Great Security Debate

Great Security Debate

By The Great Security DebateSociety & CultureBusinessTechnology
Download on the App Store

Great Security Debate episodes

  • People, Process and Product

    In the adage "people, process, technology" the technology comes last in the list for a reason as it is only as good as the people and processes that surround and support it. In this week's Great Security Debate we cover a range of topics all focused on the importance (and impacts) of the people and the process as key to the success of security technology. Said differently we can throw all the tech in the world out there, and it does no good without the other two.


    • Around the world, in some locations government drives commercial security innovation, and in others, commercial interests drive government security adoption. Where is that innovation coming from?


    • The recent rumblings that security insurance policies may soon come with "buy lists". What impacts on the efficacy of controls come when the tech is chosen for you. And how do we guarantee the genuineness of how such a formulary was created.


    • What can security learn and use to teach the wider business world about availability and resilience from the current supply chain impacts taking place in manufacturing or consumer goods after COVID-19?


    Tune in to this week's episde to learn all about these and more. Show links below have the details of articles, items we cover in the episode.

    We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.

    Support The Great Security Debate

    Links:

    • Official PCI Security Standards Council Site - Verify PCI Compliance, Download Data Security and Credit Card Security Standards
    • EU rules to force USB-C chargers for all phones - BBC News
    • What is One-Piece Flow in the Production Process? | Breakout
    • Why The Chip Shortage Is So Complex According To Experts
    • Amazon.com: The Infinite Game eBook : Sinek, Simon: Kindle Store
    • Business Roundtable Redefines the Purpose of a Corporation to Promote ‘An Economy That Serves All Americans’ | Business Roundtable
    • ISO 26262: People, Process and Product - SemiWiki
    • Auto-ISAC Summit 2021 – Auto-ISAC

    58 min
  • Stop, Collaborate and Pivot

    Over the past 18 months, the way we work has changed including within the security field. On this episode of The Great Security Debate, Dan, Brian and Erik dig into some of the long-term implications of working today and beyond.


    • From remote work to in-person or hybrid : what works best?


    • Does security have a talent shortage, and how is it exacerbated by leadership issues?


    • Was innovation and productivity stifled during COVID by remote work?


    • How to build strong remote teams and learning from the history of global remote teams?


    • Does remote work help or hurt the chances for smaller orgs to get good talent?


    • Is money the biggest driver for people in work? How does mission and team comfort play in?


    • Can we change culture of long-standing in-person culture enough to support remote/hybrid work?


    • Which is better to look at, certifications or experience?


    • What role does influence play in leadership and innovation, especially in non-management roles?


    This episode is available in both audio and video formats. The video edition is on our YouTube channel along with a growing collection of video from previous episodes. https://youtu.be/p099pC4dh3A

    Get notified via email when each new episode is published, and find out about exciting new projects from The Great Security Debate team. Sign up here: https://newsletter.greatsecuritydebate.net


    Thanks for listening! Tell your friends and let us know your comments, feedback and ideas for future Great Security Debates.

    Support The Great Security Debate

    Links:

    • Rafeeq Rehman - Personal Blog - Information Security | Entrepreneurship | Digital EnterprisesRafeeq Rehman – Personal Blog » Information Security | Entrepreneurship | Digital Enterprises
    • Cybersecurity Arm Wrestling: Winning the perpetual fight against crime by building a modern Security Operations Center (SOC): Rehman, Rafeeq: 9798733168166: Amazon.com: Books
    • Making the Great Attrition the Great Attraction | McKinsey
    • Automated hiring software is mistakenly rejecting millions of viable job candidates - The Verge
    • Michigan Council of Women in Technology Foundation / MCWT Foundation
    • Amazon.com: Radical Candor: Be a Kick-Ass Boss Without Losing Your Humanity eBook : Scott, Kim: Kindle Store
    • Amazon.com: Think Again: The Power of Knowing What You Don't Know eBook : Grant, Adam: Kindle Store
    • Amazon.com: The Infinite Game eBook : Sinek, Simon: Kindle Store
    • Happiness is Love -- and $75,000
    • Colorado = Security
    • Amazon.com: Leading Without Authority: How the New Power of Co-Elevation Can Break Down Silos, Transform Teams, and Reinvent Collaboration eBook : Ferrazzi, Keith, Weyrich, Noel: Kindle Store
    • Leaders Eat Last: Simon Sinek, Simon Sinek: 0191091429112: Amazon.com: Books
    • Webinar: The Power of Connection – Bridging the Divide – MentorCore
    • Bank Bosses Want Return to Office. Employees Want Flexibility to Work From Home - Bloomberg

