Player FM - Internet Radio Done Right
Checked 2M ago
추가했습니다 two 년 전
Adopting Zero Trust에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Adopting Zero Trust 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!
Player FM 앱으로 오프라인으로 전환하세요!
들어볼 가치가 있는 팟캐스트
스폰서 후원
<
<div class="span index">1</div> <span><a class="" data-remote="true" data-type="html" href="/series/series-2996722">The So What from BCG</a></span>


This podcast from Boston Consulting Group looks around the corner of today’s big business and social issues. The goal–the so what–is to make sense of today and prepare busy leaders and executives for the day after tomorrow. Award-winning British journalist Georgie Frost interviews the leading thinkers and doers at BCG on the trends, developments, and ideas that will shape and disrupt the future. This is not your typical business strategy podcast. This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp
Adopting Zero Trust
모두 재생(하지 않음)으로 표시
Manage series 3462572
Adopting Zero Trust에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Adopting Zero Trust 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Adopting Zero Trust offers an ongoing conversation that elevates cybersecurity conversations that encourages you to rethink how you build strategies, defend against threat actors, and implement new technology. We go beyond the millions in marketing budgets fueled by VCs, and chat with practitioners like you who want to make a difference (or hack the planet, which ever happens first).
…
continue reading
56 에피소드
모두 재생(하지 않음)으로 표시
Manage series 3462572
Adopting Zero Trust에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Adopting Zero Trust 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Adopting Zero Trust offers an ongoing conversation that elevates cybersecurity conversations that encourages you to rethink how you build strategies, defend against threat actors, and implement new technology. We go beyond the millions in marketing budgets fueled by VCs, and chat with practitioners like you who want to make a difference (or hack the planet, which ever happens first).
…
continue reading
56 에피소드
Alle episoder
×A
Adopting Zero Trust

1 How Critical Infrastructure Leaders Are Rethinking Cybersecurity 44:32
44:32
나중에 재생
나중에 재생
리스트
좋아요
좋아요44:32
In this episode of Adopting Zero Trust, hosts Elliot Volkman and Neal Dennis discuss critical infrastructure security with expert guest Ian Branson, Vice President of Global Industrial Cybersecurity at Black and Veatch. The discussion centers around the philosophical and strategic approaches to handling incidents and breaches, especially in the operational technology (OT) realm. Branson highlights the importance of understanding what needs protection, the integration of IT and OT security, and the crucial role of threat intelligence. They also explore the evolving need for converging physical and digital security data to manage risks effectively. 01:37 Starting Point for Protecting Critical Infrastructure 04:52 Funding and Resource Allocation for Cybersecurity 10:57 Threat Intelligence and Incident Response 16:25 IT and OT Convergence 23:47 Discussing Employee and Equipment Management 26:19 Integrating Physical and Cyber Security 34:39 Proactive Security Measures in New Constructions 40:46 Balancing Rapid Response and Availability…
A
Adopting Zero Trust

In this episode of Adoption Zero Trust (AZT), host Neal Dennis and producer Elliot Volkman sit down with Bradon Rogers, Chief Customer Officer at Island, to discuss how AI is compounding the already existing problems tied to shadow IT. The conversation explores how modern enterprises handle the growing complexities of unregulated software use, the role of enterprise browsers in mitigating risks, and the dynamic between user experience and cybersecurity. 01:16 Shadows within shadows 04:15 AI in Approved Solutions 09:14 Enterprise Browser and Security 14:25 Transition to Browser-Based Applications 16:23 Enterprise Browser Capabilities 18:45 Data Protection and Shadow IT 24:39 Shepherding Data in the Enterprise Browser 25:17 Policy Perspectives on AI and Data Flow 28:16 Exploring SBOM and AI Integration 35:39 Browser Security and Application Boundaries 41:40 BYOD and Privacy Concerns 44:48 Third-Party Scenarios and Onboarding…
A
Adopting Zero Trust

1 Live at ZTW2025: Cyberwire Daily’s Dave Bittner + Dr. Zero Trust 32:50
32:50
나중에 재생
나중에 재생
리스트
좋아요
좋아요32:50
Catch this episode on YouTube , Apple , Spotify , or Amazon . You can read the show notes here . Live from ThreatLocker’s Zero Trust World (ZTW), cybersecurity heavyweights Dave Bittner , host of CyberWire Daily and Dr. Chase Cunningham AKA Dr. Zero Trust shared their unfiltered thoughts on the state of cybersecurity, AI, and government regulations. From the shifting landscape of compliance enforcement to the role of hitting critical mass of AI in both defense and cybercrime, we can expect an extraordinary level of change in the years ahead. 01:37 Cybersecurity Landscape Overview 01:58 Government and Cybersecurity 02:39 Leadership and Appointments in Cybersecurity 03:47 Future of CISA and Compliance 06:41 Managing Cybersecurity News 14:54 The Role of LLMs in Cybersecurity 16:22 Global Perspective on AI and LLMs 18:47 Reflecting on Past Technological Predictions 20:18 The Double-Edged Sword of AI and Surveillance 24:21 The Dark Side of Technological Advancements 26:17 Debating the Term 'AI' and Its Implications 28:43 Historical Anecdotes and Unanswered Questions…
A
Adopting Zero Trust

