To The Point - Cybersecurity

To The Point - Cybersecurity

By Forcepoint | Global Cybersecurity Leader | Security. Simplified.NewsTechnologyTech News
Download on the App Store

To The Point - Cybersecurity episodes

  • Intersecting Investments - Cyber and Democracy with Eric Mill

    Joining the podcast this week is Eric Mill, Senior Advisor on Technology and Cybersecurity to the Federal CIO in the Office of Management and Budget (OMB). We discuss some of the latest and impactful security initiatives, policies and technologies in U.S. Government today – and highlights from some that OMB is helping to drive. We cover topics spanning the Executive Order on Improving the Nation's Cybersecurity, the Technology Modernization Fund, Zero Trust and what it has come to mean today, FIDO and PIV, and so much more!

    Eric also shares an interesting essay that is worth a read, "Reflections on Trusting Trust" by Ken Thompson. Read it here: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf.

    Eric Mill A leader in technology policy and cybersecurity, with a long background in public service. Eric currently serves in the Biden-Harris administration in the Office of Management and Budget as the Senior Advisor on Technology and Cybersecurity to the Federal Chief Information Officer, Clare Martorana.

    Prior to that, Eric was the Lead Product Manager for the security of the Chrome web browser at Google. In 2019, Eric worked for Senator Amy Klobuchar through the TechCongress program, with a focus on election security, vulnerability disclosure, and management of the .gov internet domain.

    Before that, Eric served in the 18F team at the U.S. General Services Administration, where he led the federal government's adoption of strong encryption for its online services. While at GSA, Eric oversaw Login.gov, which lets millions of people sign into U.S. public services securely and privately.

    Prior to 18F, Eric was a part of the Sunlight Foundation, a civil society group dedicated to government transparency. At Sunlight, Eric created open data services that helped the public follow government activity, advised Congress on its open data strategy, and provided expert guidance to anti-corruption NGOs around the world.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e207

    49 min
  • Cyberwar, Social Media's Future and Passing the Mic with Peter W. Singer

    Joining us this week is Peter W. Singer, a New York Times bestselling author of books including Ghost Fleet, LikeWar and the techno-thriller Burn In. He shares details on the New America volunteer, non-profit organization and its awesome #SharetheMicinCyber program helping to bring diversity of thought to the cybersecurity front lines. We also discuss the future of social media, what defines a cyberwar, Ukraine's leverage of social media to garner global support this year, and the great work Useful Fiction is delivering to organizations to address the age old problem of translating complex themes (such as cyber) into compelling business narratives audiences understand and can learn from. And definitely take a few minutes to learn more about Passing the Mic's cybersecurity fellowship program this week. Read more here: https://www.newamerica.org/the-thread/passing-the-mic-introducing-new-americas-cybersecurity-fellowship/

    Peter Warren Singer - A Strategist at New America, a Professor of Practice at Arizona State University, and Founder & Managing Partner at Useful Fiction LLC.

    A New York Times Bestselling author, described in the Wall Street Journal as "the premier futurist in the national-security environment" and "all-around smart guy" in the Washington Post, he has been named by the Smithsonian as one of the nation's 100 leading innovators, by Defense News as one of the 100 most influential people in defense issues, by Foreign Policy to their Top 100 Global Thinkers List, and as an official "Mad Scientist" for the U.S. Army's Training and Doctrine Command. No author, living or dead, has more books on the professional US military reading lists. His non-fiction books include Corporate Warriors: The Rise of the Privatized Military Industry, Children at War, Wired for War: The Robotics Revolution and Conflict in the 21st Century; Cybersecurity and Cyberwar: What Everyone Needs to Know and most recently LikeWar, which explores how social media has changed war and politics. It was named an Amazon and Foreign Affairs book of the year and reviewed by Booklist as "LikeWar should be required reading for everyone living in a democracy and all who aspire to." He is also the co-author of a new type of novel, using the format of a technothriller to communicate nonfiction research. Ghost Fleet: A Novel of the Next World War was both a top summer read and led to briefings everywhere from the White House to the Pentagon. His latest is Burn-In: A Novel of the Real Robotic Revolution. It has been described by the creator of Lost and Watchmen as "A visionary new form of storytelling—a rollercoaster ride of science fiction blended with science fact," and by the head of Army Cyber Command as "I loved Burn-In so much that I've already read it twice."

