Phishy Business

Phishy Business

By MimecastTechnology
Download on the App Store

Phishy Business episodes

  • Risk, Risk, Risk…and Beer: What Keeps the Cyber C-Suite Up at Night

    In this episode of Phishy Business, we find out everything you may have wanted to ask your CISO or CIO but were too afraid to ask. Two very experienced information technology leaders delve deeper into the roles they play in keeping their organizations safe while balancing the nos and yesses they deal in every day. You’ll learn a lot more about that it is like to be CISO or CIO and the challenges they face in their roles.

    Our special guests are Magnus Carling, CISO at Swedish shipping company Stena, and Andrew Pritchett, CIO at Grant Thornton Australia, a leading accounting and consultancy firm. Magnus runs the global information security program for shipping conglomerate Stena, which is made up of a number of companies. Andrew navigates the challenges of the CIO role to balance pleasing clients while at the same time keeping client and internal resources safe. Learn more about these two leaders and their real-world daily challenges.

    In ‘Risk, Risk, Risk…and Beer: What Keeps the Cyber C-Suite Up at Night’, we discuss:

    • What it is like being considered the department of no by colleagues.
    • The challenges of balancing protecting the organization with the needs of team members.
    • The crossroads of tech and people that occur every day at every organization.
    • How the weakest link in security can be people – and how to get that point across to those very same people.
    • The problems IT leaders face when the board don’t speak cyber.
    • How to bring cyber risk in earlier in the board’s conversations.
    • Conducting proper risk assessment before the big decisions instead of dealing with the fallout after an attack.
    • Keeping cyber teams together and not burning them out.
    • The difference between responsibility and accountability for CISOs in cyber breaches.
    • Why the need for CISOs to have battle scars from previous breaches is so valuable.
    • Beer as a stress relief strategy.
    • Why cybersecurity is everyone’s business.
    • About Phishy Business

      Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

      www.mimecast.com

      37 min
    • Is Data the new Uranium?

      In this episode of Phishy Business, we take a look at data, which some have called the new gold or the new oil and discuss why it really is something more like the new uranium because it has such a huge potential to impact society, just like uranium did in the 20th century. And just like uranium, data can be used for good, and for bad. Join us as we delve further into all things data – how it is collected, used, and what the consequences are when it is leaked.

      Our special guest is Glenn Wilkinson, world-renowned cybersecurity expert and ethical hacker for organizations ranging from startups to multi-nationals and governments. Glenn is an ethical hacker for hire who helps organizations protect themselves against real-world attackers by simulating real-world attacks. He also builds security products, conducts training sessions, and gives talks on cybersecurity.

      In ‘Is Data the new Uranium?’, we discuss:

      • The types of data that can be compromised during a security breach and what can be the most valuable data to malicious hackers.
      • The voluntary, involuntary, and necessary data we share every day, some of which is essential to live in the modern world.
      • The huge amount of personal information that is housed on social media and with other companies that claim to provide personalized services.
      • How companies want our data to sell us more personalized ads and to also sell it on to third parties.
      • The fact that companies are also collecting our personal data simply because they can – and how they are planning to figure out what to do with it later, using AI to process it for example.
      • If we are at the point in history where we can call data the new uranium because in that sense, it could contain information that if monetized, could have profound societal impact.
      • Data, and how the aggregation of it can also be used by less democratic regimes to spy on and control their population.
      • Using Glenn’s top three tips that could help you and the data you share online stay secure.
      • About Phishy Business

        Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

        www.mimecast.com

        22 min
      • Supercharging the AI tortoise

        In this episode of Phishy Business, we take a look at AI. We talk on the fact that the stigma of AI running amok in Terminator-fashion is a myth we must dispel in the face of all the good AI can do in protecting the world - from cyberattacks to helping with climate change. We also talk about the other major challenges that AI can be used to solve globally in the next decade. Our special guests are Vilas S. Dhar, President of the Patrick J. McGovern Foundation, who was named a young global leader by the World Economic Forum, and our own AI data scientist Elaine Lee. Vilas originally trained as a computer scientist who worked on early AI, also went to law school, and then worked on rule of law in technology, finally moving on to build a few businesses in the private sector. Elaine uses her expertise as a data scientist to help create products that protect users against email cyberthreats and was recently promoted to manage a team of data scientists at Mimecast.

