
Sign up to save your podcasts
Or


For our second Chats On The Road to RSA Conference 2022, we talk about a critical cybersecurity initiative led by the World Economic Forum and the Cyber Threat Alliance. It is about mapping the cybercrime ecosystem and its corresponding panel during this year's conference.
Sean and Marco are honored to introduce and tease this important upcoming session on their traditional "Chats On The Road to RSA Conference 2022" with guests: Michael Daniel & Tal Goldstein.
About the session:
“Although cybercrime is now a national security threat, our understanding of the cybercriminal ecosystem remains limited. The industry needs a holistic map to conduct effective disruption, allocate resources efficiently, and impose meaningful costs on criminal actors. The WEF has initiated a project to develop this map. This panel will discuss the mapping project’s results to date and where it is going.”
RSAC 2022 Panel With
Michael Daniel
Moderator | President and Chief Executive Officer, Cyber Threat Alliance
Tal Goldstein
Panelist | Head of Strategy, Centre for Cybersecurity, World Economic Forum Centre for Cybersecurity
Amy Hogan-Burney
Panelist | Associate Counsel and General Manager, Digital Crimes Unit, Microsoft
Derek Manky
Panelist | Chief of Security Insights & Global Threat Alliances, Fortinet
Tune in and be sure to join us for more from RSA Conference USA 2022!
____________________________
Guests
Michael Daniel
President and Chief Executive Officer, Cyber Threat Alliance [@CyberAlliance]
On LinkedIn | https://www.linkedin.com/in/j-michael-daniel-7b71a95/
On Twitter | https://twitter.com/CyAlliancePrez
Tal Goldstein
Head of Strategy, Centre for Cybersecurity, World Economic Forum Centre [@wef] for Cybersecurity [@WEFCybersec]
On LinkedIn | https://www.linkedin.com/in/tal-goldstein-a7191296/
____________________________
This Episode’s Sponsors
HITRUST: 👉https://itspm.ag/itsphitweb
CrowdSec: 👉https://itspm.ag/crowdsec-b1vp
Blue Lava: 👉https://itspm.ag/blue-lava-w2qs
BlackCloak 👉https://itspm.ag/itspbcweb
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
RSAC Session | Mapping the Cybercriminal Ecosystem: https://www.rsaconference.com/USA/agenda/session/Mapping%20the%20Cybercriminal%20Ecosystem
____________________________
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
GRC is comprised of the ethical management of an organization combined with the organization’s ability to identify, quantify, and manage risk, along with the ability to demonstrate compliance for these things in connection with internal, industry, and regulatory standards, frameworks, and requirements. If defined, implemented, and managed correctly, the organization should be in a strong position to withstand operational challenges and threats they face driven by forces such as market dynamics, competitive landscape, employee behavior, breaks in the supply chain, and exposure to cyberattacks.
Join us for this conversation where we will discuss:
◾️ What is the current definition of GRC
◾️ What are the objectives of GRC plan
◾️ What components make up a GRC plan
◾️ Who owns the plan, who are the key stakeholders
◾️ How does a GRC plan get defined and implemented
◾️ What outcomes can a company expect to achieve
◾️ How does an organization define and measure success with their GRC plan
____________________________
Guest
Kouadjo Bini
Information Security Officer of American State Bank and Trust and Founder Infosec Tattle
On LinkedIn | https://www.linkedin.com/in/kentia-bini/
On LinkedIn | https://www.linkedin.com/company/infosectattle
On Twitter | https://twitter.com/infosec_tattle
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Assessing cyber risk in M&A: https://www.ibm.com/downloads/cas/RJX5MXJD
NIST risk management framework: https://csrc.nist.gov/projects/risk-management/about-rmf
____________________________
Catch the on-demand live stream video and podcast here: https://www.itspmagazine.com/live-panels/governance-risk-and-compliance-protecting-the-business-with-policies-controls-and-audits-redefining-cybersecurity-with-sean-martin
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
How can an industry have so much data and information yet still lack the knowledge necessary to make quick, meaningful, impactful decisions? There could be many reasons, but one is no longer a missing intelligence-sharing platform.
In this second chapter of our conversation with CrowdSec CEO, Philippe Humeau, we invite The Hacker Maker, Phillip Wylie, to bring his penetration testing experience and insights. Together we explore the value of investing in the cybersecurity community information sharing platform as a way to do way more than protect your organization. By doing so, we can help secure other businesses and whole communities in the neighbors around you, such as a local hospital that could experience an attack that you've already seen on your network.
