Podcasts about integrating security

  • 33PODCASTS
  • 47EPISODES
  • 35mAVG DURATION
  • ?INFREQUENT EPISODES
  • Oct 9, 2025LATEST

POPULARITY

20172018201920202021202220232024


Best podcasts about integrating security

Latest podcast episodes about integrating security

Prolonged Fieldcare Podcast
Prolonged Field Care Podcast: Mastering Triage

Prolonged Fieldcare Podcast

Play Episode Listen Later Oct 9, 2025 58:36


In this episode of the PFC podcast, Dennis, Andrew, and Rick delve into the complexities of triage in emergency medicine, particularly in mass casualty situations. They discuss the importance of understanding triage categories, share real-life experiences, and emphasize the role of leadership and resource management in effective triage. The conversation also highlights the need for integrated training that encompasses security and command aspects, as well as the necessity of adapting training scenarios to prepare for the realities of mass casualty events. The episode concludes with reflections on how to improve triage processes and training methodologies.TakeawaysTriage is chaotic and unpredictable, requiring intuitive methods.In mass casualty situations, focus on immediate life threats first.Leadership is crucial in managing triage and patient movement.Dynamic triage requires continuous reassessment of patient conditions.Training should include realistic scenarios where not all patients survive.Effective communication and coordination are essential in triage.Incorporate security measures in triage training.Training should align with both medical and non-medical goals.Utilize available resources efficiently during triage.Commanders must be involved in triage decision-making processes.Chapters00:00 Introduction to Triage and Its Importance02:27 Understanding Triage Categories07:11 Real-Life Triage Experiences09:43 The Role of Leadership in Triage19:32 Dynamic Triage and Resource Management29:04 Integrating Security and Command in Triage38:40 Training for Mass Casualty Scenarios50:40 Final Thoughts on Triage and TrainingFor more content, go to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.prolongedfieldcare.org⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Consider supporting us: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠patreon.com/ProlongedFieldCareCollective⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ or ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.lobocoffeeco.com/product-page/prolonged-field-care⁠

Learning Through Technology
[Re-Release] Building Safer Schools Through Technology – with Lane Young

Learning Through Technology

Play Episode Listen Later Jun 18, 2025 36:11


Release Note:This is a re-release of one of our most popular episodes, originally aired as part of our school safety series. As IT and operations teams head into summer project season, we're revisiting this insightful conversation with Lane Young, whose unique dual role offers practical strategies for integrating safety, technology, and school culture.In this episode of Learning Through Technology, hosts Alex Inman and Robert Cireddu are joined once again by Lane Young, Director of Strategic Operations and Technology at Phillips Brooks School, to explore the intersection of physical security and technology in schools. They discuss the importance of cross-department collaboration, balancing safety measures with an open school culture, and the impact of funding on security initiatives. Lane shares insights on integrating long-term physical systems with evolving technologies to create cohesive, effective safety strategies. This episode offers practical advice for educators and administrators aiming to enhance school security while maintaining a welcoming environment.Here are the key touchpoints from the discussion:The Importance of Integrating Security and Technology  Navigating the Dichotomy of Safety and Openness  Flexibility in Funding for Safety Initiatives  Perception of Safety vs. Reality  Lifecycle Management of Security Systems  The Value of Integrated Roles in EducationLane Young is the Director of Strategic Operations and Technology at Phillips Brooks School, overseeing the implementation of technology leadership and strategic initiatives. His career in EdTech began unexpectedly after transitioning from a role as a 4th-grade teacher and years of experience working in public libraries. A chance opportunity led him into educational technology, and he quickly rose to a leadership position. In his current role, Lane focuses on executing the school's strategic plan and managing key areas like safety and security, ensuring digital and physical protection. His journey highlights his adaptability and dedication to educational advancement. We'd love to hear from you! Send us questions or comments at podcast@stsed.com.If you enjoyed this episode, make sure to subscribe, rate, and review it on:Apple https://podcasts.apple.com/us/podcast/learning-through-technology/id1713365771 Spotify  - https://open.spotify.com/show/2jCpGtOzrs8NwQC35xaUwKYouTube - https://www.youtube.com/@UCzWUmvnyyYS7DpK41uhLpJg Like what you're hearing on the podcasts and want to dive deeper?Follow us on  https://www.linkedin.com/company/learning-through-technology-podcast/ here. A big thank you to our sponsors!FETC:Join thousands of educators at FETC 2025! Discover the latest in education technology with exclusive sessions, hands-on workshops, and networking opportunities. Register by January 13 to save with Standard pricing. Use promo code TECHLEARN2025 to get an additional 10% off. Visit fetc.org to learn more!ViewSonic: ViewSonic is your go-to technology partner for engaging students, fostering collaboration, and elevating learning outcomes. ViewSonic is more than a brand- it's your educational edge- offering a broad array of future-ready audio-visual solutions, training, and tools that adapt to your school's changing needs. Explore the possibilities today at viewsonic.com/edu!Lenovo: Imagine a future where students can access tools that spark learning, growth, and creativity. At Lenovo, our K-12 solutions are designed to create a world where edtech tools are safe and secure, engaging and easy to use, and built for productivity wherever learning occurs. Visit us at www.lenovo.com/us/en/student/!

