
Sign up to save your podcasts
Or


Joining us this week is Jonathan Knudsen, Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc. To understand the vulnerability landscape in software, you have to first understand how software is made. Jonathan shares insights on software development and where vulnerabilities (or many, many vulnerabilities) can be integrated in the final product. (Although software is never really, final, is it?) And as we round out March Madness for 2023, he shares some sobering findings from his recent research into sports betting apps and the more than 179 vulnerabilities on average uncovered. We also dive into software composition analysis, the future of security ratings, and the notion of security as an enabler to business. We had so much to talk about we made it a two-part episode!
Jonathan Knudsen, Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc.
Jonathan Knudsen is currently the Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc. In his role, he conducts security and software research, helps people publish their research, and occasionally comments on pressing security topics. His past experiences include being an Adjunct Professor at Duke University for a year. He was also a Principal Security Engineer at Codenomicon for four years, a Principal Technical Writer at Oracle for one year, and a Senior Staff Engineer at Sun Microsystems for nine years.
He enjoys breaking software and teaching others how to make software better. Jonathan is the author of books about 2D graphics, cryptography, mobile application development, Lego robots, and has written more than one hundred articles on a wide range of technical subjects. He lives in Chapel Hill, North Carolina.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e228
Joining us this week is Jonathan Knudsen, Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc. To understand the vulnerability landscape in software, you have to first understand how software is made. Jonathan shares insights on software development and where vulnerabilities (or many, many vulnerabilities) can be integrated in the final product. (Although software is never really, final, is it?) And as we round out March Madness for 2023, he shares some sobering findings from his recent research into sports betting apps and the more than 179 vulnerabilities on average uncovered. We also dive into software composition analysis, the future of security ratings, and the notion of security as an enabler to business. We had so much to talk about we made it a two-part episode!
Jonathan Knudsen, Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc.
Jonathan Knudsen is currently the Head of Global Research for the CyRC, cybersecurity research center, at Synopsys Inc. In his role, he conducts security and software research, helps people publish their research, and occasionally comments on pressing security topics. His past experiences include being an Adjunct Professor at Duke University for a year. He was also a Principal Security Engineer at Codenomicon for four years, a Principal Technical Writer at Oracle for one year, and a Senior Staff Engineer at Sun Microsystems for nine years.
He enjoys breaking software and teaching others how to make software better. Jonathan is the author of books about 2D graphics, cryptography, mobile application development, Lego robots, and has written more than one hundred articles on a wide range of technical subjects. He lives in Chapel Hill, North Carolina.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e227
We're excited to welcome back to the podcast Maria Roat, founder of MA Roat Consulting and former U.S. Deputy Federal Chief Information Officer. For our discussion we double click into the cyber workforce gap and how to attract diverse skillsets to the industry, introducing STEM earlier in education, understanding how to nurture non-traditional learners and the awesome experience veterans bring to supporting the cyber mission. She also shares insights from her decades of experience as an IT leader on the criticality of taking risks, being comfortable with the uncomfortable, and the power of mentors. We had so much to talk about we made this a two-part episode!
Maria Roat, former U.S. Deputy Federal CIO
Maria Roat is currently retired from federal service after more than 40 years in the industry. She started her own consulting firm called MA Roat Consulting LLC, which takes up most of her time. However, she is also on the Board of Directors for On Mission IT, AFCEA Bethesda, and Aquia Inc. She also works closely with VETSports Inc. as a member of the Board of Directors.
Maria Roat served as the Deputy Federal Chief Information Officer for two years after starting the role in May 2020 with over 35 years of professional experience in information technology.
Previously, Ms. Roat served as the Small Business Administration Chief Information Officer October 2016 – May 2020 where she led SBA's digital transformation to a more proactive and innovative enterprise services organization responsive to the business technology needs of SBA program offices and small businesses & entrepreneurs across the United States.
Ms. Roat also served more than two years as the U.S. Department of Transportation Chief Technology Officer and was responsible for establishing and leading DOTs technical vision and strategic direction, driving innovation and planning for technology growth supporting internal and external facing mission activities.
Additionally, she served 10 years at the Department of Homeland Security (DHS) joining in June 2004 and serving in a number of capacities including Federal Risk Management and Authorization Program (FedRAMP) Director, FEMA Deputy CIO, Chief of Staff for the DHS CIO, USCIS Chief Information Security Officer and CIO Chief of Staff, and Deputy Director, Technology Development, for TSA's Secure Flight Program.
