
Sign up to save your podcasts
Or


In a world where everything is connected and interdependent, complexity has become part of our very way of life, and it must be part of our way of thinking. But, especially when we look at infrastructure security, the boundaries between analog and digital, physical and cyber, are simply not there anymore.
In today's conversation, we discuss the importance of looking at our society, economy, and security as a complex system of interdependent subsystems. Everything is connected, and we are not just referring to IoT.
From bridges to nuclear plants, to the President's car, and all the way up to space, the security assessment of critical infrastructure is not a checklist but a mindset.
About The Book
As a manager or engineer have you ever been assigned a task to perform a risk assessment of one of your facilities or plant systems? What if you are an insurance inspector or corporate auditor? Do you know how to prepare yourself for the inspection, decided what to look for, and how to write your report?
This is a handbook for junior and senior personnel alike on what constitutes critical infrastructure and risk and offers guides to the risk assessor on preparation, performance, and documentation of a risk assessment of a complex facility. This is a definite “must read” for consultants, plant managers, corporate risk managers, junior and senior engineers, and university students before they jump into their first technical assignment.
____________________________
Guest
Ernie Hayden
On LinkedIn | https://www.linkedin.com/in/enhayden/
Publisher's Twitter | https://twitter.com/RothsteinPub
____________________________
Resources
Book: https://www.rothstein.com/product/critical-infrastructure-risk-assessment-the-definitive-threat-identification-and-threat-reduction-handbook/
____________________________
This Episode’s Sponsors
Archer: https://itspm.ag/rsaarchweb
Edgescan: https://itspm.ag/itspegweb
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Every organization has exposure to risk. Every organization experiences events that cross over the risk threshold to quickly realize they are facing an incident head-on.
It's how the organization prepares for these situations that matter most. Preparation is so much more than recognizing that a disaster might occur. It's also more than having a documented plan draft months (maybe even years ago) that, if activated, would prove worthless—or worse—counterproductive such that the disaster turns into an all-out crisis. A disaster doesn't need to result in a crisis, and that's what we will cover in this episode—how to keep the business running without killing the business in the process.
Join us for this session as we explore the following points:
◾️ What is a disaster?
◾️ Goals of a disaster recovery plan
◾️ How to build a functional plan
◾️ Who builds it?
◾️ Who validates it?
◾️ What is in the plan
◾️ How does a BC/DR plan fit into your IT/IS programs (IR, for example)
◾️ Testing/Tabletop exercises
____________________________
Guests
Dr Rebecca Wynn
Chief Cybersecurity Strategist & CISO at Click Solutions Group
On LinkedIn | https://www.linkedin.com/in/rebeccawynncissp
Gayle Anders
Global Business Continuity Program Manager at Netflix [@netflix]
On LinkedIn | http://linkedin.com/in/gayle-anders-business-continuity-professional
____________________________
This Episode’s Sponsors
Archer: https://itspm.ag/rsaarchweb
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
____________________________
Catch the on-demand live stream video and podcast here: https://www.itspmagazine.com/live-panels/business-continuity-building-and-operationalizing-a-functional-disaster-recovery-plan-redefining-cybersecurity-with-sean-martin
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Data is the fuel that powers the business. What are organizations doing to protect it?
Organizations have become the custodians of critical information needed to remain competitive and sensitive information that their customers have entrusted them with. While some organizations have taken this responsibility seriously, governments (state, federal, and international) have had to step in to help guide companies on how best to safely manage this data. There are a ton of rules to follow balanced with a ton of business goals to achieve. That's where a data security strategy and data security program come into play. But, what is data protection and how does it impact the business operations.
Join us for this session as we explore the following points:
◾️ Roles
◾️ Policies
◾️ Controls
◾️ Assessment
◾️ Demonstrating posture
◾️ Maintenance and tuning
◾️ Advice for the future
____________________________
Guests
Chris Daskalos
Data Protection Lead at University of Southern California [@USC]
On LinkedIn | https://www.linkedin.com/in/chrisdaskalos
Andy Rappaport
Data Security Architect at iRobot [@iRobot]
