
Sign up to save your podcasts
Or


In episode 40 of the Cyber5, we are joined by Professor of Cyber Psychology and former Producer of CSI Cyber, Mary Aiken. Mary discusses the psychology of online behavior, particularly with regard to social media and how it plays a critical role leading to extremist ideology.
Here are the 5 Topics We Cover in this Episode:
In episode 39 of the Cyber5, we are joined by Director of Adversary Management & Threat Intelligence at Intuit Shannon Lietz. Shannon discusses external threat hunting and an enterprise practitioner’s perspective of active defense.
Here are the 5 Topics We Cover in This Episode:
1. Defining Active Defense and External Threat Hunting: (01:34-02:51)
We start with a proper definition of active defense and external threat hunting. While both terms are often misunderstood, an appropriate definition is the deep understanding of adversaries and the company’s capabilities to defend from the outside the firewall looking in.
2. Industry Trends versus Organizational Realities: (02:51-04:30)
When discussing intelligence gained from external threat hunting, industry should recognize the difference between what’s happening across industry and what is happening within the organization. Advice: Enterprise should focus on discerning threat intelligence and making it relevant to the organization through the lense of DEVSECOPS - resilience of prioritizing who is going to attack a certain business function/application - and matching with attack emulation.
3. Determining Urgency and Response Speed: (04:30-07:55)
To apply this to use cases, it’s critical to understand an ideal state of security within different functions such as, but not limited to, email security and fraud. The ability to decrease attacker dwell time and respond through meticulous log aggregation and analysis is important and needs to be understood at scale. For example, if one out of 250 emails is malicious but the amount of malicious web traffic hitting critical business applications is exponentially higher, a greater rate of speed and automation is critical.
4. Prioritizing What Requires Attention: (07:55-10:40)
Large enterprises have thousands of applications and no one is going to have situational awareness on all of them. Therefore, security teams need to prioritize threat models defining a target state metric beyond compliance and identify legitimate attacker traffic.
5. Measuring the Ability the Secure Your Business: (10:40-15:49)
Finally, “securability” is a critical metric looking at an organization’s attack surface and is defined in three parts:
In episode 38 of the Cyber5, we are joined by Director at Nisos Seth Arthur. Seth discusses digital identity reduction, a methodology for removing online personally identifiable information (PII).
Outline
We start by discussing what "doxxing" means and how serious enterprise takes such threats, particularly when executives are identified by malicious actors. Analyzing the threat, reviewing the digital footprint, and attributing the actor(s) are common work flows for digital executive protection. (01:00-04:12)
We then get into a discussion of how PII proliferates online and what can be done to reduce online footprints every six to twelve months. (04:13-08:24)
Finally, when a threat becomes probable to someone's physical security and they want to take action against a threat such as filing a restraining order, we discuss steps Nisos takes in online attribution (08:24-11:13)
In episode 37 of the Cyber5, we are joined by Nisos Managing Principal Jared Hudson.
Jared discusses the managed intelligence differentiator known as “The Nisos Dogpile,” a collaborative, investigative methodology that combines a wide range of skillsets, data, and technology. This unique approach enables Nisos operators, in partnership with enterprise clients, to rapidly solve security problems (01:38-05:00). We also talk about the technical data, data engineering, and data science, that we fuse with world-class analysis to solve investigations and address third-party risk (05:00-07:40). We provide details on real-world investigations of fraud, disinformation/brand reputation, cyber threat intelligence, trust and safety, third party risk management, and acquisition diligence (07:40-22:00). And finally, we peel back the onion to reveal the attributes we look for in a well-rounded Nisos operator (23:00-25:00).
Episode 36 of the podcast covers the attributes of a robust third-party risk management program including how to use threat intelligence to inform actionable outcomes with third parties.
Episode 35 of the podcast covers the creation, maintenance, and ethics of sock puppet accounts (online personas) and how enterprise can use them to solve numerous business problems.
Episode 34 of the podcast covers how enterprise can defend against Chinese state-sponsored espionage efforts to steal intellectual property.
Episode 33 of the podcast covers defending a cloud-based enterprise with a remote workforce.
Episode 32 of the podcast covers how intelligence can be used to assess exposure and pricing risk for cyber insurance coverage.
Q1 (01:13) What are the challenges for exposure and pricing risk as they pertain to cyber insurance coverage?
Q2 (06:45) What questions are best to help understand exposure risk and pricing risk?
Q3 (10:45) How can security stack maturity help underwriters understand and price the risk?
Q4 (15:30) How can the disciplines around the intelligence cycle (plan, collect, process, analyze, disseminate) be helpful to underwriters?
Q5 (18:22) How do you communicate these same disciplines to a non-technical board of directors?
Episode 31 of the podcast covers legal options for disinformation and deepfakes.
Q1 (01:06): On Twitter, Lebron James mentioned that he is trying to figure out what his legal options are. What do you tell him?
Q2 (06:27): We’ve heard many cases of deepfakes in the business setting. What are practical measures companies and individuals can take to avoid being victims?
Q3 (07:40): What are the motivations of the attackers?
Q4: (14:06) Is legislation on track to help?
Q5: (20:35) What are other possible solutions to these problems—from technology to detect deepfakes, to how the news media should respond, to what platforms can do?
From the publisher's feed