Pwned: The Information Security Podcast

Pwned: The Information Security Podcast

By Justin FimlaidNewsBusiness News
Download on the App Store

Pwned: The Information Security Podcast episodes

  • Bonus: Top 3 of '23

    To wrap up 2023, we would like to take the chance to reflect on what we’ve all seen this year, and what has headlined our coverage here at Pwned. Come on along and relive three of our past episodes that created the most activity, and join us in seeing how far we’ve all come. 

    Our top 3 episodes from this year are: 

    1. Episode 170 - Staying on Course When You've Got Headwinds - a mailbag episode dedicated to a listener who's feeling the pressure to justify continuing cybersecurity spend. 
    2. Episode 166 - Rethinking Cyber Insurance to Help it Survive, and Thrive - an episode discussing the well-publicized comments from Zurich Insurance CEO Mario Greco on the potential demise of cyber insurance. 
    3. Episode 167 - Cybersecurity Seat - Hall-full/Half-empty, Have Patience - another mailbag episode about successful paths forward when a CISO find themselves in a role that's a little larger than they expected. 

    Your continued support means the world to us. Thank you, and we'll catch you in the new year. 

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor

    Instagram: https://www.instagram.com/nuharborsecurity/

    2 min
  • Episode 189 - Shaky Plans - Pwned Takes on the President's Blueprint for an AI Bill of Rights

    In the second part of our series on Federal AI proclamations, Justin and Jack make a point-by-point assessment of the Federal view on inalienable protections from AI misbehavior. If you’re concerned with AI’s incursions into everyday life or are interested in understanding whether our leaders have a grasp on the issues, this is an episode you can’t miss.

    AI is complicated. Cybersecurity is complicated. Political language is complicated. Your Pwned team is here to make things understandable. Tune in and find out.

    Check out the resources and references mentioned in this episode:

    Blueprint for an AI Bill of Rights

    Episode 188 - Safe, Secure, and Trustworthy. Pwned on the President's AI Executive Order

    Episode 182 - The Next AI Episode - With Diana Kelley!

    Key Takeaways:

    00:00 – Title Sequence

    00:22 – Introduction to the topic

    01:47 – Safe and Effective Systems: What Exactly Does That Mean?

    10:22 – Algorithmic Discrimination Protections: Put the Human in the Loop

    14:29 – Data Privacy: Understanding the Cost of Using Services

    20:05 – Notice and Explanation: Responsibility of Data Exposure

    22:05 – Human Alternatives, Consideration, and Fallback: Why? Because the Algorithm Says So

    24:23 – Closing Statements

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor

    Instagram: https://www.instagram.com/nuharborsecurity/

    28 min
  • Episode 188 - Safe, Secure, and Trustworthy. Pwned on the President's AI Executive Order

    In this episode, Justin and Jack are reviewing the recent presidential executive order on AI. While there are plenty of good ideas in the mix, the team is taking some time to examine their feasibility, their value, and their likelihood of execution in our current, fast-paced, AI environment.

     

    Stay tuned for part two on the Blueprint for an AI Bill of Rights!

    Check out the resources we referenced in this episode:

    FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence

    Episode 176 - Outcomes, Prescriptions, and Presidental Policy

    Key Takeaways:

    00:00 – Title Sequence

    00:27 – Topic Introduction

    01:16 – What is the Fact Sheet?

    01:44 – Software Security

    04:43 - New Standards for AI Safety and Security

    14:46 – Protecting American’s Privacy

    18:27 - Advancing Equity and Civil Rights

    21:06 – Supporting Workers: Adapting to New Innovations in the Workplace

    26:43 – Recap and Positive Note

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor

    Instagram: https://www.instagram.com/nuharborsecurity/

    30 min
  • Episode 187 - Pwned Making the Case for Judicial Security

    Following Justin's work with members of the press on the recent Kansas City court system ransomware shutdown, he and Jack are talking about the potential impacts and repercussions of increasing cyberattacks against the judiciary. There are issues of timely judgements, sealed records, even courts paying criminals, as the Pwned team judges the situation and brings some new evidence to the discussion of causes and prevention.

    See Justin in the press: https://www.wibw.com/2023/10/19/cybersecurity-expert-explains-issues-facing-kansas-courts-they-remain-offline/.

