
Sign up to save your podcasts
Or


The founder's journey can directly impact what a company focuses on and why. In this Asgardeo by WSO2 story, you'll get to hear how their work is making the world a better place through software.
Starting a business built on the premise of offering open-source software wasn't something IBM wanted to do a couple of decades ago. That didn't stop WSO2's founder and CEO, Sanjiva Weerawarana, from taking his mission in life and turning it into an operational reality for his company, creating and helping foundations and non-profits in Sri Lanka and around the world along the way.
It was this initial desire to do good that continues to thrive in everything that WSO2 does - including the launch of their app authentication as a service division, Asgardeo, a customer identity, and access management (CIAM) offering which helps developers implement secure authentication flows to apps or websites in a few simple steps.
Developers don't have to be identity experts. They don't even have to write identity-specific code. They modify the code already in the web page or mobile app by cutting and pasting the bits of code, templates, and workflows that Asgardeo provides.
The use cases are many - both directly a part of a single application and as part of other services where identity is built in.
Please tune in to hear WSO2's origin story, the creation of Asgardeo and the value it brings to the developer community, and the multiple case studies that our guest from Asgardeo, Michael Bunyard, brings to life during this conversation.
Note: This story contains promotional content. Learn more.
Guest
Michael Bunyard
Vice President and Head of Marketing, IAM at WSO2 [@wso2] Asgardeo [@asgardeo]
On Linkedin | https://www.linkedin.com/in/michaelbunyard/
On Twitter | https://twitter.com/mickeydb
Resources
Learn more about WSO2 Asgardeo and their offering: https://itspm.ag/asgardeo-by-wso2-u8vc
Create seamless login experiences for your application in minutes: https://itspm.ag/asgardmn1x
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
For our next Chats On The Road for RSA Conference 2022, we talk about security program transformation through the successful development and implementation of security framework and program management.
About the RSAC 2022 Session, The Zoom Effect: A Framework for Security Program Transformation:
“When companies experience rapid growth, information security organizations must adapt to meet business needs. Establishing a robust framework can help these teams communicate and gain executive support for their program. This session will outline a framework to help transform and scale an information security program and share key learnings that can be applied to other programs.”
Tune in and be sure to join us for more from RSA Conference USA 2022!
____________________________
Guests
Heather Ceylan
Head of Security Standards, Compliance, and Customer Assurance at Zoom [@Zoom]
On LinkedIn | https://www.linkedin.com/in/heatherceylan/
Ariel Chavan
Head of Security Product and Program Management at Zoom [@Zoom]
On LinkedIn | https://www.linkedin.com/in/ariel-c-ab445a50/
____________________________
This Episode’s Sponsors
HITRUST: 👉 https://itspm.ag/itsphitweb
CrowdSec: 👉 https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉 https://itspm.ag/blue-lava-w2qs
BlackCloak 👉 https://itspm.ag/itspbcweb
AppViewX 👉 https://itspm.ag/appviewx-cbye
Checkmarx 👉 https://itspm.ag/checkmarx-i9o5
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
RSAC Session | The Zoom Effect: A Framework for Security Program Transformation: https://www.rsaconference.com/USA/agenda/session/The%20Zoom%20Effect%20A%20Framework%20for%20Security%20Program%20Transformation
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
On the surface, building an information security program may appear as is in its name, a single program. However, in reality, there are countless elements — sub-programs and adjacent programs, if you will — that comprise a comprehensive information security program.
In this conversation, we explore the overarching program, of course, including:
But, we will also look at all (or, as many as we can) of the sub-programs or adjacent programs that support the main InfoSec program. Things like network security, DevSecOps, risk management, data protection, regulatory compliance, and incident response — just to name a few.
Join us for this conversation and bring your questions about how best to plan, prioritize, budget, staff, and implement a successful information security program.
It's time to explore reality.
____________________________
Guests
Mari Galloway
CEO and a founding board member for the Women's Society of Cyberjutsu (WSC) [@womenCyberjutsu]
On LinkedIn | https://www.linkedin.com/in/themarigalloway/
On Twitter | https://twitter.com/marigalloway
James Leslie
CIO at Cambridge Housing Authority [@CambHousing]
On LinkedIn | https://www.linkedin.com/in/jameseleslie/
Cambridge Housing Authority | https://www.cambridge-housing.org
____________________________
This Episode’s Sponsors
HITRUST: 👉 https://itspm.ag/itsphitweb
CrowdSec: 👉 https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉 https://itspm.ag/blue-lava-w2qs
BlackCloak 👉 https://itspm.ag/itspbcweb
AppViewX 👉 https://itspm.ag/appviewx-cbye
Checkmarx 👉 https://itspm.ag/checkmarx-i9o5
____________________________
Resources
Watch Live on YouTube: https://www.youtube.com/watch?v=mg6aeYIDNQw
