Artwork

Player FM - Internet Radio Done Right
Checked 24d ago
추가했습니다 two 년 전
Galah Cyber에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Galah Cyber 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!
icon Daily Deals

Secured by Galah Cyber with Cole Cornford

공유
 

Manage series 3463790
Galah Cyber에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Galah Cyber 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Secured is the podcast for software security enthusiasts. Host Cole Cornford sits down with Australia's top software security experts to uncover their unconventional career paths and the challenges they faced along the way. Listen in as they share their insights on the diverse approaches to AppSec, company by company, and how each organisation's security needs are distinct and require personalised solutions. Gain insider access to the masterminds behind some of Australia's most successful Software security teams on Secured by Galah Cyber. This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/
  continue reading

50 에피소드

Artwork
icon공유
 
Manage series 3463790
Galah Cyber에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Galah Cyber 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Secured is the podcast for software security enthusiasts. Host Cole Cornford sits down with Australia's top software security experts to uncover their unconventional career paths and the challenges they faced along the way. Listen in as they share their insights on the diverse approaches to AppSec, company by company, and how each organisation's security needs are distinct and require personalised solutions. Gain insider access to the masterminds behind some of Australia's most successful Software security teams on Secured by Galah Cyber. This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/
  continue reading

50 에피소드

모든 에피소드

×
 
Episode Summary Scott Contini has a PhD in cryptography with more than a dozen research publications, and has spent the last 15 years focused on solving real-world security problems. After switching from academia to industry in 2008, Scott has identified hundreds of cryptographic implementation flaws across the world, written widely read blogs on common coding mistakes, and contributed significantly to the 2021 OWASP Top 10 topic of Cryptographic Failures. He joins Cole Cornford to discuss how cryptography often goes wrong in practice, why secure-by-default APIs are reshaping security today, and the importance of clear communication and community-building in advancing the field. Scott also shares stories from working alongside legendary figures in cryptography, and offers advice for anyone looking to build a sustainable and impactful security career. Timestamps 00:20 - Scott’s background in cryptography and transition to AppSec 02:00 - Moving from theory to real-world security challenges 05:00 - Common cryptography mistakes in the industry 07:50 - Why using the wrong encryption modes leads to vulnerabilities 10:10 - How Java’s cryptography design led to widespread issues 14:40 - The rise of secure-by-default APIs in cryptography 17:00 - Stories from working with cryptographic legends 22:00 - Improving advice in the OWASP community 27:50 - The value of writing and public speaking in AppSec careers 33:00 - Advice for newcomers in security: think like an attacker and keep learning Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Jon-Anthoney de Boer is the Product Security Lead at Transmax, overseeing security for critical infrastructure that manages traffic flow across Australia. Coming from a strong software engineering background, Jon-Anthoney shares his experience transitioning from traditional engineering into product and application security. He highlights the importance of aligning software engineering and security teams, building trust into the software development lifecycle, and fostering a security culture based on practical strategy rather than superficial metrics. Jon-Anthoney also discusses how behavioural change, organisational alignment, and operational excellence are key to achieving effective, sustainable security outcomes. Timestamps 00:32 - Jon-Anthoney’s journey from electrical engineering to product security 05:08 - Transitioning from software craftsmanship to cybersecurity 09:30 - Why aligned incentives between engineering and security teams matter 12:22 - Goodhart's Law: pitfalls of security metrics 18:21 - Rethinking cybersecurity strategies beyond tools and compliance 25:12 - Building observability into the secure software development lifecycle 32:35 - Why executive support is crucial for security initiatives 38:34 - Operational excellence: removing waste from security processes Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this episode of Secured, host Cole Cornford chats with Laura O'Neill from Fujitsu Cyber. Laura shares her journey from a pure maths and cryptography background through management consulting into the world of cybersecurity. She explains how she helped grow MF&A from a small team into a 70-person company before its acquisition by Fujitsu. Cole and Laura discuss the challenges of scaling a cyber practice, the importance of professionalising sales and board-level communications, and how embracing diverse, non-traditional talent can transform the industry. Their conversation offers valuable insights