Great Security Debate

Great Security Debate

By The Great Security DebateSociety & CultureBusinessTechnology
Download on the App Store

Great Security Debate episodes

  • Program Your Program

    This week on The Great Security Debate we have arrived at one of our favourite episodes of the year (and what is and will be an annual thing!) when Forrester Senior Analyst, Jess Burn, returns to the show to share this years recommendations for security programs.

    An overarching theme of the report is to use the captital that the CISO has acquired over the past few years and build out your program to where it needs to be. AKA, “strike while the iron is hot”

    More detailed topics including:



    • Career paths and changes in comp methodology for security teams need to change


    • Security Awareness needs adjustment for work for anywhere


    • Minimum viable security - it’s definitely not just “barely secure”


    And a reminder that Dan, Brian and Erik will be doing a live episode of the podcast at the upcoming Michigan Women in Technology ExecutiveManagement Conference on May 5 in Novi, Michigan. Tickets for the whole conference are now available (https://MCWT.org) and the agenda for the day is great. See you there


    If you want to listen to Jess’s previous episode, check out Episode 20, “It All Comes Down To Relaltionships.” https://www.greatsecuritydebate.net/20


    You can find Jess on LinkedIn (https://www.linkedin.com/in/jessburn), Twitter (https://twitter.com/jess_burn_) and at the Forrester blog (https://go.forrester.com/blogs/author/jess_burn/).


    Thanks for joining us, Jess! And thanks to you for listening and watching.

    Special Guest: Jessica Burn.

    Support The Great Security Debate

    Links:

    • Forrester's 2022 Top Recommendations For Your Security Program
    • The Return Of The Forrester Wave™: Cybersecurity Incident Response Services
    • Starlink fought off Russian jamming attack faster than the military could

    1 hr 3 min
  • Laws and Regs

    The Great Security Debate rolls on, this week looking at how governments, regulations and business values are and will shape the security posture of enterprises.


    • Is attribution worth pursuing to the end?


    • How can state and federal law enforcement help figure out who and what happened after an incident?


    • Fast (agile) vs good (quality) vs cheap (cost)


    • Are you chasing the right metrics in your organisation? Do they encourage the right behaviour?


    • Is regulation required to make good security a greater market force?


    • What will the regulations emerging in the US focus on? The “what”, the “why”, the “how”, or the “who”? How will they change when and how companies report material breaches?


    • How does attribution of attack correlate to insurance coverage? How do IR firms fit into the equation?


    Erik, Dan and Brian also announce that the podcast is going LIVE and On the road. On May 5, Great Security Debate will be recording a live episode at the MCWT Executive Connection Summit in Novi, Michigan! More info and registration details are at https://mcwt.wildapricot.org/event-4630370. Ticket sales begin on 18 April 2022.

    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.


    Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links.


    Thanks for listening!

    Support The Great Security Debate

    Links:

    • Homepage | CISA
    • SEC.gov | SEC Proposes Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies
    • Senate passes cybersecurity bill amid fears of Russian cyberattacks | The Hill
    • Cutting Edge Cybersecurity Event Experience - FutureCon Events
    • Court denies SolarWinds bid to throw out breach lawsuit
    • About the Data Management & Sharing Policies | Data Sharing
    • MCWT Foundation - Executive Connection Summit
    • Forrester's 2022 Top Recommendations For Your Security Program
    • Buffalo Wild Wings Partners With MGM, Will Encourage Sports Betting in Restaurants | The Action Network
    • Data Management and Sharing Policy | Data Sharing
    • The Great Security Debate Episode 20: It All Comes Down to Relationships (Guest Debater: Jessica Burn)

    46 min
  • Squality!

    Recently, Brian, Dan and Erik had the great fortune to do a live version of the podcast at the monthly meeting of the SIM Detroit Chapter (https://chapter.simnet.org/detroit/home). At the close of that discussion, the comment was raised as to whether or not security should be used as a competitive advantage by businesses. The topic seemed perfect for The Great Security Debate, so here we are. In this episode, we cover:


    • Can security be used as a business differentiator?


