PLAY PODCASTS
RSAC

RSAC

211 episodes — Page 3 of 5

What is DevSecOps and why is it important?

Integrating security into the development lifecycle can be a challenge, especially for those who don’t understand why security matters to development and operations. What’s the ROI of DevSecOps? What are the key KPIs? Join us for an insightful conversation that explains why DevSecOps is important while shining a spotlight on some DevSecOps bloopers to avoid. Our guests will also expose the cost of bad DevSecOps and offer suggestions for how to measure developers on security. Speakers: Keenan Skelly, CEO, Shadowbyte Stephanie Simpson, Vice President of Product, SCYTHE

Jun 17, 202218 min

Affirming LGBTQ Populations in Virtual Health through DevSecOps & Software Integrity

Virtual health providers create favorable conditions for the LGBTQ population's access to healthcare, an influx of electronic personal health information, and massive increases in cyber threats. Using software flaws, bad actors increasingly target healthcare systems to steal, monetize, and affect availability of data. This session explores software integrity and DevSecOps approaches to secure highly interconnected digital healthcare systems. Speakers: Safi Mojidi, Head of InfoSec, FOLX Health Kacy Zurkus, Content Strategist, RSA Conference

Jun 2, 202230 min

Get Your Head IN the Clouds: SOC Teams Must Live in Clouds to Secure Them

Massive cloud proliferation has driven huge increases in IT and security complexity, the vast majority of which come from trying to force fit legacy concepts, processes and even tools, into a cloud context. This will cover the most important considerations and requirements facing organizations to adequately understand and affect their new reality – and evolve their security thinking. Speakers: Nipun Gupta, Senior Security Leader, Devo Sounil Yu, CISO and Head of Research, JupiterOne Kacy Zurkus, Content Strategist, RSAC

May 9, 202235 min

The Cloud First BISO

Leading and guiding a data-driven security program as a BISO can be challenging. Data is everywhere and owned by many departments. Once a BISO has found that data they need, they must overcome the challenges of data access, storage, normalization and all the other steps required to turn that data into an actionable story. Fortunately, the Cloud can make this easier and faster. Speakers: James Binford, Director and Business Information Security Officer, Humana Ashish Rajan, Host of Cloud Security Podcast & SANS Trainer, Cloud Security Kacy Zurkus, Content Strategist, RSAC

May 3, 202230 min

How Threats in Today’s Landscape Can Be Exploited (And Avoided)

What does an attacker need to do to exploit a threat? Join us to discuss the TTPs attackers are using to exploit myriad threats in today’s threat landscape. Our guests will look across different sectors to understand new and emerging threats, how those threats can be exploited, and steps organizations can take to avoid being the next victim of a cyberattack. Speakers: Jerone Jones, Founder, JustOne Solutions, LLC Alexiaa Jordan, Cyber Security Consultant, JustOne Solutions

Apr 9, 202228 min

Defending with Passion: Cultivating a Passion for Evolving as a Cyber Defender

The technology we work to secure is ever evolving, as are the threat actors that are out there trying to exploit those technologies. Hence, the challenge we face today with securing and then defending those advances in technology requires people that are just as excited about learning how to defend that new technology as someone once was about creating it. There is absolutely someone out there that is passionate about hacking their way into that new technological advancement, no matter what it is. Join this podcast to learn what motivates hackers and how to help instill a passion for defending against cyber threats in the members of a security team. Speakers: Tiffiny Bryant, Cyber Security Analyst, Crystal Clear Technologies, Inc Kacy Zurkus, Content Strategist, RSAC

Mar 29, 202219 min

SBOM: Where We’ve Come From, and Where We’re Going

Across the security world, there’s a growing appreciation about the need to better understand our software supply chain. Transparency won’t solve all our problems, but will lay a foundation for greater resilience and more informed decisions. This discussion will review the basics of SBOM, using the recent log4j vulnerability to understand how SBOM can help across the software ecosystem—and also understand its limits. We’ll also delve into the future of SBOM, exploring some of the gaps, where we need to focus to advance the state of the art. Our ultimate goal should be the integration of SBOM into the broader vulnerability and security data ecosystem through automation. Speakers: Allan Friedman, Senior Advisor and Strategist, CISA Kacy Zurkus, Content Strategist, RSA Conference