        In ‘Supercharging the AI Tortoise’, we discuss:

        • How optimism is essential to taking control of what we want AI systems to do.
        • The sense of urgency that is needed in this work to protect people today and in the future.
        • Why human oversight of AI systems is crucial to course correct and to remove biases in the algorithms.
        • How diversity is fundamental in creating AI systems.
        • The fact that more needs to be done in relation to how AI can be a force for good, from educating policy makers to more positive media coverage.
        • How AI and data science can be used to created sustainable and scalable progress on the big issues our society faces, such as climate, poverty, and hunger.
        • The reasons why Winnie the Pooh is possibly the greatest modern philosopher of our era.
        • About Phishy Business

          Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

          www.mimecast.com

          31 min
        • Beyond Awareness Training: How to Improve User Behavior

          In this episode of Phishy Business, we take a look at how cybersecurity awareness training needs to go beyond just having users sit through training, but in fact, has to work to change user behavior. Listen in to learn more about the importance of cybersecurity awareness training at organizations of all sizes across the globe and how, with today’s diverse and threatening security landscape, cybersecurity is the responsibility of everyone in the organization, not just security professionals. Our special guests are Ira Winkler, award-winning CISO and best-selling author of Security Awareness for Dummies, and our own cybersecurity training expert Duane Nicol, Senior Product Manager – Awareness Training at Mimecast. Ira works to help organizations become more resilient against cyberattack and Duane works to make people feel more involved and included as part of the cybersecurity awareness culture at an organization, driving measurable results.

          In ‘Beyond Awareness Training: How to Improve User Behavior’, we discuss:

          • How cybersecurity awareness is part of everyone’s job responsibility.
          • Why the outcome of cybersecurity awareness training shouldn’t just be awareness, but also should be behavior change.
          • The importance of a just corporate culture to encourage employees to report mistakes.
          • The difference between ‘must’ and ‘should’.
          • Whether or not there is ever a role for blame in cybersecurity awareness training.
          • The fact that measurement of cybersecurity awareness programs is crucial.
          • Why if a user clicks on a phishing link, the failure happened much further upstream because a lot of technology had to fail to let that malicious email through, and why holistic remediation is necessary.
          • About Phishy Business

            Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

            www.mimecast.com

            34 min
          • Shining a Light on Bots: The Good and the Bad

            In this episode of Phishy Business, we take a look at bots. Listen in to learn more about what bots are, and what they do. Also, learn what can make them good…and what can make them bad. It would seem the answer lies within the intent of the person deploying them. Our special guests are Cyril Noel-Tagoe, Principal Security Researcher at Netacea, and our own Dr. Kiri Addison, Senior Product Manager at Mimecast. Cyril works to understand automated attacks to discover their aim and how to stop them; Kiri is a senior product manager and all-around cybersecurity expert who has a good amount of experience discovering and combatting malicious bots.

            In ‘Shining a Light on Bots: The Good and the Bad’, we discuss:

            • Some examples of good and bad bots, and how they can be used and misused.
            • How bad bots are responsible for as much as 3% of revenue loss.
            • That bots can be used in all kinds of cyberattacks, including phishing, and DDoS attacks.
            • How bots can skew website metrics, which can falsify entire marketing campaigns.
            • That bots are also used to automate tasks for cybercriminals such as validating credentials.
            • The fact that Marketing and IT teams should work together to understand the problem of malicious bots and discover how to best combat them.
            • The ways bots can also be used defensively, against cyberattacks.
            • How the fact remains: If the promises of a product or service sound too good to be true, they probably are.
            • About Phishy Business

              Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

              www.mimecast.com

              31 min
            • The Billion Dollar Cryptocurrency Scam

              In this episode of Phishy Business, we take a look at what has been called the smartest and biggest scam of the 21st century, OneCoin, a cryptocurrency that brought in $4 billion in investments via multi-level marketing and proved to be nothing but a scheme that made one woman who is still on the run very rich. This wasn’t a backroom con, but in fact, was perpetrated by a woman whose adoring fans filled an arena two years after OneCoin’s founding, and whose con took money from millions of people. Our special guest is Jamie Bartlett, author of The Missing Cryptoqueen: The Billion Dollar Cryptocurrency Con and the Woman Who Got Away with It, a book that started out as a podcast in which Jaime tells the all-too-true tale of Dr. Ruja Ignatova, the Oxford-educated fugitive who got away with billions.