    Key Takeaways:

    00:00 – Title sequence

    00:22 – Introduction

    00:51 – Incident Details

    01:42 – Courts shut down: back to basics

    04:10 – Chain of custody in the event of a ransomware attack?

    05:13 – Justin’s press presence: analogies

    06:48 – Courts paying criminals?

    07:18 – ETA for opening the courts

    09:32 – Targets and motivation

    11:23 – Are attackers getting all information, or are there barriers for information that should be protected?

    14:04 – CJIS

    16:15 – Digitizing paper files for security

    17:20 -- Recap

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor

    Instagram: https://www.instagram.com/nuharborsecurity/

    19 min
  • Episode 186 - The Acquisition of Revelstoke

    In this episode of Pwned, Justin and Jack discuss the recent acquisition of automation firm Revelstoke by managed security vendor Arctic Wolf. With a lot of cash on the line, is this deal a right swipe, or do they think Arctic Wolf will be left in the dark when the lights come up? Tune in for the details.

    Key Takeaways:

    00:00 – Title sequence

    00:28 – Introduction to acquisition

    02:04 – Financial details

    04:53 – Analogy: A nickel for a dollar

    06:53 – Convertible Note details

    08:20 – Jack’s decision

    10:00 – Justin’s response

    11:29 – Justin’s decision

    12:05 -- Recap

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor

    Instagram: https://www.instagram.com/nuharborsecurity/

    21 min
  • Episode 185 - An Unconventional Take on Cybersecurity Awareness

    In this episode of Pwned, Justin and Jack tackle Cybersecurity Awareness Month 2023. Coming at you with three unconventional tips to keep in the back of your mind, the duo dive into the world of security for vendors, purchasers, and members of the public. 

     

    Key takeaways

    00:00 – Title Sequence

    00:34 – Introduction to Cybersecurity Awareness Month

    01:36 – What does security awareness mean?

    02:40 – More heightened cybersecurity awareness this year overall

    05:12 – More informed public = more informed questions

    06:34 – The market is demanding more secure software and services

    07:11 – Tip #1: Be aware that it’s okay to ask for things to be secure enough

    07:49 – Analogy: Cybersecurity awareness = healthcare/consumer medicine awareness

    09:19 – What was it that made the provider think this service is good for you?

    10:04 – Providers will try to sell you their product, not what you need

    12:32 – Tip #2: Awareness = How can we all work to make things better both at work and at home?

    14:31 – Blockbuster: People shouldn’t have to be so cybersecurity-aware

    15:43 –Make security seamless, so people don’t have to worry about it in their day-to-day

    16:55 – Give your network the ability to filter out malicious content so it’s not on the backs of your employees

    17:58 – Tip #3: Vendors be aware of the vulnerabilities caused by too much functionality

    19:13 – Recap

    If you have any questions or suggestions, send us an email at [email protected]. 

    For general information, you can reach us at [email protected]. 

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one. 

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. 

    Website: https://nuharborsecurity.com 

    Facebook: https://www.facebook.com/nuharbor/ 

    Twitter: https://twitter.com/NuHarbor 

    LinkedIn: https://www.linkedin.com/company/nuharbor 

    Instagram: https://www.instagram.com/nuharborsecurity/

    21 min
  • Episode 184 - 4 Steps to a Security Strategy

    In this episode of Pwned, Justin and Jack are evaluating a four-step process for developing a cybersecurity strategy and end up creating one of their own. If you’re looking for some ideas or a blueprint for your own planning, it’s probably worth a listen. Stay tuned for our upcoming blog: 4 Steps to a Rock-Solid Cybersecurity Strategy for an in-depth look at what we came up with! 

    As a recap, here are our four steps to a cybersecurity strategy:

     

    Step 1: Ask and Understand

    The single most important component in every cybersecurity strategy is understanding your business thoroughly. 

    Step 2:

    Apply Your Expertise With a deep understanding of your business in place, you are now ready to apply your knowledge to define the appropriate security controls and measures. 

    Step 3: Measure Progress

    Now that you have your security controls in place, it's time to assess how well you're implementing them. This step involves measuring your progress and identifying any gaps. It's also an opportunity to involve key stakeholders and keep them informed. 

