PLAY PODCASTS
Info Risk Today Podcast

Info Risk Today Podcast

3,490 episodes — Page 48 of 70

The Slow Path to Password Replacement

The development of authentication technologies that could replace the password is "nearing a tipping point," but there's still several years of work to do, says Jeremy Grant, who oversees the National Strategy for Trusted Identities in Cyberspace.

Oct 6, 2014

Shellshock: The Patching Dilemma

As researchers scramble to learn more about Shellshock and the risks it poses to operating systems, servers and devices, Michael Smith of Akamai explains why not all patches are actually fixing the problem.

Oct 2, 2014

From ISIS to FISMA, A Conversation

In a wide-ranging interview, the acclaimed expert on cybersecurity strategy addresses the cyberthreat posed by ISIS and explains why Congress is unlikely to enact significant cybersecurity legislation this year.

Sep 29, 2014

Shellshock Bug: How to Respond

To mitigate the newly discovered Bash bug - AKA Shellshock - which may make millions of systems vulnerable to remote takeover, organizations must take several key steps, says security expert Alan Woodward.

Sep 26, 2014

HIPAA Omnibus: One Year Later

One year after HIPAA Omnibus Rule enforcement began, why do so many healthcare entities and business associates continue to struggle with even the most basic requirements? Security expert Andrew Hicks offers insights.

Sep 22, 2014

How Ascension Health is Battling Advanced Threats

Healthcare organizations are increasingly top targets for sophisticated data breaches. How can they improve their defenses? Paul Smith of Ascension Health and Mark Hanson of Fortinet offer tips.

Sep 22, 2014

Security: Maximize Business Benefits

When it comes to the evolution of machine data, security organizations now can improve protection <i>and</i> the top line. How can they maximize the business benefits? Jean-Francois Roy of Tibco shares tips.

Sep 16, 2014

The Biggest Challenge to EMV Migration

What's the toughest challenge the U.S. faces when it comes to EMV? Randy Vanderhoof of the EMV Migration Forum points to getting POS software and terminals certified for EMV transactions. Find out what other hurdles he identifies.

Sep 16, 2014

Helping Retailers Fight Malware

Helping merchants deal with the growing threat of POS malware is one of the biggest challenges facing Troy Leach, CTO of the PCI Security Standards Council, who says the BlackPOS malware threat, in particular, "is keeping me up at night."

Sep 15, 2014

Army Cyber Leader Touts Hacking Skills

If the U.S. military awarded a decoration for hacking, Army Col. Gregory Conti would wear it proudly on his uniform. Hear Conti, director of the Army Cyber Institute, explain why ethical hacking helps drive America's innovation engine.

Sep 12, 2014

Hacker Attacks: Are You Prepared?

Recent hacking incidents affecting HealthCare.gov, Community Health Systems and other healthcare organizations illustrate the need to urgently ramp up defenses against emerging cyberthreats, two security experts say.

Sep 12, 2014

Healthcare DDoS Attack: Mitigation Lessons

Boston Children's Hospital CIO Daniel Nigrin, M.D., describes the impact of a recent DDoS attack on the medical center and lessons that other healthcare facilities can learn from that event.

Sep 10, 2014

Keys to Fighting Insider Fraud

What steps can organizations take to mitigate insider fraud threats? Michael Theis of Carnegie Mellon, a featured speaker at ISMG's upcoming Fraud Summits in Toronto and London, explains why using data analytics is key.

Sep 9, 2014

Breach Prevention: A New Approach

Amidst a year of high-profile and costly data breaches, what can organizations be doing to help ensure they aren't the next victims? Charley Chell of CA Technologies discusses new authentication solutions.

Sep 8, 2014

Fraud: How to Secure the Call Center

Call center data and logs can help banks predict account-takeover attempts across multiple banking channels, says fraud expert Matt Anthony, a presenter at ISMG's upcoming Fraud Summits in Toronto and London.

Sep 8, 2014

How to Mitigate Merchant Malware Threat

The explosion in POS malware attacks against U.S. merchants highlights the need for retailers to take bolder security steps. Troy Leach of the PCI Council and Karl Sigler of Trustwave outline key steps.

