the CYBER5

the CYBER5

By Nisos, Inc.BusinessTechnology
Download on the App Store

the CYBER5 episodes

  • A Deep Dive on Deepfakes

    This is a bonus episode of the podcast and the second of a two part series covering a Nisos project with New York University (NYU) regarding the digital economy and misuse of deepfakes.

    • (00:26) Introductions
    • (01:33) Question 1 - What’s the biggest challenges deepfakes presents us with? How about 5 years from now?
    • (04:08) Question 2 - Are there deep/dark web capabilities that people can hire to create these? How good are they?
    • (10:31) Question 3 - Why are the majority of deepfakes focused on pornography and do you see this shifting over time?
    • (16:48) Question 4 - Should the average person be worried about this?
    • (17:57) Question 5 - How can nation states, including the US, safeguard against the misuses of this technology?
    22 min
  • A Deep Dive on Deepfakes

    This is a bonus episode of the podcast in a two part series covering a Nisos project with New York University (NYU) on the technical considerations for creating deepfakes as well as processes and procedures to detect them.

    (00:28) Introductions (01:06) Overview of Nisos Deepfake Project (02:21) Question 1 - What kind of research did you have to do to start making deepfake videos?  (03:51) Question 2 - Are there a lot of open source libraries intended to make building deepfakes easier?  (05:20) Question 3 - What was the most difficult part of the process for building a deepfake video? (06:15) Question 4 - How difficult is it to make deepfake audio? (06:56) Question 5 - How can we detect deepfakes?

    11 min
  • The Importance of Actionable Threat Intelligence for the Business

    Episode 9 of the podcast covers operationalizing threat intelligence to inform better business decisions.

    • (0:19) Introductions 
    • (2:34) Question 1: When it comes to cyber threat intelligence, what information is most actionable?
    • (5:05) Question 2: How do you filter to make sure it's relevant?
    • (7:00) Question 3: For a use case, how do you filter for insider threats?
    • (9:04) Question 4: How do you get buy-in for your program from business leaders?
    • (11:20) Question 5: What types of business decisions does your cyber security program inform?
    • (14:17) Recap & Takeaways 
    17 min
  • The Importance of Building Adversarial Context

    Episode 8 of the podcast discusses why adversarial context is critical to leverage the proper resources of a security operations team.

    • (00:25) Introductions
    • (03:43) Question 1 – What types of threats are uninteresting to you? What types lead you to investigate outside of your firewall?
    • (05:17) Question 2 – What are the questions you look to answer?
    • (07:33) Question 3 – What answers do you look for outside of the network?
    • (09:48) Question 4 – How have you built this into your decision-making?
    • (11:47) Question 5 – What are the impacts that you’ve seen in employing this overall strategy?
    • (14:08) RECAP & Takeaways
    17 min
  • COVID Impacts on Insider Threat

    Episode 7 of the podcast covers insights into current trends in commercial sector Insider Risk, stemming from the remote workforce & COVID19.

    •Intro (00:22) •Question 1 (01:05) – Does the current climate set us at increased exposure to Insider Risk? What elements of the Pandemic have led to that? •Question 2  (02:41) – How much of this has to do with the increased/imposed remote aspect of the workforce? And does this change in the status quo have any other impacts? •Question 3  (07:23) – For companies with an existing insider risk program, what are changes that they should consider making with the changes in work-dynamic? •Question 4  (09:25) – If I’m a company that doesn’t already have an Insider Risk program in place, where should I start now? •Question 5  (12:12) – When all of this ends, and the workforce starts to come back, what should companies be worried about? •Recap & Key Takeaways (14:19)
    17 min
  • A Red-teamer's Take on Threat Intelligence

    Episode 6 of the podcast covers insights into the impacts of threat intelligence from the perspective of the ultimate red-teamer, Tyler Robinson of Nisos, Inc.

    • Intro (00:27)
    • Question 1 (01:29) – As a red-teamer, when you’re doing your job, do you feel threatened by threat feeds, or things like the MITRE Attack framework?
    • Question 2 (03:37) – So you’re a sophisticated adversary – do you actually take these things into account in preparing your attack? IE pulling in threat feeds, and matching your approach against frameworks that the target may use.
    • Question 3 (07:00) – So you’ve done a lot of this over the years, what keeps you up at night, and I’d guess it’s probably similar for the black hats out there, when it comes to your success in compromising a target’s infrastructure?
    • Question 4 (09:49) – What are the gaps that you see when it comes to modern threat intelligence?
    • Question 5 (11:13) – Where do you see the industry moving in the next year or two?
    • Recap & Take-aways (14:54)
    18 min
  • Episode 5 - Understanding the Insider Threat

    Episode 5 of the podcast focuses on understanding the nuances around insider threat scenarios and features Gabe Ramsey, Partner @ Crowell & Moring.

    • Intro (00:18)
    • Question 1 (00:56) – Thinking about the team that comes together in an insider threat investigation, what does that look like? Both internal and 3rd parties.
    • Question 2 (01:50) - Are there any common trends that you see with companies that are successful in investigating and, from your angle, bringing litigation against an insider threat?
    • Question 3 (02:39) - Insider threat, its a very multi-dimensional problem, but all of the effort leads to some kind of legal action or outcome. From your perspective, what is the main network informational gap that you face in trying to prove the actions or intent of an insider?
    • Question 4 (04:21) - I've spoken with CISO's specifically on data collection surrounding insider threat, and it seems that there is a general lack of comfort with the total degree of valuable information gathering that can be done within the scope of the law, largely because it seems invasive to the individual. That said with an insider threat situation, you are often trying to prove something that falls more in the realm of human activity, than pure network activity. What are some of the tools you recommend clients use to collect the necessary information to be able to make the right assertion about an individual suspected of being an insider threat, and how do you help them navigate this often-uncomfortable situation?
    • Question 5 (07:28) - I've heard people talk about larger, more sophisticated companies allowing technical threats to dwell on specific systems so they can learn more about their motives through the actions they observe on the network, and with insider threat, I can imagine that there is a range of appropriate responses, from immediate separation to levels of overt or covert observation of the individual; from your perspective what does that look like, and what triggers lead to different actions, and what are the actions that companies end up taking?
    • Recap & Key Takeaways (10:19)
    14 min
  • Episode 4 - Understanding Your Environment
    Episode 4 of the podcast focuses on the CISO's perspective on the importance of understanding the corporate network environment and features Anthony Johnson, Managing Partner of Delve Risk. Outline:
    • (00:22) Introductions
    • (01:07) Question 1  – As a CISO, if I don’t have clear or accurate insight into the state of my assets and infrastructure, what immediate risks am I incurring?
    • (02:23) Question 2 – You’ve started a role as a CISO at a new company - how do you test the information your presented with around the the network, the current state of the security team and tech stack, and when do you trust it?
    • (03:21) Question 3 – In your experience, what percentage of the network do you think the average CISO and team have a good handle on and are there trends in the gaps?
    • (05:51) Question 4 – Are there any trivial gaps - How complete should a CISO’s knowledge and insight into their environment be; IE If they’re confident on 80% of the network, is that enough?
    • (08:43) Question 5 – How has the emphasis on maintaining a meaningful understanding of your network impacted your strategy around the staffing/teams that you’ve built?
    • (10:53) Recap & Takeaways 
    14 min
  • Episode 3 - Disinformation in the Time of Pandemics

    Episode 3 of the podcast focuses on illuminating disinformation and misinformation activity surrounding the COVID-19 Pandemic and features Cindy Otis, Managing Director at Nisos, Inc. Outline:

    • (00:00) Intro
    • (01:43) Question 1 - The pandemic is obviously something that’s touching every person’s life at this point. Due to the overall disruption, do you think people are more susceptible to disinformation surrounding it?
    • (03:48) Question 2 – What types of disinformation have you been seeing pushed out?
    • (05:35) Question 3 - Who are the actors behind it? What are they trying to accomplish with it?
    • (08:54) Question 4 – If I’m an employer, what can I do to help protect my employees from the influence of disinformation campaigns
    • (11:38) Question 5 – We’re still leading up to 2020 elections - Are you seeing corona virus disinformation tied to anything election related?
    • (14:58) Recap & Take-aways
    18 min
  • Episode 2 - Inside Purple Teaming
    Episode 2 of the podcast focuses on Purple Teaming and features Gerry Beuchelt, CISO, and Patrick Mathieu, Offensive Security Coordinator from LogMeIn. Outline:
    • (00:28) Introductions
    • (03:34) Question 1 - What lead you to start using them at LogMeIn?
    • (08:23) Question 2 - Where’s the value in using both Red and Purple Teaming?
    • (11:47) Question 3 - What improvements have you seen from using purple teams?
    • (15:06) Question 4 - What aspects of workshopping do you find most valuable and why?
    • (17:34) Question 5 – How do you measure the success of a purple team?
    • (21:50) RECAP

     

    24 min

About the CYBER5

From the publisher's feed

The CYBER5 is hosted by Landon Winkelvoss, Co-Founder at Nisos, and features cybersecurity and investigations industry leaders' thoughts and answers to five questions on one topic on actionable…