
Sign up to save your podcasts
Or


In this Their Story podcast episode, Paul Valente and Russell Sherman discuss the challenges faced by both small and large enterprises when sharing data and managing risk with business partners and third party providers. They share their experiences working together in the past where they needed to balance addressing security concerns with closing deals. The duo highlights the importance of proper scoping and understanding the context of a business relationship to help assess inherent risks.
Paul and Russell also share details of their third party risk management platform which allows users to quickly scope and define attributes of a business relationship, providing an inherent risk rating. The platform uses over 800 data points and references over 25 frameworks, streamlining the process for both the assessor and the assessed. By utilizing natural language processing (NLP) and artificial intelligence (AI), the platform is able to analyze collected data, automate manual aspects of the review process, and provide valuable insights to help make better, faster, and more contextually-relevant informed decisions.
The pair further emphasize the importance of reducing friction in the assessment process, which led them to focus on eliminating the need for lengthy questionnaires and instead utilizing existing artifacts to assess a company's security posture. This innovative approach reduces the burden on both the assessor and the assessed while providing a more accurate and comprehensive view of a company's cyber risk.
Overall, this episode provides valuable insights into how technology is transforming the traditional third-party cyber risk assessment process and paving the way for a more efficient and secure future.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guests:
Paul Valente, CEO & Co-founder at VISO TRUST [@VISOTrust]
On LinkedIn | https://www.linkedin.com/in/pauldvalente/
Russell Sherman, Co-founder and CTO at VISO TRUST [@VISOTrust]
On LinkedIn | https://www.linkedin.com/in/neverenoughinfo/
On Twitter | https://twitter.com/russellsherman
Resources
Learn more about VISO TRUST and their offering: https://itspm.ag/visotrust8x4i
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
Mayuresh Ektare, an expert in risk management and SVP of Product Management at Brinqa, joins Sean Martin for a quick dive into the world of centralizing risk management frameworks. Ektare explains that the magic sauce isn't just bringing the data together, but stitching it together to create a unified understanding of an organization's attack surface. By overlaying business context, customers can prioritize and act upon the right set of findings in a timely fashion. Martin and Ektare discuss the challenges faced by customers in finding a centralized repository for business context, with many relying on tribal knowledge or CMDB records.
Ektare introduces the concept of a Risk Operations Center (ROC), which allows organizations to orchestrate the risk lifecycle and proactively reduce exposure. Comparing it to a Security Operations Center (SOC), he highlights the importance of extending vulnerability management programs to encompass cloud infrastructure and application security posture management. The conversation also touches on the challenges of managing false positives and distilling a vast amount of findings into actionable items. By overlaying business context and understanding the impact of vulnerabilities on their organization, customers can fine-tune security scores, prioritize effectively, and respond accordingly.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guest:
Mayuresh Ektare, SVP of Product Management at Brinqa [@brinqa]
On Linkedin | https://www.linkedin.com/in/mektare/
Resources
Learn more about Brinqa and their offering: https://itspm.ag/brinqa-pmdp
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
The rapid evolution of technology has ushered in the API revolution in cybersecurity, transforming the way organizations navigate an AI-driven threat and security landscape. As CTOs and CISOs grapple with the delicate balancing act of managing risk and innovation, they must adapt to the demands of securing a modernized world. This postmodern paradigm shift in cybersecurity necessitates a comprehensive understanding of emerging trends and cutting-edge solutions to effectively safeguard our increasingly interconnected digital ecosystem.
Dive into this captivating podcast episode featuring Kunal Anand, the CTO and CISO of Imperva, as he discusses the evolving world of cybersecurity and the impact of emerging technologies such as artificial intelligence. Alongside host Sean Martin, Kunal shares his experiences as both a CTO and CISO, highlighting the importance of peer-to-peer collaboration and the integration of modern technologies in the cybersecurity landscape.
Kunal and Sean delve into the significance of APIs in modern applications and the challenges of securing them in the face of ever-increasing data breaches. They also explore the transformative power of AI in both offensive and defensive security, including its role in enhancing productivity and effectiveness in cybersecurity efforts crossing all cybersecurity roles from analyst to executive.
Kunal also shares his insights into the future of cybersecurity and the need for the industry to embrace AI and other emerging technologies. This discussion offers valuable perspectives for anyone interested in understanding the evolving challenges and opportunities in the cybersecurity world. Don't miss this chance to learn from someone who thinks differently, thinks creatively, and thinks broadly about the challenges we face and the paths we can take to overcome them.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guest:
Kunal Anand, CTO and CISO at Imperva [@Imperva]
On Linkedin | https://www.linkedin.com/in/kunalanand/
On Twitter | https://twitter.com/ka
Resources
Learn more about Imperva and their offering: https://itspm.ag/imperva277117988
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
In this Their Story podcast episode, Pam Murphy, CEO of Imperva, talks to Sean Martin about the challenges facing businesses in terms of cybersecurity.
Murphy explains that data is the most valuable asset of any company and that protecting data is a vital aspect of cybersecurity. Murphy discusses the growing importance of APIs in the current environment, and how securing APIs is a challenge for CISOs, with many Shadow APIs being used. Murphy also notes that the regulatory aspect of security is increasing, with more rules and regulations emerging around the world.
Businesses face reputational risk and can suffer major operational disruption as a result of a breach, making security more important than ever. Murphy explains how Imperva helps customers protect their data, applications, and APIs from cyberattacks, and discusses the need for security vendors as trusted partners to focus on time to value and total cost of ownership, especially given the growing skills shortage in the security sector.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guest:
Pam Murphy, CEO at Imperva [@Imperva]
On Linkedin | https://www.linkedin.com/in/pam-murphy-a5297915/
On Twitter | https://twitter.com/PamMurphyInTech
Resources
Learn more about Imperva and their offering: https://itspm.ag/imperva277117988
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
In this Their Story podcast, Sean Martin talks with Matthew Vinton and Sergey Medved from Quest about the challenges associated with Active Directory (AD) and the importance of these systems in a company's overall security methodology and posture.
Active Directory remains an integral part of an organization’s IT infrastructure as it is the pillar of identity that most organizations use to enable their workforce, partners, and business processes. The trio discusses how Quest helps companies manage their AD environment across a variety of functional areas like assessing the environment, detecting changes, putting in preventive controls, and guiding response and recovery.
They also cover the growing challenges security leaders face concerning AD and the gap between the people in the trenches and business leaders who may not understand the inherent importance of AD. Exacerbating this reality is the ongoing security talent shortage, where few new entries into the field learn the technology as it is not as forward-looking when compared to Azure.
About the Cybersecurity risk management for Active Directory from Quest
Microsoft Active Directory (AD) is under attack. That’s why cybersecurity risk management is so important. With 95 million attempted AD attacks every day, it should be no surprise to hear AD was the target of another cybercrime. But these concerns aren’t contained to on-prem AD; in 2021 alone, there were more than 25 billion Azure AD attacks. It’s clear cybersecurity risk management needs to be a consideration, and even if the issues you’ve encountered aren’t intentional or nefarious, you still need to be prepared for the worst.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guests:
Matthew Vinton, Strategic Systems Consultant at Quest [@Quest]
On Linkedin | https://www.linkedin.com/in/matthew-vinton/
On Twitter | https://twitter.com/Mister_momentum
Sergey Medved, VP, Product Management and Marketing at Quest [@Quest]
On Linkedin | https://www.linkedin.com/in/sergeym/
Resources
Learn more about Quest: https://itspm.ag/quest-adp23
Learn more about the Quest Cybersecurity for Active Directory Solution: https://itspm.ag/quest-pp49
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
In this podcast, Mathieu Gorge, CEO and founder of VigiTrust, talks with Sean Martin about GRC (Governance, Risk, and Compliance) software. Gorge's award-winning VigiOne tool enables clients to prepare for, validate, and manage continuous compliance with more than 100 security frameworks worldwide.
Gorge also discusses the idea that security is a journey, not a destination, and how risk surfaces change continually. He recommends choosing a GRC platform that allows different stakeholders to view risk from different perspectives. Gorge also discusses his Five Pillars of Security framework, which focuses on physical security, people's security, data security, infrastructure security, and crisis management. Gorge also talks about the VigiTrust Global Advisory Board, a think-tank that brings together people from all over the world to discuss topics such as geopolitical risk, critical infrastructure protection, and diversity and inclusion in cybersecurity.
The risk conversation has become a hot topic. Listen in to this episode to think differently about how you approach, analyze, and address the risk your organization faces.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guest:
Mathieu Gorge, CEO at VigiTrust [@VigiTrust] - Chairman of the VigiTrust Global Advisory Board
On Linkedin | https://www.linkedin.com/in/mgorge/
On Twitter | https://twitter.com/MatGorge
Resources
Learn more about VigiTrust and their offering: https://itspm.ag/vigitrust04e618
More about Mathieu Gorge: https://mathieugorge.com/
Book | The Cyber Elephant in the Boardroom: Cyber-Accountability with the Five Pillars of Security Framework: https://mathieugorge.com/book/
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
Guests:
Leah McLean, Vice President - Cybersecurity Specialist, Mastercard Data & Services [@Mastercard]
On LinkedIn | https://www.linkedin.com/in/leahrmclean/
On Twitter | https://twitter.com/lmclean
Diana Kelley, Chief Security Officer / Chief Strategy Officer, Cybrize
On LinkedIn | https://www.linkedin.com/in/dianakelleysecuritycurve/
At RSAC | https://www.rsaconference.com/experts/diana-kelley
Davi Ottenheimer, VP Trust and Digital Ethics, Inrupt [@inrupt]
At RSAC | https://www.rsaconference.com/experts/Davi%20Ottenheimer
____________________________
Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
____________________________
This Episode’s Sponsors
BlackCloak | https://itspm.ag/itspbcweb
Brinqa | https://itspm.ag/brinqa-pmdp
SandboxAQ | https://itspm.ag/sandboxaq-j2en
____________________________
Episode Notes
In this panel, we will explore the potential impact artificial intelligence technologies can have on the role of the security analyst and security operations. How can these technologies be used for:
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac23sp
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Be sure to share and subscribe!
In this Their Story podcast on ITSPmagazine, Huxley Barbee delves into the world of InfoSec and asset management, discussing the importance of having a full asset inventory and how his company, RunZero, addresses this challenge with a cyber asset management solution.
Founders HG Moore and Chris Kirsch identified the need for better tooling as security teams' scopes expanded beyond managing traditional IT devices to securing IoT and OT devices across various environments. RunZero helps organizations understand gaps in security controls coverage, identify potentially vulnerable devices in the face of zero-day threats, and more.
Huxley Barbee explains that a full asset inventory, including asset details like location within the network, device function, and business context, can assist in determining which vulnerabilities or misconfigurations need immediate attention. Huxley highlights the delicate process of gathering information on devices and the importance of incremental fingerprinting, particularly in OT environments and those with often-unmanaged IoT devices.
The trio also cover the business side, discussing the typical clients for RunZero and the mindset shift required to realize that existing asset discovery tools may not be sufficient. They discuss the collaboration between IT, OT, and security teams, emphasizing that having a full cyber asset inventory beyond the traditional IT asset inventory can help reduce remediation time and improve overall business decision-making.
Tune in to this episode to learn more about RunZero's modern approach to asset management, the crucial role of visibility in addressing security challenges, and how a robust asset inventory by RunZero can help businesses leaders and security practitioners make better decisions.
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guest: Huxley Barbee, Security Evangelist at RunZero [@runZeroInc] and lead organizer for BSides NYC [@bsidesnyc]
On LinkedIn | https://www.linkedin.com/in/jhbarbee/
On Twitter | https://twitter.com/huxley_barbee
On Mastodon | https://infosec.exchange/@huxley
Resources
Learn more about RunZero and their offering: https://itspm.ag/runzervvyh
Catch the video and podcast version of this conversation: https://itspmagazine.com/their-stories/its-difficult-to-secure-the-invisible-reinventing-asset-management-for-modern-challenges-in-it-iot-and-ot-a-runzero-story-with-huxley-barbee
BSides NYC Podcast: https://itsprad.io/event-coverage-1388
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
In this engaging conversation, industry experts discuss the value of mainframes, the importance of cybersecurity, and how businesses can benefit from implementing mainframe technology in a secure manner. Join Sean Martin, Phil Buckellew, and Cynthia Overby as they explore real-world use cases, share valuable insights, and discuss innovative solutions to modernize and secure mainframe infrastructures. They also discuss the importance of not only focusing on the technical aspect of mainframes but also understanding the business operations and end-user needs.
Cynthia Overby shares an experience she had with a client who believed that securing their mainframe would prevent access to their customers. She emphasizes the importance of finding a balance between security and accessibility. Automated tools and the zero-trust framework are crucial in achieving this balance.
Phil Buckellew highlights the value that Cynthia's team brings to Rocket Software due to their deep and extensive experience in mainframe security. KRI and Rocket Software, together, strive to make security a part of everything they do, ensuring transparency and seamless integration. The pair also discuss the challenges and benefits of migrations to and from mainframe environments.
Phil explains that the value of mainframes lies in their continuity, scalability, and high availability. These factors make them attractive to businesses that prioritize secure and reliable transaction processing. Cynthia adds that mainframes can offer better security and efficiency than other platforms, which is evident from their continued growth in the marketplace.
Tune in to this insightful episode of Redefining CyberSecurity and learn how to empower your business with security and innovation in the new age of mainframes. Don't miss out – listen now!
Note: This story contains promotional content. Learn more: https://www.itspmagazine.com/their-infosec-story
Guests:
Cynthia Overby, President & Co-Founder at Key Resources, Inc. [@KeyResourcesInc ]
On Linkedin | https://www.linkedin.com/in/cynthia-overby-41110a3/
Phil Buckellew, President, Infrastructure Modernization BU at Rocket Software [@rocket ]
On Linkedin | https://www.linkedin.com/in/phil-buckellew/
On Twitter | https://twitter.com/Buckellew
Resources
Catch the video and podcast version of this conversation: www.itspmagazine.com/their-stories/the-mainframe-advantage-robust-security-meets-infrastructure-modernization-a-rocket-software-and-kri-security-story-with-phil-buckellew-and-cynthia-overby
Learn more about Rocket Software and their offering: https://itspm.ag/keyresources-2876
Mainframe Modernization and Cybersecurity: https://itspm.ag/kri-secs4m
Podcast: The Humans In The Mainframe | Common Misunderstandings In Mainframe Security Management | A Key Resources Story With Ray Overby
Podcast: When Failure Is Not An Option, Organizations Turn To The Mainframe — Incorporating Mainframes Into Your Zero Trust Architecture | A Key Resources Story With Cynthia Overby
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
Guest: Dr. Christina Liaghati, AI Strategy Execution & Operations Manager for MITRE’s AI and Autonomy Innovation Center [@MITREcorp]
On LinkedIn | https://www.linkedin.com/in/christina-liaghati/
On Twitter | https://twitter.com/CLiaghati
At RSAC | https://www.rsaconference.com/experts/dr%20christina%20liaghati
____________________________
Hosts:
Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
Marco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli
____________________________
This Episode’s Sponsors
BlackCloak | https://itspm.ag/itspbcweb
Brinqa | https://itspm.ag/brinqa-pmdp
SandboxAQ | https://itspm.ag/sandboxaq-j2en
____________________________
Episode Notes
In this Chats on the Road to RSA Conference podcast episode, listeners are treated to an insightful discussion between Dr. Christina Liaghati, Sean Martin, and Marco Ciappelli about the evolving landscape of AI security, its impact on various sectors, and the proactive steps being taken to address emerging threats. Dr. Liaghati shares her unique experiences working with government sponsors and her involvement in the development of MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems), a knowledge base of adversary tactics, techniques, and case studies for machine learning (ML) systems based on real-world observations, demonstrations from ML red teams and security groups, and the state of the possible from academic research. ATLAS is modeled after the MITRE ATT&CK framework and its tactics and techniques are complementary to those in ATT&CK.
The conversation highlights how the rapid adoption of AI systems, combined with the lack of understanding of the risks involved, has led to new vulnerabilities and threats that need to be addressed. Listeners are also offered a glimpse into the challenges presented by the integration of AI into various systems, the need for collaboration between the AI and cybersecurity sectors, and the importance of understanding the new threat landscape created by AI adoption. Dr. Liaghati shares real-life examples of attacks on AI systems, emphasizing the need for constant vigilance and collaboration between industry, government, and academia to tackle these challenges.
The conversation also digs deeper into the potential consequences of AI deployment in high-stakes environments, such as finance and healthcare, and the importance of allocating resources to red teaming to identify vulnerabilities and secure these critical systems. By examining the current state of AI security and discussing the steps being taken to ensure its future, this episode provides an engaging and informative look at the complex interplay between AI, cybersecurity, and the systems we rely on every day.
____________________________
Resources
Session | Hardening AI/ML Systems - The Next Frontier of Cybersecurity: https://www.rsaconference.com/USA/agenda/session/Hardening%20AIML%20Systems%20-%20The%20Next%20Frontier%20of%20Cybersecurity
Learn more about MITRE Atlas: https://atlas.mitre.org/
MITRE Atlas on Slack (invitation): https://join.slack.com/t/mitreatlas/shared_invite/zt-10i6ka9xw-~dc70mXWrlbN9dfFNKyyzQ
Learn more about MITRE ATT&CK framework: https://attack.mitre.org/
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsa-cordbw
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverage
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac23sp
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Be sure to share and subscribe!
From the publisher's feed

90,949 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

418 Listeners

30 Listeners

179 Listeners

191 Listeners

73 Listeners

137 Listeners

5,554 Listeners

2 Listeners

46 Listeners

23 Listeners

4 Listeners

0 Listeners

5 Listeners