1 Rapid fire update: Silk Typhoon and DOJ's indictment of twelve Chinese nationals 3:20
3:20
나중에 재생
나중에 재생
리스트
좋아요
좋아요3:20
New intelligence: Silk Typhoon, formerly tracked as HAFNIUM, is a China-based threat actor most recently observed targeting IT supply chains in the US. Today, we released a new report in conjunction with the Department of Justice's action against twelve Chinese nationals that includes mercenary hackers, law enforcement officers, and employees of a private hacking company. This group has been charged in connection with global cyberespionage campaigns. Dive into our latest blog for all the details.…
A
Adopting Zero Trust

1 Predicting the year of cybersecurity ahead (minus regulations) 1:02:52
1:02:52
나중에 재생
나중에 재생
리스트
좋아요
좋아요1:02:52
It’s mid-February, but somehow, we’ve already been through what feels like a year's worth of change in the cybersecurity and regulation world. Beyond the standard incidents, outages, and attacks… there have been obvious impacts that have downstream effects. Regardless of regulatory changes, which we’ll cover as those impact our space, AZT brought together a few minds who have thoughts on the year ahead. To properly kick off season four, we have the privilege of chatting with two wonderful guests: Lawrence Pingree , VP of Technical Marketing at Dispersive, but you are more likely to know his name from his time at Gartner. However, he has a varied background ranging from CTO to security engineer, so don’t let that marketing line in his title fool you. Oliver Plante , VP of Support at ThreatLocker, has around 15-20 years of IT under his belt. He also has seen a thing or two when it comes to implementing new cybersecurity strategies 03:21 Predictions for the Year Ahead 04:06 Zero Trust and Least Privilege 05:40 The Future of Cyber Defense 07:21 AI and Cybersecurity 08:41 Threat Intelligence and Preemptive Defense 09:50 Challenges and Innovations in Cybersecurity 14:23 The Role of AI in Cyber Attacks 26:18 Quantum Computing: Threat or Savior? 29:31 Passwordless Security: The Future 30:57 Challenges of Deepfake Technology and Passwordless Security 33:03 Blockchain and Its Applications in Security 35:33 Debate on Password Management Practices 38:03 User Responsibility and Security Automation 47:50 Government's Role in Cybersecurity 57:14 Future of Cybersecurity and Zero Trust…
A
Adopting Zero Trust

Catch this episode on YouTube , Apple , Spotify , or Amazon . You can read the show notes here . Neal and I are excited to welcome you back to AZT as we kick off our fourth season. After four years of trying out different formats and episodes, including at least an entire season terrorizing vendors for slapping Zero Trust on their box as if it were something you could buy, we’re ready to narrow our focus a bit.…
A
Adopting Zero Trust

1 The key to growing a cybersecurity career are soft skills 50:38
50:38
나중에 재생
나중에 재생
리스트
좋아요
좋아요50:38
In this episode of 'Adopting Zero Trust (AZT)', host Neal Dennis and producer Elliot Volkman delve into the often-overlooked realm of soft or 'non-tech' skills in cybersecurity. This week, we chat with Courtney Hans , VP of Cyber Services at AmTrust Financial Services, and Evgeniy Kharam , author of Architecting Success: The Art of Soft Skills, who help us explore how non-technical skills are vital in shaping the careers of cybersecurity professionals. Our guests share the importance of effective communication, emotional intelligence, and adaptability. The hosts and guests share personal anecdotes, training tips, and the necessity of bridging technical prowess with essential soft skills to improve stakeholder engagement and career advancement. The episode emphasizes the value of being comfortable with discomfort and soliciting feedback to enhance one’s professional journey in cybersecurity.…
A
Adopting Zero Trust