Mar 21, 202222 min

Zero-sum Security: Zero Trust is Compromised as Long as Passwords Remain

Furthering the White House Cybersecurity EO, the OMB just released a Zero Trust Architecture Strategy with one of its 5 pillars focused on identity, and requiring implementation of strong, phishing-resistant MFA for agency and citizen access. This session explores the gatekeeper role of identity in ZTA, and the business and technology challenges faced in managing access while passwords persist. Speakers: Mario Duarte, Vice President of Security, Snowflake Tom (TJ) Jermoluk, CEO and Co-Founder, Beyond Identity Kacy Zurkus, Content Strategist, RSA Conference

Mar 9, 202233 min

Beware AI Landmines: Legal and Policy Considerations Revisited

In 2021, artificial intelligence emerged as a viable technology, which warranted a conversation about the legal and policy considerations underlying modern society. We’ll look back at the ethical, legal, and policy considerations discussed in May of 2021 and ask where are we now? What more needs to be done in order to maximize a successful implementation and minimize potential risk? Speakers: Behnam Dayanim, Partner, Global Chair of Privacy & Cybersecurity Practice and Chair, Advertising & Gaming Practice, Paul Hastings LLP Kacy Zurkus, Content Strategist, RSAC

Feb 18, 202225 min

The Road to Smart Cities is Paved with Good AI Intentions

In a world where the terms “AI” and “machine learning” are used liberally to describe new products and technologies, creating an assessment framework for buyers (and sellers!) to evaluate these products is essential. In this session, we’ll follow the Cost and Vulnerability dimension of MITRE’s AI Relevance Competence Cost Score (ARCCS) Framework and consider the security and privacy implications of AI for smart cities and the humans that travel them. Speakers: Anne Townsend, Department Manager and Cybersecurity Engineer, The MITRE Corporation Kacy Zurkus, Content Strategist, RSAC

Feb 16, 202222 min

What’s Trending in Protecting Data & the Supply Chain

Protecting Data & the Supply Chain so deeply intertwined with everything from software to identity. Join Program Committee members Edna Conway and Diana Kelley as they discuss the challenges that folks are struggling with right now and some potential mitigation strategies. We'll explore what’s happening with Log4j and other vulnerabilities as well as the need for a software Bill of Materials (SBOM). Speakers: Edna Conway, Vice President, Security & Risk Officer, Azure, VP, Chief Security & Risk Officer, Azure Microsoft Diana Kelley, CTO and Co-Founder, SecurityCurve Kacy Zurkus, Content Strategist, RSAC

Feb 1, 202239 min

Cybersecurity? Isn't it really the Data Care industry?

Countless conversations with students, politicians, and leaders about cybersecurity suggest that the term ‘cybersecurity’ does not invoke the personal sense of responsibility necessary, nor is it inviting to the majority of the public including minorities, women and young adults who we want to seek a career in this field. How do we change that? Let's start with Data Care. In this podcast, our guests will discuss what’s missing from the term ‘cybersecurity’ and how taking a ‘Data Care’ approach can help us all to build a more secure world. Speakers: Britta Glade, Senior Director, Content & Curation, RSA Conference Ron Gula, President, Gula Tech Adventures Cyndi Gula, Managing Partner, Gula Tech Adventures

Jan 19, 202229 min

Privacy Tech: The Crossroads of Cybersecurity

The Rise of Privacy Tech (TROPT) recently released a whitepaper categorizing the privacy tech landscape. It explores privacy tech's relationship to its adjacent industries, which include cybersecurity, identity management, and data governance, among others. Join this podcast for a look at key takeaways and insight into the 8-month-long working group drafting process. Speakers: Lourdes Turrecha, Founder and CEO, The Rise of Privacy Tech Kacy Zurkus, Content Strategist, RSAC

