Redefining CyberSecurity

Redefining CyberSecurity

By Sean Martin, ITSPmagazineBusinessTechnologyEducation
Download on the App Store

Redefining CyberSecurity episodes

  • Ethical Issues In Cybersecurity Research And Practice | Redefining CyberSecurity With Kevin Macnish And Jeroen Van Der Ham

    While it may seem appealing — and you can certainly try — sorry, but you can't tech your way out of ethics issues.

    In this episode we speak to co-authors of a research paper to critique existing governance in cyber-security ethics as they did so in providing an overview of some of the ethical issues facing researchers in the cybersecurity community and highlighting shortfalls in governance practice as part of their research work and resulting publication, Ethics in cybersecurity research and practice.

    ____________________________

    Guests
    Dr Kevin Macnish
    On Twitter 👉https://twitter.com/KMacnish
    On Linkedin 👉https://www.linkedin.com/in/kevinmacnish/

    Dr Jeroen van der Ham
    On Twitter 👉https://twitter.com/1sand0s
    On Linkedin 👉https://www.linkedin.com/in/vdham/

    ____________________________

    This Episode’s Sponsors

    HITRUST: https://itspm.ag/itsphitweb

    Semperis: https://itspm.ag/semperis-1roo

    ____________________________

    Resources
    Inspiration — Ethics in cybersecurity research and practice: https://www.sciencedirect.com/science/article/pii/S0160791X19306840

    Smart Information Systems in Cybersecurity: An Ethical Analysis: https://www.sciencedirect.com/science/article/pii/S2515856220300080?via%3Dihub

    Code of Ethics for Incident Response and Security Teams (ethicsfIRST): https://ethicsfirst.org/

    University of Twente and NCSC-NL: https://www.ncsc.nl/

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships

    42 min
  • Practical Cybersecurity Architecture: A Guide To Creating And Implementing Robust Designs For Cybersecurity Architects | Redefining CyberSecurity With Diana Kelley And Ed Moyle

    What is an architecture? Is it a document? A process? A policy? A map? A discipline? A mindset? When you hear what it is, you may have to re-evaluate how you approach your cybersecurity program. Are you ready?

    “The ideal architect should be a man of letters, a skillful draftsman, a mathematician, familiar with historical studies, a diligent student of philosophy, acquainted with music, not ignorant of medicine, learned in the responses of jurisconsults, familiar with astronomy and astronomical calculations.” ― Vitruvius

    About the Book
    Cybersecurity architects work with others to develop a comprehensive understanding of the business' requirements. They work with stakeholders to plan designs that are implementable, goal-based, and in keeping with the governance strategy of the organization.

    With this book, you'll explore the fundamentals of cybersecurity architecture: addressing and mitigating risks, designing secure solutions, and communicating with others about security designs. The book outlines strategies that will help you work with execution teams to make your vision a concrete reality, along with covering ways to keep designs relevant over time through ongoing monitoring, maintenance, and continuous improvement. As you progress, you'll also learn about recognized frameworks for building robust designs as well as strategies that you can adopt to create your own designs.

    By the end of this book, you will have the skills you need to be able to architect solutions with robust security components for your organization, whether they are infrastructure solutions, application solutions, or others.

    Guests
    Diana Kelley
    On ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/diana-kelley

    Ed Moyle
    On Twitter 👉 https://twitter.com/securitycurve
    On Linkedin 👉 https://www.linkedin.com/in/edmoyle/

    This Episode’s Sponsors
    Imperva: https://itspm.ag/imperva277117988

    Archer: https://itspm.ag/rsaarchweb

    Edgescan: https://itspm.ag/itspegweb

    ____________________________

    Resources
    Book — Practical Cybersecurity Architecture: A guide to creating and implementing robust designs for cybersecurity architects: https://www.amazon.com/Practical-Cybersecurity-Architecture-implementing-cybersecurity/dp/1838989927

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships

    39 min
  • Automated Feeds Are Killing The CTI Community; I Only Want Human Created Threat Intel!!! | Redefining CyberSecurity With CyberSquarePeg And Andy Piazza

    Threat intelligence automation should be how we share, not how “Intel” is produced.

    Yet, we continue to create more data - generate more noise - introduce more false positive - require more analysis - increase the need for correlation - which, in turn, forces the need for more automation.

