Redefining CyberSecurity

Redefining CyberSecurity

By Sean Martin, ITSPmagazineBusinessTechnologyEducation
Download on the App Store

Redefining CyberSecurity episodes

  • Evolution of the CISO | A Conversation With Patricia Muoio | Redefining CyberSecurity Podcast With Sean Martin

    Guest: Patricia Muoio, Ph.D, General Partner, SineWave Ventures [@SineWaveVC]

    On LinkedIn | https://www.linkedin.com/in/patricia-muoio-10037775/

    ____________________________

    Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
    ____________________________

    This Episode’s Sponsors

    Imperva | https://itspm.ag/imperva277117988

    Pentera | https://itspm.ag/penteri67a

    ___________________________

    Episode Notes

    The Chief Information Security Officer's (CISO's) role in an enterprise is challenging due to ambiguity around security requirements, lack of clear understanding of security as a business imperative, and the increasing complexity of technology. Placing the CISO closer to engineering and IT can help make better recommendations and choices but may require additional views of risk management alongside other types of business risks.

    This conversation highlights the changing role of CISOs in companies and the potential need for multiple CISOs (or sub-CISOs) to manage different aspects of security may be on the horizon, something startups may not be ready for but should begin to prioritize during the early build stage if they are to avoid costly situations later.

    ____________________________

    Resources

    Podcast: CISO Stories Recounted By The World's First CISO | A Conversation With Steve Katz: https://itspmagazine.simplecast.com/episodes/ciso-stories-recounted-by-the-worlds-first-ciso-a-conversation-with-steve-katz

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Watch the webcast version on-demand on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    43 min
  • The Impact Of Log4j Since Its Disclosure | Steps Businesses Can Take To Maintain Software Supply Chain Security | Part 2 Of 2 | An Imperva Brand Story With Peter Klimek

    In this second episode, we take a closer look at Log4j and what business/operations impacts it had on organizations faced with the attacks against the vulnerability. We also get to hear about some successful mitigation measures Imperva customers used to mitigate the impact of Log4j and take that to the next level for some actionable steps companies can take to prepare for other supply chain vulnerabilities.

    Note: This story contains promotional content. Learn more.

    Guest: Peter Klimek, Director of Technology - Office of the CTO at Imperva [@Imperva]

    On LinkedIn | https://www.linkedin.com/in/peter-klimek-37588962/

    Resources

    Learn more about Imperva and their offering: https://itspm.ag/imperva277117988

    Blog: Log4j: One Year Later

    Solution page: Stopping software supply chain attacks

    Learning center: Supply Chain Attack

    Learning center: Zero-day (0day) exploit

    National Telecommunications and Information Administration: Software Bill of Materials

    National Telecommunications and Information Administration: Vulnerability-Exploitability eXchange

    Podcast Part 1 of 2: https://redefining-cybersecurity.simplecast.com/episodes/the-impact-of-log4j-since-its-disclosure-steps-businesses-can-take-to-maintain-software-supply-chain-security-part-1-of-2-an-imperva-story-with-gabi-stapel

    Are you interested in telling your story?
    https://www.itspmagazine.com/telling-your-story

    41 min
  • The Impact Of Log4j Since Its Disclosure | Steps Businesses Can Take To Maintain Software Supply Chain Security | Part 1 Of 2 | An Imperva Brand Story With Gabi Stapel

    The December 2021 log4j vulnerability was a major event in the cybersecurity world. When it was released and exposed to the internet, it caused an explosion in attacks with five and a half million attacks per day and up to 25,000 sites attacked per hour. The vulnerability affects any system running that version of Java lookup and could be at risk, even if it is only exposed internally to insiders. The attackers initially used scanning and checking to see which sites were vulnerable, and then it was automated. Attack tools were created to make it easier for attackers to reach as many targets as possible. Public awareness campaigns have been effective, but vulnerabilities can reappear due to the prevalence of the software. 72% of organizations still had some level of vulnerability to log4j as of October 2022.

    As captured in this episode, remediation is not a one-and-done solution, as seen with Log4j, where organizations would fix the problem, and then it would come right back due to the prevalence of the software and how deep it went. The importance of API security is emphasized since 15% of the numbers were coming from APIs. The need to check and document new things added to the system is crucial to maintain proper documentation and be up on remediation. In short, software supply chain security is critical.

