PLAY PODCASTS
Info Risk Today Podcast

Info Risk Today Podcast

3,490 episodes — Page 45 of 70

U.S. Attorney: Managing Fraud Investigations

Knowing exactly when to share information with law enforcement in the wake of a breach is challenging, says Assistant U.S. Attorney William Ridgway, a featured speaker at ISMG's Fraud Summit Chicago on May 19.

May 4, 2015

Defending Against Hacker Attacks

Security expert Mike Canavan of Kaspersky Lab North America pinpoints several critical security steps that organizations can take to help reduce the likelihood they'll become a victim of a hacking attack.

May 4, 2015

ABA on Cyber, Third-Party Risks

Emerging cybersecurity risks are now banking institutions' top concern, says the ABA's Heather Wyson-Constantine. What are institutions' contractual protections in the wake of a third-party data breach?

May 4, 2015

EMV: Changing U.S. Payments

The emergence of the EMV chip in the U.S. is soon going to change the payments game for issuers and merchants. Here, Sophos' Chet Wisniewski describes what bankers should be doing now to prepare.

May 1, 2015

Security: Moving to the Endpoint

Securing the enterprise means securing the endpoint, not the network, says Bit9's Harry Sverdlove. Learn why the expanding perimeter is a source of concern.

Apr 29, 2015

Bugcrowd Unites Code Builders, Breakers

Why not tap a community of bug hunters to find vulnerabilities in your products? That's the pitch behind Bugcrowd, which enables thousands of bug hunters to earn prestige - and cash - for finding and reporting new vulnerabilities.

Apr 29, 2015

Security Services Keep Evolving

In today's cloud-based and mobile-security world, data and applications regularly operate both inside and outside any supposed "traditional" network perimeter, and that makes them tough to secure, say F5 Networks' Preston Hogue and Greg Maudsley.

Apr 29, 2015

Application Protection: A New Approach

How can businesses ensure that the content coming into an application is executed safely, and that the application itself isn't under attack? That's the problem being addressed by Prevoty, says CEO Julien Bellanger.

Apr 29, 2015

How to Consume Threat Intelligence

Trying to consume threat data remains a difficult and highly manual process, says Solutionary's Joseph Blankenship. But better machine learning and artificial intelligence could make the task easier for enterprises.

Apr 29, 2015

The Commoditization of DDoS

Waging DDoS attacks is much easier today for hackers than it was three years ago, says Dave Lewis of Akamai. Learn why he says the online world is experiencing a commoditization of DDoS.

Apr 28, 2015

What's on Your Network?

To better secure enterprise networks, as well as detect and respond more rapidly to data breaches, businesses need to know the who, what, where, when and why of all endpoints that connect to network resoruces, says ForeScout's Sandeep Kumar.

Apr 28, 2015

Securing the Corporate Brand

Rogue applications designed to impersonate a company's corporate brand are increasingly prevalent, offering attackers an easy way to fool online users into downloading malicious apps aimed at compromising credentials, says Arian Evans of the online security firm RiskIQ.

Apr 28, 2015

Botnets Get More Opportunistic

Botnet operators are increasingly selling access to interesting zombie PCs, as well as continuing to launch DDoS and financial attacks, warns Menno van der Marel, CEO of investigation firm Fox-IT.

Apr 28, 2015

Helping Cybercrime Takedowns

Malware researchers can track important technical details about attacks, but shutting down cybercrime networks requires law enforcement agencies to take the next step, says Alexander Erofeev of Kaspersky Lab.

Apr 28, 2015

Threat Intelligence: Standards Required

To deliver effective information sharing and threat intelligence, the security industry must settle on a single set of threat-sharing standards, says David Duncan of the Internet security firm Webroot.

Apr 28, 2015

Monitoring Behavior to Flag Intrusions

To mitigate the threat posed by malicious insiders or attackers who compromise real users' credentials, businesses must create and monitor a baseline of legitimate user behavior and activities, says Idan Tendler, CEO of Fortscale.