Dec 10, 202123 min

What Do We Owe Each Other? Securing Systemic Dependencies and Beyond

Recognizing that the security of our interconnected world is as interdependent and fragile as a Jenga puzzle, how do we ensure that the entire system doesn’t fall apart when a single block is pulled? What do we ow each other, and how do we work together to ensure those organizations—be they non-profits, NGOs, or public schools and institutions—have the resources they need to be resilient in the face of a cyberattack? In this podcast, we’ll examine the security poverty line and our systemic dependencies and explore what we owe each other in order to ensure a more secure world. Speakers: Dr. Kelley Misata, Founder and CEO, Sightline Security Kacy Zurkus, Content Strategist, RSAC

Dec 8, 202119 min

Informed Consent in the Age of Big Data

How much responsibility should people really bear in the big data realm? Does informed consent equate to waiving rights? Is it realistic that they understand how data travels and is there an incorrect underlying assumption that data is their priority when they are consenting to its collection or use? In this podcast, we will examine the reasons people sign consent forms (to access care or information), the limited ability of informed consent to protect people from hacking and cybersecurity breaches, and its irrelevance to compensating people whose data is aggregated, sold, and resold. We will explore the limitations of informed consent in governing data collection and use in the healthcare arena. Speakers: Anne Zimmerman, Founder, Modern Bioethics Kacy Zurkus, Content Strategist, RSAC

Nov 16, 202121 min

Privacy Top of Mind at RSAC 2022

The Program Committee for the RSAC 2022 Privacy track was challenged with selecting the top session that would make it onto the agenda, but privacy topics were not limited to this one track. So why is privacy trending, and what are this year’s privacy trends? Join two members of the Privacy Program Committee as they reveal their favorite picks and what attendees have to look forward to at Conference. Speakers: Bernard Brantley, Chief Information Security Officer, Corelight Francesca Ginexi, Privacy Policy Manager, Facebook Kacy Zurkus, Content Strategist, RSAC

Nov 15, 202119 min

Shift-left! Scanning for Security Compliance from Day Zero

Migrating to public cloud introduces new attack surfaces commonly the exploitation of misconfigured resources. In a cloud landscape that contains millions of resources, how do we detect these threats. This session explores the journey from security policy documentation to scanning and detecting security compliance violations in product infrastructure from the start of the development life cycle. Joe McCrea, Cloud Security DevOps Engineer, SAP Mariam Triki, DevSecOps Engineer, SAP Kacy Zurkus, Content Strategist, RSAC

Oct 12, 202129 min

Cloud Security & Cloud Sec Ops: Trends that Matter Most for 2022

The importance of cloud security has, perhaps, never been more critical, following massive shifts to remote workforces and ramped up digital transformation across organizations of all sizes. In this podcast, two members of the Cloud Security & Cloud Sec Ops Program Committee discuss trends observed in their selection process for 2022 RSA Conference and what matters most as organizations look to secure and further mature their multi-cloud and hybrid deployments. Speakers: Britta Glade, Senior Director, Content & Curation, RSA Conference Shawn Harris, Director, Information Security, Starbucks Rich Mogull, CEO/CISO, Securosis

Oct 8, 202133 min

Turn It Up to 11: MITRE’s 11 Strategies for a World Class Cybersecurity Operations Center (CSOC)

Refreshed and updated to include the latest technologies and best practices in cybersecurity operations, guests will share key takeaways from the new 11 Strategies for Operating a World Class Cybersecurity Operations Center (CSOC) book that will be coming out later this year. We will discuss the 11 strategies, how to balance the CSOCs core incident response mission with supporting functions such as threat intelligence and threat hunting, the importance of growing staff in house, and why the CSOC can never stop evolving. As with the original book, this new edition will include a free electronic version available to everyone. Speakers: Kathryn Knerler, Department Manager, Cyber New Professionals Development Program, The MITRE Corporation Ingrid Parker, Chief Engineer, Homeland Security Enterprise Division, The MITRE Corporation Kacy Zurkus, Content Strategist, RSAC

