Redefining CyberSecurity

Redefining CyberSecurity

By Sean Martin, ITSPmagazineBusinessTechnologyEducation
Download on the App Store

Redefining CyberSecurity episodes

  • IoT Village At DEF CON 30 | Chats On The Road | A Conversation With Rachael Tubbs | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    Everything is connected these days — from coffee machines to home security cameras to drones. And they all could use a good ole hacking. Regardless of your hacking skills level, join the IoT Village crew for good vibes and tons of stuff to get your hands on.

    Join us and our guest, Rachael Tubbs, as we get into the vibe of all things IoT Village at DEF CON 2022!

    About the IoT Village
    IoT Village advocates for advancing security in the Internet of Things (IoT) industry through bringing researchers and industry together. IoT Village hosts talks by expert security researchers, interactive hacking labs, live bug hunting in the latest IoT tech, and competitive IoT hacking contests. Over the years IoT Village has served as a platform to showcase and uncover hundreds of new vulnerabilities, giving attendees the opportunity to learn about the most innovative techniques to both hack and secure IoT. IoT Village is organized by security consulting and research firm, Independent Security Evaluators (ISE), and the non-profit organization, Loudmouth Security.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    Rachael Tubbs
    Marketing and Events Lead at Independent Security Evaluators [@ISEsecurity]
    On LinkedIn | https://www.linkedin.com/in/rachael-tubbs-1a1085135/
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    IoT Village DEF CON Schedule: https://www.iotvillage.org/defcon.html

    IoT Village website: https://www.iotvillage.org/

    On LinkedIn | https://www.linkedin.com/showcase/iotvillage

    At DEF CON: https://forum.defcon.org/node/239789

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    24 min
  • From Hackathon To Hacked: Web3’s Security Journey | Chats On The Road | A Conversation With Nathan Hamiel | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    Web3 is a live experiment that is happening now. Around us. To us. By us. How will it affect privacy and security? Let's find out.

    In this conversation with Black Hat speaker, Nathan Hamiel, we explore the definition and promise of Web3 and its impact — positive and negative — on society.

    About the Session "From Hackathon to Hacked: Web3's Security Journey": 
    If there's one prediction you can make with certainty, it's that security in the Web3/blockchain space will get a whole lot worse before it gets better. We have the perfect cocktail of inexperience mixed with emerging technology playing out in full public view with large sums at stake and the permanence of immutable transactions. The result is predictable. An environment free from constraints can seem like an innovation paradise, but when the stakes are so high, you have to get everything right the first time because there may not be a next time. We tend to forget that what we see from this space are experiments playing out in production, and the time between exploitation and losing millions of dollars worth of value can be measured in seconds. So, how did we get here? Is it all doom and gloom? What can be done?

    This talk is a grounded look at the factors contributing to the security failures we've witnessed, free from the hype and hatred associated with the space. We look at the similarities and differences between the development of this new technology and more traditional applications and how some of the attacks manifested. Better testing and tools aren't enough to solve the problem. We discuss actionable steps projects and chains can use today to address these issues and make the ecosystem safer for projects and users.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    Nathan Hamiel
    Senior Director of Research at Kudelski Security [@KudelskiSec]
    On LinkedIn | https://www.linkedin.com/in/nathanhamiel/
    On Twitter | https://twitter.com/nathanhamiel
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Session | From Hackathon to Hacked: Web3's Security Journey: https://www.blackhat.com/us-22/briefings/schedule/index.html#from-hackathon-to-hacked-webs-security-journey-26692

    Kudelski Security Research Blog: https://research.kudelskisecurity.com/

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    34 min
  • Social Engineering Community Village At DEF CON 30 | Chats On The Road | A Conversation With Stephanie "snow" Carruthers | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    What's old is new again. With a fresh new pair of amazing co-founders, the social engineering community will come together to make some calls, have some laughs, and discuss the morals and ethics of getting someone to do something they wouldn't have otherwise done.

    In this Chats on the Road to Las Vegas, we have the privilege of chatting with the new Social Engineering Community Village at DEF CON, Stephanie "Snow" Carruthers. Join us to get the low-down on what's staying the same, what's new, and what's certain to be a fantastic time.

    About the Social Engineering Community Village
    The Social Engineering Community is formed by a group of individuals who have a passion to enable people of all ages and backgrounds interested in Social Engineering with a venue to learn, discuss, and practice this craft. We plan to use this opportunity at DEF CON to present a community space that offers those elements through panels, presentations, research opportunities, and contests in order to act as a catalyst to foster discussion, advance the craft and create a space for individuals to expand their network.