On LinkedIn | https://www.linkedin.com/in/andyrappaport/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Data Security Roadmap Example: https://docs.google.com/presentation/d/1t6otQ5a8h3d8euN6bnzCZMxhPcKtVUKf/edit#slide=id.p1
____________________________
Catch the on-demand live stream video and podcast here: https://www.itspmagazine.com/live-panels/creating-a-data-security-strategy-and-operationalizing-a-mature-data-security-program-redefining-cybersecurity-with-sean-martin
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Do you think you know all of the cybersecurity vendors on the market? Think again. Need help getting a clear view for how they all fit into the bigger InfoSec picture in your org? Have a listen.
In today's episode, long-time industry analyst, Richard Stiennon, takes us on a journey down memory lane into the world of cybersecurity and the ever-growing landscape of innovation, technology, features, products, solutions, and more.
About the book
Security Yearbook 2020 was launched at RSA Conference 2020 on February 24 and has been identified as One of the Best Cybersecurity Books of 2021 by Ben Rothke!
The 2021 directory has been completely updated. 300 small vendors and two abject failures stopped supporting their websites in 2020. 600 new vendors were added, although only 13 high profile startups are listed. The Directory now contains 2,615 vendors of security products.
Two new stories of the pioneers of the cybersecurity industry have been added. Renaud Deraison, creator of Nessus, and Amit Yoran founder of Riptech and CEO of Tenable contribute their stories.
A new section has been added to track the performance of 21 publicly traded security vendors like Crowdstrike, Zscaler, Fortinet, and Palo Alto Networks.
Thanks to AGC Partners, Security Yearbook 2021 contains a complete listing of M&A activity for 2020.
There were over $10 billion in new investments in high-flying security vendors. A complete list and analysis of these deals is included.
The biggest difference in the directory this year is that the percent change in headcount is listed for each vendor. This is probably the most important metric for quickly assessing a vendor’s health. Successful vendors grow.
Having known each other for years, Richard and Sean reminisce and they talk about the past, present, and future of the entire cybersecurity field.
____________________________
Guest
Richard Stiennon
Chief Research Analyst at IT-Harvest [@cyberwar]
On Twitter | https://twitter.com/stiennon
On LinkedIn | https://www.linkedin.com/in/stiennon/
On YouTube | https://www.youtube.com/channel/UCJbNLvhmVGnRerhrSU1mFug
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Security Yearbook | A Complete History And Directory Of The Entire Cybersecurity Industry
- 2021 edition: https://it-harvest.com/shop/security-yearbook-2021/
- 2022 edition: https://it-harvest.com/shop/security-yearbook-2022/
Connect with Richard at IT-Harvest: https://it-harvest.com/
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
As the CISO role has revolved from chief security engineer to cyber risk advisor, successful CISOs are focusing on culture, strategy, and leadership. Let's discuss some real-world observations and explore some tips for what can prove to be successful across a variety of industries.
In addition to the fantastic conversation, there are a ton of resources that Rock and Dutch have provided. Have a listen, and then dig into the articles and reports to keep the learning going.
____________________________
Guests
Dutch Schwartz
Principal Security Specialist, Amazon Web Services (AWS) [@AWSSecurityInfo]
On Twitter | https://twitter.com/dutch_26
On LinkedIn | https://www.linkedin.com/in/dutchschwartz
On Clubhouse | @dutchzilla
Rock Lambros
CEO at RockCyber [@rockcyberllc], Cybersecurity Leader, and Co-Author of "The CISO Evolution: Business Knowledge for Cybersecurity Executives"
On Twitter | https://twitter.com/rocklambros
On LinkedIn | https://www.linkedin.com/in/rocklambros/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/imperva277117988
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Culture feels "squishy" post on LinkedIn: https://www.linkedin.com/posts/dutchschwartz_unicornsecuritysquad-ciso-cybersecurity-activity-6850499679394807808-Mc7Y
The Role Of A CISO In Creating A Strong Security Culture: https://www.eccu.edu/the-role-of-a-ciso-in-creating-a-strong-security-culture/
Use Networks to Drive Culture Change: https://sloanreview.mit.edu/article/use-networks-to-drive-culture-change/
Why Does Culture 'Eat Strategy For Breakfast'?: https://www.forbes.com/sites/forbescoachescouncil/2018/11/20/why-does-culture-eat-strategy-for-breakfast/
The EI Advantage: Driving Innovation and Business Success through the Power of Emotional Intelligence: https://hbr.org/sponsored/2019/08/the-ei-advantage-driving-innovation-and-business-success-through-the-power-of-emotional-intelligence