Sep 2, 2014

Cyber Framework: Setting Record Straight

In an in-depth interview, Adam Sedgewick, the point man for the NIST cybersecurity framework, addresses misconceptions about the guidance, the costs to implement it and its role as a marketplace catalyst.

Aug 27, 2014

Fighting Cybercrime in Canada

Canada is considering adopting tougher data security and cybercrime legislation that could serve as a model for other nations, says Claudiu Popa, an information security expert who'll be a panelist at the Fraud Summit Toronto.

Aug 27, 2014

Breach Response: Are We Doing Enough?

What lessons can be learned from recent high-profile breaches? IT security experts John Pescatore of the SANS Institute and Ron Ross of NIST explain how organizations can work to mitigate the new-style data breach threat. Listen to the conversation.

Aug 25, 2014

Mobile Banking: Evolved Services, Risks

2014 has seen an explosion of mobile banking demand and services. But as the channel grows, so do the threats against it. What are today's top threats, and how can institutions offer more secure mobile banking?

Aug 22, 2014

Are Web-Enabled Health Devices Risky?

Patients and healthcare providers need to recognize that Web-enabled mobile health devices that fall under the umbrella of the "Internet of Things" potentially can put personal information at risk, says Intel Security executive Greg Brown.

Aug 22, 2014

Michael Daniel's Path to the White House

Michael Daniel explains that among his biggest challenges as special assistant to the president is fully understanding the economics and psychology behind cybersecurity, topics that few people have mastered.

Aug 21, 2014

Cybersecurity: What Boards Must Know

As the Target breach demonstrated, boards of directors will be held accountable when their organizations are breached. Attorney Kim Peretti offers tips on how to educate boards about security issues.

Aug 20, 2014

Apple iOS 8: What's New for Security?

Apple's forthcoming iOS 8 includes a number of useful new security and privacy features, says Symantec threat researcher Candid Wueest. But there are missing features he'd still like to see implemented.

Aug 20, 2014

Simplifying Cybersecurity Complexity

Finding a common theme from the Black Hat USA conference isn't easy, but a few emerged - simplifying complexity and developing community-based solutions - from sessions and discussions with top cybersecurity experts.

Aug 12, 2014

Spear Phishing: How Not to Get Hooked

Spear phishing attacks are increasingly sophisticated. Banking institutions must learn more about how fraudsters dupe one's customers and employees, says a panel of three financial fraud experts.

Aug 12, 2014

Does U.S. Truly Want Cyber Peace?

Cyber-historian Jason Healey contends the U.S. government does not want peace in cyberspace so it can conduct more attacks and exploitations. Instead, he says the feds should make the Internet's economic benefits its top priority.

Aug 11, 2014

Blackphone: Inside a Secure Smart Phone

Can a smart phone increase your privacy and security while remaining both highly usable and attractive to buyers? The inaugural Blackphone is testing that question for consumers and businesses.

Aug 8, 2014

A Holistic Approach to Security

No single security solution is enough to defend against today's multifaceted exploits. So it's time for a new holistic and cooperative approach to information security, says Bob Hansmann of Websense.

Aug 8, 2014

Cybersecurity: Why It's Got to Be a Team Sport

Former NSA information assurance leader Tony Sager goes on the road to the Black Hat USA security conference to promote the notion that no one should try to solve cybersecurity threats alone.

Aug 8, 2014

The Password Is 'Dead'

Millions of user credentials are breached regularly - whether we hear of the incidents or not. So, why do we continue to rely on passwords? Derek Manky of Fortinet discusses authentication and data retention.

Aug 7, 2014

Incident Response: 'Drowning in Alerts'

When it comes to incident response, organizations don't lack threat intelligence. They lack the automation, tools and the skilled staff to act on that intelligence, says Craig Carpenter of AccessData.

Aug 7, 2014

New PCI Guidance for Third-Party Risks

The PCI Council has unveiled new guidance for mitigating payment card risks posed by third parties. Troy Leach, the council's CTO, explains how banking institutions and merchants can put the guidance to use.