into shifting from a compliance-based mindset to a risk-based strategy that truly supports business objectives. Timestamps 00:10 - Introduction to Laura O'Neill and her role at Fujitsu Cyber 02:27 - Laura recounts her journey from pure maths and cryptography to cybersecurity 05:31 - Discussing the rapid growth of MF&A from a small team to 70 staff 07:30 - Overcoming scaling challenges through improved processes and support 11:23 - Professionalising sales and board-level communications in cyber 15:30 - Moving from a compliance-driven approach to a risk-based strategy 26:16 - Embracing diversity and non-traditional hiring in cybersecurity 31:20 - The value of diverse backgrounds and soft skills in solving security challenges 40:43 - The importance of empathy and listening in leadership 42:16 - Closing thoughts on security as an enabling function for business success Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Cole Cornford speaks with Kat McCrabb, founder of Flame Tree Cyber, about navigating cybersecurity compliance and risk, particularly within education, government, and mission-driven organisations. Kat shares insights from her experience in federal government and as CISO at Brisbane Catholic Education, highlighting the strengths and weaknesses of compliance frameworks like Australia's Essential Eight and MITRE ATT&CK. The conversation covers how to effectively communicate cyber risks to stakeholders, align security with organisational priorities, and why prevention beats incident response every time. Kat also discusses strategies for meaningful conversations around funding and shares her perspective on the evolving landscape of security in the age of SaaS and cloud technologies. Timestamps 00:59 - Kat’s background and founding Flame Tree Cyber 03:10 - Defining mission-driven organisations 04:29 - Challenges of prescriptive compliance frameworks (ISM, Essential Eight, DISP) 05:41 - Compliance vs meaningful security improvement 06:51 - How threat modelling with MITRE ATT&CK helps allocate resources 07:35 - Balancing foundational cybersecurity and advanced threat intelligence 08:52 - Incident response and the value of understanding threat actors 11:46 - Allocating budget and demonstrating security value to executives 16:31 - How to effectively request security funding from the board 20:00 - Relevance of Essential Eight in modern SaaS environments 29:21 - Kat’s role with AISA and building the cybersecurity community in Queensland Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Kiera Farrell, Cyber Analyst at David Jones, shares her journey from studying a Bachelor of Cybersecurity to landing a role in cybersecurity operations. She reflects on the challenges of breaking into the industry, the lessons learned from risk management, and the importance of networking in career growth. Kiera and Cole discuss the value of stepping outside your comfort zone, the evolving landscape of cybersecurity degrees, and what hiring managers can do to attract and retain young talent. If you're an aspiring cybersecurity professional or a leader looking to support early-career hires, this episode is packed with insights. Timestamps 2:00 – Kiera’s journey: From Bachelor of Cybersecurity to David Jones 5:00 – What studying cybersecurity is really like 8:10 – The surprising importance of risk management 12:00 – Ethical hacking & the role of security education 16:30 – The grad job hunt: what works, what doesn’t 19:45 – The power of stepping out of your comfort zone 21:30 – Building a strong professional network 23:50 – What makes an employer attractive for graduates? 26:40 – How mentorship accelerates career growth 30:35 – Advice for students and early-career professionals Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this special solo episode, host Cole Cornford reflects on the journey of the Secured podcast over the past two years. He shares behind-the-scenes insights, from the unexpected challenges of cicada season disrupting recordings to the podcast’s growth, hitting 45 episodes and over 7,000 downloads. Cole discusses listener feedback, format changes, and his plans to expand the show, including moving to weekly episodes, introducing video content, and diversifying guest profiles. He also highlights listener engagement stats, the importance of audience reviews, and the future direction of Secured with a focus on delivering more valuable and dynamic cybersecurity content. Timestamps 00:20 – The impact of cicada season on recording and production 01:10 – Hitting 45 episodes: reflections on the podcast’s growth 01:54 – Asking for listener feedback and reviews to support the show 02:51 – Plans to move to weekly episodes and potential sponsorships 03:51 – The possibility of introducing video content and its challenges 04:35 – Listener engagement stats: unique listeners, downloads, and demographics 08:05 – Most downloaded and highest engagement episodes revealed 10:55 – Diversity in guests and topics: striving for representation 13:48 – Changes in podcast format: cutting certain segments for better engagement 17:03 – The shift towards professional development-focused content 19:50 – Future goals: more international guests and sharper conversations Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Madhuri Nandi is the Head of Security at Till Payments and a trailblazer in the Australian