
Sign up to save your podcasts
Or


This month the panel is a party of one - Rob Yandow joins again to talk with Dave about high stress situations and preparedness. This is especially relevant given the reopenings and the latest hostile event situations. Rob goes into detail about the phsiology of fear, as well as how and why individuals respond to high stress situations the way they do. Using various examples, Rob hammers home the various stages in the survival arc - denial, deliberation, and decisive action. And most importantly, the podcast talks about the ways organizations can use this information to train and prepare to respond. Then Dave is joined by a special guest to talk about the greatest band ever.
Rob Yandow is a security expert who is a former police officer and who works with the Faith-Based Information Sharing and Analysis Organization (FB-ISAO) and serves as the Co-Chair of their Business Resilience Group - website: https://faithbased-isao.org. Twitter: @RobYandow
Despite the razzing I got from the guys (David Pounder - host of the NerdOut! Security Panel Discussion, and Andy Jabbour - host of The Gate 15 Interview) during the last Risk Roundtable, the TCE ISAC Series continues!!! This time, REN-ISAC (Research & Education Networks Information Sharing & Analysis Center) joins me. REN-ISAC serves the higher education and research community by promoting cybersecurity operational protections and response.
For this episode, I enjoyed a fun and lively chat with Krysten Stevens, “new” Director of Technical Operations, and Brett Zupan, Risk Analyst and DC Liaison. We talked about threats facing the research and higher education community and bragged on Kim Milford’s (REN-ISAC’s Executive Director) amazing vision in 2019 to execute a series of workshops that had colleges, universities, and relevant community partners, such as state/local health departments and law enforcement working together through an infectious disease scenario – a scenario the team thought might be going too far…
Resources discussed on this episode:
The Risk Roundtable crew looked at the increasingly important idea of security bias and security blindness. The group specifically looked at how bias in analysis can lead to security blindness and the minimization and exaggeration of threats. Within the analytical community it is important to note how bias exists in virtually everything and the team discussed ways in which bias could exist from the analyst, but also by those that receive the data. Andy, Jen and Dave discussed some of the root causes and how this can lead to and continue a cycle of misinformation and disinformation if not handled correctly. In fact, the more divisive our politics become, the more bias our media, the more people – politicians, the media, foreign governments, and others - fan the flames of division, the more challenging the role of the analyst can become. In the end, bias is a discussion that is encouraged to be had by all organizations to ensure they are accurately representing the threat and risk to the organization.
Next the team looked at their roulette items (Dave even shared the theme song on demand!) reminding listeners of the Microsoft Exchange Vulnerability and to update their systems. In addition, as reopenings are occurring around the world in varying degrees, it is important that organizations review security plans and processes.
Items highlighted in the Podcast:
Health ISAC Spring Summit open to members and non-members: https://h-isac.org/summits/secured-in-paradise-spring-2021-summit/
Troy Hunt Confirmation Bias - and good read: https://www.troyhunt.com/lets-stop-the-5g-hysteria-understanding-hoaxes-and-disinformation-campaigns/
Additional information about the Microsoft Exchange Vulnerability:
FortiOS Vulnerability: https://us-cert.cisa.gov/ncas/current-activity/2021/04/02/fbi-cisa-joint-advisory-exploitation-fortinet-fortios
CISA Cybersecurity Directives and Implementation Guidance Site: us-cert.cisa.govus-cert.cisa.gov
In this episode of The Gate 15 Interview, Andy Jabbour talks with James Whalen, SVP, Chief Information & Technology Officer, Boston Properties. In this podcast we address:
James Whalen: James Whalen serves as Senior Vice President, Chief Information & Technology Officer for Boston Properties where he is responsible for the direction and implementation of technology services and solutions. Prior to joining the Company in March 1998, he served as Vice President, Information Systems of Beacon Properties. He is a graduate of the University of Notre Dame and a recipient of the New York City Urban Fellowship. Mr. Whalen is a current trustee and past President of the Boston Chapter of the Society for Information Management (SIM) and serves on the Real Estate Cyber Consortium, Realcomm Advisory Council, Commercial Facilities Cyber Working Group, TechHire Boston and Boston Private Industry Council. LinkedIn.
A few references mentioned in or relevant to our discussion include:
· The Real Estate Information Sharing and Analysis Center (RE-ISAC). “The Real Estate Information Sharing and Analysis Center (RE-ISAC), a not-for-profit information sharing entity organized by The Real Estate Roundtable in February 2003, is a public-private partnership between the US commercial facilities sector and federal homeland security officials which serves as the primary conduit of terrorism, cyber and natural hazard warning and response information between the government and the commercial facilities sector.”
· InfraGardNCR: Commercial Facilities Cyber Working Group (CCWG)
· FBI IC3 Cyber Crime Report: FBI Releases the Internet Crime Complaint Center 2020 Internet Crime Report & PDF: 2020 Internet Crime Report, 17 Mar 21
· Palo Alto Networks: Highlights from the 2021 Unit 42 Ransomware Threat Report & Ransomware Threat Assessments: A Companion to the 2021 Unit 42 Ransomware Threat Report, 17 Mar 21
· Group-IB: ransomware empire prospers in pandemic-hit world. Attacks grow by 150%, 04 Mar 21
· Realcomm Advisory Council
In the latest episode of Nerd Out, Dave and his merry band of nerdies, Bridget, Travis, and Joe, look at the latest news around the reopening and what organizations need to be on guard for as crowd sizes and capacity limits will test the ongoing health pandemic. Then the group looks at the way threat actors may respond. Will it be a target of opportunity or will new security measures be disruptive enough. Next, the panel looked at recent protests, and the potential for future protests (did people really forget about May Day!) and what ways they may change in a reopened world. Finally, what is the future of conspiracy theories and the movements that were charged over the past several years? The group then lightened it up a bit and went through some lightning round questions and discovered that the Snyder Cut really isn't a thing because no one particularly cared for it in the first place to even know it was a thing.
Dave Pounder is a Senior Risk Analyst for Gate. Twitter: @dpounder; email: [email protected]
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Travis Moran is the Assistant Deputy Director, Critical Infrastructure Protection & Physical Security. Twitter: @dronin_on; email: [email protected]
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
TCE welcomes Faith-Based ISAO Executive Director, Mayya Saab on this episode. And no, this isn't the "FBI" ISAO... ;-) Listen in to find out what Mayya loves most about her role and her heart's desire in helping the entire community of faith be secure and resilient.
Check out FB-ISAO at https://faithbased-isao.org/
In the latest episode of the Risk Roundtable, Andy, Jen, and Dave look at some recent events (Oldsmar) while looking ahead to upcoming events that may present risks (Qanon, the George Floyd murder trial, and upcoming religious holidays) but only after talking about Andy's taste in shirts. Then in the risk roulette, which Dave forgot again to find music for (or did he), Dave wonders about weather preparedness is overhyped while Jen circles back to lessons learned from Solar Winds and the concept of "zero trust" - not in Andy and Dave but in terms of cybersecurity. The gang wraps up talking about some of their struggles and what they are watching. But that's not all - after the credits Dave may have redeemed himself with a new theme for the risk roulette.
Some of the links from today's episode:
YouTube: Treatment Plant Intrusion Press Conference, 08 Feb.
From the publisher's feed