    Guests
    CyberSquarePeg (aka Rebecca Ford)
    On Twitter 👉 https://twitter.com/CyberSquarePeg

    Andy Piazza
    On Twitter 👉 https://twitter.com/klrgrz
    On Linkedin 👉 https://www.linkedin.com/in/andypiazza/

    This Episode’s Sponsors
    Imperva: https://itspm.ag/imperva277117988

    Archer: https://itspm.ag/rsaarchweb

    Edgescan: https://itspm.ag/itspegweb

    ____________________________

    Resources
    What's Wrong with Cyber Threat Intelligence: https://www.tandfonline.com/doi/full/10.1080/08850607.2020.1780062

    CTI is Better Served with Context: Getting better value from IOCs: https://klrgrz.medium.com/cti-is-better-served-with-context-getting-better-value-from-iocs-496343741f80

    Considerations for Leveraging Cyber Threat Feeds Effectively: https://klrgrz.medium.com/considerations-for-leveraging-cyber-threat-feeds-effectively-1d1cfa9fb140

    Inspiring tweet thread: https://twitter.com/klrgrz/status/1382412354063831040

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships

    35 min
  • Supply Chain Resilience In A Time Of Techtonic Geopolitical Shifts | Redefining CyberSecurity With Andrea Little Limbago

    Geopolitical winds of change are upending global supply chains at an unprecedented pace and scope. There are challenges and opportunities.

    Guest
    Andrea Little Limbago
    On Twitter 👉 https://twitter.com/limbagoa
    On Linkedin 👉https://www.linkedin.com/in/andrea-little-limbago/

    This Episode’s Sponsors
    Edgescan: https://itspm.ag/itspegweb

    Key Resources Security: https://itspm.ag/keyresources-2876

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships

    20 min
  • The State Of Worldwide Cybersecurity From The People Who Run It | Redefining CyberSecurity With Dr. Reem Faraj AlShammari

    The CISO role has always been challenging. The last year brought the meaning of RESILIENCE to an all new level.

    Guest
    Dr Reem Faraj AlShammari
    On Twitter 👉  https://twitter.com/Q8Thunders
    On Linkedin 👉  https://www.linkedin.com/in/dr-reem-faraj-alshammari-b6324159/

    This Episode’s Sponsors
    Blue Lava: https://itspm.ag/blue-lava-w2qs

    Key Resources Security: https://itspm.ag/keyresources-2876

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    17 min
  • Don’t Be Afraid Of A Crisis And Don’t Let The Crisis Define You | Redefining CyberSecurity With Parham Eftekhari

    Pushing the Panic or the Not Panic button may as well just be a difference in company culture. Planning, readiness, and experience are part of it, but not all of it. It all starts with how we define a crisis and how we react to it.

    Successfully leading an organization through a crisis is one of the most challenging – and rewarding – experiences a leader will face in their career. Effective executives understand that the foundation for crisis management planning begins long before the problem arises and is grounded in developing cultures of trust and integrity.

    This episode explores the role of communication, relationships, accountability, humility, kindness, and confidence in navigating a crisis, giving listeners insight into how to lead their teams and organizations through adversity.

    If you are looking for ways to balance risk management with incident management... Have a listen.

    If you want to find the best path forward to escape the chaos that often surrounds a crisis... Have a listen.

    If you are wondering how to come out of a disaster, recovered as opposed to broken... Have a listen.

    Guest
    Parham Eftekhari, S.V.P. & Executive Director | The Cybersecurity Collaborative

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    Archer: https://itspm.ag/rsaarchweb

    Edgescan: https://itspm.ag/itspegweb

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    33 min
  • It's #TableTopTuesday On Twitter | What Serious Silliness Did We Spot While Redefining CyberSecurity With Meg Hargrove?

    Unless there's a plan that's been practiced, one's gut reaction is probably how things will roll when an incident occurs. #TableTopTuesday on Twitter from Meg Hargrove captures some of those "moments" — let's discuss.