Prior to joining DHS in 2004, Ms. Roat was in the private sector for 5 years deploying and managing global enterprise network management systems, as well as running Network and Security Operations Centers.
Ms. Roat is a graduate of the University of Maryland (UMUC), Harvard Business School Executive Education Program for Leadership Development, and the Navy Senior Enlisted Academy.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e226
We are excited to welcome back to the podcast Maria Roat, founder of MA Roat Consulting and former U.S. Deputy Federal Chief Information Officer. For our discussion we double click into the cyber workforce gap and how to attract diverse skillsets to the industry, introducing STEM earlier in education, understanding how to nurture non-traditional learners and the awesome experience veterans bring to supporting the cyber mission. She also shares insights from her decades of experience as an IT leader on the criticality of taking risks, being comfortable with the uncomfortable, and the power of mentors. We had so much to talk about we made this a two-part episode!
Maria Roat, former U.S. Deputy Federal CIO
Maria Roat is currently retired from federal service after more than 40 years in the industry. She started her own consulting firm called MA Roat Consulting LLC, which takes up most of her time. However, she is also on the Board of Directors for On Mission IT, AFCEA Bethesda, and Aquia Inc. She also works closely with VETSports Inc. as a member of the Board of Directors.
Maria Roat served as the Deputy Federal Chief Information Officer for two years after starting the role in May 2020 with over 35 years of professional experience in information technology.
Previously, Ms. Roat served as the Small Business Administration Chief Information Officer October 2016 – May 2020 where she led SBA's digital transformation to a more proactive and innovative enterprise services organization responsive to the business technology needs of SBA program offices and small businesses & entrepreneurs across the United States.
Ms. Roat also served more than two years as the U.S. Department of Transportation Chief Technology Officer and was responsible for establishing and leading DOTs technical vision and strategic direction, driving innovation and planning for technology growth supporting internal and external facing mission activities.
Additionally, she served 10 years at the Department of Homeland Security (DHS) joining in June 2004 and serving in a number of capacities including Federal Risk Management and Authorization Program (FedRAMP) Director, FEMA Deputy CIO, Chief of Staff for the DHS CIO, USCIS Chief Information Security Officer and CIO Chief of Staff, and Deputy Director, Technology Development, for TSA's Secure Flight Program.
Prior to joining DHS in 2004, Ms. Roat was in the private sector for 5 years deploying and managing global enterprise network management systems, as well as running Network and Security Operations Centers.
Ms. Roat is a graduate of the University of Maryland (UMUC), Harvard Business School Executive Education Program for Leadership Development, and the Navy Senior Enlisted Academy.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e225
Joining the podcast this week is Mishi Choudhary, SVP and General Counsel at Virtru. Mishi shares with us some legal perspective on the privacy discussion including freedom of thought, the right to be forgotten, end-to-end encryption for protecting user data, finding a middle ground between meeting customer privacy demands and complying with legal requirements, getting to a federal privacy regulation, and so much more! You won't want to miss what is a truly spirited and candid conversation – in two parts!
Mishi Choudhary
SVP and General Counsel, Virtru
A technology lawyer with over 17 years of legal experience, Mishi has served as a legal representative for many of the world's most prominent free and open source software developers and distributors, including the Free Software Foundation, Cloud Native Computing Foundation, Linux Foundation, Debian, the Apache Software Foundation, and OpenSSL. At Virtru, she leads all legal and compliance activities, builds internal processes to continue to accelerate growth, helps shape Virtru and open source strategy, and activates global business development efforts.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e224
Joining the podcast this week is Mishi Choudhary, SVP and General Counsel at Virtru. Mishi shares with us some legal perspective on the privacy discussion including freedom of thought, the right to be forgotten, end-to-end encryption for protecting user data, finding a middle ground between meeting customer privacy demands and complying with legal requirements, getting to a federal privacy regulation, and so much more! You won't want to miss what is a truly spirited and candid conversation – in two parts!
Mishi Choudhary, SVP and General Counsel, Virtru
A technology lawyer with over 17 years of legal experience, Mishi has served as a legal representative for many of the world's most prominent free and open source software developers and distributors, including the Free Software Foundation, Cloud Native Computing Foundation, Linux Foundation, Debian, the Apache Software Foundation, and OpenSSL. At Virtru, she leads all legal and compliance activities, builds internal processes to continue to accelerate growth, helps shape Virtru and open source strategy, and activates global business development efforts.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e223