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e206

    48 min
  • Welcome to the Podcast, Petko! And other security headlines

    This week we officially welcome Petko Stoyanov as the new co-host for the To The Point podcast. Petko shares perspective on how he found his way to cyber, the origin of the name "Petko", and differences in working in government and the private sector. We also discuss the state of cybersecurity landscape and the ongoing challenge of attribution – which is really asking the question, "Who is smarter" in executing cyber attacks. And we dive into the latest headlines on cybersecurity labels for IoT devices which Singapore started actively addressing a few years ago and has partnered with Finland and recently Germany. The US will start embracing security labels in 2023, on a voluntary basis at first, for the most vulnerable IoT devices such as routers and connected home cameras. Big implications here on the future of consumer IoT devices we'll want to continue tracking in the year ahead.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e205

    34 min
  • Embracing SBOMs Can Help Reduce the F-Bombs When Adversaries Exploit OSS Vulnerabilities with Derek Weeks

    We're excited to welcome back Derek Weeks, recognized as the world's foremost researcher on the topic of DevSecOps and securing software supply chains, to the podcast! Derek shares insights on just how little has changed relative to securing software supply chains and using SBOMs in the two years since we last caught up with him. For those new to SBOMs, they are like the nutritional label on a cereal box except for open source software (OSS). We're we're seeing astronomical growth in organizations' use of OSS to the tune of 3+ trillion downloads in 2023. And even with events such as Log4j within the last year, we still haven't had the cataclysmic event to act as a forcing function for more organizations to embrace SBOMs. This has opened the door for the U.S. Government to bring to the table the Securing Open Source Software Act of 2022. Derek also shares perspective on the importance of automation, accountability for supply chain security, investment range for industry to improve the security of code the next two years, and today's realities for those buying cyber insurance.

    Derek Weeks, Cybersecurity Advocate

    Derek E. Weeks is the world's foremost researcher on the topic of DevSecOps and securing software supply chains. For the past seven years, he has championed the research of the annual State of the Software Supply Chain Report and the DevSecOps Community Survey. Derek is also the co-founder of All Day DevOps, an online community of 95,000 IT professionals. In 2018, Derek was recognized by DevOps.com as the "Best DevOps Evangelist" for his work in the community.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e204

    46 min
  • On Digital Privacy and Stopping Stalkerware with Eva Galperin

    Joining the podcast this week is Eva Galperin, Director of Cybersecurity for the Electronic Frontier Foundation (EFF). She is also the co-founder of the Coalition Against Stalkerware and has long been a champion for providing privacy and security for vulnerable populations around the world. "What is stalkerware?" many may ask. Stalkerware is considered a more personal way of invading someone's privacy such as using malware to track a person's activity on a device. Eva shares insights from her many years on the frontlines of digital privacy both educating the broader population on how to protect oneself while also navigating the labyrinth of new regulations and laws being created that impact digital privacy of the future. Be sure to visit StopStalkerware.org to learn more! Eva Galperin is EFF's Director of Cybersecurity

    Prior to 2007, when she came to work for EFF, Eva worked in security and IT in Silicon Valley and earned degrees in Political Science and International Relations from SFSU. Her work is primarily focused on providing privacy and security for vulnerable populations around the world. To that end, she has applied the combination of her political science and technical background to everything from organizing EFF's Tor Relay Challenge, to writing privacy and security training materials (including Surveillance Self Defense and the Digital First Aid Kit), and publishing research on malware in Syria, Vietnam, Lebanon, and Kazakhstan. Since 2018, she has worked on addressing the digital privacy and security needs of survivors or domestic abuse. She is also a co-founder of the Coalition Against Stalkerware.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e203

    50 min
  • Hot Topics! Threat Hunting, CDM and Driving Cyber Innovation with CISA's Richard Grabowski and Jonathan McBride

    Joining us this week are Richard Grabowski, Acting Program Manager for CISA's CDM Program, and Jonathan McBride, Chief of Adversary Pursuit for CISA's Threat Hunting Subdivision. We dive into the hot topics of threat hunting, adversary pursuit, the evolution of CISA over the years including the growth and maturity of the organization, the power of public/private partnerships, and the drive for innovation. They also share perspective on the recent Cyber Executive Order as well as how the CDM program is increasing visibility into the federal cyberattack surface and security posture. We also dig into the continued talent gap challenge and modernizing the approach to talent recruitment (hint: four-year degrees aren't a requirement!). It truly is an exciting time to be in cyber! And, for those interested in a career move it is a VERY exciting time to be at CISA!