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
For our next Chats On The Road to RSA Conference 2022, we talk about voices, biometrics, metadata, privacy, neurology, deep fakes, and so much more. Join us for a chat to hear how your voice may be doing things for — and against — you in all aspects of life and work.
About the RSAC 2022 Session, Can You Hear Me Now? Security Implications of Voice as the New Keyboard
"Use of voice as a biometric identifier or as a virtual keyboard is growing. While AI/ML have vastly improved capabilities, there are challenges to relying on voice. Get it right and remove user friction and accelerate input. Get it wrong and introduce new vulnerabilities. As uses for vocal and silent speech recognition emerge and expand, security teams need to consider the potential security risks."
with:
Rébecca Kleinberger, Voice Researcher at MIT Media Lab [@MIT @medialab] and Disruptive Research Strategist at HARMAN International [@Harman]
Jeremy Grant, Managing Director, Technology Business Strategy, Venable LLP [@jgrantindc]
Lisa Lee, Chief Security Advisor/Lead for Vertical Industries and Engagement, Microsoft [@Microsoft]
Tune in and be sure to join us for more from RSA Conference USA 2022!
____________________________
Guest
Rébecca Kleinberger
Voice Researcher at MIT Media Lab and Disruptive Research Strategist at HARMAN International
On LinkedIn | https://www.linkedin.com/in/rebklein/
Website | https://rebeccakleinberger.com/
____________________________
This Episode’s Sponsors
HITRUST: 👉https://itspm.ag/itsphitweb
CrowdSec: 👉https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉https://itspm.ag/blue-lava-w2qs
BlackCloak 👉https://itspm.ag/itspbcweb
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
RSAC Session | Can You Hear Me Now? Security Implications of Voice as the New Keyboard: https://www.rsaconference.com/USA/agenda/session/Can%20You%20Hear%20Me%20Now%20Security%20Implications%20of%20Voice%20as%20the%20New%20Keyboard
TEDTalk | Why you don't like the sound of your own voice: https://www.ted.com/talks/rebecca_kleinberger_why_you_don_t_like_the_sound_of_your_own_voice
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
For our next Chats On The Road to RSA Conference 2022, we talk about the need to advance our tools, techniques, and our environment to better handle the risks and threats facing our organization. No surprise, say hello to the cloud.
About the RSAC 2022 Session with Phillip Wylie | Building a Cloud-Based Pentesting Platform
“Often offensive cybersecurity professionals require a way to perform external pentesting of Internet facing targets. This ability to test externally facing systems is nothing new and has been done over the years using various configurations. In this presentation attendees will learn how to build a cloud-based pentesting environment useful to pentesters, red teamers, and bug bounty hunters.”
Join us for this conversation, meet Phillip in San Francisco, and start poking at the cloud to make it rain vulnerabilities!
____________________________
Guest
Phillip Wylie
On ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/phillip-wylie
____________________________
This Episode’s Sponsors
HITRUST: 👉https://itspm.ag/itsphitweb
CrowdSec: 👉https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉https://itspm.ag/blue-lava-w2qs
BlackCloak 👉https://itspm.ag/itspbcweb
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
RSAC Session | Building a Cloud-Based Pentesting Platform: https://www.rsaconference.com/USA/agenda/session/Building%20a%20Cloud-Based%20Pentesting%20Platform
Recommended Reading Available in the RSAC Bookstore:
The Pentester BluePrint: Starting a Career as an Ethical Hacker (ISBN: 978-1-119-68430-5) by Phillip Wylie
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
For more podcast stories from The Hacker Factory with Phillip Wylie, visit: https://www.itspmagazine.com/the-hacker-factory-podcast
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
Organizations have made little progress in addressing cyber risk. This is in large part because they have viewed the issue with an excessively narrow focus as just a technical/operational issue. This needs to change.
To compete in the modern economy, enterprises must engage in digital transformation, which can generate a substantial increase in growth and profitability but can also vastly increase risk. Sure, foundational technical security measures are necessary, but they, alone, are not sufficient to address cyber threats. Cybersecurity must be an enterprise-wide risk management issue built on appropriate understanding, structure, investment, and risk-management methods.
Listen in to learn more about why, and how, we need to fundamentally rethink our approach to cybersecurity.
____________________________
Guest
Larry Clinton
President and CEO of the Internet Security Alliance (ISA) [@isalliance]
On LinkedIn | https://www.linkedin.com/in/larry-clinton-20237b4/
On YouTube | https://www.youtube.com/channel/UCbeFbrVg-aNu-mMSzsCiYnw
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Learn more about ISA: https://www.isalliance.org
On LinkedIn: https://www.linkedin.com/company/internet-security-alliance
On Twitter: https://twitter.com/isalliance
On Facebook: https://www.facebook.com/ISAlliance
ISA Publications:
https://isalliance.org/isa-publications/cyber-risk-oversight-handbook/
https://isalliance.org/isa-publications/international-cyber-risk-management-handbooks/