    1 hr 1 min
  • Risks, Regulations, and Reputations

    A recent visit by US companies to the White House sparked a debate between Dan, Brian and Erik about how to improve security. Was the result useful to the cause, or useful to the marketing goals of the attendees? The risks are high, but are the responses going to move the needle? We discuss on this week's Great Security Debate.

    Leave some feedback, give a thumbs up, a star or whatever your favourite podcast app prefers, and tell your friends about the podcast. Thanks for being a listener!

    Support The Great Security Debate

    Links:

    • FACT SHEET: Biden Administration and Private Sector Leaders Announce Ambitious Initiatives to Bolster the Nation’s Cybersecurity | The White House
    • Biden discusses cybersecurity with Amazon, Google, Apple CEOs at White House - The Washington Post
    • National Council of ISACs
    • Financial Services Information Sharing and Analysis Center
    • Big tech proud as punch about cameos in Joe Biden's security theatre • The Register
    • Why is there a chip shortage? - BBC News
    • Process Failure Mode Effects Analysis (PFMEA) Explained
    • What is Design Failure Mode and Effects Analysis (DFMEA)?
    • Welcome to TISAX · ENX Portal
    • Amazon.com: Outliers: The Story of Success eBook : Gladwell, Malcolm: Kindle Store
    • Think Again: The Power of Knowing What You Don't Know: Grant, Adam: 9781984878106: Amazon.com: Books
    • World War Z (2013) - IMDb

    59 min
  • It's Personal

    If you want to check out the new video edition of the podcast, please go to:

    https://youtu.be/FBBmA9YDNfQ

    where you can subscribe, give thumbs up and ring bells like YouTubers have been asking you to do for years. You know the drill.


    Also, our apologies for the hum in the audio throughout the entire episode. The problem has been identified and the source (Dan) has been taken out back and schooled on the difference between mic-level and line-level audio feeds. He promises it won't happen again... often.


    Now, on to the show.


    This week, Dan, Brian and Erik tackle the recent changes announced by Apple regarding moves to protect children from online predators and from the passing of illegal material about children. The project has three parts, each with its own benefits and concerns. We cover them each individually:


    First, the scanning of messages inbound to minors (Under 18s) on a Apple Family Sharing account in which images are tested for inappropriateness, blurred and the child alerted that they may be about to look at something that they may want to reconsider. If they are under 13 and decide to view the image the parents are notified. This is an opt-in programme and parents decide whether or not to join for the family.


    Next comes the proactive scanning of iCloud Photo Library stored at Apple. For a long time many have wondered why end-to-end encryption had not been put into iCloud, and this is a likely factor. The photos are tested against the hashes of a set of known images containing child pornography and issues are raised to the authorities. This is and has been happening on other cloud photo services including Microsoft and Flickr for some time.


    Finally, and most controvertially from a privacy perspective, Apple is implementing a proactive test of the hashes ofphotos stored on customers' Apple devices against this same set of known images. In the US there is no law that prevents this but runs counter to the marketing emphasis Apple has placed on the privacy of data within their devices. The method is rather intricate and strives to prevent Apple from seeing anything unless it suspects there are systemic child pornography issues at bay.


    These technology approaches change the game for prosecutors and law enforcement, and they expose issues earlier. But what happens when this capability gets expanded, or brought into law as mandatory for use against its citizens who speak out politically, or is taken over by bad actors? Look at the link in the show notes regarding the keys the TSA made for physical locks at the airport - every hole is a potential future vulnerability. Does the end justify the means? We discuss in depth on this week's Great Security Debate!


