Podcasts about chief security

  • 80PODCASTS
  • 107EPISODES
  • 36mAVG DURATION
  • 1MONTHLY NEW EPISODE
  • Aug 13, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about chief security

Latest podcast episodes about chief security

ChannelBuzz.ca
Logging in, not breaking in: Blackpoint Cyber’s Wil Santiago on the 2026 threat landscape

ChannelBuzz.ca

Play Episode Listen Later Aug 13, 2026 30:07


Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

Crucial Tech
Episode 12.13 -- Are we realizing AI can't replace humans?

Crucial Tech

Play Episode Listen Later Jul 10, 2026 14:05


The idea that humans can be excluded from technology operations has been an aspiration in the AI industry, and that interest is NOT going away. But companies are pushing the idea less and redefining how important humans are in the process, described as humans in the loop, at the helm and in the middle depending on whom you are talking to,A lot of the aspirational efforts have been in automating security operations centers (SOCs), but, like much of the threat that AI will eventually replace all humanity, is being tempered by reality. Many companies are pushing the idea autonomous response in SOCs tempered with human involvement. The latest is Blackpoint Cyber who have announced their first offering in the area. We are talking with Chief Security and Trust Officer Wil Santiago about how human involvement in security is still a requirement now and for the foreseeable future.This episode is sponsored by Haven

ai humans socs chief security
ITSPmagazine | Technology. Cybersecurity. Society
After RSAC Conference 2026, Reflecting on Agentic AI, Community, and the Evolution of Cybersecurity | A Brand Highlight at RSAC Conference 2026 with Tony Anscombe, Chief Security Evangelist of ESET

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later May 23, 2026 7:33


Agentic AI was the theme that pulled away from the pack at RSAC Conference 2026. Tony Anscombe of ESET makes the case that once AI shifts from being directed by humans to operating with its own objectives and logic, the security surface changes with it, and organizations are being forced to rethink what they protect and how. At the show, ESET announced two products that meet that moment head on. The ESET AI Skills Checker is a free-to-use tool coming to market. ESET AI Protection looks inside AI sessions on the endpoint, flagging sensitive data leakage, malicious links returned by AI systems, and suspicious behavior, and surfacing it all inside normal cybersecurity operations for investigation, blocking, or detection. Tony closes with a reminder worth keeping. His first RSA was in 1998, and the technology he worked on then (sandboxing, dynamic code, remote windowing, encryption, authentication) mirrors a lot of what walks the RSAC Conference floor today. The packaging evolves, the core principles do not. Build forward, but do not lose sight of what the past already proved. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES Learn more about ESET: https://www.eset.com ESET AI Skills Checker and ESET AI Protection: https://www.eset.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, agentic AI, AI security, RSAC Conference 2026, threat intelligence, MDR, EDR, endpoint security, AI Skills Checker, AI Protection, cybersecurity community, multifactor authentication, cybersecurity evolution Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Ep. 323 AI Threat Detection and Federal Cybersecurity Trends

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later May 21, 2026 24:11


Connect to John Gilroy on LinkedIn   https://www.linkedin.com/in/john-gilroy/ Everyone seems to have an opinion on AI. Today, we interviewed Levi Gundert, the Chief Security and Intelligence Officer for Recorded Future. He thinks that AI gives federal leaders an opportunity to fight back. For example, one aspect of cybersecurity is velocity; the number of attacks has expanded exponentially. Gundert thinks this is an opportunity to match this attack's velocity. Many will balk at this opinion. They will describe federal data as challenged in cross-domain sharing, data labeling, and data trapped in PDFs or legacy systems. During the interview, in a refreshing observation, Gundert observes that defenders have always been on the back foot. Always in defense. Finally, AI can give tools that level the playing field. One application of AI is the ingestion of the data provided to federal systems. AI can be used to provide actionable intelligence. In some systems, this deluge can result in false alerts. When used properly, AI can filter through the signal and identify what is critical. Gundert emphasizes the need for automation and decision advantages in threat intelligence, the challenges of data fragmentation and legacy systems, and the urgency of upgrading systems to address vulnerabilities. They also touch on the role of AI in insider threats, the potential of Mythos to increase vulnerabilities, and the importance of sharing threat information to enhance cybersecurity.

CiscoChat Podcast
S7 E5: Talking securing legacy networks in the AI era with Anthony Grieco and Eric Wenger

CiscoChat Podcast

Play Episode Listen Later May 5, 2026 22:14


AB chats with Anthony Grieco, Cisco's SVP & Chief Security & Trust Officer, Security and Trust Organization. and Eric Wenger, Cisco's Senior Director, Technology Policy, Global Government Affairs, about how Cisco is revolutionizing product security by removing insecure protocols, updating defaults, and strengthening authentication across our portfolio.

Cisco TechBeat
S7 E4: Talking the vulnerability of legacy equipment, protecting network infrastructure, and ensuring ongoing lifecycle management in the AI era, with Anthony Grieco and Eric Wenger

Cisco TechBeat

Play Episode Listen Later Apr 13, 2026 22:14


AB chats with Anthony Grieco, Cisco's SVP & Chief Security & Trust Officer, Security and Trust Organization, and Eric Wenger, Cisco's Senior Director, Technology Policy, Global Government Affairs, about how Cisco is revolutionizing product security by removing insecure protocols, updating defaults, and strengthening authentication across our portfolio. 

Modern Digital Applications with Lee Atchison
Understanding AI Security Risks with Preston Wood

Modern Digital Applications with Lee Atchison

Play Episode Listen Later Apr 7, 2026 25:43 Transcription Available


Today's discussion centers on the vulnerabilities associated with AI systems and the increasing threats they face. Our guest, Preston Wood, the Chief Security and Strategy Officer at Databox, highlights the lack of transparency in AI technologies as a significant factor that makes them more susceptible to attacks. We explore how this obfuscation creates challenges in understanding and defending against potential threats. As AI continues to advance, we also consider the evolving nature of phishing attacks and the importance of robust data management strategies to mitigate risks. This episode aims to provide insights for software architects and leaders on navigating the complexities of AI integration while ensuring security and reliability.The podcast episode features an insightful discussion about the growing vulnerabilities associated with AI systems. The guest, Preston Wood, the Chief Security and Strategy Officer at Databox, addresses the surge in AI-related attacks, emphasizing the need for greater transparency and understanding of AI operations. He explains that the ambiguous nature of AI systems makes them appealing targets for attackers, who can exploit the lack of visibility into how these systems function. Throughout the conversation, Preston highlights the importance of ensuring that AI-generated data is clean and comprehensible to mitigate risks. He compares today's AI landscape to early phishing attacks, which have evolved into sophisticated threats due to advancements in AI technology. This episode serves as a crucial resource for software architects and technology leaders, offering them guidance on how to navigate the complexities of securing AI systems and understanding the implications of AI on data management and security practices.Takeaways:The podcast discusses the growing vulnerabilities associated with AI-based systems due to their lack of transparency.Preston Wood emphasizes the importance of clean and understandable data for AI performance and security.Organizations are advised to improve their data architecture to ensure AI projects are successful and not hindered by poor data quality.The conversation highlights the evolving nature of phishing attacks, which are now more sophisticated due to AI advancements.Effective security requires a layered approach that combines model training and guardrails for AI systems.Listeners are encouraged to consider how well their organizations are integrating AI into their existing technology frameworks.

ITSPmagazine | Technology. Cybersecurity. Society
From Threat Intelligence to Cyber Resilience: What SMBs and Enterprises Need to Know Now | A Brand Spotlight at RSAC Conference 2026 with Tony Anscombe, Chief Security Evangelist of ESET

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 1, 2026 24:01


On the RSAC Conference show floor, Tony Anscombe shared how ESET has expanded its threat intelligence offering with ECR reports -- designed to give commercial organizations both machine-readable feeds and human-readable analysis. The reason: threat actors are increasingly hard to attribute, they share tools, run coordinated campaigns, and reinvest profits into more sophisticated operations. Having someone do the research and surface actionable intelligence is no longer a luxury. Anscombe pointed to a telling campaign pattern from last year: threat actors refined attack methods against UK retailers, then rapidly adapted those same techniques against US retailers. The implication is clear -- your business may be unique in its infrastructure, but it is not unique in its sector. Understanding how your sector is being targeted is the foundation of a prevention-first posture. Automation came up as equally non-negotiable. If it takes three days to collect all the information needed to make a determination about an incident, the post-attack phase has already begun. ESET Inspect is designed to flip that equation: when an analyst opens an incident, the forensic analysis is done, the evidence is visualized, and the determination can be made on facts rather than gathered through investigation. Anscombe was careful to draw a line between automation as speed and automation as replacement. ESET's position is that AI should operate alongside human expertise -- trust and verify applies to AI-assisted analysis just as it does to any intelligence feed. Oversight remains essential, even as the tooling gets faster. A preview of upcoming survey data offered one of the more striking moments in the conversation. Roughly 35% of SMBs using MDR are sourcing that service directly from their cyber insurer. Anscombe flagged the monoculture risk: when a large share of businesses in the same sector run identical security stacks, a single point of failure becomes a sector-wide vulnerability. His advice after 30 years in the industry -- different organizations should deliberately choose different platforms to maintain diversity. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES ESET: https://www.eset.com ESET Threat Intelligence: https://www.eset.com/int/business/services/threat-intelligence/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, Marco Ciappelli, brand spotlight, brand marketing, marketing podcast, threat intelligence, cyber resilience, MDR, EDR, XDR, managed detection and response, SMB security, cybersecurity automation, RSAC Conference 2026, prevention-first security, cyber insurance, monoculture risk, ESET Inspect, APT research Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
eCrime, Threat Intelligence, and What's Coming at RSAC Conference 2026 | A Brand Spotlight at RSAC Conference 2026 with Tony Anscombe, Chief Security Evangelist of ESET