Prolonged Fieldcare Podcast
Prolonged Field care Podcast 225: Mastering Triage

Prolonged Fieldcare Podcast

Play Episode Listen Later Apr 14, 2025 58:38


In this episode of the PFC podcast, Dennis, Andrew, and Rick delve into the critical topic of triage in emergency medicine. They explore the complexities of triage during mass casualty situations, emphasizing the importance of quick decision-making and prioritization of patient care. Andrew shares his experiences as an emergency medicine physician, highlighting the chaotic nature of triage and the necessity of using intuitive methods to assess patients effectively. The conversation covers various triage categories, techniques, and the significance of clinical judgment in determining patient needs during emergencies. This conversation delves into the complexities of triage in emergency medical situations, emphasizing the importance of decision-making under pressure, the role of medical leadership, and the integration of security measures. The speakers discuss the dynamic nature of triage, the ethical dilemmas faced in resource allocation, and the necessity of effective communication and collaboration among medical teams and command structures during mass casualty events. This conversation delves into the complexities of triage in high-pressure medical situations, particularly in military contexts. The speakers discuss the importance of effective training, the management of mass casualty scenarios, and the need for a comprehensive approach that includes both medical and non-medical personnel. They emphasize the necessity of adapting training to reflect real-world challenges and the importance of leadership in ensuring successful outcomes during emergencies.TakeawaysTriage is never perfect; it's chaotic and unpredictable.Use the simplest methods for triage in emergencies.Identify who is dying now versus who is stable.Focus on life-saving interventions first.Triage is a continuous process, not a one-time event.Utilize all available resources during a mass casualty.Clinical judgment is crucial in triage decisions.Trust your instincts when assessing patient urgency.Most patients in mass casualty scenarios are routine or priority.Effective communication and organization are key in triage situations. Triage decisions must be made quickly and efficiently under pressure.Assessing patient stability is crucial for effective resource allocation.Medical leaders must maintain situational awareness during triage.Communication between medical and non-medical leaders is essential.Security measures must be integrated into medical response plans.Triage is a dynamic process that requires constant reassessment.Ethical dilemmas arise when deciding how to allocate limited resources.Collaboration with surgical teams is vital for patient outcomes.Training should address both medical and security aspects of triage.Effective management of patient flow can improve overall care during crises. Triage in high-volume situations requires strategic patient distribution.Chapters00:00 Introduction to Triage and Its Importance03:05 Understanding Triage Categories09:01 Triage Techniques and Strategies11:59 Evacuation Categories and Decision Making14:59 Clinical Judgment in Triage21:20 Assessing Patient Stability and Resource Allocation25:19 Security Considerations in Mass Casualty Events29:27 Integrating Security and Medical Response38:50 Triage in High-Volume Situations41:53 Managing Mass Casualty Scenarios44:48 Command and Control in Triage45:57 Defining Success in Mass Casualty Training51:05 Improving Triage Processes57:59 Final Thoughts on Triage and Training Thank you to Delta Development Team for in part, sponsoring this podcast.⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠deltadevteam.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠For more content, go to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.prolongedfieldcare.org⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Consider supporting us: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠patreon.com/ProlongedFieldCareCollective⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ or ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.lobocoffeeco.com/product-page/prolonged-field-care⁠

@BEERISAC: CPS/ICS Security Podcast Playlist
Bridging the Gap: IT vs. OT Challenges and Solutions in Cybersecurity with Chris Robertson

