The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • The Virtual CISO Moment S4E57 - A Discussion About Cybersecurity Consulting

    I've started a limited YouTube series on lessons I've learned from being a successful consulting business owner. It's not all sunshine and roses, and I've made a lot of mistakes, but I've learned from them. Here are the first two episodes - Consulting: Introduction and Consulting: Risk Assessment. If you find these interesting and useful, please subscribe to the vCISO Services, LLC YouTube channel (link below) to be notified when future episodes drop (episodes drop roughly weekly, and episode three will drop the week of November 14th).

    https://youtube.com/@vciso

    24 min
  • VCM Quick Strike for Monday, November 14, 2022

    KmsdBot, email server extortion, Fed requirements and ITAM, CMMC advice, ways data can be exposed, and a primer on pen testing - plus thoughts on when pen tests aren't exactly pen tests (and the SMB loses out).

    • https://thehackernews.com/2022/11/new-kmsdbot-malware-hijacking-systems.html
    • https://www.infosecurity-magazine.com/news/mass-email-extortion-claims-server/
    • https://itassetmanagement.net/2022/11/07/us-federal-cybersecurity-requirements-raise-itam-for-all/
    • https://washingtontechnology.com/companies/2022/11/cmmcs-father-warns-companies-not-wait-final-rule/379617/
    • https://www.csoonline.com/article/3675542/8-strange-ways-employees-can-accidently-expose-data.html
    • https://www.intruder.io/blog/what-is-an-external-pentest
    • 20 min
    • The Virtual CISO Moment Wrap Up for Friday, November 11, 2022

      Why phishing emails have typos, repeat ransomware demands, SMS used in banking attack, CISOs making job changes, Twitter CISO and CPO resign, plus some thoughts on the Twitter infosec exodus.

      • https://securityboulevard.com/2022/11/why-do-phishing-emails-have-such-obvious-typos/
      • https://www.insurancejournal.com/news/national/2022/11/09/694534.htm
      • https://thehackernews.com/2022/11/warning-this-widespread-malicious.html
      • https://www.zdnet.com/google-amp/article/cybersecurity-leaders-want-to-quit-heres-what-is-pushing-them-to-leave/
      • https://www.cnn.com/2022/11/10/tech/twitter-executives-resign/index.html
      • 15 min
      • Throwback Thursday for November 10, 2022 - A Conversation with Anthony Scarola

        From July 26, 2022 - Anthony Scarola is an IT Governance, Risk, and Compliance (GRC) expert; has many years in cybersecurity; is a U.S. Army veteran; holds the CISSP; and is a virtual CISO. And he's writing a security book! Listen to his wisdom as it pertains to risk management and learn one mistake many may make when discussing risk with the c suite and board of directors.

        23 min
      • VCM Quick Strike for Monday, November 7, 2022

        National Guard to assist with election cyber security, supply chain stops train, predictions for 2023, MFA fatigue explored, and CEO sanctioned in breach, plus thoughts on the C-Suite and Board of Directors responsibility.

        • https://www.politico.com/news/2022/11/04/nationa-guard-midterm-election-cybersecurity-00065236
        • https://www.securityweek.com/cyberattack-causes-trains-stop-denmark
        • https://www.proofpoint.com/us/blog/ciso-perspectives/cybersecurity-predictions-for-2023
        • https://www.theregister.com/AMP/2022/11/03/mfa_fatigue_enterprise_threat/
        • https://therecord.media/ftc-seeks-action-against-drizly-and-its-ceo-for-cybersecurity-failures/
        • 16 min
        • The Virtual CISO Moment Wrap Up for Friday, November 4, 2022

          2022 cybersecurity threat landscape report, election cybersecurity concerns, arrest in dark web market, five cybersecurity mistakes for businesses, and a primer on threat hunting - plus thoughts on career planning and management.

          • https://www.enisa.europa.eu/news/volatile-geopolitics-shake-the-trends-of-the-2022-cybersecurity-threat-landscape
          • https://www.helpnetsecurity.com/2022/10/31/election-cybersecurity/
          • https://www.bleepingcomputer.com/news/security/student-arrested-for-running-one-of-germany-s-largest-dark-web-markets/
          • https://venturebeat.com/security/5-cybersecurity-mistakes-that-will-haunt-you/
          • https://securityboulevard.com/2022/11/the-no-nonsense-benefits-of-threat-hunting/

          • 15 min
          • Throwback Thursday for November 3, 2022 - A Conversation with J.J. Powell

            From July 19, 2022 - J.J. Powell of Cyber Defense Group (https://www.cdg.io/) discusses his career journey from police officer to system administrator to CISO and now as leading virtual CISO services. He is also a pivotal component into my decision to leave corporate and become an independent vCISO - listen to find out what was "the straw that broke the camel's back" for me!

            25 min
          • VCMS4E54 - The RETR3AT Sessions - A Conversation with Dan Bradley

            Dan Bradley, CIPP/E, CIPP/US, CIPM, is the Senior Associate General Counsel at Global Payments, Inc. and a former Federal Prosecutor. We discuss privacy regulations both for financial institutions and SMBs, including the importance of frameworks. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

            16 min

          About The Virtual CISO Moment

          From the publisher's feed

          The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.