1 Behind the scenes of cybersecurity media and reporting 1:04:53
1:04:53
나중에 재생
나중에 재생
리스트
좋아요
좋아요1:04:53
Season 3, Episode 15: We gather a panel of journalists, communications, and a researcher to discuss how cybersecurity news and incidents are reported. You can read the show notes here . In the world of cybersecurity journalism, you can broadly divide it into four competing forces: reporters, communications teams, researchers, and readers. Each requires the other to accomplish its goals, but they all have very different priorities and goals. Journalists have a duty to inform the public about security-related events. Communication teams have a duty to inform the public about related incidents and research, but in a controlled setting. Researchers help provide answers to communication teams and journalists. Readers want to be informed of information that impact them, and their habits shape what kind of reporting is invested in the most. This week we explore some of these dynamics by bringing together a panel representing comms, journalism, and research to discuss the game of tug-of-war during incident response and incident reporting. Danny Palmer was a long-standing cybersecurity reporter at ZDNet prior to recently joining DarkTrace, Josh Swarz is the Senior Communications Manager at Microsoft focusing on threat intelligence, our host Neal Dennis is former NSA and has lived many lives around either keeping secrets or uncovering them, and producer Elliot Volkman has been a reporter for two decades and works with Josh on elevating research at Microsoft Threat Intelligence.…
A
Adopting Zero Trust

1 GRC tool or spreadsheets, that is the question | GRC Uncensored Preview 43:13
43:13
나중에 재생
나중에 재생
리스트
좋아요
좋아요43:13
In our final preview episode of GRC Uncensored, we explore a particularly bipolar debate: do you need a GRC tool to manage compliance, or will spreadsheets suffice? After this, we will be back to our regularly produced AZT episodes. The last episodes of our pilot for GRC Uncensored can be found on your favorite podcast app or newsletter on Substack.…
A
Adopting Zero Trust

1 Podcast Preview: GRC Uncensored and the commoditization of compliance 41:30
41:30
나중에 재생
나중에 재생
리스트
좋아요
좋아요41:30
We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored. This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks. ----- In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time. The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards. 00:00 Welcome to GRC Uncensored 01:34 Introducing Kendra Cooley 02:05 Love-Hate Relationship with GRC 03:16 The SOC 2 Debate 04:33 Challenges with SOC 2 Audits 09:10 The Value of SOC 2 in the Industry 12:04 The Evolution of Compliance Frameworks 20:39 False Sense of Security in Compliance 24:46 The Buzz Around AI and Quantum 25:10 Staying Updated as a Security Professional 26:45 Challenges in Penetration Testing and Vendor Assessments 27:37 Compliance and Its Impact on Security 30:10 Government Regulations and Their Effectiveness 32:23 The Complexity of Privacy Laws 38:29 The Role of GRC Teams in Risk Management 42:30 Concluding Thoughts and Future Episodes…
A
Adopting Zero Trust

Welcome back to Adopting Zero Trust! In this episode, hosts Elliot Volkman and Neal Dennis are joined by Rob Allen, Chief Product Officer of ThreatLocker, to dive deep into the operationalization of Zero Trust. Despite covering various aspects over three seasons, this crucial topic is addressed thoroughly. They explore pre-adoption preparation, aligning organizational actions, and the importance of education in security. Additionally, the conversation highlights the 'assume breach' perspective and how concepts like default deny and least privilege are essential. With real-world examples and anecdotes, they provide actionable insights on implementing Zero Trust strategies effectively. Tune in to learn about the foundational steps necessary to transition into a Zero Trust environment. This is the first of a three-part mini-series, so stay tuned as we explore more aspects of how to prepare your organization for adopting a Zero Trust strategy.…
A
Adopting Zero Trust

Season 3, Episode 13: Cato Network’s Etay Maor provides fresh research on the abuse of unpatched log4j libraries. Catch this episode on YouTube , Apple , Spotify , or Amazon . You can read the show notes here . This week on Adopting Zero Trust (AZT), we highlight a significant cybersecurity risk focused on the notorious Log4j vulnerability and the growing concern around shadow IT. Featuring expert insights from Etay Maor, the Chief Cybersecurity Strategist at Cato Networks, the conversation initially looks into the persistent exploitation methods, the importance of knowing one’s cybersecurity environment, and strategic approaches to mitigating risks.…
A
Adopting Zero Trust

