Phishy Business

Phishy Business

By MimecastTechnology
Download on the App Store

Phishy Business episodes

  • Using Criminal Skills for Good - a Memoir of a Burglar for Hire

    In this episode of Phishy Business, we discuss social engineering, the professional con game of burglary for hire, and different aspects of how this very specialized skill can impact organizations and individuals.

    Our special guest is Jenny Radcliffe, who was our very first interview on the podcast and made a return appearance in our episode on job hacking. Jenny is well known for being able to get in anywhere and past anyone. She has turned a schooling in the art of breaking and entering during her childhood, into a celebrated career as an expert in social engineering, where she exploits the flaws and weaknesses in top-grade security operations.

    Now, Jenny has returned for a third visit to tell us all about her new book, People Hacker. It’s a memoir about her unusual career as an ethical burglar and as you can imagine, it’s filled with fascinating stories.

    In ‘Using Criminal Skills for Good - a Memoir of a Burglar for Hire’, we discuss:

    • The importance of context in social engineering and how good people hackers adapt their methods according to the scenario and culture
    • How real-world social engineering compares to the virtual world
    • The importance of diversity in security
    • Why Jenny didn’t go over to the dark side despite having all the skills of a successful criminal
    • How everyone is hackable and it’s important to make security relevant to everyone
    • How to do penetration testing well and without negatively impacting employees
    • 34 min
    • It’s Time to Retire the Risk Management Profession

      In this episode of Phishy Business, we discuss some important ways to think about and look at risk and how its more about making decisions than assessing threats.

      Our special guest is Stefan Gershater, Director of Risk at Burberry. Stefan is a risk management expert, a biochemist, and a navy veteran. Stefan says that as a risk expert, he tries to make sense of uncertainty, which means he thinks a lot about how everyday decisions impact people and organizations. Stefan feels that when defining “risk”, it should be disassociated from the word “threat”, and simply be about making better decisions to improve outcomes.

      In ‘It’s Time to Retire the Risk Management Profession’, we discuss:

      • How being in the royal navy shaped Stefan’s understanding of risk
      • The difference between risk in the navy and risk in a corporate setting
      • Why Stefan thinks the risk management profession should be retired
      • The importance of data in risk assessment
      • How to communicate risk to stakeholders
      • Mental health in the workplace
      • About Phishy Business

        Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

        www.mimecast.com

        35 min
      • Why Security Professionals Should Consider Career Coaching

        In this episode of Phishy Business, we discuss career coaching, looking at what it is, and how it can benefit all professionals, including those in the cybersecurity space. We delve into the differences between coaching and mentoring and discuss what to expect when working with a career coach.

        Our special guests are executive coach and mentor Fiona Anderson, and Dr. Kiri Addison, Senior Product Manager at Mimecast. Fiona is a change catalyst who works with professionals from all sectors with a particular focus on culture change. Fiona loves working with people to help them become the best versions of themselves. Kiri is a senior product manager and all-around cybersecurity expert who recently won a Most Inspiring Women in Cyber award and worked with Fiona on her own career development.

        In ‘Understanding More About Career Coaching’, we discuss:

        • The difference between coaching and mentoring
        • Recognizing that there may be career ceilings of our own making
        • How different personalities and even gender identity can lead to different perspectives
        • How the career coaching process works and key things to insist on, such as confidentiality
        • The importance of knowing your own values
        • What Kiri got out of the coaching process
        • Tips to combat stress and burnout, a major issue in the cybersecurity sector 
        • About Phishy Business

          Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

          www.mimecast.com

          33 min
        • Scary Smart AI? Or the Potential to Be a Force for Good?

          In this episode of Phishy Business, we discuss what can be a very scary side of AI – when bots start thinking for themselves. We delve into some examples of this actually happening, but also look at the good AI is providing humankind.

          Our special guest is Mo Gawdat, former chief business officer at Google X and bestselling author of the books Solve for Happy and Scary Smart. Mo describes himself as having two lives – a first life as a “maker” who coded, built robots, and developed technology, and a second life following a personal tragedy, as an author, podcaster, and “thinker” who analyzes things that tend to be overlooked by others.

          Mo spends much of his time championing the importance of happiness and acceptance of events we cannot change. Mo also has a lot to say about the similarity between developing AI and raising children. Mo believes that one day AI will become more intelligent than humans and that we need to prepare now to coexist with AI.