    If you want to support the efforts of The Great Security Debate, please feel free to become a patron and get some cool benefits of supporting this independent show - https://www.patreon.com/securitydebate

    Support The Great Security Debate

    Links:

    • Child Safety - Apple — Apple's official landing page for the new programs.
    • National Center for Missing and Exploited Children
    • TSA Master Keys - Schneier on Security
    • Apple's Plan to "Think Different" About Encryption Opens a Backdoor to Your Private Life | Electronic Frontier Foundation
    • Apple says any expansion of CSAM detection outside of the US will occur on a per-country basis - 9to5Mac
    • Apple to Scan Every Device for Child Abuse Content — But Experts Fear for Privacy
    • Why You Should Stop Using iMessage After Shock iPhone Update
    • Future Crimes by Marc Goodman
    • We Build Tools to Defend Children From Sexual Abuse | Thorn
    • OpEd on Privacy Risks by Alex Stamos and Matthew Green — Apple Wants to Protect Children. But It’s Creating Serious Privacy Risks.

    1 hr 2 min
  • We'll See

    Get notified in an email every time a new episode of The Great Security Debate drops, or when we announce in-person episode recordings (coming soon)! Sign up for our newsletter: https://newsletter.greatsecuritydebate.net

    Dan, Brian, and Erik find themselves debating whether or not the new up-to-$10M reward for information regarding ransomware and other attacks will make a material difference in the upward trend in technology as a weapon.


    • What are some non-technical examples of ransomware (hint: it involves warm weather islands and boats and flags with skulls)


    • How will the new ransomware bounty work? Will it work at all?


    • Who sets the definition of "minimum viable security?" Who should and who can set that definition?


    • Can we get beyond human nature to take advantage of a situation that is beneficial to them?


    • What other economic impacts take place if we can eliminate bad actors (other than a lot of out-of-work security practitioners?)


    Tune in and enjoy this episode of The Great Security Debate. Please let us know your thoughts by leaving rating feedback in your podcast app, and/or sending us an email to [email protected]. Thanks for listening!

    Support The Great Security Debate

    Links:

    • Watch Black Sails Online: Stream Full Series on STARZ - Free Trial
    • The Lost Pirate Kingdom | Netflix Official Site
    • $10 Million Reward Offered for Information on Ransomware Attacks - The New York Times
    • Cybersecurity and the Curse of Binary Thinking
    • Watch Charlie Wilson's War | Prime Video
    • The FBI’s Advice on Ransomware: Don’t Pay, but Tell Us if You Do - WSJ (Subscription required)
    • SEC.gov | Office of the Whistleblower
    • The Great Security Debate Episode 24: Back to Basics

    1 hr 1 min
  • Back to Basics

    Recently a lot of newsworthy security incidents have taken place. A common thread through many is not that they were sophisticated or required lots of time to plan and execute, or even that the victim had not invested in a lot of whizbang security technology which led to them not noticing the attack. The common thread much more simple: that fundamental security measures were not being taken by the organisation. Things like turning off accounts when people left the organisation, removing disused technology from the network, and the reuse of passwords by staff amongst public-facing and internal systems.

    The fundamentals make it easy for attackers to get into networks and systems, both enterprise and personal, and are all things that we can each work on individually and within our organisations to improve and make the attacks that much harder for the bad actors to execute. This week's episode discusses those fundamentals and how to approach them.

    The "slide" that is often referenced in the episode comes from a talk that Dan gave to the National Information Standards Organisation (NISO) last week on why it was so important to maintain the security of their systems. The whole presentation deck is available at http://slideshare.net/secratic/security-is-an-enabler-not-securing-is-an-inhibitor-249421889 and the specific slide is on Slide 8.