Building a Model of Organizational Cybersecurity Culture by Identifying Factors Contributing to Cybersecure Workplaces: http://web.mit.edu/smadnick/www/wp/2020-05.pdf
The Leader’s Guide to Corporate Culture: https://hbr.org/2018/01/the-leaders-guide-to-corporate-culture
Why Every Executive Should Be Focusing on Culture Change Now: https://sloanreview.mit.edu/article/why-every-executive-should-be-focusing-on-culture-change-now/
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
There's a cyber crisis brewing. Not the first. Definitely not the last. But current. Here's some advice as seen on social media (paraphrased)... "take your years of strategizing, planning, budgeting, staffing, and procuring … and do it all within a few days."
How is that helpful?
It isn't. It could actually be counter-productive.
With the rising concerns over the growing threat of cyberattacks from well-funded, highly-skilled, and aggressively-motivated bad actors, there's been a mad rush for offerings of advice and products and services from all around the web. While the intentions may be good, the expected outcomes may not match reality in some cases.
That's where the post I saw from Mick Douglas comes in ... a post of organized thoughts with actionable steps organizations can consider given their day-to-day playbook probably isn't going to hold to the intensity of a widespread cyber attack. There's a lot in the thread; we cover a good portion of it, but not all of it. There's also some discussion outside of the original post to help frame the conversation.
____________________________
Guest
Mick Douglas
InfoSec Innovations | SANS Principal Instructor | IANS Faculty
On Twitter | https://twitter.com/bettersafetynet
On LinkedIn | https://www.linkedin.com/in/mick-douglas/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/rsaarchweb
Archer: https://itspm.ag/itsphitweb
____________________________
Resources
Inspiring Tweet: https://twitter.com/bettersafetynet/status/1496496087741480960
National Council of ISACs: https://www.nationalisacs.org/
Other social posts mentioned:
https://www.linkedin.com/posts/rocklambros_mick-douglas-on-twitter-activity-6902610864369664000-KaBd
https://twitter.com/hackinglz/status/1497035113170886656
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
If the goal is to fill a role and keep it filled, we may be missing the point of hiring and retaining top talent.
More than ever, investing in the human element of cybersecurity is paramount. How we staff and maintain our cyber teams will determine the success of the individuals, the team, and the program.
In today's conversation, we connect with two authors, Leeza Garber and Scott Olson, to talk about this topic in-depth, as we explore the catalyst behind the writing of their book, Can. Trust. Will. Hiring for the Human Element in the New Age of Cybersecurity.
About the Book
Cyberthreats evolve at a staggering pace, and effective cybersecurity operations depend on successful teams. Unfortunately, statistics continue to illustrate that employers are not finding the people they need.
The Can. Trust. Will. system guides the C-Suite, HR professionals and talent acquisition to build unbeatable cybersecurity teams through advanced hiring processes and focused on-boarding programs. Additionally, this book details how successful cybersecurity ecosystems are best built and sustained, with expert analysis from high-level government officials, Fortune 500 CSOs and CISOs, risk managers, and even a few techies.
Those already in the field (and newbies) will glean invaluable knowledge about how to find their most effective position within a cybersecurity ecosystem. In a tech-driven environment, cybersecurity is fundamentally a human problem: and the first step is to hire for the human element.
Are you looking to fill roles? Or are you looking for people? This nuanced difference can make all the difference.
Listen in.
____________________________
Guests
Leeza Garber
Founder, Leeza Garber Esq Consulting LLC & Can. Trust. Will. LLC
On Twitter | https://twitter.com/leezagarber
On LinkedIn | https://www.linkedin.com/in/leeza-garber/
Scott Olson
Co-Founder, Can. Trust. Will. LLC
On LinkedIn | https://www.linkedin.com/in/scottolsonexec/
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/rsaarchweb
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
Book: Can. Trust. Will. Hiring for the Human Element in the New Age of Cybersecurity: https://www.amazon.com/Can-Trust-Will-Element-Cybersecurity-ebook/dp/B09H1V8LHL/
Cyber Seek: https://www.cyberseek.org/
Previous podcast with Scott Olson: Be Fascinated: What It Takes To Find Fulfillment And To Be A Good Leader | Redefining Security With Scott Olson
____________________________
To see and hear more Redefining Security content on ITSPmagazine, visit:
https://www.itspmagazine.com/redefining-security