              In ‘The Billion Dollar Cryptocurrency Scam’ we discuss:

              • How Jaime discovered this amazing story after presenting his findings following an investigation into drug sales on the Dark Web and was approached by a fellow journalist who was propositioned with this too-good-to-be-true cryptocurrency scam.
              • A little background on cryptocurrency, its history, and how it works, as well as how Dr. Ruja presented a story and a cryptocurrency that was so appealing to so many people.
              • How cryptocurrencies currently make ideal attack vectors for scammers.
              • How FOMO is a very powerful tool in the cybercriminal arsenal and how it worked for Dr. Ruja.
              • Why most people’s murky understanding of the tech behind cryptocurrency allowed the alleged victims to be more easily duped by Dr. Ruja and her real and impressive credentials
              • Why cries of OneCoin being a Ponzi scheme from the very beginning went unheeded by investors and regulators.
              • How a simple selfie posted on social media can reveal a treasure trove of information for investigators…and for cybercriminals.
              • If the promises of a product or service sound too good to be true, they probably are.
              • About Phishy Business

                Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                www.mimecast.com

                32 min
              • Closing the cybersecurity skills gap through education and opportunity

                In this episode of Phishy Business, we take a look at the skills shortage being faced by IT departments when it comes to hiring cybersecurity experts and how the Absa Cybersecurity Academy is working with its partner, the Maharishi Institute, to assist in helping marginalized South African youth to become certified cybersecurity experts. Together, Absa and the Maharishi Institute are consistently working to develop a sustainable means to give youth the training they need to maintain careers and break the cycle of poverty they have been born into. Our special guests are Shenaaz Abrahams, who has made it her mission to ensure the Absa Academy is giving the most marginalized in her community access to cybersecurity training, and one of the Absa Academy’s success stories, student Kerwin Jacobs.

                In ‘Closing the cybersecurity skills gap through education and opportunity’ we discuss:

                • What the Absa Cybersecurity Academy is, and its aim
                • The holistic learning experience at the Maharishi Institute, which includes a lot of self-development and getting to learn things like transcendental meditation
                • Absa’s latest partnership with the Hein Wagner Academy and teaching cybersecurity skills to the visually impaired
                • The opportunities for Africa to be a cybersecurity hub and how the continent can help plug the global skills gap while offering employment opportunities in a market with a high unemployment rate
                • Why individuals from disadvantaged backgrounds – like those enrolled at the academy – make good cybersecurity professionals
                • How the academy has impacted Kerwin’s life
                • Some inspiring stories about other students enrolled in the academy
                • About Phishy Business

                  Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                  www.mimecast.com

                  33 min
                • Actors, tabletop exercises, and insider threats

                  In this episode of Phishy Business, we take a look at cyber crisis exercises and insider threats. Our special guest is Lisa Forte, an expert on running cyber crisis exercises and training high-risk staff on insider threats and social engineering, who was named one of the top 30 female cybersecurity leaders by SC Magazine. Lisa works hard to simulate cybersecurity disasters for organizations in order to train them in how to deal with real-world cyberattacks. Lisa shares her insights on cyber crisis exercises and preparing organizations on how to handle cyberattacks as well as how to prevent insider threats.

                  In ‘Actors, tabletop exercises, and insider threats’ we discuss:

                  • The fact that 70% of organizations in EMEA do not have a plan for dealing with insider threats despite it being a growing risk.
                  • How insider threats can be both accidental and malicious, different ways to look at the term “insider threat”, and some of the factors that may play into people becoming insider threats.
                  • How to balance fear and empowerment to get every employee to care personally about an organization’s cybersecurity, and how cybersecurity needs to be marketed internally to people across the organization.
                  • Some of the creative ways to use role-playing and acting in cyber crisis exercises to make simulations as real as possible, which is key to educating teams in dealing with cyberattacks.
                  • Top tips for getting started with a plan to deal with insider threats and cyberattacks and the importance of explaining to key personnel that just having backups really is not a solid plan for dealing with today’s threats.
                  • The importance of a happy workforce, properly and legally monitoring for insider threats, and tech-for-good and cybersecurity-for-good initiatives.
                  • Why CISOs might benefit from rock climbing 
                  • About Phishy Business