          In ‘Scary Smart AI? Or the Potential to Be a Force for Good?’, we discuss:

          • Why AI could be scary, but also, why it could be good for humankind
          • How raising AI is similar to parents raising children
          • Why AI is humanity’s biggest opportunity
          • The potential for AI to develop emotions and consciousness
          • When AI becomes smarter than humans and what the implications could be
          • How Mo stays happy as explained in his book Solve for Happy
          • About Phishy Business

            Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

            www.mimecast.com

            45 min
          • Work Inspired – What’s Possible in Shaping Corporate Culture

            In this episode of Phishy Business, we discuss the idea of Work Inspired, a corporate culture where employees all love to work because it turns out that happy employees are very good for business.

            Our special guest is Aron Ain, award-winning, retired CEO of UKG, formerly known as Kronos. Aron now serves as Executive Chair of the UKG Board of Directors and is also the author of Work Inspired, a book that depicts an inspiring example of what’s possible in shaping corporate culture.

            Aron transformed his company’s culture at Kronos, building a billion-dollar business. Aron truly believes that great organizations are powered by great people and that great people build better products, services, and outcomes. He also believes the biggest challenge in building such an organization is creating an engaging environment where people feel wanted and valued. We also discuss how Aron’s leadership style and authenticity were key weapons when his organization fell victim to a cyberattack.

            In ‘Work Inspired – What’s Possible in Shaping Corporate Culture’, we discuss:

            · How employees are a powerful strategic weapon in any organization.

            • The concept of being an ‘unleader’ and the importance of humility – how you don’t need to throw your title around and be forceful to get things done.
            • Being conscious of being authentic.
            • How Aron handled the COVID-19 pandemic as a leader.
            • Aron’s views on the future of work.
            • The importance of transparency and overcommunication when dealing with a cyberattack.
            • Why organizations often aren’t transparent in the event of a cyberattack.
            • How Aron’s values showed up in his people during the attack.
            • About Phishy Business

              Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

              www.mimecast.com

              26 min
            • Cyber Extortion – The Next Evolution of Ransomware

              In this episode of Phishy Business, we discuss the very definition of ransomware and how it can be an overused and underdefined concept. We also take a closer look at the world of threat research.

              Our special guest is former professional hacker Charl van der Walt, Head of Security Research at Orange CyberDefense, who now spends his time asking and answering the important questions around cybersecurity, specifically those that pertain to ransomware.

              Charl believes we need to move beyond the term ransomware and look more at the concept of cyber extortion because the days of one-off ransomware attacks have given way to a massive, highly profitable, well-organized cyber-crime industry. Charl is working to ensure cybersecurity professionals look at ransomware more in terms as being part of a series of crimes in which security is breached and then something of value is taken and held for ransom. This is because ransom attacks are moving beyond just denial of access to data and are more frequently including confidential data exposure and denial of service in some form.

              In ‘Cyber Extortion – The Next Evolution of Ransomware’, we discuss:

              • Redefining the term “ransomware” as “cyber extortion”.
              • Why cyber extortion is now a much more appropriate term for security professionals to use.
              • The main categories of threats in cybersecurity.
              • The trends in ransomware over the past few years that have led to its transformation.
              • How to effectively communicate about ransomware to a non-technical audience.
              • The work communities can do to prevent ransomware attacks, known as ecosystem-based security.
              • About Phishy Business

                Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                www.mimecast.com

                34 min
              • Marketing as Customer Experience – Be an Active Listener

                In this episode of Phishy Business, we discuss how cybersecurity marketing, sales, and support are for the most part inadequate, and how there can be a big disconnect between how marketers market and how technology professionals buy. We talk more about how marketing should consider the customer experience and how marketing departments should not only market their products and services but should also be active listeners and understand what their buyers need and want.

                Our special guest is cybersecurity marketing expert and podcaster Dani Woolf, who spent the past decade running high impact marketing departments for technology startups. She has since started Audience 1st to help cybersecurity vendors understand what CIOs and CISOs really want from them. Dani helps cybersecurity marketers better understand their buyers so they can sell more.