    • SHOULD security be used as a business differentiator?


    • If security is added too deeply into the sales cycle does it incentivise the wrong behaviours just to make a sale?


    • How can we quantify the value of security in the purchasing process when it is not easily attributable to direct cost saving or value?


    • How do closed systems compare to open systems with regard to security?


    • How does the rise of customer trust as a key organisational focus indicate the use of security as a business differentiator?


    • Do the fears that using security as a differentiator means that the collaborative nature and history of security will disappear?


    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links.


    Thanks for listening!

    Support The Great Security Debate

    Links:

    • SEC Proposes Cybersecurity Rules for Public Companies
    • TISAX: Information security for the automotive industry | TÜV SÜD
    • Failure mode and effects analysis - Wikipedia
    • Bridgestone Americas confirms ransomware attack, LockBit leaks data
    • Quantitative Information Risk Management | The FAIR Institute
    • Dawn of the Code War: America's Battle Against Russia, China, and the Rising Global Cyber Threat: Carlin, John P.: 9781541773837: Amazon.com: Books
    • Saudi Aramco facing $50 million cyber extortion over leaked data
    • Leaked Conti files reveal life inside ransomware gang • The Register
    • KOJIMA INDUSTRIES CORPORATION Company Profile | TOYOTA, AICHI, Japan | Competitors, Financials & Contacts - Dun & Bradstreet
    • Higher Education Community Vendor Assessment Toolkit | EDUCAUSE
    • Home Page – CORL Technologies
    • Home – Cyturus
    • Financial Services Information Sharing and Analysis Center
    • Auto-ISAC Summit 2021 – Auto-ISAC
    • The SSO Wall of Shame | A list of vendors that treat single sign-on as a luxury feature, not a core security requirement.
    • The Great Security Debate

    1 hr 6 min
  • How Do You Sleep At Night?

    Current global events have led to increased focus on technology security. In this week's episode we debate to what extent this does or will confirm the rise of the information security roles within organisations. Our thoughts and good wishes go out to the people of Ukraine.


    • Do current events confirm that the rise of the CISO organisation was warranted?


    • How do CISOs sleep at night considering everything going on?


    • How to reply to the question “what else should we be doing?”


    • Are the attacks the primary objective or are they a smokescreen?


    • How does the game of chess tie into to information security practises?


    • What is the CISOs role in reducing FUD (fear, uncertainty, doubt)?


    • Will current information it pay for acts of war? Does it raise our collective stature?


    • Why is humility so important in the information security world?


    The underlying message is that while it is late in the process now to do all the steps to protect your organisation, it’s never too late to get started!

    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.


    Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links.


    Thanks for listening!

    Support The Great Security Debate

    Links:

    • HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine - SentinelOne
    • The Untold Story of NotPetya, the Most Devastating Cyberattack in History | WIRED
    • Amazon.com: Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers eBook : Greenberg, Andy: Kindle Store
    • Elon Musk says SpaceX's internet service is available in Ukraine
    • Destructive Malware Targeting Organizations in Ukraine | CISA
    • Morris worm - Wikipedia
    • Amazon.com: Dawn of the Code War: America's Battle Against Russia, China, and the Rising Global Cyber Threat eBook : Carlin, John P., Graff, Garrett M.: Kindle Store
    • Moonlight Maze - Wikipedia
    • New Shadow Brokers 0-day subscription forces high-risk gamble on whitehats | Ars Technica
    • An NSA-derived ransomware worm is shutting down computers worldwide | Ars Technica
    • FIRST - Improving Security Together
    • Conti ransomware group announces support for Russian invasion of Ukraine, threatens retaliation
    • Maersk says global IT breakdown caused by cyber attack | Reuters
    • GitHub - Netflix/chaosmonkey: Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures.