Aug 7, 2014

Putting CyberVor in Perspective

That Russian hackers may be hording 1.2 billion credentials merely reflects the insecurity of the world we live in today, says David Perry, threat strategist at the Finnish IT security company F-Secure.

Aug 7, 2014

Waging a War Against Healthcare Fraud

Healthcare fraud will increasingly be linked to some form of cybercrime, says Brendan Johnson, U.S. attorney in South Dakota, whose office is ramping up its anti-fraud efforts.

Aug 7, 2014

Will Low-Cyber Diet Improve Security?

Ex-Navy Secretary Richard Danzig likens society's growing dependence on IT to surviving on a diet of poisoned fruit. He says we're taking risks with critical cybersystems that ultimately can cause irreparable harm.

Aug 6, 2014

Targeted Attacks: Raising Risk Urgency

Detecting and preventing advanced attacks isn't just a technology issue - it's a business risk that needs to be elevated to the highest levels of an organization. Trend Micro's Tom Kellermann shares strategies.

Aug 5, 2014

Assessing Controls: A NASCAR Lesson

In devising advice to help organizations identify which information security and privacy controls to adopt, NIST risk management expert Ron Ross, a NASCAR fan, looks to the way mechanics decide how to fix a car.

Aug 4, 2014

'Internet of Things' Security Analysis

Vendors are rushing useful new "Internet of Things" products to market, but too often treat device security and data privacy as an afterthought, says Forrester Research analyst Andrew Rose.

Aug 1, 2014

Fighting Back Against Retail Fraud

Financial institutions feel the pain of recent retail breaches, and they seek new ways to secure payments and fight fraud. But how can security leaders influence changes within their own organizations?

Jul 30, 2014

Banks as Cybercrime Fighters?

Karl Schimmeck of the Securities Industry and Financial Markets Association won't discuss reports about the group's alleged backing of the formation of a cyberwar council, but says financial institutions must play a role in protecting critical infrastructure.

Jul 29, 2014

'Masquerading': New Wire Fraud Scheme

A new impersonation scheme is taking aim at business executives to perpetuate ACH and wire fraud, says Bank of the West's David Pollino, who explains steps institutions should take now to protect their customers.

Jul 28, 2014

Shaping a Cloud Services Contract

As a customer, Delaware Chief Security Officer Elayne Starkey has seen the evolution of cloud computing over the past three years to a point where she has more sway over the security terms of cloud services contracts.

Jul 24, 2014

Big Lessons in Small Data

Big data has been the recent buzz in security circles, but what are organizations missing by overlooking the power of "small data?" Verizon's Jay Jacobs discusses how to get the most from data analytics.

Jul 23, 2014

Application Security: The Leader's Role

Attackers increasingly focus on software vulnerabilities in what application security expert Anthony Lim calls "the invisible onslaught." How can the CISO exert more control over software development?

Jul 23, 2014

Attack Response: Before, During, After

Attacks are more frequent, severe and complex. How can security pros defend against the entire attack continuum - before, during and after? Cisco's Bret Hartman describes a threat-centric approach.

Jul 22, 2014

Card Fraud: Why Consumers Don't Get It

New research shows consumers believe online purchases are more secure than those made at bricks-and-mortar retailers. Researcher Shirley Inscoe of Aite explains why misconceptions about card fraud should be worrisome to banks.

Jul 22, 2014

The Analytics-Enabled SOC

To detect and deter today's threats, security teams need new and dynamic data analytics capabilities. Haiyan Song of Splunk discusses the analytics-enabled SOC and how to improve incident response.

Jul 21, 2014

Art Coviello: Divided We Fall

"United we stand; divided we fall." That's the message from Art Coviello to kick off the 2014 RSA Conference Asia Pacific & Japan in Singapore. What advice does the RSA chair offer to global security leaders?

Jul 18, 2014

Testing Your APT Response Plan

Enterprises should test the processes they establish to respond to advanced persistent threat attacks, just as they vet their <b><a href='https://www.inforisktoday.com/business-continuitydisaster-recovery-c-76'>business continuity</a></b> plans, ISACA International President Robert Stroud says.

Jul 15, 2014