    Step 4: Create and Communicate

    The final step involves formalizing your cybersecurity strategy and ensuring its ongoing relevance and effectiveness. It's about creating a living, breathing strategy that evolves with your organization's needs. 

    Key elements of this episode: 

    0:26 – Introduction to 4 steps to build a cybersecurity strategy 

    2:32 – Know your organization’s tolerance for risk mitigation 5:04 – Planning roadmaps for internal success 

    5:33 – These four steps are a great starting point, but they won’t get you all the way home 

    6:02 – Crucial missing piece: Your cybersecurity strategy should start with your business strategy 

    7:33 – Building a cybersecurity strategy = building a house 

    9:07 – Meet the organization where they're at 

    11:49 – Educate organizations on what they need to know for their security strategy 

    13:09 – NuHarbor’s 4 steps to creating a cybersecurity strategy 

    14:00 – Step 1 – Ask and Understand 

    18:08 – Step 2 – Apply Your Expertise 

    21:24 – Step 3 – Measure Progress 

    24:58 – Step 4 – Create and Communicate 

    If you have any questions or suggestions, send us an email at [email protected]. 

    For general information, you can reach us at [email protected]. 

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one. 

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. 

    Website: https://nuharborsecurity.com 

    Facebook: https://www.facebook.com/nuharbor/ 

    Twitter: https://twitter.com/NuHarbor 

    LinkedIn: https://www.linkedin.com/company/nuharbor 

    Instagram: https://www.instagram.com/nuharborsecurity/

    33 min
  • Episode 183 – Making a New Cybersecurity Job Work

    In this mailbag episode of Pwned, Justin and Jack respond to a listener question that has all the earmarks of a well-known security problem: a new leader starting in an organization with what feels like a random mix of products and problems. By talking through the different elements of the situation, the team offers proven and straightforward suggestions for making the transition more action-oriented, more measurable, and much less stressful.

    Check out this week’s video:

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com

    Facebook: https://www.facebook.com/nuharbor/

    Twitter: https://twitter.com/NuHarbor

    LinkedIn: https://www.linkedin.com/company/nuharbor/

    Instagram: https://www.instagram.com/nuharborsecurity/

    13 min
  • Episode 182 – The Next AI Episode – With Diana Kelley!

    This week, Justin and Jack are talking AI with one of the security industry’s most well-known experts and influencers, Diana Kelley of Protect AI. The topics, like the growth of AI, are all over the place, from the impacts of AI on security teams to secure AI development, and even a quick mention of the rights of sentient AI. Come hear what’s new in ML SecOps and high-integrity AI, and some well-informed predictions for the future.

    If you want to get in touch with Diana, you can find her LinkedIn here.

    Check out this week’s video:

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com
    Facebook: https://www.facebook.com/nuharbor/
    Twitter: https://twitter.com/NuHarbor
    LinkedIn: https://www.linkedin.com/company/nuharbor/
    Instagram: https://www.instagram.com/nuharborsecurity/

    34 min
  • Episode 181 – Breached Trust: Lazarus Making Friends

    In this breach of the week episode, Justin and Jack look into the recent attacks targeting the GitHub developer community. Developers are increasingly being targeted by North Korean state-sponsored threat actors to use and execute poison code. Tune in to get the scoop.

    The DarkReading article can be found here: North Korean Cyberspies Target GitHub Developers (darkreading.com)

    CISA’s request for comment can be found here: Request for Comment on Secure Software Self-Attestation Common Form | CISA

    Watch this week’s video:

    If you have any questions or suggestions, send us an email at [email protected].

    For general information, you can reach us at [email protected].

    If you like our content, please like, share, and subscribe! We’ll catch you on the next one.

    Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.

    Website: https://nuharborsecurity.com
    Facebook: https://www.facebook.com/nuharbor/
    Twitter: https://twitter.com/NuHarbor
    LinkedIn: https://www.linkedin.com/company/nuharbor/
    Instagram: https://www.instagram.com/nuharborsecurity/

    19 min

About Pwned: The Information Security Podcast

From the publisher's feed

Pwned is a weekly information and cyber security podcast addressing real-world security challenges. Occasionally funny, always informational, and driven by those who live and breathe security. Each…