The Security Swarm Podcast

The Security Swarm Podcast

By HornetsecurityNewsTechnologyTech News
Download on the App Store

The Security Swarm Podcast episodes

  • EP19: How to Sell Cybersecurity to the C-Suite

    As cybersecurity professionals, MSSPs, and security vendors, we often get mired down in the weeds of the “tech” involved in the job and frequently struggle to convey the value of said technology to the C-Suite. With that said, we’re deviating from our regularly scheduled programming this week to bring you something of a “soft-skills” episode to address this key point.  

    This week we’re excited to bring you the business and C-Suite knowledge of our very own Hornetsecurity Chief Operating Officer, Daniel Blank for a discussion on how you can get your leadership team to see value in technology, put priority on security, and ultimately sell cybersecurity to the C-Suite. Hope you enjoy! 

    Timestamps:

    2:23 – Conveying the Value of Cybersecurity to Leadership without Using the Fear Angle 

    15:50 – Compliance and Similar Issues Often Drives C-Suite Attention 

    26:05 – An Example - What Would Daniel Look for When Having to Make a C-Suite Decision? 

    Episode Resources:

    365 Total Protection 

    Email Encryption 

    Andy on LinkedIn, Twitter or Mastodon 

    Daniel on LinkedIn 

    31 min
  • EP18: Generative AI in Defensive Tools

    In today’s episode, Andy and Umut are unravelling the transformative impact of AI in cybersecurity defense. Discover how AI empowers defenders with enhanced knowledge of setting up robust defense mechanisms, from firewalls to anomaly detection systems. Amidst the prevailing focus on AI's darker aspects, this episode illuminates its positive role in the security space, equipping blue teams to match wits with increasingly intelligent adversaries. Our hosts, Andy and Umut, both distinguished members of the Security Lab at Hornetsecurity, will provide expert insights into how Hornetsecurity's suite of products leverages AI to display a concrete example in the industry. 

    Join us as we shift the narrative from AI's potential for malicious use to how defensive toolsets and security experts are harnessing its power.  

    Timestamps: 

    3:12 – How has AI changed the threat landscape? 

    6:10 – How can AI help blue teams? 

    16:08 – An example of AI used defensively in a software stack 

    26:24 – What advancements in AI in the security space are we likely to see in the future? 

    Episode Resources:

    EP08: Advanced Threat Protection: A Must Have in Today's Ecosystem?

    EP03: The Reemergence of Emotet and Why Botnets Continue to Return

    Advanced Threat Protection

    Security Awareness Service

    OpenAI Cybersecurity Grant Program

    AI can steal data by listening to keystrokes with 95% accuracy

    Andy on LinkedIn, Twitter or Mastodon 

    Umut on LinkedIn 

    32 min
  • EP17: On-Prem Security vs Cloud Security

    In today’s episode we have Eric Siron, Microsoft MVP, joining Andy for a discussion on the debated topic of On-Prem Security versus Cloud Security from a security standpoint. The digital landscape has transformed, raising questions about securing multiple cloud services, APIs, and the scattered user base. We explore how defenses have evolved and although default protections have strengthened, attack vectors have grown smarter with the growth of ransomware. Join us as we dissect these changes and their impact on modern security paradigms in an era where protection and adaptation are paramount. 

    Disclaimer: This episode was recorded just before news of the Microsoft breach hit the headlines. Thus, while some of the perspectives may seem momentarily misaligned due to the unfolding events, the core insights and conclusions drawn remain the same.  

    Timestamps:

    3:50 – What is the current state of on-premises infrastructure in terms of security?  

    12:37 – How does compliance factor into on-premises security? 

    21:12 – Is Infrastructure in the cloud more secure? 

    33:12 – Is “The Cloud” or “On-Premises” more secure? 

    Episode Resources:

    Monthly Threat Report - August 2023 

    Andy and Paul Discuss M365 Security

    Andy and Paul Discuss the Difficulty of Licensing Security Features in M365

    Hornetsecurity Ransomware Survey Findings

    The Backup Bible

    Hornetsecurity's Security Awareness Service

    Information on Recent SEC Announcement

    41 min
  • Monthly Threat Report - August 2023

    The Monthly Threat Report by Hornetsecurity brings you monthly insights into M365 security trends, email-based threats, and commentary on current events in the cybersecurity space. Every month, Andy will be hosting an episode to dive into the key takeaways from the report. 

    In today’s episode, Andy and Umut will be sharing a threat overview based on data from the Security Lab throughout July 2023. From the changing tactics in email attacks, to new brand impersonations and the impact of dark-web generative AI (Artificial Intelligence) tools like WormGPT, we will equip you with the right information to help you stay ahead of these new emerging threats.  

    Timestamps:

    (2:43) – Net increase in all email threat categories during the data period 

    (4:17) – The mostly commonly used file-types for payload delivery during the data period 

    (7:24) – The most targeted industry vertical during the data period 

    (10:13) – Most impersonated brands during the data period 

    (15:49) – The rise of malicious generative AI like WormGPT 

    (22:55) – The continued fallout from the MOVEit vulnerabilities 

    (26:46) – The breach of Microsoft Cloud services by Storm-0558 

    Episode Resources:

    Monthly Threat Report - August 2023 

    EP 01 - We Used ChatGPT to Create Ransomware

    Andy on LinkedIn, Twitter or Mastodon 

    Umut on LinkedIn 

    39 min
  • EP16: Backup’s Modern Role in Security

    In today's episode, Andy has a special guest from our product development team at Hornetsecurity - Jean Paul (JP) Callus. The episode goes into an insightful discussion on how threats have morphed over the years. Andy and Jean Paul recount the days when backup primarily served as a safety net against accidental data loss and hardware failures. Fast forward to today, and backups have become a key weapon in the fight against ransomware and other sophisticated attacks. 

    Tune in to discover the power of modern backups in the ever-evolving world of cybersecurity and how organizations can establish seamless data protection measures, ensuring minimal data loss and downtime in the face of cyber threats. 

    Timestamps:

    (2:16) – Ransomware continues to drive backup and recovery decisions.

    (10:10) – How has the industry traditionally mitigated ransomware and how are things done now? 

    (14:13) – Revisiting the 3-2-1 backup strategy and adding an extra “1” 

    (16:10) – Cloud backups and WORM (Write Once Read Many) states. 

    (19:10) – What other backup technologies play a role in security? 

    (23:43) – Deduplication, Immutability, and Backup 

    Episode resources:

    Podcast EP01: We Used ChatGPT to Create Ransomware

    Podcast EP05: What is Immutability and Why Do Ransomware Gangs Hate it?

    Hornetsecurity Ransomware Attack Survey

    VM Backup V9

    The Backup Bible 

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Jean Paul on LinkedIn

     

    29 min
  • EP15: A Frank Discussion on Licensing M365 Security Features

    Join us for an insightful discussion on the topic of licensing Microsoft 365 security features. Microsoft Certified Trainer, Paul Schnackenburg, joins us once again to share his valuable insights on how M365 licensing practices have evolved and why they’ve become so complex. 

    In this episode Andy and Paul look at all the different ways native security features in M365 are licensed, what challenges come along with that process, how the process is confusing and more! This includes some discussion around how M365 licensing in general is flawed as well as how third-party software vendors help plug-in and do what they can to simplify this mess. 

    Timestamps:

    2:22 – O365 licensing vs M365 licensing 

    5:06 – Is the complexity in M365 licensing deliberate? 

    7:09 – Licensing and security with M365 business 

    13:30 – Licensing and security in the M365 Enterprise SKUs 

    19:30 – What about the EMS Suite? 

    21:42 – What are E5 Compliance and E5 Security? 

    28:05 – How can a 3rd party vendor help make licensing security features easier? 

    Episode Resources:

    SysAdmin Dojo Podcast Episode on General M365 Licensing 

    Andy and Paul’s M365 Compliance Webinar

    Defender for Endpoint

    Hornetsecurity Services

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Paul on LinkedIn or Twitter

    36 min
  • EP14: The Permissions Management Nightmare in SharePoint Online

    We’re back for another episode with Philip Galea, R&D Manager at Hornetsecurity. In today’s episode, Andy and Philip discuss the frustrations and challenges IT admins face when managing permissions and sharing effectively in SharePoint Online.  

    As more organizations embrace remote work, collaborate with external freelancers, and rely on tools like Microsoft Teams and emails for sharing files, the need to manage permissions has become crucial. Tune in to this episode to learn about the complexities of SharePoint and discover ways to regain control over your access management. 

    Timestamps:

    4:44 – The problems with managing permissions in SharePoint Online 

    8:34 – The ease of file sharing in M365 has created a problem. 

    11:16 – Have SharePoint security capabilities just been “lifted and shifted” to the cloud? 

    14:43 – The egregious problem with duplicate named SharePoint custom roles. 

    23:32 – What should M365 admins be doing about this problem?  

    27:10 – Behind the scenes with M365 Permission Manager by Hornetsecurity 

    Episode Resources:

    365 Permission Manager

    Introducing 365 Permission Manager – Webinar

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Philip on LinkedIn

    38 min
  • EP13: Real-Life Security Horror Stories

    Join host Andy and special guest Martin Tanner from ADM Computing as they discuss real-life security horror stories. This fun and engaging episode was recorded live at Infosecurity Europe in London. Expect to hear interesting stories which both Andy and Martin have experienced first-hand. 

    With a mix of humor and valuable insights, this episode is a must-listen for anyone interested in the fascinating, and at times terrifying, world of real-life security horror stories. 

    Timestamps: 

    2:28 – The Dangers of Unmanaged IOT devices 

    5:30 – Hacked Video Conferencing Unit and Premium Rate Numbers 

    8:18 – Email Forwarding Rules and Data Leakage 

    11:59 – The Need for Proper Backup and Archival + Scheduled Payment Woes 

    15:40 – Rogue Admin and Embezzlement 

    18:17 – A Flattened Network and Ransomware Infection 

    22:16 – The Publicly Accessible Hypervisor 

    Episode Resources:

    Security Awareness Service

    Email Encryption from Hornetsecurity

    Email Encryption Fact Sheet

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Martin on LinkedIn

    26 min
  • EP12: What We Learned by Asking the Community About Compliance

    Get ready for an eye-opening episode recorded live at Infosecurity Europe in London. In this episode, Andy and Matt Frye dissect the results of a comprehensive IT compliance survey conducted by Hornetsecurity. In the rapidly evolving digital landscape, maintaining IT compliance has become a pressing concern for businesses worldwide.  

    Tune in to explore the key findings from this survey, featuring insights from over 200 IT professionals representing diverse roles, regions, industries, and experience levels. 

    Timestamps:

    02:32 – Compliance is a growing concern 

    03:52 – Do businesses see compliance as important? 

    06:24 – The burden of compliance on IT teams

    12:08 – How are businesses verifying compliance? 

    14:46 – Trust in the cloud continues to be a problem for some organizations 

    17:00 – M365 administrators are struggling with compliance tools 

    20:57 – The cost of non-compliance 

    Episode Resources:

    IT Cybersecurity Compliance Survey 

    365 Permission Manager 

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Matt on LinkedIn

    27 min
  • EP11: On-Prem Exchange Server Throttling

    Microsoft's recent decision to throttle traffic from old and outdated versions of On-Premises Exchange has sent shockwaves through the tech community. In today's episode, Andy and Paul Schnackenburg delve into the details of Microsoft's plans to protect Exchange Online against persistently vulnerable on-premises Exchange Servers by throttling and blocking emails from these unsupported servers. 

    Tune in to understand the reasoning behind Microsoft's strategy with this change, how organizations can keep themselves protected through process, and where third-party vendors can plug in and provide value. 

    Timestamps:

    4:00 – Microsoft’s plan details and communication 

    10:50 – Paul and Andy’s thoughts on why Microsoft is making this change 

    18:40 – Is it “Ethical” for Microsoft to block on-prem Exchange traffic? 

    26:31 – What should affected organizations do? 

    Episode Resources:

    Microsoft's Announcement

    SMB1 Changes at Microsoft

    Hornetsecurity's 365 Total Protection

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Paul on LinkedIn or Twitter

    34 min

About The Security Swarm Podcast

From the publisher's feed

Welcome to The Security Swarm Podcast – a weekly conversation of the most critical issues facing the world of cybersecurity today, hosted by Andy Syrewicze, Security Evangelist at Hornetsecurity.