    Thanks for listening. You can subscribe to the podcast on your favourite podcast application or by visiting our website https://www.greatsecuritydebate.net/subscribe. Please let us know what you think by leaving a comment in the podcast application's rating section or emailing us [email protected]

    Support The Great Security Debate

    Links:

    • The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win: Kim, Gene, Behr, Kevin, Spafford, George: 8601404253799: Amazon.com: Books
    • Amazon.com: The Unicorn Project: A Novel about Developers, Digital Disruption, and Thriving in the Age of Data eBook: Kim, Gene: Books
    • Home - Chaos Monkey
    • The Great Security Debate Episode 21: Why Does My CISO Hate Me?
    • Presentation: Security Is an Enabler, Not Securing Is an Inhibitor
    • Transforming Content Through Transformed Systems | NISO website
    • Largest US propane distributor discloses '8-second' data breach
    • Private Communication Coaching for Business Leaders & Teams
    • A CISO's First 100 Days
    • The 18 CIS Controls
    • Five Whys and Five Hows | ASQ
    • BeyondCorp Zero Trust Enterprise Security  |  Google Cloud

    1 hr 1 min
  • It Depends

    A wide range of cause and effect discussion in this week's episode.


    • What happens when a cellphone gets compromised for one purpose and has unrelated, follow-on consequences?


    • Will there be material impact from the recent decrees, executive orders and vocal support by President Biden that additional focus is required on information security, ransomware and corruption?


    • What are the downstream impacts of paying, and not paying a ransom and what happens if they are prohibited by law?


    • Is doing the mininum amount of security OK, or is the minimum not really the required minimum?


    • And more on the security position on data lakes, too.


    Join Erik, Brian and Dan as they count their pieces of flair and determine if we are the right fit to keep working at Flingers.

    Support The Great Security Debate

    Links:

    • How Jeff Bezos' Phone Was Likely Hacked by Saudi Crown Prince MBS
    • Watch The Dissident | Prime Video
    • Saudi Arabia claims anti-corruption purge recouped $100bn | Saudi Arabia | The Guardian
    • How to opt out of (or into) Amazon’s Sidewalk network - The Verge
    • Post | Feed | LinkedIn - It’s time for security teams to embrace security data lakes
    • Hacking Airplanes - Schneier on Security
    • SolarWinds lawsuit expands to include private equity owners
    • Supreme Court narrows Computer Fraud and Abuse Act: Misusing access not quite the same as breaking in • The Register
    • Supreme Court sides with police officer who improperly searched license plate database - CNNPolitics
    • Post | Feed | LinkedIn - Fundamentals of Security > Shiny Technology
    • Amazon.com: Office Space [Blu-ray]: Jennifer Aniston, Ron Livingston, Mike Judge: Movies & TV
    • Post | Feed | LinkedIn - Security Debt
    • Biden to Require Pipeline Companies to Report Cyberattacks - The New York Times
    • Biden Describes Combating Corruption as National Security Priority, Orders Interagency Review to Bolster Anti-Corruption Tools including Private Sector Partnerships | News & Resources | Dorsey
    • Judge grants definitive suspension of the biometric data registry — e grants definitive suspension of the biometric data registry
    • Tiktok's new privacy policy lets it harvest biometric data, including 'faceprints and voiceprints'
    • Companies Will be Prosecuted for Paying Ransom: U.S. Dept. of Treasury
    • US Treasury Department ban on ransomware payments puts victims in tough position | CSO Online

    1 hr
  • Sidewalks and AirTags

    The news of the week includes discussion about some changes to Amazon's home devices including Echo and Ring with the activation of their Sidewalk Network on all those devices by default and the potential for both ubiquitous connectivity for IoT devices, and the possibiity of abuse of the data that is seen . Brian, Erik and Dan also talk about the impact that the launch of the new Apple Application Tracking Transparency (ATT) program which asks users if they want to be tracked (spoiler alert: they very much do not). This will impact ads and apps that depends on ads pretty heartily, and we debate the pros and cons. Enter the data lakes (troves of data just waiting to be mined by companies to find "interesting things" (or targets for attackers).

    We really appreciate your feedback, both through subscribing and rating on your favourite podcast application, and by email to us at [email protected]

    Thanks for listening!