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Mar 19, 2026 21:47


Tony Anscombe has attended RSA Conference since 1998 -- back when it was held at the Fairmont Hotel. That long view informs everything about how ESET approaches threat intelligence. It is not about volume. It is about accuracy, speed, and putting the right signal in front of the right team at the right moment. The ESET eCrime Ecosystem Report comes in two forms: a business-facing summary outlining current risks for leadership, and a long-form technical report for analysts -- complete with IOCs, coding examples, and structured intelligence feeds covering ransomware, crypto scams, malicious email attachments, and infostealer data. These feeds are built to plug directly into SOC workflows and firewall rules, not to create more work for already stretched teams. Tony Anscombe is direct about the quality problem in threat intelligence. Open-source feeds sound appealing -- until you factor in the analyst hours required to clean out the noise. By then, the intelligence is stale. Attacks circle the globe in hours. Near-real-time, verified intelligence is not a premium -- it is the baseline requirement. The threat detection conversation has also moved well past malware. Anscombe walks through how modern attackers often skip the payload entirely -- credential theft gets them in, then slow lateral movement and data exfiltration follow, with ransomware as the final act rather than the first signal. ESET's platform focuses on behavioral anomaly detection across the full environment, with on-site, cloud, and managed deployment options for organizations that cannot or will not go all-in on cloud architecture. At RSAC Conference 2026, ESET will be at booth 5253 in Moscone North. Anscombe has two sessions on the Wednesday agenda: one on supply chain blind spots -- urging security teams to engage directly with the business side to map third-party risk fully -- and a community rant session tackling four things that need to change in cybersecurity, including the cryptocurrency regulation debate. On AI, his message is measured: the real conversation at the show is not about using AI -- it is about securing it. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES ESET website: https://www.eset.com ESET threat research blog (WeLiveSecurity): https://www.welivesecurity.com ESET at RSAC Conference 2026 -- Booth 5253, Moscone North Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, RSAC Conference 2026, eCrime, threat intelligence, eCrime Ecosystem Report, cybersecurity, endpoint protection, MDR, threat detection, supply chain security, AI security, ransomware, infostealer, brand spotlight, brand marketing, marketing podcast, brand story Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Quick Talk: A TM Forum podcast
Howard Watson on AI and telco foundations

Quick Talk: A TM Forum podcast

Play Episode Listen Later Mar 18, 2026 45:00


Howard Watson, who is retiring from his role as BT's Chief Security and Networks Officer, shares his perspective on today's telecoms industry gained from more than 40 years in the technology and telecoms space.   Guest speakers: Howard Watson, Chief Security & Networks Officer, BT   Host: Mark Newman, Chief Analyst, TM Forum Joanne Taaffe, Editor in Chief, TM Forum

foundations bt telco chief analyst chief security tm forum
Empowered Patient Podcast
Avoiding Critical Cybersecurity Vulnerabilities in Healthcare Systems with Kory Daniels LevelBlue TRANSCRIPT

Empowered Patient Podcast

Play Episode Listen Later Mar 16, 2026


Kory Daniels, Chief Security and Trust Officer at LevelBlue, discusses the multifaceted cybersecurity challenges in the healthcare industry and the risks posed by legacy systems not designed for secure internet connectivity. Artificial intelligence is being used successfully to defend against cyber attacks, while threat actors are using AI without ethical constraints to launch sophisticated attacks. Managing cybersecurity includes using digital twins to model vulnerabilities and to develop strategies for identity and access management for human and non-human identities, such as robots and AI agents.  Kory explains, "We must recognize that we're not starting from a clean slate - we have a lot of decades-old systems operating both within the physical footprint of the healthcare and hospital facility and in record retention and data management. Many organizations are looking at how to get ahead in identifying what needs to happen to embrace new technology and much of the innovation. At the same time, being conscious and cognizant of opportunities to retrofit, taking what's there already today and making it internet-connected as an example, making it Internet of Things-connected so that devices that weren't purpose-built to communicate to the internet now can communicate to the internet, but it creates some risks and it poses some challenges."   "We highlighted that some of these legacy systems or initial systems that have been in the organization for years, some 10 years or more, were not necessarily purpose-built or designed at the time of manufacturing, nor with the software needed for those tools to operate with current speed, expectations, and requirements. Healthcare entities are engaging both patients and supporting care doctors and patient care professionals in 2026 and beyond."  #LevelBlue #HealthcareCybersecurity #DigitalTransformation #AIinHealthcare #LegacySystems #PatientSafety #CyberThreats #HealthTech #DataSecurity #MedicalDevices #DigitalHealth #HealthcareIT #CyberDefense #HealthcareInnovation #RiskManagement #ComplianceMatters LevelBlue.com Listen to the podcast here

Empowered Patient Podcast
Avoiding Critical Cybersecurity Vulnerabilities in Healthcare Systems with Kory Daniels LevelBlue

Empowered Patient Podcast

Play Episode Listen Later Mar 16, 2026 21:38


Kory Daniels, Chief Security and Trust Officer at LevelBlue, discusses the multifaceted cybersecurity challenges in the healthcare industry and the risks posed by legacy systems not designed for secure internet connectivity. Artificial intelligence is being used successfully to defend against cyber attacks, while threat actors are using AI without ethical constraints to launch sophisticated attacks. Managing cybersecurity includes using digital twins to model vulnerabilities and to develop strategies for identity and access management for human and non-human identities, such as robots and AI agents.  Kory explains, "We must recognize that we're not starting from a clean slate - we have a lot of decades-old systems operating both within the physical footprint of the healthcare and hospital facility and in record retention and data management. Many organizations are looking at how to get ahead in identifying what needs to happen to embrace new technology and much of the innovation. At the same time, being conscious and cognizant of opportunities to retrofit, taking what's there already today and making it internet-connected as an example, making it Internet of Things-connected so that devices that weren't purpose-built to communicate to the internet now can communicate to the internet, but it creates some risks and it poses some challenges."   "We highlighted that some of these legacy systems or initial systems that have been in the organization for years, some 10 years or more, were not necessarily purpose-built or designed at the time of manufacturing, nor with the software needed for those tools to operate with current speed, expectations, and requirements. Healthcare entities are engaging both patients and supporting care doctors and patient care professionals in 2026 and beyond."  #LevelBlue #HealthcareCybersecurity #DigitalTransformation #AIinHealthcare #LegacySystems #PatientSafety #CyberThreats #HealthTech #DataSecurity #MedicalDevices #DigitalHealth #HealthcareIT #CyberDefense #HealthcareInnovation #RiskManagement #ComplianceMatters LevelBlue.com Download the transcript here

The Security Podcasts
Strategies for Security Leaders in the Midst of Skill Shortages

The Security Podcasts

Play Episode Listen Later Feb 23, 2026 13:10


In this episode of Lock It Down with Security Magazine, Chief Security & Trust Officer Kory Daniels shares how security leaders struggling with skill shortages can make strategic tradeoffs to lessen their team's burden.

strategy skill shortages chief security security leaders security magazine
Zone 7 with Sheryl McCollum
Nancy Guthrie Missing: Blood, Bitcoin, and a Story That Doesn't Add Up

