
Sign up to save your podcasts
Or


Community Member Contributor: Frank Kim
CISO-in-Residence at YL Ventures [@ylventures] and Fellow and Curriculum Director at the SANS Institute [@SANSInstitute]
On Twitter | https://twitter.com/fykim
On LinkedIn | https://www.linkedin.com/in/frank-kim/
Host: Sean Martin
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
______________________
Episode Description
As businesses migrate more and more applications to the cloud and continue relying on SaaS applications, CISOs are under pressure to ensure every IT environment is secure. This requires a new paradigm in formulating cloud security strategies because the technologies differ from on-premises technologies, and the security aspects vary from one cloud provider to another.
In this episode, Frank Kim—a Fellow and a Curriculum Director at the SANS Institute—examines the approach CISOs must take to secure multiple cloud and SaaS environments. Kim also discusses the importance of understanding the differences between on-premises security and the cloud and why the speed of the cloud requires a new security paradigm. Kim then presents why CISOs need to give business units and software developers security options (rather than locking them into one tool) while balancing a combination of governance and technical expertise.
Understanding the criticality of protecting access credentials and the needs of all stakeholders is also key to a CISO's success in safeguarding multiple cloud environments.
______________________
For more podcasts from Crucial Conversations with The Blue Lava Community, visit: https://www.itspmagazine.com/crucial-conversations-podcast
To access the full collection of Blue Lava Community resources, visit: https://itspm.ag/blclog22
To learn more about Blue Lava, visit: https://itspm.ag/blue-lava-w2qs
______________________
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
Guest
Andy Rappaport
Data Security Architect at iRobot [@iRobot]
On LinkedIn | https://www.linkedin.com/in/andyrappaport/
Host
Sean Martin
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
On Mastodon | https://infosec.exchange/@seanmartin
____________________________
This Episode’s Sponsors
Asgardeo | https://itspm.ag/asgardeo-by-wso2-u8vc
Edgescan | https://itspm.ag/itspegweb
___________________________
Episode Notes
We've come a long way in software development, moving from a months-long waterfall model to a software development lifecycle (SDLC) that's all about continuous improvement and continuous delivery (CI/CD). Has security testing kept up, and how can it fit in? Let's find out during this chat with Data Security Architect, Andy Rappaport.
____________________________
Resources
____________________________
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
Guests
Jerry Bell
VP and CISO, IBM Public Cloud [@IBM | @IBMcloud] and founder & co-host of the Defensive Security Podcast [@defensivesec]
On Mastodon | https://infosec.exchange/@jerry/109302267835657653
On Linkedin | https://www.linkedin.com/in/maliciouslink/
On Twitter | https://twitter.com/Maliciouslink
Marco Ciappelli
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli
On Mastodon | https://infosec.exchange/@Marcociappelli
Host
Sean Martin
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
On Mastodon | https://infosec.exchange/@seanmartin
____________________________
This Episode’s Sponsors
Imperva | https://itspm.ag/imperva277117988
Pentera | https://itspm.ag/pentera-tyuw
___________________________
Episode Notes
As turmoil ensues on the bird social platform and we witness the information security community making a mad dash to the InfoSec.Exchange instance operating on Mastodon. In this episode, we bring the creator of InfoSec.Exchange, Jerry Bell, to learn more about the Mastodon platform, the vision for InfoSec.Exchange, and what the cybersecurity community can do to ensure this platform continues to reach its potential.
____________________________
Resources
Infosec.Exchange on Mastodon: https://infosec.exchange/home
Volunteer for InfoSec Exchange: https://infosec.exchange/@jerry/109302267835657653
Donate to InfoSec Exchange: https://liberapay.com/Infosec.exchange/
Jerry's Blog: https://infosec.engineering/
Defensive Security Podcast: https://defensivesecurity.org
____________________________
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
In the first episode of this two-part series, we looked at the history of privacy law and regulation and we explored how the definitions and requirements are expanding for the benefit of consumers and the impact and challenges they create for the business. We also dissected the differences between data privacy, compliance, and security and how organizations can determine what its data privacy posture will look like in comparison/contrast to its security posture.
In this second episode, we take a closer look at actionable strategies and steps organizations can take to operationalize data privacy compliance and how to leverage data privacy initiatives to create a stronger security posture. As we explore these challenges, we begin to uncover the realities of the increased complexity that comes with each decision the business makes to create, collect, store, process, and share sensitive information throughout multiple business systems, applications, and geographies. While there is a clear need to protect the data from being inappropriately accessed by authorized or unauthorized users, a better strategy can be found in the simplification of the business systems and processes thereby avoiding (or at least reducing) the exposure to compliance and security risk.