                In ‘Marketing as Customer Experience – Be an Active Listener’, we discuss:

                • How cybersecurity can help solve very complex problems.
                • Vendors should have a ‘mission over money’ mindset.
                • Some traditional demand- and lead-gen techniques that don’t work with a cybersecurity audience.
                • Why CISOs tend to be a more cynical and less trustworthy audience, which is understandable because of the high stakes and stressful nature of the job.
                • Co-creating with influencers who have polarizing opinions in the market is a good strategy in cybersecurity marketing.
                • How the cybersecurity community values concise and clear content.
                • The fact that technology leaders want marketing to be authentic and to cut through the ‘noise’.
                • The mass over use of buzzwords that is all too common and alarming in the sector.
                • How the cybersecurity community is open to giving feedback and taking feedback and how not a lot of vendors take advantage of this.
                • That in order to be successful, marketing mindset needs to shift from product first to customer first.
                • About Phishy Business

                  Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                  www.mimecast.com

                  34 min
                • Cybermindz - Bonus Episode

                  In this bonus episode of Phishy Business, we continue to recognize the value of the work of cybersecurity professionals. Join us as Peter Coroneos, Founder and Executive Chairman of Cybermindz.org, takes us through a 10-minute meditation aimed at lowering stress. This is a just a taste of the whole Cybermindz protocol, and worth a try!

                  13 min
                • Cybermindz – Hope in a Burnt-Out Sector

                  In this episode of Phishy Business, we honor and recognize the value of the work of those professionals who spend their days defending people and organizations from cyberattacks by taking a close look at one of the biggest problems the industry faces today: worker burnout and the associated mental health issues. Join us as we discuss how while many of us say we are simply “fine” when someone asks how we are, we may, in fact, actually be suffering silently from stress and burn out.

                  Our special guest is cybersecurity expert Peter Coroneos, Founder and Executive Chairman of Cybermindz.org, an organization that recognizes that many cybersecurity professionals are themselves under sustained and increasing stress and sets out to provide direct support to restore and rebuild emotional and cognitive health. Peter has worked in cybersecurity for a long time and was once head of the Internet Industry Association in Australia which gave him special and early insight into how cybersecurity workers can suffer from on-the-job stress. With cybersecurity professionals suffering more and more from stress and burnout, Peter is working to develop and deploy programs that are designed to help.

                  In ‘Cybermindz – Hope in a Burnt-Out Sector’, we discuss how:

                  • Stressed-out security teams make companies less secure.
                  • Hope and reinvigoration through a proven relaxation protocol is the aim of Cybermindz.
                  • The brain is not designed for constant periods of stress.
                  • The brain can’t distinguish between a physical and psychological threat – and how in cybersecurity teams there is a constant sense of being under attack.
                  • In preliminary findings, CISOs are polling worse than frontline healthcare workers on their sense of efficacy and ‘doing a good job’.
                  • Through research, connecting the dots between cyber teams’ mental health and an organization’s cybersecurity posture is paramount to bring this issue to the forefront.
                  • The huge skills gap is making it impossible to simply throw more resources at the problem.
                  • It is a holistic issue, meaning that the skills gap needs to be filled and corporate culture needs to be improved before we see some improvement in CISO burnout.
                  • About Phishy Business

                    Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                    www.mimecast.com

                    30 min
                  • Criminals are like water, adapting to new circumstances

                    In this episode of Phishy Business, we discuss how criminals are like water because of how they flow, and adapt around obstacles and security measures, always looking for a way in no matter what security professionals put in their way. You’ll learn more about how well-thought-out cybersecurity strategies, tools, and responses can be, especially in the military vs. the private sector, and, why this needs to be the case when protecting users from very fluid criminals.

                    Our special guest is threat intelligence expert Jason Rivera, who is currently serving as a senior director in the Strategic Threat Advisory Group at CrowdStrike. He provides threat intelligence thought leadership to commercial and government organizations across the globe. Jason is an Army veteran who worked in cyber roles for the military, built cyber intelligence programs for civilian organizations, and today combines both of those elements of his experience into helping advise CrowdStrike and its customers on cybersecurity strategy.

                    In ‘Criminals Are Like Water, Adapting to New Circumstances’, we discuss:

                    • The military vs. the private sector and understanding how they are not always what they seem.
                    • Identifying the cyber domain as a new part of warfare, and how this is different from the traditional domains such as land, sea, and air.
                    • How the need to understand risk is ever-increasing and how to best deploy scarce resources.
                    • Identifying the various types of adversaries, what they’re motivated by, how they operate, and how they sometimes collaborate with each other.
                    • New trends in cybercrime such as callback phishing, data extortion, and multifactor authentication bypass, including what these are and how they work.
                    • Cybersecurity vendor collaboration and how a second opinion is healthy.
                    • How cybersecurity vendor integration and collaboration is increasing.
                    • Being happy at work because if you’re happy, a job doesn’t feel like work and that happiness leads to much more productivity.
                    • About Phishy Business

                      Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                      www.mimecast.com

                      35 min

                    About Phishy Business

                    From the publisher's feed

                    Ready to change how you think about cybersecurity?