Zone 7 with Sheryl McCollum

Play Episode Listen Later Feb 10, 2026 50:05 Transcription Available


When 84-year-old Nancy Guthrie disappeared from her home, investigators were quickly faced with blood evidence and ransom claims that did not align with standard abduction patterns. In this episode of Zone 7, Sheryl McCollum, retired NYPD homicide detectives Dan Murphy and Tom Smith, and forensic pathologist Dr. Priya Banerjee assess why blood at the scene, a prolonged presence inside the home, and Nancy’s medical vulnerabilities undermine the ransom narrative. The panel also examines investigative decisions and evidence handling that may shape accountability. For those looking to catch up further as the situation develops, additional coverage and updates can be found on Crime Stories with Nancy Grace. Highlights: • (0:00) Sheryl McCollum welcomes listeners, introduces the Nancy Guthrie case, and brings in Dan Murphy, Tom Smith, and Dr. Priya Banerjee • (1:30) Savannah Guthrie’s early silence and why not using her platform immediately raised concern • (2:15) Blood at the scene, smashed cameras, and why this should have been treated as an abduction from the start • (4:15) Interior crime scenes, early release, and how evidence integrity can be compromised • (4:45) Dr. Priya Banerjee on age, blood thinners, cardiac disease, and stress-related death • (7:15) The 41-minute timeline inside the home and why it defies kidnapping patterns • (8:30) Delayed ransom demands, media involvement, and why the timing doesn’t track • (12:15) Lights left on inside the house and behavior inconsistent with covert abduction • (13:30) Bitcoin ransom logic and why mixed-payment demands raise red flags • (14:15) A robbery-gone-wrong scenario and what happens if the victim recognizes the offenders • (16:15) Chronic pain, medication dependency, and why prolonged captivity is medically unlikely • (19:00) Family video statements, proof-of-life questions, and linguistics shifts investigators notice • (21:00) Reactionary law enforcement activity and repeated returns to the scene • (24:30) Pacemakers, Apple Watch connectivity, and what technology may still reveal • (28:30) Leadership optics, media interference, and the impact of active investigations • (36:45) Reward amounts, chain of custody concerns, and courtroom implications • (41:30) Final thoughts from the panel on recovery efforts, investigative outlook, accountability, and why Sheryl believes it was never about the money Guest Bio: Dr. Priya Banerjee is a board-certified forensic pathologist with extensive experience in death investigation, clinical forensics, and courtroom testimony. A graduate of Johns Hopkins, she served for over a decade as Rhode Island’s state medical examiner and now runs a private forensic pathology practice. Dan Murphy is a retired NYPD Detective-Sergeant with extensive experience in homicide, major case investigations, and counterterrorism. During his career, he served in units including the Major Case Squad and the FBI/NYPD Joint Terrorism Task Force. Since retiring from law enforcement, Dan has served as Chief Security officer for U.S. Bancorp, co-authored Workplace Safety: Establishing an Effective Violence Prevention Program, and co-hosts the podcast Gold Shields. Tom Smith is a retired NYPD detective and 2024 National Law Enforcement Hall of Fame inductee. Over 30 years of service, he worked in patrol, narcotics, and robbery investigations and spent 17 years working with the FBI/NYPD on the Joint Terrorism Task Force, including an overseas deployment to Afghanistan. Tom co-hosts the podcast Gold Shields, lectures on criminal justice and terrorism, and provides investigative commentary for national media outlets. Enjoying Zone 7? Leave a rating and review where you listen to podcasts. Your feedback helps others find the show and supports the mission to educate, engage, and inspire. Sheryl “Mac” McCollum is an active crime scene investigator for a Metro Atlanta Police Department and the director of the Cold Case Investigative Research Institute, which partners with colleges and universities nationwide. With more than 4 decades of experience, she has worked on thousands of cold cases using her investigative system, The Last 24/361, which integrates evidence, media, and advanced forensic testing. Her work on high-profile cases, including The Boston Strangler, Natalie Holloway, Tupac Shakur and the Moore’s Ford Bridge lynching, led to her Emmy Award for CSI: Atlanta and induction into the National Law Enforcement Hall of Fame in 2023. Social Links: • Email: coldcase2004@gmail.com • Twitter: @ColdCaseTips • Facebook: @sheryl.mccollum • Instagram: @officialzone7podcast Preorder Sheryl’s upcoming book, Swans Don’t Swim in a Sewer: Lessons in Life,Justice, and Joy from a Forensic Scientist, releasing May 2026 from Simon and Schuster. https://www.simonandschuster.com/books/Swans-Dont-Swim-in-a-Sewer/Sheryl-Mac-McCollum/9798895652824 See omnystudio.com/listener for privacy information.

Les Causeries Data
#38 - Cybersécurité spatiale : protéger l'espace à l'ère du numérique et de l'IA - Avec Yohann Bauzil

Les Causeries Data

Play Episode Listen Later Jan 9, 2026 8:51


Enregistré lors du Cybersecurity Business Convention, cet épisode nous plonge au cœur des enjeux de cybersécurité spatiale. Nous recevons Yohann Bauzil, Directeur de la Sécurité et des Systèmes d'Information chez Lookup Space, une start-up du New Space spécialisée dans la surveillance de l'espace. Double casquette, culture start-up, sécurité produit, réserve opérationnelle au sein du commandement de l'espace, Yohann partage une vision concrète d'un secteur où le numérique est omniprésent, une discussion sur les menaces, l'IA, la défense numérique et la montée en puissance du spatial en Occitanie.Yohann BauzilYohann Bauzil est Chief Security & Information Officer chez Look Up Space, start-up spécialisée dans la surveillance de l'espace. Conseiller technique cyber, il est également réserviste opérationnel spécialiste, officier supérieur, au service de la France. Expert en cybersécurité et en sécurité des systèmes d'information, il intervient régulièrement pour sensibiliser, transmettre et apporter une lecture opérationnelle des défis cyber contemporainsFrance CharruyerFrance Charruyer est fondatrice d'Altij & Oratio Avocats, réseau Baker Tilly, avocate en propriété intellectuelle, technologies de l'information et protection des données, DPO / AI Officer. Présidente de l'association d'intérêt général Data Ring, fondatrice du Lab IA Data Ring, elle s'engage activement pour une gouvernance éthique et responsable des données, au service d'une innovation durable et sécurisée.Elle est chargée d'enseignement à l'INSA sur les enjeux de l'IA de confiance, et intervient à l'Université Paris-Dauphine dans le cadre du D.U. RGPD et délégué à la protection des données. Elle enseigne également à l'Université Toulouse 1 Capitole (Master II DJCE – Master II Propriété Intellectuelle) ainsi qu'à Toulouse Business School (TBS) sur la gouvernance des données, les cyber-risques, et les enjeux liés à l'entrepreneuriat et aux startups.Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.

Crucial Tech
Episode 20.26 - The rise of NHI and the impact of Predatory Sparrow

Crucial Tech

Play Episode Listen Later Jul 9, 2025 22:44


If you are one of the smart people who have a subscription to Cyber Protection Magazine you will soon receive our next special issue focused on the rise of non-human identities (NHI) and their impact on society. If not, you get just this podcast with a hint of what is in the issue.We talk with Mike Towers, Chief Security & Trust Officer at Veza, about the meteoric increase of NHI. As a bonus, we also look into the theft of $90 million in cryptocurrency by the Israeli hacktivist group Predatory Sparrow. This represents a new area of asymmetric warfare.

israelis sparrow predatory nhi trust officer chief security veza
My Precious Data
Het belang van kritische evaluatie van technologieën om cybersecurity te versterken, een gesprek met Brenno de Winter.

My Precious Data

Play Episode Listen Later Apr 2, 2025 57:15


Eddy Willems in gesprek met Brenno de Winter, expert informatiebeveiliging en privacy.In de nieuwste aflevering van de podcastserie 'My Precious Data' gaat Eddy Willems, Security Evangelist bij WAVCi, in gesprek met Brenno de Winter, een vooraanstaand expert op het gebied van informatiebeveiliging en privacy. Brenno is bekend om zijn diepgaande kennis en ervaring, onder andere door zijn betrokkenheid bij het kraken van de OV-chipkaart en zijn werk als Chief Security & Privacy Operations bij het Ministerie van Volksgezondheid, Welzijn en Sport in Nederland.In deze aflevering bespreken Eddy en Brenno de huidige uitdagingen en ontwikkelingen binnen de cybersecuritywereld. Ze gaan in op de balans tussen innovatie en privacy, en hoe organisaties kunnen navigeren in een tijdperk waarin digitale transformatie en beveiliging hand in hand moeten gaan. Brenno deelt zijn inzichten over de 'validatiecrisis' en het belang van kritische evaluatie van technologieën om besluitvorming ivm cybersecurity te versterken. ​ Deze aflevering biedt luisteraars waardevolle perspectieven op hoe samenwerking en kennisdeling cruciaal zijn voor effectieve informatiebeveiliging. Het gesprek benadrukt het belang van openheid en overleg, niet alleen binnen organisaties, maar ook op internationaal niveau, om gezamenlijk de uitdagingen van cybersecurity het hoofd te bieden.