    Note: This story contains promotional content. Learn more.

    Guest: Gabi Stapel, Content Manager @ Imperva Threat Research [@Imperva]

    On LinkedIn | https://www.linkedin.com/in/gabriella-stapel/

    On Twitter | https://twitter.com/GabiStapel

    Resources

    Learn more about Imperva and their offering: https://itspm.ag/imperva277117988

    Blog: Log4j: One Year Later

    Solution page: Stopping software supply chain attacks

    Learning center: Supply Chain Attack

    Learning center: Zero-day (0day) exploit

    National Telecommunications and Information Administration: Software Bill of Materials

    National Telecommunications and Information Administration: Vulnerability-Exploitability eXchange

    Are you interested in telling your story?
    https://www.itspmagazine.com/telling-your-story

    24 min
  • Challenges With The Alphabet Soup Of Security | A Conversation With Mehran Farimani And Jay Thoden Van Velzen | Redefining CyberSecurity Podcast With Sean Martin

    Guests:

    Jay Thoden Van Velzen, Strategic Advisor to the CSO at SAP [@SAP]

    On LinkedIn | https://www.linkedin.com/in/jay-thoden-van-velzen/

    On Twitter | https://twitter.com/JayThvV

    On Mastodon | https://infosec.exchange/@jaythvv

    Mehran Farimani, CEO at RapidFort [@RapidFortInc]

    On LinkedIn | https://www.linkedin.com/in/farimani/

    On Twitter | https://twitter.com/farimani

    On Mastodon | https://infosec.exchange/@farimani

    Marco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli

    ____________________________

    Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
    ____________________________

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    HITRUST: https://itspm.ag/itsphitweb

    ___________________________

    Episode Notes

    Cybersecurity is a vast field with many categories and seemingly countless products and services. Some workflows can be implemented and automated to great effect if the organization understands them. However, many solutions within the cybersecurity space focus on the threat and the response but not on the environment of the organization and its business goals. An overload of options and this lack of understanding lead to an ineffective approach to security and wasted time and money.

    Inspired by a post on Mastodon, Mehran Farimani and Jay Thoden Van Velzen join Sean Martin and special guest, Marco Ciappelli to discuss the challenges with the alphabet soup that is the cybersecurity industry.

    ____________________________

    Resources

    Inspiring Post: https://infosec.exchange/@jaythvv/109530373418320875

    Community Containers: https://github.com/rapidfort/community-images

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Watch the webcast version on-demand on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    55 min
  • Developing Cybersecurity Leadership Capabilities And Scaling The Competency Of Your Team | A Crucial Conversation With Dutch Schwartz

    Community Member Contributor: Dutch Schwartz, Principal Security Specialist, Amazon Web Services (AWS) [@AWSSecurityInfo]

    On LinkedIn | https://www.linkedin.com/in/dutchschwartz

    On Twitter | https://twitter.com/dutch_26

    Hosts
    Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin

    Marco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli

    ______________________

    Episode Description

    In this episode, Dutch Schwartz—a Principal Security Specialist with Amazon Web Services—discusses how CISOs and other cybersecurity leaders need to expand upon their technical skills and include leadership competencies. Doing so allows cybersecurity leaders to connect with other leaders in the organization and their cybersecurity teams. This, in turn, makes it possible for cybersecurity activities to enable the business to knowingly take the risks it wants to take and then manage and mitigate those risks when they become problematic.

    ______________________

    For more podcasts from Crucial Conversations with The Blue Lava Community, visit: https://www.itspmagazine.com/crucial-conversations-podcast

    To access the full collection of Blue Lava Community resources, visit: https://itspm.ag/blclog22

    To learn more about Blue Lava, visit: https://itspm.ag/blue-lava-w2qs

    ______________________

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    50 min
  • Rating 2022 Cybersecurity Predictions | A No Holds Barred Conversation About Realities Of Our Cyber Society With Matthew Rosenquist | Redefining CyberSecurity Podcast With Sean Martin

    Guest: Matthew Rosenquist, CISO at Eclipz.io

    On LinkedIn | https://www.linkedin.com/in/matthewrosenquist/

    On Twitter | https://twitter.com/Matt_Rosenquist

    On Medium | https://matthew-rosenquist.medium.com/

    ____________________________

    Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]