    1 hr 5 min
  • Security Super Agent

    This week’s episode was sparked by a recent TechCrunch article https://techcrunch.com/2022/02/01/free-agent-series-a/ asking whether tech workers should have agents to negotiate their salaries. We took up the debate on this and a few adjacent topics including:


    • The Great Resignation’s impact on working habits


    • Should security practitioners and leaders be represented by “agents” to negotiate better compensation for roles?


    • What are the ways that formal agents exacerbate bias and increase the gaps between levels?


    • The importance of networks for getting advice to help you be your own “agent”


    • Is it the Great Resignation or the Great Realisation?


    • How do ethics and values play into staff’s desire to go to or stay at a company?


    • At different levels in one’s career who can help be your agent of change?
We should not be afraid to talk about our salaries and numbers


    And yes, those are Pączki on Brian’s hat. If you are not sure what this about, take a look at the video version on our YouTube channel https://www.youtube.com/watch?v=CAYRL1flZic

    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.


    Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links.


    Thanks for listening!

    Support The Great Security Debate

    Links:

    • TechCrunch
    • Who Is Driving the Great Resignation?
    • The Great Resignation looks more like The Great Renegotiation : Planet Money : NPR
    • Business Roundtable Redefines the Purpose of a Corporation to Promote ‘An Economy That Serves All Americans’ | Business Roundtable
    • The Infinite Game: Sinek, Simon: 9780735213500: Amazon.com: Books
    • Scott Boras
    • How to Negotiate the Tech Salary You Deserve – The New Stack
    • Amazon.com: Lego Movie 70819 Bad Cop Car Chase : Toys & Games
    • Amazon.com: Kitchen Confidential: Adventures in the Culinary Underbelly eBook : Bourdain, Anthony: Kindle Store
    • MentorCore – Growth and Development at your Fingertips
    • Home | CSA
    • Google to work with Ford on Detroit research hub - ABC News
    • Fun Fact | Undeniably Dairy - YouTube

    1 hr 3 min
  • From the Inside Out

    We got a message from a listener asking for some discussion about putting the data first and securing it with that mind - the inside out, rather than looking at the perimeter and infrastructure and working back toward the data - outside in.

    And since we love our listeners and your feedback, we took the chance to cover this topic in depth. In the process we also covered:


    • Data Loss Prevention - Is it possible to improve this without the painful data classification, startup work or culture change?


    • When doing data analysis for attacks (or fraud) you have to account for the fraud already baked in the normal you know today


    • We can’t meaningfully count on IP address for geography…thanks to security asking for more use of VPNs


    • The pros and cons and risks to ponder when securing data in on premise vs. cloud/SaaS arrangements


    • When is the right time to establish a security team in a growing company? And how bad will the data sprawl be when they arrive?


    • Will the CTO/CIO and the CISO merge into a single role? Will the CIO report to the CISO eventually? It depends, of course, on the people and the organisation


    • Controls today may not be the controls we need for tomorrow


    • We try to secure things, but there’s also important value in good use of data to improve a business


    • Sunk cost fallacy and Security: when to burn it all down and start over


    • Audit is the best friend of the CISO: a new set of eyes and accountability partner makes all the difference


    Dan also goes on a small tirade over the way security professionals use the term “the business” as something distinct from the security team that is absolutely part of the business itself. Enjoy that soapbox moment.


    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.


    Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links.


    Thanks for listening!

    Support The Great Security Debate

    Links:

    • The Security of Cloud Services and SaaS in 2021 – Part 1 – Secratic
    • The Great Security Debate Episode 33: Log4Jelly of the Month Club
    • The Future Of The CISO — Six Types Of Security Leaders
    • Amazon.com: Rocket Fuel: The One Essential Combination That Will Get You More of What You Want from Your Business: 9781942952312: Wickman, Gino, Winters, Mark C.: Books
    • The Sunk Cost Fallacy - The Decision Lab
    • Amazon.com: The Infinite Game eBook : Sinek, Simon: Kindle Store
    • The Innovator's Dilemma: The Revolutionary Book That Will Change the Way You Do Business: Christensen, Clayton M.: 8601300047348: Amazon.com: Books
    • How Emotionally Intelligent People Use the 'Emergency Exit Rule' to Win Almost Every Argument
    • Why CIOs Should Report to CISOs

