The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • The Virtual CISO Moment S4E49 - A Conversation with Keith Maune

    Keith Maune, Founder & COO at Acumen Technology, discusses his IT and cybersecurity path, from doing consulting work for companies needing website design and programming services, working after school and full-time during the summers, pursuing a BS and MBA while working full-time as co-owner and CIO of Advanced Network Solutions, earning a law degree, and launching Acumen Technology, a comprehensive managed services organization that serves Middle Tennessee as the premier IT services provider for community banks, healthcare providers, and professional services organizations.

    24 min
  • VCM Quick Strike for Monday, October 17, 2022

    AMLBot cleans house, Windows Zero Day details, White and Black Hat, Magnibar ransomware, and SMBs feeling financial pain from county system attack.

    • https://krebsonsecurity.com/2022/10/anti-money-laundering-service-amlbot-cleans-house/
    • https://www.hackademicus.nl/experts-disclose-technical-details-of-now-patched-cve-2022-37969-windows-zero-day/
    • https://www.bestcolleges.com/bootcamps/guides/white-hat-black-hat/
    • https://www.infosecurity-magazine.com/news/magniber-ransomware-adopts/
    • https://bronx.news12.com/county-vendors-feeling-the-pinch-of-suffolk-computer-systems-hack
    • 11 min
    • From The Vault - Information Security Theater

      From January 1, 2020 Information security theater, improvements that look and sound good but make no real impact to overall security stance of an organization, can do more harm than good. Are you understanding the information security risks of your organization before designing and implementing controls?

      8 min
    • The Virtual CISO Moment Wrap Up for Friday, October 14, 2022

      Update on Optus, why ji32k7au4a83 is a common password, Russia's version of GitHub, Lockbit used in attack, Malwarebytes new MDR, White House unveils IoT labeling initiative, and a new CMMC-focused podcast - plus a few thoughts on podcasts in general.

      • https://www.cisc.gov.au/news-media/archive/article?itemId=955
      • https://www.gizmodo.com.au/2022/10/why-ji32k7au4a83-is-a-remarkably-common-password/
      • https://cybernews.com/news/russias-version-of-github/
      • https://www.theregister.com/2022/10/14/nhs_software_hosting_provider_advanced_ransomware_lockbit/
      • https://www.securityweek.com/malwarebytes-launches-mdr-solution-smbs
      • https://www.cyberscoop.com/white-house-to-unveil-internet-of-things-labeling/
      • https://www.youtube.com/watch?v=VjmXH7b5kJU&ab_channel=Summit7Systems
      • 15 min
      • The Virtual CISO Moment S4E47 - A Conversation with David Leech

        David Leech is a vCISO using his global, operational, program management, and security experience together with leadership skills to drive digital transformation, product innovation, and risk reduction for business growth, involving work across Risk Management, Technical Architecture, Control Frame Works, HIPAA, FFIEC, PCI, HITRUST, FedRamp, and SOC compliance. He has supported clients in multiple sectors, including Finance, Manufacturing, Insurance, Healthcare and GovEd.

        27 min
      • VCM Quick Strike for Monday, October 10, 2022

        Uber trial a lost opportunity to promote cyber governance, hacked IP scanning tool, leak of Alder Lake BIOS, LilithBot Malware as a Service, and healthcare provider IT incident likely malware - plus thoughts on the importance of business continuity table top exercises.

        • https://www.forbes.com/sites/jodywestby/2022/10/08/uber-trial-a-lost-opportunity-for-cyber-governance/amp/
        • https://www.scmagazine.com/analysis/network-security/backdoored-version-of-popular-network-admin-tool-hits-80-organizations-around-the-globe
        • https://thehackernews.com/2022/10/intel-confirms-leak-of-alder-lake-bios.html
        • https://www.theregister.com/2022/10/10/eternity_lilithbot_malware_bundle/
        • https://www.healthcaredive.com/news/commonspirits-it-security-incident-likely-cyberattack-security-expe/633509/
        • 12 min
        • The Virtual CISO Moment Wrap Up for Friday, October 7, 2022

          Threat actors may influence US midterm elections, DIB org attached with APT, an interesting approach to password expiration policies, an updated primer and review on cyber insurance, and Uber's CISO convicted on two counts related to breach actions - plus more thoughts on ethics.

          • https://www.ic3.gov/Media/PDF/Y2022/PSA221006.pdf
          • https://www.bleepingcomputer.com/news/security/hackers-stole-data-from-us-defense-org-using-impacket-covalentstealer/amp/
          • https://www.helpnetsecurity.com/2022/10/04/mandatory-password-expiration-helping-or-hurting-password-security/
          • https://www.csoonline.com/article/3643054/cyber-insurance-explained.amp.html
          • https://thehackernews.com/2022/10/former-uber-security-chief-found-guilty.html
          • https://www.justice.gov/usao-ndca/press-release/file/1306781/download

          • 13 min
          • Throwback Thursday for October 6, 2022 - A Conversation with Nick Santora

            From June 21, 2022 - Nick Santora, CEO of Curricula (curricula.com), discusses information security awareness and how Curricula uses storytelling to make both short term and long term impressions, resulting in increased security across the organization. He also discusses his path to entrepreneur, challenges in the SMB infosec awareness space, and "wisdom walks"!

            23 min

          About The Virtual CISO Moment

          From the publisher's feed

          The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.