The value of investing in the security knowledge sharing economy directly impacts IT operations, security operations, businesses, society, and, therefore, humanity.
Join us for a philosophical yet fun, thought-provoking conversation that will likely prompt you to not only share this podcast with your friends, colleagues, and peers but also start sharing your cybersecurity insights with your digital neighbors through the power of the CrowdSec platform.
Note: This story contains promotional content. Learn more.
Guests
Philippe Humeau
CEO at CrowdSec [@Crowd_Security]
On Linkedin | https://www.linkedin.com/in/philippehumeau/
On Twitter | https://twitter.com/philippe_humeau
Phillip Wylie
On ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/phillip-wylie
____________________________
Be sure to visit CrowdSec at https://itspm.ag/crowdsec-b1vp to learn more about their offering.
On Linkedin 👉https://www.linkedin.com/company/crowdsec/
On Twitter 👉https://twitter.com/Crowd_Security
Free access to the CrowdSec console: https://itspm.ag/crowdsec-6b7321
Watch the video here: https://itspmagazine.com/their-stories/investing-in-the-crowd-means-investing-in-society-and-humanity-a-crowdsec-story-with-philippe-humeau-and-phillip-wylie
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
The rise of digitalization has led to more interconnected rail systems. While this has propelled forward our trains and metros at some seriously high speed, it has also dramatically expanded the threat landscape.
In response, governments around the world are racing to implement measures that promote technological advancements for these rail systems whilst assuring that the systems are protected and secure. Sure, it's easy to think about providing timely service, operating efficiently, delivery comfort, keeping up constant communications, and more – but what really matters is that these digital data centers remain safe as they travel between and arrive at various stations both out in the sticks and in the heart of the cities.
Where does this leave rail companies? What steps should they take in the event of a cyberattack?
Listen in as Sean speaks with Amir Levintal as they get on track as they dig into the elements of the rail systems from the sensors to the tracks to the WiFi and more. It doesn't take long before they jump the rails to test the boundaries of reality.
____________________________
Guest
Amir Levintal
CEO and CoFounder of Cylus Cybersecurity [@cylus_security]
On LinkedIn | https://www.linkedin.com/in/amir-levintal/
On Twitter | https://twitter.com/amirlevintal
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Understanding IEC 62443: https://www.iec.ch/blog/understanding-iec-62443
European Standard CLC/TS 50701 Railway applications - Cybersecurity: https://www.en-standard.eu/clc/ts-50701-2021-railway-applications-cybersecurity/
Train of Consequences: The Real Cost of Rail Cybersecurity Incidents: https://www.cylus.com/post/the-real-cost-of-rail-cybersecurity-incidents
The Long-Term Effects of Log4Shell on Railway Systems: https://www.cylus.com/post/log4shell-effect-railway-systems
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Consumers worry about sharing data online, yet most feel they have “no choice” but to share their data if they want to use online services. It's a catch 22 — and it is not a bus.
Trust is waning. A majority of consumers, globally, say that trust in the many digital service providers’ ability to keep their personal data secure has decreased over the past five years.
Still, despite serious concerns, most consumers share their darkest secrets online via cloud messaging services even though they recognize there would be repercussions for them if the information they shared was leaked.
No question, it's a catch 22. But what do we do? That's the catch. Again.
Have a listen to learn more about the connections and responsibilities between consumers and the businesses they rely upon to live their digital lives.
Note: This story contains promotional content. Learn more.
Guest
Terry Ray
SVP Data Security GTM, Field CTO and Imperva Fellow
On Linkedin | https://www.linkedin.com/in/terry-ray/
On Twitter | https://twitter.com/TerryRay_Fellow
Resources
Learn more about Imperva and their offering: https://itspm.ag/imperva277117988
Report | No Silver Linings: Insights into global consumers’ perception of trust, data security, and privacy in the digital world:
https://itspm.ag/impervpovw
Are you interested in telling your story?
https://www.itspmagazine.com/telling-your-story
We are thrilled to kick off our event coverage for our first Chats On The Road to RSA Conference 2022 with our good friends to us to give the latest and greatest for what we can expect at this year's event.