Apr 28, 2015

Threat Intelligence Versus Threat Data

There's a big difference between threat data and threat intelligence, says Kevin Epstein of threat intelligence firm Proofpoint. Data alone is not enough to predict emerging threats, he says.

Apr 28, 2015

Strategies for Secure Messaging

As organizations increasingly focus on securing critical data, they mustn't overlook one huge vulnerability: enterprise email. Steven Malone of Mimecast discusses the latest in unified email management.

Apr 28, 2015

Prioritizing Gaps in Breach Prevention: The Role of Third Party Risk Ratings

BitSight Technologies conducted research on breached organizations and how they were impacted by botnets. The results are eye-opening, says CTO Stephen Boyer, offering insights from this study.

Apr 28, 2015

Securing Access from Anywhere

To secure the growing number of devices being used within enterprises requires organizations to be sure they're providing the right access to the right resources for the right people, says Ping Identity's Nat Klassen.

Apr 27, 2015

Automating Cyberthreat Analysis

Automating processes could help organizations tackle the shortage of cybersecurity practitioners by making the job of analyzing threats simpler and more efficient, says Jessica Gulick, a vice president at security provider CSG Invotas.

Apr 27, 2015

Analyzing Behavior to Identify Hackers

Using behavior analytics is key to identifying hackers, says Mark Seward, vice president of marketing for IT security provider Exabeam

Apr 27, 2015

Bracing for Uptick in CNP Fraud

As the U.S. completes its payments migration to the EMV chip, merchants and card issuers should be bracing for an uptick in card-not-present fraud, says Carol Alexander, head of payment security at software provider CA Technologies.

Apr 27, 2015

Automating Cloud Security

As organizations move toward storing and processing more data on the public cloud, security needs be automated and based on sound policies to mitigate growing threats, says HyTrust President Eric Chiu.

Apr 27, 2015

Simplifying Data Protection

Organizations are moving to security solutions that protect applications and data without software agents, code changes or network devices, say Waratek's Anand Chavan and Michael Adams.

Apr 27, 2015

Why Target Could Owe Banks

A class-action suit filed by U.S. banks and credit unions that's pending against Target could prove fruitful for the banks and credit unions, says attorney Chris Pierson, chief security officer at invoicing and payments provider Viewpost.

Apr 24, 2015

Lessons from Intelligence Info Sharing

Mark Clancy, CEO of Soltra, which provides an automated information sharing platform, says banks and credit unions that don't share threat intelligence will never advance their information risk management practices.

Apr 21, 2015

Information Sharing: A Matter of Trust

Attitudes about cyberthreat information sharing, as well as attack attribution, have dramatically changed in the last 18 months, says the FS-ISAC's Bill Nelson, a featured speaker at RSA Conference 2015.

Apr 19, 2015

PCI DSS Version 3.1 - What's New?

The PCI Council has just released PCI DSS 3.1, which calls for mothballing the SSL encryption protocol. What do security leaders need to know about the revised standard? Troy Leach of the council offers insights.

Apr 17, 2015

Cyber-Attack Risk Mitigation: Key Steps

Healthcare organizations need to take several key steps to protect their environments from the type of cyber-attacks that recently affected Anthem Inc. and Premera Blue Cross, says security expert Mac McMillan of CynergisTek.

Apr 17, 2015

Inside the National Security Database

With India facing a major staffing deficit in cybersecurity, the National Security Database is redoubling its efforts to organize a credible workforce. Director Rajshekhar Murthy shares these initiatives.

Apr 17, 2015

Healthcare Hacker Attacks: Who's Next?

Although recent hacking incidents in the healthcare sector have targeted large insurers, business associates, self-insured companies and even smaller hospitals should be bracing for cyber-attacks, says Daniel Berger, CEO of the consultancy Redspin.

Apr 16, 2015

How to Ensure Security and Convenience

For years, security leaders have struggled to find the balance between ensuring strong security and maintaining customer convenience. Benjamin Wyrick of VASCO Data Security says mobility may be the answer.

Apr 16, 2015

Framework for a New ID Ecosystem

What is the Identity Ecosystem Framework, and why is it so important for security professionals to embrace? Kimberly Little Sutherland of LexisNexis Risk Solutions shares insights on the future of online identity.

