The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • Cyber Quick Strike - February 6, 2023

    https://www.reuters.com/legal/legalindustry/sec-reveals-2023-priorities-new-agenda-2023-01-31/

    https://www.darkreading.com/mobile/hornetsecurity-combats-qr-code-phishing-with-launch-of-new-technology

    https://www.secureworld.io/industry-news/security-concerns-businesses-chatgpt

    https://thehackernews.com/2023/02/new-wave-of-ransomware-attacks.html

    https://www.techrepublic.com/article/the-importance-of-data-retention-policies/

    LIST

    https://www.darkreading.com/edge-articles/what-cisos-can-do-about-brand-impersonation-scam-sites

    16 min
  • Infosec Wrap Up - February 3, 2023
    • https://thehackernews.com/2023/02/new-high-severity-vulnerabilities.html
    • https://nakedsecurity.sophos.com/2023/02/01/password-stealing-vulnerability-reported-in-keypass-bug-or-feature/
    • https://www.techrepublic.com/article/cybersecurity-bec-attack-mimics-vendors/
    • https://financialit.net/news/security/romance-scammers-break-over-60-hearts-and-wallets-every-week-warns-tsb-bank-reveals
    • https://www.cnn.com/2023/01/31/politics/ransomware-attack-schools-nantucket/index.html
    • https://techunofficial.com/openai-launches-chatgpt-plus-starting-at-20-per-month
    • https://cybersecurity.att.com/blogs/security-essentials/the-top-8-cybersecurity-threats-facing-the-automotive-industry-heading-into-2023
    • 17 min
    • Throwback Thursday - A Conversation with Gary Chan

      From October 4, 2022 - Gary Chan of Alfizo LLC helps businesses stay secure from hackers and insider threats, meet legal and regulatory compliance, and enable sales by meeting their customers' expectations for security. He is also a "security mentalist", and if you're like me and have never heard of this term, you need to check out this episode - it's fascinating!

      Gary's websites:

      • Creating memorable experiences for corporate audiences, https://www.gschan2000.com/

      • Helping organizations build their information security programs, https://alfizo.com/

      24 min
    • S5E5 - A Conversation with Derek Morris

      Derek Morris is a virtual Chief Information Security Officer (vCISO) with almost 3 decades in IT, Information Security, Cybersecurity. He possesses numerous industry certifications including: CISSP, CISM, CISA, CDPSE, PCI-QSA, CCSFP, CCNA, and MCSA. Bachelor's Degree in Computer Information Systems from Bryant University with a minor in Applied Statistics. We discuss the virtual CISO space and what to look for in a virtual CISO, including "IT empathy".

      27 min
    • Cyber Quick Strike - January 30, 2023

      Links:

      • https://www.bbc.com/news/business-64452986
      • https://heimdalsecurity.com/blog/new-mimic-ransomware-uses-windows-search-engine-to-find-and-encrypt-files/
      • https://www.bankinfosecurity.com/blogs/targets-opportunity-how-ransomware-groups-find-victims-p-3365
      • https://www.securityweek.com/the-effect-of-cybersecurity-layoffs-on-cybersecurity-recruitment/
      • https://coruzant.com/security/three-essential-proactive-steps-for-keeping-enterprises-cybersecure/

      • 11 min
      • Infosec Wrap Up - January 27, 2023

        Article links: 

        • https://www.theguardian.com/us-news/2023/jan/26/hive-ransomware-servers-seized-us
        • https://www.msn.com/en-us/news/technology/microsoft-365-outages-affect-office-teams-and-more/ar-AA16IX6
        • https://www.securityweek.com/us-government-agencies-warn-of-malicious-use-of-remote-management-software/
        • https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach
        • https://www.usnews.com/news/national-news/articles/2023-01-25/americas-broken-system-for-classifying-information
        • https://thehackernews.com/2023/01/is-once-yearly-pen-testing-enough-for.html
        • https://www.csoonline.com/article/3686118/9-api-security-tools-on-the-frontlines-of-cybersecurity.html
        • 17 min
        • Throwback Thursday - A Conversation with Mark Burnette

