The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • Infosec Wrap Up - April 7, 2023

    A third of organizations cover up data breaches, Uber data exposed, crackdown on malicious Colbalt Strike servers, ChatGPT Samsung data leak, using ChatGPT as a risk and compliance enabler, and four steps to avoid a ransomware attack. Plus our first shout out for helping cybersecurity pros land their next great opportunity.

    https://venturebeat.com/security/a-third-of-organizations-admit-to-covering-up-data-breaches/

    https://www.infosecurity-magazine.com/news/uber-data-exposed-law-firm-breach/

    https://www.bleepingcomputer.com/news/security/microsoft-and-fortra-crack-down-on-malicious-cobalt-strike-servers/

    https://cybernews.com/news/chatgpt-samsung-data-leak/

    https://securityintelligence.com/posts/using-chatgpt-as-an-enabler-for-risk-and-compliance/

    https://www.eschoolnews.com/it-leadership/2023/03/30/4-steps-to-avoid-a-ransomware-attack/

    https://www.linkedin.com/in/colemic/

    16 min
  • Throwback Thursday - A Conversation with Dan Bradley

    From November 2, 2022 - Dan Bradley, CIPP/E, CIPP/US, CIPM, is the Senior Associate General Counsel at Global Payments, Inc. and a former Federal Prosecutor. We discuss privacy regulations both for financial institutions and SMBs, including the importance of frameworks. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

    16 min
  • S5E19 - A Conversation with Don Colliver

    In a special Wednesday episode, Don Colliver joins us to discuss how to be successful making technical presentations. He is an Enterprise Communications Consultant and Technology Evangelist and the author of "Wink: Transforming Public Speaking With Clown Presence" available in paperback, eBook, hardcover, and audiobook through Amazon and all major retailers. He empowers leaders and enterprise organizations to connect more effectively through their messaging with new-school authenticity, spontaneous fun, and transformative results. For more information, check out:

    https://www.winktechtalks.com

    https://www.doncolliver.com/engage


    26 min
  • S5E18 - A Conversation with Ryan Spelman

    Ryan Spellman is the Managing Director, Cyber Risk Managing Director, Cyber Risk at K logix. There are many vCISO and other cyber security consultants who offer third-party risk services but have minimal exposure to the issues associated with third-party risk, which are markedly different than enterprise risk. Learn what a vTPCISO is, why it matters, and what questions to ask of your vCISO when they suggest adding third party risk service to their offerings.

    32 min
  • Cybersecurity Quick Strike - April 3, 2023

    ChatGPT banned in Italy, regulatory action for internet connected medical devices, CISA KEV flaws affect 15 million public facing services, WordPress plugin active explout, German police raid DDoS hoster, Azure bug allowed critical system access, Cadbury Easter egg scam, and today's list - 12 tips for Microsoft Excel success.

    https://www.bbc.com/news/technology-65139406

    https://innovationorigins.com/en/us-regulator-takes-action-to-ensure-internet-security-in-connected-medical-devices/

    https://www.bleepingcomputer.com/news/security/15-million-public-facing-services-vulnerable-to-cisa-kev-flaws/

    https://hothardware.com/news/wordpress-sites-being-actively-exploited-thanks-to-plugins

    https://krebsonsecurity.com/2023/03/german-police-raid-ddos-friendly-host-flyhosting/

    https://www.scmagazine.com/news/cloud-security/azure-bug-allowed-access-to-critical-systems

    https://www.infosecurity-magazine.com/news/cadbury-warns-of-easter-egg-scam/

    https://cmitsolutions.com/blog/12-tips-for-microsoft-excel-success/

    20 min
  • Infosec Wrap Up - March 31, 2023

    IRS tax scam, phishing emails up over 500%, 3CX supply chain attack, insecure storing of work passwords, Defender oops, AlienFox, Apple security releases, Minnesota K-12, cyber legislation, and a preview of my BSides tak.


    https://www.hackread.com/irs-tax-forms-w-9-email-scam-emotet-malware/

    https://www.darkreading.com/attacks-breaches/phishing-emails-up-whopping-569-percent-2022

    https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html

    https://www.infosecurity-magazine.com/news/70-employees-keep-work-passwords/

    https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-mistakenly-tagging-urls-as-malicious/

    https://securityaffairs.com/144239/cyber-crime/alienfox-toolset-cloud-service-providers.html

    https://www.cisa.gov/news-events/alerts/2023/03/28/apple-releases-security-updates-multiple-products

    https://sahanjournal.com/education/minnesota-legislature-education-cybersecurity-minneapolis-ransomware/

    https://bsidesnash2023.sessionize.com/session/400189


    15 min
  • Throwback Thursday - A Conversation with Christian Espinosa

    From November 1, 2022 - Christian Espinosa is the author of "The Smartest Person in the Room: The Root Cause and New Solution for Cybersecurity", Founder and CEO of Alpine Security, a cybersecurity engineer, certified high-performance coach, professor, and lover of heavy metal music and spicy food. He’s also an Air Force veteran and Ironman triathlete. He used to value being the “smartest guy in the room,” only to realize that his greatest contribution to the fight against cybercrime is his ability to bring awareness to the issue through effective communication. Christian is a speaker, coach, and trainer in the Secure methodology, helping to make the smartest people in the room the best leaders in the field. For more information, visit www.christianespinosa.com, and to order his book, visit https://www.amazon.com/dp/B08T6QK6FN.

    26 min
  • S5E17 - A Conversation with Greg van der Gaast

    For our special last Wednesday of the month episode for March, Greg van der Gaast joins us. Greg is an international speaker on Why Security Fails, IT Quality, Leadership, and Strategy. He also is a former hacker, FBI & DoD operative, author, advisor, CISO, and people and culture enthusiast. Listen to hear his fascinating story and what is a major threat for SMB information security that most don't consider. He can be reached at https://gregvandergaast.com/.

    29 min
  • S5E16 - A Conversation with Bill Butler

    Bill Butler is an experienced Vice President Of Engineering with a demonstrated history of working in the hospital and health care and security compliance industry. He is the Founder and VP Engineering of PolicyCo (policyco.io), a platform that lets you tie Regulations, Policies, Procedures, Control Testing and Remediation together in a single platform, along with a host of other features like version control, reporting, sharing, attestations, and a public API.

    27 min
  • Cybersecurity Quick Strike - March 27, 2023

    Gordon Moore has died, ChatGPT bug exposed more, Windows snip vulnerability, a different take on BEC, North Dakota cyber education program, CISA pre-ransomware notifications initiative, proposed SWEC cyber regs, and today's list - 5 tips for cyber beginners.


    • https://nakedsecurity.sophos.com/2023/03/27/in-memoriam-gordon-moore-who-put-the-more-in-moores-law/
    • https://www.hackread.com/chatgpt-bug-exposed-payment-details/
    • https://thehackernews.com/2023/03/microsoft-issues-patch-for-acropalypse.html
    • https://www.bleepingcomputer.com/news/security/fbi-business-email-compromise-tactics-used-to-defraud-us-vendors/
    • https://www.kxnet.com/news/state-news/north-dakota-is-first-state-to-approve-required-cybersecurity-education/
    • https://securityaffairs.com/143990/security/cisa-pre-ransomware-notifications-intiative.html
    • https://www.natlawreview.com/article/divided-sec-proposes-slew-cybersecurity-regulations-securities-market-entities
    • https://alebogadodev.medium.com/5-essential-cybersecurity-tips-for-beginners-7544cf7d5a9c

    • 16 min

    About The Virtual CISO Moment

    From the publisher's feed

    The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.