PLAY PODCASTS
Adopting Zero Trust

Adopting Zero Trust

Adopting Zero Trust

58 episodesEN

Show overview

Adopting Zero Trust has been publishing since 2022, and across the 4 years since has built a catalogue of 58 episodes, alongside 2 trailers or bonus episodes. That works out to roughly 45 hours of audio in total. Releases follow a monthly cadence, with the show now in its 5th season.

Episodes typically run thirty-five to sixty minutes — most land between 42 min and 54 min — and the run-time is fairly consistent across the catalogue. Roughly 48% of episodes carry an explicit flag from the publisher. It is catalogued as a EN-language Technology show.

There hasn’t been a new episode in the last ninety days; the most recent episode landed 5 months ago. The busiest year was 2023, with 19 episodes published.

Episodes
58
Running
2022–2026 · 4y
Median length
48 min
Cadence
Monthly

From the publisher

Adopting Zero Trust offers an ongoing conversation that elevates cybersecurity conversations that encourages you to rethink how you build strategies, defend against threat actors, and implement new technology. We go beyond the millions in marketing budgets fueled by VCs, and chat with practitioners like you who want to make a difference (or hack the planet, which ever happens first). Hosted on Acast. See acast.com/privacy for more information.

Latest Episodes

View all 58 episodes

S5 Ep 1The Security Debt We Pretend Isn’t There

As organizations push return-to-office (RTO) mandates and chase efficiency, many security teams are quietly accumulating debt they don’t know how to unwind.In this episode, we are joined by Lea Cure Thorpe and Kayne McGladrey to unpack the less-discussed consequences of recent security decisions: RTO exposure, endpoint blind spots, tooling overload, analyst burnout, and the slow erosion of junior talent (thanks AI).Rather than going too crazy on hot takes and obvious trends, we focus in on operational reality, business risk, and what security leaders need to confront before these issues compound further.Where to Skim02:00 | Is the perimeter really dead?06:30 | RTO fallout and the return of local network risk12:30 | Endpoint sprawl, dirty devices, and SOC fatigue18:30 | Cloud tooling, visibility gaps, and false assurances26:00 | AI adoption: risk appetite vs. reality33:30 | Identity, agentic AI, and trust amplification risk41:00 | Workforce erosion and the efficiency trap50:30 | The business math CISOs can’t avoid58:30 | Career development, communication, and relevance Hosted on Acast. See acast.com/privacy for more information.

Jan 29, 202650 min

S4 Ep 6Whisper Leak: How Encrypted AI Chats Still Leak Conversation Topics

In this episode, we break down Whisper Leak, a newly disclosed side-channel issue affecting encrypted LLM communications. JBO explains how attackers can infer conversation topics using packet size and timing metadata without breaking encryption. The discussion covers how the research team discovered the issue, how vendors (including Microsoft and OpenAI) mitigated it, and what it means for the future of secure AI systems.01:30 – What Whisper Leak Actually Is02:30 – Understanding Side-Channel Attacks04:00 – Why LLMs Are Uniquely Vulnerable08:00 – Stream Ciphers vs Block Ciphers13:30 – “Did You Break Encryption?” Clearing Up Misconceptions16:00 – Fixes & Mitigations Across LLM Vendors18:30 – Why Some Vendors Were More Vulnerable Than Others20:00 – Could High-End Adversaries Still Pull This Off?24:00 – How API Users Can Protect Themselves25:00 – Designing LLM Systems with Side Channels in MindGuests: Jonathan (JBO) Bar Or, Principal Security Researcher, Microsoft Threat Intelligence, who just joined CrowdStrikeHosts: Elliot Volkman & Neal Dennis Hosted on Acast. See acast.com/privacy for more information.

Dec 11, 202531 min

S4 Ep 5How Critical Infrastructure Leaders Are Rethinking Cybersecurity

In this episode of Adopting Zero Trust, hosts Elliot Volkman and Neal Dennis discuss critical infrastructure security with expert guest Ian Branson, Vice President of Global Industrial Cybersecurity at Black and Veatch.The discussion centers around the philosophical and strategic approaches to handling incidents and breaches, especially in the operational technology (OT) realm. Branson highlights the importance of understanding what needs protection, the integration of IT and OT security, and the crucial role of threat intelligence. They also explore the evolving need for converging physical and digital security data to manage risks effectively. 01:37 Starting Point for Protecting Critical Infrastructure04:52 Funding and Resource Allocation for Cybersecurity10:57 Threat Intelligence and Incident Response16:25 IT and OT Convergence23:47 Discussing Employee and Equipment Management26:19 Integrating Physical and Cyber Security34:39 Proactive Security Measures in New Constructions40:46 Balancing Rapid Response and Availability Hosted on Acast. See acast.com/privacy for more information.

Apr 17, 202544 min

S4 Ep 4Shadows Within Shadows: How AI is Challenging IT Teams

In this episode of Adoption Zero Trust (AZT), host Neal Dennis and producer Elliot Volkman sit down with Bradon Rogers, Chief Customer Officer at Island, to discuss how AI is compounding the already existing problems tied to shadow IT. The conversation explores how modern enterprises handle the growing complexities of unregulated software use, the role of enterprise browsers in mitigating risks, and the dynamic between user experience and cybersecurity.01:16 Shadows within shadows04:15 AI in Approved Solutions09:14 Enterprise Browser and Security14:25 Transition to Browser-Based Applications16:23 Enterprise Browser Capabilities18:45 Data Protection and Shadow IT24:39 Shepherding Data in the Enterprise Browser25:17 Policy Perspectives on AI and Data Flow28:16 Exploring SBOM and AI Integration35:39 Browser Security and Application Boundaries41:40 BYOD and Privacy Concerns44:48 Third-Party Scenarios and Onboarding Hosted on Acast. See acast.com/privacy for more information.

Mar 20, 202548 min

S4 Ep 3Live at ZTW2025: Cyberwire Daily’s Dave Bittner + Dr. Zero Trust

Catch this episode on YouTube, Apple, Spotify, or Amazon. You can read the show notes here.Live from ThreatLocker’s Zero Trust World (ZTW), cybersecurity heavyweights Dave Bittner, host of CyberWire Daily and Dr. Chase Cunningham AKA Dr. Zero Trust shared their unfiltered thoughts on the state of cybersecurity, AI, and government regulations. From the shifting landscape of compliance enforcement to the role of hitting critical mass of AI in both defense and cybercrime, we can expect an extraordinary level of change in the years ahead.01:37 Cybersecurity Landscape Overview01:58 Government and Cybersecurity02:39 Leadership and Appointments in Cybersecurity03:47 Future of CISA and Compliance06:41 Managing Cybersecurity News14:54 The Role of LLMs in Cybersecurity16:22 Global Perspective on AI and LLMs18:47 Reflecting on Past Technological Predictions20:18 The Double-Edged Sword of AI and Surveillance24:21 The Dark Side of Technological Advancements26:17 Debating the Term 'AI' and Its Implications28:43 Historical Anecdotes and Unanswered Questions Hosted on Acast. See acast.com/privacy for more information.

Mar 6, 202532 min

Ep 25Rapid fire update: Silk Typhoon and DOJ's indictment of twelve Chinese nationals

New intelligence: Silk Typhoon, formerly tracked as HAFNIUM, is a China-based threat actor most recently observed targeting IT supply chains in the US. Today, we released a new report in conjunction with the Department of Justice's action against twelve Chinese nationals that includes mercenary hackers, law enforcement officers, and employees of a private hacking company. This group has been charged in connection with global cyberespionage campaigns. Dive into our latest blog for all the details. Hosted on Acast. See acast.com/privacy for more information.

Mar 5, 20253 min

S4 Ep 2Predicting the year of cybersecurity ahead (minus regulations)

It’s mid-February, but somehow, we’ve already been through what feels like a year's worth of change in the cybersecurity and regulation world. Beyond the standard incidents, outages, and attacks… there have been obvious impacts that have downstream effects. Regardless of regulatory changes, which we’ll cover as those impact our space, AZT brought together a few minds who have thoughts on the year ahead.To properly kick off season four, we have the privilege of chatting with two wonderful guests:Lawrence Pingree, VP of Technical Marketing at Dispersive, but you are more likely to know his name from his time at Gartner. However, he has a varied background ranging from CTO to security engineer, so don’t let that marketing line in his title fool you.Oliver Plante, VP of Support at ThreatLocker, has around 15-20 years of IT under his belt. He also has seen a thing or two when it comes to implementing new cybersecurity strategies 03:21 Predictions for the Year Ahead04:06 Zero Trust and Least Privilege05:40 The Future of Cyber Defense07:21 AI and Cybersecurity08:41 Threat Intelligence and Preemptive Defense09:50 Challenges and Innovations in Cybersecurity14:23 The Role of AI in Cyber Attacks26:18 Quantum Computing: Threat or Savior?29:31 Passwordless Security: The Future30:57 Challenges of Deepfake Technology and Passwordless Security33:03 Blockchain and Its Applications in Security35:33 Debate on Password Management Practices38:03 User Responsibility and Security Automation47:50 Government's Role in Cybersecurity57:14 Future of Cybersecurity and Zero Trust Hosted on Acast. See acast.com/privacy for more information.

Feb 18, 20251h 2m

S4 Ep 1Kicking Off Season 4 of Adoption Zero Trust (AZT)

Catch this episode on YouTube, Apple, Spotify, or Amazon. You can read the show notes here.Neal and I are excited to welcome you back to AZT as we kick off our fourth season. After four years of trying out different formats and episodes, including at least an entire season terrorizing vendors for slapping Zero Trust on their box as if it were something you could buy, we’re ready to narrow our focus a bit. Hosted on Acast. See acast.com/privacy for more information.

Feb 11, 202522 min

Ep 24The key to growing a cybersecurity career are soft skills

In this episode of 'Adopting Zero Trust (AZT)', host Neal Dennis and producer Elliot Volkman delve into the often-overlooked realm of soft or 'non-tech' skills in cybersecurity.This week, we chat with Courtney Hans, VP of Cyber Services at AmTrust Financial Services, and Evgeniy Kharam, author of Architecting Success: The Art of Soft Skills, who help us explore how non-technical skills are vital in shaping the careers of cybersecurity professionals.Our guests share the importance of effective communication, emotional intelligence, and adaptability. The hosts and guests share personal anecdotes, training tips, and the necessity of bridging technical prowess with essential soft skills to improve stakeholder engagement and career advancement. The episode emphasizes the value of being comfortable with discomfort and soliciting feedback to enhance one’s professional journey in cybersecurity. Hosted on Acast. See acast.com/privacy for more information.

Dec 19, 202450 min

S3 Ep 15Behind the scenes of cybersecurity media and reporting

Season 3, Episode 15: We gather a panel of journalists, communications, and a researcher to discuss how cybersecurity news and incidents are reported.You can read the show notes here.In the world of cybersecurity journalism, you can broadly divide it into four competing forces: reporters, communications teams, researchers, and readers. Each requires the other to accomplish its goals, but they all have very different priorities and goals.Journalists have a duty to inform the public about security-related events.Communication teams have a duty to inform the public about related incidents and research, but in a controlled setting.Researchers help provide answers to communication teams and journalists.Readers want to be informed of information that impact them, and their habits shape what kind of reporting is invested in the most.This week we explore some of these dynamics by bringing together a panel representing comms, journalism, and research to discuss the game of tug-of-war during incident response and incident reporting.Danny Palmer was a long-standing cybersecurity reporter at ZDNet prior to recently joining DarkTrace, Josh Swarz is the Senior Communications Manager at Microsoft focusing on threat intelligence, our host Neal Dennis is former NSA and has lived many lives around either keeping secrets or uncovering them, and producer Elliot Volkman has been a reporter for two decades and works with Josh on elevating research at Microsoft Threat Intelligence. Hosted on Acast. See acast.com/privacy for more information.

Nov 21, 20241h 4m

Ep 23GRC tool or spreadsheets, that is the question | GRC Uncensored Preview

In our final preview episode of GRC Uncensored, we explore a particularly bipolar debate: do you need a GRC tool to manage compliance, or will spreadsheets suffice?After this, we will be back to our regularly produced AZT episodes. The last episodes of our pilot for GRC Uncensored can be found on your favorite podcast app or newsletter on Substack. Hosted on Acast. See acast.com/privacy for more information.

Oct 24, 202443 min

Ep 22Podcast Preview: GRC Uncensored and the commoditization of compliance

bonus

We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.-----In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.00:00 Welcome to GRC Uncensored01:34 Introducing Kendra Cooley02:05 Love-Hate Relationship with GRC03:16 The SOC 2 Debate04:33 Challenges with SOC 2 Audits09:10 The Value of SOC 2 in the Industry12:04 The Evolution of Compliance Frameworks20:39 False Sense of Security in Compliance24:46 The Buzz Around AI and Quantum25:10 Staying Updated as a Security Professional26:45 Challenges in Penetration Testing and Vendor Assessments27:37 Compliance and Its Impact on Security30:10 Government Regulations and Their Effectiveness32:23 The Complexity of Privacy Laws38:29 The Role of GRC Teams in Risk Management42:30 Concluding Thoughts and Future Episodes Hosted on Acast. See acast.com/privacy for more information.

Oct 10, 202441 min

S3 Ep 14How to prepare your operations team for Zero Trust

Welcome back to Adopting Zero Trust! In this episode, hosts Elliot Volkman and Neal Dennis are joined by Rob Allen, Chief Product Officer of ThreatLocker, to dive deep into the operationalization of Zero Trust. Despite covering various aspects over three seasons, this crucial topic is addressed thoroughly.They explore pre-adoption preparation, aligning organizational actions, and the importance of education in security. Additionally, the conversation highlights the 'assume breach' perspective and how concepts like default deny and least privilege are essential. With real-world examples and anecdotes, they provide actionable insights on implementing Zero Trust strategies effectively. Tune in to learn about the foundational steps necessary to transition into a Zero Trust environment.This is the first of a three-part mini-series, so stay tuned as we explore more aspects of how to prepare your organization for adopting a Zero Trust strategy. Hosted on Acast. See acast.com/privacy for more information.

Sep 26, 202446 min

S3 Ep 13Log4j Continues to act as Organizational Vulnerability

Season 3, Episode 13: Cato Network’s Etay Maor provides fresh research on the abuse of unpatched log4j libraries.Catch this episode on YouTube, Apple, Spotify, or Amazon. You can read the show notes here.This week on Adopting Zero Trust (AZT), we highlight a significant cybersecurity risk focused on the notorious Log4j vulnerability and the growing concern around shadow IT. Featuring expert insights from Etay Maor, the Chief Cybersecurity Strategist at Cato Networks, the conversation initially looks into the persistent exploitation methods, the importance of knowing one’s cybersecurity environment, and strategic approaches to mitigating risks. Hosted on Acast. See acast.com/privacy for more information.

Sep 5, 202447 min

S3 Ep 6Overturning of Chevron Deference’s Impact on Cybersecurity Regulation

Season 3, Episode 12: Could the overturning of Chevron Deference impact cybersecurity and privacy regulations?Catch this episode on YouTube, Apple, Spotify, or Amazon. You can read the show notes here.Welcome back to Adopting Zero Trust or AZT. In our latest episode, we assembled a distinguished panel to dig into a timely topic affecting the cybersecurity landscape but has the fog of war wrapped around it. Today’s conversation centered around the recent developments in cybersecurity regulations and their potential impacts, ignited by the Supreme Court overturning Chevron Deference. This, of course, has other potential impacts on all regulation types enforced and shaped by federal agencies, but our focus is, of course, on cybersecurity, privacy, and AI.The PanelWe welcome back Ilona Cohen, Chief Legal and Policy Officer at HackerOne, who joined us last year to discuss the National Cybersecurity Strategy. Ilona is also the former General Counsel for OMB. We are also joined by the GRC meme king, Troy Fine, the Director of SOC and ISO Assurance Services at Gills Norton. Beyond the memes, Troy takes a practical perspective on regulations and acts as our voice for those who may be most immediately impacted.Key TakeawaysChevron Deference overturned: The Supreme Court's decision removes the requirement for courts to defer to federal agencies' interpretations of ambiguous statutes and now relies on the courts.Increased regulatory uncertainty: This ruling may lead to more challenges to existing and future regulations, potentially affecting cybersecurity and AI policies.State vs. Federal regulation: The uncertainty at the federal level might prompt states to act more quickly on issues like AI and cybersecurity, potentially creating a patchwork of regulations.Impact on AI regulation: With about 40 federal bills addressing AI in the pipeline, the ruling could complicate the process of creating comprehensive federal AI regulations.Cybersecurity implications: Existing and proposed cybersecurity regulations, such as the Cyber Incident Reporting for Critical Infrastructure Act, may face new challenges.Business concerns: While some business organizations applauded the ruling, the resulting regulatory uncertainty could be problematic for companies trying to plan and comply with regulations.Expertise concerns: There are worries that courts may lack the technical expertise to make decisions on complex technological issues like AI without deferring to agency experts.Potential for innovation: The regulatory uncertainty might create a wild west period for AI, potentially fostering innovation before more stringent regulations are imposed.Self-regulation importance: In the absence of clear federal regulations, industry self-regulation initiatives may become more significant, especially in rapidly evolving fields like AI. Hosted on Acast. See acast.com/privacy for more information.

Aug 20, 202451 min

S3 Ep 11Applying Vulnerability Management to Zero Trust

Season 3, Episode 11: Vulnerability management is critical to any Zero Trust strategy, but you probably already know that. Fortra’s Tyler Reguly breaks down severity vs. risk.Catch this episode on YouTube, Apple, Spotify, or Amazon. You can read the show notes here.Every organization relies on some form of technology to run, and each tool you add increases the risk of vulnerabilities causing problems. If you don’t stay on top of patching, you increase the odds of a bad actor finding their way more easily within your network.This week, we chat with Tyler Reguly, a senior manager of security research at Fortra, who shares insights from his 18 years in vulnerability management. Tyler discusses the importance of staying on top of patching to maintain a Zero Trust strategy, the differences between vulnerability and patch management, and emphasizes that the Common Vulnerability Scoring System (CVSS) measures severity, not risk.We also briefly nerd out about the significance of groups like the Canadian Cyber Threat Exchange (CCTX) for knowledge sharing and collaboration in cybersecurity. And then, we wrap things up by exploring the efficacy of existing security policies and benchmarks, such as CIS and DISA STIGs, and the role of vendor relationships in maintaining effective security practices. Hosted on Acast. See acast.com/privacy for more information.

Aug 1, 202445 min

S3 Ep 10The Unstoppable Phish: A Discussion with Vivek Ramachandran

Season 3, Episode 10: Elliot chat’s with Vivek Ramachandran of SquareX about his approach to tackling the impossible: Social engineering.Catch this episode on YouTube, Apple, Spotify, Amazon, or Google. You can read the show notes here.For nearly three decades, social engineering, particularly phishing, has been one of the most impactful and financially draining cyber threats. Between security awareness training, email security gateways, generative AI, enterprise browsers, and a slew of other tech like EDRs and XDRs, social engineering has yet to be thoroughly thwarted. The reason for that is straightforward enough: social engineering is a psychological threat, not just a technological one.In our last round of interviews from RSA, we chatted with Vivek Ramachandran, the founder of SquareX, who is attempting to tackle the challenge. Vivek also walks us through a more realistic perspective of how threat actors use generative AI today, which goes beyond the more unique what-if scenarios we’ve seen in headlines in the past two years.Key TakeawaysSocial engineering and phishing attacks remain a significant threat, and everyone can be a target. The sophistication of these attacks has increased due to advances in AI.AI can craft messages that sound remarkably like someone the recipient knows, enabling rapid scalability.Social media platforms are becoming common channels for launching phishing attacks. Attackers exploit the trust that users place in these platforms and their contacts.Vivek Ramachandran's company, SquareX, deploys a browser extension that can attribute attacks and detect and block them in real-time, providing valuable information to the enterprise.Traditional technologies like Secure Web Gateways (SWG) have matured, and attackers can easily bypass them.Enterprise browsers solve the problem for a small niche group of websites but have adoption friction due to the inconvenience of having a dedicated browser. Hosted on Acast. See acast.com/privacy for more information.

Jul 2, 202426 min

S3 Ep 9Breaking Down the SMB Threat Landscape and The Value of MSPs with SonicWall

Season 3, Episode 9: We chat with SonicWall’s Doug McKee about the top 5 threats targeting SMBs based on recent research.Catch this episode on YouTube, Apple, Spotify, Amazon, or Google. You can read the show notes here.Cybersecurity challenges come in many different flavors regardless of how old your company is or how many employees it houses. Larger companies have to deal with layers upon layers of technology, processes, and the people who support it. Smaller organizations are resource-constrained, often lack the experience or expertise to build a proper program, and typically rely on external support systems.While larger companies may not be nimble, typically, they employ and understand the value of threat intelligence to hone in on risks that could impact the business. They also have larger targets on their back because they are seen as more valuable targets for data, financial drain, and other nefarious purposes. In the same, smaller organizations may not be as valuable as a direct target, but they can be seen as a doorway into these larger companies. It’s for these reasons that supply chain attacks, even older ones, are among the top threats targeting small businesses and startups.This week on AZT, we examine the top five threats targeting startups and small businesses and chat with SonicWall’s Executive Director of Threat Research about the WHY behind them. As a researcher and educator through SANS, Doug McKee shares his perspective on why smaller shops need to consider threat intelligence as part of their cybersecurity program and how MSPs can help fulfill that capability.Top 5 threats to SMBs (According to SonicWall)Log4j (2021) more than 43% of organizations were under attackFortinet SSL VPN CVE-2018-13379 - 35% of orgs were under attackHeartbleed (2012) - 35% of organizationsAtlassian CVE-2021- 26085 - 32 %Vmware CVE-2021 - 21975 - 28% of orgsThe Guest: Douglas McKeeDoug is an experienced information security professional who possesses extensive technical expertise acquired through involvement in application and system security testing, hardware and software vulnerability research, malware analysis, forensics, penetration testing, red team exercises, protocol analysis, application development, and risk mitigation activities. These technical proficiencies are complemented by adept leadership and communication skills, honed through the leadership of teams and projects, collaboration within both large and small teams, and the composition of technical reports for clients.Doug is recognized for discovering numerous CVEs and regularly speaks at prominent security conferences such as Blackhat, DEFCON, RSA, Hardware.io, and Ekoparty. Additionally, Douglas's research is frequently featured in publications with a wide readership, including Wired, Politico, Bleeping Computer, Security Boulevard, Venture Beat, CSO, Politico Morning eHealth, Tech Republic, and Axios.Key TakeawaysNone of these vulnerabilities in SonicWall’s research were found or disclosed between 2022-2024, and yet we’re still dealing with themOld vulnerabilities remain a significant threatThe most widespread attacks for SMBs include Heartbleed and Log4j vulnerabilitiesMany widespread vulnerabilities are supply chain vulnerabilitiesThese vulnerabilities are embedded in multiple products and systemsPatching vulnerabilities can be complex and costlyCompliance and regulatory standards can complicate the processAttackers are becoming increasingly nuanced in their approaches Hosted on Acast. See acast.com/privacy for more information.

Jun 13, 202446 min

S3 Ep 8Decoding Emerging Threats: MITRE, OWASP, and Threat Intel

Season 3, Episode 8: AZT and Dr. Zero Trust have a crossover episode where we chat with reps from MITRE and OWASP about challenges associated with emerging threats.Catch this episode on YouTube, Apple, Spotify, Amazon, or Google. You can read the show notes here.Every few weeks, and occasionally every few days, we hear report of a new novel technique or zero day. Those headlines often create an unnecessary level of fear for organizations, but battle-worn cybersecurity professionals know just because it’s on a headline doesn’t necessarily mean it will impact their environment. That is because emerging threats are just that, new and novel. While zero day threats can be interesting and something to be aware of, most threat actors stick to tried and true methods.But how do we identify what is most impactful to our security posture, attack surface, or insert your other buzzy term? Threat intelligence and the collective defense. And for that, it’s time to introduce our two very equipped guests to navigate this conversation and our guest moderator:This week on AZT, we have representatives from OWASP and MITRE, with Dr Zero Trust leading the charge.The GuestsSpecial Guest ModeratorDr. Chase Cunningham - Dr. Zero Trust and Vice President of Security Market Research for G2Avi Douglen - Chair of the Global Board of Directors for the OWASP Foundation and Founder and CEO of Bounce Security.Avi is a security architect and software developer, leading development teams in building secure products for over 20 years. As a systems developer and security consultant, over the years Avi has amassed much technical knowledge and understanding of the enterprise security needs at the business level. Avi currently serves on the OWASP Global Board of Directors, and leads the Israel chapter. He is the founder and leader of the the popular AppSecIL security conference, the OWASP Threat Modeling Project, and co-authored the Threat Modeling Manifesto. He is a community moderator on Security StackExchange, and a frequent speaker at industry conferences, recent ones can be seen here.Stanley Barr - Senior Principcal Cyber Researcher for MITREDr. Stanley Barr is a three time graduate of University of Massachusetts Lowell. He has a BS in Information Sciences, an MS in Mathematics, and a PhD in Computer Science. He has coauthored published papers in malware analysis, barrier coverage problems, expert systems for network security, and robotic manufacturing. He has spoken at MILCOM, RSA, Bsides Boston, and Defcon. He has been a panelist for conferences. Panels topics have included fighting through real world computer network attacks from both external and internal threats. Currently, he is a Senior Principal Scientist at The MITRE Corporation, a not-for-profit corporation that manages six federally funded research and development centers (FFRDCs).Key TakeawaysEmerging threats are interesting, but threat modeling and understanding how systems work to identify potential issues is more impactfulAI can pose a threat due to its ability to remember and tailor information, as well as its scalability.The panel emphasized that basic security hygiene is often overlooked, such as enabling 2FA on all accounts.The OWASP Top 10 most common attack vectors are still a significant concern, but they should not be the only focus.The panel argued that responsibility for security breaches should extend beyond the CISO to the entire board and engineering organization.Cybersecurity is a people-centric challenge, and relying on people not to make mistakes is not a sustainable strategy.There is value in investing in proper security measures, as it can save organizations money in the long run. Hosted on Acast. See acast.com/privacy for more information.

Jun 6, 202425 min

S3 Ep 7Navigating the Ever-Changing Landscape of Cybersecurity Regulations With Lacework and Drata

Season 3, Episode 7: Though regulation impacting cybersecurity moves slow, when new laws are introduced it often puts significant strain on companies. Lacework’s Tim Chase and Drata’s Matt HIllary discuss navigating the latest broad-sweeping regulations.Catch this episode on YouTube, Apple, Spotify, Amazon, or Google. You can read the show notes here.The time between a law being proposed and going into effect may feel like a snails pace, but for cybersecurity and GRC professionals, it may feel like the DNA of an organization may need to change. This week we chat with cybersecurity leaders Tim Chase from Laceworks and Matt Hillary of Drata who delve deep into the ever-evolving landscape of cybersecurity regulations. They explore topics such as the challenges of rapid incident reporting, the role of collaboration in the industry, and the emerging onslaught of AI-related laws and proposed bills.This Week’s GuestsTim Chase, Lacework’s Global Field CISOWith over 15 years of experience in the cybersecurity industry, Tim is a Global Field CISO at Lacework, a leading cloud security platform. Tim holds CCSK, CISSP, and GCCC certifications and has a deep understanding of product security, DevSecOps, application security, and the current and emerging threats in the cybersecurity landscape.Matt Hillary, Drata’s CISOMatt Hillary currently serves as VP, Security and Chief Information Security Officer at Drata. With more than 15 years of security experience, Matt has a track record of building exceptional security programs. He most recently served as SVP, Systems and Security and CISO at Lumio, and he’s also held CISO and lead security roles at Weave and Workfront, Instructure, Adobe, MX, and Amazon Web Services. He is also a closet raver. Like really, actually is.TL;DRThe landscape of cybersecurity regulations is ever-changing, with new bills and regulations continually emerging which impact businesses of various sizes.The recent rules released by the SEC regarding the time frame for announcing a breach or incident have significantly impacted organizations. The term "material" is a key aspect of these rules, leading to discussions around what constitutes a material cybersecurity incident.The role of a CISO is challenging due to the potential for breaches and incidents despite implementing comprehensive security measures. The additional regulations add further complexity to the role.Transparency and honesty are vital in the event of a breach. Companies that are open about incidents and their impact are viewed more favorably than those that attempt to cover things up.The concept of 'carrot and stick' in regulation is discussed. There are mixed feelings about this approach, with some preferring collaboration and industry-led standards over punitive measures such as fines. However, there is recognition that both incentives (the carrot) and punitive measures (the stick) can drive companies to improve their cybersecurity measures.AI is a hot topic in the cybersecurity field, with potential to assist in quickly sorting through data and reducing false positives. However, the implementation of AI also brings its own set of regulations and challenges. Hosted on Acast. See acast.com/privacy for more information.

May 30, 202430 min
Copyright 2026 All rights reserved.