    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
    ____________________________

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    HITRUST: https://itspm.ag/itsphitweb

    ___________________________

    Episode Notes

    In the last episode on this topic, Matthew gave us some insights into how and where he expected cybersecurity to take us in 2022. During the conversation he said, “Cybersecurity will continue to rapidly gain in both relevance and importance in 2022 as the world relies more upon digital technologies and unknowingly embraces the increasing accompanying risks of innovation. 2022 will see the rise of government orchestrated cyber-offensive activities, the growth of cybercriminal impacts at a national level, and the maturity of new technology used as powerful tools by both attackers and defenders. Overall, 2022 will be a more difficult and trying year for cybersecurity than its predecessors.”

    In this episode, we take a look back at the year of cybersecurity that was 2022, including the predictions, the outcomes, and the misses. It's a wild ride that you won't want to miss, even if you experienced some of it first-hand in your own InfoSec programs.

    ____________________________

    Resources

    Previous Episode #844 - It Is 2022: Here Are Some Cybersecurity Predictions And Their Impact On Business, Governments, Citizens, And Society: https://itsprad.io/redefining-security-844

    Original 10 Predictions: https://www.linkedin.com/pulse/10-cybersecurity-predictions-2022-matthew-rosenquist/

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Watch the webcast version on-demand on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    1 hr 16 min
  • Managing Human Cyber Risk | A Conversation About Aligning Cybersecurity Culture To The Organization's Strategy With Lance Spitzner | Redefining CyberSecurity Podcast With Sean Martin

    Guest
    Lance Spitzner
    Director, SANS Senior Instructor - SANS Technical Institute [@sansinstitute]
    On LinkedIn | https://www.linkedin.com/in/lance-spitzner-0ab0ba1/
    On Twitter | https://twitter.com/lspitzner

    Host
    Sean Martin
    Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
    ____________________________

    This Episode’s Sponsors
    Pentera | https://itspm.ag/penteri67a
    Asgardeo | https://itspm.ag/asgardeo-by-wso2-u8vc

    ___________________________

    Episode Notes

    There are many security frameworks, maturity models, and best practices to leverage when developing ‘user friendly’ security policies to foster greater adoption and behavioral change. How these new policies are effectively communicated to ensure both compliance and collaboration across the organization (including remote workers) is equally important.

    ____________________________

    Resources

    SANS: https://www.sans.org/

    NIST CSF: https://www.nist.gov/cyberframework

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    40 min
  • Why Protecting Your Business Data Is More Like Securing A Museum Than A Bank | Demystifying Data Protection | An Imperva Brand Story With Terry Ray

    Data is dynamic. Data is unique. It's critical for businesses to maintain data security and integrity by treating it differently based on what it is, what it's for, who is accessing it, how it's being used, and the overall context surrounding these things.

    Join us for a conversation with Terry Ray, SVP Data Security GTM, Field CTO and Imperva Fellow, as we explore:

    • What challenges do businesses face when it comes to protecting data in our modern world?
    • What security risks do insider threats present to an organization and why are they so hard to stop?
    • Why are more organizations moving to agentless data security?
    • How have Imperva Data Security solutions evolved to meet the new challenges of securing data wherever it lives?

    Note: This story contains promotional content. Learn more.

    Guest
    Terry Ray
    SVP Data Security GTM, Field CTO and Imperva Fellow
    On Linkedin | https://www.linkedin.com/in/terry-ray/
    On Twitter | https://twitter.com/TerryRay_Fellow

    Resources
    Learn more about Imperva and their offering: https://itspm.ag/imperva277117988

    Product: Imperva Data Security Fabric

    Data Discovery Solution: Data discovery and classification

    Data Security Solution: Sensitive and personal data security

    Video: Demystifying Data Protection: Steps To Find, Monitor And Control Without Chaos

    Webinar: What Security Professionals Need to Know About Privacy in 2023

    Whitepaper: A data-centric cybersecurity framework for digital transformation

    Are you interested in telling your story?
    https://www.itspmagazine.com/telling-your-story

    49 min
  • Military Experience Sets The Stage For Cybersecurity Success In Corporate Sector | A Crucial Conversation With Billy Pugh

    Community Member Contributor: William Pugh
    Security Consultant at AWS [@awscloud]
    On LinkedIn | https://www.linkedin.com/in/billy-pugh/

    Hosts
    Sean Martin
    Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin

    Marco Ciappelli
    Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast
    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli

    ______________________

    Episode Description

    Companies looking to strengthen their cybersecurity programs would do well to look toward military veterans who are transitioning to the corporate sector. Veterans come equipped with the necessary experience and a cybersecurity paradigm that sets them up for success in helping protect vital digital assets.