Sep 27, 202130 min

Pay What You Owe: Fiduciary Duty and Ransomware

In today’s world, data is currency. With that in mind, organizations need to consider the fiduciary duty they owe to data subjects, especially when they suffer a ransomware attack. This session outlines what types of fiduciary duties organizations have, why paying a ransom falls under those duties, how negotiations mitigate harm, and three steps for effectively responding to a ransomware attack. Speakers: Robert Fitzgerald, Founder and CEO, Arcas Risk Management Karen Walsh, CEO and Founder, Allegro Solutions Kacy Zurkus, Content Strategist, RSAC

Sep 9, 202142 min

Cybersecurity Jobs that Don't Require a Cybersecurity Background

Have you been wondering how to get into Cybersecurity? It may seem that you have to be a security tester or expert. It's not true! There are many paths into Cybersecurity using your existing experience, skills, and schooling. This talk will show the multiple paths people have followed into the Schneider Electric IT Security and Application Security organizations. Cassie Crossley, Director, Product Security Office, Schneider Electric Kacy Zurkus, Content Strategist, RSAC

Aug 23, 202125 min

Leveling Up Your Career

You've gotten the job in tech—congrats! So now what do you do? We’ve heard stories from those who struggled with overcoming unexpected obstacles while new to the job. Let’s talk about what you can do to prepare for the unexpected. In this podcast, you’ll hear from an industry expert on ways to level up your career. This talk will provide various tools and resources to help navigate the tech space and make the most of what you have and help you in reaching your future goals. Speakers: Mari Galloway, Chief Executive Officer and Founding Board Member, Women’s Society of Cyberjutsu Kacy Zurkus, Content Strategist, RSAC

Aug 13, 202121 min

Thinking about Android – A Multi-Faceted Discussion

Humans engage with Android technology in myriad ways, but how has the technology been used to date and how is it evolving? This podcast will explore the ways in which the Android ecosystem has evolved by looking at Android from a techno-sociological, security, and privacy context. We will discuss dimensions of privacy, the impact Android has had on humans, the kinds of threats we are seeing in the wild, the security challenges that need to be addressed, and the evolution of features like Digital Well Being. Speakers: Aditi Bhatnagar, Product Security Engineer, Atlassian Kacy Zurkus, Content Strategist, RSAC

Jul 26, 202127 min

Trust, but Verify: Maintaining Democracy Despite Информационные контрмеры

In this podcast, we discuss how countries have influenced worldwide elections historically and in modern day using cyberwarfare. We explore how countries and critical infrastructure respond to these attacks and how they should respond in the future. By the end, we brainstorm the ways to disrupt a future election in order to understand how to better protect it. Geoff Hale, Senior Cybersecurity Advisor, Cybersecurity and Infrastructure Security Agency Allie Mellen, Analyst, Security and Risk, Forrester Research

Jul 22, 202134 min

The Ransomware Paradigm Change — Lessons from Insurers and Breach Coaches

Throughout 2020, ransomware was consistently amongst the most challenging cyber exposures for organizations to manage. The insurance market can provide critical insights on how to understand the evolving ransomware landscape, given the volume of insurance claims being seen and emerging data on loss and exposure trends. This session will bring together experts from across the cyber insurance and breach coach space and give end to end insights on the financial and organizational impact of ransomware, risk implications, and challenges that will be seen in the market. Speakers: Marcello Antonucci, Global Cyber & Tech Claims Team Leader, Beazley Benjamin Di Marco, Cyber Specialist, Willis Towers Watson Christina Terplan, Founding Partner and President, Atheria Law This episode is brought to you by Axonius. Axonius helps organizations immediately know what assets they have, and shows which devices, cloud instances, and users adhere to or deviate from security policies. Try it free at axonius.com/rsac

Jun 23, 202149 min

Hunting Sodinokibi: Insights from Tracking the King of Ransomware

Drawing on original research, the speakers will dive deep into one of the most prominent ransomware strains today: Sodinokibi/REvil. By tracking its operators’ activity in affected organizations, on the dark web, and through the group’s public blog, we will bring our collective insights to the audience, detailing how Sodinokibi operates, its malware uniqueness, and the damage it has inflicted. Speakers: Limor Kessem, Executive Security Advisor, IBM Security Camille Jackson Singleton, Strategic Cyber Threat Lead, IBM Kacy Zurkus, Content Strategist, RSAC

Jun 6, 202131 min

Who’s Driving Your Security Architecture Bus?