Twins Talk it Up Podcast
Episode 225: Delivery Responsible AI

Twins Talk it Up Podcast

Play Episode Listen Later Nov 12, 2024 41:03


As workflows become more automated and the use of cloud and communication platforms becomes more commonplace, organizations are understandably more concerned about their digital security postures. Prioritizing protection and delivering responsible AI are expected. Doug Fisher, Senior Vice President and Chief Security and AI Officer with Lenovo shares thoughts on Lenovo's responsible AI governance initiative as well as guiding successful teams. Highlights include: Lenovo Pantheon platform. Military background and training as core to providing teams with structure, clarity of expectation and permission to lead. Teamwork and responsibility to deliver secure, ethical and reliable products. Joining the Joint Cyber Defense Collaborative (JCDC). Partnership with Formula One as they are all about performance. Lenovo Tech World 2024 Conference. His commitment to Oregon State University. Follow Doug on LinkedIn and visit lenovo.com --- more --- If you are looking to learn the art of audience engagement while listening for methods to conquer speaking anxiety, deliver persuasive presentations, and close more deals, then this is the podcast for you. Twins Talk it Up is a podcast where identical twin brothers Danny Suk Brown and David Suk Brown discuss leadership communication strategies to support professionals who believe in the power of their own authentic voice. Together, we will explore tips and tools to increase both your influence and value. Along the way, let's crush some goals, deliver winning sales pitches, and enjoy some laughs. Danny Suk Brown and David Suk Brown train on speaking and presentation skills. They also share from their keynote entitled, “Identically Opposite: the Pursuit of Identity”. Support and Follow us: YouTube: youtube.com/channel/UCL18KYXdzVdzEwMH8uwLf6g Instagram: @twinstalkitup Instagram: @dsbleadershipgroup Twitter: @dsbleadership LinkedIn: linkedin.com/company/twins-talk-it-up/ LinkedIn: linkedin.com/company/dsbleadershipgroup/ Facebook: facebook.com/TwinsTalkitUp Facebook: facebook.com/dsbleadership/ Website: dsbleadershipgroup.com/TwinsTalkitUp

ITSPmagazine | Technology. Cybersecurity. Society
Leveraging AI for Effective Healthcare Solutions | A Brand Story Conversation From HITRUST Collaborate 2024 | A HITRUST Story with Walter Haydock and Steve Dufour

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Oct 17, 2024 25:41


The Emergence of Innovative Partnerships: As AI becomes increasingly integral across industries, healthcare is at the forefront of adopting these technologies to improve patient outcomes and streamline services. Sean Martin emphasizes the collaboration between StackAware and Embold Health, setting the stage for a discussion on how they leverage HITRUST to enhance healthcare solutions.A Look into StackAware and Embold Health: Walter Haydock, founder and CEO of StackAware, shares the company's mission to support AI-driven enterprises in measuring and managing cybersecurity compliance and privacy risks. Meanwhile, Steve Dufour, Chief Security and Privacy Officer of Embold Health, describes their initiative to assess physician performance, guiding patients toward top-performing providers.Integrating AI Responsibly: A key theme throughout the conversation is the responsible integration of generative AI into healthcare. Steve Dufour details how Embold Health developed a virtual assistant using Azure OpenAI, ensuring users receive informed healthcare recommendations without long-term storage of sensitive data.Assessment Through Rigorous Standards: Haydock and Dufour also highlight the importance of ensuring data privacy and compliance with security standards, from conducting penetration tests to implementing HITRUST assessments. Their approach underscores the need to prioritize security throughout product development, rather than as an afterthought.Navigating Risk and Compliance: The conversation touches on risk management and compliance, with both speakers emphasizing the importance of aligning AI initiatives with business objectives and risk tolerance. A strong risk assessment framework is essential for maintaining trust and security in AI-enabled applications.Conclusion: This in-depth discussion not only outlines a responsible approach to incorporating AI into healthcare but also showcases the power of collaboration in driving innovation. Sean Martin concludes with a call to embrace secure, impactful technologies that enhance healthcare services and improve outcomes.Learn more about HITRUST: https://itspm.ag/itsphitwebNote: This story contains promotional content. Learn more.Guests: Walter Haydock, Founder and CEO, StackAwareOn LinkedIn | https://www.linkedin.com/in/walter-haydock/Steve Dufour, Chief Security & Privacy Officer, Embold HealthOn LinkedIn | https://www.linkedin.com/in/swdufour/ResourcesLearn more and catch more stories from HITRUST: https://www.itspmagazine.com/directory/hitrustView all of our HITRUST Collaborate 2024 coverage: https://www.itspmagazine.com/hitrust-collaborate-2024-information-risk-management-and-compliance-event-coverage-frisco-texasAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

Redefining CyberSecurity
Leveraging AI for Effective Healthcare Solutions | A Brand Story Conversation From HITRUST Collaborate 2024 | A HITRUST Story with Walter Haydock and Steve Dufour

Redefining CyberSecurity

Play Episode Listen Later Oct 17, 2024 25:41


The Emergence of Innovative Partnerships: As AI becomes increasingly integral across industries, healthcare is at the forefront of adopting these technologies to improve patient outcomes and streamline services. Sean Martin emphasizes the collaboration between StackAware and Embold Health, setting the stage for a discussion on how they leverage HITRUST to enhance healthcare solutions.A Look into StackAware and Embold Health: Walter Haydock, founder and CEO of StackAware, shares the company's mission to support AI-driven enterprises in measuring and managing cybersecurity compliance and privacy risks. Meanwhile, Steve Dufour, Chief Security and Privacy Officer of Embold Health, describes their initiative to assess physician performance, guiding patients toward top-performing providers.Integrating AI Responsibly: A key theme throughout the conversation is the responsible integration of generative AI into healthcare. Steve Dufour details how Embold Health developed a virtual assistant using Azure OpenAI, ensuring users receive informed healthcare recommendations without long-term storage of sensitive data.Assessment Through Rigorous Standards: Haydock and Dufour also highlight the importance of ensuring data privacy and compliance with security standards, from conducting penetration tests to implementing HITRUST assessments. Their approach underscores the need to prioritize security throughout product development, rather than as an afterthought.Navigating Risk and Compliance: The conversation touches on risk management and compliance, with both speakers emphasizing the importance of aligning AI initiatives with business objectives and risk tolerance. A strong risk assessment framework is essential for maintaining trust and security in AI-enabled applications.Conclusion: This in-depth discussion not only outlines a responsible approach to incorporating AI into healthcare but also showcases the power of collaboration in driving innovation. Sean Martin concludes with a call to embrace secure, impactful technologies that enhance healthcare services and improve outcomes.Learn more about HITRUST: https://itspm.ag/itsphitwebNote: This story contains promotional content. Learn more.Guests: Walter Haydock, Founder and CEO, StackAwareOn LinkedIn | https://www.linkedin.com/in/walter-haydock/Steve Dufour, Chief Security & Privacy Officer, Embold HealthOn LinkedIn | https://www.linkedin.com/in/swdufour/ResourcesLearn more and catch more stories from HITRUST: https://www.itspmagazine.com/directory/hitrustView all of our HITRUST Collaborate 2024 coverage: https://www.itspmagazine.com/hitrust-collaborate-2024-information-risk-management-and-compliance-event-coverage-frisco-texasAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

ITSPmagazine | Technology. Cybersecurity. Society
Incident Materiality and Meeting New SEC Requirements with Malcolm Harkins | Cybersecurity Insights Podcast with Matthew Rosenquist

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 29, 2024 33:57


Guest: Malcolm Harkins, Chief Security and Trust officer at HiddenLayer, former CISO at Intel, and fellow at the Institute for Critical Infrastructure Technology (ICIT)On LinkedIn | https://www.linkedin.com/in/malcolmharkins/Host: Matthew RosenquistOn ITSPmagazine  

The Public Sector Show by TechTables
ep.168 Racing to Get Left of Boom: How CXOs Stay Steps Ahead of Nation States like China and Russia with Jamie Grant, fmr. CIO, State of Florida & Morgan Wright, Chief Security Advisor, at SentinelOne

The Public Sector Show by TechTables

Play Episode Listen Later Feb 6, 2024 67:17


The Jedburgh Podcast
#130: Health, Safety, Intelligence & the Role of the Chief Security Officer - International SOS Sally Llewellyn, Kelly Johnstone, And Dr. Mark Fischer