    A vital part of that paradigm is the ambiguity of cybersecurity. New technologies keep emerging that need protection by applying security controls. At the same time, cybercriminals constantly change their tactics, exploiting known weaknesses and bypassing common controls.

    Both the military and the corporate world also face a dearth of security talent and often have to throw professionals with little experience at the cybersecurity ambiguity challenges. Private companies and public organizations thus need professionals who are accustomed to working under the pressure of ambiguous scenarios with limited resources to support them.

    ______________________

    For more podcasts from Crucial Conversations with The Blue Lava Community, visit: https://www.itspmagazine.com/crucial-conversations-podcast

    To access the full collection of Blue Lava Community resources, visit: https://itspm.ag/blclog22

    To learn more about Blue Lava, visit: https://itspm.ag/blue-lava-w2qs

    ______________________

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    45 min
  • Just How Defensible Is Your InfoSec Program? | A Conversation About Security Awareness And Culture With Javvad Malik And Marco Ciappelli | Redefining CyberSecurity Podcast With Sean Martin

    Guests
    Javvad Malik
    Lead Security Awareness Advocate at KnowBe4 [@KnowBe4]
    On LinkedIn | https://www.linkedin.com/in/javvad/
    On Mastodon | https://infosec.exchange/@Javvad
    On Twitter | https://twitter.com/J4vv4D
    On TikTok | https://www.tiktok.com/@j4vv4d
    On YouTube | https://www.youtube.com/infoseccynic

    Marco Ciappelli
    Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast
    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli

    Host
    Sean Martin
    Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
    On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
    ____________________________

    This Episode’s Sponsors
    Asgardeo | https://itspm.ag/asgardeo-by-wso2-u8vc
    Pentera | https://itspm.ag/penteri67a

    ___________________________

    Episode Notes

    Security awareness and security culture are talked about a lot in the community. In this episode, we get into the nitty gritty of both of these topics, hearing about them via real-world stories and discussing them in the context of real-life analogies. A program is just a program unless it can be understood, measured, and defended from all angles.

    As one example discussed in this episode, there's no point in just teaching people to spot a phishing email because phishing now comes in text messages, on social media, direct messages on Twitter or Instagram, on Discord channels, even in your WhatsApp messages. There's no way you can train everyone on every single channel out there. A better option is to teach them about the red flags, give them knowledge about how the bad actors will approach their targets, and what some of the signs are to look out for. Help them understand that if you're careful, then you won't fall victim to it. One analogy used to help illustrate this point comes in the form of the crosswalks in London where information is shared with the street crosser at the point when/where they are crossing as opposed to trying to train the traveler weeks in advance of visiting London.

    This is one of the many, many points that our guest, Javvad Malik, shares with us during this episode.

    Enjoy and learn!

    ____________________________

    Resources

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    50 min

About Redefining CyberSecurity

From the publisher's feed

Redefining CyberSecurity Podcast

More shows like Redefining CyberSecurity

This American Life by This American Life

This American Life

90,949 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

The ITSPmagazine Podcast by ITSPmagazine, Sean Martin, Marco Ciappelli

The ITSPmagazine Podcast

30 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hard Fork by The New York Times

Hard Fork

5,554 Listeners

Audio Signals Podcast by ITSPmagazine, Marco Ciappelli, Sean Martin

Audio Signals Podcast

2 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

Microsoft Threat Intelligence Podcast by Microsoft

Microsoft Threat Intelligence Podcast

23 Listeners

Stories From Space by ITSPmagazine, Matthew S Williams

Stories From Space

4 Listeners

An Analog Brain In A Digital Age | With Marco Ciappelli by Marco Ciappelli

An Analog Brain In A Digital Age | With Marco Ciappelli

0 Listeners

CyberSecurity Summary by CyberSecurity Summary

CyberSecurity Summary

5 Listeners