With the increased scale and pace of automated processes along with migrations to the cloud, proper design of security architecture becomes a critical component of your overall IT architecture implementation. Considering this, what should your business prioritize as the ultimate driver for security architecture decisions - and where does risk, privacy and compliance fit into the picture? Speakers: Shinesa Cambric, CISSP, CISA, CISM, CDPSE, Principal Program Manager, Microsoft Aparna Murthy, Aparna Murthy, CA, CPA, Principal Risk and Compliance Consultant Kacy Zurkus, Content Strategist, RSAC

May 25, 202135 min

The Journey Toward a Singular Security Framework: Lessons from Finland

Turku Energia - a Finnish energy distribution company - secured its power supply & IT network for the city’s 200,000 citizens. Utility SCADA systems are hacking targets, due to the damage that can be inflicted by sending cities dark or damaging the grids. The utility’s IT team ensured data integrity, visibility, and rapid threat detection and remediation within both IT and OT environments. Speakers: Vikram Sharma, Senior Engineering Manager, IoT, Cisco Kacy Zurkus, Content Strategist, RSAC

May 13, 202120 min

The Art & Science of Using Cybersecurity Talent Frameworks & Taxonomies

Study after study shows cybersecurity job descriptions lack clarity across most roles and industries — stifling talent recruitment, development and retention efforts. Infosec Institute and Aspen Cybersecurity Workforce Coalition will provide data-backed insights into how organizations are aligning job descriptions and training to tools like the NICE Framework, including what’s working and what’s not. Speakers: David Forscey, Senior Policy Analyst, National Governors Association Megan Sawle, VP of Research & Marketing, Infosec Kacy Zurkus, Content Strategist, RSA Conference

Apr 22, 202131 min

Catch a Hacker if You Can: Social Engineering Meets Risk Mitigation

Rachel Tobac hacks people based on publicly available information. Camille Stewart encourages people to mitigate risk and defend against Rachel’s methods. We’re bringing these two industry leaders together for this one-of-a-kind podcast that will explore social engineering risks and highlight some best practices to help protect users and organizations. Presenters: Camille Stewart, Cyber Fellow, Harvard Belfer Center and Head of Security Policy, Google Play & Android, Google Rachel Tobac, CEO, SocialProof Security, White Hat Hacker Kacy Zurkus, Content Strategist, RSA Conference

Apr 13, 202127 min

Fraud on the Rise! An In-Depth Look at the FBI’s 2020 Internet Crime Report

The FBI’s Internet Crime Complaint Center received more than 791,000 complaints in 2020—a record number, representing a 69% increase over 2019. Join us for an in-depth discussion as we examine details of the report with FBI’s Cyber Division's Deputy Assistant Director Herb Stapleton. Speakers: Herb Stapleton, Deputy Assistant Director, Cyber Division, FBI Kacy Zurkus, Content Strategist, RSA Conference

Mar 25, 202124 min

Reduce the Cybersecurity Risks for Property Management Systems through Secure Payment Practices

Hotel chain data breaches have resulted in huge financial loss and reputational harm. Unlike other consumer-facing businesses, such as retail stores, hotels must hold onto payment card data for extended periods passing this valuable data among many participants in the payment security ecosystem as customers make reservations and complete travel. In this podcast, our guests will identify and discuss how organizations can reduce the risks associated with handling payment card information for hotels and, in turn, begin to strengthen the cybersecurity of the property management system (PMS). For more information, visit NIST’s project on Securing Property Management Systems. https://www.nccoe.nist.gov/projects/use-cases/securing-property-management-systems Speakers: John T. Bell, Founder and Principle Consultant, Ajontech LLC Arshad Noor, CTO, StrongKey Bill Newhouse, Cybersecurity Engineer, National Cybersecurity Center of Excellence (NCCoE) Kacy Zurkus, Content Strategist, RSA Conference