The Jedburgh Podcast

Play Episode Listen Later Dec 6, 2023 43:58


The security challenges we face today are more complex, less predictable and faster evolving than at any point in recent history. When Fran Racioppi isn't hosting the Jedburgh Podcast he runs FRsix, his security company. From this year's industry trade show, Global Security Exchange, Fran sat down with International SOS, the global leader in health and security services, to dig deep on today's biggest threats. International SOS cares for over 9000 organizations in 1000 locations across 90 countries. They field over 11,000 calls for assistance each day. Sally Llewellyn is the global security Director of information and Analysis. Kelly Johnstone served as the Chief Security Officer at Coca Cola. Dr. Mark Fischer is the Regional Medical Director for the Americas. They explain why intelligence is so important in the decision making process for executives of any organization.They define Duty of Care and how it's evolved as we've transitioned from workplace to remote work. They also explain the importance of developing networks of influence, whether that be for intelligence to understand what's happening, or medical support to help people in their time of need. Finally, they break down the roles of the Chief Security officer and analysts and how the information they provide to decision makers is critical for the resiliency of an organization.The world is evolving faster than ever seems to change on a minute-by-minute basis. Our job as leaders is to understand what's happening out there, how it affects our people and our business, and then make decisions and bring in the resources that keep us successful, no matter the challenge. Protection of our people starts with us as leaders. Take the first step today. Learn more on The Jedburgh Podcast Website. Subscribe to us and follow @jedburghpodcast on all social media. Watch the full video version on YouTube. Highlights:0:00 Welcome to the International SOS Booth as GSX3:37 Kelly's lessons from NCIS, to Customs to leading Coca-Cola4:03 Sally explains why intelligence is the first step to decision-making10:22 The evolution of “Duty of Care”17:18 How preparation transitions organizations from react to response21:25 Mark shares how to respond to medical crisis in the most austere parts of the world26:52 The influence of the chief security in executive risk management32:10 The biggest threats to the world todayQuotes: “The threats we're looking at today…are just so much more difficult to predict.” (5:34) “What's going on in the world? What might happen next? To try and inform really good decision-making.” (7:41)“Mitigating risk doesn't eliminate risk. Where there's a medical case there's often security. (9:13)“If you're on a conference call in your car now, do I have a duty of care if you get in a car wreck?” (12:00)“Intelligence doesn't just serve you from a security perspective…it's a business enabler.” (28:30) “Our job there is to ensure that the environment is conducive for the business to meet business objectives.” (29:00) “You are the problem solver, so you get the call on everything.” (30:13)

The Chris Voss Show
The Chris Voss Show Podcast – Nick Espinosa, Chief Security Fanatic, CIO, Columnist, Author, Radio Host, Board Member, Forbes Tech Council & TEDx Speaker

The Chris Voss Show

Play Episode Listen Later Nov 23, 2023 49:56


Nick Espinosa, Chief Security Fanatic, CIO, Columnist, Author, Radio Host, Board Member, Forbes Tech Council & TEDx Speaker Forbes.com Securityfanatics.com Show Notes About The Guest(s): Nick Espinosa is a cybersecurity expert, author, and speaker. He is the founder of Security Fanatics, a company that specializes in cybersecurity and risk management. With over two decades of experience in the field, Nick has worked with clients ranging from small businesses to Fortune 100 companies. He is passionate about educating individuals and organizations on the importance of cybersecurity and helping them develop effective defense strategies. Summary: Nick Espinosa is a cybersecurity expert and the founder of Security Fanatics. In this episode, he discusses the biggest threats to personal and business security in 2023, emphasizing the importance of educating individuals on cybersecurity. He also talks about the role of artificial intelligence (AI) in cybersecurity and the potential risks associated with AI in the future. Nick highlights the need for customized cybersecurity solutions and risk assessment for each organization. He also shares insights on the impact of AI on disinformation campaigns and the challenges of detecting AI-generated content. Key Takeaways: The human factor is the biggest threat to cybersecurity, as many individuals lack the necessary knowledge and understanding of cybersecurity risks. AI is becoming increasingly sophisticated and can be used by hackers to exploit vulnerabilities and launch cyber attacks. Education and training on cybersecurity should start at an early age to ensure individuals are aware of the risks and can make informed decisions. The future of AI in cybersecurity is uncertain, as AI algorithms can learn from other AI models, leading to a dilution of accuracy and reliability. Security theater, such as airport security measures, can create a false sense of security and may not effectively prevent threats. Quotes: "If there's a vulnerability, it will be exploited." - Nick Espinosa "We are so distrusting. We are so disoriented. And this is essentially where we're heading." - Nick Espinosa "Security theater... It's literally the term for it." - Nick Espinosa About Nick Espinosa For over 25 years, Nick has been on a first name basis with computers. Since the age of 7 he's been building computers and programming in multiple languages. Landing his first IT job at age 15, Nick founded Windy City Networks, Inc at 19 which was acquired in 2013. In 2015 Nick created Security Fanatics, a Cybersecurity/Cyberwarfare outfit dedicated to designing custom Cyberdefense strategies for medium to enterprise corporations. An expert in cybersecurity and network infrastructure, Nick has consulted with clients ranging from the small business owners up to Fortune 100 level companies for decades. Nick has designed, built, and implemented multinational networks, encryption systems, and multi-tiered infrastructures as well as small business environments. He is passionate about emerging technology and enjoys creating, breaking, and fixing test environments. As a member of the Board of Advisors for Roosevelt University's College of Arts and Sciences as well as their Center for Cyber and Information Security, the Official Spokesperson for the COVID-19 Cyber Threat Coalition and a board member of Bits N' Bytes Cybersecurity Education, contributor to the Cyber Peace Institute, Strategic Cybersecurity Advisor for the Private Directors Association and humanID as well as the President of The Foundation for a Human Internet, Nick helped to create an NSA certified curriculum that will help the Cybersecurity/Cyberwarfare community to keep defending our government, people and corporations from Cyber threats globally. In 2017 Nick was accepted into the Forbes Technology Council, an invitation-only community for world-class CIOs, CTOs and technology executives,

Pig Wrestling Podcast - Unleashing Human Potential
Chief Security Fanatic of Security Fanatics! - Nick Espinosa

Pig Wrestling Podcast - Unleashing Human Potential

Play Episode Listen Later Sep 4, 2023 54:03


Welcome to our Hack Podcast, where we have the pleasure of featuring the only Nick Espinosa joining us from across the pond. We are thrilled to have Nick here with us after Leon and Dean had the privilege of collaborating with him in Amsterdam as part of IT Nation Evolve. Imagine sitting at a dinner table, and someone leans over and asks Nick, What is it that you do?" Nick's response is always intriguing. He looks them straight in the eye and says, "I lie to you." They usually say really, and he replies 'no'. Of course, this usually catches them off guard, but it's just his way of injecting humour into the conversation. In reality, Nick is deeply involved in cyber security, with his company specialising in cyber warfare, cyber terrorism, infrastructure, and government compliance. And it's not just limited to the US government; they also handle compliance on a global scale, including GDPR. Nick's expertise extends beyond his company Security Fanatics; he is a regular contributor to Forbes, a seasoned TED talk speaker, and even hosts a syndicated radio show in the USA. Nick's job title says it all, he thrives in the fast-paced world of cyber security. He always seeks new challenges and never likes to be bored. Join us as we deep dive into the fascinating world of Nick Espinosa and gain insights into the ever-evolving realm of cyber security.

The Norm
The Norm - March 15, 2023 - Tony Anscombe, Chief Security Evangelist With ESET Canada

The Norm

Play Episode Listen Later Mar 15, 2023 20:12


Norm Murray speaks with Tony Anscombe, Chief Security Evangelist with ESET Canada. For 30 years, his company has developed industry-leading IT security software and services to protect businesses, critical infrastructure, and consumers worldwide from increasingly sophisticated digital threats. And now they apply this wisdom to the recent auto theft epidemic. http://www.eset.com

canada norm evangelist eset chief security tony anscombe newstalksauga960am norm murray thenorm
The Public Sector Show by TechTables
Interview with Morgan Wright, Chief Security Advisor at SentinelOne

The Public Sector Show by TechTables

Play Episode Listen Later Jan 26, 2023 144:59


Connect with Morgan Wright: https://www.linkedin.com/in/morganwright150/Follow the Game of Crimes Podcast - https://gameofcrimespodcast.com/ Subscribe to the Game of Crimes Membership on Patreon! https://www.patreon.com/gameofcrimes  SponsorAnd before we jump into today's episode, this podcast is sponsored by  @Sentinelone-inc SentinelOne redefines cybersecurity by pushing the boundaries of autonomous technology —with its singularity XDR platform— SentinelOne is the leader in endpoint protection and beyond. Simply put they stop the bad guys. To learn more about SentinelOne, check out https://www.sentinelone.com  Timestamps0:00 Intro 3:12 The Ultimate Meritocracy: 08:09 K9s4COPs 19:48 Controlled, Classified, Confidential 21:25 "One lesson I've learned after investigating crimes: you follow the facts. Too many people want to change the facts to fit their theory. You don't do that. You change your theory to fit the facts." 29:14 The Fifth Domain 36:03 Background 01:38:51 Part II: Cyberspace A History: The Coming Cyberspace Cold War with Russia 01:49:46 Cyberwarfare and the Strategy of "Low-Intensity Conflict" 01:59:29 Part III: Cybersecurity Threats Coming up in 2023 02:01:19 Deep Fake, AI, ChatGPT 2:22:00 Outro Whenever you're ready, here is the one way I can help you:→ Join the TechTables+ Community Today https://www.techtables.com/membership. Listen on:

CXOInsights by CXOCIETY
PodChats for FutureCISO: How to be a successful CISO in 2023

CXOInsights by CXOCIETY

Play Episode Listen Later Dec 17, 2022 10:47


The role of the Chief Information Security Officer (CISO) is growing, and the scope of digital business intensifies. Among board directors, 64% say their organization is trying to significantly alter its economic architecture to put more emphasis on digital (revenues, margins, productivity, etc.). At the same time, 88% say they recognize cybersecurity is a risk to the business.A great CISO has the ability to assess and prioritize appropriate assets that need to be protected. Understand and prioritize the risks to those assets. Convey those risks in terms that boards can understand to allocate necessary budgets. Identify and implement appropriate controls to protect those assets.In this PodChats for FutureCISO, we are joined by Apol Salud, Chief Security and Digital Officer for Gur Lavi Corporation.1.       How has the role of the CISO shifted in the current environment?2.       When demonstrating business value, what is one of the most important strategies for CISOs to keep in mind?3.       How do you juggle the differing expectations, interests, and demands of leaders in your organisation, as well as users, third-party business partners, regulators, and customers?4.       Coming into 2023, what will be the key challenge facing the CISO?5.       What makes for a successful CISO? What one quality do you think will prove most valuable to a CISO's future?6.       Where do you see the CISO career moving?