Whatever the drivers are behind your business outcomes and IT operations decisions, having an outcome in mind for privacy and security will give you something to shoot for. Whether it's creating the strongest posture possible or simply checking the boxes for compliance, at least you know where you're going and can begin to head down that path. Clarity and consistency in action brings improved preparedness and increased confidence to the conversation, which leads to more positive outcomes all the way around.
Note: This story contains promotional content. Learn more.
Guest
Kate Barecchia
Deputy General Counsel & Global Data Privacy Officer at Imperva [@Imperva]
On Linkedin | https://www.linkedin.com/in/kate-barecchia-82759a14/
Resources
Learn more about Imperva and their offering: https://itspm.ag/imperva277117988
Product: Imperva Data Security Fabric
Data Discovery Solution: Data discovery and classification
Data Security Solution: Sensitive and personal data security
Webinar: What Security Professionals Need to Know About Privacy in 2023
Whitepaper: A data-centric cybersecurity framework for digital transformation
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
Guest
Scott Schober
President and CEO of Berkeley Varitronics Systems [@BVSystems]
On Linkedin | https://www.linkedin.com/in/snschober/
On Twitter | https://twitter.com/ScottBVS
On Facebook | https://www.facebook.com/scott.schober.585
Host
Sean Martin
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
____________________________
This Episode’s Sponsors
Asgardeo | https://itspm.ag/asgardeo-by-wso2-u8vc
Pentera | https://itspm.ag/pentera-tyuw
___________________________
Show Notes
What is a cybersecurity best practice anyway? And which company is it “best” for? In this conversation, Scott Schober and Sean Martin break down common cybersecurity practices and how businesses of all sizes (especially SMBs/SMEs) can dissect what matters most for their business and how the organization as a whole can adopt the most appropriate cybersecurity practices.
Scott also shares his personal story of being targeted by cyber activists and cybercriminals, along with the details for how his personal compromise became a vector to the business being threatened. This is a serious conversation that many don’t talk about. However, hearing this story sheds some much-needed light on how threats and attacks become reality — targeted or not.
____________________________
Resources
Books | Hacked Again Cybersecurity is Everybody’s Business: https://scottschober.com/cybersecurity-is-everybodys-business/
____________________________
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
The large ratio gap in the availability of IT security professionals to open positions existed long before COVID-19. And that gap has grown even bigger thanks to the great resignation that has continued to take place in the IT industry since the pandemic. This has created a huge challenge for CISOs and other security leaders in their efforts to recruit and retain skilled security teams.
In this episode, Megan McCann—CEO & Founder of the IT recruitment firm McCann Partners—presents creative approaches CISOs and hiring managers can apply to go beyond scanning resumes to finding prospects who can offer true value. McCann also discusses what CISOs can do to nurture their own careers.
_______________________
Community Member Contributor: Megan McCann
CEO & Founder at McCann Partners [@McCannPartners]
On Twitter | https://twitter.com/meganpmccann
On LinkedIn | https://www.linkedin.com/in/meganpmccann/
Hosts: Sean Martin and Marco Ciappelli
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli
______________________
For more podcasts from Crucial Conversations with The Blue Lava Community, visit: https://www.itspmagazine.com/crucial-conversations-podcast
To access the full collection of Blue Lava Community resources, visit: https://itspm.ag/blclog22
To learn more about Blue Lava, visit: https://itspm.ag/blue-lava-w2qs
______________________
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
Guests
LeAnn Cary
Senior Director - Advanced Fusion Center Practice Leader, Optiv [@Optiv]
On Twitter | https://twitter.com/leanncary
On Linkedin | https://www.linkedin.com/in/leanncary/
Yolanda Craig
Director, Business Strategy and Development, IC at Raytheon BBN [@RaytheonIntel]
On Linkedin | https://www.linkedin.com/in/yolanda-c-r-craig/
Sunday Oludare Ogunlana
Security Incident Management Team, Citi [@Citi]
On Linkedin | https://www.linkedin.com/in/sogunlana/
On Twitter | https://twitter.com/abovejordan
Jay Jay Davey
SOC Client Lead, Bridewell [@bridewellsec]
On Linkedin | https://www.linkedin.com/in/biggingerhoneypot/
On Twitter | https://twitter.com/NoxCyber
Hosts
Sean Martin
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
Marco Ciappelli
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society Podcast
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli
____________________________
Episode Introduction
The SOC is changing. Cybersecurity teams are investing in AI-driven security technologies and planning to outsource many of the Tier-1 and Tier-2 analyst responsibilities to combat talent shortages—enabling in-house teams to become much more focused on threat intelligence. In this panel, SOC professionals from MSSPs and in-house teams will come together to discuss dividing and conquering responsibilities to keep organizations secure.
Want more on this topic? Be sure to watch the live stream of the Second Annual SOC Analyst Appreciation Day: https://itspm.ag/devo2p8i
For more SOC Analyst Appreciation Day Event Coverage podcast and video episodes visit: https://itspmagazine.com/second-annual-soc-analyst-appreciation-day