    Support The Great Security Debate

    Links:

    • Home | Sidewalk Labs
    • Amazon.com Help: Enable or Disable Amazon Sidewalk for Your Account
    • Amazon's Sidewalk Network Is Turned On by Default. Here's How to Turn It Off | Inc.com
    • Amazon partners with Tile to take on Apple AirTags
    • Amazon.com: Amazon Sidewalk: Amazon Devices & Accessories
    • Tile says Apple's behavior is anticompetitive and has 'gotten worse, not better' | Reuters
    • The Great Security Debate Episode 1: Privacy Drone

    55 min
  • Why Does My CISO Hate Me?

    We got asked by a listener to help answer the question, "Why Does My CISO Hate Me?" While we may not be privy to the exact situation in play there, we are pretty sure that no one's CISO truly hates them (but they may not be fond of all the things that everyone does all the time). In the debate today, we talk about some of the things that challenge CISOs including:


    • Security is more than just confidentiality... there's also integrity and availability


    • Undocumented processes and changes make it hard to figure out where things go wrong


    • Security is a bidirectional partnership, not an Q&A/task queue from the rest of the organisation, nor the acceptor of risks


    • Please ask questions if you are concerned about something or want more info, or even if something sort of smells fishy (or phishy). There are no such thing as stupid questions, only unasked ones.


    We also highlight a number of the things that CISOs and security teams can improve on to build better and stronger relationships across the organisation, too, such as:


    • Better listening and asking good questions


    • Understanding the business through servant leadership


    • Helping to determine what is most important to the business (and what needs to be protected)


    We are all heading toward a common goal, so let's work together to accomplish it!


    Thanks for listening. Until next time...

    Support The Great Security Debate

    Links:

    • Amazon.com: The Toyota Way: 14 Management Principles from the World's Greatest Manufacturer (8601404279935): Liker, Jeffrey: Books
    • ITSM A Complete Guide - 2020 Edition: Gerardus Blokdyk: 9780655914921: Amazon.com: Books
    • ITIL Foundation, ITIL 4 Edition (ITIL 4 Foundation): AXELOS: 9780113316076: Amazon.com: Books
    • Jocko Willink - Echelon Front
    • Watch Saturday Night Live Highlight: Nick Burns, Your Company's Computer Guy with Billy Bob Thornton - NBC.com

    52 min
  • It All Comes Down to Relationships (Guest Debater: Jessica Burn)

    We open season 2 with a new format: guests! Our first guest, Jessica Burn, has been working closely with CISOs and the security industry at Forrester where she is a Senior Analyst covering the role of the CISO, Incident Response, Zero Trust Strategy and Continuous Controls Monitoring.

    Dan, Erik, Brian and Jess use a new Forrester report about recommendations for security programs in 2021 as the basis for the discussion (and debate), including a few major themes:


    • The impacts of the consolidation of technology, both in security and the wider tech arena


    • Balancing the monitoring and the privacy when tracking employees as they work remotely as a result of the pandemic


    • Securing what you sell both because you need to, but also because it is good for your business


    • Where are our inventories and why do we still generally fail at knowing what systems we have


    • Of course, third party risk management. It's a mandatory "slide 3" on every board presentation, of course.


    We still debate, we still discuss, we still shift the discussion to automotive and manufacturing from time to time, but now we have some additional voices to add to the debate, too. Thanks so much, Jess!

    Special Guest: Jessica Burn.

    Support The Great Security Debate

    Links:

    • So Good They Can't Ignore You: Why Skills Trump Passion in the Quest for Work You Love: Newport, Cal: 8601420220263: Amazon.com: Books
    • Security Recommendations 2021: Taking Stock For The Long Term
    • A CISO's First 100 Days
    • Developer Security Champions Are Needed Now More Than Ever
    • Financial Services Information Sharing and Analysis Center
    • Legal Services Information Sharing | LS-ISAO
    • Only 10 Percent of People Are Natural Leaders. The Rest of Us Have to Work on Developing These 3 Qualities | Inc.com

    1 hr 3 min

About Great Security Debate

From the publisher's feed

Two CISOs and a security-minded friend discuss and debate topics of security and privacy, with a focus on looking at the topic from various angles, both that they support and those they don't.