
Sign up to save your podcasts
Or


Greg provides his post-RSA Conference report. We discuss the origins of worms and viruses, and continuous audit, Bill discloses his history in code testing, and why buffer overflows persist. We give a list of some cool AI-in-security use cases. There's even a SoundCloud analogy. And more!
Bill and Greg interview Richard Stiennon, who discusses his new book Security Yearbook 2020 and how it is a survey and history of the industry. We discuss that how non-security CEOs fare in the security market, and why non-security companies don't lead in security. And how awesome/nasty an "I Told You So, Security Edition" book would be, how small the cybersecurity industry is, and our favorite security leaders.
His book is available here: https://www.amazon.com/dp/1945254041/ref=cm_sw_em_r_mt_dp_U_VwxxEb5J3J4CW
We don't have one of those cool discount codes, but you can say "REALCYBERSECURITY" out loud when you order it and feel better.
Backdoors, software assurance, and supply chain are big topics in cybersecurity and related. Backdoors can be intentional or just sloppy design. The concern over manufacturer added backdoors in 5G has been a political and policy issue. Bill and Greg discover a shared love of Vancouver bar bands of the 80s, and Bill plants a Beastie Boys earworm.
5G security is a real cybersecurity topic (play on words intended). It's not just a mere upgrade from 4G, like 3G to 4G was. The architecture of wireless communication is changing and driving more and different edge computing - security changes with that new reality. And if that weren't enough buzzword-bingo, IoT security will change, and so will privacy and lawful intercept.
Bill and Greg measure the cybersecurity skills gap and find out that is may be measured in units of Mismanagementograms. Bill seems to know a lot of companies in Southern New Jersey. We give some career tips for anyone looking at getting into cybersecurity. Greg mentions feral donkeys, and rants about automated HR CV filters that filter out qualified candidates. Bill and Greg give shoutouts to unrecognized heroes of ITSecurity who deserve awards.
#cybersecurity #hacking #security #crytography
Bill and Greg are not experts in Identity and Authentication Management (IAM), but they have some opinions. Why "Passwordless Authentication" isn't. The business friction that is created by lazy authentication. We cover why we should start using the approaches of threat facing security for IAM - like the data lake of XDR to spot bad things, why not a similar approach of a bunch of data to spot good people and let them in? Bill discloses his long password.
Bill just returned from Japan and we discuss whether there are regional differences in cybersecurity. The focus of our talk is IoT, why we are still talking about IoT security, and why the standards efforts around IoT are misplaced. It finishes up with ... gasp.. actionable advice!
This is what the Real CyberSecurity Podcast is about. FUD-free analysis of the bigger topics in securing enterprises, with a guarantee of actionable advice in each weekly episode. Hosted by Bill Malik and Greg Young.
From the publisher's feed