the CYBER5

the CYBER5

By Nisos, Inc.BusinessTechnology
Download on the App Store

the CYBER5 episodes

  • Third Party Risk Management in the View of Medium Size Businesses

    Episode 19 of the podcast covers third party risk management considerations for medium size businesses, including how to respond to larger enterprises who contact with alleged vulnerability exposure.

    • (01:40) Question 1: There are tens of thousands of companies that have robust but resource constrained security operations centers (between 10-20 personnel). What are some instances when you get called by SOC’s of larger clients with vulnerabilities that are exposed?
    • (03:40) Question 2: Are those vulnerabilities accurate? If not, why not? What are they missing?
    • (07:48) Question 3: Understanding resources are limited with small and medium businesses, how should small to medium businesses be best prepared for getting the call from larger enterprises that they have an immediate vulnerability needing to be remediated? What can medium size businesses do to create threat intelligence programs to help alert to these vulnerabilities?
    • (12:06) Question 4: What should larger SOCs be doing, not only in the vendor management onboarding risk process, but in practice when potential vulnerabilities are discovered after onboarding is complete?
    • (15:18) Question 5: Do you think the current processes many companies have in place truly mitigate risk?
    22 min
  • Using Threat Intelligence Throughout the Enterprise

    Episode 18 of the podcast covers methodologies to produce actionable outcomes from threat intelligence, and use cases where threat intelligence can be applied throughout the enterprise.

    • (01:11) Question 1: With your threat intelligence program, what steps do you take to filter the firehose of noise and determine what has context and what is actionable?
    • (03:32) Question 2: A lot of SOCs believe threat intelligence should be defined as “new information that tells a SOC what the security stack does not know about and/or cannot detect”. Do you agree or disagree and why?
    • (04:16) Question 3: As security professionals, we have a tendency to find out the “who” of attribution. Do you think that is important? Do you think the “how” and “why” are the better measures of attribution research and is that even possible given limited resources of a medium size organization? Explain.
    • (07:22) Question 4: What do you see as use cases for threat intelligence across an organization? Anything beyond cyber related crime?
    • (11:09) Question 5: With all of the advancements in threat intelligence feeds and platforms around enrichment, automated analysis, correlation, etc, have you seen a down-tic in the amount of analyst time that it takes to get to something actionable? What are some technologies you like for aggregation and automation?
    15 min
  • Shared Responsibility of Security, Securing Your Platform

    Episode 17 of the podcast covers different uses of threat intelligence to protect against platform abuse and application security.

    • (00:45) Intro
    • (01:09) Q1: File sharing companies have a heavy attack surface not only from cyber actors trying to infiltrate their network perimeter, but also using the platform itself to store illicit information they steal. How do you defend against all these threats and how do you prioritize?
    • (09:55) Q2: As a medium size business, how do you prioritize threat intelligence that shows vulnerabilities against your tech stack? 
    • (14:37) Q3: There’s been a lot of talk about the shared responsibility model, particularly after the Capital One incident, what are your thoughts on shared responsibility? What is Egnyte responsible for and what are your clients responsible for in regards to security? 
    • (20:18) Q4: Does attribution matter? If so, no organization is going to be able to devote resources to attributing all attempted threat activity, where do you draw the line? Which types of attacks or actors are you willing to make that investment on and why? 
    • (23:33) Q5: Many say that modern day application development does not take into consideration or prioritize security controls. What approach and strategy did you take to bake in security controls when building Egnyte?
    30 min
  • Managing Cyber Risk Through Data Flow Accountability and Corporate Governance

    Episode 16 of the podcast covers actionable advice for companies around risk management especially third-party due diligence, privacy, network security, and vulnerabilities.

    • (00:08) Intro
    • (00:55) Question 1: What advice would you give to companies in how to think about cyber risk - whether through data management, compliance or processes themselves?  Can and should this risk even be quantified?
    • (05:15) Question 2: M&A issues around data mapping: How should companies think about integration issues when acquiring legacy data of a target company? For example, should companies ask for reps and warranties around that data?  Can companies be advised to properly determine indemnification amounts?
    • (12:02) Question 3: How should organizations be building teams to work through these issues - whether internal or external?  What are the characteristics of teams and vendors that are effectively addressing cyber risk on behalf of organizations?  What do you look for in a vendor for clients?
    • (19:14) Question 4: We think about regulations including CCPA, GDPR, and requirements pushed down through various industries - how should companies be thinking about compliance?  How do third parties play into this?
    • (22:40) Question 5: How are you seeing the work from home movement affecting cyber risk and how should companies be evaluating their security stances and policies in light of the remote workforce reality we find ourselves in?
    30 min
  • Analysis of Betterment and Exclusions within Cyber Insurance Policies

    Episode 15 of the podcast covers how a cyber incident is defined by insurance carriers, how that is changing, and an in-depth analysis of betterments and exclusions often overlooked in cyber insurance policies.

    • (00:48) Intro
    • (01:13) Question 1: How do most cyber policies define a cyber incident?
    • (03:54) Question 2: What do cyber policies cover once a cyber incident has occurred?
    • (04:44) Questions 3: With betterment language, what will cyber insurance pay for with regard to remediations?
    • (12:30) Question 4: What are important exclusions to pay attention to and what can be done to have them included in your policy
    • (16:33) Question 5: What are some new themes and trends you see going forward in the cyber insurance market?
    22 min
  • OSINT Provides Valuable Context Moving Data to Intelligence

    Episode 14 of the podcast covers techniques and tradecraft of open source intelligence and investigations. How these investigations can help businesses and executives avoid online crimes and where automation plays a helping hand.

    • (00:44) Intro
    • (02:51) Question 1: What is the difference between a cyber threat intelligence analyst and an OSINT investigator?
    • (04:22) Question 2: What are some general skillsets you need to be a good online investigator and what kinds of security problems do you solve?
    • (09:50) Questions 3: Many people don’t know where to start when they are being scammed, extorted, or hacked. What are the methodologies you’d like to spread to level the playing field? Examples?
    • (13:57) Questions 4: What can executives know about removing PII from the internet to protect themselves from physical and cyber attacks?
    • (16:50) Question 5: What kinds of interesting datasets are out there in this profession? Where is automation helpful?
    • (23:39) Closing
    25 min
  • Gaining Actionable Insights to Global Physical Security Threats

    Episode 13 of the podcast covers the importance of building rapport with the workforce to gain actionable insights to global physical security threats.

    • (01:09) Introduction
    • (01:48) Question 1: The world of physical security controls has changed a lot in the last ten years with many threats emanating online. How do you use cyber threat and OSINT information to evaluate and reduce risk to physical threats?
    • (03:03) Question 2: How important is the attribution of those threats in a digital environment?
    • (04:22) Question 3: From an executive protection standpoint, how do you minimize risk to senior executives that emanate online particularly including home, travel, and workplace security?
    • (06:40) Question 4: From a privacy perspective, how do you build rapport with the workforce to bring forward physical security incidents?
    • (09:40) Question 5: What metrics and impacts are important to capture to show effectiveness of your program(s)?
    • (12:09) Closing + Bonus: What trends in the security industry keep you up at night?
    15 min
  • What Makes an Effective Insider Threat Program?

    Episode 12 of the podcast covers the importance of building rapport with the workforce to gain actual insights to insider threats. 

    • (00:48) Introduction
    • (01:55) Question 1: What are the general backgrounds of insider threat personnel and why does that matter for how a program is developed and run?
    • (02:59) Question 2: What are important policies to put into place that foster positive collaboration between the workforce and security?
    • (04:10) Question 3: How do you foster a collaborative culture to have employees be the front lines of insider threat?
    • (06:48) Question 4: What are the important monitoring mechanisms to put into place that alert on the appropriate behavior but don't poison the innovative culture?
    • (10:35) Question 5: What are the important metrics and administrative actions that indicate a program is appropriately mitigating the risk of negligent or malicious insider threat behavior?
    • (13:00) Closing
    14 min
  • Challenges of Containerized and Cloud Environments

    Episode 11 of the podcast covers challenges and baselining of container and cloud security. 

    • (0:54) Introduction
    • (01:29) Question 1: What are the right and left bounds when deciding to use a container environment as part of the infrastructure and how much of that is security minded?
    • (03:03) Question 2: How do you approach a baseline level of security for your containerized environments? Is it mainly configuration or do you consider other aspects for hardening of your containerized environments?
    • (06:30) Question 3: From your experience, which of the environments, if any, are more security forward than any other and why? Kubernetes? Docker?
    •  (12:06) Question 4: Does the way you defend and track threats against container environments differ from the non-containerized environments? Is a containerized environment inherently easy to secure or more work? 
    •  (12:54) Question 5: How have containerized environments changed the penetration testing, threat hunting, and incident response process? Are there different skillsets needed? Could you provide examples? 
    • (19:41) Bonus: In the security world, what keeps you up at night?
    • (21:50) Closing
    23 min
  • How Today's CISOs Think About the Future of Threat Intelligence

    Episode 10 of the podcast covers how modern CISOs think about the future of threat intelligence.

    • (0:21) Introductions 
    • (1:55) Question 1: What kind of information do you see threat intel feeds providing, and which ones are most compelling to you?
    • (4:35) Question 2: Is it unique to have information sharing with other portfolio companies? How does that work programmatically?
    • (7:01) Question 3: What are the new, hot data sets you’re seeing?
    • (9:35) Question 4: Are you aware of an increase in adversaries targeting containerized environments?
    • (11:55) Question 5: Are you thinking about threat intelligence differently as it relates to cloud and containerized environments that support a dispersed workforce?
    • (17:36) Closing Remarks
    19 min

About the CYBER5

From the publisher's feed

The CYBER5 is hosted by Landon Winkelvoss, Co-Founder at Nisos, and features cybersecurity and investigations industry leaders' thoughts and answers to five questions on one topic on actionable…