    Richard Grabowski is the Acting Program Manager for the Continuous Diagnostics and Mitigation (CDM) at CISA

    As Acting Program Manager for the CDM program, Richard has specific responsibilities for managing portfolios to deliver CDM capabilities to agencies, engineering deployment and architecture-related activities, program support and acquisition, and outreach activities. Through partnerships with agencies and industry, the CDM Program fortifies the cybersecurity of civilian government data and networks by providing capabilities that deliver relevant, timely and actionable information. CDM enables cybersecurity professionals to manage risks by providing innovative tools, processes, governance and training required to defend against cybersecurity threats and vulnerabilities. Prior to Richard's current role, he led the CDM Program's Architecture and Technology Integration Section. He started with CDM in 2014 as a Systems Engineer supporting the CDM Dashboard and Dynamic and Evolving Federal Enterprise Network Defense (DEFEND; formerly Task Order [TO2]) Group C agencies. Previous to this, Richard spent over nine years providing client/server and virtualization integration services to the Federal government. Richard holds a B.S. in Systems and Information Engineering from the University of Virginia and a M.S. in Systems Engineering from The George Washington University.

    Jonathan McBride Chief of Adversary Pursuit, CISA's Threat Hunting subdivision

    McBride oversees CISA's federal persistent hunt mission and services, driving innovation in service delivery, sensing solutions, detection, and advanced analytics. He previously served as an engagement lead within the Host Forensics Section of CISA's Threat Hunting Subdivision, leading rapid response personnel on incident response activities supporting the federal government, states, local tribes, territories, and critical infrastructure. Mr. McBride has reached this point in his career by a non-traditional path. A third-generation US Army veteran where he served the special operations community as a military intelligence specialist. Completing multiple deployments to Iraq, Afghanistan, and Africa focused on counter-terrorism and counter-insurgency operations. Upon leaving the US Army he transitioned into the cybersecurity workforce as a computer network defense (CND) intrusion analyst and quickly excelled. Highlights include CND Operations lead for the Missile Defense Agency's Ground-Based Midcourse Defense Intercontinental Ballistic Missile system and senior Fusion Analyst for Defense Information Systems Agency – Europe supporting the Department of Defense's European and Africa Combatant Commands, Information Assurance Branch Chief for the Executive Office of the President – Office of Administration, and Incident Response Manager for the Federal Communications Commission. He is an avid outdoorsman and dabbles in ultramarathon running.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e202

    56 min
  • ModSecurity and the Impending Swiss Cyber Storm with Christian Folini

    Joining us this week is Christian Folini (@chrfolini), co-lead of the OWASP Core Rule Set project, co-author of the second edition ModSecurity Handbook and one of the few teachers on this subject. And he brings a first to the podcast – a discussion on ModSecurity and the OWASP project! For those that are new to these topics, Christian shares many insights on the OWASP volunteer organization mission and how it serves as the first line of defense against web application attacks. Many may not know that 70% of attacks are carried out at the web application level. He also shares perspective on the end-of-life support for the Trustwave ModSecurity Engine and what that means for the open-source community, along with details of the upcoming Swiss Cyber Storm event in October of which he is a program chair. It's going to be an awesome event you won't want to miss! Learn more here: https://www.swisscyberstorm.com/

    Christian Folini, Author of the ModSecurity Handbook 2ed. OWASP Core Rule Set project co-lead and program chair Swiss Cyber Storm.

    Christian Folini brings more than ten years of experience with ModSecurity configuration in high security environments, DDoS defense and threat modeling. Christian is the author of the second edition of the ModSecurity Handbook and one of the few teachers on this subject. He is a Co-Lead of the OWASP ModSecurity Core Rule Set project. Christian serves as vice president of the Swiss federal public-private-partnership "Swiss Cyber Experts" and as the program chair of the "Swiss Cyber Storm" conference. He is also a frequent speaker at national and international conferences, where he tries to use his background in the humanities to explain hardcore technical topics to various audiences.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e201