1 Overturning of Chevron Deference’s Impact on Cybersecurity Regulation 51:44
51:44
나중에 재생
나중에 재생
리스트
좋아요
좋아요51:44
Season 3, Episode 12: Could the overturning of Chevron Deference impact cybersecurity and privacy regulations? Catch this episode on YouTube , Apple , Spotify , or Amazon . You can read the show notes here . Welcome back to Adopting Zero Trust or AZT. In our latest episode, we assembled a distinguished panel to dig into a timely topic affecting the cybersecurity landscape but has the fog of war wrapped around it. Today’s conversation centered around the recent developments in cybersecurity regulations and their potential impacts, ignited by the Supreme Court overturning Chevron Deference. This, of course, has other potential impacts on all regulation types enforced and shaped by federal agencies, but our focus is, of course, on cybersecurity, privacy, and AI. The Panel We welcome back Ilona Cohen, Chief Legal and Policy Officer at HackerOne, who joined us last year to discuss the National Cybersecurity Strategy . Ilona is also the former General Counsel for OMB. We are also joined by the GRC meme king, Troy Fine, the Director of SOC and ISO Assurance Services at Gills Norton. Beyond the memes, Troy takes a practical perspective on regulations and acts as our voice for those who may be most immediately impacted. Key Takeaways Chevron Deference overturned: The Supreme Court's decision removes the requirement for courts to defer to federal agencies' interpretations of ambiguous statutes and now relies on the courts. Increased regulatory uncertainty: This ruling may lead to more challenges to existing and future regulations, potentially affecting cybersecurity and AI policies. State vs. Federal regulation: The uncertainty at the federal level might prompt states to act more quickly on issues like AI and cybersecurity, potentially creating a patchwork of regulations. Impact on AI regulation: With about 40 federal bills addressing AI in the pipeline, the ruling could complicate the process of creating comprehensive federal AI regulations. Cybersecurity implications: Existing and proposed cybersecurity regulations, such as the Cyber Incident Reporting for Critical Infrastructure Act, may face new challenges. Business concerns: While some business organizations applauded the ruling, the resulting regulatory uncertainty could be problematic for companies trying to plan and comply with regulations. Expertise concerns: There are worries that courts may lack the technical expertise to make decisions on complex technological issues like AI without deferring to agency experts. Potential for innovation: The regulatory uncertainty might create a wild west period for AI, potentially fostering innovation before more stringent regulations are imposed. Self-regulation importance: In the absence of clear federal regulations, industry self-regulation initiatives may become more significant, especially in rapidly evolving fields like AI.…
A
Adopting Zero Trust

Season 3, Episode 11: Vulnerability management is critical to any Zero Trust strategy, but you probably already know that. Fortra’s Tyler Reguly breaks down severity vs. risk. Catch this episode on YouTube , Apple , Spotify , or Amazon . You can read the show notes here . Every organization relies on some form of technology to run, and each tool you add increases the risk of vulnerabilities causing problems. If you don’t stay on top of patching, you increase the odds of a bad actor finding their way more easily within your network. This week, we chat with Tyler Reguly, a senior manager of security research at Fortra, who shares insights from his 18 years in vulnerability management. Tyler discusses the importance of staying on top of patching to maintain a Zero Trust strategy, the differences between vulnerability and patch management, and emphasizes that the Common Vulnerability Scoring System (CVSS) measures severity, not risk. We also briefly nerd out about the significance of groups like the Canadian Cyber Threat Exchange (CCTX) for knowledge sharing and collaboration in cybersecurity. And then, we wrap things up by exploring the efficacy of existing security policies and benchmarks, such as CIS and DISA STIGs, and the role of vendor relationships in maintaining effective security practices.…
A
Adopting Zero Trust

1 The Unstoppable Phish: A Discussion with Vivek Ramachandran 26:31
26:31
나중에 재생
나중에 재생
리스트
좋아요
좋아요26:31
Season 3, Episode 10: Elliot chat’s with Vivek Ramachandran of SquareX about his approach to tackling the impossible: Social engineering. Catch this episode on YouTube , Apple , Spotify , Amazon , or Google . You can read the show notes here . For nearly three decades, social engineering, particularly phishing, has been one of the most impactful and financially draining cyber threats. Between security awareness training, email security gateways, generative AI, enterprise browsers, and a slew of other tech like EDRs and XDRs, social engineering has yet to be thoroughly thwarted. The reason for that is straightforward enough: social engineering is a psychological threat, not just a technological one. In our last round of interviews from RSA, we chatted with Vivek Ramachandran, the founder of SquareX, who is attempting to tackle the challenge. Vivek also walks us through a more realistic perspective of how threat actors use generative AI today, which goes beyond the more unique what-if scenarios we’ve seen in headlines in the past two years. Key Takeaways Social engineering and phishing attacks remain a significant threat, and everyone can be a target. The sophistication of these attacks has increased due to advances in AI. AI can craft messages that sound remarkably like someone the recipient knows, enabling rapid scalability. Social media platforms are becoming common channels for launching phishing attacks. Attackers exploit the trust that users place in these platforms and their contacts. Vivek Ramachandran's company, SquareX, deploys a browser extension that can attribute attacks and detect and block them in real-time, providing valuable information to the enterprise. Traditional technologies like Secure Web Gateways (SWG) have matured, and attackers can easily bypass them. Enterprise browsers solve the problem for a small niche group of websites but have adoption friction due to the inconvenience of having a dedicated browser.…
플레이어 FM에 오신것을 환영합니다!
플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.