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Feb 4, 2025 67:40


Podcast: PrOTect It All (LS 25 · TOP 10% what is this?)Episode: Bridging the Gap: IT vs. OT Challenges and Solutions in Cybersecurity with Chris RobertsonPub date: 2025-02-03Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationIn this episode, host Aaron Crow welcomes Chris Robertson, CISO at Apogee Defense, to discuss the evolving landscape of cybersecurity, focusing on the distinction and strategy behind Virtual CISO (vCSO) roles.  Chris shares insights from his dual roles at Apogee Defense and as a virtual chief security officer for various companies. The conversation dives into the intricacies and responsibilities of vCSOs, the importance of understanding IT and OT risks, and the necessity of integrating cybersecurity deeply into business practices.  Chris and Aaron explore practical solutions for businesses, emphasizing adaptability and continuous improvement in security measures, drawing parallels between accounting a century ago and cybersecurity today.  They also touch on future trends, the impact of AI on security, and the importance of setting aside egos to foster a culture of learning and collaboration.  Join them as they navigate the challenges and opportunities at the intersection of IT and OT cybersecurity, offering actionable advice and anecdotes from their extensive experience in the field. Key Moments:  00:00 Outsourcing Risk Management Expertise 08:22 Hiring External Experts: Cost-Effective Strategy 12:04 Understanding OT Risks in Cyber Leadership 20:36 MBA Curriculum Needs Security Focus 23:31 Integrating Security in Legacy Systems 27:47 Tech Efficiency and Shadow IT Challenges 35:56 Optimizing Inefficient Appointment Systems 39:08 Bridging Tech and Business Worlds 45:43 Simplifying Risk Communication 51:52 Joe Rogan's Impact and Risks 57:09 AI Evolution: Professionals Riding the Wave 01:05:53 "Embrace Vulnerability, Seek Help" About the guest :  Chris Robertson is a seasoned cybersecurity expert, currently serving as the Chief Information Security Officer (CISO) at Apogee Defense. In addition to this role, Chris extends his expertise as a virtual CISO for various companies across multiple sectors. He specializes in implementing robust security solutions that Apogee Defense delivers to its clients, predominantly within the Small and Medium Business (SMB) space.  With a keen focus on the defense industrial base, Chris's work also spans various other industries, enabling businesses to strengthen their cybersecurity frameworks. He is highly regarded in the industry for facilitating vital connections and contributing to advancing cybersecurity practices. How to connect Chris: https://www.linkedin.com/in/christophersrobertson/ Connect With Aaron Crow: Website: www.corvosec.com  LinkedIn: https://www.linkedin.com/in/aaronccrow   Learn more about PrOTect IT All: Email: info@protectitall.co  Website: https://protectitall.co/  X: https://twitter.com/protectitall  YouTube: https://www.youtube.com/@PrOTectITAll  FaceBook:  https://facebook.com/protectitallpodcast    To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 190: Integrating Security in Software Development - Exploring SDLC, Agile, and DevSecOps for the CISSP (Domain 8.1)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Nov 4, 2024 46:13 Transcription Available


Send us a textUnlock the secrets of integrating security within every phase of software development as we tackle Domain 8 of the CISSP exam. Our exploration begins with a deep dive into the software development lifecycle (SDLC) and its various methodologies like Agile, Waterfall, DevOps, and DevSecOps. Through a gripping tale of a Disney World IT insider's digital manipulation, we underscore the critical importance of safeguarding systems, especially when skilled employees exit the stage. This episode promises to arm you with the knowledge to fortify your organization's cybersecurity posture effectively.We then navigate the contrasting landscapes of software development models, weighing the structured order of the Waterfall model against the adaptive flexibility of Agile and the risk-focused Spiral model. Each approach comes with its own set of challenges and benefits, particularly concerning security integration and usability. Through the lens of iterative feedback and prototype development, we highlight how these methodologies can help refine requirements and minimize ambiguities, ensuring that security and functionality walk hand in hand.Finally, explore how the IDEAL model can transform your organization's security practices. Designed to improve cybersecurity and risk management, this structured improvement approach offers clear phases: Initiating, Diagnosing, Establishing, Acting, and Learning. We also discuss the impactful mission behind CISSP training, where proceeds support a nonprofit for adoptive children. This initiative not only enhances your cybersecurity skills but also contributes to a cause greater than yourself. Join us as we unpack these strategies, providing insights that could significantly shape your cybersecurity career.Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

The Liquid Lunch Project
Integrating Security into Software Development with Brittany Greenfield