    Before we do, though, do any of these sound like your go-to first step during a cyber incident?
    - “Brown alert”
    - “Cry for a minute”
    - “Update resume”

    While there may get a chuckle from someone looking in on a fake situation presented on social media, incident response is no joking matter when real life is at stake. And that's why I wanted to have a conversation with @cybersecmeg — what she is doing with #TableTopTuesday on Twitter is nothing short of brilliant: present an incident use case and get feedback from the community for how they would respond.

    There's no single right nor wrong answer, of course. And, the conversation doesn't just stop abruptly with an answer either — there's some good dialog from the community, presenting some solid options and some meaningful back-and-forth as the scenario unfolds.

    Take this scenario, for example:

    Credentials for your AWS cloud environment have been accidentally left hard coded into a PUBLIC GitHub repository. You check your cloud portal and find $75K worth of spend not created by your org. What do you do?

    Well, time us up. The incident is happening. What do you do? What should you do?

    First, listen to this chat with Meg and then check out the #TableTopTuesday threads to start planning and practicing.

    Guest
    Meg Hargrove, Cybersecurity Incident Response Manager (@cybersecmeg on Twitter)

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    Archer: https://itspm.ag/rsaarchweb

    Edgescan: https://itspm.ag/itspegweb

    ____________________________

    Resources
    Inspiration for this conversation:

    https://twitter.com/cybersecmeg/status/1384603498323582976

    https://twitter.com/cybersecmeg/status/1379523065999155201

    https://twitter.com/cybersecmeg/status/1376981399719321604

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    38 min
  • The Relationship Between Roles — PR/Media Relations And Information Security | Redefining CyberSecurity With Melanie Ensign And Ed Amoroso

    A lot can be done by CSOs/CISOs to maximize value and reduce risks when working with PR/media. However, the path forward is not always straightforward. What are the common hiccups, screw-ups, and give-ups?

    As part of our ongoing "CISO functional relationships" series, in today's episode, we look at the role of PR and the media as a function of establishing and maintaining trust internally with the executives, the board, the partners, and externally with the customers and the public.

    There's an old saying, "There is no such thing as bad press. All press is good press," but that is precisely an "old" saying. Nowadays, branding and reputation matter, which is even more true in information security. 

    The impact of a breach on the company's reputation and bottom line can cause some severe damage, but the story is more complex than that. Nowadays, there is an entire system that needs to change to manage reputation in the right way. 

    The conversation with the media and the public can be more positive, constructive, and transparent.

    In this podcast, we talk about this and much more.

    Guests
    Melanie Ensign, Founder & CEO, Discernible (@iMeluny on Twitter)

    Ed Amoroso, Founder and CEO of TAG Cyber (@hashtag_cyber on Twitter)

    This Episode’s Sponsors

    HITRUST: https://itspm.ag/itsphitweb

    Semperis: https://itspm.ag/semperis-1roo

    ____________________________

    Resources
    Medium Post by Melanie: https://medium.com/discernible/security-privacy-incident-hiccups-f-ck-ups-and-give-ups-e972ef46c3d

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    39 min
  • The Connection Between Product Quality Assurance And Application Security In Business | Redefining CyberSecurity With Tom Morrissey And Cassio Goldschmidt

    Nowadays, every company is pretty much a technology company, and as such, they all should have some understanding of quality assurance (QA). Also, an understanding of information security would be nice. The question is, how and where do these two worlds collide?

    And, is that security world AppSec or DevSecOps? Or is it something completely different?

    The QA role often approaches testing an application through user stories and use cases, working toward verifying that it does everything it is supposed to do. On the other hand, an application security team often comes to the situation from a different perspective; they try to get the system to do something it is not supposed to do, going beyond the user interface and breaking free from documented user scenarios.

    While these two perspectives may differ significantly, there is still a ton of shared vision for reaching the end goal: rooting out as many bugs as they can to deliver the best possible product. They also share some common challenges as they try to connect and work with the line-of-business owners, architects, IT, operations, and engineering teams. 

    With this in mind, what, specifically, are the synergies, and how can these two teams help each other succeed? Should they be working together, or does it make sense for them to remain separate?

    Tune in to this episode with guests: Tom Morrissey (a long-time QA and engineering director) and Cassio Goldschmidt (a very active application security expert and OWASP leader) reach back to the past to help us understand how QA has evolved and what lessons the application security professionals can learn from their history.