Book | Cybersecurity for Business: Organization-Wide Strategies to Ensure Cyber Risk Is Not Just an IT Issue: https://www.amazon.com/Cybersecurity-Business-Organization-Wide-Strategies-Ensure-dp-1398606146/dp/1398606146/ref=mt_other?_encoding=UTF8&me=&qid=1648037695
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
For our next Chats On The Road to RSA Conference 2022, we talk about transformation. Which, of course, can't be accomplished without talking about change. Which is constant.
About the RSAC 2022 Keynote with Rohit Ghai, Chief Executive Officer of RSA:
“Emerging technologies, expanding connections, hidden vulnerabilities: our sector understands that the only constant is change. As the world adapts once again, our industry’s experience shaping transformational shifts will determine the next normal. So let’s review how we’ve evolved, examine our missteps, predict where we’re headed, and start planning our next transformation.”
Tune in and be sure to join us for more from RSA Conference USA 2022!
____________________________
Guest
Rohit Ghai
Chief Executive Officer of RSA [@RSAsecurity]
On LinkedIn | https://www.linkedin.com/in/rohitghai/
On Twitter | https://twitter.com/rohit_ghai
____________________________
This Episode’s Sponsors
HITRUST: 👉https://itspm.ag/itsphitweb
CrowdSec: 👉https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉https://itspm.ag/blue-lava-w2qs
BlackCloak 👉https://itspm.ag/itspbcweb
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
RSAC Keynote Session | The Only Constant: https://www.rsaconference.com/USA/agenda/session/The%20Only%20Constant
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
The U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) released a Request for Information (RFI) seeking input from the public on two requirements of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act), as amended in 2021. How does it impact cybersecurity and risk management programs? Why do (should) CISOs care about this? Are we about to throw more money at this problem?
Maybe a smart question: Is there an opportunity to be smarter?
While all are important, that final question is certainly the most valid question. But, the details of the provisions will come when the community feedback comes in. The thing to make note of as you listen to this episode is that there's an opportunity to shape these provisions for the better of the overall healthcare ecosystem, moving beyond lowest common denominator frameworks, standards, and controls.
John Houston and Michael Parisi share their thoughts in the current state of cyber risk management affairs, the opportunity to do more in the RFI and potential responses coming in from the community, and how John's experience with an advanced, mature risk management program at UPMC can help set the bar for what's possible — not just from a guidance or framework perspective, but from a fiscally responsible, scalable, operational perspective.
Listen in to learn more about the RFI and the role you can have in shaping its outcome.
Not in the healthcare space? You should still pay attention. There's a lot going on in the healthcare sector that other industries can leverage.
Note: This story contains promotional content. Learn more.
____________________________
Guests
John Houston
Vice President, Information Security and Privacy; Associate Counsel at UPMC [@UPMC]
On Linkedin | https://www.linkedin.com/in/john-houston-5b9915b/
Michael Parisi, VP of Adoption, @HITRUST
____________________________
Catch the webcast and the podcast here: https://itspm.ag/hitrust-hhs-ocr-hitech-rfi
Be sure to visit HITRUST at https://itspm.ag/itsphitweb to learn more about their offering.
____________________________
Resources
News Release: https://www.hhs.gov/about/news/2022/04/06/hhs-ocr-seeks-public-comment-on-recognized-security-practices-sharing-civil-money-penalties-monetary-settlements-under-hitech-act.html
Individuals seeking more information about the RFI or how to provide written or electronic comments to OCR should visit the Federal Register to learn more: https://www.federalregister.gov/documents/2022/04/06/2022-07210/considerations-for-implementing-the-health-information-technology-for-economic-and-clinical-health
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
____________________________
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
What if we could create the Internet architecture from scratch? You might think that this is a crazy endeavor, but that's exactly what a research team in Zurich, Switzerland, is doing. And for good reason.
In today's episode, we are joined by Nicola Rustignoli, a research assistant at the Network Security Group at ETH Zürich, to take a look at the history of the Internet, its purpose, the challenges it has introduced, and the path forward to an Internet that allows for its intent to be met while maintaining scalability, control, and resiliency. Nicola works on making the Internet more secure and reliable with the SCION Architecture and by helping to start the SCION Foundation.
SCION was born as a research project 11 years ago, from the research question: how secure can an Internet be? There's a lot to learn from this project.
About the SCION Architecture