Apr 16, 2015

Medical Device Security Often Neglected

Despite the growing attention that federal regulators have been giving to medical device cybersecurity, many healthcare organizations still neglect those devices in their risk management and compliance programs, says security expert Andrew Hicks.

Apr 15, 2015

Exclusive: Inside Verizon Breach Report

High-profile breaches at Home Depot, Sony and others led many to declare 2014 "The Year of the Breach." But was it really? Verizon's Bob Rudis shares insights from the 2015 Verizon Data Breach Investigations Report.

Apr 14, 2015

How to Fight a Surge in Phishing

Over the last six months, the University of Vermont Medical Center has seen a spike in phishing attempts, including those laced with malware in an attempt to steal credentials, says CISO Heather Roszkowski, who describes her defensive efforts.

Apr 14, 2015

ONC's Privacy Officer: The Latest Tips

Lucia Savage, chief privacy officer at the Office of the National Coordinator for Health IT, describes an updated privacy and security guide for physician practices and discusses a variety of other cybersecurity issues in an interview at HIMSS15.

Apr 13, 2015

NIST Publishes Supply Chain Risk Guide

New NIST guidance is aimed at helping organizations to better understand the risks associated with the information and communications technology supply chain, says Jon Boyens, a NIST senior adviser.

Apr 13, 2015

RSA Conference 2015: A Sneak Peek

RSA Conference 2015 is expected to be the biggest gathering in the event's history. What's new at this year's event, and how can attendees get the most out of it? Program chair Hugh Thompson shares tips.

Apr 7, 2015

The 2015 State of DDoS

DDoS attacks are easy to launch yet difficult to defend against. Margee Abrams of Neustar discusses the state of DDoS and how organizations can best defend against today's potentially damaging attacks.

Apr 7, 2015

Art Coviello on RSA Conference

The RSA Conference is nearly a quarter-century old. What is the legacy of this event, and how is it flourishing in new geographic regions? Art Coviello, former chairman of RSA, reflects on the event's impact.

Apr 7, 2015

Talking Security to the Board

We all know that breaches and cybersecurity are topics of boardroom discussion. But how should security leaders present them to their boards? Jim Anderson of BAE Systems Applied Intelligence offers tips.

Apr 7, 2015

EMV: Should Liability Shift Be Delayed?

Some merchants want to postpone the EMV-related fraud liability shift, which major card brands have slated for October. But Randy Vanderhoof of the EMV Migration Forum sees "no reason to move the date."

Apr 7, 2015

Enhancing Authentication: Status Report

In the four years that he led the National Strategy for Trusted Identities in Cyberspace, Jeremy Grant says he saw significant progress in the use of new forms of authentication - yet widespread acceptance remains years away.

Apr 6, 2015

RSA's Amit Yoran: 2015 Security Agenda

RSA President Amit Yoran's focus is on refining RSA's vision, growth strategy and emerging technology. A key consideration in honing that strategy: the rise and pervasiveness of advanced threat actors.

Apr 6, 2015

RSA's Coviello on the State of Security

Art Coviello is retiring after 20 years with RSA. How does the company chairman size up the state of information security? "Precarious at best." Hear his top concerns and his advice to the next generation of security leaders.

Apr 6, 2015

BitSight CEO on Nation-State Attacks

The advanced and persistent nature of today's cyber-attacks, which are often waged by nation-states, is changing the way organizations address network security, says BitSight CEO Shaun McConnon.

Apr 1, 2015

Why Cyber-Insurers Will Demand Better InfoSec

As more mega-breaches occur, cyber-insurers will more closely assess the security risks of potential clients, leading more organizations to improve their information security programs, attorney John Yanchunis predicts.

Apr 1, 2015

Hacker Attacks: InfoSec Strategy Impact

A critical step healthcare organizations must take to improve their information security programs is to prepare for the changing threat landscape, especially hacker attacks, says security expert Tom Walsh, who analyzes results of a new survey.

Mar 27, 2015