                    Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                    www.mimecast.com

                    31 min
                  • The Internet Tattoo Effect and common sense online safety

                    In this episode of Phishy Business, we take a look at ways for children and teens to stay safe while online. Our special guest is Emma Sadleir, a leading expert in social media law who educates individuals and organizations about the legal, disciplinary, and reputational risks of social media. Emma is also the co-author of Selfies, Sex, and Smartphones: A Teenager’s Online Survival Guide, which explains the legal pitfalls, hidden dangers, and future implications of what teens do, see, and post online. Emma shares her insights on using common sense to stay safe when participating in social media.

                    In ‘The Internet Tattoo Effect and Common Sense Online Safety’, we discuss:

                    • What children and teens should and should not put online, or even commit to digital content, and the limitations of the billboard test (don’t post online what you would not put on a billboard next to a photo of yourself on the side of the highway) in today’s online world.
                    • How digital content is dangerous because it is out of our control, even when we think we are in a private online setting, and how deepfake technology is beginning to become a big problem.
                    • The legal guidebooks Emma has had a hand in creating and the benefits they provide for readers.
                    • The six p’s (police, parents, principals, predators, prospective schools/employers, phishers) that teenagers should keep in the back of their minds when posting content or interacting online.
                    • How parents can keep their heads above water while trying to maintain their child’s online safety in today’s online world.
                    • How the lines between the real world and the digital world are fading – we need to now consider the digital world as an extension of the real world.
                    • The age at which children should be allowed online and the fact that the Internet has no “shallow end” in which to get acclimated.
                    • Whether or not social media platforms are doing enough to protect children online? Learn why Emma says they are not.
                    • The steps children themselves can take and the tools they can use to maintain their safety online.
                    • About Phishy Business

                      Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                      www.mimecast.com

                      34 min
                    • Advanced Persistent Threat Groups: Preparing Instead of Hoping

                      In this episode of Phishy Business, we take a look at advanced persistent threat groups, also known as APT Groups. Special guest Krijn de Mik, Incident Response and Intelligence Lead at Hunt & Hackett, where he specializes in investigations, forensic analysis, and tracking threat actors and threat actor groups, gives his insight on how organizations can protect themselves from APT Groups and their advanced cyberattacks. 

                      In ‘Advanced Persistent Threat Groups: Preparing Instead of Hoping’, we discuss:

                      • What advanced persistent threat groups are, their tactics, their motivations, how large and organized they can be, and why we distinguish them as threat actors
                      • The ransom amounts that APT Groups seek, how and why the amounts differ by industry and victim, and the three most targeted industries (listen to learn which three)
                      • To pay or not to pay – some of the things that organizations should consider and what they should do when it comes to making this decision
                      • How prevention remains an organization’s best bet and how prevention tactics such a table-top and crisis management exercises can help organizations prepare for attacks and reduce chaos
                      • One of the largest-scale and most fascinating APT group hacks Krijn and Hunt & Hackett have investigated
                      • The importance of:
                      •     o Forensic readiness and how it can be achieved

                            o Two-factor authentication

                            o Backups and how organizations need to ensure they are complete

                        About Phishy Business

                        Fed up with the same old cybersecurity stories? Come with us on a journey that explores the lesser-known side. Whether it’s social engineering, taking criminals to court or the journalists hunting down hackers — our new podcast series, Phishy Business, looks for new ways to think about cybersecurity. Mimecast’s very own Brian Pinnock and Alice Jeffery are joined by guests from a range of unique security specialisms. Each episode explores tales of risk, reward and just a dash of ridiculousness to learn how we can all improve in the fight to stay safe. For more tales of risk, reward and ridiculousness, subscribe to Phishy Business on iTunes, Spotify, Anchor or wherever you get your podcasts.

                        www.mimecast.com

                        26 min

                      About Phishy Business

                      From the publisher's feed

                      Ready to change how you think about cybersecurity?