Great Security Debate

Great Security Debate

By The Great Security DebateSociety & CultureBusinessTechnology
Download on the App Store

Great Security Debate episodes

  • Out of Office: One Year Later

    Exactly one year ago, most of the population of the US was given the word to begin to work from home. Security and technology teams were large parts of the preparation for this change, and were also largely able to move their operations to a home office for the duration of the last twelve months. The last year has been one of constant "on", whether due to changing technology requirements that need to be worked on, increasing incident and response, 10 hours per day in front of the camera on Zoom, and filling what used to be commutes with (wait for it) even more work.

    Dan, Brian and Erik cover a lot of topics, including security of remote work, the mental health impacts of prolonged working remotely, looking out for ourselves and those in our lives, and reconnecting with those that we may have lost contact with over the years. The guys also share positive and negative observations about work/life from the past year, too.

    Please subscribe and leave ratings or feedback in your favourite podcast application! It really helps the podcast out a lot when you do!

    Support The Great Security Debate

    Links:

    • MentorCore – Growth and Development at your Fingertips
    • Watch kid 90 Streaming Online | Hulu
    • Smarter Faster Better: The Transformative Power of Real Productivity - Kindle edition by Duhigg, Charles. Health, Fitness & Dieting Kindle eBooks @ Amazon.com.
    • Amazon.com: The 7 Habits of Highly Effective People: 30th Anniversary Edition eBook: Covey, Stephen R., Collins, Jim, Covey, Sean: Kindle Store
    • What is KAIZEN™
    • Algorithms of Oppression: How Search Engines Reinforce Racism: Noble, Safiya Umoja: 9781479837243: Amazon.com: Books

    58 min
  • The ABCs of CISOs

    This week we look at the security organisation through the looking glass. From within the org, the leaders and the partners and product/service providers we work with, we dig into some of the ways that security works with the rest of the business and customers, and how the needs of each org changes over time and necessitates the need for different mindsets to support those needs from a security perspective.


    • CISO tenure, churn and average age compared to other C-levels


    • How security applies to business value (or sometimes not in the obvious ways)


    • What's better on an RFP response? More detail, or just yes/no answers?


    • CISOs (and all security professionals) as storytellers


    • Relationships with security product vendors, VARs and others selling into organisations on how to build trust and transparency and turn from selling into true partnerships


    Also, Dan successfully makes an automotive analogy; you can't miss that!

    We name drop a few friends who have shared insights that led to our comments today. Check them out and give them wave and a thanks from us!


    John Bingham, Chief Operating Officer at Speak by Design


    Jeff Pollard, VP & Principal Analyst at Forrester - https://twitter.com/jeff_pollard2?s=20


    Enjoy the episode.

    Support The Great Security Debate

    Links:

    • The Great Security Debate Episode 15: Jobs (Not Woz)
    • Home | WomSA
    • Michigan Council of Women in Technology Foundation / MCWT Foundation
    • How To Quantify Cyber Risk In A (Somewhat) Simple Way | by Opinionated Security | CISO & Cyber Leaders | Medium
    • The Future Of The CISO — Six Types Of Security Leaders
    • 6 types of CISO and the companies they thrive in | CIO Dive
    • Busting the Myth of the Two Year CISO Tenure
    • Data Breaches Will Impact Stock Prices Long-Term - Intelligize
    • Ransomware attack or not, Kia's resilience is under the microscope
    • Leader Communication Consulting & Speaking Coach | Speak by Design

    1 hr 10 min
  • Our Favourite Things

    It's Valentine's Day and you get presents. Dan, Brian and Erik discuss the books, people and tools that they each love and changed their lives. None are specifically security-related, so see what's been impactful on each of them in this episode. The links are an especially big part of the episode, so take a look in your podcast app or on the site (https://www.greatsecuritydebate.net/17) to see all the recommendations and get more info about the topics and items covered.

    Support The Great Security Debate

    Links:

    • Neil Peart, the drummer and lyricist of Rush, has died at 67 - CNN
    • Amazon.com: Medium Raw: A Bloody Valentine to the World of Food and the People Who Cook (P.S.) eBook: Bourdain, Anthony: Books
    • CNN's Anthony Bourdain dead at 61 - CNN
    • Kitchen Confidential Updated Edition: Adventures in the Culinary Underbelly (P.S.): Bourdain, Anthony: Amazon.com: Books
    • The 7 Habits of Highly Effective People: Powerful Lessons in Personal Change: Covey, Stephen R.: 9780743269513: Amazon.com: Books
    • Hamilton: The Revolution: Miranda, Lin-Manuel, McCarter, Jeremy: 9781455539741: Amazon.com: Books
    • Amazon.com: The Third Door: The Wild Quest to Uncover How the World's Most Successful People Launched Their Careers (9780804136662): Banayan, Alex: Books
    • Security Career Connection | Corporate Compliance Insights
    • Born to Run: A Hidden Tribe, Superathletes, and the Greatest Race the World Has Never Seen: McDougall, Christopher: 9780307279187: Amazon.com: Books
    • Three Cups of Tea: One Man's Mission to Promote Peace - One School at a Time: Greg Mortenson, David Oliver Relin: 9780143038252: Amazon.com: Books
    • Amazon.com: The Alchemist (9780061122415): Paulo Coelho, Alan R. Clarke: Books
    • Secratic: A Personal Legend – Pragmatically Cynical
    • Harold and the Purple Crayon (Purple Crayon Books): Johnson, Crockett, Johnson, Crockett: 9780064430227: Amazon.com: Books
    • What Got You Here Won't Get You There: How Successful People Become Even More Successful: Goldsmith, Marshall, Reiter, Mark: 9781401301309: Amazon.com: Books
    • Discover Your True North: George, Bill, Gergen, David: 9781119082941: Amazon.com: Books
    • What Warren Buffett Taught Me About Setting Goals
    • Kung Fu Panda (2008) - IMDb
    • Amazon.com: Sony Radio Listeners Kit - ICF-SW7600GR AM/FM Shortwave World Band Radio: Electronics — This is the model I use for world band listening and it is 10+ years old. Go get any world band radio to hear the world in your own home.
    • Brian Schneble | Chili Cook Off Recipe
    • Amazon.com: KENSHIN R2/SG2 GYUTO JAPANESE CHEF KNIFE 240MM: Kitchen & Dining
    • Samurai Hotel - SNL - YouTube
    • WebSDR - Listen to World Radio Online
    • GLOBAL - The Official brand site | Professional Chef’s knives & Japanese Specialist Knives
    • Tramontina Store | Tramontina

    1 hr 6 min
  • The Winds of Change

    The time for job change happens and there are a lot of things go along with it including. We cover a ton of them in this week's episode:


    • The reasons to make a career change


    • Deciding the time is right to make a change (and how do you know)


    • Taking our own advice when it comes to our own career change


    • The importance of support of family to make more drastic changes


    • The power of self-reflection and the need to let go of the present to achieve the future


    • The importance of strong personal and community networking in career growth


    • Impostor syndrome


    • Certification overload in security and privacy


    • Letting someone you know that it may be time for them to make a change


    And the quote of the day is from The Great One, Wayne Gretsky - you miss 100% of the shots you don't take!

    Support The Great Security Debate

    Links:

    • Security Leadership: Moving On. How to Know When It’s Time To Go | by Helen Patton | Jan, 2021 | Medium
    • MentorCore – Growth and Development at your Fingertips
    • Colorado = Security — If you are in Colorado and in security, click on Join our Slack Workspace at the bottom to join the Colorado=Security Slack!
    • Six Months Ago I Applied for a Chief of Staff Role
    • Home | WomSA
    • Chumbawamba – Tubthumping Lyrics | Genius Lyrics
    • Speed of Trust: The One Thing That Changes Everything: Stephen M .R. Covey, Stephen R. Covey, Rebecca R. Merrill: 8601405449078: Amazon.com: Books
    • My Favorite CISOs aren't CISOs

    52 min
  • Jobs (Not Woz)

    We are 9 months into a period in which many workers, including technology and security professionals, are still doing their jobs remotely. Some have moved away from their primary homes, often without letting their company know that this has happened. As business processes catch up with this change in approach, some companies are taking steps to a) formalise work from home as a more standard offering, b) determine how to pay people wherever they are in the country/world, c) decide if in-person culture is key to their ethos, and how to deal with the new focus on remote work.

    In this week's debate, Brian, Erik and Dan chat look at these topics from the pros and the cons, and what it could be like if everyone stays remote, the benefits and risks of geographically independent pay scales, and more.

    Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at [email protected] or on Twitter at https://twitter.com/securitydebate

    Support The Great Security Debate

    Links:

    • Do New Jersey Residents Working From Home Still Have To Pay New York Income Taxes? – CBS New York
    • Microsoft will remove user names from ‘Productivity Score’ feature after privacy backlash - GeekWire
    • Watch Silicon Valley American Experience | Prime Video
    • Robert Noyce, Statesman of Silicon Valley
    • Amazon.com: Trillion Dollar Coach: The Leadership Playbook of Silicon Valley's Bill Campbell (9780062839268): Schmidt, Eric, Rosenberg, Jonathan, Eagle, Alan: Books
    • How orange juice is made - production process, making, used, processing, product, industry
    • These Tech Companies Are Paying Workers the Same Rates Across U.S. - WSJ
    • Minimum pay at Basecamp is now $70,000 - Signal v. Noise
    • This Company's New 2-Sentence Remote Work Policy Is the Best I've Ever Heard — Siemens's new remote work policy is a master class in emotional intelligence.

    59 min
  • Sun and Breeze

    A few weeks ago, a company called SolarWinds was discovered to have had some bad actors in placing things in their technology (code) for a while. How did it happen? What does it mean to others? We don't know all the answers yet but we do know that it means we will have to make some changes to things like those universally hated security questionnaires, and how we manage our own source code to ensure better security.

    Along with a discussion about how cow stomachs relate to information security, and Brian's invoking of The Art of War, there's something for everyone in this epsiode.

    Propeller head warning - this one's a bit more security "inside baseball" than other episodes as we dig into the recent SolarWinds technology attack and some of the ways that the technology and security practitioners can address issues that have been identified. It's still a "for everyone" episode, but we do go a little more in depth that we usually do in some parts. Let us know what you think!


    Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at [email protected] or on Twitter at https://twitter.com/securitydebate

    Support The Great Security Debate

    Links:

    • Identifying UNC2452-Related Techniques for ATT&CK | by Matt Malone | MITRE ATT&CK® | Dec, 2020 | Medium
    • The Art of War: Tzu, Sun, Giles, Lionel: 9781604598933: Amazon.com: Books

    1 hr 3 min
  • E-Phish-Ency

    One of the ways that companies have tried to improve education and awareness about the risks of phishing is the use of phishing tests to see if colleagues click on the link or open the suspect attachment in an unsuspecting yet controled environment. If they do, some instant education comes their way. There are those that think that this approach keeps the topic at the front of everyone's mind, and there are those that think that it can have the effect of chilling the relationship between IT/Security and the rest of the organisation. There are a lot of variables in the equation like how you respond when someone clicks on the phish, how you encourage reporting of potential phishing and more, so the answer is a resounding "it depends."

    We also cover some of the increased security challenges that come with the now more common "working remotely," and what happens when you walk into an empty castle after having gotten past the moat and door, but there is no one inside to defend it.

    Support The Great Security Debate

    Links:

    • What Is DFMEA?
    • Process FMEA | Process Failure Mode & Effects Analysis | Quality-One
    • How to Overcome Obstacles by Using Toyota’s Five Whys Technique | Sam Thomas Davies
    • Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon: Zetter, Kim: 9780770436193: Amazon.com: Books
    • The Perfect Weapon: War, Sabotage, and Fear in the Cyber Age: Sanger, David E.: 9780451497895: Amazon.com: Books
    • BeyondCorp - Enterprise Security  |  Google Cloud
    • The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win: Kim, Gene, Behr, Kevin, Spafford, George: 8601404253799: Amazon.com: Books
    • The Perfect Weapon - Watch the HBO Original Documentary | HBO
    • Homeland: Seasons, Episodes, Cast, Characters - Official Series Site | SHOWTIME

    1 hr 3 min
  • A Frictional Response

    A regular complaint by those who consume and use technology is that security adds friction to their process, which often means they get frustrated at the control put in their path, curse technology in general, or abandon the activity altogether. In today's episode, Dan, Erik and Brian explore the balance necessary to understand when certain controls (and the friction they add) are necessary, or can be made smoother. Each decision on reduction of friction has the potential for knock-on effects to the security, privacy and performance of the system and should be considered before making any change to the control. In some cases the conscious addition of friction is the better approach, too, especially to support transparency with users and enable meaningful, informed choices.

    Support The Great Security Debate

    Links:

    • Amazon.com: RSA SecurID Authenticator SID800 Key Fob (Pack of 25): Computers & Accessories
    • Understanding Office 365 Impossible Travel
    • BeyondCorp - Enterprise Security  |  Google Cloud
    • Half of security pros would rather walk barefoot in a public restroom than use public Wi-Fi - TechRepublic
    • Amazon.com: Step2 KidAlert V.W.S. Safety Sign: Toys & Games
    • iOS 14's Upcoming Anti-Tracking Prompt Sparks Antitrust Complaint in France - MacRumors
    • Popular app T&Cs 'longer than Harry Potter' - BBC News
    • MDOT - CAV Corridor
    • Amazon waves goodbye to its one-click purchase patent | Engadget

    1 hr 7 min
  • Who You Gonna Call?

    When bad things happen to the computers in your organisation, who is the first person you call? IT, the FBI, your general counsel, the insurance company? Today, Erik, Dan and Brian cover attacks, response and middle people negotiating with the attackers on your behalf.

    Other topics discussed include:


    • The risk of cheap IoT devices and long term support (or lack thereof),


    • Whose insurance policy covers the tree on your neighbour's land that falls and hits your house,


    • The law of unintended consequences when creating things, and


    • The joy of reading fake Amazon reviews


    Support The Great Security Debate

    Links:

    • An Interview with "UNKN" Sheds Light on REvil's Operations & Future Victims
    • Schedule - GrrCON
    • Ransomware Activity Targeting the Healthcare and Public Health Sector | CISA
    • Tavour - Craft Beer Delivery
    • Amazon.com: Amazon Sidewalk: Amazon Devices & Accessories
    • Amazon Reviews: Thousands are fake, here's how to spot them
    • Amazon.com : Sugar Free Gummy Bear 1LB Bag : Grocery & Gourmet Food
    • Shodan
    • TV Maker Vizio to Pay Out Millions After Secretly Collecting Customer Data
    • Vizio Reorg Folds Inscape Data Operations Into Platform Business - Variety
    • How Does the Homeowners’ Policy Deal with Trees?
    • SEC.gov | Form 8-K
    • Ransomware WannaCry: All you need to know | Kaspersky
    • Marcus Hutchins: UK ransomware ‘hero’ pleads guilty to US hacking charges | Cybercrime | The Guardian
    • The Confessions of Marcus Hutchins, the Hacker Who Saved the Internet | WIRED

    1 hr 5 min
  • Yippie Ki-Yay... Let's Hack the Gibson

    So many movies about technology and security, so little time. We start our with some of our favourite (and least favourite) security movies. We also wander into a few other areas including: data use and ethics, balancing when to let an attack happen vs. when to let it happen to not let on that you know, Shodan, Stuxnet, Wannacry and more. Check out the complete list of movies we discuss and mention in the links list below!

    Support The Great Security Debate

    Links:

    • We Analyze 13 Hacks in the 1995 Movie ‘Hackers’ and How They Compare to Today | by Cloudbric | Medium
    • Sneakers (1992) - IMDb
    • Swordfish (2001) - IMDb
    • Mr. Robot (TV Series 2015–2019) - IMDb
    • Hackers (1995) - IMDb
    • Blackhat (2015) - IMDb
    • Cyber Security Courses | SANS Institute
    • British Airways hit with UK data watchdog's biggest-ever fine | Reuters
    • The Great Security Debate Episode 6: Pippen and Jordan
    • WarGames (1983) - IMDb
    • Shodan
    • Censys
    • Bananaphone By Raffi - YouTube
    • The Imitation Game (2014) - IMDb
    • Spy Game (2001) - IMDb
    • Antitrust (2001) - IMDb
    • Office Space (1999) - IMDb
    • The Complete List of Hacker And Cybersecurity Movies, Version 2.0
    • Superman III (1983) - IMDb
    • The Circle (2017) - IMDb
    • Three Days of the Condor (1975) - IMDb
    • The Conversation (1974) - IMDb
    • The Net (1995) - IMDb
    • TRON (1982) - IMDb
    • Jurassic Park (1993) - IMDb
    • Cloak & Dagger (1984) - IMDb
    • Amazon.com: Ready Player One eBook: Cline, Ernest: Kindle Store
    • Amazon.com: Ready Player Two: A Novel (Ready Player One Book 2) eBook: Cline, Ernest: Kindle Store
    • Ready Player One (2018) - IMDb
    • The Matrix (1999) - IMDb
    • Star Trek (TV Series 1966–1969) - IMDb
    • Weird Science (1985) - IMDb
    • Danny Elfman On His "Embarrassing" Oingo Boingo Days - YouTube
    • Eagle Eye (2008) - IMDb
    • Die Hard 4.0 (2007) - IMDb
    • Die Hard (1988) - IMDb
    • Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon: Zetter, Kim: 9780770436193: Amazon.com: Books
    • The Perfect Weapon: War, Sabotage, and Fear in the Cyber Age - Kindle edition by Sanger, David E.. Politics & Social Sciences Kindle eBooks @ Amazon.com.
    • Ransomware WannaCry: All you need to know | Kaspersky
    • The Perfect Weapon - Watch the HBO Original Documentary | HBO
    • The Great Hack (2019) - IMDb
    • Ferris Bueller's Day Off (1986) - IMDb
    • Real Genius (1985) - IMDb
    • Enemy of the State (1998) - IMDb
    • Michigan Hacker Modifies Jail Records To Get Friend Released, Now Faces Jail Time

    1 hr 5 min

About Great Security Debate

From the publisher's feed

Two CISOs and a security-minded friend discuss and debate topics of security and privacy, with a focus on looking at the topic from various angles, both that they support and those they don't.