WE'RE IN!

WE'RE IN!

Download on the App Store

WE'RE IN! episodes

  • Lifelong Hacker Alyssa Miller Breaks Down Cybersecurity Barriers

    Alyssa Miller, Business Information Security Officer at S&P Global Ratings and author of the forthcoming book, “Cyber Defenders' Career Guide, is one of the most provocative, unfiltered and interesting voices in the cybersecurity community. She’s essential reading on infosec Twitter and a regular draw at conferences around the world. In this episode, she dives into all sorts of issues in the cybersecurity community, from incoherent job postings to a lack of diversity—she covers it all. Tune in to find out how you can best address these problems and also learn how to reach out of your comfort zone and forge your own path to success. 

    --------

    Why you should listen:

    * Figure out why most cybersecurity job postings “suck” and how the industry can help fix the issue.

    * Learn how to address key issues that come up during a cybersecurity job hunt.

    * Identify how to maximize opportunities for personal growth and realize your potential in the infosec community.

    * Understand how to be a better ally to underrepresented groups in the cybersecurity community.

    * Hear about the value of diversity and inclusion in cybersecurity. 

    --------

    Key Quotes:

    * “Read the narrative at the beginning of the job description. If that sounds like something you can do and something you can learn and grow in, apply. The very worst thing they can do is tell you no."

    * "The difference between you experiencing success or not is in how you respond to opportunities. Do you take those moments and go after them or do you let them go by the wayside."

    * “If we want to be better at cybersecurity, having diversity matters.”

    * "You don't get diversity of thought by having 20 heterosexual white males sitting in a room talking about how to build cybersecurity defenses."

    --------

    Related Links:

    * Synack.com

    * https://www.synack.com/lp/cloud-security-solutions/

    *https://twitter.com/AlyssaM_InfoSec?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor

    * https://alyssasec.com/


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    40 min
  • Google Cloud Evangelist Stephanie Wong on “Blameless” Security Culture

    In this episode, Stephanie Wong, head of Google Cloud Developer Engagement, explores Google’s security culture, why it conducts “blameless” postmortems after security testing and how it’s working to dispel lingering misconceptions about the cloud. She also talks about her journey in Silicon Valley and how her experiences winning pageants such as Miss Asian North America 2020 helped her become one of today’s most visible technology content gurus.

     

    Why you should listen:

    * Learn how to build an effective cybersecurity culture within your organization.

    * Get the inside scoop on the security precautions that Google takes with its physical data center.

    * Hear about what Google is doing to overcome misperceptions about cloud security.

    * Figure out how to conduct security postmortems the Google way. 

    * If you don't know about the "pancake principle," you'll find out why it matters, and how it can work for you.

     

    Key Quotes:

    * "It's become really clear that remote work will be a very defining characteristic of the new normal and modernizing security is going to be imperative."

    * "Our teams are really horrified by network-based security because network-based security is hackable, even with two factor authentication."

    * “It's all about empowering [users] so that they can be the ones to flag suspicious activity, websites, and phishing in emails."

    * "Being in Silicon valley, we're often in a bubble where we assume that a lot of people already understand the value of [the cloud] and how it can actually increase your security posture overall."

    * "It's all about blameless postmortems and a blameless culture. No pointing fingers. If something goes wrong, it's all about how can we improve it."

     

    Related Links:

    * Synack.com

    * https://www.synack.com/lp/cloud-security-solutions/

    * https://twitter.com/stephr_wong

     * https://bit.ly/2Vkckh5 (Stephanie’s Youtube Page) 

    * https://www.stephrwong.com/about


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    44 min
  • Cory Doctorow and the Infosec Apocalypse

    Cory Doctorow, activist, journalist, and author who wrote the influential Little Brother cyberpunk series, gets into some big issues like surveillance capitalism and his work with the Electronic Frontier Foundation. He doesn’t hold anything back.

