the CYBER5

the CYBER5

By Nisos, Inc.BusinessTechnology
Download on the App Store

the CYBER5 episodes

  • Forensic Cyberpsychology: How Anonymity Normalizes the Abnormal

    In episode 40 of the Cyber5, we are joined by Professor of Cyber Psychology and former Producer of CSI Cyber, Mary Aiken. Mary discusses the psychology of online behavior, particularly with regard to social media and how it plays a critical role leading to extremist ideology.

    Here are the 5 Topics We Cover in this Episode:

    1. Defining Cyber Psychology as it Relates to Cyber Space: (01:00-05:52) Cyber psychology is the study of the impact of technology on human behavior. We maintain that human behavior can fundamentally change or mutate in cyber context. Key constructs include ODE, or the Online Disinhibition Effect, which dictates that people will perform actions in a cyber context they would not normally do in the real world. In addition, anonymity is a powerful psychological driver online and while some argue that online anonymity is a fundamental right, they are not accurate; it’s an invention of the internet and behavior is evolving at the speed of technology.
    2. Defining Cyberspace for Corporate Enterprise: (05:24-09:52) In 2016, NATO ratified cyberspace as an environment, acknowledging battles of the future will take place on land, sea, air, and computer networks. In addition to thinking about how the military fights these future battles, it’s also important for enterprises to understand how their businesses and employees operate online and address various threat actors.
    3. Psychology Evolving as Extremism Transitions Online: (09:52-12:00) People are prone to write more adversarial thoughts online because they are not receiving the same micro-expressions, body language, proximity, and feedback they would receive in person. Mary feels addiction does not exist with technology because we rely on it just like we rely on air or water; however, we have to play catch up as a society for how to recognize and curb aggressive online behavior.
    4. Online Safety Technology: (12:00-16:00) While a lot of threat intelligence is geared toward the confidentiality, integrity, and availability (C.I.A.) of data, systems, and networks, it does not focus on what it means to be human. Many in the business community, including Paladin Capital, are starting to invest in safety technologies and services that combat the relationship between the C.I.A. of data systems and the behavioral aspects of cyber security, such as insider threat, harassment, cyber bullying, and disinformation to deliver holistic security capabilities.
    5. Extremist Behavior Online Filtering into Violence in the Real World: (16:00-21:00) When people are constantly circulating in echo chambers online, fueled by false information and hate speech, combined with ODE, this has huge potential for violence in the real world, as displayed during the Capitol Hill riots in 2021. It’s going to be critical for enterprises to monitor cyberspace from a brand reputation perspective, and not just for negative sentiment against products and services. It will also be critical to understanding the sentiment behind how employees behave in a manner that is not detrimental to the brand’s image. 
    23 min
  • External Threat Hunting & Active Defense

    In episode 39 of the Cyber5, we are joined by Director of Adversary Management & Threat Intelligence at Intuit Shannon Lietz. Shannon discusses external threat hunting and an enterprise practitioner’s perspective of active defense.

    Here are the 5 Topics We Cover in This Episode:

    1. Defining Active Defense and External Threat Hunting: (01:34-02:51)

    We start with a proper definition of active defense and external threat hunting. While both terms are often misunderstood, an appropriate definition is the deep understanding of adversaries and the company’s capabilities to defend from the outside the firewall looking in.

    2. Industry Trends versus Organizational Realities: (02:51-04:30)

    When discussing intelligence gained from external threat hunting, industry should recognize the difference between what’s happening across industry and what is happening within the organization. Advice: Enterprise should focus on discerning threat intelligence and making it relevant to the organization through the lense of DEVSECOPS - resilience of prioritizing who is going to attack a certain business function/application - and matching with attack emulation.

    3. Determining Urgency and Response Speed: (04:30-07:55)

    To apply this to use cases, it’s critical to understand an ideal state of security within different functions such as, but not limited to, email security and fraud. The ability to decrease attacker dwell time and respond through meticulous log aggregation and analysis is important and needs to be understood at scale. For example, if one out of 250 emails is malicious but the amount of malicious web traffic hitting critical business applications is exponentially higher, a greater rate of speed and automation is critical.

    4. Prioritizing What Requires Attention: (07:55-10:40)

    Large enterprises have thousands of applications and no one is going to have situational awareness on all of them. Therefore, security teams need to prioritize threat models defining a target state metric beyond compliance and identify legitimate attacker traffic.

    5. Measuring the Ability the Secure Your Business: (10:40-15:49)

    Finally, “securability” is a critical metric looking at an organization’s attack surface and is defined in three parts: 

    • Attack resilience are risks an organization takes that allow adversary opportunity. 
    • Controls escapes are the controls in place to address the opportunity
    • Adversary dwell time is the resources and time it takes attackers to convert the opportunity.
    17 min
  • Digital Identity Reduction for Executive Protection

    In episode 38 of the Cyber5, we are joined by Director at Nisos Seth Arthur. Seth discusses digital identity reduction, a methodology for removing online personally identifiable information (PII).

    Outline

    We start by discussing what "doxxing" means and how serious enterprise takes such threats, particularly when executives are identified by malicious actors. Analyzing the threat, reviewing the digital footprint, and attributing the actor(s) are common work flows for digital executive protection. (01:00-04:12)

    We then get into a discussion of how PII proliferates online and what can be done to reduce online footprints every six to twelve months. (04:13-08:24)

    Finally, when a threat becomes probable to someone's physical security and they want to take action against a threat such as filing a restraining order, we discuss steps Nisos takes in online attribution (08:24-11:13)

    13 min
  • Exploring the Intelligence Differentiator: The Nisos Dogpile

    In episode 37 of the Cyber5, we are joined by Nisos Managing Principal Jared Hudson.