    50 min
  • Game On! Insider Risk vs Security Culture with Dr. Maria Bada

    Closing out Insider Threat Awareness Month with us is Maria Bada, Ph.D, a Lecturer in Cyberpsychology at Queen Mary University in London and a RISCS Fellow in cybercrime. Maria shares insights on the insider threat challenge through a human-centric lens and the criticality of educational awareness, transparency and training (note: check out AwareGo!) to better mitigate the threat. When 98% of organizations are vulnerable to insider threat, and the "accidental" insider is the one most often reported, empowering employees with tools and knowledge to understand and be aware of the threats can really make a positive impact. We also discuss the myriad profiles of functional insiders, promoting a culture of security impact, the power of positive vs punitive training (think fake phishing campaigns executed by internal security teams) and how we should start thinking about and addressing the growing social engineering threat.

    Maria Bada, Ph.D

    A Lecturer in Cyberpsychology at Queen Mary University in London and a RISCS Fellow in cybercrime. Her focus is the human aspect of cybercrime and cybersecurity. She is also a cyber expert at AwareGo.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e200

    50 min
  • Talking Insider Threat Awareness with Bill Evanina

    Bill Evanina, Founder and CEO of the Evanina Group and former Director of the National Counterintelligence and Security Center Office of the Director of National Intelligence, joins the podcast this week to take a deep dive view into insider threat as September is Insider Threat Awareness Month. He shares insights from his many years on the counterintelligence and security front lines on what defines insider threat (Note: harm to self or others), the opportunities and challenges in available tools, information sharing and detection across organizations, the importance of leadership training and cross functional partnership to help mitigate insider threats and the criticality of sharing success stories (these really make a difference!).

    **************************************************************** Founder and CEO of the Evanina Group advising CEOs and Board of Directors on strategic corporate risk, strategy, insider threats, cyber security, geopolitical risk, intelligence centers, etc.

    Instructor, University of Chicago, Graham School.

    Former Director of the National Counterintelligence and Security Center Office of the Director of National Intelligence responsible for leading and supporting the counterintelligence and security activities of the US Intelligence Community, the U.S. Government, and U.S. private sector entities at risk from intelligence collection or attack by foreign adversaries.

    Served as Chair of the NATO Counterintelligence Panel and the National Counterintelligence Policy Board, and the Allied Security and Counterintelligence Forum comprised of senior counterintelligence and security leaders from Australia, Canada, New Zealand, and the UK.

    Previously served as the Chief of the Central Intelligence Agency's Counterespionage Group, as Assistant Special Agent in Charge of the FBI's Washington Field Office and spent 24 years as a Special Agent with the Federal Bureau of Investigation (FBI).

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e199

    52 min
  • The Complexities of the Taiwan-China Conflict with Ellen Nakashima

    Joining the podcast this week is Ellen Nakashima, National Security Reporter for The Washington Times, and shares insights into the ongoing conflict between China and Taiwan. Ellen provides perspective on the much publicized Pelosi trip to Taiwan and why the timing of that trip raised concerns in China as well as the complicated relationships the two countries have with international governments around the world, complex supply chain interdependencies (particularly in semiconductors), cyberattack impacts (or not) and why this conflict is different from Russia and Ukraine. This is truly a riveting and insightful conversation that you won't want to miss.

    Ellen Nakashima, National Security Reporter, The Washington Post

    Ellen Nakashima is a national security reporter for The Washington Post. She covers cybersecurity counterterrorism and intelligence issues. She has probed Russia's efforts to influence the outcome of the 2016 presidential election and contacts between aides to President Trump and Russian officials, work which led her and her colleagues to win a Pulitzer Prize in 2018. She was part of another team awarded the Pulitzer Prize for Public Service in 2014 for reporting on the hidden scope of government surveillance and its policy implications. Nakashima has also served as a Southeast Asia correspondent and covered the White House and Virginia state politics. She joined The Post in 1995.

    For links and resources discussed in this episode, please visit our show notes at https://www.forcepoint.com/govpodcast/e198

    43 min

About To The Point - Cybersecurity

From the publisher's feed

Stay ahead in the dynamic world of cybersecurity with "To the Point Cybersecurity." This podcast offers in-depth discussions on the latest cyber threats, trends, and technologies impacting businesses, governments, and communities globally.

More shows like To The Point - Cybersecurity

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,498 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

48 Hours by 48 Hours

48 Hours

10,735 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,535 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners