
DrZeroTrust
239 episodes — Page 4 of 5

S2 Ep 45Cyber news and Zero Trust insights for 11/30/2022
EDo buyers always configure vendor security solutions correctly? Is there a magic button to push and then your organization is secure? Do vendors have no risks or avenues of compromise? How bad is the MSQL database security that is out there right now (think millions). The DoD released it's strategy for Zero Trust, what should we take away from that? Amazon is offering a security data lake recently, is that a good thing? The White House and Starlink were hit by a threat group via a DDoS attack, so what? And another attack on an island nation that is now working off of paper to run the government, super. Those points and more on this episode.

S2 Ep 44What happens when two former analysts have a real conversation?
EA former Forrester analyst and a former Gartner analyst talk about the market and a variety of topics. Is it a good idea for layoffs to be taking place right now in cyber as the economy takes a dive? How will that affect our collective security? What should you know about analyst reports like the Wave or the Magic Quadrant? Does security product bloat actually hurt operational capabilities? Should automation be everywhere? How does strategy start, and where? Why do customers still run towards point solutions, rather than broader strategic offerings? What about the new book "The Art of Selling Cybersecurity"? Those questions and more on this one.

S2 Ep 43Cyber news and Zero Trust insights for 11/17/2022
EZscaler has come up with their own certification for Zero Trust. Is that a good thing? What else is up with Medibank and how bad is the security for the Australian government that is pushing the formation of these new "hack back" teams? Is that even a thing? China is using universities to plunder research and intellectual innovations from America, so what? Why isn't that more of a problem? Don't we have a means to address this insider threat activity? Navigation systems for pilots were affected recently, did you hear about that on the news? Why not? How much financial impact can one tweet have on a major company? It's a lot y'all. Those questions and more on this episode.

S2 Ep 42Cyber news and Zero Trust insights for 11/9/2022
EA noted Russian "leader" openly admits to tampering with elections, does that close the book on whether or not that has happened? An article on the Hill says that "ignorance" is the issue for legislators regarding cyber. Is it "ignorance" or willful ignoring of the problem? With the midterm elections going on surely I can't find potentially insecure and misconfigured election related systems? Right? And surely the company that has been tasked with securing those election networks isn't at risk, right? The CIO of the US DoD will release their Zero Trust strategy in the coming weeks, what should we take away from that? And a great article from Andy Ellis on some of the realities of being a CISO in today's business world. Those points and more on this episode.

S2 Ep 41Cyber news and Zero Trust insights for 11/2/2022
EBanks have paid out a massive multi-billion dollar plus to ransomware operations, but where does all that money go? Is crypto entirely to blame? Dropbox had a compromise issue, but luckily it's never happened before? Right? And it's good that it wasn't related to any companies intellectual property. Oh wait. And then let's talk about Chegg. They get the award for continued cyber negligence I think. But the FTC is now suing them, even though this is the fourth breach in a few years. Good thing they moved fast. Why does this keep happening and how are such major companies getting away with ignoring basic best practices? Those questions and more on this episode.

S2 Ep 40Cyber news and Zero Trust insights for 10/27/2022
EA major insurance provider for an millions of people is dealing with a compromise, surely they have buttoned up the easy stuff? Right? Wanna bet. Can I find a misconfigured SSH server that pipes me directly into an adversary nations internal networks? Maybe. More problems with TikTok as it gets reported in Forbes that the company was working to access American citizens personal location data "without their knowledge". Uh oh. How about the new mandates from TSA for the rail companies? Do those requirements really have teeth and will they help things? How many standards for compliance and the legal requirements to do business via digital connections are there? Guess. FastCompany got hit via the use of really bad passwords, that must have been a really hard problem to solve. Right? Those questions and more on this episode.

S2 Ep 39Cyber news and Zero Trust insights for 10/19/2022
EHow long does it take to find possible vulnerable assets online, about 21 minutes. Yeah. Is the OPM data breach "settlement" even worth it? Surely I can't find admin usernames and passwords with 1234 on the internet, right? Certainly not for a state or local system, right? Is data security up to par after a breach? Why aren't states and local governments willing to work through the paperwork to get a cyber security grant? That's nuts! Is the job market getting any better for staffing? Do trends indicate that? A free resource for ZT planning, really? Well, some of it's free but the resources are great. Do vendors sell "snake oil" or is more a factor of the market at large and are investors and VC's affecting the ability to execute? Those questions and more on this episode!

S2 Ep 38Cyber news and Zero Trust insights for 10/12/2022
EDell has setup a Zero Trust Center of Excellence, that's pretty cool. Real investment into strategic technology alignment sounds like a good idea to me. Disinformation around the hurricane Ian fiasco. How can we defend democracy when folks buy into this stuff? Are you using Reddit to gain insight into your customer experience, you should be. How secure is the organization that is forcing me to renew my business and cyber insurance policy, wanna guess? And what about the Uber CISO issue? Does that scenario really affect us all? Those questions and more on this episode.

S2 Ep 37Cyber news and Zero Trust insights for 9/28/2022
EHow many VPN's are out there that might have a configuration issue? Are there any major companies that might be piping threats into their networks (the answer is probably). Has Uber fixed the low hanging fruit from it's recent issue? More ICS and SCADA vulnerable systems aren't out there, right? Research from ZScaler on the use and adoption of the VPN is interesting, has the tide shifted with this old technology? Are users really the weakest link, or has the security industry misled that group? Those questions and more on this one!

S2 Ep 37Thoughts and Perspectives on the Twitter Whistleblower
EWhy are security leaders going "scorched earth" when they leave employers? How can an organization better be prepared to deliver on their promises? Does ethics apply in technology (it sure should)? What's the right and wrong way to go about blowing the whistle when the need is there? Does money paid out call into question the motives for speaking out? Is it better to go out with a bang or just fade away? Some hard hitting questions on this one!

S2 Ep 36Cyber news and Zero Trust insights for 9/14/2022
EWhat a wake up call this week when working with SMB's on their cyber security strategy and the reality of the space. Do SMB's use outsourced security, and is that smart? Does that hurt their overall awareness? Why aren't things getting patched the way they should even when we have been notified by CISA and others of "critical vulnerabilities"? Does the upcoming legislation around semi-conductors and silicon pointed at China have any impact on our national security and cyber future? Those questions and a few more on this one.

S2 Ep 35Cyber news and Zero Trust insights for 9/7/2022
EIs the news media collaborating to manipulate our collective consciousness? How would that happen? Is local news "more true" than national news? What about OPSEC for the war in Ukraine? Could an organization cause a kinetic attack based on pictures that came from soldiers sharing via social media? How does politics play into the space around cyber and disinformation? Some hard hitting questions in this one to ponder.

S2 Ep 34Security for Apps and Low or No Code Systems
How can you secure no code or low code applications? Is devsecops a real thing? Does anyone actually do this? How should organizations look at the risks from these types of "factory made" apps? Why is the 8200 unit such a big thing in the Israeli cyber scene? What types of pricing make sense for security applications that you might not own? How should the market approach the future of application security in an all cloud world? Those questions and more on this one.

S2 Ep 33Cyber news and Zero Trust insights for 8/24/2022
EAn article from Recorded Future points out new legislation in North Carolina and Florida that bars state backed organizations from paying ransomware attacks. Surely that means they have their stuff on lock and have no misconfigured assets, right? Google has an AI and privacy program that seem to be intersecting and could impact all of us, and Apple is dealing with those issues as well. How do we handle this problem? According to new research from Tessian "apathy" is the biggest vulnerability for an organization, but don't we train our folks enough to mitigate that risk? Those questions and more on this episode.

S2 Ep 32Selling Zero Trust at enterprise scale.
Do enterprises really buy Zero Trust? How should they think about a strategic approach to a problem. What about rip and replace? Are there no-go's when it comes to working to help an enterprise adopt ZT? Where do they budget for these endeavors? Is this only a big business problem? Those questions and more on this episode.

S2 Ep 31Cyber news and Zero Trust insights for 8/17/2022
EOkta's Zero Trust study. What does it say about the market and the growth of ZT? More cyber insurance shenanigans, why does this keep coming up? Should we really use this "service"? Water treatment plant is hacked in the UK, but is it really a clear case of compromise? What happens if you try and send someone shit in a box (literally) and the service is hacked? Is that a PII violation, or HIPPA or what? How many devices are out there that are possibly exploitable right now (hint, it's a lot!). Those questions and more on this episode.

S2 Ep 31How to sell into the channel the right way.
Truths about selling into the channel market with a real expert. How should your organization go about selling to a channel? Is the market different? How can you use those partners smarter? Do you have to sell twice? What shouldn't you do to leverage that channel? How can you optimize your channel approach and force multiply your sales efforts? Those points and more on this episode!

S2 Ep 30Cyber news and Zero Trust insights for 8/10/2022
EHow hard is it to find "internal use only" files with a simple crafted search? How about spreadsheets with passwords and admin logins? What should we think about this whole Trello thing? What happened when I got phished (yup, they got me). Was it even a problem? Is the national emergency alert system really vulnerable? How big does the Zero Trust market get in the next 9 years? Those points and more on this episode!

S2 Ep 29Cyber news and Zero Trust insights for 8/3/2022
EAre there potential ways to attack a nuclear site via online misconfigurations? What about water as a vital national resource, can you attack a water supply system? Or a dam? Are containers inherently secure, and does that matter when they are part of a cluster? PE firms keep buying up the security market players, is there an anti-trust issue there? Is your threat intelligence service pulling in IOC's from US Cyber Command? Was the Pelosi visit part of a cyber attack? Does that matter and is it cyberwarfare? Weak security in the system used to track organ transplant systems, that's ok right? And some points on how to stay motivated (lol) and my thoughts on dealing with trolls online. My cool new swag from Lumu and more on this episode. Check it out!

S2 Ep 28Cyber news and Zero Trust insights for 7/27/2022
ECan I find privacy violations with Shodan? What companies are using hackable unpatched scada systems that are misconfigured? Can we find osint on a company that has government contracts but is not secure? Why is phishing training still a multi-billion dollar business when a variety of reports indicate that the numbers for that "defense" don't justify that expense? Is the government really as secure as we think they are? What about finding illegal violations of compliance mandates in ics systems? Isn't breaking the law a bad thing? Those questions and more on this podcast!

S2 Ep 27Applying Zero Trust to Cloud Workloads and Kubernetes.
More ideas and thoughts around applying Zero Trust to cloud workloads and kubernetes. How should we think about the inherent vulnerabilities in these application development environments? How can you secure something that only exists for minutes at a time? Can you use open source solutions to approach the problems in this space? Do developers really need to be security engineers, and should security people know how to build apps to make things more secure? Check this one out and look for a video demo on Tigera.io and their open source Calico solution soon!

S2 Ep 26Cyber news and Zero Trust insights for 7/6/2022
EMarriott got hacked again, say what? Does it mean anything? What about their fines, didn't that teach them something? Can I find vulnerable government assets that are misconfigured and make 30 grand in bug bounties in half an hour? What about cloud resources that the DoD uses? A billion records are stolen in China, what's up with that? Those questions and more on this episode!

S2 Ep 25What's up with the WAF market?
EWhat's up with the WAF market? Talking about how we should and shouldn't use a WAF with an expert. Is the WAF the best way to address the problems we face? Where is this market going? What about the evolution of the WAF and it's place in history? And some hard questions with data to challenge why we might need to move to a new approach.

S2 Ep 24Cyber news and Zero Trust insights for 6/29/2022
ECan I find medical offices open to the internet? How hard would it be to hack them? Why is phishing training a problem for enterprises and businesses? Deepfakes and PII are being used for nefarious purposes, say what? Those points and more on this episode.

S2 Ep 23Cyber news and Zero Trust insights for 6/15/2022
EThoughts on RSA2022. New research from Digital Shadows breaks down key areas of concern for us. I find some vulnerable databases on the web (some are "security vendors"...uh oh). We are still failing at the basics, and the password is eating our lunch, why is this still a problem? A great new blog from the S/R team at Forrester on the economy and the security market. Did AI just go sentient? Those thoughts and more on this episode!

S2 Ep 21What is Collaboration Security?
ECan an organization be compliant if they are using Slack to share files, passwords, and other critical and risky data? How does an agent-less system keep up with all of those short communications in collaboration applications? Is there more risk if we use modern applications that allow unlimited interaction and collaboration? What about business context, is there value to deciphering risk?

S2 Ep 21Cyber news and Zero Trust insights for 6/1/2022
ERSA is next week, I really need a beard trim. See y'all out there! Finding vulnerable hospital systems on the internet shouldn't be this easy, but here we go. Don't worry though they all are HIPPA compliant lol. How powerful is pimeyes at finding images of people on the internet and how does that affect privacy and security? Should you be worried? The new Microsoft Zero Day, how bad is it? What about hacking tractors and affecting the food supply, that can't be a thing right? DHS took seven years to hire one person, yeah. Your tax dollars at work. Costa Rica ignored it's own cyber defense strategy, and that worked out well right? How much money is going into the Zero Trust market? And the tech jerk of the year award goes to an absolute turd of a person. Those questions and more on this one!

S2 Ep 20Cyber news and Zero Trust insights for 5/25/2022
ECan you find vulnerable stuff online from 2003? Surely not? Uh oh. Do we need a cyber moonshot to get past the failures we face in cyber security? Is there more evidence that legislation isn't dealing with reality, and that some of our leaders are missing the point? Using your phone SIM to do MFA, good or bad? Is DuckDuckGo really a "private" browser? Those points and more on this episode.

S2 Ep 19Cyber news and Zero Trust insights for 5/18/2022
EWhat matters more, targeting the "asset" (tractors) or the infrastructure for John Deere. Can you overthrow a government with a ransomware attack? Why are insurers changing their approach to cyber policies and why are they raising rates? What about the NSA guidance on best practices, is it really that different? Those questions and more on this one!

S2 Ep 18Cyber news and Zero Trust insights for 5/11/2022
ECan we find vulnerable ICS and SCADA controls on the internet? What about the physical doors that are in those facilities? Have we really learned anything a year after the pipeline hack? Microsoft has put out it's advise for ransomware defense, is it any good? What about F5 and it's big new vulnerability, should you be worried? Why shouldn't we talk about gangs "going down" in cyber, and does that hurt or help as we deal with those threats? Those points and more on this episode!

S2 Ep 17Cyber news and Zero Trust insights for 5/4/2022
EFinding vulnerable passwords with Google dorks, it's super easy (don't do this). How many VPN's can I find that are possibly misconfigured? Why does it take a 600 million dollar hack for a company to adjust it's approach to cyber? New banking legislation and rules on a 36 hour reporting mandate, good or bad? Those points and more on this episode.

S2 Ep 17Helping Small and Mid Sized Businesses in Cyber with Arctic Wolf
EWhat do SMB's care about in cyber? Where do they need help? How do they budget for this issue? Is there value to training or is it better to have a technical control? What is "security theater for businesses, and what fixes problems? Those questions and more on this episode!

S2 Ep 17Cyber news and Zero Trust insights for 4/21/2022
EWhy is the government looking at legislation on "quantum security"? Can I find vulnerable systems for ICS and SCADA that have no authentication on a livestream? Does a cyber attack have the ability to stop a university from operating and put it out of business for good? What about T-Mobile's "unstoppable" phish? Should we be scared? Those questions and more on this episode.

S2 Ep 16Cyber news and Zero Trust insights for 4/14/2022
EThe dog barks, like always. What is the Zero Trust market map? How about Microsoft's new CVE issue, is that something that we should have fixed years ago (the answer is hell yes). Can I find vulnerable assets with no authentication in real time? Forrester research published some great data on enterprise breach activity globally, what does it mean and how should we think about it? What about cyber and nuclear threats, do those relate? Those questions and more on this episode.

S2 Ep 16Cyber Insurance, Truth and Consequences with an Expert
EIs cyber insurance worth it? Do insurers actually know what they are doing, and why are policies not being honored? Is a strategy useful for better security and helping lower a premium? What data is being used to validate a policy, or is that even a thing? Is this a big deal for small business, or is cyber insurance better suited for enterprises? And am I wrong by saying it's a "rip off"? Those questions and more on this very cool episode.

S2 Ep 15Deploying Zero Trust at the Enterprise Level
EWorking with big enterprise ZT, how does one engage the leadership effectively? Is this about more tech? Who holds the keys to the kingdom on budget? Where does it make sense to start with a big time roll out? How hard is it to get ZT in place? How long is the journey? Where does one go after they solve their first problem? And why is Sean Connery on the line for this call?

S2 Ep 14The Devil Never Sleeps new book review
"The Devil Never Sleeps" is one of the best books out there that can help us better understand how to deal with today's never ending threats. Juliette Kayyem has done a great job of helping break down a variety of past historical issues and applied realistic and insightful ways to help her readers think more intelligently about accepting the threats and dealing with them, rather than being fearful of them. Her book is a must read, go get your copy now!

S2 Ep 13Conversations with an Enterprise Architect doing the work to enable ZT!
EIs #zerotrust happening in Australia? What problems do the folks doing the work run into? How does he deal with the business side of the issues he face? Where did he start? How should one go about discussing security strategy with folks that aren't in our space? And what is a no no for getting things done when collaborating with business leaders?

S2 Ep 12Cyber news and Zero Trust insights for 3/23/2022
EWhat should we take from the Okta situation? More legislation to mandate training for government cyber security, really? Too many agencies are getting involved in cyber, right? What about the White House's "guidance" on the Russian threats? Deepfakes and disinformation can influence actual combat, say what? More bad hiring practices in cyber and some real issues with state and local cyber practices. Check it out!

S2 Ep 11Cyber news and Zero Trust insights for 3/17/2022
EWhy isn't cyber getting any better nationally with all this legislation? How should we view CISA's new rules? What about the Committees that congress and the Senate sit on? Analysis on a deepfake that has some very interesting implications. Where can we do better?

S2 Ep 11Cyber news and Zero Trust insights for 3/2/2022
EWhere can you go to learn how to "do" a deepfake, I'll tell you, but be careful. My thoughts on "getting involved in the conflict" in Ukraine from a cyber perspective. The Conti group had a leak and some great reporting was published on it, wow! Analysis on wiper malware, and the "most advanced malware ever", lol. Also, some finer points on what Zero Trust means and how to enable this strategy from a variety of vendors, and a new report on 9 steps to ZT, most of them are business related! Say what?

S2 Ep 10Cyber news and Zero Trust insights for 2/23/2022
EZero Trust world was a blast, well done Threatlocker! Microsoft has done some great work in helping people to understand Zero Trust. Misinformation for critical infrastructure and corporate security is hard to do without a solid technology in place, especially at scale. Reference architectures for Zero Trust are available. Is the IRS the agency that can finally help with the ransomware problem and crypto crime? The Justice Department's three year plan to move to Zero Trust and how they are approaching the issue, and an example of a state and local government that is enabling Zero Trust. Check it out!

S2 Ep 9Cyber news and Zero Trust insights for 2/16/2022
E#cyberwarfare and first strike capabilities in the Ukraine conflict? Finding vulnerable SCADA and electric systems in @shodan isn't hard, how much is out there? How did the #fbi get back stolen #crypto? Should we be "afraid" of hacking and cyber threats (weird things are happening everywhere lately, are you worried)? Some tips on how to read through congressional documents that are available on the hill. Also, some pork that is being tossed into the new protecting America act that has been passed. Lastly, how should we think about getting and using threat intelligence without paying for it. Check it out!

S2 Ep 8Cyber news and Zero Trust insights for 2/8/2022
EMore ways cyber insurers are getting out of paying. Two students hack a school system and ask for a job, awesome. Microsoft talks about the lack of good IAM for Azure. Google breaks down cryptojacking in it's cloud. The insanity around threat intelligence and naming a threat actor group, and more on this episode.

Cyber news and Zero Trust insights for 2/2/2022
Interesting points on a Zero Trust report by Illumio. How to stop the majority of ransomware, it's not that hard. How did we allow the US DoD to buy drone technology that was financed by China? And what about some Shodan results that we should be aware of (like a submarine)?

S2 Ep 5Threat intelligence and the cyber security market with Brian Kime.
EWhat is threat intelligence, and what is the value in data? Does brand defense make a difference? Do his customers worry about deepfakes? What is attack surface management and how is that market changing? And more on this episode.

S2 Ep 3Cyber news and Zero Trust insights for 1/19/2022
EThe new memorandum on cyber security for the federal government and Zero Trust. Drones are used to attack an airport in the Middle East. Lawyers and cyber insurance team up as they address the issues we face in cyber, and more on this episode.

S2 Ep 2Cyber news and Zero Trust insights for 1/12/2022
EPredictions from vendors for 2022. Are the leaders on Capitol Hill actually doing anything on the cyber front? The first log4j malware attacks are showing up, what can we do? What about insider trading using hacked systems to gain a financial advantage? Those questions and more on this episode!

S2 Ep 1A look back at the major hacks of 2021
EA look back at 2021 and the major hacks we endured. How did they happen? What should we learn? Where did it all go wrong? Can we defend ourselves from these threats in the future? Does Zero Trust really make sense?

S1 Ep 37Disinformation and Narrative Intelligence in Cyber
EIs disinformation actually affecting people? What is narrative intelligence? Should corporate organizations defend their brand from trolls and narrative attacks? Will this be more important in the near future?