Mar 22, 202142 min

Detect BEC and Vishing Attacks Before the Deal Is Done

Business email compromise (BEC) has made a comeback. Vishing calls have proven profitable for cybercriminals as well. How can you stay ahead of these threats and detect fraud before any money is sent? Join us for a podcast that discusses how these attacks work, who they target and why. Our guests will also offer tips on what to do both professionally and personally to limit risk—from small things like training those who are handling the financial transactions to working with the banks and the cyber team. Speakers: Nicole Beckwith, Staff Cyber Intelligence Analyst, GE Aviation Ursula Cowan, Threat Research Analyst, FireEye/Mandiant Kacy Zurkus, Content Strategist, RSA Conference

Mar 16, 202129 min

Could 2021 Be the Year of Product Security?

In the industrial space, we’ve seen more organizations bringing in Chief Product Security Officers—with good reason. Security needs to be baked into the products that companies are delivering to customers, particularly when there is a life/safety impact. But the need for product security extends beyond ICS and OT. Join us with our guests Megan Samford and Patrick Miller who will look at why product security is the new frontier of the cybersecurity industry. Presenters: Patrick Miller, Founder, Director & President Emeritus, EnergySec and US Megan Samford, Chief Product Security Officer, Schneider Electric Kacy Zurkus, Content Strategist, RSA Conference

Feb 22, 202127 min

Rising Flaws, and Slow to Fix: What’s at Stake for Software Security?

The majority of applications contain at least one security flaw and fixing those flaws typically takes months. Automating scanning and scanning via API can help development teams fix faster by a pretty wide margin. Veracode’s Chris Eng and Cyentia’s Jay Jacobs explore what’s driving the volume of code flaws, what factors influence fix rates, how organizations with higher fix rates are tackling the problem successfully, and automation as a best practice for DevSecOps and an action developers can take to "nurture" their apps to better security. Presenters: Chris Eng, Chief Research Officer, Veracode Jay Jacobs, Co-Founder and Chief Data Scientist, Cyentia Institute Kacy Zurkus, Content Strategist, RSA Conference

Feb 9, 202124 min

How to Apply Pandemic Principles to Battle Cyber Outbreaks

Principles of epidemiology can be effectively applied to cyber security, with some adaptations. What do travel quarantines and firewalls, social distancing and port closures have in common? Learn how much cyber incident responders can learn from the recent pandemic that effectively shut down so many of the human connections in the modern world. Presenters: Steve Faruque, Cyber Security Manager, IBM Dr. Manisha Juthani-Metha, Associate Professor of Medicine and Epidemiology and Infectious Diseases Specialist, Yale School of Medicine and Yale New Haven Hospital Kacy Zurkus, Content Strategist, RSAC This podcast is sponsored by Axonius. Axonius is the cybersecurity asset management platform that gives organizations a comprehensive asset inventory, uncovers security solution coverage gaps, and automatically validates and enforces security policies.

Jan 13, 202147 min

What's Trending with Hackers & Threats

The submissions and decisions have been made. The Program Committee’s selections will soon be announced. Before that happens join me and two members of a Hackers & Threats PC to discuss what trends they saw come through in this year's RSA Conference submissions. They'll also give a sneak peak into what attendees of RSAC 2021 have to look forward to on the Hackers & Threats track. Greg Day, VP and Chief Security Officer, EMEA, Palo Alto Networks Nicole Little, Walt Disney Studios Kacy Zurkus, Content Strategist, RSA Conference