    1 hr 6 min
  • Log4Jelly of the Month Club

    Some say that Log4J is the gift that keeps on giving, much like the Jelly of the Month Club. After the initial surge of discussion a couple weeks ago there were mitigations, a vaccine and multiple iterations of official patches to keep the issue at bay and the new ones that cropped up afterwards. Brian, Dan and Erik discuss the log4j vulnerability as it relates to enterprise systems, supportability, balancing the risk of patching and the ways that open-source software are used within the enterprise.

    Join us this week as we cover:


    • The Log4J vulnerability and saga in a nutshell


    • The pros and cons of waiting to patch until there's a stable one vs. patching again with each iteration and risk my system's stability


    • The critical need for system and application (and library) inventory and keeping up to date


    • How best to react when the media and public discussion picks up on a vulnerability and causes a stir


    • The challenges in the flurry of email and surveys from and to SaaS and service providers about their state on the vulnerability of the day


    • What is the cost of "free" when it comes to running (and maintaining) open source software like Log4j


    • How to make sure procurement departments are not just involved but include the risks of procurement decisions into the process


    • Are the external capability assessments like SOC2 able to move beyond perfunctory review by those asking for them


    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Support The Great Security Debate

    Links:

    • UPDATED: Cybereason Log4Shell Vaccine Offers Permanent Mitigation Option for Log4j Vulnerabilities (CVE-2021-44228 and CVE-2021-45046)
    • log4j-affected-db/SOFTWARE-LIST.md at develop · cisagov/log4j-affected-db · GitHub
    • A Log4J Vulnerability Has Set the Internet 'On Fire' | WIRED
    • Alibaba Employee First Spotted Log4j Software Flaw but Now the Company Is in Hot Water With Beijing - WSJ
    • Meltdown and Spectre
    • Hackers launch over 840,000 attacks through Log4J flaw | Ars Technica
    • 5 Whys: The Ultimate Root Cause Analysis Tool
    • NSO Group spyware used to hack at least nine US officials’ phones – report | Surveillance | The Guardian
    • The internet runs on free open-source software. Who pays to fix it? | MIT Technology Review
    • Perfunctory Definition & Meaning - Merriam-Webster

    1 hr 4 min
  • Sweet or Suite?

    It's a sports analogy-filled episode of The Great Security Debate, but don't let that scare you away. This week, we cover a whole host of topics, primarily focused on the ideas of simple vs. complex and best-of-breed vs. tightly integrated when dealing with technology, change, process or securing your environment.


    • Pace of change in security is ridiculous right now


    • How does reducing complexity and technical debt improve security and technology?


    • (Said differently: simplicity is the heart of good security)


    • Tech is nothing without process or people (see Episode 29 - People Process and Product)


    • Can security vendors be everything to everyone? In what environments do "suites" give better security balance than "best of breed"?


    • What are the risks and benefits of a set of suite technologies vs. best of breed?


    • How does securing your organisation parallel with American Football?


    • What's changing in how we buy technology (and security technology)? Shorter contracts, even if it means less "savings"?


    • Should we invest in security technology heavily up front to win one battle at all costs, or plan for the long-term war?


    Note that all American Football references were to games that had not yet been played at the time of recording. Congratulations, University of Michigan Wolverines on winning the Big Ten championship later that evening.