Listen in to hear more about the theme, venue, sessions, speakers, expo hall, community event, and so much more. And, yes, we decided to capture this one on video too, so be sure to give that a watch for a funny moment as well.
Tune in and be sure to join us for more from RSA Conference USA 2022!
____________________________
Guests
Linda Gray Martin
Vice President at RSA Conference [@RSAConference]
On LinkedIn | https://www.linkedin.com/in/linda-gray-martin-223708/
On Twitter | https://twitter.com/LindaJaneGray
Britta Glade
Senior Director, Content & Curation at RSA Conference [@RSAConference]
On LinkedIn | https://www.linkedin.com/in/britta-glade-5251003/
On Twitter | https://twitter.com/brittaglade
Cecilia Murtagh Marinier
Cybersecurity Advisor - Strategy, Innovation & Scholars at RSA Conference [@RSAConference]
On LinkedIn | https://www.linkedin.com/in/cecilia-murtagh-marinier-14967/
On Twitter | https://twitter.com/CMarinier
____________________________
This Episode’s Sponsors
HITRUST: https://itspm.ag/itsphitweb
CrowdSec: https://itspm.ag/crowdsec-b1vp
Blue Lava: https://itspm.ag/blue-lava-w2qs
____________________________
Resources
Learn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsac-b8ef76
____________________________
Catch the video here: https://youtu.be/UitxhJn2Gps
For more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2022-rsac-san-francisco-usa-cybersecurity-event-coverage
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Are you interested in telling your story in connection with RSA Conference by sponsoring our coverage?
👉 https://itspm.ag/rsac22sp
Your organization has precious resources all over the place: on-premises in the data center on servers and in databases; in the office, at home, on the road on desktops, laptops, tablets, mobile phones, and smart devices; in the cloud inside containers, applications, and a variety of storage services.
Assuming you have identified and verified the person and/or system and/or service as a valid entity, how do you ensure they only have access to these resources, when they need them, from the location they need them, from the system they are requesting them, and at the time they are requesting them? This challenge is much more complex than ensuring a user is set up in the directory and has entered a valid password. That’s what this discussion is going to be all about.
Join us for this session as we explore the following points:
◾️ What does “secure access” mean to security, to ops, to the users, to the business?
◾️ Does the conversation and language need to change between groups?
◾️ How and where is secure access managed?
◾️ How to deal with the systems, applications, and data?
◾️ How does it fit in with Risk Management and SecOps?
◾️ What are some key challenges orgs face?
◾️ What are some of the core elements many orgs leave out?
◾️ Are there processes and/or tools to make things easier?
◾️ Any best practices or tips to simplify the program?
____________________________
Guests
Shinesa Cambric
Identity Champion at Identity Defined Security Alliance [@idsalliance] | Principal Product Manager for Emerging Identity at Microsoft [@Microsoft]
On LinkedIn | https://www.linkedin.com/in/shinesa-cambric-cissp-ccsp-cisa®-0480685/
On Twitter | https://twitter.com/Gleauxbalsecur1
John Sapp Jr
VP, Information Security & CISO at Texas Mutual Insurance Company [@texasmutual]
On LinkedIn | https://www.linkedin.com/johnbsappjr
On Twitter | https://www.twitter.com/czarofcyber
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Identify Defined Security Alliance Best Practices: https://www.idsalliance.org/identity-defined-security-framework/best-practices/
Enterprise Risk - Engaging Others: https://www.isaca.org/resources/isaca-journal/issues/2020/volume-5/addressing-risk-using-the-new-enterprise-security-risk-management-cycle
____________________________
Catch the on-demand live stream video and podcast here: https://www.itspmagazine.com/live-panels/secure-access-and-authorization-keeping-precious-resources-safe-from-prying-eyes-and-bad-actors-redefining-cybersecurity-with-sean-martin
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
When it comes to implementing efficient and effective information security programs, higher education institutions can use all the help they can get. That's where the RRCoP community comes in.
In today's episode, our guests, Carolyn Ellis, Erik Deumens, and Michael Parisi talk through the goals of the RRCoP community and the impact is has on the higher education cybersecurity community as they work hard to raise the security and compliance posture for their institutions.
The 5 RRCoP Goals
Goal 1: Build a Community
The Regulated Research Community of Practice (RRCoP) builds a network of people able to help each other in implementing an affordable but effective cybersecurity and compliance program at academic institutions.
Goal 2: Collect and Share Resources
Establish a leadership training and development program accelerating availability of distributed university resources.
Goal 3: Advocate and Negotiate
Develop representation through strategic partnerships with industry and government entities.
Goal 4: Manage Change
The Department of Defense modified the DFARS clause to mandate that NIST 800-171 be followed for data classified and marked as CUI in 2017. The next evolution of this program, CMMC, has already undergone significant changes now called CMMC 2.0. Other agencies, for example, Department of Education, have indicated that they are considering following a similar path to safeguard data.
Goal 5: Simplify Compliance
A collective and streamline approach to compliance lowers the barrier to entrance for expansion of supported regulations by individual institutions.
____________________________
Guests
Carolyn Ellis
CMMC Program Manager at UC San Diego [@ucsandiego]
On LinkedIn | https://www.linkedin.com/in/carolynellis1/
Erik Deumens
Research Computing Director, Information Technology at University of Florida [@UF]
On LinkedIn | https://www.linkedin.com/in/deumens-erik-164167146/
Michael Parisi, VP of Adoption, @HITRUST
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
____________________________
Resources
Regulated Research Community of Practice: https://www.regulatedresearch.org/
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
In this episode, NIST Fellow, Ron Ross, and Pepperdine Graziadio Business School Advisory Board Member, Howard Miller, join the show to discuss risk assessment, reward analysis, and security management in the age of advanced technology and complex system innovation.
To secure a system, the sum of all of its parts must also be secure. This includes firmware, applications, APIs, networks, communications, storage, and more. Each complete system is often comprised of multiple subsystems, making it unique and bringing with it its own risk profile different from all other systems.
Join us as we explore the concept of analyzing the reward in connection to the risk as a means to help make better risk-vs-reward decisions in support of securely fostering innovation as opposed to stifling innovation out of fear, uncertainty, and doubt.
____________________________
Guests
Ron Ross
Fellow at National Institute of Standards and Technology (NIST) [@NIST]
On Twitter | https://twitter.com/ronrossecure
On LinkedIn | https://www.linkedin.com/in/ronrossecure/
Howard Miller
SVP, Director at Tech Secure and Adjunct Professor and Advisory Board Member at Pepperdine Graziadio Business School Cyber Risk Professional Certification [@Pepperdine / @GraziadioSchool]
On LinkedIn | https://www.linkedin.com/in/howardmillerrisk/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
ERMO - Enterprise Risk Management Optimization: https://link.springer.com/article/10.1007/s10669-021-09819-x
SAE Cyber Physical Systems Security Engineering Plan (CPSSEP) JA7496: https://www.sae.org/standards/content/ja7496/?_ga=2.203579798.760907735.1641314977-1116152771.1641314951
NIST Systems Engineering Group: https://www.nist.gov/el/systems-integration-division-73400/systems-engineering-group
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
We may see new "graph" processors in the future that can better handle the data-centric computations in data science. Will that be enough?
About David
David A. Bader is a Distinguished Professor in the Department of Computer Science and founder of the Department of Data Science and inaugural Director of the Institute for Data Science at New Jersey Institute of Technology. Prior to this, he served as founding Professor and Chair of the School of Computational Science and Engineering, College of Computing, at Georgia Institute of Technology.
____________________________
Guest
David Bader
Distinguished Professor and Director, Institute for Data Science, New Jersey Institute of Technology [@NJIT]
On Twitter | https://twitter.com/Prof_DavidBader
On LinkedIn | https://www.linkedin.com/in/dbader13/
On Facebook | https://www.facebook.com/ProfDavidBader
Website: https://davidbader.net/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
GitHub: https://github.com/Bader-Research
Arkouda: https://github.com/Bears-R-Us/arkouda
NJIT Institute for Data Science: https://datascience.njit.edu/
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
From the publisher's feed

90,949 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

418 Listeners

30 Listeners

179 Listeners

191 Listeners

73 Listeners

137 Listeners

5,554 Listeners

2 Listeners

46 Listeners

23 Listeners

4 Listeners

0 Listeners

5 Listeners