Joining us this week is Jennifer Cook, Senior Director of Marketing at the National Cybersecurity Alliance and we discuss all the hot and trending online scams facing consumers today including the growing prevalence of romance scams ($1.3B in losses last year!), job seeker scams, tax fraud scams, sextortion, and the latest scam making the rounds – pig butchering scams. Jennifer shares insights on the many free resources available to consumers – and the awesome work being done by the National Cybersecurity Alliance working with partners and champions around the globe – that raise awareness of what to look for and how to avoid online and mobile scams that take advantage of our day-to-day engagement channels including email, social media and, increasingly, mobile text messages.
Jennifer Cook - Senior Director of Marketing at the National Cybersecurity Alliance
Jennifer Cook is the Senior Director of Marketing at the National Cybersecurity Alliance (NCA). Jennifer leads the development and coordination of NCA's growing suite of campaigns and programs, including Cybersecurity Awareness Month and Data Privacy Week. She joined the National Cyber Security Alliance in 2017 and holds a degree in Marketing from Drexel University.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e222
This week joining the podcast is Anton (Tony) Dahbura, executive director of the Johns Hopkins University Information Security Institute and co-director of the Johns Hopkins Institute of Assured Autonomy. We deep dive into the realm of AI/ML technology and the exponential applications for it across every aspect of our lives. And the criticality of building trust, implications of bias, the realities of planning for "edge cases" that just can't be planned for, and the growing sophistication and personalization of AI-leveraged attacks. He also shares details on the most awesome CyberCorps: Scholarship for Service program. Learn more here: https://isi.jhu.edu/scholarship-service-program/
Executive Director of Johns Hopkins - Information Security Institute and Co-Director of the Johns Hopkins Institute for Assured Autonomy
Anton (Tony) Dahbura is the executive director of the Johns Hopkins University Information Security Institute, co-director of the Johns Hopkins Institute of Assured Autonomy, and an associate research scientist in computer science. His research focuses on security, fault-tolerant computing, distributed systems, and testing.
He received his BSEE, MSEE, and PhD in Electrical Engineering and Computer Science from the Johns Hopkins University in 1981, 1982, and 1984, respectively.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e221
Joining the podcast this week is Brian Hajost, the founder and COO of SteelCloud. Brian shares insights on his concept of a Compliance Bill of Materials (CBOM). For those that have heard of Software Bill of Materials (SBOM) it's a similar concept. In addition to CBOM's, Brian also breaks down the challenges and opportunities in automating compliance as well as well frameworks organizations can leverage to help them achieve compliance. Compliance is a super hot topic for every organization! This is a podcast you don't want to miss!
Brian Hajost, Chief Operating Officer at SteelCloud, LLC
Brian Hajost is the founder and COO of SteelCloud, a company that develops technology for automated compliance for DISA STIGs and the CIS Security Benchmarks. Mr. Hajost has transformed SteelCloud into a recognized leader in delivering new technologies that allow government customers and commercial enterprises to effectively meet the compliance mandates of RMF, NIST 800-53, NIST 800-171, CMMC, and IRS Pub 1075.
Brian's technical career has spanned over thirty years, primarily with leading-edge technologies in regulated industries. He holds 10 patents in IT security and two patents in mobile security. Mr. Hajost is an active contributor to AFCEA International through his membership on the Technology Committee and Secure Supply Chain subcommittee. He is also the Vice Chair of the Advanced Technology Academic Research Center (ATARC) Continuous ATO Working Group.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e220
For this week's episode, Casey Ellis, founder and CTO of Bugcrowd and co-founder of the http://disclose.io project., joins us to explore the risks and rewards of AI technology, including concerns around the notorious Chat GPT chatbot. As the global race to AI supremacy intensifies, Casey shares his thoughts on AI in the workplace, as a cyber defense, and the future of regulation and the ethics around determining AI liability.
Casey is the Chairman, Founder, and Chief Technology Officer of Bugcrowd, as well as the co-founder of The disclose.io Project. He is a 20-year veteran of information security who spent his childhood inventing things and generally getting technology to do things it isn't supposed to do. Casey pioneered the Crowdsourced Security as-a-Service model, launching the first bug bounty programs on the Bugcrowd platform in 2012, and co-founded the disclose.io vulnerability disclosure standardization project in 2014. Since then, he has personally advised the US Department of Defense and Department of Homeland Security/CISA, the Australian and UK intelligence communities, and various US House and Senate legislative cybersecurity initiatives, including preemptive cyberspace protection ahead of the 2020 Presidential Elections. Casey, a native of Sydney, Australia, is based in the San Francisco Bay Area with his wife and two children.
For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e219
From the publisher's feed

227,498 Listeners

1,029 Listeners

10,735 Listeners

318 Listeners

421 Listeners

8,535 Listeners

8,059 Listeners

179 Listeners

314 Listeners

73 Listeners

138 Listeners