    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Support The Great Security Debate

    Links:

    • The Great Security Debate Episode 29: People, Process and Product
    • The Innovator's Dilemma: The Revolutionary Book That Will Change the Way You Do Business: Christensen, Clayton M.: 8601300047348: Amazon.com: Books
    • A rising tide lifts all boats - Wikipedia
    • Progressive Insurance Commercial - How Not To Become Your Parents
    • Agent Scott Boras Rips MLB System Following Braves World Series Win | The Daily Wire
    • What Got You Here Won't Get You There: How Successful People Become Even More Successful: Goldsmith, Marshall, Reiter, Mark, Goldsmith, Marshall: 9780739342237: Amazon.com: Books

    56 min
  • The Infinite Game

    In security (and elsewhere) the long game is often overlooked in lieu of short-term advances and accomplishments. From building security into the culture of an organisation to setting goals and objectives for leaders and staff, being strategic in your security approach is critical.

    In this episode we cover:


    • How to balance an organisation's drive to shareholder value over the short term with the need to invest strategically in security, privacy and compliance


    • What are we doing wrong by throwing technology alone at security problems (and not looking at the process or people issues along the way)


    • Does proceduralising security or training up staff reduce the efficiency of the organisation or set up the org for longer-term efficiency?


    • Degrees vs. experience? And the ever deteriorating definition of "entry level"


    • The impact and importance of building the time in to train entry-level staff vs. hiring "ready now" experienced people (if you can find them at all)


    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Support The Great Security Debate

    Links:

    • The Infinite Game: Sinek, Simon: 9780735213500: Amazon.com: Books
    • The Great Security Debate Episode 29: People, Process and Product
    • Michigan Council of Women in Technology Foundation / Michigan council of women in technology foundation
    • Education Should Take Additional Steps to Help Protect K-12 Schools from Cyber Threats
    • Library Journal INFOdocket — Information Industry News from Gary Price
    • Amazon.com: The Third Door: The Wild Quest to Uncover How the World's Most Successful People Launched Their Careers: 9780804136662: Banayan, Alex: Books

    1 hr 1 min
  • Monkeys On Your Back

    Security has truly gone mainstream. From late night television jokes to state governors not knowing how technology works, as a profession and a vocation, we have arrived.


    • Jimmy Fallon has jokes about security on his show


    • What are the implications of out of date security laws that define what it is to “hack” systems? Keep in mind that some were written as much as 30+ years ago!


    • Is it security’s job to know all the tools in place? Or the business to approach security to help make their tools secure?


    • Is viewing publicly available information or information pushed to your browser actually hacking, or is it legal/OK?


    • Creating laws that stand the test of time is hard. And subject to lots of lobbying.


    • CISO Liability and visibility based on the prominence of the role. Does this lead to targeting to discredit? (think: false social media profiles and deepfakes)


    • Offensive techniques and what happens when companies go offensive against attackers?


    • Prevention as a growing tactic by security teams - especially when life is on the line in the products we make


    • SPAM: is it food or is it email?


    • When is the right time to bring security into your startup? Weaving it in when it is young!


    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Support The Great Security Debate

    Links:

    • Jimmy Fallon's Hilarious Cybersecurity Jokes
    • SecureWorld News
    • Burp Suite - Application Security Testing Software - PortSwigger
    • Computer Fraud and Abuse Act | JM | Department of Justice
    • Computer Misuse Act 1990
    • UK's Computer Misuse Act to be reviewed, says Home Secretary as she condemns ransomware payoffs • The Register
    • American Paul Whelan, Held In Russia On Spy Charges, Is Sentenced To 16 Years : NPR
    • hiQ Labs v. LinkedIn: Is Scraping Public Data Protected Speech? - Harvard Journal of Law & Technology
    • hiQ Labs v. LinkedIn on CFAA Data Scraping Litigation
    • Renee Murphy | LinkedIn
    • International Operation Knocks Notorious REvil Ransomware Group Offline | WIRED
    • A Hospital Hit by Hackers, a Baby in Distress: The Case of the First Alleged Ransomware Death - WSJ
    • The Future Of The CISO — Six Types Of Security Leaders
    • Conti Statement 10.22.2021 - Pastebin.com

    59 min

About Great Security Debate

From the publisher's feed

Two CISOs and a security-minded friend discuss and debate topics of security and privacy, with a focus on looking at the topic from various angles, both that they support and those they don't.