    Snow and JC plan to accomplish the above by bringing together passionate individuals to have a shared stake in building this community with the goal to continuously grow and iterate members of the Social Engineering Community in various roles to all have an opportunity to give back equally.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    Stephanie "Snow" Carruthers
    Co-Founder of the new Social Engineering Community (SEC), a DEF CON village [@sec_defcon]
    On Twitter | https://twitter.com/_sn0ww
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Social Engineering Community Village DEF CON Schedule: https://www.se.community/village-schedule/

    Social Engineering Community Village website: https://www.se.community/

    On LinkedIn | https://www.linkedin.com/company/social-engineering-community/

    On YouTube | https://www.youtube.com/channel/UCFlepVHh7k5rBRTXwDrHyJA

    At DEF CON: https://forum.defcon.org/node/240918

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    27 min
  • AppSec Village At DEF CON 30 | Chats On The Road | A Conversation With Chris Kubecka, Liora Herman, And Erez Yalon | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    Applications run the world. They provide an interface to the rest of the technologies and data we create, share, and make decisions with. Sometimes these interfaces come in the form of a user interface (UX), sometimes in the form of an API. In both cases, they offer a path to the systems and information we hold dear to us.

    In this Chats on the Road to DEF CON, we connect with the co-founders and organizers of the AppSec Village along with their keynote speaker at the village this year. This is a conversation about the real-world that you won't want to miss.

    About the AppSec Village
    Welcome to AppSec Village, where red, blue and purple teamers, come together learn from the best of the best on how to exploit software vulnerabilities and how to secure software. Software is everywhere, and Application Security vulnerabilities are lurking around every corner making the software attack surface attractive for abuse. If you are just an AppSec n00b or launch deserialization attacks for fun and profit, you will find something to tickle your interest at the AppSec Village.

    Our mission is to promote diverse voices and perspectives in an inclusive environment driven for and by the appsec community to increase education and awareness of application security methods and practices.

    About Chris Kubecka's Keynote: Wartime AppSec
    To understate things, the 2020s have been a challenging time for AppSec. First, Corona took the hardware out of the office for everyone. Now, with a war in Ukraine activating hacktivists, patriotic hackers, and nation-state level actors are wreaking havoc on our apps and websites. Cyber-attacks are targeting the code and products of allied nations, pro-Russian, and pro-sanction companies.

    Come on a journey with a hacker who will share the top ten geopolitical gotchas in your AppSec and real-world examples. Through her experiences in several cyber warfare incidents as well as her recent experiences in Ukraine, Romania, Moldova, and Transnistria.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guests

    Chris Kubecka
    CEO at HypaSec NL [@HypaSec] and Keynote speaker at AppSec Village at DEF CON 30
    On LinkedIn | https://www.linkedin.com/in/chris-kubecka/
    On Twitter | https://twitter.com/SecEvangelism

    Liora Herman
    Founder and Queen of Details at AppSec Village [@AppSec_Village] and Head of Field and Channel Marketing, EMEA & APAC at Pentera [@penterasec]
    On LinkedIn | https://www.linkedin.com/in/liorarherman/
    On Twitter | https://twitter.com/tzionit411
    On Facebook | https://www.facebook.com/liorarherman
    On YouTube | https://www.youtube.com/c/AppSecVillage/

    Erez Yalon
    Founder and Mayor at AppSec Village [@AppSec_Village] and VP of Security Research at Checkmarx [@Checkmarx]
    On LinkedIn | https://www.linkedin.com/in/erezyalon/
    On Twitter | https://twitter.com/ErezYalon

    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    AppSec Village DEF CON Schedule: https://www.appsecvillage.com/events/dc-2022

    AppSec Village website: https://www.appsecvillage.com/

    On LinkedIn | https://linkedin.com/company/appsecvillage

    On YouTube | https://www.youtube.com/c/AppSecVillage/

    At DEF CON: https://forum.defcon.org/node/240922

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    27 min
  • The Relationship Between Roles — When Data Engineering Meets CyberSecurity | A Conversation With Saman Fatima | Redefining CyberSecurity Podcast With Sean Martin

    When you combine a DevOps engineer with a data engineer that is also interested in cybersecurity and privacy, what does that relationship look like for the business? Let's find out.

    In today's episode, we catch up with DevOps engineer and data engineer, Saman Fatima. We dig into how her experience in a variety of engineering roles and her connections to the cybersecurity community help shape how she looks at and uses data to drive business outcomes.