The Tech Trek
Empathy-driven process development

The Tech Trek

Play Episode Listen Later Nov 17, 2022 27:50


In this episode, Ty Sbano, an Information Security executive with over 17 years of experience heavily focused on empowering end users securely, talks about “Empathy-Driven Process Development.” He speaks about driving change and how we are changed by empathy. Key takeaways: What is empathy-driven process development Taking yourself out of the equation when changing processes How fast do you want to drive change Understand the impact of change on people The larger the scale of the impact, the more time you might need Understanding your change curve and having your champions Avoiding thrash by making only a finite number of touches to your process Intentional process development Thinking about the process, so your successor is set up for success About today's guest: Ty Sbano is an Information Security executive with over 17 years of experience heavily focused on empowering end users securely. Ty currently serves as Vercel's Chief Information Security Officer (CISO). Previously, Ty was the Chief Security & Trust Officer at Sisense. Ty's career has been focused on developing application and product security programs for Capital One, JPMorgan Chase, LendingClub, and Target. Key areas of knowledge include developing security champions, threat modeling, secure code training, static code analysis, component analysis, dynamic analysis, penetration testing, and red teaming. Outside of being a CISO, Ty is an active angel investor in Silicon Valley CISO Investment Groups (SVCI) and advisor to Cider Security, Nightfall.ai, and Identify Security. Ty's security mentality has been concentrated on enabling engineering and product teams to move securely at the speed of the business to make it a competitive advantage. Ty graduated from Penn State University with a B.S. in Information Science & Technology and from Norwich University with a M.S. in Information Assurance. He currently holds a CISSP, CEH, CCSK, and CPT. LinkedIn: https://www.linkedin.com/in/tysbano/ Thank you so much for checking out this episode of The Tech Trek, and we would appreciate it if you would take a minute to rate and review us on your favorite podcast player. Want to learn more about us? Head over at https://www.elevano.com Have questions or want to cover specific topics with our future guests? Please message me at https://www.linkedin.com/in/amirbormand (Amir Bormand)

The Jedburgh Podcast
#079: Global Security Exchange - Chief Security Officers Rich Davis of United Airlines & Steve Bernard of Sony Pictures l International SOS

The Jedburgh Podcast

Play Episode Listen Later Oct 13, 2022 67:42


Security is one of our basic, most fundamental needs. To keep up on the latest trends in security Fran Racioppi traveled to the Global Security Exchange in Atlanta to sit down with retired Chief Security Officers Rich Davis of United Airlines and Steve Bernard of Sony Pictures.Rich oversaw United's response to the 9/11 attacks involving two of United airplanes. Steve led Sony through the North Korean cyber attack after the premier of The Interview starring Seth Rogan and James Franco. They cover the evolution of the industry, the threats we face in both the physical and cyber domains, how thought leaders are needed in senior security positions, and how we build a security culture in our organizations. The world is a complex place and today's companies require dedicated support for the protection of their number one asset - their people. International SOS is the industry leader in travel risk management, medical support, evacuations, mental health, crisis management and workforce resilience. On the ground in over 90 countries and 1000 locations, International SOS is there 24/7 no matter the challenge. Learn more at InternationalSOS.com and @intlsos. Steve Bernard is the Founder of Bernard Global and Rich Davis is the founder of Rich Davis Security Consulting. Read the full episode transcription here and learn more on The Jedburgh Podcast Website. Watch the full video version of Fran's conversation with Steve and Rich on YouTube. Subscribe to us and follow @jedburghpodcast on all social media. Highlights:-0:00 Welcome to the International SOS booth, GSX and ASIS International-6:29 The chief security officer as a thought leader-15:01 Rich's career at United Airlines from the kitchen to chief security officer-19:27 Steve's transition from Vietnam Veteran to Corporate Security-23:30 The evolution of the security industry-26:00 Prioritizing security at United Airlines and Sony Pictures -33:47 North Korea's hack of Sony Pictures-37:37 The impact of 9/11 on United and the hack on cyber-45:14 The next generation of security leadership and the remote workforce-53:05 The role of International SOS-59:55 Three Daily FoundationsQuotes: -”We're all about assessing risk, assessing threats and how to counter those threats, because the most important thing we do is protect people and assets.” (10:08) -”Crisis management begins long before the crisis has arrived.” (12:26)-”I worked for United Airlines for 40 years. I actually started in the kitchen.” (16:22)-”A CSO doesn't have to be the expert in all this. They have to figure out how do they add the greatest value and to set the strategy, lead the team.” (21:28)-”Everything's a priority, that was my mindset.” (29:39)-”When you connected, the meltdown on your hard drive started. ” (35:22)-”They're in 27 different call centers around the world.” (55:10)This episode is brought to you by Jersey Mike's, 18A Fitness, and Analytix Solutions

Cybercrime Magazine Podcast
The Modern Security Architecture. Managing Through Uncertainty. Beth Anne Bygum, Acxiom.

Cybercrime Magazine Podcast

Play Episode Listen Later Sep 15, 2022 19:32


Beth Anne Bygum is the SVP and Chief Security & Compliance Officer at Acxiom. In this episode of The Modern Security Architecture, Beth Anne joins host Hillarie McClure to discuss the three must-have investments needed while managing through uncertainty. Safebreach provides a breach and attack simulation platform that identifies vulnerabilities in cybersecurity environments by mimicking the likely attack paths and techniques used by malicious actors. To learn more about our sponsor, visit https://safebreach.com

AML Conversations
Chief Security Officers need to be more proactive on issues of national security

AML Conversations

Play Episode Listen Later Sep 13, 2022 24:40


Mark Freedman, CEO / Founder of Rebel Global Security and former Chief of Section in the Counter-Terrorism Bureau at the US State Department discusses the need for Chief Security Officers to be more proactive on issues of national security including cyber, terrorism, and other issues related to financial crime.

Clean Talk - The State of Infection Control w/ Brad Whitchurch
Clean Talk | Ep 35 | Transforming Healthcare with Telemedicine w/ William Lewis

Clean Talk - The State of Infection Control w/ Brad Whitchurch

Play Episode Listen Later Aug 26, 2022 30:28


In this week's episode of Clean Talk, William Lewis, General Counsel and Chief Security & Privacy Officer at MORE Health, joins us to reveal the solutions his company provides to improve healthcare overall.Tune in to hear about a range of topics including:• How the innovation of telemedicine is growing the market for American doctors.• How important expert medical second opinions are.• What it's like pushing new methods of caretaking through healthcare systems.• What telemedicine could mean to the reduction of hospital acquired infections.• And more!William Lewis is the General Counsel and Chief Security & Privacy Officer at MORE Health. MORE Health helps improve patient outcomes by connecting patients from around the world with physicians at leading academic medical centers. Healthcare is highly regulated in all jurisdictions and Will manages MORE Health's legal and regulatory risk. Before joining MORE Health, Will was in private litigation practice. He obtained his LL.M. in Taxation from New York University School of Law and his B.A. from Pomona College.Clean Talk Registration: https://cleantalk.onlineClean Talk Official Website: https://cleantalk.tvClean Talk Youtube: https://youtube.com/CleanTalk_TVLinkedin Group: https://linkedin.com/groups/9094477/Facebook Group: https://facebook.com/groups/986587845276744

HealthcareNOW Radio - Insights and Discussion on Healthcare, Healthcare Information Technology and More
1st Talk Compliance: William J McBorrough, Co-Founder and Chief Security Advisor at MCGlobalTech

HealthcareNOW Radio - Insights and Discussion on Healthcare, Healthcare Information Technology and More

Play Episode Listen Later Jul 27, 2022 25:02


Host Catherine Short welcomes William J McBorrough, co-Founder and Chief Security Advisor at MCGlobalTech, a D.C.-based Information Security Consulting Firm on the topic of “How to Combat Ransomware in Healthcare.” They examine how ransomware attacks have impacted thousands of organizations worldwide with the healthcare sector having been the most targeted. They discuss the state of ransomware in the healthcare sector and best practices to prepare your organization from the inevitable attacks. To stream our Station live 24/7 visit www.HealthcareNOWRadio.com or ask your Smart Device to “….Play Healthcare NOW Radio”. Find all of our network podcasts on your favorite podcast platforms and be sure to subscribe and like us. Learn more at www.healthcarenowradio.com/listen

David Webb Show
Morgan Wright, Chief Security Advisor at Sentinel One

David Webb Show

Play Episode Listen Later Jun 11, 2022 14:45


Morgan Wright joins David Webb to discuss voting software vulnerabilities in some states.