    Guests
    Tom Morrissey, Director of Software Engineering

    Cassio Goldschmidt, Sr. Director & CISO at ServiceTitan | OWASP Chapter Leader (@CassioGold on Twitter)

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    Archer: https://itspm.ag/rsaarchweb

    Edgescan: https://itspm.ag/itspegweb

    ____________________________

    Resources
    Learn more about OWASP: https://owasp.org/ (@owasp on Twitter)

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    47 min
  • The Relationship Between Roles: Human Resources And Information Security | HR Is The Organization's Communications Super Glue | Redefining CyberSecurity Culture With Dora Ross, Global Security Culture Specialist

    The human resources department within any organization is well-positioned to feel the pulse and monitor a company's culture—teams, divisions, and the organization as a whole. Because of this, it could be the ideal ally to the InfoSec team. But is it? Let's find out.

    Consider the lifecycle of an employee. The initial company awareness, gaining familiarity with its brand, exploring its job opportunities, moving on to the next role, all the way to retirement—or perhaps even getting fired. Of course, there's everything in-between as well, including annual performance reviews, salary and compensation discussions, workplace behavior and related training, ongoing education, promotions, and more.

    At each stop along their journey and throughout each of the phases within the candidate/employee journey, HR has an opportunity to help shape the company's culture by reinforcing fundamental principles, operational ethics, and the related policies and actions. Just as we should be baking information security into the products—as early, and as often as possible—we should follow this same model for building our workforce and the company culture in which they exist.

    There's an opportunity for InfoSec and HR to collaborate to present and discuss the value of good information security hygiene: using a password manager, connecting through a VPN, paying attention to potential leaks or loss of data, and thinking critically during a security awareness training event—these are just a few examples.

    The importance of security shouldn't begin once the person becomes an employee; the organization can demonstrate their investment in InfoSec well before the jobs are posted and the interviews start.

    On the other side of the equation, there's an opportunity to maintain security and safety for the organization by encouraging a now-former employee to continue to carry with them the lessons they've learned as they move on to another company or retire into the sunset.

    Easy to say, but is it that simple? How are HR departments holding on with all the new responsibilities piling up on their desk lately? Can they take one more role without a fundamental redefinition of their role within a company?

    There's so much to be gained here. This is definitely a conversation worth listening to, especially if you are in HR, InfoSec, or are an employee (I think that captures everyone, doesn't it?).

    Enjoy!

    NOTE: This episode is part of our "Building Better Security Relationships" series. Catch the last episode  with Legal Counsel here: http://itsprad.io/redefining-security-411

    Guests
    Dora Ross, Global Security Culture Specialist

    This Episode’s Sponsors

    Imperva: https://itspm.ag/imperva277117988

    HITRUST: https://itspm.ag/itsphitweb

    Key Resources: https://itspm.ag/keyresources-2876

    ____________________________

    To see and hear more podcasts and webcasts about Redefining CyberSecurity for your business, tune in to ITSPmagazine at:
    https://www.itspmagazine.com/redefining-cybersecurity

    Are you interested in advertising on ITSPmagazine?
    👉 https://www.itspmagazine.com/sponsorship-introduction

    Are you interested in sponsoring an ITSPmagazine podcast?
    👉 https://www.itspmagazine.com/podcast-series-sponsorships


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    34 min

About Redefining CyberSecurity

From the publisher's feed

Redefining CyberSecurity Podcast

More shows like Redefining CyberSecurity

This American Life by This American Life

This American Life

90,949 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

The ITSPmagazine Podcast by ITSPmagazine, Sean Martin, Marco Ciappelli

The ITSPmagazine Podcast

30 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hard Fork by The New York Times

Hard Fork

5,554 Listeners

Audio Signals Podcast by ITSPmagazine, Marco Ciappelli, Sean Martin

Audio Signals Podcast

2 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

Microsoft Threat Intelligence Podcast by Microsoft

Microsoft Threat Intelligence Podcast

23 Listeners

Stories From Space by ITSPmagazine, Matthew S Williams

Stories From Space

4 Listeners

An Analog Brain In A Digital Age | With Marco Ciappelli by Marco Ciappelli

An Analog Brain In A Digital Age | With Marco Ciappelli

0 Listeners

CyberSecurity Summary by CyberSecurity Summary

CyberSecurity Summary

5 Listeners