The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • Throwback Thursday for December 15, 2022 - A Conversation with Susan Richards

    From August 30, 2022 - Susan Richards is a dynamic director of Information Security concentrated in compliance, project management, application development, and database administration. She is skilled in IT Strategy, Management, Compliance Assurance, and Risk Management including HITRUST, NIST and ISO security frameworks. She is also very involved in the information security community, including ISSA chapter leadership and has this year started a local HITRUST chapter - plus we discuss election integrity!

    26 min
  • The Virtual CISO Moment S4E62 - A Conversation with Greg Flatt

    Greg Flatt is the founder of Flatt Earth Networking, Inc. Since 1996, Flat Earth Networking, Inc. has provided mid- to large-sized businesses an authoritative approach to network security that includes superior enterprise products and effective problem-solving. Greg discusses his path beginning and growing Flat Earth Networking, Inc. over the past 26 years.

    22 min
  • VCM Quick Strike for Monday, December 12, 2022

    You can bet on increasing cyberattacks on casinos, new air gap attack method, education institutes have higher cyber risk this time of year, is cyber security being taught correctly, Sequoia PEO data breach, QA error turns ransomware into wiper, and cars' data easily accessed by law enforcement.


    • https://cdcgaming.com/experts-warn-of-further-cyberattacks-on-casinos/
    • https://heimdalsecurity.com/blog/covid-bit-a-new-attack-method-that-can-breach-air-gapped-pcs/
    • https://universitybusiness.com/for-cybercriminals-the-holidays-are-the-most-wonderful-time-of-the-year/
    • https://www.bcs.org/articles-opinion-and-research/is-cyber-security-being-taught-correctly/
    • https://www.wired.com/story/sequoia-hr-data-breach/
    • https://www.bitdefender.com/blog/hotforsecurity/design-flaw-accidentally-turns-open-source-ransomware-toolkit-into-wiper-malware/
    • https://www.forbes.com/sites/thomasbrewster/2022/12/01/10000-cars-can-be-data-raided-by-police-ice-cbp-love-it/

    • 15 min
    • The Virtual CISO Moment Wrap Up for Friday, December 9, 2022

      Why SMBs should prioritize outsourcing cybersecurity, an interesting observation on the IHG cyberattack, log4j persists, the main cause of cybersecurity incidents, and this week's predictions discussed - plus why we made our next position entry level.

      • https://www.standard.co.uk/tech/why-smes-should-prioritise-outsourcing-cyber-security-b1006499.html
      • https://www.cpomagazine.com/cyber-security/it-should-not-take-a-cyberattack-to-force-changes-at-our-biggest-hotel-chains/
      • https://www.tenable.com/press-releases/tenable-research-finds-72-of-organizations-remain-vulnerable-to-nightmare-log4j
      • https://www.digit.fyi/whats-the-main-cause-of-avoidable-cybersecurity-incidents/
      • https://venturebeat.com/security/forrester-analysts-share-5-shocking-cybersecurity-predictions-for-2023/
      • https://www.indeed.com/job/information-security-analyst-i-7f8fce23ece0695f
      • 17 min
      • The Virtual CISO Moment S4E61 - A Conversation with Derek Andrews

        Derek Andrews, Incident Response Manager at a Financial Institution, joins VCM to discuss his journey, incident response in the financial sector, and different types of virtual CISOs from the perspective of one who has worked with both the good and not so good. He also explains why he is the Resident Birdman of LinkedIn!

        24 min
      • VCM Quick Strike for Monday. December 5, 2022

        Chome Zero Day (again), offshore energy vyber threats, Rackspace Exchange hit by "incident", Australia dramatically increases breach penalties, and a ping vuln in FreeBSD - plus a couple of thoughts for entry-level information security analysts.

        • https://cybersecuritynews-com.cdn.ampproject.org/c/s/cybersecuritynews.com/google-chromhe-9th-zero-day-bug/?amp
        • https://www.pipeline-journal.net/news/us-offshore-natural-gas-oil-infrastructure-faces-rising-cybersecurity-threats
        • https://www.securityweek.com/rackspace-shuts-down-hosted-exchange-systems-due-security-incident
        • https://www.bleepingcomputer.com/news/security/australia-will-now-fine-firms-up-to-au50-million-for-data-breaches/
        • https://thehackernews.com/2022/12/critical-ping-vulnerability-allows.html
        • 12 min
        • The Virtual CISO Moment Wrap Up for Friday, December 2, 2022

          LastPass second incident, aged domains, Trigona ransomware, unemployment benefit fraud, ConectWise flaw, attackers target FI customers, and this week's 2023 predictions from SpiceWorks - plus some thoughts  on cyber culture.

          • https://thehackernews.com/2022/12/lastpass-suffers-another-security.html
          • https://www.bleepingcomputer.com/news/security/crafty-threat-actor-uses-aged-domains-to-evade-security-platforms/
          • https://www.techradar.com/news/this-new-ransomware-is-seeing-rapid-growth-so-beware
          • https://www.infosecurity-magazine.com/news/eight-30m-unemployment-benefits/
          • https://krebsonsecurity.com/2022/12/connectwise-quietly-patches-flaw-that-helps-phishers/?
          • https://www.scmagazine.com/news/email-security/attackers-target-vulnerable-financial-customers-rather-than-the-institutions-themselves
          • https://www.spiceworks.com/it-security/cyber-risk-management/interviews/top-cybersecurity-trends-2023/
          • 20 min
          • The Virtual CISO Moment S4E60 - A Conversation with Jacob Horne

            In this month's special end of month Wednesday episode we talk with Jacob Horne, who was born with a rare genetic mutation that allows him to read NIST publications and government regulations without experiencing boredom like a normal person and has made a career out of using this power for good. He does a great job of using NIST SP 800-53 to clarify the bizarre, heavily tailored world of NIST SP 800-171 and CMMC - if you're interested in CMMC you must follow him on LinkedIn! He is also co-host of the Sum It Up podcast which sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

            28 min

          About The Virtual CISO Moment

          From the publisher's feed

          The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.