
Sign up to save your podcasts
Or


Exactly one year ago, most of the population of the US was given the word to begin to work from home. Security and technology teams were large parts of the preparation for this change, and were also largely able to move their operations to a home office for the duration of the last twelve months. The last year has been one of constant "on", whether due to changing technology requirements that need to be worked on, increasing incident and response, 10 hours per day in front of the camera on Zoom, and filling what used to be commutes with (wait for it) even more work.
Dan, Brian and Erik cover a lot of topics, including security of remote work, the mental health impacts of prolonged working remotely, looking out for ourselves and those in our lives, and reconnecting with those that we may have lost contact with over the years. The guys also share positive and negative observations about work/life from the past year, too.
Please subscribe and leave ratings or feedback in your favourite podcast application! It really helps the podcast out a lot when you do!
Support The Great Security Debate
Links:
This week we look at the security organisation through the looking glass. From within the org, the leaders and the partners and product/service providers we work with, we dig into some of the ways that security works with the rest of the business and customers, and how the needs of each org changes over time and necessitates the need for different mindsets to support those needs from a security perspective.
Also, Dan successfully makes an automotive analogy; you can't miss that!
We name drop a few friends who have shared insights that led to our comments today. Check them out and give them wave and a thanks from us!
John Bingham, Chief Operating Officer at Speak by Design
Jeff Pollard, VP & Principal Analyst at Forrester - https://twitter.com/jeff_pollard2?s=20
Enjoy the episode.
Support The Great Security Debate
Links:
It's Valentine's Day and you get presents. Dan, Brian and Erik discuss the books, people and tools that they each love and changed their lives. None are specifically security-related, so see what's been impactful on each of them in this episode. The links are an especially big part of the episode, so take a look in your podcast app or on the site (https://www.greatsecuritydebate.net/17) to see all the recommendations and get more info about the topics and items covered.
Support The Great Security Debate
Links:
The time for job change happens and there are a lot of things go along with it including. We cover a ton of them in this week's episode:
And the quote of the day is from The Great One, Wayne Gretsky - you miss 100% of the shots you don't take!
Support The Great Security Debate
Links:
We are 9 months into a period in which many workers, including technology and security professionals, are still doing their jobs remotely. Some have moved away from their primary homes, often without letting their company know that this has happened. As business processes catch up with this change in approach, some companies are taking steps to a) formalise work from home as a more standard offering, b) determine how to pay people wherever they are in the country/world, c) decide if in-person culture is key to their ethos, and how to deal with the new focus on remote work.
In this week's debate, Brian, Erik and Dan chat look at these topics from the pros and the cons, and what it could be like if everyone stays remote, the benefits and risks of geographically independent pay scales, and more.
Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at [email protected] or on Twitter at https://twitter.com/securitydebate
Support The Great Security Debate
Links:
A few weeks ago, a company called SolarWinds was discovered to have had some bad actors in placing things in their technology (code) for a while. How did it happen? What does it mean to others? We don't know all the answers yet but we do know that it means we will have to make some changes to things like those universally hated security questionnaires, and how we manage our own source code to ensure better security.
Along with a discussion about how cow stomachs relate to information security, and Brian's invoking of The Art of War, there's something for everyone in this epsiode.
Propeller head warning - this one's a bit more security "inside baseball" than other episodes as we dig into the recent SolarWinds technology attack and some of the ways that the technology and security practitioners can address issues that have been identified. It's still a "for everyone" episode, but we do go a little more in depth that we usually do in some parts. Let us know what you think!
Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at [email protected] or on Twitter at https://twitter.com/securitydebate
Support The Great Security Debate
Links:
One of the ways that companies have tried to improve education and awareness about the risks of phishing is the use of phishing tests to see if colleagues click on the link or open the suspect attachment in an unsuspecting yet controled environment. If they do, some instant education comes their way. There are those that think that this approach keeps the topic at the front of everyone's mind, and there are those that think that it can have the effect of chilling the relationship between IT/Security and the rest of the organisation. There are a lot of variables in the equation like how you respond when someone clicks on the phish, how you encourage reporting of potential phishing and more, so the answer is a resounding "it depends."
We also cover some of the increased security challenges that come with the now more common "working remotely," and what happens when you walk into an empty castle after having gotten past the moat and door, but there is no one inside to defend it.
Support The Great Security Debate
Links:
A regular complaint by those who consume and use technology is that security adds friction to their process, which often means they get frustrated at the control put in their path, curse technology in general, or abandon the activity altogether. In today's episode, Dan, Erik and Brian explore the balance necessary to understand when certain controls (and the friction they add) are necessary, or can be made smoother. Each decision on reduction of friction has the potential for knock-on effects to the security, privacy and performance of the system and should be considered before making any change to the control. In some cases the conscious addition of friction is the better approach, too, especially to support transparency with users and enable meaningful, informed choices.
Support The Great Security Debate
Links:
When bad things happen to the computers in your organisation, who is the first person you call? IT, the FBI, your general counsel, the insurance company? Today, Erik, Dan and Brian cover attacks, response and middle people negotiating with the attackers on your behalf.
Other topics discussed include:
Support The Great Security Debate
Links:
So many movies about technology and security, so little time. We start our with some of our favourite (and least favourite) security movies. We also wander into a few other areas including: data use and ethics, balancing when to let an attack happen vs. when to let it happen to not let on that you know, Shodan, Stuxnet, Wannacry and more. Check out the complete list of movies we discuss and mention in the links list below!
Support The Great Security Debate
Links:
From the publisher's feed