
Sign up to save your podcasts
Or


In episode 60 of The Cyber5, we are joined by Tom Thorley, the Director of Technology at the Global Internet Forum to Counter Terrorism (GIF-CT).
We discuss the mission of GIF-CT and how it's evolved over the last five years, with particular interest on violent terrorist messaging across different social media platforms. We also discuss the technical approaches to countering terrorism between platforms and how their organization accounts for human rights while conducting their mission.
Four Key Takeaways:
1) The Evolving Mission of GIF-CT
GIF-CT combats terrorist messaging on digital platforms and is particularly focused on removing live streaming of violence. They were founded in 2017 by Microsoft, Facebook, YouTube, and Twitter to mostly combat advanced ISIS messaging efforts across their platforms, particularly after several high profile terrorist attacks were live streamed.
GIF-CT has grown to include 17 different technology companies that participate in the mission of combating terrorist exploitation of their platforms. Since ISIS has been degraded over the last three years, GIF-CT has expanded their mission to include supporting the United Nations Security Council’s Consolidated Sanctions List.
2) Behavioral Models as Opposed to Group Affiliation
Due to the fast adaptation and evolution of terrorism, GIF-CT has moved to track behavioral models of violence rather than attempt to focus on known terrorist groups. They built out an incident response framework to review emergency crisis situations using technology called “hash sharing.” Now, they are looking at expanding into:
3) Hash Sharing Across Social Media Platforms with Content
User created content is not associated with an identifiable individual, like an IP address generally tied to a device. When GIF-CT hashes videos, they not only use traditional MD5 hashes, but also use perceptual hashes, which are locality sensitive. These hashing techniques and different algorithms provided by the technology companies, allow images, videos, and URLs to be flagged and potentially removed from the platform in close to real time.
There is some new hash sharing technology that is being explored around PDFs. The need has been driven in part because malware is exploited because the backend code of the PDF is manipulated whereas terrorist manifestos are not, they are just content. Technology is being explored by GIF-CT where they can hash certain content strings in PDFs for alert.
4) Optimizing for Human Rights
GIF-CT hashing algorithms minimizes impact to human rights during emergency situations and differentiates between legitimate journalism and normal discord between people on the platform. GIF-CT goes through tremendous transparency initiatives that focus their algorithms on violence extremism.
In episode 59 of The Cyber5, we are joined by active security compliance practitioner, Dylan McKnight.
We discuss the business of security. We unpacked how security can be effective at driving profitability and not just be a cost center toward an organization. We discuss how compliance measures can drive meaningful metrics around profitability and avoiding breaches. And finally, we talk about where threat intelligence provides the proper risk-based approach for security teams in this process.
Five Key Takeaways:
1) Making “Security” Be Seen as More than Just a “Cost Center”
Prioritize external-facing business leaders and help them to become security stakeholders. Give Sales, Customer Success, and Marketing a reason to care about security. In the technology space it’s important to understand how your organization makes money. You must embed security practices into the contracts to ensure your organization is being a good steward of each department’s data. Third party risk management processes are an example of how this shows up in the everyday.
In the pre-close world, work with the sales team to ensure security functions are assisting to close deals faster. As a communicator, you must also improve customer relationships through privacy programs and a good incident notification policy after the sale.
You must still maintain key relationships with necessary internal stakeholders such as:
2) Security Roadmap is Critical with Limited Resources
It’s critical for security practitioners to understand that the vortex of power within technology teams is centered around sales and product engineering teams. Security practitioners lament that they don’t get enough time in front of internal decision makers, that’s why they need to embed themselves in the sales cycle. Critical security functions like identity and access management (IAM) and file integrity monitoring are two examples of having value, but are time intensive and don’t necessarily improve the bottom line unless they are part of customer contracts.
However, privacy requirements are becoming critical to engineering and sales teams and a security program should be adapted to meet those needs first.
3) Developing the GTM-focused Security Playbooks that Scale with the Business Growth
Risk assessments for what could cause the most business loss are important to start, backed by standards and controls that align to this potential loss.
“Move fast and break things” could have monetary losses in security, so it’s important to go to quarterly business reviews with the sales team and understand the pain points in the sales process. Security should exist to make sales move through the process quicker and then by illuminating potential risk.
4) Compliance is Important for Maintaining Customers
It’s cheaper to keep existing customers than gain new customers. To keep existing customers, trust becomes a critical aspect. Transparency around security controls and incident notification with your customers can go a long way to keeping them satisfied during renewals.
Compliance standards that meet these transparency requirements are beneficial for building trust with customers including the right levels of monitoring of cloud infrastructure and managed detection and response. It’s important to understand how all the different teams use data in the environment and protect what really matters, which in technology companies is usually the “least privilege” permissions around the production environment.
5) The Role of Threat Intelligence in Risk Assessments
Risk-based approaches are always a good starting point. Threat intelligence should be geared to focusing on who, how, and why threat actors are actually attacking your organization. Simple defenses should be built around threats that are happening, not just what is possible. Not only monitoring the dark and open web, but closely analyzing your firewall logs and providing an “outside-in” inspection to closely enrich data your internal telemetry with external signals for more risk-based context and prioritization.
In episode 58 of The Cyber5, we are joined by Magen Gicinto, Director People Strategy and Culture for Nisos.
We discuss the “Great Resignation’” that's happening in the work environment during the COVID pandemic and how to realign your “people strategy” to recruit and retain the best talent in spite of those challenges. We address the aspects of recruiting and retaining the best talent and how to calibrate total rewards in consideration of employees’ ever-changing motivations. Finally, we cover the nature of startup culture in the technology sector and the convergence of generalists and specialists in high performance organizations.
Four Key Takeaways:
1) Recruiting and Retaining Talent During the COVID-19 Pandemic
Employees who would have otherwise left their jobs decided to stay put during the pandemic. Now, even though we are still in the throes, people feel safe again to move jobs, which is leading to an unprecedented turnover in the global workforce. In fact, according to statistics published by the U.S. Department of Labor, voluntary turnover dipped significantly in 2020, but in early 2021, it jumped higher than ever before, with 4 million people leaving jobs in April 2021 alone in the U.S.
Employees that are looking for new opportunities and want to integrate work/life responsibilities are looking for employers who support those values. What remains is employees continue to want opportunities for career advancement and building their skill sets.
One core solution for employers is to reimagine the employee experience so you can keep your best people and recruit great talent. Understanding what your employees value and what motivates them is key to reducing churn and attracting new people. High performing People Strategy departments are adept at creating employee engagement, from onboarding through the employee lifecycle, that help to continue to satisfy employee motivations throughout their tenure with an organization.
2) Experiential Support to Employees Is Critical
Organizations that invest heavily in creating the best employee experience will have better success at recruitment and retention. Organizations and teams are most successful when the organization’s strategies, structure, and culture are aligned.
During the infancy stage of startups, there is little consistency for people to hang on to. Leaders are focused on doing what they can to source and hire the best talent, while outsourcing other services. Once you move past the infancy stage and start growing, your attention needs to move to ensuring stability and creating a life cycle for employees.
Employees who are embedded into the organization from day one who have experience with a strong onboarding regimen will have more staying power and satisfaction with the organization. While white-glove on-boarding is not always achievable at a startup level (based on lean staffing), companies that can find the resources to do so win it back with stronger employee integration in the entity from day one.
3) Challenge Playbooks to Create the Best Employee Experience
Here are some ways to create an environment where employees can succeed and grow within an organization. This is especially crucial within cybersecurity where the table stakes can be higher, and the goal posts can move quicker.
4) Prevent Silos and Bring People Together When New Departments are Created
When recruiting, look for talent who create value and can deliver on company objectives. Employees want to have purpose in their work and know that they’re making a difference. As a startup organization, you have a great opportunity to create and influence organizational decisions and add value. Hire individuals who are up for the challenge and want to lean into the company’s goals with the team.
To avoid departmental silos, it’s important to:
By bringing different departments into the recruitment and retention process, it helps avoid silo-type organizations. It creates more alignment, and helps employees understand what’s going on in the business. Once a new hire comes on, all of the departments are similarly invested in the individual, and can incorporate them, which will allow them and you to begin to utilize their skillsets effectively.
In episode 57 of The Cyber5, we are joined by Colby Clark, Director for Cyber Threat Management. He’s also the author of the recently published book, The Cyber Security Incident Management Master’s Guide.
We baseline incident response playbooks around customer environment, threat, landscape, regulatory environment, and security controls. Afterward, we discuss how incident response (IR) playbooks have evolved in the last five years and they have scaled in the cloud. We discuss telemetry that is critical to ensure an IR team can say with confidence that an incident is accurate, complete and truthful in order to avoid breaches. Lastly, we discuss the criticality of threat intelligence in the IR process and what boards really care about during an incident.
Four Topics Covered in this Episode:
Playbooks used to be contact lists, and an outline of roles and responsibilities of who to call during a cybersecurity incident. It was typically based on recovery from natural disasters. Today, threat -based playbooks are more specific and actionable tailored to the enterprise environments that were based on compliance and insurance requirements.
In Clark’s book, in his execution with clients, 13 distinct domains are relevant for baselining these playbooks; including customer environment, threat landscape, regulatory environment, and security controls. Most importantly, incident management is a repeatable process over a period time that adapts to regulators. Enterprise solution tooling is always behind the tooling of the attackers, and therefore, gap analysis within IR playbooks is a constant job for any IR team.
In episode 56 of The Cyber5, we are joined by Ray O’Hara, Executive Vice President for Allied Universal.
We discuss the use of intelligence for corporate security programs, usually overseen by a Chief Security Officer (CSO). We talk about some of the challenges this role faces and how intelligence can be actionable to mitigate those risks. We also work through various case studies, talk about metrics for success, and what technology platforms are used to aggregate intelligence that might be useful in the future.
Four Topics Covered in this Episode:
In episode 55 of The Cyber5, we are joined by Nate Singleton, a security practitioner who was most recently the Director of IT, Governance, and Incident Response at Helmerich and Payne.
We discussed the conundrums of operational technology security within gas and energy sectors, including risks downstream and upstream. We also compared the aggressive and constant need for interconnectivity on the information operation technology sides of the house to show that events like the Colonial Pipeline ransomware attack are probably just the beginning of future attacks against critical infrastructure.
We also discussed what more major oil and gas companies can do to help improve cybersecurity for small companies critical in the oil and gas supply chain.
Five Topics Covered in this Episode:
In episode 54 of The Cyber5, we are joined by Aaron Barr, Piiq Media’s Chief Technology Officer.
We discuss how data breaches are combined with other open source information to paint a more holistic target profile for bad actors. We also discussed the true information anchors and weaponization that can lead to an online attack against someone. Finally, we discussed what executives and individuals can do to protect themselves and how protective intelligence is playing a greater role in physical security.
Four Topics Covered in this Episode:
Education to executives and the workforce about simple technology such as the ability to flag suspicious emails that get escalated to the security team still goes a long way in securing the workforce.
In episode 53 of The Cyber5, we are joined by Ciaran Martin, the former United Kingdom National Cybersecurity Center CEO and former Director General for Cybersecurity of GCHQ. He’s currently a professor at the University of Oxford and a strategic advisor for Paladin Capital.
We discuss the political, legal, and ethical challenges of today's ransomware threats and the corresponding nation state challenges of Russia, China, and Iran. We also discuss what the U.S. and global economies can do to reduce these threats and how the financial industry can assist in a greater capacity.
Four Topics Covered in this Episode:
With semi-conductor shortages caused by the pandemic and corresponding geopolitical rifts between the U.S., Russia, and China, ransomware is at the center of national security threats While ransomware actors are just organized criminals, three characteristics have made this a broader national security threat:
The U.S. and Western model of technology has created flaws that lead to ransomware. The “move fast and break things” mantra of Silicon Valley prioritizes connectivity over security. The Chinese model is one of consistent integration, overwatch, authority, and frugality. Russia seeks regional control and the overall weakening of democracies through disinformation and offensive computer network exploitation operations.
Key Differences:
Ransomware actors are not yet causing widespread harm to individuals. If this starts to occur, we could see increased offensive campaigns against ransomware actors similar to what we’ve seen against other non-state actors.
Non-state actors of the last 15 years were usually under a failed state whereas ransomware actors enjoy state protection in many cases.
Key Commonalities:
The world economies will eventually join to stop the movement of money that is used by ransomware actors, repeating what happened to the non-state actors of the last 15 years.
Cybersecurity risk is well understood by the major financial sectors as it pertains to their own security. Cybersecurity, fraud, insider theft, and general resilience are well understood and defended by the major banks. Aspects of cryptocurrency and money laundering aspects of cyber security are still major opportunities for the FIs.
In episode 52 of The Cyber5, we are joined by Nisos Managing and Technical Principals Robert Volkert and Travis Peska who lead operations within the Pandion Intelligence team.
We talk about the evolution of Nisos over the past six years, including how we now position ourselves within the private sector threat intelligence market under our new Chief Executive Officer, David Etue.
Our managed intelligence mission combines open-source intelligence analysis, technical cyber security investigative tradecraft, and data engineering to solve enterprise threats around cyber security, trust and safety platforms, reputation, fraud, third party risk, and executive protection. We reminisce about our favorite investigations and talk about what’s next for Nisos.
Three Topics Covered in this Episode:
In the last six years, Nisos evolved its mission to focus on being the Managed Intelligence Company™. Using skill sets combining offensive operators, forensic and network analysts, open source intelligence experts, and data engineers, we collect and analyze data to solve problems within six primary intelligence domains:
Since our “outside of the firewall” investigations and tradecraft over the years, we realized customizing smaller datasets around customer problems is more helpful to customers and helps differentiate our offering with actionable intelligence with appropriate context.
Aggregating data to a product that doesn’t provide the answers is often a waste of resources for many organizations who need to make information actionable to security operations teams and executives. As part of these services, routine monitoring services followed by an aggressive RFI service is generally viewed as the most effective way to quickly answer customer intelligence requirements within a 24-48 hour period.
While the most prolific investigations have involved the unmasking of threat actors when the appropriate context is needed, the most well known investigations generally involve attributing attacker infrastructure and unraveling different malicious tool sets against platform technology companies and business applications.
In episode 51 of The Cyber5, we are joined by Chris Castaldo. Chris is the Chief Information Security Officer for CrossBeam and has been CISO for a number of emerging technology companies.
In this episode, we talk about his newly released book, “Startup Secure” and how different growth companies can implement security at different funding stages. He also talks about the reasons security professionals should want to be a start-up CISO at a growing technology company and how success can be defined as a first time CISO. We also talk about how start up companies can avoid ransomware events in a landscape that is not only constantly changing but also gives little advantage for defenders of small and medium sized enterprises.
Two Topics Covered in this Episode:
When a B2B company is pre-seed or before Series A funding, customers might have leeway for lax cybersecurity controls. However, after an A round, policies, certifications (SOC2 or ISO27001), procedures will be required to ensure customer data is staying safe. A B2C technology company might not be asked by the public for certifications, but auditors and regulators may. Basic policies include:
Blocking and tackling from inside-out to get in front of ransomware is challenging. The simple items to tackle are the following:
At the point when resilience and compliance controls are in place and an organization can bounce back from an incident in a timely manner, adversary insights via threat intelligence is a logical next step.
From the publisher's feed