    --------

    Why you should listen:

    * Hear from one of the smartest and most engaged technologists today on how technology can be used both for malicious purposes or for good.

    * Consider how bias can be built into code and have real-world implications. 

    * Listen to Cory’s view on tech monopolies and his proposals for reversing their power over users and the internet more broadly.

    * Better understand why independent security research might seem counterintuitive to many people. 

    * Hear the author of one most influential cyberpunk series discuss the origins of his latest book, Attack Surface.

    --------

    Key Quotes:

    * “Wishful thinking isn’t going to solve real-world technical security issues.”

    * “It’s so important that we build safeguards against our own frailty.”

    * “Tech has become a kind of dangerous monoculture ...technologically dangerous because a breach or a defect in a system has consequences for hundreds of millions, if not billions of users.”

    * “Monopoly is a really bad tool for protecting privacy because monopoly only protects privacy where privacy is in the interests of the monopolist.”

    * "We should hold everyone to account for being good privacy actors by having a privacy law -- a real, no fooling privacy law."

    * "One of the things that we need to take consideration of is that the security apocalypse is here. It's just not evenly distributed."

    --------

    Related Links:

    * Synack.com 

    * https://www.linkedin.com/company/synack-inc-

    * https://twitter.com/synack

    * https://craphound.com/

    * https://pluralistic.net/

    * https://twitter.com/doctorow


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    38 min
  • Nationalize Cloudflare? Berkeley Researcher Nick Merrill on Making it a Public Utility

    In this episode, Nick Merrill, a research fellow at the UC Berkeley Center for Long-Term Cybersecurity, makes a cybersecurity case for nationalizing major CDNs such as Cloudflare, issues some pretty stark warnings about the dangers of machine learning, and digs into why stereotypical images of hackers in hoodies doesn’t help anyone. His viewpoints are sobering if not controversial and worth listening to for anyone who cares about the future of the global internet. 

    ---------

    Why you should listen:

    * Get a fresh perspective on some of the biggest risks to the global web: unchecked algorithmic bias, the risk of attacks on massive CDNs, and the growing internet fragmentation.

    * Consider some of the boldest ideas from one of the sharpest thinkers when it comes to how policymakers can make fundamental changes to protect the internet.

    * Hear Nick’s take on why art matters in cybersecurity -- and why stereotypical images of hackers in hoodies harm the public’s perceptions of information security. 

    * Learn more about Fairness, Accountability and Transparency in Machine Learning and the growing movement to look more critically at the hidden algorithms that control the internet and much of technology today. 

    * Consider how ransomware takedowns and other large-scale cyberattacks such as Colonial Pipeline erode public trust in technology.

    * Get a better understanding of why diversity in the cybersecurity industry matters when it comes to identifying real-world threats.

    ---------

    Key Quotes:

    * “That power over the internet is like a huge strategic asset for the U.S. It's analogous to controlling global trade.”

    * “Imagine a Stuxnet level attack on Cloudflare.”

    * “I would nationalize Cloudflare. I would make it like a national publicly-run utility company.”

    * “This word ‘hacker’ got so diluted. It means different things to different people. And it became this totally useless way for describing what's actually happening in security.” 

    * “The future of cybersecurity … is the future of machine learning.”

    * “The real risk of ransomware is just that it freaks people out.” 


    ---------

    Related Links:

    * Synack.com

    * https://nickmerrill.substack.com/about

    * iSchool (Berkeley) Bio

    * https://www.synack.com/lp/enterprise-security-testing-101

    * https://cltc.berkeley.edu/

    * https://daylight.berkeley.edu/

    * https://www.codedbias.com/

    * https://www.fatml.org/


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    31 min
  • Hacking the Novel: A Journey From Tech Support to Published Author with Ryan Rutan, Senior Director of Community at Synack

    Ryan Rutan has worked in tech support, as a computer repairman, application developer, software engineer, entrepreneur, and head of community…and most recently, fiction writer. Listen to this episode to hear what inspired Fork This Life, a novel that follows the life of a teenager growing up with the early internet of the 90s who eventually gets into hacking, and how it relates to today’s cybersecurity challenges.