Let's Talk About Digital Identity
Enabling and Protecting Children’s Digital Identity with Nicky Hickman and Rachel O'Connell, TrustElevate – Podcast Episode 70

Let's Talk About Digital Identity

Play Episode Listen Later Jun 8, 2022 41:13


Let's talk about digital identity with Rachel O'Connell, Founder & CEO, and Nicky Hickman, Product Innovation Manager, at TrustElevate. In episode 70, Nicky Hickman and Rachel O'Connell of TrustElevate discuss children's digital identity – why this is so important, what challenges are currently being faced and what solutions need to be put in place to help protect children within the digital landscape. [Transcript below] "There is a clear and present need for regulatory drivers to enhance children's safety online to ensure the companies are held accountable and are transparent in terms of the measures that they take to keep kids safe online. And critical and central to that is digital identity." Nicky Hickman Nicky Hickman is a freelance product & innovation manager based in the UK with international experience in APAC, Europe and Africa.  With a background in telecoms she has worked with digital identity and personal data markets for ~20 years researching, designing and delivering multi-channel large scale CIAM services and strategies for clients including Vodafone, O2, GSMA, Barclays, Sky and Verizon.  In the last 5 years she has been a contributor to open-source communities at the Sovrin Foundation, where she served as a Trustee and Chair of the Identity for All Council,  and at Trust over IP Foundation where she is a co-chair of the Human Experience Working Group.  Nicky is also an active researcher and is an industry contributor and guest lecturer at the University of Jyväskylä's Blockchain & Digital Identity Start-Up Lab in Finland. Find Nicky on LinkedIn. Dr. Rachel O'Connell Dr Rachel O'Connell is a leading expert on online child safety. Her PhD examined paedophile activity online and  the implications for investigative strategies. Rachel set up the first UK Internet safety centre in 2000; she was Chief Security office for Bebo a social networking platform 2006-2010. Rachel is the founder of TrustElevate, author of a technical standard published by the British Standards Institution that describes how to verify the age band a person belongs in a privacy-preserving, secure manner. Find Rachel on LinkedIn. We'll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!   Podcast transcript Let's Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla. Oscar Santolalla: Hello and welcome to this new episode. And today, we'll talk about enabling and protecting children's digital identity. And for that, we have two guests who are working together in this very important issue. Let me introduce my first guest, it's Nicky Hickman. She is a Freelance Product and Innovation Manager based in the UK with international experience in the Asia Pacific, Europe and Africa. With a background in telecoms, she has worked with digital identity and personal data markets for 20 years researching, designing and delivering multichannel, large-scale CIAM services and strategies for clients including Vodafone, O2, the GSMA, Barclays, Sky, and Verizon. All of Nicky's recent work focuses on using digital identity to promote socio-economic inclusion, and impact against the United Nations Sustainable Development Goals with an underlying commercial business model that is sustainable for the long-term. For the last year, Nicky has focused on youth and child identity through work with a UNICEF YOMA programme, and with TrustElevate as a Product and Innovation Manager. Our second guest is Dr. Rachel O'Connell. She is a leading expert on online child safety. Her PhD examined paedophile activity online and the implications for investigative strategies. Rachel set up the first UK Internet Safety Centre in 2000. She was Chief Security Officer for Bebo, a social networking platform between 2006 and 2010. Rachel is the founder of TrustElevate. She's an author of a technical standard published by the British Standards Institution that describes...

ITSPmagazine | Technology. Cybersecurity. Society
A Conversation With Chief Security & Trust Officer, Malcolm W Harkins | Securing Bridges With Alyssa Miller | Episode 11

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 2, 2022 41:45


In this episode, Alyssa talks to Malcolm Harkins, Chief Security & Trust Officer.________________________________It is a podcast, yes, but you can join us as we record each episode live on Twitter, LinkedIn, Facebook, and Youtube.Live, Every Wednesday at 1pm PDT | 4pm EDT (USA) | The Recorded Podcast version is published a few days later.Our ability to improve the security posture of our organizations depends heavily on connecting the security function with the various aspects of the business. Join our host, Alyssa Miller, as she and her guests examine key ways to build and secure the bridges between security, product development, the executive suite, and beyond.Listen in as Alyssa sits down with senior and executive security leaders from various industries to share stories of successes and failures we experience working across business teams. Explore practical strategies for building sponsorship and gaining buy-in for security initiatives.It's time to build and secure the bridge to the business.________________________________GuestMalcolm M HarkinsChief Security & Trust Officer at Epiphany Systems [@EpipSys]On LinkedIn | https://www.linkedin.com/in/malcolmharkins/On Twitter | https://twitter.com/ProtectToEnable________________________________HostAlyssa MillerOn ITSPmagazine  

Acxiom Podcast
Real Identity: Knowledge Builds Trust

Acxiom Podcast

Play Episode Listen Later Apr 12, 2022 27:44


Identity and privacy are tied together to drive value for brands and consumers, and as data breeches continue to rise, cyber security is the foundation for the identity supply chain. Acxiom's Beth-Anne Bygum, Chief Security and Compliance Officer, joins the Real Identity podcast to discuss the booming cyber security business and what that means for real Identity. Cyber security is the enabler of a frictionless ecosystem, connecting brands and consumers to enable the ultimate relationship builder: trust.

Dr. Dark Web
How to Converge Security and Business to Reduce Risk with Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea

Dr. Dark Web

Play Episode Listen Later Mar 2, 2022 46:49


Digital security and risks are some of the most significant concerns companies face. And they look for various ways to mitigate those risks and establish a safe environment for their core business operations, even implementing security solutions that merely put a band-aid on vulnerabilities.But what companies don't know is that the key to augmented security lies in asking the right questions. And changing the mindset that it's not security first, it's business first, it's people first, it's risk. And security is a supporting pillar in that.In this episode of Dr. Dark Web, Chris Roberts welcomes Joseph Carson, the Chief Security Scientist (CSS) and Advisory CISO at Delinea. They get into the role of threat intelligence in strengthening security, the importance of knowing where the threats come from, how to translate intelligence and risk to the board, and why people should always come first.

RSA Conference
What's Trending in Protecting Data & the Supply Chain

RSA Conference

Play Episode Listen Later Feb 1, 2022 39:00


Protecting Data & the Supply Chain so deeply intertwined with everything from software to identity. Join Program Committee members Edna Conway and Diana Kelley as they discuss the challenges that folks are struggling with right now and some potential mitigation strategies. We'll explore what's happening with Log4j and other vulnerabilities as well as the need for a software Bill of Materials (SBOM). Speakers: Edna Conway, Vice President, Security & Risk Officer, Azure, VP, Chief Security & Risk Officer, Azure Microsoft Diana Kelley, CTO and Co-Founder, SecurityCurve Kacy Zurkus, Content Strategist, RSAC

Fortinet Cybersecurity Podcast
Cyber Fire Fight #4 - From Enforcer to Strategic Partner with Beth Anne Bygum

Fortinet Cybersecurity Podcast

Play Episode Listen Later Jan 12, 2022 19:51


This was recorded live on 01/11/22 Welcome to the Cyber Fire Fight podcast where we discuss “Fight Fire with Fire: Proactive #Cybersecurity Strategies for Today's Leaders,” a new book offering collective advice from industry experts to improve cyber strategies. Join #Fortinet's Renee Tarun, Deputy CISO, and Beth-Anne Bygum, Chief Security & Compliance Officer at Acxiom as they discuss their perspectives around the changing role of governance, risk, and compliance in #cybersecurity. #CyberFireFight

LeaderTalks@Acxiom
Lead with Business Savvy, Part 3: Business Acumen and Command Skills - with Beth-Anne Bygum and Dave Van Epps

LeaderTalks@Acxiom

Play Episode Listen Later Dec 9, 2021 57:07


In this episode, Amy chats with Beth-Anne Bygum, Chief Security & Compliance Officer, and Dave Van Epps, a Senior Director of Delivery in Financial Services, to continue discussing the leader expectation of Lead with Business Savvy with a focus on the competencies of Business Acumen and Command Skills. Business Acumen is all about understanding Acxiom's business, our industry, our client's business and really understanding our financial processes and the role leaders play in all of these elements. Command Skills is all about using your business savvy to take stands when necessary because you understand the implications and risks of situations as they arise because of your expertise, all while maintaining relationships and getting to the desired outcomes, especially when things aren't going to plan. Show Links: Strategic Pause by Don Graumann In Our Weakness We Are Strong by Dave Van Epps The Tipping Point by Malcom Gladwell Outliers by Malcom Gladwell LeaderTalks@Acxiom is edited by Levi Gilbert.