Are you interested in sponsoring an ITSPmagazine Channel?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
Many organizations are ill-prepared when it comes to making sure their hospital is protected from risk, both from an organizational and IT standpoint. It's increasingly important to have a concrete risk assessment strategy, one that explicitly includes utilizing third-party (vendor) risk management.
When our guest, Jesse Fosolo, joined St. Joseph’s Health in August of 2014, he's completely flipped the risk assessment and IT protocols at the hospital on its head, partnering with the legal team—more specifically, General Counsel/Chief Operating Officer, Ebony Riley. This connection between the CISO and legal counsel has proven to be a huge win for risk management throughout the organization, mapping risks through various security frameworks, including HIPAA, NIST CSF, HITRUST, and others.
Listen in to get some third-party risk management insights from this New Jersey-based, 1000+ provider, 150+ location network healthcare organization created a Vendor Risk Management strategy as this dream team discuss their journey down risk management lane.
____________________________
Guests
Ebony Riley
Associate Council, St. Joseph's Health (@sjh_nj)
On LinkedIn | https://www.linkedin.com/in/ebonyriley/
Jesse Fasolo
Director, Technology Infrastructure & Cyber Security, Information Security Officer, St. Joseph's Health (@sjh_nj)
On LinkedIn | https://www.linkedin.com/in/jessefasolo/
____________________________
This Episode’s Sponsors
Archer: https://itspm.ag/rsaarchweb
HITRUST: https://itspm.ag/itsphitweb
____________________________
To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in advertising on ITSPmagazine?
👉 https://www.itspmagazine.com/sponsorship-introduction
Are you interested in sponsoring an ITSPmagazine podcast?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
As is common for the Redefining Security show, conversations are often inspired by a social post. This one about standards is no different. However, what you think about standards may be different after you listen to this episode.
Some of the social comments we discuss:
What are your views on the value of standards?
____________________________
Guests
Alyssa Miller
On ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/alyssa-miller
Accidental CISO
On Twitter | https://twitter.com/AccidentalCISO
____________________________
This Episode’s Sponsors
HITRUST: https://itspm.ag/itsphitweb
Archer: https://itspm.ag/rsaarchweb
____________________________
Resources
Inspiring Tweet | https://twitter.com/AlyssaM_InfoSec/status/1479210767513755648
____________________________
To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in advertising on ITSPmagazine?
👉 https://www.itspmagazine.com/sponsorship-introduction
Are you interested in sponsoring an ITSPmagazine podcast?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
The sea is broad and deep. So is the information that is created by and for the maritime vessels floating around and underneath the surface. What is this information used for? And how can it be misused?
Some OSINT should give us a few answers.
Let's hear from a hacker with a passion to explore this world of open source intelligence generated by the maritime industry - commercial, defense, and otherwise.
All aboard!
____________________________
Guest
Rae Baker
On LinkedIn | https://www.linkedin.com/in/rae-baker-7668644b/
On Twitter | https://twitter.com/wondersmith_rae
On YouTube | https://www.youtube.com/channel/UCdPwaG4HiqFR8nV2jg_IXBw
____________________________
This Episode’s Sponsors
Imperva: https://itspm.ag/rsaarchweb
HITRUST: https://itspm.ag/itsphitweb
____________________________
Resources
OSINT on the Ocean: Maritime Intelligence Gathering Techniques - https://wondersmithrae.medium.com/osint-on-the-ocean-maritime-intelligence-gathering-techniques-2ee39e554fe1
Maritime OSINT: Port Analysis - https://wondersmithrae.medium.com/maritime-osint-port-analysis-d09b4531728d
YouTube: Layer 8 2020: OSINT On The Ocean: Maritime Intelligence Gathering - https://www.youtube.com/watch?v=mfHYE5Xanfw
YouTube: Layer 8 2021: Illuminating Maritime Supply Chain Threats using OSINT: A Suez Canal Post Mortem - https://www.youtube.com/watch?v=GGIuP6fMZ2g
____________________________
To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
https://www.itspmagazine.com/redefining-cybersecurity
Are you interested in advertising on ITSPmagazine?
👉 https://www.itspmagazine.com/sponsorship-introduction
Are you interested in sponsoring an ITSPmagazine podcast?
👉 https://www.itspmagazine.com/podcast-series-sponsorships
From the publisher's feed

90,949 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

418 Listeners

30 Listeners

179 Listeners

191 Listeners

73 Listeners

137 Listeners

5,554 Listeners

2 Listeners

46 Listeners

23 Listeners

4 Listeners

0 Listeners

5 Listeners