          From September 28, 2022 -  Mark Burnette, Shareholder-In-Charge at LBMC Information Security, discusses his path from Senior IT Auditor to overseeing and directing LBMC’s Risk Services practice nationwide. He is very active in the information security community, including as co-founder and past president of the Middle Tennessee ISSA chapter (one of the largest in the world), and co-founder and board member of the Southern CISO Security Council. His certifications include CPA, CISA, CISSP, CISM, and CRISC, and he frequently speaks on information security topics, including a fabulous TEDx talk on the Humanity Behind Cyber Attacks - https://www.ted.com/talks/mark_burnette_the_humanity_behind_cybersecurity_attacks.

          27 min
        • S5E4 - A Conversation with BJ Withrow

          BJ Withrow, Manager, Major Accounts, East Coast at Tenable, is a self-proclaimed geek at heart and cybernerd by trade. When he is passionate about something, it comes out in everything he does, and he loves what he does. We cover a variety of topics, including cybersecurity for small and midsized businesses, exercising, and the importance of a servant's heart.

          Note a production error resulted in mismatched video and audio for host, not guest. We have switched platforms going forward because of this issue.

          30 min
        • Cyber Quick Strike - January 24, 2023

          Southwest upgrades, NIST CSF update, ransomware affects 1000 ships' connectivity,  ransomware threat in next 24 months, iOS 12 zero-day fix, SCOTUS infosec risk management fails, securing IoT (list), my appearance this morning on the KAJMasterclass, and a thanks to Cynomi for including me as a top vCISO influencer.


          • https://www.ciodive.com/news/southwest-airlines-technology-data-upgrades-FAA/640890/
          • https://news.yahoo.com/southwest-didnt-heed-calls-upgrade-020007630.html
          • https://www.nextgov.com/cybersecurity/2023/01/nist-releases-potential-updates-its-cybersecurity-framework/381970/
          • https://www.theregister.com/2023/01/19/ransomware_attack_cuts_1000_ships/
          • https://www.darkreading.com/attacks-breaches/organizations-likely-to-experience-ransomware-threat-in-the-next-24-months-according-to-info-tech-research-group
          • https://nakedsecurity.sophos.com/2023/01/24/apple-patches-are-out-old-iphones-get-an-old-zero-day-fix-at-last/
          • https://www.csoonline.com/article/3685938/us-supreme-court-leak-investigation-highlights-weak-and-ineffective-risk-management-strategy.html#tk.rss_all
          • https://www.techrepublic.com/article/securing-edge-securing-iot-devices/
          • https://www.youtube.com/watch?v=vHyQyfRa4So&ab_channel=TheKAJMasterclassLIVE
          • https://www.cynomi.com/blog/top-12-vciso-influencers/
          • 16 min
          • Infosec Wrap Up - January 20, 2023

            T-Mobile breach (again), MailChimp breach (again), ransomware payments down, TikTok fined for cookie issue, Avast posts decryptor for BianLian, five trends for 2023, and leveraging LNK files. 

            • https://www.wsj.com/articles/t-mobile-says-hackers-stole-data-on-about-37-million-customers-11674166048
            • https://techcrunch.com/2023/01/19/t-mobile-data-breach/
            • https://www.msn.com/en-gb/money/technology/mailchimp-suffers-another-major-data-breach-following-employee-hack/ar-AA16w1Z3
            • https://www.theregister.com/2023/01/19/ransomware_payments_down/
            • https://www.secureworld.io/industry-news/tiktok-fined-cookie-policies
            • https://www.scmagazine.com/news/ransomware/avast-posts-decryptor-for-the-bianlian-ransomware
            • https://www.enterprisetimes.co.uk/2022/12/22/the-security-outlook-for-2023-five-trends/
            • https://thehackernews.com/2023/01/new-research-delves-into-world-of.html
            • https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware/
            • 15 min

            About The Virtual CISO Moment

            From the publisher's feed

            The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.