The Liquid Lunch Project

Play Episode Listen Later Jul 29, 2024 31:34


  Is your software security strategy an impenetrable fortress or a crumbling wall of illusions?   In this episode of The Liquid Lunch Project, Matthew R. Meehan and Luigi Rosabianca sit down with Brittany Greenfield, the CEO and founder of Wabbi, a continuous Security Platform based in Boston. Wabbi's mission is to simplify the integration of security into the software development lifecycle. By providing scalable application security solutions that seamlessly integrate into DevOps pipelines, Wabbi empowers rapid development teams to bridge the gap between security and development without sacrificing velocity or agility.   Brittany shares her journey from being a tech industry rock star to creating a groundbreaking company that integrates security into the software development lifecycle. With a mix of humor and hard-hitting truths, she dives into the importance of embracing imperfections, the realities of cybersecurity, and the critical decisions small and medium-sized businesses must make to protect themselves.   Recognized by the Boston Business Journal as a 40 Under 40 honoree and awarded as a top woman in cyber by Cyber Security Excellence and Cyber Defense Magazine, Brittany is a true pioneer in the cybersecurity field.   Episode Highlights:   The challenges of integrating security into the software development lifecycle. The surprising advice Brittany gives to small business owners about cybersecurity.Real-life examples of cybersecurity breaches and how to prevent them. Her candid take on why she chose to become a founder instead of joining tech giants. Brittany explains the concept of Wabi Sabi and its significance to her company's philosophy.   Brittany's insights are invaluable for anyone looking to understand the complexities of cybersecurity in today's digital landscape. Tune in to discover why securing your software is crucial and learn practical steps to protect your business from cyber threats.  Favorite Quote:   “Starting a business is where overachievers go to fail 99% of the time. Accept that this journey is inherently imperfect.”   Connect with Brittany: https://www.brittanygreenfield.com/  https://www.linkedin.com/in/brittanygreenfield/   Stay Connected: Connect with Matt and Luigi on Instagram: @matthew.r.meehan @luigi_rosabianca @theLiquidLunchProject @ShieldAdvisoryGroup Visit The Liquid Lunch Project website and subscribe to The Weekly, our Friday morning newsletter, for all the latest in the world of finance, tech, small business, and more. www.theliquidlunchproject.com Make sure you never miss an episode — check out The Liquid Lunch Project on Apple Podcasts, and don't forget to subscribe, rate, and review.      

Government Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Government Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Government Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Government Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Data Breach Today Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Data Breach Today Podcast

Play Episode Listen Later Jun 24, 2024


Data Breach Today Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Data Breach Today Podcast

Play Episode Listen Later Jun 24, 2024


Banking Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Banking Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Banking Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Banking Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Healthcare Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Healthcare Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Healthcare Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Healthcare Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Careers Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Careers Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Careers Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Careers Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Info Risk Today Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Info Risk Today Podcast

Play Episode Listen Later Jun 24, 2024


Info Risk Today Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Info Risk Today Podcast

Play Episode Listen Later Jun 24, 2024


Credit Union Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Credit Union Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Credit Union Information Security Podcast
Fighting Payment Fraud by Integrating Security Into Finance

Credit Union Information Security Podcast

Play Episode Listen Later Jun 24, 2024


Building Cities, Shaping Lives
Integrating security and FM for smarter buildings

Building Cities, Shaping Lives

Play Episode Listen Later May 7, 2024 17:07


Chan Hsien Hung, Vice President of Integrated Enterprise Services and Sustainability at SJ's member company AETOS, speaks about unlocking the value of integrated facilities management to help clients and asset owners enhance operational efficiency, reduce costs, and meet sustainability targets through data-driven insights. Tune in to discover how digitalisation and AI are reshaping the built environment industry.This podcast is brought to you by SJ.

The Cybersecurity Readiness Podcast Series
Securing Application Programming Interfaces (APIs)

The Cybersecurity Readiness Podcast Series

Play Episode Listen Later Apr 10, 2024 38:44


Application Programming Interfaces (APIs) play a vital role in modern software development, enabling the integration of services and facilitating the exchange of information. The ubiquity of APIs is a testament to their success in supporting many functions. However, their prominence has also made APIs a target for cyberattacks. Jeremy Snyder, Founder & CEO of Firetail.io, joins me in discussing how to secure APIs effectively. Our discussion revolves around the following questions:What do we need APIs for? Why do we need API security? What are the consequences of lax API security?What are the risks of APIs today? How can we remedy current API security issues?Time Stamps00:02 -- Introduction00:49 -- Setting the Stage and Context for the Discussion02:26 -- Guest's Professional Highlights04:37 -- Overview of APIs09:12 -- Common API Security Risks and Vulnerabilities12:29 -- Design with security in mind13:23 -- Securing APIs13:36 -- Integrating Security into the Development Process13:52 -- Different Ways of Security Testing APIs17:08 -- Vulnerability Monitoring and Promptly Acting on Alerts19:22 -- Role of Humans in Acting on Vulnerability Alerts21:33 -- Staying on the Right Side of the Law23:37 -- Significance of Maintaining Logs25:36 -- Selecting Robust APIs27:59 -- Key Takeaways28:57 -- API Governance30:25 -- Zero Trust Approach32:10 -- Use of APIs in Leveraging Large Language Models (AI)33:41 -- API Governance and Taking Ownership36:12 -- Final ThoughtsMemorable Jeremy Snyder Quotes/Statements"Application Programming Interface (API) -- It's basically the way two pieces of software talk to each other, that can be to send data from system A to system B, or that can be for system A to request system B to process something for it.""We've got sensitive data crossing the wires over an API, but we've also got critical business functions like processing credit card transactions over an API.""API's are pretty much happening behind the scenes, they enable a huge volume of interactions and transactions every day.""So we've been cataloging the API data breaches for the last couple of years, these breaches go back about a decade or started about a decade ago, or let me say started to be recognized about a decade ago. And as we've catalogued them, we've kind of categorized them as well, to try to understand in each of these breach scenarios, what was the primary error or breach vector? How was the API breached? And if there's a secondary cause, or things like that, we look at that as well. Two of the main things that we see are are really authentication and authorization." "Authorization turns out to be the number one root cause of data breaches around API's. And this has been true for many years now.""Proactive security is always much cheaper than reactive security.""From the proactive standpoint, the number one thing that any provider of an API can do is actually just check the API's before they go live.""You should actually pen test your API's before they go live.""Very often, we find that API's get shipped into production environments without going through either the static code analysis, or the pre launch testing." "The average time that a vulnerability existed in a production environment before being patched and updated, was around 180 days.""The best practice that we recommend to customers about reacting to the logs or the alerts or the suspicious conditions that you're seeing in your logs