SCION is the first clean-slate Internet architecture designed to provide route control, failure isolation, and explicit trust information for end-to-end communication. SCION organizes existing ASes into groups of independent routing planes, called isolation domains, which interconnect to provide global connectivity. Isolation domains provide natural isolation of routing failures and misconfigurations, give endpoints strong control for both inbound and outbound traffic, provide meaningful and enforceable trust, and enable scalable routing updates with high path freshness. As a result, the SCION architecture provides strong resilience and security properties as an intrinsic consequence of its design. Besides high security, SCION also provides a scalable routing infrastructure, and high efficiency for packet forwarding. As a path-based architecture, SCION end hosts learn about available network path segments, and combine them into end-to-end paths that are carried in packet headers. Thanks to embedded cryptographic mechanisms, path construction is constrained to the route policies of ISPs and receivers, offering path choice to all the parties: senders, receivers, and ISPs. This approach enables path-aware communication, an emerging trend in networking. These features also enable multi-path communication, which is an important approach for high availability, rapid failover in case of network failures, increased end-to-end bandwidth, dynamic traffic optimization, and resilience to DDoS attacks.
Why a clean-slate design? Why can't we adopt existing solutions? Is it easy to "replace" the Internet?
Listen in to learn more about this exciting program.
____________________________
Guest
Nicola Rustignoli
Research Assistant at ETH Zürich and Founding Engineer at the SCION Association.
On LinkedIn | https://www.linkedin.com/in/nicola-rustignoli-830b7512/
On Twitter | https://twitter.com/Nicorusti
On YouTube | https://www.youtube.com/channel/UCATqViXMlA0cCroLuoJVAGw
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Learn more about SCION: https://scion-architecture.net/
On LinkedIn: https://www.linkedin.com/company/78769571
On Twitter: https://twitter.com/SCIONassociatio
On Facebook: https://www.facebook.com/SCIONinternet
SCION Day 2022 videos: https://scion-architecture.net/pages/scion_day_2022/
“The Complete Guide to SCION” is coming out with Springer Verlag in June 2022. An old version is open access and available on scion-architecture.net
The White House & 50 more countries recently released a Declaration for the Future of Internet: https://www.whitehouse.gov/wp-content/uploads/2022/04/Declaration-for-the-Future-for-the-Internet_Launch-Event-Signing-Version_FINAL.pdf
The FCC recently launched an inquiry about routing security: https://www.fcc.gov/document/fcc-launches-inquiry-internet-routing-vulnerabilities
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Dr Chris Pierson has held many roles and has been a regular speaker at RSA Conference over the years. What's he up to this year as the event goes back to in-person engagements?
As the CEO of BlackCloak, Chris Pierson is looking forward to connecting with peers, partners, customers, and prospects as the world of executive cybersecurity heats up. In addition to seeing friends old and new, Dr Pierson has two sessions in which he will be participating. He shares some insights into both of these sessions. Here's a snippet for each:
Collateral Damage: Prepping Your Organization for a Supply Chain Attack
Supply chain risks can allow a backdoor into a company. This learning lab will focus on a fast moving scenario that examines risks to a company from hardware and software and will focus on the (1) risk assessment, (2) governance, and (3) response and isolation phases. This session will follow Chatham House Rule to allow for free exchange of information and learning. We look forward to participants actively engaging in the discussion and remind attendees that no comment attribution or recording of any sort should take place. This is a capacity-controlled session. If added to your schedule and your availability changes, please remove this session from your schedule to allow others to participate. A Learning Lab with James Shreve, Partner and Cybersecurity Chair, Thompson Coburn LLP
Hacking Back – To Be or Not to Be?
Are there options to hack back for ransomware attacks? Without deterrence for ransomware attacks it is unlikely there will be changes to the risk equation that hackers think through. We’ll discuss legal, ethical, operational, and security issues surrounding hacking back and give some insight into potential pitfalls for getting attribution incorrect or causing collateral damage. A law track session with Giorgi Gurgenidze, Founder, GSI Partners and James Shreve, Partner and Cybersecurity Chair, Thompson Coburn LLP.
Chris has some other things up his sleeve as well. Can you say MySpace? 🤔
Note: This story contains promotional content. Learn more.
Guest
Chris Pierson
On Linkedin 👉 https://www.linkedin.com/in/drchristopherpierson/
On Twitter 👉 https://twitter.com/drchrispierson
____________________________
Learn more about BlackCloak and their offering: https://itspm.ag/itspbcweb
Connect with BlackCloak at RSA Conference: https://itspm.ag/94949a
Watch the video here: https://youtu.be/rqu47E8ryXY
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
From the publisher's feed

90,949 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

418 Listeners

30 Listeners

179 Listeners

191 Listeners

73 Listeners

137 Listeners

5,554 Listeners

2 Listeners

46 Listeners

23 Listeners

4 Listeners

0 Listeners

5 Listeners