CTO Mastermind: Il Podcast per i CTO
Assumere un manager | 💻🍔 CTO Lunch #039

CTO Mastermind: Il Podcast per i CTO

Play Episode Listen Later Dec 1, 2021 53:43


Abbiamo parlato spesso di Talent Acquisition, vero: ma recruting e hiring sono dei processi molto diversi quando cerchi un Manager, come può essere un CTO o un Chief Security o un Engineering Manager. Come identificare la figura più adatta? E dove cercarla?  Ne abbiamo parlato in questo CTO Lunch con Alex Pagnoni e la Community del CTO Mastermind. Buon ascolto!  🖖 HOST: Alex Pagnoni: imprenditore di servizio e di prodotto, https://www.axelerant.it/ (Fractional CTO) e Managing Partner di https://www.axelerant.it/ (Axelerant). Sono speaker, content creator, conduttore del CTO Show e del CTO Podcast, fondatore della https://www.ctomastermind.it/community/ (community CTO Mastermind) (+380 CTO italiani). 🤝 PARTNER: Vuoi conoscere e confrontarti con più di 270 CTO e Leader Tecnologici? Ti aspettiamo nella Community CTO Mastermind di Alex Pagnoni. Per entrare vai su https://www.ctomastermind.it/community/ (www.ctomastermind.it) Ci vediamo su Slack! Ringraziamo della partecipazione: Nicolò Risitano (CTO di GenomeUp), Roberto Luberti (AWS Cloud Architect di Overdata Sagl), Roberto Martino, Cesare D'Amico (Senior Engineering Manager di WorkWave), Roberto Beneduci (Founder & CEO di CoreTech), Mirko Di Serafino (Head of DevOps di Talent Garden). ⭐️⭐️⭐️⭐️⭐️ Il Podcast ti è piaciuto? Aiutaci a farlo a conoscere a altri CTO e leader tecnologici. Aggiungilo ai tuoi preferiti e lascia una recensione su Apple Podcast o su Podchaser!

Cloud Security Reinvented
The Challenges and Stress of Being a CSO with Ty Sbano

Cloud Security Reinvented

Play Episode Listen Later Sep 20, 2021 25:45


One of the aspects where we can see how much the technology has progressed is the cloud system. Cloud has become more prevalent than on-premise IT infrastructure, mainly since it is more secure and more reliable than it used to be at its very first beginnings. But how is it like to be a part of cloud security systems, or, better said, a CSO?Ty Sbano is the Chief Security and Trust Officer at Sisense. His career journey has been pretty rich and interesting and has helped him determine his end goal: becoming a CSO. Being CSO can be stressful, which is why Ty suggests that one must be ready for the stress before committing to cybersecurity. Aside from coping with all the stress and challenges that come with cloud security, it is fundamental to have a strong mentor who will help you go through the entire process.In this episode of Cloud Security Reinvented, Ty Sbano and Andy Ellis have an insightful conversation about the basic concepts of cloud security, data analytics, risk management, and other essential aspects future CSOs will find incredibly handy.

stress challenges cloud cso csos andy ellis sisense trust officer chief security
Tomorrow's Tech Today
Next Generation Security meets Diversity in Tech with Lesley Kipling, Chief Security Advisor at Microsoft

Tomorrow's Tech Today

Play Episode Listen Later Mar 31, 2021 26:42


In this episode we meet the pioneering Lesley Kipling, former Geologist now Chief Security Advisor at Microsoft. This is a deep dive across all aspects of Next Generation Security considering the current cybersecurity threat landscape and growing areas of vulnerability from SME to Enterprise, and through IT & OT Convergence. We explore how to build Zero Trust defence in depth with technology from the latest developments in the Cyber Defence Operations Center, to advances that bring together the power of Cloud Computing with Machine Learning and integrated signals to detect and remedy issues real-time. We also discuss the importance of education, embedding security in culture, values and shared responsibility, and how to better build inclusion and diversity in the sector. And we would love your thoughts on the episode too - thanks for listening! Sally, Lesley and the #TTT Team Please join us on Twitter @techradiotttAnd our host Prof. Sally Eaves on Twitter @sallyeavesAnd LinkedIn www.linkedin.com/in/sally-eaves

SecureConnection Podcast: IT Security/Security Experts for MSP’s

Brian talks risk appetite with James Bowers II, CEO and Chief Security and Information Officer with Input Output. James takes the 10,000 ft. view and breaks down risk, both quantitatively and qualitatively and then gives some good insights on determining where you are at and what really is needed for you to become compliant. In many cases we may already be well on our way.

Check Point CheckMates Cyber Security Podcast
S03E01: Chief Security Advisor Dan Wiley on Cyber Threats in 2020

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Jan 18, 2021 16:40


As part of our CheckMates Fest, Check Point's Chief Security Advisor Dan Wiley gave us an overview of what Incidence Response saw in 2020 in terms of threats. To see what Dan Wiley looked like during his presentation, head over to the show page on CheckMates.

The Get Cyber Resilient Show
Ep 30 | How Estonia became a global cyber security heavyweight - with Joseph Carson, Thycotic's Chief Security Scientist

The Get Cyber Resilient Show

Play Episode Listen Later Sep 7, 2020 53:26


This week Gar is joined by Joseph Carson, Thycotic's Chief Security Scientist and Advisory CISO. He's the architect behind some of the worlds largest cloud environments, has worked to digitally transform cyber security education to online delivery, and now based in Estonia he has been working in areas such as digital identity. He's won many awards and is driven by a desire to give back to the community. Joseph walks us through what cyber resilience looks like at a country level, including how Estonia has gone about building trust with their citizens. He speaks about education for cyber security, immigration policies, data resilience through data embassies, and Jospeh outlines the jaw dropping economic benefits that an advanced digital society can achieve through removing friction. Connect with Joseph on LinkedIn: https://www.linkedin.com/in/josephcarson/ Follow Joseph on Twitter: https://twitter.com/joe_carson Check out Jospehs books: https://thycotic.com/resources/wileys-dummies-cybersecurity/ https://thycotic.com/resources/wileys-privileged-access-cloud-security-for-dummies/

Global CISO Forum Podcast
Global CISO Forum 2020 - Todd Bell

Global CISO Forum Podcast

Play Episode Listen Later Aug 18, 2020 26:22


Todd Bell is the Chief Security & Trust Officer for Verdigris Holdings, a 100% cloud Banking as a Service (BaaS) located in Scottsdale, AZ. Todd brings more than 15+ years of information security & technology experience working at Fortune 500 global corporations to Start-up ventures. Bell is a recognized industry veteran that serves as a Subject Matter Expert (SME) for various analyst firms needing industry insights and market trends. Bell has made numerous contributions to the technology and cyber industry as CISOonline.com contributing writer and written white papers for EC Council and various organizations.Prior to Verdigris Holdings, Todd served as VP of Enterprise Architecture & CISO for Intersec Worldwide, advising corporations how to build, sustain, and operationalize cybersecurity programs at scale. Before joining Intersec Worldwide, Todd was a Customer Chief Information Security Officer for a major franchise while at Fishnet Security and worked at Verizon Business that was formerly Cybertrust.Bell holds an M.B.A. from Regis University in Denver, CO and bachelor's degree in Business Information Systems. Bell holds a variety of professional certifications consisting of Corporate Governance (SOX) from Tulane University Law School, PMP credential from Project Management Institute, Information Security (CISSP), and a certified Master Project Manager from Regis.Register for Global CISO Forum: https://globalcisoforum2020.eventbrite.com/?aff=ToddBell Register for Hacker Halted: https://hackerhalted2020.eventbrite.com

fortune register forum banking scottsdale regis ciso pmp regis university project management institute enterprise architecture service baas verizon business global ciso trust officer business information systems chief security subject matter expert sme ec council todd bell
The SecureWorld Sessions
Developing Cybersecurity Advocates

The SecureWorld Sessions

Play Episode Listen Later Feb 25, 2020 15:00


The SecureWorld Sessions is a cybersecurity podcast that gives you access to people and ideas that impact your career and help you secure your organization. In this episode: How do you develop cybersecurity advocates across the organization? Featured interviews with: Deneen DeFiore, VP & CISO, United Airlines; Zaki Abbas, VP & CISO, Brookfield Asset Management; Milinda Rambel Stone, VP & CISO, Provation Medical; Brent Lassi, CISO, Bluecore; Mike Muha, Chief Security and Privacy Officer, Workforce Software. Also, Trend Micro shares about Dynamic Challenges to Threat Detection and Endpoint Security—and how to overcome them. RESOURCE LINKS: • SecureWorld 2020 conference schedule: https://www.secureworldexpo.com/events • Trend Micro “Dynamic Challenges to Endpoint Security” paper: https://www.trendmicro.com/vinfo/us/security/news/security-technology/dynamic-challenges-to-threat-detection-and-endpoint-security-and-how-to-overcome-them