Security Forum Podcasts
S15 Ep3: Steve Durbin - The Future of the Security Leader: Integrating security with business

Security Forum Podcasts

Play Episode Listen Later Dec 6, 2022 28:52


In today's episode, which was recorded together in the studio — a rare and happy occurrence when we're able to be together in person — ISF CEO Steve Durbin and producer Tavia Gilbert discuss the future of the security leader, including the characteristics of security leaders today compared to those likely to be required in the future, as well as the future operating model of the security function. Mentioned in this episode: ISF Analyst Insight Podcast Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management

leader integrating security information security forum steve durbin tavia gilbert
Security Forum Podcasts
S15 Ep3: Steve Durbin - The Future of the Security Leader: Integrating security with business

Security Forum Podcasts

Play Episode Listen Later Dec 6, 2022 28:52


In today's episode, which was recorded together in the studio — a rare and happy occurrence when we're able to be together in person — ISF CEO Steve Durbin and producer Tavia Gilbert discuss the future of the security leader, including the characteristics of security leaders today compared to those likely to be required in the future, as well as the future operating model of the security function. Mentioned in this episode: ISF Analyst Insight Podcast Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management

leader integrating security information security forum steve durbin tavia gilbert
ITSPmagazine | Technology. Cybersecurity. Society
Security-As-Code | Integrating Security Testing Into The SDLC | A Conversation With Andy Rappaport | Redefining CyberSecurity Podcast With Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Nov 23, 2022 57:14


GuestAndy RappaportData Security Architect at iRobot [@iRobot]On LinkedIn | https://www.linkedin.com/in/andyrappaport/HostSean MartinCo-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martinOn Mastodon | https://infosec.exchange/@seanmartin____________________________This Episode's SponsorsAsgardeo | https://itspm.ag/asgardeo-by-wso2-u8vcEdgescan | https://itspm.ag/itspegweb___________________________Episode NotesWe've come a long way in software development, moving from a months-long waterfall model to a software development lifecycle (SDLC) that's all about continuous improvement and continuous delivery (CI/CD). Has security testing kept up, and how can it fit in? Let's find out during this chat with Data Security Architect, Andy Rappaport.____________________________Resources____________________________To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-cybersecurity-podcastAre you interested in sponsoring an ITSPmagazine Channel?

Redefining CyberSecurity
Security-As-Code | Integrating Security Testing Into The SDLC | A Conversation With Andy Rappaport | Redefining CyberSecurity Podcast With Sean Martin

Redefining CyberSecurity

Play Episode Listen Later Nov 23, 2022 57:14


GuestAndy RappaportData Security Architect at iRobot [@iRobot]On LinkedIn | https://www.linkedin.com/in/andyrappaport/HostSean MartinCo-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martinOn Mastodon | https://infosec.exchange/@seanmartin____________________________This Episode's SponsorsAsgardeo | https://itspm.ag/asgardeo-by-wso2-u8vcEdgescan | https://itspm.ag/itspegweb___________________________Episode NotesWe've come a long way in software development, moving from a months-long waterfall model to a software development lifecycle (SDLC) that's all about continuous improvement and continuous delivery (CI/CD). Has security testing kept up, and how can it fit in? Let's find out during this chat with Data Security Architect, Andy Rappaport.____________________________Resources____________________________To see and hear more Redefining CyberSecurity content on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-cybersecurity-podcastAre you interested in sponsoring an ITSPmagazine Channel?