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
Guests
Deborah Blyth
Executive Public Sector Strategist at CrowdStrike [@CrowdStrike]
On Linkedin | https://www.linkedin.com/in/deborah-blyth/
On Twitter | https://twitter.com/debbiblyth
Merlin Namuth
CISO at REPAY [@REPAYholdings]
On Linkedin | https://www.linkedin.com/in/merlin-namuth/
Host
Sean Martin
Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
Edgescan | https://itspm.ag/itspegweb
___________________________
Show Notes
When security leaders are preparing to speak with executive-level leaders and the board of directors, it's important to "know your audience" — but there is so much more to it than that.
Join us as we discuss how to learn more about the board of directors, what they care about, how to connect with them, and how to get what you want and need from them to succeed. Equally important is what you can do for them for the business and the greater good of the business world ... we're all connected at some level.
Each and every conversation is important and potentially nerve-wracking. None more so than the very first time you are going to present to the board. Thankfully, Debbi and Merlin share some insights on this stage-setting activity as well.
Enjoy!
____________________________
Resources
LinkedIn Post | Why Cybersecurity Should be a Board-Level Discussion: https://www.crowdstrike.com/blog/why-cybersecurity-should-be-a-board-level-discussion/
____________________________
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity-podcast
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
Over 100+ countries and counting (along with a growing number is U.S. states) have enacted data privacy legislation, creating a super-complex global data privacy landscape. Unless, of course, you approach the situation with a different mindset.
Join us to explore the relationship between privacy, security, compliance, and ethics as organizations try to find the perfect balance in data creation, collection, storage, usage, and collaboration.
Don’t worry, we’ll set the record straight for the differences between the “DPO” and the “DPO” … as well as the participation and responsibilities of security, privacy, engineering, legal, compliance, and more.
In this first episode, we look at the history of privacy law and regulation and we explore how the definitions and requirements are expanding for the benefit of consumers and the impact and challenges they create for the business.
We also get into the differences between data privacy, compliance, and security and how organizations can determine what its data privacy posture will look like in comparison/contrast to its security posture.
Is it a one-size-fits-all approach? As an engineer turned legal professional turned privacy executive, you might be surprised to hear what Kate’s recommendations are.
Note: This story contains promotional content. Learn more.
Guest
Kate Barecchia
Deputy General Counsel & Global Data Privacy Officer at Imperva [@Imperva]
On Linkedin | https://www.linkedin.com/in/kate-barecchia-82759a14/
Resources
Learn more about Imperva and their offering: https://itspm.ag/imperva277117988
Product: Imperva Data Security Fabric
Data Discovery Solution: Data discovery and classification
Data Security Solution: Sensitive and personal data security
Webinar: What Security Professionals Need to Know About Privacy in 2023
Whitepaper: A data-centric cybersecurity framework for digital transformation
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
Global supply chains have grown much more complex than simply figuring out how to get products and services from Point A to Point B. Companies also depend on second-tier, third-tier, and even nth-tier vendors they don’t know and have no relationship with for the services and components they require to operate.
Cyberattacks on software across these complex supply chain ecosystems have resulted in disruptions, defects, and diversions that are difficult to identify and resolve—one weak link in the chain can bring the entire ecosystem to a halt.
In this episode, Mark Weatherford—CSO at AlertEnterprise and Chief Strategy Officer at the National Cybersecurity Center—examines the importance of understanding vendor cybersecurity postures, not only primary suppliers but also their suppliers as well. Weatherford also discusses how enterprise software components can come from vendors all over the world and how global events can impact supply chains. Weatherford then presents why the jobs of CISOs are so difficult in defending supply chains, along with a few tips for organizations to protect their operations.
_______________________
Community Member Contributor: Mark Weatherford
CSO at AlertEnterprise [@AlertEnterprise] and Chief Strategy Officer at the National Cybersecurity Center [@NATLCyberCenter]
On Twitter | https://twitter.com/marktw
On LinkedIn | https://www.linkedin.com/in/maweatherford/
Host: Sean Martin
On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martin
______________________
For more podcasts from Crucial Conversations with The Blue Lava Community, visit: https://www.itspmagazine.com/crucial-conversations-podcast
To access the full collection of Blue Lava Community resources, visit: https://itspm.ag/blclog22
To learn more about Blue Lava, visit: https://itspm.ag/blue-lava-w2qs
______________________
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network
From the publisher's feed

90,949 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

418 Listeners

30 Listeners

179 Listeners

191 Listeners

73 Listeners

137 Listeners

5,554 Listeners

2 Listeners

46 Listeners

23 Listeners

4 Listeners

0 Listeners

5 Listeners