cybersecurity industry. As co-chair of the Australian Women’s Security Network, she brings decades of experience to the table, breaking barriers for women in tech and redefining what leadership looks like in cybersecurity. Madhuri shares how a love for gaming and cheat codes sparked her journey into application security and the cultural challenges she overcame to thrive in a male-dominated industry. They explore the realities of leading security functions in scaling FinTechs, why compliance doesn’t equate to security, and the critical role of aligning cybersecurity strategies with business objectives. Timestamps 01:13 Cheat Codes Ignite a Cybersecurity Path 02:26 From Database Admin to Security Professional 05:09 Lessons from Gaming & Early Misperceptions 07:29 The Jump into Executive Leadership 10:53 Compliance vs. True Risk Management 18:45 Overcoming Cultural & Workplace Hurdles 31:55 Diversity, Women in Tech & Final Reflection Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this episode of Secured, host Cole Cornford chats with Neha Malik, Head of Product Security at REA Group, about building and scaling effective application security (AppSec) programs. They delve into the importance of empathy, communication, and relationship-building between security teams and developers. Neha shares her journey from a Microsoft graduate program, through external consulting at KPMG, and into her current leadership role. They discuss making security easy for engineers, managing security champions programs with realistic expectations, and learning from other disciplines—like psychology and marketing—to better influence and engage stakeholders. Neha and Cole also highlight how tailoring approach and tooling can differ for startups and large enterprises, and emphasise that collaboration, not confrontation, leads to long-term AppSec success. Timestamps 00:20 - Neha’s Role at REA Group and Positive AppSec Outcomes 01:30 - Starting a Career in Security at Microsoft’s Grad Program 05:45 - Building an AppSec Program from Scratch at REA 10:00 - Startups: Embedding Security in Tools Over Heavy Process 14:40 - Security Champions Programs: Value, Expectations, and Incentives 20:25 - Learning from Other Disciplines (e.g., Psychology) to Influence Teams Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this special christmas episode of Secured, Cole Cornford does something a little different to usual and answers listener questions. Lots of topics are covered, including new years resolutions, cybersecurity trends of 2024, career and life advice, and plenty more. A huge thank you to everyone who sent in questions! We had so many responses that we weren't able to get to all of them. Let us know if you enjoy this format and we may do it again in the future. Timestamps 1:00 - Cole's thoughts on new year's resolutions 3:00 - Cole's experiences working in large organisations 13:30 - Critical cybersecurity steps for organisations in 2025 20:30 - Using security tools to protect APIs 26:20 - Protecting against supply chain attacks 36:20 - Cole's perspective on DevSecOps 40:50 - Trends of 2024 50:40 - Diversity in the cybersecurity industry 1:01:02 - ASPM tools 1:13:20 - Why Cole enjoys making the podcast 1:21:00 - Life advice that has stayed with Cole Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Elizabeth Stephens is CEO of DBS Cyber, where her team deliver IT solutions for clients in various industries. A retired Marine Corps Major and author of the book Building a Resilient Digital Future: A Comprehensive Guide to Cyber Risk Monitoring, Elizabeth draws from her diverse experience in her work. In her conversation with Cole Cornford, they discuss leveraging AI to be helpful and not harmful the politics and nuance of cybersecurity, lessons from Elizabeth's military experience that she applies to her current role, and plenty more. Timestamps 1:00 - Elizabeth's background 7:30 - How we can leverage AI to be useful not harmful 14:30 - Using AI to help with parenting 20:30 - The politics & nuance of cybersecurity 23:30 - Roblox & cybersecurity for kids 27:00 - Lessons from the military Elizabeth applies to cybersecurity 30:30 - Elizabeth's journey as an author 36:30 - Cybersecurity for small business Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this episode, Cole Cornford is joined by cybersecurity experts and IRAP assessors, Kat McCrabb and Toby Amodio, to unpack the latest updates to the Protective Security Policy Framework (PSPF) for 2024. They explore the significant changes introduced in the PSPF, such as the heightened emphasis on IRAP assessments, the potential strain on resources due to increased demand for assessors, and the impact on government agencies' compliance efforts. The discussion delves into the restructuring of the PSPF domains, including the separation of information and technology, and the challenges this presents for reporting and governance. They also address issues with self-attestation in agencies, insights from ANAO reports, and the critical importance of managing legacy IT systems. Kat and Toby offer valuable perspectives and practical advice for organisations navigating these new requirements, highlighting the need for proactive planning and adaptation in the evolving cybersecurity landscape. Timestamps 01:27 - What is the PSPF? Toby explains the framework 03:07 - Kat discusses the