The Great Conversation
Integrating ”Security and Safety” into the Fabric of the Business

The Great Conversation

Play Episode Listen Later May 31, 2022 31:16


Tyson Aiken is a former executive at Nike with an intelligence background from the CIA. He left Nike and went on a journey exploring different opportunities in the commercial marketplace. When I spoke with him before and during his “sabbatical”, I discovered that his purpose and passion could never be realized in a typical security executive role. I felt he needed to be ‘at the executive table', like many of his peers but with one striking difference: he needed an organizational model anchored with core values and a mission he could believe in. He found one with the Wildlife Conservation Society (WCS), a global company with over 4,000 people, many who are thought leaders in their field. Navigating risk and the opportunity to save endangered species and the world, WCS could be classified as a “security and safety” organization for animals and its people. This great conversation explores .com, .gov, and .org business models, the way growth and profit can obstruct good judgement, and the integration of the business model with a data driven security model. Enjoy the conversation!

IT Visionaries
Integrating Security and Performance with Dr. Robert Blumofe EVP & CTO, Akamai

IT Visionaries

Play Episode Listen Later Feb 8, 2022 38:25


Likely on the phone in your hand, while you're playing this very podcast, is an app or site using Akamai in the background, so that you can listen, search, and discover new information as fast as you can think, type, or speak. Accelerating the delivery of the right content and blocking potentially harmful content are the nitty-gritty details that Akamai solves to give you a safe and seamless experience. Leading the charge to improve security and accelerate connectivity is Dr. Robert Blumofe, Executive Vice President and CTO of Akamai. Main TakeawaysPower and Protect Together: A common problem with security is that it slows things down for users and causes them to want to avoid using the security measures in the first place. To solve this problem, Dr. Blumofe explains that Akamai has integrated security and performance products on its platform so that they can work cooperatively. The lesson here for any sort of business is to constantly be considering how security and performance can function seamlessly so that neither is hindered by the other,Endpoint to Endpoint Mindset: Since the world is becoming more remote and more open, security must adapt to this environment. According to Dr. Blumofe, this means the framework of being on a network versus off a network is no longer really applicable. Instead, it is more helpful to consider how apps are connected together from one endpoint to another.The Office as a Coffee Shop: You can think about a new problem, like an increase in remote work, as being stressful, or as a chance to reframe it as an opportunity. Dr. Blumofe points out that returning to the office for face-to-face time will be even more purposeful — sort of like hanging out at the coffee shop with colleagues. He describes solving for the new remote office network as a high-performance coffee shop as being a “freeing and enabling concept.” The new perimeter-less architecture of access can actually facilitate collaboration.IT Visionaries is brought to you by the Salesforce Platform - the #1 cloud platform for digital transformation of every experience. Build connected experiences, empower every employee, and deliver continuous innovation - with the customer at the center of everything you do. Learn more at salesforce.com/platform

CISO Stories Podcast
Developing Secure Agile Code Quickly is Very Achievable! - Glenn Kapetansky - CSP #26

CISO Stories Podcast

Play Episode Listen Later Jul 20, 2021 22:50


Speed to market is the mantra of software development today. This does not mean that a process is not followed, it means that an iterative approach to software development produces code changes and usable code much faster. Join this podcast to learn how security can be imbedded into agile software development to produced fast and secure code.   To view the article from the CISO COMPASS Book that sparked this interview, please visit: https://securityweekly.com/wp-content/uploads/2021/04/CISOCOMPASS_Glenn_Kapetansky_Article.pdf Kapetansky, G. 2019. Integrating Security with SDLC/Agile Development In CISO COMPASS: Navigating Cybersecurity Leadership Challenges with Insights from Pioneers, 1st Ed, pg 27. Fitzgerald, T. CRC Press, Boca Raton, Fl. www.amazon.com/author/toddfitzgerald This segment is sponsored by Cybereason. Visit https://www.cybereason.com/cisostories to learn more about them! Visit https://securityweekly.com/csp for all the latest episodes! Follow us on Twitter: https://www.twitter.com/cyberleaders Follow us on LinkedIn: https://www.linkedin.com/company/cybersecuritycollaborative/

Semaphore Uncut
Justin Cormack on Integrating Security into Software Building

Semaphore Uncut

Play Episode Listen Later Oct 13, 2020 36:10


In this episode of Semaphore Uncut, Justin Cormack, Senior Security Engineer at Docker and member of the Technical Oversight Committee at CNCF, shares insights from the security industry. We talk about why it’s important to think about what could go wrong when building software, how hackers are now exploiting vulnerabilities before shipping your code to production, and what companies can really do and use to secure their products.Key takeaways:Security – a matter of software qualityThe threat modeling practice – understanding the potential security threatsUsing the experience of expertsSupply-chain securitySecurity integration into CI/CD pipelinesImportant vs. overhyped practices in the security industryAbout Semaphore UncutIn each episode of Semaphore Uncut, we invite software industry professionals to discuss the impact they are making and what excites them about the emerging technologies.

The Secure Developer
Ep. #57, Integrating Security into Development with Neil Drennan

The Secure Developer

Play Episode Listen Later May 5, 2020 25:31


Many banks are still running on decades-old sets of legacy technologies, but the security and performance advantages cloud-native systems offer is changing that. Today, we're going into the future of banking technology with Neil Drennan, CTO at 10x Future Technologies. His firm is building the first cloud-native banking platform that can be used by large-scale banks in order to solve the cost and security related problems caused by their legacy systems. Neil fills listeners in about his role in the overall mission at 10x before diving right into the topic of how they integrate security into their development practices. Often security and development teams find it difficult to integrate into each other because they are kept in separate silos from the outset. Things are different at 10x though as Neil explains, talking about the back and forth conversations between his different teams and their use of vulnerability dashboards to keep things transparent. Neil weighs in on the necessity for 10x to get security right, but the benefits of working with banks as clients because of their high level of insight into potential threats. We hear all sorts of amazing improvements for threat monitoring that cloud-native solutions can provide, making the legacy moat model look outdated indeed. A key takeaway from Neil today is the importance of building security into development from the ground up, so tune in to hear how he manages best practices at 10x.10x is looking for more talent to join its team with roles in the UK in London and Leeds. You can see their latest roles here Show notes and transcript can be found here 

Advice Worth Keeping
Integrating security into your DevOps environment

Advice Worth Keeping

Play Episode Listen Later Jun 11, 2019 10:33


environment devops integrating security
Advice Worth Keeping
Integrating security into your DevOps environment

Advice Worth Keeping

Play Episode Listen Later Jun 11, 2019 10:33


environment devops integrating security
Advice Worth Keeping
Integrating security into your DevOps environment

Advice Worth Keeping

Play Episode Listen Later Jun 11, 2019 10:33


environment devops integrating security
Application Security Weekly (Audio)
Level of Trust - Application Security Weekly #51

Application Security Weekly (Audio)

Play Episode Listen Later Feb 20, 2019 52:12


This week, Matt and Paul interview Gurpreet S. Sachdeva, the Assistant Vice President of Technology for Altran! Gurpreet will be discussing "Integrating Security into DevOps"! In the Application Security News, A PNG Android Vulnerability, 620 million stolen accounts for sale on the dark web, how shifting security left speeds development, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode51 Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

trust interview technology development security android hacking breach devops dark web leftists png assistant vice president devsecops asw gurpreet altran paul asadoorian integrating security matt alderman application security weekly application security news gurpreetssachdeva stolenaccounts gurpreet s sachdeva
Paul's Security Weekly
Level of Trust - Application Security Weekly #51

Paul's Security Weekly

Play Episode Listen Later Feb 20, 2019 52:12


This week, Matt and Paul interview Gurpreet S. Sachdeva, the Assistant Vice President of Technology for Altran! Gurpreet will be discussing "Integrating Security into DevOps"! In the Application Security News, A PNG Android Vulnerability, 620 million stolen accounts for sale on the dark web, how shifting security left speeds development, and more!   Full Show Notes: https://wiki.securityweekly.com/ASW_Episode51 Visit https://www.securityweekly.com/asw for all the latest episodes!   Visit our website: https://www.securityweekly.com Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

trust interview technology development security android hacking breach devops dark web leftists png assistant vice president devsecops asw gurpreet altran paul asadoorian integrating security matt alderman application security weekly application security news gurpreetssachdeva stolenaccounts gurpreet s sachdeva
Paul's Security Weekly TV
Integrating Security into DevOps, Altran - Application Security Weekly #51

Paul's Security Weekly TV

Play Episode Listen Later Feb 19, 2019 27:07


Gurpreet S. Sachdeva is the Assistant Vice President of Technology for Altran. Gurpreet Sachdeva will be discussing "Integrating Security into DevOps"! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode51 Follow us on Twitter: https://www.twitter.com/securityweekly

interview technology devops assistant vice president gurpreet altran integrating security application security weekly gurpreetssachdeva gurpreet s sachdeva
Application Security Weekly (Video)
Integrating Security into DevOps, Altran - Application Security Weekly #51

Application Security Weekly (Video)

Play Episode Listen Later Feb 19, 2019 27:07


Gurpreet S. Sachdeva is the Assistant Vice President of Technology for Altran. Gurpreet Sachdeva will be discussing "Integrating Security into DevOps"! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode51 Follow us on Twitter: https://www.twitter.com/securityweekly

interview technology devops assistant vice president gurpreet altran integrating security application security weekly gurpreetssachdeva gurpreet s sachdeva
Access Control
Ep. 2: Terry Gold Integrating Security Part 2

Access Control

Play Episode Listen Later Aug 13, 2018 22:43


Part 2 of a discussion with Terry Gold of D6 Research on integrating physical and cybersecurity efforts.

gold integrating security
Security Forum Podcasts
ISF Podcast: The challenges integrating security into the product development process

Security Forum Podcasts

Play Episode Listen Later Jul 19, 2018 19:49


ISF Podcast: The challenges integrating security into the product development process by Information Security Forum

Security Forum Podcasts
ISF Podcast: The challenges integrating security into the product development process

Security Forum Podcasts

Play Episode Listen Later Jul 19, 2018 19:49


ISF Podcast: The challenges integrating security into the product development process by Information Security Forum

Software Engineering Institute (SEI) Podcast Series
Integrating Security in DevOps

Software Engineering Institute (SEI) Podcast Series

Play Episode Listen Later Jun 29, 2017 28:50


The term "software security" often evokes negative feelings among software developers because it is associated with additional programming effort, uncertainty, and road blocks to fast development and release. To secure software, developers must follow numerous guidelines that, while intended to satisfy some regulation or other, can be very restrictive and hard to understand. As a result, a lot of fear, uncertainty, and doubt can surround software security. In this podcast, Hasan Yasar discusses how the Secure DevOps movement attempts to combat the toxic environment surrounding software security by shifting the paradigm from following rules and guidelines to creatively determining solutions for tough security problems. Listen on Apple Podcasts.

devops integrating security
Brakeing Down Security Podcast
2015-017: History of ITIL, and integrating Security

Brakeing Down Security Podcast

Play Episode Listen Later Apr 17, 2015 55:59


Much of InfoSec and Compliance is all about processes, procedures, controls, audits, and the proper management of all of these.  To do so, you need a proper framework to make these as seamless as possible. ITIL is one of these types of frameworks. We introduce Mr. Tim Wood on the podcast, who has over 20 years of ITIL experience and began ITIL implementations in banks and Healthcare systems in the United Kingdom. He currently works with different industries to change culture and make an ITIL a reality. This week, we go over the History of ITIL, and understand the various incarnations from v1.0 to v3.0. You quickly understand where security will start fitting into all those facets of the ITIL framework.   Tim Wood's Presentation: https://drive.google.com/file/d/0B-qfQ-gWynwiVS0zLTZidml0VzA/view?usp=sharing (view only)

Software Engineering Institute (SEI) Podcast Series
Integrating Security Incident Response and e-Discovery

Software Engineering Institute (SEI) Podcast Series

Play Episode Listen Later Nov 11, 2008 25:34


Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident. Related Course Managing Computer Security Incident Response Teams Listen on Apple Podcasts.

Human Rights (Video)
Louise Arbour: Integrating Security Development and Human Rights

Human Rights (Video)

Play Episode Listen Later Nov 10, 2008 59:00


Louise Arbour, the former High Commissioner for Human Rights at the United Nations, lays out a strategy for integrating security, development and human rights around the world in this talk to the Joan B.Kroc Institute for Peace & Justice at the University of San Diego. Series: "Peace exChange -- Kroc School of Peace Studies, University of San Diego" [Public Affairs] [Show ID: 15126]

Human Rights (Audio)
Louise Arbour: Integrating Security Development and Human Rights

Human Rights (Audio)

Play Episode Listen Later Nov 10, 2008 59:00


Louise Arbour, the former High Commissioner for Human Rights at the United Nations, lays out a strategy for integrating security, development and human rights around the world in this talk to the Joan B.Kroc Institute for Peace & Justice at the University of San Diego. Series: "Peace exChange -- Kroc School of Peace Studies, University of San Diego" [Public Affairs] [Show ID: 15126]

Software Engineering Institute (SEI) Podcast Series
Resiliency Engineering: Integrating Security, IT Operations, and Business Continuity

Software Engineering Institute (SEI) Podcast Series

Play Episode Listen Later Oct 15, 2007 18:24


By taking a holistic view of business resilience - similar in many ways to classical engineering - business leaders can help their organizations stand up to known and unknown threats. Related Course Introduction to the CERT Resiliency Engineering Framework Listen on Apple Podcasts.