on more breakthroughs from companies like OpenAI, Anthropic, and Meta?

    Show Notes: https://securityweekly.com/esw-369

    34 min
  • Generative AI (as used by defenders AND attackers) will Drive SOC Evolution - Greg Notch - ESW #369

    The emergence of generative AI has caused us to rethink things on two fronts:

    1. how we consume threat detection data, as defenders
    2. how we need to shift our thinking and approaches to prepare for attackers' newfound GenAI capabilities

    But wait - is GenAI even useful for defenders or attackers? We'll dive deep into the state of AI as it pertains to security operations, just as Gartner announces that AI is hitting the trough of disillusionment. What better time to dispel the hype and focus on where real progress can be made?

    Show Notes: https://securityweekly.com/esw-369

    31 min
  • Rumored Wiz Deal Would be HISTORIC (if it happens), redefining shared responsibility - ESW #368

    In this week's enterprise security news,

    1. Google is rumored to be considering acquiring Wiz for $23 BILLION
    2. ThreatConnect acquires Polarity
    3. XBOW and Sola Security are interesting new companies we'll discuss
    4. What does "shared responsibility" actually mean?
    5. Palo Alto probably isn't going to buy your startup
    6. Snowflake-related breaches continue getting worse
    7. MUCH less AI talk than usual
    8. Defragmenting your browser

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-368

    55 min
  • What's wrong with the cybersecurity industry and what we can do about it - Richard Hollis - ESW #368

    On this segment, we're going to zoom all the way out to discuss one of my favorite topics: what's fundamentally wrong with this industry? I believe we're at an inflection point: security teams have budget, staff, and more sway at the board level than ever. The cybersecurity market is doing great - growing at an astonishing rate with cyber startups that almost never fail and funding that survives every market downturn.

    So why are failures also breaking records? What are we getting wrong? Why are we failing?

    These are the questions Richard, Katie, and I will try to answer in this segment.

    Segment Resources:

    • www.riskcrew.com/resources-2/cybersecurity-circle-of-failure/

    Show Notes: https://securityweekly.com/esw-368

    37 min
  • Book Discussion: Jump-start Your SOC Analyst Career - Jarrett Rodrick, Tyler Wall - ESW #368

    Three years after we last discussed this book on episode #221, Jarrett Rodrick returns, joined by co-author Tyler Wall to discuss an update of the book. We talk opportunities and layoffs. Career paths and experience. Degrees, certifications, and home labs. We talk about who cybersecurity is the right field for, and the pros and cons of the industry as a whole.

    We also talk myths and reality about a cybersecurity career. Can you really make $100k just a few years in? Is it really an entry level field? Are you better off entering cyber from IT or the military?

    Segment Resources:

    • Pick up the book on the publisher's website
    • Pick up the book on Amazon
    • Actual junior roles and entry level opportunities

    Show Notes: https://securityweekly.com/esw-368

    35 min
  • Rockyou2024 is a scam, Google has a whoopsie, and AI is giving folks indigestion - ESW #367

    In this week's enterprise security news,

    1. Seed rounds are getting huge
    2. Lots of funding for niche security vendors
    3. Rapid7 acquires Noetic Cyber
    4. but Rapid7 is also rumored to sell itself!
    5. Slack battles infostealers
    6. The loss of Chevron deference impacts cyber
    7. Should cybersecurity put up a no vacancy sign?
    8. Figma and Google both make some embarrassing mistakes
    9. The RockYou2024 file does NOT contain 10 billion passwords
    10. I introduce a new news category: AI indegestion

    All that and more, on this episode of Enterprise Security Weekly!

    Show Notes: https://securityweekly.com/esw-367

    59 min
  • Joiners, Movers, Leavers, and Failures: Why is Identity Management Still Struggling? - Henrique Teixeira - ESW #367

    I'm always thrilled to chat with ex-analysts, and Henrique Teixeira can cover a lot of ground with us on the topic of identity management and governance. The more I talk to folks about IAM/IGA, the more I'm shocked at how little has changed. If anything, it seems like we've gone backwards a bit, with the addition of cloud SaaS, mobile devices, and shadow IT. Identity is one of the most common entry points for attacks, so we've got to do better as an industry here.

    We'll cover a variety of topics in this interview, including:

    • Why Henrique chose to go to Saviynt from Gartner
    • Vendor risk concentration in identity
    • Resilience in identity, especially when depending on a SaaS IdP
    • Identity attack evolution (and the creation of the ITDR category)
    • What's working in identity to move things forward, and what is holding us back

    This segment is sponsored by Saviynt. Visit https://securityweekly.com/saviynt to learn more about them!

    Show Notes: https://securityweekly.com/esw-367

    34 min
  • Is GenAI Having a Rough Time? We check in to see how it's doing. - ESW #366

    We've made a slight tweak to the news format, only focusing on the most interesting funding and acquisition stories. As always, you can go check out Mike Privette's Return on Security newsletter for the full list of funded and acquired companies every week.

    This week, we discuss two $100M+ rounds, from Huntress and Semperis. We also discuss NetSPI's acquisition of Hubble, and the future of the CAASM market.

    We focus on the important of detection engineering, echoing some of Martin Roesch's thoughts from our interview with him just before the news. One story is from the excellent DFIR report, a website and newsletter you should absolutely be subscribed to if detection engineering is important to you. The other story is from Thinkst, and showcases their ability to create file share honeypots with file listings that can now be tailored to specific industries.

    We discuss the results of some polls that RSnake ran on Twitter, to get feedback from folks on what they think about these models where CISOs are reportedly getting kickbacks for buying products from companies they advise.

    We also discuss the latest whistleblower insights about Microsoft and the state of security there, and the recent Polyfill.io incident that targeted over 100k websites with malware.

    Finally, we spend the rest of the news segment discussing the current state of Generative AI, from our own perspectives, but also through the lens of Bruce Schneier's latest blog post, a year old post from Marc Andreesen, and a rage-fueled rant from an angry Aussie.

    Don't miss the squirrel story - we highly recommend sending it to all your PhD friends (or not, if they're easily insulted and/or likely to hold a grudge).

    Show Notes: https://securityweekly.com/esw-366

    1 hr 1 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…