    ____________________________

    Guests
    Saman Fatima
    Management Lead and Vice-Chair of Board at BBWIC Foundation [@barriers_in]
    On LinkedIn | https://www.linkedin.com/in/saman-fatima-30/
    On Twitter | https://twitter.com/saman_3014

    ____________________________

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    Asgardeo by WSO2: https://itspm.ag/asgardeo-by-wso2-u8vc

    ____________________________

    Resources

    Training resource for Data Engineering: https://www.coursera.org/professional-certificates/ibm-data-engineer

    Data Community: https://www.linkedin.com/company/dataworksforeveryone/

    Saman's Talk on "How to build a STRONG Data Driven Organization" at TECH)K)NOW DAY: https://www.youtube.com/watch?v=S2962uhQpaE

    BBWIC Foundation: https://www.bbwic.com/ (on LinkedIn: https://www.linkedin.com/company/bbwic-foundation/mycompany)

    ____________________________

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    41 min
  • Blue Team Village At DEF CON 30 | Chats On The Road | A Conversation With muteki And OMENScan | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    Sometimes the best offense is a good defense. The Blue Team Village aims to bring an amazing experience to DEF CON where the community joins together to hack the defensive side of security: mindset, techniques, tools, mentoring, and more.

    About the Blue Team Village
    Blue Team Village (our friends just call us BTV) is both a place and a community built for and by defenders. It’s a place to gather, talk, share, and learn from each other about the latest tools, technologies, and tactics that our community can use to detect attackers and prevent them from achieving their goals. Whether we are in the same physical space, or in the ether, BTV is a place for encouraging, teaching, and supporting Blue Teamers.

    We will have plenty of defender focused sessions held throughout the year. Don’t forget to hang out in the Discord channels to ask questions, catch up with old friends, and meet new ones.

    BTV promises to be a firehose of Blue Team learning, sharing, and fun for the defenders who build things, defend things, and innovate. Come celebrate the other side of the hacking mirror with us. We’ll keep a blue light on for you!

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guests
    Cassandra Young (muteki)
    Director at the Blue Team Village [@BlueTeamVillage]
    On LinkedIn | https://www.linkedin.com/in/cassandray
    On Twitter | https://twitter.com/muteki_rtw
    On YouTube | https://www.youtube.com/blueteamvillage

    David Porco (Quix0te/OMENScan)
    Director at the Blue Team Village [@BlueTeamVillage]
    On LinkedIn | https://www.linkedin.com/in/dporco/
    On Twitter | https://twitter.com/OMENScan
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Blue Team Village DEF CON Schedule: https://dc30.blueteamvillage.org/call-for-content-2022/schedule/#

    Blue Team Village website: https://blueteamvillage.org/

    On LinkedIn | https://www.linkedin.com/company/the-blue-team-village/

    At DEF CON: https://forum.defcon.org/node/239819

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    38 min
  • ICS Village At DEF CON 30: Chats On The Road | A Conversation With Bryson Bort And Tom VanNorman | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    The ICS Village is one of the first DEF CON villages we ever connected with. A lot has changed over the years, including the threats faced by critical infrastructure entities around the world. Let's find out what to expect at this year's village.

    About the ICS Village
    High profile industrial control system (ICS) security issues have grabbed headlines and sparked change throughout the global supply chain. The ICS Village allows defenders of any experience level to understand the unique failure modes of these systems and how to better prepare and respond to the changing threat landscape.

    Interactive simulated ICS environments, such as Hack the Plan(e)t and Howdy Neighbor, provide safe yet realistic environments to preserve safe, secure, and reliable operations. The ICS Village brings a compelling experience for all experience levels and types, with IT and industrial equipment. Our interactive learning approach invites you to get hands on with the equipment to build your skills.

    We bring you real components such as programmable logic controllers (PLC), human-machine interfaces (HMI), remote telemetry units (RTU), and actuators to simulate a realistic environment by using commonly used components throughout different industrial sectors. You will be able to connect your machine to the different industrial components and networks and try to assess these ICS devices with common security scanners to sniff the industrial traffic, and more!