    Jared discusses the managed intelligence differentiator known as “The Nisos Dogpile,” a collaborative, investigative methodology that combines a wide range of skillsets, data, and technology. This unique approach enables Nisos operators, in partnership with enterprise clients, to rapidly solve security problems (01:38-05:00). We also talk about the technical data, data engineering, and data science, that we fuse with world-class analysis to solve investigations and address third-party risk (05:00-07:40). We provide details on real-world investigations of fraud, disinformation/brand reputation, cyber threat intelligence, trust and safety, third party risk management, and acquisition diligence (07:40-22:00). And finally, we peel back the onion to reveal the attributes we look for in a well-rounded Nisos operator (23:00-25:00).

    26 min
  • Attributes of a Robust Third Party Risk Management Program

    Episode 36 of the podcast covers the attributes of a robust third-party risk management program including how to use threat intelligence to inform actionable outcomes with third parties.

    • Q1 (01:25) Within your threats and safeguards matrix, you identify vendor and partner data as a major threat. How do you rank order each vendor and what are risk factors of vendors you assess?
    • Q2 (05:33) How does cyber threat intelligence play a factor?
    • Q3 (06:44) What are the critical, actionable outcomes you are looking for with threat intelligence as it pertains to TPRM?
    • Q4 (11:15) Are you using threat intelligence to inform other threats to the business such as compliance, financial, HR, or legal?
    • Q5 (14:00) What’s the best advice you would give to people coming out of the IC and want to be CISOs?
    19 min
  • Creation, Maintenance, and Ethics of Sock Puppet Accounts (Online Personas)

    Episode 35 of the podcast covers the creation, maintenance, and ethics of sock puppet accounts (online personas) and how enterprise can use them to solve numerous business problems. 

    • Question 1: (01:35) What are best practices for growing your connections, follows, or friends on sock puppets accounts?
    • Question 2: (04:10) With the widespread tracking and analytics conducted by social media companies, how do you prevent cross contamination on your sock puppets from your legitimate social media?
    • Question 3: (06:00) What are some appropriate operational security measures that are important in creating sock puppets to ensure they are backstopped?
    • Question 4: (10:02) What are some ethical and legal considerations to consider when creating sock puppets? Can/should you ever use a real persons photos? How do you source pictures for a sock puppet to stay consistent?
    • Question 5: (12:58) What are some good investigative use cases for using sock puppets? What is a reasonable time frame to have a sock puppet before one would consider it "aged"?
    22 min
  • Defending Against Chinese State-Sponsored Espionage Efforts

    Episode 34 of the podcast covers how enterprise can defend against Chinese state-sponsored espionage efforts to steal intellectual property. 

    • Q1 (01:00) What are the computer network exploitation and insider threat TTPs you've seen throughout your career to steal intellectual property on the part of the Chinese government? 

     

    • Q2 (04:09) What are some investigative examples of each?

     

    • Q3 (09:35) What can companies do to protect themselves? What are the critical monitoring mechanisms that are critical to detecting a breach?

     

    • Q4 (13:51) What are the critical monitoring mechanisms to put in place on insider threat?

     

    • Q5 (16:15) If you were advising a CISO with limited budget, and this was your biggest threat, what would you prioritize?
    20 min
  • Defending a Cloud-Based Enterprise with a Remote Workforce

    Episode 33 of the podcast covers defending a cloud-based enterprise with a remote workforce. 

    • Q1 (01:44) What are the threats that worry you the most? Are you more worried about developer misconfigurations and inadvertent leaks more than an endpoint being compromised?

     

    • Q2 (04:29) What are the controls you put in place that are the most cost-effective? So much is talked about defending a remote workforce; what strategies have you put in place?

     

    • Q3 (13:10) Is logging at scale or even network segmentation even rational for small to mid-sized companies especially ones that are in the cloud? If so, what does that look like in implementation ?

     

    • Q4 (15:25) What are some custom ways you use threat intelligence to alert for developer mishaps in open-source repositories?

     

    • Q5 (17:20) In large enterprise you have TH, SOC, AppSec, Red Team, CTI, VM, TPRM, IAM, etc. Can a lot of this be condensed for a company that is cloud-based and operate more efficiently at scale?
    26 min
  • Consuming Intelligence to Assess Exposure and Pricing for Cyber Insurance Coverage

    Episode 32 of the podcast covers how intelligence can be used to assess exposure and pricing risk for cyber insurance coverage. 

    • Q1 (01:13) What are the challenges for exposure and pricing risk as they pertain to cyber insurance coverage? 

    • Q2 (06:45)  What questions are best to help understand exposure risk and pricing risk?

    • Q3 (10:45) How can security stack maturity help underwriters understand and price the risk? 

    • Q4 (15:30) How can the disciplines around the intelligence cycle (plan, collect, process, analyze, disseminate) be helpful to underwriters?

    • Q5 (18:22) How do you communicate these same disciplines to a non-technical board of directors?

    22 min
  • Legal Options for Disinformation and Deepfakes

    Episode 31 of the podcast covers legal options for disinformation and deepfakes. 

    • Q1 (01:06): On Twitter, Lebron James mentioned that he is trying to figure out what his legal options are. What do you tell him?

    • Q2 (06:27): We’ve heard many cases of deepfakes in the business setting. What are practical measures companies and individuals can take to avoid being victims?

    • Q3 (07:40): What are the motivations of the attackers?

    • Q4: (14:06) Is legislation on track to help?

    • Q5: (20:35) What are other possible solutions to these problems—from technology to detect deepfakes, to how the news media should respond, to what platforms can do?

    28 min

About the CYBER5

From the publisher's feed

The CYBER5 is hosted by Landon Winkelvoss, Co-Founder at Nisos, and features cybersecurity and investigations industry leaders' thoughts and answers to five questions on one topic on actionable…