    --------

    Why You Should Listen:

    Hear about Ryan’s approach to hacking the fiction writing process.

    * Get the inside story of how working in tech support informed Ryan’s career in cybersecurity. 

    * Nerd out on nostalgia about the nineties tech scene.

    * Pick up tips for developing your creative voice.  

    * Get tips for how you can help spread a culture of good security hygiene. 

    --------

    Key Quotes:

    * “I’m a technical person, therefore I create.” 

    * “I need a computer but why? I want to get online, but why? Everyone knew they needed it and wanted it but they didn’t know why.”

    * “The people who know and understand what it means to keep things secure... It’s incumbent upon them to pay if forward as much as possible.” 

    * “Security back in the 90s.. your death was going to come from a swift sledgehammer to the head...now it’s death by a thousand cuts from a million different websites.” 

    --------

    Related Links:

    * Synack.com

    * https://www.synack.com/lp/enterprise-security-testing-101/

    * Forkthislife.com

    * https://twitter.com/ryanrutan


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    25 min
  • Why Identity Matters in National Security with Lauren Buitta, CEO, Girl Security

    In this episode, Girl Security CEO Lauren Bean Buitta discusses the importance of supporting, encouraging, and training girls for careers in cybersecurity. She gets into why it's so critical to create — and protect — pathways for young women in order to build a more diverse industry, and why that really matters when it comes to making tough national security decisions that affect the entire population. She also describes her journey into security, and what led her to start Girl Security in the first place. 

    ----------

    Why You Should Listen:

    * To better understand the value of gender diversity in cybersecurity.

    * Learn how to create trauma-informed programming that builds trust and understanding.

    * Discover how you can help develop new pathways for underrepresented cybersecurity talent.

    * Hear Lauren’s take on how identity can inform security decisions.

    ----------

    5 Key Quotes:

    * “Everyone’s identity has a place in a discussion about national security because it's the most consequential field in the world.”

    * “What we are seeing in in our country is evidence of how long it takes to uproot any kind of systemic discrimination.”

    * “We are cultivating a generation of girls and women who will hopefully be more well represented in the short, near and long term and we hope that that results in more equitable national security policies of which cyber is so crucial”

    * “Girls and women from childhood live in a world in which they are taught to fear everything … and we do a really good job at keeping ourselves secure.”

    * “We don't know what a national security field would look like where there's gender parody. What would national security look like if women were co-equally represented? I want to see what that world looks like.”

    ----------

    Related Links:

    * Synack.com  

    * https://www.synack.com/were-in-synack-podcast/

    * https://www.girlsecurity.org/about

    * https://www.linkedin.com/in/lauren-bean-buitta/

    * https://www.synack.com/trust-report/

    * https://www.synack.com/lp/enterprise-security-testing-101/


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    39 min
  • From Digital Delinquent to Government Hacker with Author, Entrepreneur, and Cybersecurity Influencer Alissa Knight

    In this episode, author, hacker, entrepreneur, and content creator Alissa Knight reveals her journey from “bullied computer nerd” to federal cybersecurity contractor to famed car hacker. She gets real about the risk of APIs, offers up some must-hear advice for anyone getting into cybersecurity, and delivers candid views about the infosec industry as a whole. 

    -------

    Why you should listen:

    * Get inside the head of one of the most provocative and interesting cybersecurity influencers today.

    * Hear about her work with federal agencies to help secure the future of transportation.

    * Learn more about the urgent need for better Application Programming Interface (API) security.

    * Get new insights into the growing threat to health care organizations and financial institutions.

    * Hear Alissa’s take on how cybersecurity companies can improve their approach to content and marketing.

    -------

    Key Quotes: 

    * “I care more about the adversary that can hack my car from her living room. I care more about the hacker that can take remote control of my car that I'm driving around in my family with, from anywhere.”