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guests
    Bryson Bort
    Co-Founder of the ICS Village [@ICS_Village]
    On LinkedIn | https://www.linkedin.com/brysonbort
    On Twitter | https://mobile.twitter.com/brysonbort
    On YouTube | https://youtube.com/c/ICSVillage

    Tom VanNorman
    Founding member of the ICS Village
    On LinkedIn | https://www.linkedin.com/in/thomasvannorman/
    On Twitter | https://twitter.com/Tom_VanNorman
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    ICS Village Website: https://www.icsvillage.com/

    ICS Village at DEF CON 30 Schedule: https://www.icsvillage.com/schedule-def-con-30

    ICS Village 360 Tour: https://www.exhibitstudiosmedia.com/tours/21396_ics_360_tour/

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    37 min
  • Trying To Be Everything To Everyone: Let’s Talk About Burnout | A Conversation With Stacy Thayer | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    The industry recognizes there is a problem with staff being overworked and reaching a point of burnout. What is the definition of burnout, and how can we spot the signs? Perhaps we need to look at this from a different angle to begin to make some progress in this area.

    In this conversation with Black Hat speaker, Dr Stacy Thayer, we explore the history, definition, and progress we are making as we attempt to deal with burnout and the overarching challenges of employee experience.

    About the session, "Trying to Be Everything to Everyone: Let’s Talk About Burnout"
    Research shows computer security professionals describe the computer security industry as a high-risk yet high-reward profession with negative effects on the workforce. There is an estimated 805,000 computer security professionals working in the US, but meeting the business demand for computer security professionals would require 62% industry growth. This leaves those in the field understaffed and highly stressed, ultimately leading to burnout. Stress and burnout can lead to mental fatigue, which can negatively impact motivation and engagement. It can also cause diminishing focus and performance levels, and have a negative impact on operational security, satisfaction, and performance, both in the office and at home. This talk will discuss the existing research on burnout in the computer security industry and will discuss what really causes burnout, why it happens, and what you can do to mitigate it, including setting healthy boundaries, avoiding guilt, realistic ways to manage anxiety, and honest self-talk so you can identify what is needed to refill your energy and passion.

    I will discuss how to recognize burnout in hidden places and explore the root causes of it.

    I will address what to do about it – going beyond simply meditation, exercise, and healthy eating. If it was that easy, we would all be doing that. This talk is unique in that it will utilize a knowledge of practical psychology to keep it real and use behavioral change models as a guide for reducing burnout. How do you find motivation, appreciation, and time for yourself when it feels like the world around you is demanding you give more? You will leave this talk with a better understanding of how burnout happens, your personal relationship to burnout, and an idea of what to do to help reduce, relieve, and manage it.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    Stacy Thayer
    Ph.D, Clinical and Organizational/Business Psychology, Norfolk State University [@Norfolkstate]
    On LinkedIn | https://www.linkedin.com/in/stacythayer/
    On Twitter | https://twitter.com/DrStacyThayer
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Session | Trying to Be Everything to Everyone: Let’s Talk About Burnout: https://www.blackhat.com/us-22/briefings/schedule/#trying-to-be-everything-to-everyone-lets-talk-about-burnout-28230

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    44 min
  • A Fully Trained Jedi You Are Not | A Conversation With Adam Shostack | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    While many in the InfoSec industry try to be all things to all people, sometimes that just isn't a winning strategy? What is? Let's have a chat with Adam Shostack to find out.

    About the session, "A Fully Trained Jedi, You Are Not"

    As software organizations try to bring security earlier in the development processes, what can or should regular software or operations engineers know about security? Taking as given that we want them to build secure systems, that demands a shared understanding of the security issues that might come up, and agreement on what that body of knowledge might entail. Without this knowledge, they'll keep building insecure systems. With them, we can have fewer recurring problems that are trivially attackable.

    Training everyone at a firm is expensive. Even if the training content is free, people's time is not. If you have 1,000 people, one hour per person is half a person year (before any overhead). So there is enormous pressure to keep it quick, ensure it meets compliance standards like PCI, and … the actual knowledge we should be conveying is almost an afterthought. We need to design knowledge scaffolding and tiered approaches to learning, and this talk offers a structure and tools to get there.

    We don't need every developer to be a fully trained Jedi, and we don't have time to train everyone to that level or even as much as we train security champs. So what could we ask everyone to know, and how do we determine what meets that bar?

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    Adam Shostack
    President at Shostack & Associates
    On LinkedIn | https://www.linkedin.com/in/shostack/
    On Twitter | https://twitter.com/adamshostack
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Session | A Fully Trained Jedi, You Are Not: https://www.blackhat.com/us-22/briefings/schedule/#a-fully-trained-jedi-you-are-not-26650

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    41 min
  • Open Threat Hunting Framework: Enabling Orgs To Build, Operationalize, And Scale Threat | A Conversation With John Dwyer | Black Hat 2022 And DEF CON 30 Las Vegas Event Coverage | Redefining CyberSecurity Podcast With Sean Martin And Marco Ciappelli

    Threat hunting is all the rage. But what the heck is it? "Ask 10 InfoSec professionals to define threat hunting, and you'll get 11 different answers," writes John Dwyer in his Black Hat session abstract. Will we get to hear the 12th definition in this episode?

    About the session, "The Open Threat Hunting Framework: Enabling Organizations to Build, Operationalize, and Scale Threat Hunting"

    "Ask 10 infosec professionals to define threat hunting and you'll get 11 different answers." Threat hunting is one of those interesting components of cybersecurity where everyone knows they should be doing it but not everyone can fully articulate what threat hunting is.

    In our roles as threat hunters, we're lucky enough to be witness to, and evaluate, the hunt programs of Fortune 100 companies, state and national governments, and partners and MSPs. This experience has shown us that one person's definition of threat hunting does not necessarily equal another's.

    If you do an Internet search for "how to build a threat hunting program" there are plenty of results and some include great insights into what makes a threat hunting program effective. However, while resources do exist, they're often tied to a specific vendor or a particular product and the best way to hunt using it. There's useful information, but you're left trying to find a way to make the proposed processes and techniques work for your environment and not the one driven by the vendor.

    "If you don't like the road you're walking, start paving another one." It's with that in mind that we're releasing a threat hunting framework that can help organizations start a threat hunting program as well as improve threat hunting operations for existing programs that's free and not tied to any particular technology.

    This framework will enable organizations to take control of building a threat hunting program by providing a clear path to operationalizing threat hunting as well as a well-defined threat hunting process to ensure threat hunters are set up for success.
    We've responded to far too many incidents that could have been prevented with solid threat hunting operations and we hope this project can help prevent future incidents.

    Be sure to catch all of our conversations from Black Hat and DEF CON 2022 at https://www.itspm.ag/bhdc22

    ____________________________

    Guest
    John Dwyer
    Head of Research at IBM X-Force [@IBM | @XForceIR | @IBMSecurity]
    On LinkedIn | https://www.linkedin.com/in/john-dwyer-xforce/
    On Twitter | https://twitter.com/TactiKoolSec
    ____________________________

    This Episode’s Sponsors

    CrowdSec | https://itspm.ag/crowdsec-b1vp
    Edgescan | https://itspm.ag/itspegweb
    Pentera | https://itspm.ag/pentera-tyuw

    ____________________________

    Resources

    Session | The Open Threat Hunting Framework: Enabling Organizations to Build, Operationalize, and Scale Threat Hunting: https://www.blackhat.com/us-22/briefings/schedule/#the-open-threat-hunting-framework-enabling-organizations-to-build-operationalize-and-scale-threat-hunting-26702

    ____________________________

    For more Black Hat and DEF CON  Event Coverage podcast and video episodes visit: https://www.itspmagazine.com/black-hat-2022-and-def-con-hacker-summer-camp-las-vegas-usa-cybersecurity-event-and-conference-coverage

    Are you interested in telling your story in connection with Black Hat and DEF CON by sponsoring our coverage?
    👉 https://itspm.ag/bhdc22sp

    To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
    https://www.itspmagazine.com/redefining-cybersecurity-podcast

    Are you interested in sponsoring an ITSPmagazine Channel?
    👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network

    38 min

About Redefining CyberSecurity

From the publisher's feed

Redefining CyberSecurity Podcast

More shows like Redefining CyberSecurity

This American Life by This American Life

This American Life

90,949 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

The ITSPmagazine Podcast by ITSPmagazine, Sean Martin, Marco Ciappelli

The ITSPmagazine Podcast

30 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hard Fork by The New York Times

Hard Fork

5,554 Listeners

Audio Signals Podcast by ITSPmagazine, Marco Ciappelli, Sean Martin

Audio Signals Podcast

2 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

Microsoft Threat Intelligence Podcast by Microsoft

Microsoft Threat Intelligence Podcast

23 Listeners

Stories From Space by ITSPmagazine, Matthew S Williams

Stories From Space

4 Listeners

An Analog Brain In A Digital Age | With Marco Ciappelli by Marco Ciappelli

An Analog Brain In A Digital Age | With Marco Ciappelli

0 Listeners

CyberSecurity Summary by CyberSecurity Summary

CyberSecurity Summary

5 Listeners