biggest changes in the PSPF 2024 updates 04:20 - Challenges with IRAP assessments: time, cost, and limited assessors 06:18 - When are IRAP assessments required? Clarifications 08:13 - Changes in PSPF domains: splitting information and technology 10:08 - Implications of the changes for reporting and governance 12:15 - Comparison with NIST framework and governance considerations 13:38 - Issues with self-attestation and insights from ANAO reports 15:09 - Strategies for improving reporting and assessments in agencies 17:36 - Managing legacy IT systems under the new PSPF requirements 18:52 - Key takeaways and final thoughts from Kat and Toby Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this episode, Cole Cornford speaks with Anand, an API security expert at Traceable AI with over 18 years of experience in crafting innovative IT solutions. Anand's expertise spans API design, microservices architecture, cloud technologies like Kubernetes and AWS, and security architecture including IAM and OAuth. Together, they delve into the critical importance of API security in today's digital landscape, discussing why traditional web security measures are insufficient, lessons learned from incidents like the Optus breach, the challenges of managing API inventories, and how AI and machine learning can enhance security practices. Anand also shares his experience writing a book during the pandemic and the value of continuous learning. This episode is packed with insights on modern application development, cybersecurity, and plenty more. Timestamps 4:20 - Understanding API security challenges 9:30 - The role of AI in API security 16:55 - The importance of API inventory management 24:00 - The business impact of API security 28:00 - Cole & Anand discuss books & writing 34:00 - Current state of API security in Australia Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary In this episode, Cole Cornford speaks to two guests on the topic of robotics: Damith Herath, a Professor at the University of Canberra, and Adam Haskard, co-founder and Director of Bluerydge, a Canberra-based cybersecurity and technology firm. Together, Damith and Adam are conducting research into Secure Robotics, an emerging field of study that addresses the intersection of robotic safety, trust, and cybersecurity. In their conversation with Cole, they discuss the growth opportunities for robotics, how someone interested in the field could pursue a career in robotics, potential risks of the common household vacuum robots, and plenty more. Timestamps 2:00 - Robotics: definitions & applications 8:45 - The intersection of robotics & cybersecurity 10:00 - Trust & safety in robotics & cyber 15:00 - Emerging risks in robotics 18:40 - The role of cybersecurity in robotics 20:30 - Regulation and innovation in robotics 40:00 - Growth opportunities for robotics 29:00 - Future of robotics & AI 32:00 - Career pathways into robotics 39:00 - Rapid fire questions Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Episode Summary Ilkka Turunen is the CTO at Sonatype, a company that helps millions of software developers use open-source software while minimising security risk. In this conversation, Ilkka chats with Cole Cornford about the benefits and risk of using open-source software, how Maven helped standardise software development processes, the different approaches to AppSec regulation in Australia and Europe, and plenty more. Timestamps 1:33 - Ilkka's career background 4:00 - Varying quality of open-source software 6:10 - How Maven helped standardise software development processes 13:00 - The balance between speed of delivery & quality 17:00 - Importance of environment parity in software dev 21:40 - Risk of using 3rd party code in software 25:10 - Regulation of AppSec in Australia vs Europe 32:10 - How new European software security regulations will be enforced 35:00 - Recommendations for compliance with European regulations 39:00 - Rapid fire questions Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Summary Daisy Wong is the Head of Security Awareness at Medibank, as well as a disability advocate. Originally from a marketing background, Daisy gained experience in the cybersecurity industry working as part of penetration teams, before making her way into the security culture and awareness space. In her conversation with Cole Cornford, Daisy discusses using the tools of marketing to educate people on cybersecurity, what are the hallmarks of a good security culture and awareness program, and the importance of diversity in cybersecurity. Timestamps 4:00 - Daisy's transition from marketing to cybersecurity 8:10 - The importance of security culture and awareness 11:00 - Building effective security awareness programs 14:15 - The role of diversity in cybersecurity 17:00 - Strategies for inclusive hiring practices 19:40 - The power of communication in security awareness 23:20 - Creative approaches to security awareness campaigns 31:45 - Daisy's personal perspective on the importance of diversity 43:40 - Rapid fire questions Mentioned in this episode: Call for Feedback This podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrp Spotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/…
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

icon Daily Deals
icon Daily Deals
icon Daily Deals

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생