Dec 14, 202025 min

The Geopolitics of Cyber (In)security

TikTok and Huawei are probably two of the most notable Chinese technology companies that are enveloped in policy debates. The US government's most recent actions against TikTok could be an indication of future actions that could be taken against Chinese technology companies. Join us for the important discussion about how geopolitical motivations impact technology regulations and international interference operations. We'll look at how Western businesses are changing their technology development, operations and staffing strategies in Greater China and much more. Gabo Alvarado, Managing Director, Pointe Bello Katherine Koleski, Program Analyst, Defense Innovation Unit Aaron Turner, President and Chief Security Officer, HighSide Kacy Zurkus, Content Strategist, RSAC

Dec 9, 202035 min

Mind the Gap: Strategies for Finding and Retaining Cyber Talent

Sometimes the greatest obstacles we must overcome are the ones we put in front of ourselves. It’s no different for businesses or even for an entire industry. In cybersecurity, one of the greatest barriers to entry could be the perception people have of what cybersecurity is. Many outsiders believe a job in cybersecurity equals sitting in front of a screen and coding all day. So, how do we rebrand ourselves in order to develop talent from various diverse sources? Join us to discuss different strategies for addressing the talent shortage.

Nov 12, 202031 min

Increasing Threats to OT/ICS Assets Need a Robust Cybersecurity Program

What is OT systems management and why is it so critical to protecting our critical infrastructure? What are the necessary controls to ensure ICS/OT cybersecurity? A comprehensive program includes a range of controls and design efforts, In this podcast, industry leaders will discuss the challenges and requirements of protecting Operating Information Technology systems, which includes the need for establishing OT Systems Management, a holistic approach to hardening, updating, maintaining, and monitoring the endpoints and networks in industrial environments.

Nov 11, 202029 min

Election Security Concerns, Expectations and How You Can Get Involved

Though concerns over election security did not begin with the 2016 Presidential election, new and emerging threats coupled with an expanding attack surface have exacerbated what were already major security concerns for municipalities, states and the federal government. So what is the current risk environment and what has changed in CISA and the FBI’s cyber missions? We’ll answer these questions and offer tips on how the tech community and citizens can get involved in this can’t miss podcast.

Oct 22, 202043 min

Networking with the Right People

Networking has many advantages and has the potential to open doors of opportunity, but how do you identify the right people to network with? What do you bring to the table and what are you looking for from others? Join us for an engaging exchange with two industry leaders who will share their perspectives on the value of education, experience and relationship building. They’ll share advice on how to meet security practitioners, motivate other, be a well-rounded worker and an industry influencer.

Oct 12, 202033 min

Zero Trust Architecture: The Defacto Network Segmentation Approach

Agility is not a strategy, and Zero Trust is not a product you can buy. In a Zero Trust approach as identity becomes more important than ever, managing the lifecycle correctly is critical, during provisioning, use as well as destruction. These are some of the reasons why Zero-trust architecture is becoming the defacto segmentation approach in our digital-first world. Interrelated are the opportunities in both Edge Computing and DevSecOps to help businesses differentiate products and services by transitioning to more collaborative and risk-based security. Join us as we discuss Zero Trust, DevSecOps and Edge Computing with two industry experts who will explore the ways in which these approaches to customer-centric transformation can help businesses stay competitive.

Sep 29, 202035 min

Proactive Steps to Securely Build for the Future

COVID-19 has forced enterprises to adopt new ways of working in order to ensure their data remains protected as they navigate the impacts of the global pandemic and manage a distributed workforce. As more employees work remotely and an organization’s attack surface area increases, it’s never been more important to invest in security. At the same time, IT budgets are shrinking and security is at risk of being deprioritized or compromised in this new reality, where many employees are working from home and not on secure corporate networks. The only way to protect organizations is by protecting your endpoints, and in this podcast, we’ll discuss how adopting a zero-trust strategy can help organizations quickly adapt and prepare for a different post-pandemic world.

Sep 21, 202024 min

How Diversity is Key to Risk Management

As Camille Stewart wrote, “Cyber diplomacy and international cyber capacity building are better served by having diverse representation that understands the cultural nuances that determine how technology will move through a society.” Similarly, when it comes to managing security risk management programs, diversity matters. Risk management has many challenges, which is why a team can only be enriched and strengthened by including those with a vast range of experiences. There is no one-size-fits-all when it comes to risk management, however being attune to issues of race and other forms of discrimination and how they manifest themselves in their work, will result in building better programs. In this podcast, we will hear from esteemed industry experts who will share their different perspectives on why diversity matters to risk management and the consequences of not addressing the lack of diversity in cybersecurity and risk management.

Aug 25, 202024 min

Why Your Security Organization Needs a Communications Lead

Having a communications person as part of the security organization ensures that the enterprise communicates security not only through awareness programs but also across silos. A security communications lead plays a critical role in developing and executing incident response plans as well as other security policies that impact the business. In order to effectively create a security aware culture, your security organization needs to be able to communicate the risks, the strategies to mitigate risks and the policies that must be followed in the event of a security incident. People need to understand their roles and responsibilities, which need to be clearly communicated. In this podcast, we will hear from industry experts who will help you understand the value of and implement good, clear security communications.

Aug 19, 202030 min

“Robot Downsizing”—How the Ultimate Solution to Security is Human

Security vendors come to the rescue with AI and automation to save the day. But even smart technology can only go so far, and while it can definitely help lessen the noise, it can never replace the intuition, inventiveness and insight of a human.Technology can’t replace humanity in security defense because endpoint lockdowns don’t work, and repetitive scenarios don’t advance anything but boredom. Rather, we need to give users the tools to be skeptical, aware and intuitive. Analysts need to find patterns in the process, not just the results. Security teams need to work together and across an environment to find what can be fixed, not just what individuals can break, and technology needs to assist, amplify and augment human behavior, not lead.

Jul 21, 202036 min

Researcher Relations: Building Trusted Relations Between Security Researchers and Organizations

Security is one of the most evolving and impactful landscapes in the regulatory sphere. Proposed initiatives in the areas of Internet of Things (IoT) security and Coordinated Vulnerability Disclosure (CVD) are among the most active and developing areas of security regulation around the world. The vulnerability disclosure landscape has been rapidly evolving for the past decade, but there’s still a way to go. In this podcast, we’ll talk with industry experts about policy trends and how to build trust and understanding so that developers, researchers and vendors can all work in harmony toward the goal of promoting security. Highlights will include researchers’ collaboration, IoT Security, anti-hacking laws. We will also talk about bug bounties and vulnerability disclosure programs, what are some of the industry's best practices in this area, and how to implement programs at your organization to foster security, collaboration and transparency.

Jul 9, 202038 min

Contact Tracing: Ethics in Privacy and Technology in a Post COVID World

As the world continues to navigate what a “return to work” environment will look like and how that will play out for businesses, many are concerned about contact tracing, their role in becoming a point of contact and the privacy concerns inherent in the collection of all that data. In this podcast, we will be talking with privacy experts who will discuss how legislative proposals are responding to specific trends/worries in pandemic data response. While both are a bit bearish on any actual legislation being passed at the state/federal level, there are generalized privacy concerns that companies and employers would be wise to consider as we try to open post-COVID.

Jul 1, 202034 min

We're Facing a Remote Working Future and It's a Security Opportunity

Pieter Danhieux and Fatemah Beydoun both have a long history of working remotely, but as their company moved to a completely remote work environment in response to the COVID-19 global pandemic, it presented its own set of challenges... along with some very compelling benefits. This unprecedented situation has shown many companies that remote work is not only possible, it's the future. And it's a great opportunity to improve cybersecurity and general security awareness. In this podcast, Pieter and Fatemah detail how remote teams can be effective and secure, the benefits of access-anywhere collaboration tools and cybersecurity training, and how the time won back from eliminating commutes can be used to bolster a workforce to weather larger storms, including improving development practices and considering security much earlier. With cyberattacks on the rise, it's a great time to assess and improve your security culture.

Jun 15, 202032 min