    * “Okay. Yes. I can take remote control of this vehicle. I can move the steering wheel. I can push the brakes.”

    * “You would be shocked if I told you how endemic [it is in] the industry to hard-code not only tokens, keys, and credentials like usernames and passwords and to apps for their own APIs, but also third-party APIs like payment processors.”

    * “The plumbing for our entire financial system and healthcare system is APIs...that data is worth more than oil, right? So hackers are shifting their attention to hacking APIs.”

    -------

    Related Links:

    * Alissa Knight’s Twitter: @alissaknight 

    * Knight Ink Media: ​​https://knightinkmedia.com/

    * Alissa Knight’s Website: https://www.alissaknight.com/

    * Official Trailer: Law Enforcement Vehicle Hack: https://www.youtube.com/watch?v=Soj3P3S3i_o

    * Synack Website: Synack.com 

    * Synack Trust Report: https://www.synack.com/trust-report/

    * Jeremiah Roe’s Twitter: ​​@c1ph3rflux

    * Bella DeShantz-Cook’s Twitter: @bellarosedc

    * Black Hat Events: https://go.synack.com/black-hat-events-2021


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    49 min
  • There is No ‘Take Down the Whole US Grid’ with Sarah Freeman and Andy Bochman

    Why you should listen:

    • Hackers are targeting critical infrastructure and there’s an urgent need for smarter cybersecurity defenses to protect Operational Technology. 
    • The best practices to defend against attacks on utilities.
    • Why there is no such thing as “taking down the whole US grid.”

    Five Key Quotes: 

    • “How can you secure what you don’t even know you have? If you don’t even know what you have down to some level of detail...you’re not going to be in a good position to defend it.”  - Andy Bochman 
    • “The most senior person with the word cyber in their title ideally is at least at the VP level.” - Andy Bochman 
    • “You have to not only understand how the attacker can gain access to your network but ultimately gain access to the accounts that are most valuable – where are those crown jewel accounts?” - Sarah Freeman
    • “IT and OT needs to be merged …the problem is cyber is here to stay and everybody needs to take part in this security process.” - Sarah Freeman
    • “The government is most interested in who conducted the attack... The fact that there are two parties here with differing interests is a core issue.” - Sarah Freeman

    Related Links:

    • Countering Cyber Sabotage: Introducing Consequence-Driven, Cyber-Informed Engineering (CCE) 1st Edition
    • https://hbr.org/2018/05/internet-insecurity
    • https://medium.com/cxo-magazine/the-missing-chief-security-officer-11979a54fbf9
    • https://www.synack.com/
    • LinkedIn: 
      • Andy Bochman
      • Sarah Freeman
    • Twitter:
      • @andybochman

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    43 min
  • Trailer

    News about cyberattacks and data breaches is relentless and overwhelming. We're drowning in stories about ransomware and the latest digital threats. But we don't hear enough about the people fighting on the frontlines of information security, the researchers making us more secure and the pioneers doing the hard work to fix today’s cybersecurity crisis. 

    We launched WE’RE IN! to tell those stories. You'll hear directly from hackers, security pioneers and technologists working in the trenches of cybersecurity. They’ll share their strategies, tactics and solutions for today's tough problems. We'll also go inside the cybersecurity community to talk about the issues and challenges in the industry. You'll hear from some of the most prominent, interesting and provocative people in the field about their journeys in this community, and what it’s like on the inside.

    WE'RE IN! is for anyone who cares about cybersecurity. It’s for anyone who wants to go beyond the headlines. It’s for anyone who wants to drive change. We're all facing the cybersecurity dilemma together -- and together we can solve it. Join the conversation on WE'RE IN!


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    2 min

About WE'RE IN!

From the publisher's feed

On WE’RE IN!, you'll hear from the newsmakers and innovators who are making waves and driving the cyber security industry forward. We talk to them about their stories, the future of the industry,…

More shows like WE'RE IN!

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners