The Next Phase of Cybersecurity: Recent Episodes

EM360

In this EM360 podcast, we investigate the cutting edge Cybersecurity issues that organisations are facing today. These discussions are led by the organisations at the forefront of defence as they walk us through the issues people are facing and how to effectively implement prevention strategies.

View Details

Identity fabric, a contemporary, flexible identity and access management (IAM) architecture, should “be involved at every stage of authentication and authorisation,” says Stephen McDermid, CSO, EMEA at Okta Security.

According to CISCO’s VP, 94 per cent of CISOs believe that complexity in identity infrastructure decreases their overall security.

In this episode of The Security Strategist podcast, Alejandro Leal, podcast host and cybersecurity thought leader, speaks with McDermid about Identity Fabric, the modern threats to identity security, the role of AI in cybersecurity, and the importance of collaboration among industry players to combat these novel threats.

Stephen emphasises the need for organisations to adopt a proactive approach to identity governance and to recognise that identity security is a critical component of overall cybersecurity strategy.

Poor Identity GovernanceEnterprises today face a complicated web of users, applications, and data. Identity, once hailed as a small IT problem, is now at the forefront of cyberattacks, and they are becoming highly lucrative targets for cybercriminals.

Alluding to recent high-profile breaches on the UK high street, McDermid points out the financial impact estimated in hundreds of millions of dollars. The common feature observed among these cyber incidents is the misuse of “poor identity governance.” This happens when users’ old login information lacks multi-factor authentication (MFA) or when attackers use social engineering to reset passwords.

The reality today is that attackers now use automation and AI to find valid identities, which makes their work easier than ever, owing to a vast number of compromised credentials available online. The scale of the threat is massive. McDermid noted that "fraudulent sign-ups actually outnumbered legitimate attempts by a factor of 120." This indicates that organisations need to accept that "a breach is inevitable."

Ultimately, McDermid's message was clear and pressing. He urged CISOs to understand where their identities are throughout their businesses. Furthermore, he stressed on the need to assume a breach and consider how to respond.

The CSO also called for them to challenge their SaaS vendors to commit to the new standards. In his opinion, only through this type of collective action can the security community hope to make a difference in what seems to be a losing battle right now.

Takeaways* Identity Fabric is a framework for managing identities at scale. * Modern attacks exploit poor identity governance and lack of MFA. * Organisations must assume breaches are inevitable and prepare accordingly. * AI can enhance identity threat detection and response. * Collaboration among vendors is essential for improving security standards. * Human oversight is crucial in AI decision-making processes. * Shared Signals Framework improves API efficiency and security. * Interoperability is key to addressing identity security challenges. * Organisations should centralise governance of identities throughout their lifecycle. * CISOs must stay informed about emerging threats and trends.

Chapters* 00:00 Understanding Identity Fabric * 02:21 Modern Threats to Identity Security * 06:32 Collaboration in Cybersecurity * 10:38 AI Agents and Identity Security * 14:14 Key Takeaways for CISOs

View Details

Enterprises can no longer afford the old trade-off between speed and safety. Developers are under constant pressure to release code faster. At the same time, security teams face an endless stream of new threats. The middle ground is clear, and that is software must be secure and resilient from the start, without slowing innovation.

This is the philosophy Ian Amit, CEO of Gomboc AI, shared in a recent conversation with Dana Gardner, Principal Analyst at Interarbor, on the Security Strategist podcast. Amit argues that the next era of DevSecOps depends on rethinking how engineering and security come together.

Moving Beyond Shift-Left FatigueThe traditional push to “shift security left” has often backfired. Developers face alert fatigue, drowning in warnings that obscure the real issues. Security teams end up chasing vulnerabilities rather than preventing them. Amit reframes the goal as engineering excellence:

“I want to be proud of my code. It should be secure, resilient, efficient, and fully optimized. That’s what I call engineering excellence.” — Ian Amit, CEO, Gomboc AI

Attackers only need to succeed once; defenders must be right every time. By closing the gap between development and operations, organizations can cut MTTR and reduce risk exposure.

Balancing AccuracyGenerative tools can accelerate development, but they introduce instability.

“With that 10x code, you’re also getting 10x the bugs,” Amit explains.

Deterministic approaches, by contrast, deliver repeatability and precision. Neither alone is a silver bullet. As Amit puts it:

“Use generative to cut through tedious work. Use deterministic approaches to align output to your own standards. You don’t want someone else’s standards creeping into your environment.”

Seamless DevSecOpsThe future of enterprise security isn’t about more checkpoints. It’s about weaving security into development pipelines, enabling distributed teams to collaborate without friction. Gomboc AI’s approach centres on reducing engineering toil and empowering enterprises to achieve fast, safe, and automated development.

Key Takeaways* Traditional shift-left security can create alert fatigue. * Generative tools speed development but may increase bugs. * Deterministic approaches offer accuracy and repeatability. * Mean time to remediate (MTTR) is the most critical success metric. * Collaboration across distributed teams is essential. * Security must integrate seamlessly with DevOps processes.

Chapters00:00 Introduction to DevSecOps and Its Importance

03:08 Challenges in Traditional Shift Left Approaches

06:07 The Role of AI in Development and Security

08:58 Balancing Generative and Deterministic AI

11:52 Automation and Metrics of Success in Security

14:44 Collaboration in Distributed Teams

17:59 Integrating SecOps into Existing Processes

20:56 Future of AI in DevSecOps

23:53 Gomboc AI's Approach to Bridging Gaps

About Gomboc AIGomboc.ai is a cloud infrastructure security platform built to simplify and strengthen security at scale. By connecting directly to cloud environments it provides complete visibility and protection across risks. Its deterministic engine automatically detects and fixes policy deviations in Infrastructure as Code (IaC), delivering tailored, policy-aligned fixes as pull requests or commits straight into existing DevOps workflows. With Gomboc.ai, enterprises eliminate security backlogs, accelerate remediation, and release with confidence—without slowing innovation.

View Details

In an era of AI, it’s no longer a question of whether we should use it, but instead, we need to understand how it should be used effectively, conveys Sam Curry, the Chief Information Security Officer (CISO) at Zscaler. He believes that the growth of agentic AI is not meant to replace human security teams; rather, it aims to improve the industry as a whole.

In this episode of The Security Strategist podcast, host Richard Stiennon, an author and the Chief Research Analyst at IT-Harvest, speaks with Curry, Zscaler CISO, about the need for a shift to a model derived from authenticity, the role of agentic AI in security operations, and the criticality of awareness in adopting to changes brought by AI.

The conversation also touches on the necessity of establishing trust and accountability in AI systems, as well as the implications for cybersecurity professionals in an increasingly automated world.

AI Allows Easy Transition to Complex & Strategic Work The cybersecurity industry is constantly warring against malicious actors. As attackers become more skilled, especially with AI in the picture now. Security professionals must step up their skills just to keep pace with the advancements brought by AI. Instead of taking away jobs, it enables security experts to break free from repetitive manual tasks. Such a transition allows them to focus on more complex and strategic work.

"We spend a lot of our time in the SOC doing manual tasks repetitively and trying to glue things together," Curry says. "When you manage not to think about the tools, your ability to perform a task improves drastically."

AI adaptations bring other changes that also help IT teams find better ways to perform their jobs. They move from simple detection and response to a more proactive approach to security. Curry believes that in this new environment, there will still be plenty of jobs; they'll just be more engaging and valuable.

Ethics & Logic are Crucial to Work With AIFor universities and educational institutions, the rise of AI in cybersecurity poses a significant challenge. The traditional emphasis on technical certifications like Certified Ethical Hacking and Security+ is no longer adequate. Future jobs will demand a deeper understanding of fundamental principles.

"They're going to have to walk over to the philosophy department," Curry explains. "They'll probably need to engage with the social sciences department. Understanding ethics and logic is crucial because they have to work with AI and assess whether the information it provides is logical."

The key is in coding, running scripts, but most importantly, it’s in learning to collaborate with AI as a partner. However, a boost in education is necessary to help cybersecurity professionals comprehend the principles of logic, ethics, and sociology. Such an approach to awareness will help IT teams find their way through the convoluted relationships between humans and AI.

As agentic AI becomes more common, we are shifting away from traditional security models. Authentication and authorisation are no longer sufficient. The new reality calls for a focus on authenticity.

Takeaways* The rise of agentic AI necessitates a new security model based on authenticity. * AI is not just a tool for attacks; it can enhance defensive strategies. * Organisations must consider privacy and data handling when implementing AI. * The role of cybersecurity professionals will evolve, focusing on more complex tasks. * Education in cybersecurity must adapt to include ethics and logic. * AI can help automate repetitive tasks, allowing for more interesting work. * Trust and accountability are crucial in the deployment of AI systems. * Consumption metrics can provide deeper insights into product value. * Understanding user engagement is more important than just satisfaction surveys. * The future of cybersecurity will involve continuous adaptation to new threats.

Chapters* 00:00 The Rise of Agentic AI in Cybersecurity * 09:05 The Future of Cybersecurity Jobs * 12:45 The Role of Education in Cybersecurity * 19:42 Establishing Trust in Agentic AI

View Details

It has been eight years since the NIST Special Publication 800-190: Application Container Security Guide was published, and its recommendations remain central to container security today. As cloud-native applications have become the foundation of modern enterprise IT, securing containers has shifted from an afterthought to a critical priority.

In this episode, Richard Stiennon, Chief Research Analyst at IT-Harvest and host of Security Strategist, discusses container security with John Morello, CTO and Co-Founder of Minimus, and Murugiah Souppaya, Former Computer Scientist at the National Institute of Standards and Technology (NIST). Together, they focus on NIST Special Publication 800-190, exploring its role in providing best practices for securing containers, the recommendations outlined in the guide, and the approach required for effective container security.

The conversation also examines current best practices and the future of container security, emphasizing the importance of compliance and the integration of security throughout the development lifecycle.

Why NIST SP 800-190 Still MattersNIST’s framework was designed for both government and industry, offering guidance on how to:

  • Integrate security early in the application lifecycle.
  • Apply a holistic approach from hardware to workload.
  • Build with minimalistic and secure container images.
  • Maintain compliance with regulations and standards.
  • Continuously monitor and update security practices.
  • Understand the full container lifecycle from creation to retirement.

As Murugiah Souppaya explains:

“We want to make sure that people think of container security holistically, and also think about the full lifecycle management of the container itself. Like anything else in the enterprise, you want to look at this end-to-end and fill those gaps.”

Insights on the Development of Container SecurityNIST SP 800-190 arrived at a time when containers were new to most organizations. Now, they have become the standard way to deploy applications at scale.

John Morello recalls:

“Around 2016 or so, containers were pretty new in the world. Containers and containerization in other forms had existed in the past, but it was really becoming a mainstream technology that was commonly used across many organizations.”

This fast-paced adoption forced organizations to rethink their security culture. Containers required not only new technical controls, but also a shift in mindset: security had to be built-in from the start.

Takeaways* Container security became critical with the rise of cloud-native applications. * NIST aims to provide guidance for both government and industry. * The 800-190 guide offers a framework for securing containers. * Security must be integrated early in the application lifecycle. * Containers require a shift in security culture and practices. * Holistic security involves securing hardware to workload. * Best practices include using minimalistic and secure images. * Compliance with regulations is essential for container security. * Continuous monitoring and updating of security practices are necessary. * Understanding the full lifecycle of containers is crucial for security.

Chapters00:00 Introduction to Container Security and NIST 800-190

02:58 The Importance of NIST in Container Security

05:52 Key Recommendations from the NIST Guide

08:44 Holistic Approach to Container Security

11:53 Current Best Practices in Container Security

14:47 Future of Container Security and Continuous Improvement

About MinimusMinimus solves the endless treadmill of cloud software vulnerabilities by simply preventing them from existing. Minimus provides secure, minimal container and VM images, rebuilt from scratch daily to eliminate over 95% of CVEs.
Founded by the team behind container security pioneer Twistlock, Minimus raised $51 million seed funding from YL Ventures and Mayfield. The company is headquartered in Baton Rouge with offices in New York, Tel Aviv, and Portland, OR. To learn more, visit minimus.io.

View Details

AI is rapidly changing how cybercriminals operate. Social engineering, once easy to spot, has entered a new era. Phishing emails that used to be riddled with spelling mistakes and clumsy language are now polished, persuasive, and tailored using data scraped from social media and other online sources. The result? Messages that look legitimate enough to trick even the most security-aware employees.

In this episode of Security Strategist, host Trisha Pillay sits down with Director of Threat Research at N-able, Kevin O’Connor to unpack how AI is reshaping phishing and what it means for businesses, especially small and medium-sized organizations that often lack the resources to keep up. Drawing on insights from the N-able Threat Report, O’Connor explains why traditional defenses and old-school user training aren’t enough to stop today’s AI-crafted scams.

O’Connor says:

“In the past, phishing emails were easy to spot, you’d see clumsy grammar mistakes, generic wording, they were just very obvious. But with the new wave of AI-enabled phishing emails, we’re seeing tailored attacks that pull from social media profiles and other sources. These messages are highly polished, they look convincing, and the worrying part is that attackers can now do this at scale. That means even IT professionals and security pros are at risk.”

Why Even Experts Are Falling for AI-Powered Phishing

Drawing on insights from the latest N-able Threat Report, this is why the shift is so dangerous:

  • AI is changing the landscape of social engineering. Messages are tailored, credible, and increasingly difficult to block or filter.
  • Phishing emails are now more convincing than ever. Attackers can create unique, targeted scams instead of blasting out obvious mass emails.
  • Even experts are vulnerable. IT teams and security professionals are no longer immune.
  • User training must evolve. Old advice like “look for spelling mistakes” won’t cut it anymore. Employees need new skills to recognize modern threats.

The conversation also looks ahead at what enterprises can do now to strengthen defenses, updating training, and preparing for a future where AI will play a role on both sides of the cybersecurity battle.

Takeaways* AI is changing the landscape of social engineering. * Phishing emails are now more convincing than ever. * Even tech-savvy employees can fall for scams. * SMBs are increasingly targeted due to their vulnerabilities. * User training must evolve to address modern threats. * Two-factor authentication is critical for financial transactions. * Organizations need to know their data exposure. * Incident response planning is essential for preparedness.

Automated responses can enhance security measures.

The threat of compromise is a matter of when, not if.

Chapters00:00 Introduction to AI-Driven Threats

02:09 The Evolution of Phishing with AI

05:42 The Rise of Attacks on SMBs

08:56 Preventative Measures for Organizations

12:36 The Future of AI in Cybersecurity

About Kevin O’ConnorKevin O’Connor is the Director of Threat Research at N-Able and brings over eight years of experience in U.S. Intelligence Community and Department of Defense cyber operations, gaining first-hand insight into how nation-state adversaries think and operate. He later applied that expertise in private industry threat research, translating intelligence into practical, enterprise-grade security solutions. O’Connor continues to focus on Threat Research, bringing those capabilities from a startup to a larger organization, increasing reach, insights, and cross-industry impact.

O’Connor’s strength lies in bridging technical depth with strategic insight. He can analyze advanced persistent threats and kernel-level exploits while advising business leaders on risk, investment, and operations. With expertise in offensive cyber operations, defensive engineering, and threat intelligence, he turns complex security challenges into actionable strategies that help enterprises stay resilient.

View Details

"What we're seeing as a response to coding agents is one of the biggest risks in security vulnerabilities to date,” said Jaime Jorge, Founder and CEO of Codacy. “It's almost like a game to see how fast we can exploit vulnerabilities in some of these applications that are created so quickly."

In this episode of The Security Strategist Podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks with Jaime Jorge, the Founder and CEO of Codacy, about secure software development in the age of AI.

The speakers talk about how quickly coding is evolving due to AI tools, the rise of autonomous coding agents, and the major security issues that come from this faster development.

Jorge emphasised the importance of maintaining security practices and highlighted Codacy's role in providing thorough security analysis to ensure that AI-generated code is safe and reliable. The discussion also looks at the future of AI in software development and what IT leaders need to do to manage these changes.

Software Development in an Era of AIThe world of software development is changing dramatically, the Codacy founder conveyed on the podcast. With AI tools like GitHub Copilot and Cursor becoming mainstream, developers are writing code faster than ever. Host Stiennon refers to this new era as "vibe coding," meaning the ability to create code at an incredible speed.

However, this speed can bring serious and risky consequences. Data has shown that AI-generated code often has vulnerabilities. Some studies have found that these vulnerabilities can reach as high as 30-50 per cent. A Front Big Data study reported that 40% of the code suggested by Copilot had vulnerabilities. “Yet research also shows that users trust AI-generated code more than their own.”

This trend is widening the gap between quick development and secure, enterprise-grade software.

How to Keep up With Autonomous Coding Agents?“Without a doubt, one of the most significant trends that we're seeing is coding agents,” the CEO of Codacy told Stiennon. “Autonomous coding agents are becoming extremely skilled at taking a prompt and creating full-fledged products, getting even to the intentions that users have.”

However, the challenges of autonomous agents cannot be denied. Jorge believes this is more than just a technical issue. It reflects a basic misunderstanding of how to use these powerful new technologies.

He pointed out that it's dangerous to assume we can completely hand over decisions about the code generated by AI. Important software development practices, such as building security into the design and having human code reviews, shouldn't be overlooked.

The convenience of using AI to quickly generate code for a project means we have a greater responsibility to review the code ourselves, to evaluate it, or to ensure that other people approve it.

Jorge’s key message to CISOs, CTOs and IT decision-makers is that AI is here to stay and that their teams are already likely using it. This wave is hard to ,ride but “you have a choice in how to ride it.”

"AI-generated code can secure our tools, and our agents are empowered with security capabilities. You can move fast if you have the right guardrails."

The best practices Codacy developed over decades, such as CI/CD, code review, and security by design, are the tools that can help them use AI effectively.

Takeaways* AI tools are accelerating software development significantly. * Autonomous coding agents are becoming increasingly capable. * The speed of development introduces new security vulnerabilities. * 30-50% of AI-generated code contains vulnerabilities. * Security practices like code reviews are more important than ever. * Companies are still defining policies for AI use in coding. * Codacy provides end-to-end security analysis for code. * AI can enhance security if integrated properly into workflows. * IT leaders must adapt to the rapid changes in coding practices. * The future of coding will involve more collaboration between AI and human developers.

Chapters* 00:00 Introduction to AI in Software Development * 02:54 The Rise of Autonomous Coding Agents * 05:47 Security Challenges in Rapid Development * 09:12 Codacy's Approach to Security * 12:08 Future of AI in Software Development * 15:09 Key Takeaways for IT Leaders

About CodacyCodacy is a developer-first, API-driven platform that provides a curated collection of best-in-class code analysis, AppSec scanning, and AI governance tools.

Codacy integrates seamlessly into existing development workflows, empowering development teams to deliver secure, high-quality software faster.

Codacy is the only DevSecOps platform that delivers plug-and-play AppSec and Code Quality for AI-generated and human-written code. Future-proof your software – from source code to runtime – without extra servers or build steps. Deploy within minutes and stay ahead of emerging risks today.

View Details

"When you're encrypting the traffic and giving the keys only to the owner of the traffic, it provides a specific door for attackers to walk right in,” stated Eva Abergel, the Senior Solution Expert at Radware.

In this episode of The Security Strategist Podcast, Richard Stiennon, the Chief Research Analyst at IT-Harvest, an author and a trusted cybersecurity advisor, speaks with Abergel about how Hypertext Transfer Protocol Secure (HTTPS) encryption is creating new challenges for cybersecurity professionals.

They also talked about how DDoS attacks have changed to take advantage of new weaknesses that are hidden in plain sight within encrypted traffic. They discussed what organisations need to do to improve their defences.

HTTPS Encryption Creating Challenges for DefendersHypertext Transfer Protocol Secure (HTTPS) encryption is known to have made the internet safer, especially from DDoS attacks. However, it has also created new opportunities for attackers. Threat actors in the modern day are leveraging encrypted traffic to camouflage malicious activity. Unfortunately, traditional cybersecurity tools have been unsuccessful at spotting and blocking these hidden attacks. This is simply because they cannot decrypt the data of such modern-day cyber breaches.

Abergel says that unless an organisation can decrypt the traffic, it cannot see what's inside, allowing sophisticated DDoS attacks to go undetected. This presents a dilemma for IT decision-makers, as they are understandably reluctant to surrender the "keys to their castle" by allowing a third party to decrypt their protection walls.

Especially, with the rise of “tsunami attacks”, in other words, DDoS attacks, the network layer becomes more vulnerable. Attackers deliberately target the application layer of a protected network to overwhelm the application, not the entire network.

Essentially, hackers take advantage of a grey area in cybersecurity, explains Abergel. "WAFs are not equipped to deal with sophisticated web DDoS attacks. And network layer mechanisms and defences for DDoS attacks cannot recognise a DDoS attack on the application layer only by looking at the network layer."

This means attackers found a comfortable and effective spot to launch their campaigns, often without severe consequences.

Also Watch: From Prompt Injection to Agentic AI: The New Frontier of Cyber Threats

How to Protect Your Business Without Compromising Your KeysWhat is the solution when an organisation can't share their encryption keys? This is a major concern, especially for regulated industries that are legally prohibited from sharing this sensitive information to even the most trusted cybersecurity firms.

To learn more about the solution, and how Radware can help you defend against modern cybersecurity threats, watch the podcast on EM360tech.com. You can watch the video version on our YouTube channel, @EM360Tech, or listen to the audio version on EM360Tech’s Spotify series, The Security Strategist podcast.

Takeaways* DDoS attacks have evolved significantly since their inception. * HTTPS encryption, while beneficial, has created new vulnerabilities. * Modern DDoS attacks often mimic legitimate traffic, complicating detection. * AI is accelerating the sophistication of DDoS attacks. * Organisations must balance user experience with security measures. * The financial sector faces severe consequences from DDoS downtime. * Solutions exist that do not require sharing encryption keys. * CISOs should seek tailored solutions for their specific needs. * Understanding the threat landscape is crucial for effective defence. * Proactive measures are essential to stay ahead of evolving threats.

Chapters* 00:00 Introduction to DDoS Attacks and Their Evolution * 02:52 The Impact of HTTPS on DDoS Attacks * 06:08 Modern DDoS Attacks: Scale and Sophistication * 08:46 AI's Role in DDoS Attacks * 12:05 Challenges in Mitigating Application Layer DDoS Attacks * 14:58 Finding Solutions Without Decryption Keys * 17:02 Key Takeaways for IT Decision Makers

View Details

“For a long time, we focused on defending the perimeter and thought that was enough to keep businesses safe,” stated Ram Varadarajan, CEO and Co-founder of Acalvio. “It’s like putting locks on doors. The problem is that more people are finding ways to cross those boundaries and enter your business at an alarming rate.”

In the recent episode of The Security Strategist podcast, Chris Steffen, the Vice President of Security Research at Enterprise Management Associates (EMA), sits down with Varadarajan to talk about how deception is changing threat detection in compromised enterprise environments.

The CEO of Acalvio, alluding to the main issue in modern cybersecurity, explains that the old security model, which aims to create an impenetrable perimeter, is no longer enough. Attackers, equipped with more advanced tools, are discovering new methods to bypass these defences. The old "fortress mentality" is outdated.

Assume Compromise!Both Varadarajan and Steffen agree that modern-day cybersecurity is not a matter of if an attacker will get in, but it's about anticipating when the attacker will get in. This mindset, referred to as "assumed compromise," means that a determined attacker will eventually find a way inside your network, especially with AI in the picture.

Varadarajan explains, "The defender has to be right all the time in stopping the attacker at the door, whereas the attacker needs to be only right once to get past the perimeter and get inside the house."

This imbalance gives attackers a significant edge. The vast number of entry points—from on-premise systems to cloud services and remote access—makes it impossible to secure each one perfectly. Consequently, the focus should be on what happens after an attacker is inside.

So, how are businesses approaching such constantly looming threats?

Deception: A Preemptive StrikeThis is where deception technology becomes an effective, proactive defense strategy. Instead of waiting for a breach to happen and then trying to fix the damage, deception actively engages and misleads the attacker.

"If you're assuming that the attacker is going to be inside, the question is how do you find these attackers and bad actors quickly and precisely so that you can conduct the enterprise's business?,” elucidates Varadarajan.

Deception technology creates a web of fake assets, data, and credentials, forming a digital minefield for attackers. When an attacker tries to move laterally through the network or gain higher privileges, they interact with these decoys. This interaction provides an immediate, clear signal that a malicious actor is present, allowing defenders to stop them before they can reach their real target.

The old methods of securing a network are no longer enough, agree both Varadarajan and Steffen. The rise of sophisticated, AI-driven attacks requires a new, proactive approach.

"Preemptive defense based on deception is a very legitimate and well-understood way of solving this problem,” stated Varadarajan.

Enterprises are advised to switch strategy from defending the perimeter to actively deceiving and identifying within the network. This would help organisations to regain control. Deception technology offers a vital home-field advantage, making it an important part of any modern cybersecurity strategy.

Takeaways* Deception technology is a natural and effective strategy in cybersecurity. * Traditional perimeter defenses are no longer sufficient against modern threats. * The 'assumed breach' mindset is essential for contemporary cybersecurity strategies. * Operationalizing deception technology can significantly enhance threat detection. * AI can streamline the creation and management of deception environments. * Preemptive defense is more effective than reactive strategies in cybersecurity. * Organizations must adapt to the increasing number of entry points into their networks. * Reducing dwell time for attackers is crucial for effective defense. * Cybersecurity strategies should account for both external and internal threats. * Deception technology can help identify both active attackers and dormant malware.

Chapters* 00:00 Introduction to Cybersecurity Challenges * 03:05 Understanding Deception Technology * 06:14 Shortcomings of Conventional Cybersecurity * 09:11 The Shift from Fortress Mentality * 12:03 Assumed Breach: The New Normal * 15:00 Operationalizing Deception Technology * 18:01 The Role of AI in Cybersecurity * 21:03 Velocity of Cyber Attacks * 23:46 Preemptive Defense Strategies * 26:59 Key Takeaways and Conclusion

View Details

Passwords remain one of the weakest links in enterprise security. Despite advances in multi-factor authentication (MFA), recent data breaches show that attackers continue to bypass traditional protections. In this episode of The Security Strategist, host Trisha Pillay speaks with Nic Sarginson, senior solutions engineer at Yubico.

Together, they explore the vulnerabilities of passwords and conventional MFA, and why phishing-resistant authentication is no longer optional; it’s a strategic imperative for chief information security officers (CISOs).

"Passwords alone just don’t cut it," says Sarginson. Hackers can launch sophisticated attacks in minutes, and traditional MFA often isn’t enough to stop them. Organisations should turn to device-bound passkeys and physical security keys not just as tools, but as a way to rethink enterprise security, stay ahead of compliance pressures, and embrace a passwordless future.

"Attackers can now launch sophisticated campaigns quickly and cheaply using publicly available data. That’s why breaches today are far more dangerous, and why weak MFA or social engineering is often involved." — Nic Sarginson, Yubico,

Why This Matters for CISOsCybersecurity leaders face growing pressure to defend against phishing attacks, navigate evolving compliance demands, and deliver secure experiences for users. Sarginson shares practical strategies, expert insights, and real-world examples to help CISOs and IT leaders build a stronger, passwordless future.

Takeaways* Passwords are fundamentally broken and pose a major vulnerability. * Recent breaches highlight the inadequacy of traditional MFA. * Device-bound passkeys offer stronger protection against phishing. * Integration of new security methods is a significant challenge for enterprises. * Real-world case studies show measurable improvements with security keys. * Regulatory frameworks are increasingly mandating strong MFA. * Phishing resistance must become the default in security strategies. * The technology for passwordless solutions is now prevalent. * Security leaders must advocate for proactive security measures. * User education is crucial for the adoption of new security technologies. *

Chapters00:00 Introduction to Authentication Challenges

02:15 The Impact of Recent Data Breaches

05:30 The Entrenchment of Passwords and MFA

08:22 Exploring Device Bound Passkeys

11:20 Integrating Physical Security Keys

14:34 Real-World Case Studies and Metrics

17:24 Regulatory Pressures and Future Trends

20:27 The Path to Passwordless Security

About Nic SarginsonNic Sarginson is a senior solutions engineer for UKI and RSA at Yubico. An industry veteran, he has held a range of roles in cybersecurity and enterprise solutions, helping organisations adopt strong authentication methods and enhance their phishing resistance strategies.

View Details

"With every technological wave, technology weaponises very quickly. You can create targeted attacks at an unprecedented scale, a human-centric attack at a scale that's never been before humanly possible,” states Sage Wohns, CEO and Founder of Jericho Security.

In this episode of The Security Strategist podcast, host Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks with Wohns about modern-day cybersecurity threats driven by AI. They discuss the need for a strong security culture, innovative training methods, and the importance of adapting to new attack vectors.

The founder of Jericho Security, an AI-powered human risk management platform, talks about the shift from traditional rule-based defences to probabilistic approaches. Additionally, Wohns spotlighted the necessity of using AI to counter AI in the fight against cyber threats.

Generative AI: A Cause for Concern in Cyber SecurityThe speakers agree that every organisation today has one common and new challenge. It’s the rise of generative AI. This is because gen AI is a tool quickly and widely being used in cyber tech. “We have moved past simple, templated attacks to a new era,” iterated Wohns. Threats have now become more dynamic, personalised, targeted and scalable in ways the world has never witnessed before.

For years, cybersecurity training has depended on static, rule-based defences. Consider those generic phishing emails from a "Nigerian Prince" or a fake Google logo. However, as Wohns points out, attackers no longer follow a script. They are using AI to create complex, multi-channel attacks that can take advantage of publicly available information and stolen data to target individuals.

This new reality shows that old "checkbox training" is outdated. An attack on a salesperson will differ significantly from an attack on an accountant, and both will be tailored to exploit specific weaknesses. These attacks go beyond emails; they include deepfake voice calls, fake videos, and coordinated messages that blur the line between what is real and what poses a threat.

Takeaways* AI is rapidly changing the landscape of cyber threats. * A strong security culture is essential for organisations. * Traditional training methods are outdated and ineffective. * Probabilistic defences are needed to counter dynamic attacks. * Creating a positive security culture encourages reporting mistakes. * Multi-channel attacks are becoming more sophisticated. * Generative AI can be used to simulate realistic attacks. * Tailored training can enhance employee engagement and effectiveness. * Using real-world data makes training relevant and impactful. * AI solutions must evolve to keep pace with attackers.

Chapters* 00:00 Introduction to Cybersecurity and AI Threats * 03:01 The Evolution of Cyber Threats * 05:50 Innovative Approaches to Security Training * 08:55 Probabilistic Defences vs. Rule-Based Systems * 11:49 Creating a Positive Security Culture * 15:02 Multi-Channel Attacks and Emerging Threats * 18:13 Key Takeaways for IT Decision Makers

About Jericho Security Jericho Security is transforming cybersecurity training with an AI-powered platform that defends against modern phishing threats. Its proprietary agentic AI delivers multi-channel simulations mimicking real-world attacks across email, voice, messaging, and video. Designed for highly scalable deployments, customizable training and performance tracking. Trusted by the U.S. Department of Defense and honoured with four Global InfoSec Awards at RSA Conference 2025, Jericho is at the forefront of human-centred, AI-driven cyber defence.

View Details

When cybercriminals breach an organization, they're not just after one piece of data - they're hunting for the keys that unlock everything.

"Think of Hardware Security Modules (HSMs) like a master vault in a bank for an entire organization's digital security," said David Close, Chief Solutions Architect at Futurex. More than just an analogy, this is the reality of how modern enterprises are secured.

Cybersecurity is full of complexities despite various advancements. Some aspects of it run constantly behind the scenes and occasionally go unnoticed until a breach strikes. Among these essential elements, Hardware Security Modules (HSMs) play a key role in maintaining digital trust.

In a recent episode of The Security Strategist podcast, Richard Stiennon explores with Close why HSMs have become the invisible guardians protecting our digital lives.

What is a Hardware Security Module (HSM)?At its core, a Hardware Security Module (HSM) is specialized, tamper-proof hardware that protects cryptographic keys and performs cryptographic operations. Close alludes to an analogy to describe an HSM, stating it's "the vault where you store all the keys to everything. The vault keys, the safety deposit keys, even the digital keys to the security system itself."

Born in the early 1980s for the payment industry, HSMs have evolved into the root of trust for almost every sector. They verify authenticity and safeguard encryption for tasks like processing payments, signing code, issuing identities, and encrypting sensitive data.

"If someone gets into the master vault, they don't just have access to one thing. They have access to everything," says Close, illustrating the importance of HSMs for stronger security. This is why regulatory bodies like PCI mandate HSM usage for organizations handling sensitive payment data.

To make HSMs more accessible and user-friendly, Futurex's main solution is CryptoHub Cloud. It works as an HSM as a Service (HSMaaS).

Close describes HSMaaS as not just a cloud version of HSM but a "centralized cryptographic service provider." Unlike some solutions that operate in shared cloud infrastructure, Futurex's CryptoHub Cloud runs in purpose-built cryptographic environments that are fully isolated.

Such a unique approach gives customers full control, predictable performance, and independence from the cloud provider's native crypto stack. This is also an important factor for organizations in regulated industries.

HSMs Enforce Policy"HSMs don't just solve crypto problems,” says Close, “they create predictability and enforce policy, also allow you to have a true security model that is effective at scale."

In a world that depends more on digital systems, it is essential to understand and use the power of HSMs. They act as invisible protectors, making sure our most sensitive digital assets remain secure and trustworthy.

Takeaways* HSMs are essential for protecting cryptographic keys and sensitive data. * The evolution of HSMs has made them easier to use and integrate into cloud environments. * Crypto agility allows organizations to adapt to new cryptographic algorithms without replacing existing infrastructure. * HSMs enforce strict access controls and audit logs for all cryptographic operations. * Regulatory bodies mandate the use of HSMs for managing sensitive payment data. * HSMs provide a physical layer of security that software alone cannot offer. * Organizations can achieve significant performance improvements by offloading cryptographic operations to HSMs. * Futurex's CryptoHub Cloud offers a centralized cryptographic service for organizations. * HSMs help organizations meet compliance requirements while leveraging cloud benefits. * Real-world use cases demonstrate the operational efficiencies gained through HSM deployment.

Chapters* 00:00 Introduction to Cybersecurity and Cryptography * 02:19 Understanding Hardware Security Modules (HSMs) * 08:00 FuturexX CryptoHub Cloud and Its Applications * 11:04 The Importance of HSMs in Payment Security * 13:02 True or False: HSM Myths and Facts * 20:56 Real-World Use Cases of HSMs

About FuturexFor over 40 years, Futurex has been an award-winning leader and innovator in the encryption market, delivering uncompromising enterprise-grade data security solutions. Over 15,000 organizations worldwide trust Futurex to provide groundbreaking hardware security modules, key management servers, and cloud HSM solutions.

Futurex is headquartered outside of San Antonio, Texas, with regional offices worldwide and over a dozen data centers across five continents, and delivers unmatched support for its clients’ mission-critical data encryption and key management requirements.

View Details

"In this technology-centric world, where we see new advantages, new paths, new adventures, at the end of the day, the other side of the screen is always a human being,” Bartosz Skwarczek, Founder & President at G2A Capital Group, reflectively said.

The quote sets the tone of the recent episode of The Security Strategist podcast. In this episode, Shubhangi Dua, Podcast Host and Producer, sits down with Skwarczek, an award-winning CEO recognised by Forbes. They talk about the evolution of online marketplaces, the importance of security, and the role of people in business.

They discuss the challenges of operating a global marketplace, the significance of diversity in teams, and the future of payment security technologies.

Bartosz emphasises the importance of a proactive approach to cybersecurity and the use of AI in business operations. He also highlights the essential role of human values and communication in creating a successful organisation.

Proactive and Multi-Layered Approach to CybersecuritySecurity is a top priority for G2A, Skwarczek articulated. He adds that it's a "constant improvement" and a "kind of battle that you have with the bad actors." To stay "one step ahead of attackers," G2A deploys a multi-layered defence strategy.

The multi-layered strategy starts with careful monitoring of threat intelligence channels to ensure organisations stay on top of the latest threats, vulnerabilities, and methods used by malicious actors.

A dedicated incident response team has clearly defined roles and responsibilities. They can respond immediately to any security incidents, especially those related to different types of fraud, such as friendly fraud (chargeback fraud) or traditional credit card fraud.

Skwarczek says that employee training is extremely important. G2A conducts mandatory training every month for its employees, assuring they know how to avoid common mistakes like phishing emails. Especially considering that over 3 million phishing emails are sent every day.

Skwarczek also emphasises the importance of these ongoing audits. Alluding to the constantly changing market, He says cyber criminals constantly devise new tricks. This is why frequent evaluations are needed to ensure G2A is moving in the right direction.

AI, Blockchain, and the Future of Payment SecurityLooking ahead, Skwarczek talked about the future of payment security. He recognised the complicated relationship between new technologies and strict regulations.

The payment industry is inherently "conservative because it's regulated," he added, with extensive regulatory frameworks that ensure the safety of people's money. This intentional pace, however, coexists with rapid technological advancements. Skwarczek specifically pointed to the growing influence of AI and blockchain.

While AI offers immense promise in enhancing security and streamlining operations, it's also a "double-edged sword," with "bad actors" leveraging AI to become "smarter with cheating." G2A's approach to AI is to be "AI native," focusing on educating every department on the basics of AI and guiding them to use specific AI tools relevant to their functions, from marketing to security. Regular evaluations ensure that these AI implementations are effective and continually improved.

Takeaways* The core message is always about people. * Security is a top priority in online marketplaces. * Diversity presents both challenges and opportunities. * Building a strong team is essential for global operations. * AI can be both beneficial and a threat in cybersecurity. * Education and training are crucial for preventing phishing attacks. * Proactive cybersecurity measures are necessary to stay ahead of threats. * Communication within teams is vital for success. * Diversity enhances problem-solving and innovation. * The future of payment security is uncertain but full of potential.

Chapters00:00 Introduction to G2A and Bartosz Skwarczek

02:10 The Importance of People in Business

03:23 Understanding Cloud Marketplaces

05:08 Security Frameworks in Online Marketplaces

06:38 Challenges of Global Payment Diversity

11:15 Building a Strong Team for Global Operations

15:54 The Role of AI in Cybersecurity

20:03 Securing Transactions and Avoiding Fraud

24:40 Proactive Cybersecurity Measures

27:34 The Importance of Communication in Teams

29:52 Diversity as a Strength in Business

32:03 Future of Payment Security Technologies

36:37 Key Takeaways for Decision Makers

About G2AG2A.COM is the largest and most trusted marketplace for digital entertainment in the world. More than 30 million people in 180 countries have made over 100 million purchases on the platform.

Customers can explore a vast catalogue of over 75,000 digital products, including games, DLCs, in-game items, and non-gaming items like gift cards, subscriptions, software, and e-learning resources. These products are offered by sellers from around the globe.

G2A.COM is also known for its strong focus on online security. It has received the American CNP award, joining well-known companies like Microsoft, Barclay's Bank, and First Data.

View Details

Artificial intelligence (AI) is on everyone’s mind, and its impact doesn't escape the cybersecurity industry. The industry experts acknowledge not just the benefits but also the cybersecurity threats of AI integrations.

As Pascal Geenens, Director of Threat Intelligence at Radware, puts it, "It's AI, so everything is changing weekly. What I talked about two weeks ago has already changed again."

The constant change means that malicious actors are not just adopting AI, they're leveraging it to create new threats at a striking pace.

In this episode of The Security Strategist Podcast, Richard Stiennon, an industry Analyst, Author and Chief Research Analyst at IT-Harvest, speaks with Geenens.

They discuss how cybersecurity threats are enhanced by AI. This includes how attackers are using AI tools, the implications of new technologies like agentic AI, and the challenges posed by AI advancements.

The conversation also touches on the role of nation-states in utilising AI for cyber operations, the concept of vibe hacking, and the future of interconnected AI agents.

AI-Driven Attacks Fuelled by Prompt InjectionMalicious hackers evidently first used AI in 2023, specifically through prompt injection attacks on large language models (LLMs) such as ChatGPT.

Attackers would find "evasion techniques" to bypass ethical guardrails, asking questions indirectly to generate malicious scripts or gather information for attacks.

Geenens says, "If you would ask the direct question, how can I commit a murder and get away with it? He would say, no, no, no, that goes against my ethical principles. But there are ways around it."

The game changed with the emergence of offline models and specialised services like WormGPT and FraudGPT. These models, distilled from larger ones and enhanced with hacking-specific information from underground forums, lowered the barrier to entry for aspiring cyber criminals.

"They created their own model and sold it as a service underground. And that model was geared towards helping anyone with questions to interact with a prompt and to make their malware better, increase the effectiveness of their malware," explained Geenens.

This accessibility meant that "more actors would actually move from script kiddie level to a more sophisticated level." Teenagers, in particular, took advantage of these AI assistants. They provided a friendly, non-toxic environment to learn and develop hacking tools, unlike the often unwelcoming underground forums.

The Rise of Agentic AI & Automated ExploitsIn 2024, the focus shifted to AI agents, which provide attackers with automated workflows. Unlike LLMs, agents can interact with their environment, gather updated information, execute tools, and even spawn new agents that communicate with each other.

"You can have a manager agent that says, okay, I need to develop something. It’s a big problem here. I need to develop a tool. I have an agent that does the development. I have an agent that does the QA testing,” depicts Geenens. “And then I have another agent who's a problem solver who will help the other tools do their job. And they interact with each other.”

This agentic capability majorly hastens the exploitation of vulnerabilities. Research showed that AI agents can quickly rebuild proof-of-concept exploits for published CVEs.

Geenens stressed the dramatic reduction in time: "Earlier, when the CVE was published, it took 24 hours-48 hours and a security researcher who typically posted a proof of concept online in Python before the actual attacks in the wild would start.”

“But now with those agents and those workflows has been proven as much easier to get access and to get a proof of concept. That window might now reduce from 48 hours to a couple of minutes,” he added.

Takeaways* AI is changing the landscape of cybersecurity threats. * Attackers are using AI to enhance their hacking capabilities. * Guardrails in AI are not foolproof against malicious intent. * Teenagers are increasingly entering the cybercrime space due to AI tools. * Agentic AI allows for automated workflows in attacks. * The sophistication of attacks has not drastically changed, but entry barriers have lowered. * Nation-states are using AI for disinformation and phishing. * Vibe hacking represents a new frontier in automated vulnerability discovery. * MCP and agent-to-agent protocols will shape the future of AI interactions. * AI will be necessary to combat AI-driven threats.

Chapters00:00 AI in Cybersecurity: The New Frontier

06:51 The Evolution of Hacking: From Script Kiddies to AI-Enhanced Threats

12:48 Nation States and AI: The New Age of Cyber Warfare

15:12 Vibe Hacking: The Future of Coding and Security

19:14 The Internet of Agents: A New Era in Cybersecurity

25:11 Emerging Threats: Indirect Prompt Injection Attacks

View Details

"The thing to challenge is the fact that fraud prevention is a vertical by itself," says Guido Ronchetti, CTO at XTN Cognitive Security. He stresses that recent fraudulent trends exhibit "no real separation between fraud, cybersecurity, and AML.”

In this episode of The Security Strategist podcast, Jonathan Care discusses fraud prevention with Ronchetti and Paolo Carmassi, Head of Sales at XTN. They explore the connection between fraud, cybersecurity, and artificial intelligence (AI), emphasising the need for a holistic approach to tackle modern fraud challenges.

The conversation further spotlights how to take advantage of local identity and data privacy as competitive advantages, particularly in Europe. The speakers discuss emerging threats such as shell game malware.

The relation between fraud, cybersecurity, and AI is apparent in scenarios like authorised push payment fraud. It often involves an initial data breach, followed by social engineering, and culminating in financial fraud.

Future of Fraud Prevention To effectively fight such threats, a detailed picture of the entire "kill chain" is critical. It should include expertise from cybersecurity and anti-money laundering (AML).

Expanding on “kill chain,” Carmassi says that "fraud is no longer a case of just the banking industry or the financial services at large. It's something that is starting to spill out into other industries as well."

The head of sales points to examples in gambling, with issues like account takeover and bonus abuse, and even the automotive sector, where app vulnerabilities could lead to physical security threats.

The emergence of sophisticated bots further complicates this space. That makes it a unified defence strategy pressing across all sectors.

Alluding to an example, Ronchetti explained, "Last year we were dealing with one of the top 10 European banks. The reason for that was GDPR." The bank had to replace a well-established American vendor after over a year of a Proof of Concept (POC). This was because the vendor's data-sharing practices, particularly with clients outside the European Union, clashed with GDPR requirements.

This incident stresses the importance of a provider's ability to tackle the complex European regulations. The upcoming AI Act further accentuates this divide, with European and US approaches to AI regulation diverging significantly.

The episode concludes with insights on the future of fraud prevention, focusing on trust and the integration of behavioural biometrics.

Takeaways* Fraud prevention must integrate with cybersecurity and AI. * The traditional view of fraud as a silo is outdated. * Emerging technologies blur the lines between industries. * GDPR sets a global standard for data privacy. * Cultural and geographical factors influence fraud solutions. * New threats like shell game malware are evolving. * Younger demographics are becoming targets for fraud. * Trust is essential for competitive advantage in fraud prevention. * Behavioural biometrics can enhance identity validation. * A holistic view of fraud prevention is necessary.

Chapters00:00 Introduction to Cognitive Security

04:01 Rethinking Fraud Prevention

08:12 Leveraging Local Identity and Data Privacy

11:53 European-Centric Fraud Solutions

16:07 Behavioural Biometrics in Fraud Prevention

20:11 Emerging Threats in Fraud

23:59 Future Paradigms in Fraud Prevention

About XTN Cognitive Security XTN is a European vendor of online fraud prevention solutions, empowering organisations to trust their digital users. Our AI-powered platform delivers top-level protection against fraud and cyber threats across multiple sectors and channels. Since 2024, XTN has been part of the CY4GATE Group, strengthening its international leadership in the cybersecurity sector.

View Details

"What we're seeing now is a lot of the vendors that were traditionally one of the identity pillars are kind of expanding into other pillars,” says Kevin Converse, Vice President, Identity and Access Management, GuidePoint Security.

In this episode of The Security Strategist podcast, Richard Stiennon speaks with Converse, VP at GuidePoint Security. They discuss identity management, focusing on identity convergence, the impact of agentic AI, and the complexities of non-human identities.

The conversation also taps into ethical dilemmas surrounding AI decision-making and future predictions for digital identity in a rapidly changing technological environment.

AI’s Impact on Identity and Access Management (IAM) Identity and Access Management (IAM) takes centre stage in this episode. The speakers spotlight two major relevant trends – identity convergence and the influence of agentic AI on digital identity.

Converse explains that traditionally, IAM was built on "three pillars—the IGA stack, the privilege access management, and the access manager." However, a change in fashion is taking place where "a lot of the vendors that were traditionally one of those pillars are kind of expanding into other pillars."

This change is a result of cybersecurity challenges that require businesses to adopt comprehensive solutions and tap into new markets. Converse further notes, "Some of it for the capabilities so they can expand on what they're doing, but it's also to hit some customers and verticals that we didn't usually do in identity."

This means moving from a multi-tool approach to a more unified platform, aiming to provide a "one-stop shop" for identity needs.

"There's a lot of focus on unified platforms for identity, particularly," Converse says, "that's a big investment piece right now." He also points out, "vulnerability management tools right now are getting in there too. You name it, they're coming into identity. Identity is the hot space at the moment."

This offers cost-saving potential, but Converse urges caution. "The question is, from an overall risk perspective, is that enough for your company?" He stresses the importance of evaluating whether integrated solutions deliver the same "functionality and the same security posture" as specialised tools.

The VP also reminds us that "the tools are all pretty capable, but it's just a matter of understanding exactly what you're trying to accomplish and what you're willing to accept as a risk."

Takeaways* Identity convergence is reshaping the identity management landscape. * Agentic AI requires a mature identity framework for effective implementation. * Non-human identities present unique challenges in cybersecurity. * Ethical considerations are crucial when allowing AI to make decisions. * Organisations must balance speed and security in adopting new technologies. * Real-time visibility and control are essential for managing non-human identities. * AI can automate low-level tasks but requires careful oversight. * The convergence of identity pillars can lead to cost savings but may compromise functionality. * Future technologies like quantum computing could disrupt current encryption methods. * Continuous adaptation is necessary to keep pace with evolving cyber threats.

Chapters00:00 Introduction to Identity and Access Management

02:57 Understanding Identity Convergence

06:02 The Role of Agentic AI in Identity Management

08:59 Navigating Non-Human Identities

11:47 Ethical Dilemmas in AI Decision-Making

14:46 Future Predictions for Digital Identity

About GuidePointGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organisations make better decisions that minimise risk. Their experts act as your trusted advisors, helping you understand your business and challenges. They evaluate your cybersecurity posture and ecosystem to identify risks, optimise resources, and implement best-fit solutions.

GuidePoint’s unmatched expertise has enabled Fortune 500 companies and U.S. government cabinet-level agencies to improve their security posture and reduce risk. Learn more at www.guidepointsecurity.com.

View Details

In this episode of The Security Strategist podcast, host Richard Stiennon, industry analyst and author, speaks to Craig Roberts, Principal Software Engineer at Rapid7, about digital exposure and the increasing challenges of Attack Surface Management (ASM).

The conversation peels back the layers of hidden vulnerabilities and misconfigurations that plague today’s digital world. The speakers offer expert advice into how businesses can better understand, prioritise, and manage their expanding attack surfaces.

"It's all about the kind of different steps an attacker takes. The attack surface simply means when an attacker can exploit to get to my goal and align to my mission," says Craig Roberts, Principal Software Engineer at Rapid7.

Attack Surface Goes Beyond External ScansAlso the Co-founder of Noetic (acquired by Rapid7), Roberts’ journey into attack surface management began from a practical observation. He found that many cybersecurity incidents came from overlooked assets. Such incidents could be unmonitored servers or lack of Endpoint Detection and Response (EDR).

"We set out to raise that hygiene bar through preventative controls," he explains. The typical view of an attack surface is often limited to external website scans. "That's only a small piece of it these days. It's often where an attacker will start. It’s an initial foothold. Everything past that point is also still an attack surface."

Emphasising the diverse nature of attack vectors, Roberts adds, "We don't have a homogenous way. Attackers both initially gain access and then start moving towards their target." This means that a single misstep or vulnerability across any of these areas can allow an attacker to achieve their objective.

Holistic Exposure Management Looking ahead, Roberts recommends CISOs to focus on having all enterprise data and understanding their environment across all assets. These assets are – cloud, users, and traditional infrastructure.

Then, layer on an understanding of "exposures" rather than just Common Vulnerabilities and Exposures (CVEs). This includes cloud misconfigurations, identity-related issues like MFA misconfigurations, and, zero-days.

"Treat those in a similar way because at the end of the day, we need to prioritise those exposures because the attacker isn't going to care about the weapon they use," Roberts concludes. This holistic approach, built on foundational trust in shared data across various security vendors and tools.

Such a strategy is crucial for gaining a central view of risk and efficiently mitigating the diverse threats facing modern enterprises.

A key takeaway from the discussion is the importance of understanding an organisations’ assets and how critical each is. Roberts argues that, while organisations may spend significant effort on re-scoring and building "vulnerability intelligence pipelines," it’s not often known which critical assets those vulnerabilities reside on.

"The asset is a really important thing. How important that is to your business, and what data and mitigations it has in it hugely affects the risk of that vulnerability," he stresses.

Takeaways* Understanding the attack surface is crucial for effective cybersecurity. * Attackers exploit various vulnerabilities to achieve their goals. * Prioritization of vulnerabilities is essential due to the overwhelming number of CVEs. * Zero-day vulnerabilities pose significant risks that require immediate attention. * IoT devices present unique challenges in vulnerability management. * Effective management of attack surfaces can deter opportunistic attackers. * Visibility into assets and their configurations is key to risk management. * Collaboration between security vendors enhances data sharing and threat response. * Organisations must treat all exposures equally, regardless of their nature. * A proactive approach to security can reduce the likelihood of successful attacks.

Chapters00:00 Introduction to Attack Surface Management

03:02 Understanding the Evolving Attack Surface

05:55 Types of Attackers and Their Motivations

08:52 Prioritizing Vulnerabilities and Exposures

12:09 Zero-Day Vulnerabilities and IoT Challenges

15:04 Management Strategies for Attack Surfaces

17:56 The Importance of Asset Visibility

20:57 Key Takeaways for CISOs

About Rapid7Rapid7, Inc. (NASDAQ: RPD) is on a mission to create a safer digital world by making cybersecurity simpler and more accessible. We empower security professionals to manage a modern attack surface through our best-in-class technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help more than 11,000 global customers unite cloud risk management and threat detection to reduce attack surfaces and eliminate threats with speed and precision. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.

View Details

Infosecurity Europe, Europe's leading cybersecurity event, is celebrating its 30th anniversary from June 3rd to 5th at ExCeL London. This year's conference is setting the stage for major moments in the enterprise tech space. The event aims to foster collaboration and promises to showcase the top cutting-edge cybersecurity solutions.

In this episode of the Security Strategist podcast, host Shubhangi Dua speaks with Saima Poorghobad, Portfolio director RX Global, the organiser of Infosecurity Europe about the upcoming Infosecurity Europe conference.

They discuss the significance of the event, which celebrates its 30th anniversary, and explore key topics such as quantum computing, AI, and ransomware that will be highlighted this year. Saima shares insights into new features and innovations at the conference, emphasizing the importance of networking and preparation for attendees.

"What we're really passionate about at Infosecurity Europe is building a safer cyber world for everyone," says Poorghobad. "We support this mission by giving the community somewhere that they can combine innovation with insights, with relationships."

Over the past three decades, Infosecurity Europe has served as a crucial cornerstone for the cybersecurity community, evolving alongside the rapidly changing threat scenarios, from the early internet to the rise of cloud and AI.

Setting Agenda With Quantum Computing One emerging theme at Infosecurity Europe 2025 is expected to be quantum computing. Once a distant prospect but now quantum computing is a near-term horizon. The conference will kick off with a headline keynote from Professor Brian Cox, exploring how black holes and quantum mechanics hold the answer to the future of computing and cybersecurity.

This will be followed by a panel discussion moderated by BBC cyber correspondent Joe Tidy, focusing on immediate actions organisations should take.

Poorghobad emphasising the practical applications of this says, "teaming up that session with Professor Brian Cox followed by that panel kind of gives you that overarching theory and view of the overarching threat to see how we can actually implement and what should we be doing today and make it really practical?"

Geopolitics is another major driver of cyber. For this, Rory Stewart, former diplomat, politician, and host of "The Rest Is Politics," will speak at the event on global power dynamics. He plans to particularly discuss how shifting alliances, emerging threats, and potential global trade wars could impact access to essential hardware and software for cybersecurity.

AI and Generative AI continue to be a key theme. Despite their initial hype, they remain at the forefront of cyber concerns. Cited as the most pressing threat in Infosecurity Europe's annual Trends Report, AI lowers the barrier to entry for bad actors and enhances capabilities for skilled attackers. A keynote session titled "Calling BS on AI" will bring together AI experts to provide insights on defending against AI threats, particularly deepfakes and AI-powered social engineering campaigns.

For more details on the event and some surprises planned, watch the full podcast.

Takeaways* Infosecurity Europe is a leading gathering of cybersecurity professionals. * The conference has evolved significantly over the past 30 years. * Quantum computing poses a near-term threat to existing encryption protocols. * AI is a pressing concern for cybersecurity professionals. * Ransomware continues to be a major threat in the cyber landscape. * New exhibitors and innovative formats are introduced each year. * Networking opportunities are crucial for building relationships in the industry. * Preparation is essential for maximizing the conference experience. * Attendees can expect hands-on master classes and exclusive sessions. * The 30th anniversary celebration will include special events and recognitions.

Chapters00:00 Introduction to Infosecurity Europe

02:45 The Evolution of Cybersecurity Over 30 Years

06:04 Key Topics for Infosecurity Europe 2025

09:12 Emerging Threats: Quantum Computing and Geopolitics

11:56 AI and Ransomware: Current Challenges

15:11 New Features and Innovations at Infosecurity Europe

22:03 Leveraging Opportunities at the Conference

View Details

“The types of attacks that we're seeing today are malicious in nature. They go to the very heart of the functioning of businesses,” stated Brett Ley, VP, Global Technical Sales at A10 Networks.

This observation from Ley sets the stage for a crucial discussion on The Security Strategist podcast. Shubhangi Dua, podcast producer and Tech journalist at EM360Tech sits down to talk about the critical need for a strong and unified approach to safeguarding digital assets against threats like DDoS attacks.

Expanding on the pervasive nature of these threats, Ley emphatically agrees that no organisation can afford to be complacent. Whether a large or small organisation and no matter where you are in the world, “everybody with IT data, employee data, application data, intellectual property of your product” faces potential risks.

Alluding to a common pitfall in security strategies, Ley points out that "a lot of people believe it's a technology only problem”. However, he explains that it’s actually a “people processing technology issue”.

He stresses that effective cybersecurity isn't solely about the tools deployed, but also about clear roles and responsibilities, questioning "who owns the accountability within the company?” Is it everyone or is it one person or team in particular?

This leads him to advocate for the vital role of strong CISOs within organisations.

Takeaways* DDoS attacks are increasingly sophisticated and varied. * A unified security platform enhances visibility and control. * Granular detection is essential to differentiate between good and bad traffic. * Organisations often underestimate their exposure to cyber attacks. * AI is becoming a crucial tool in fighting cyber threats. * Human expertise is vital in deploying and managing security technologies. * Continuous penetration testing helps identify vulnerabilities. * Cybersecurity is a shared responsibility across all levels of an organisation. * Smaller organisations need to leverage external expertise for security. * Proactive measures are essential to prevent potential cyber threats.

Chapters00:00 Introduction to Cybersecurity Challenges

03:06 Understanding DDoS Attacks

05:45 The Importance of Unified Security Platforms

09:05 Granular Detection in Cybersecurity

12:09 Real-World DDoS Mitigation Examples

15:07 AI in Cybersecurity: The New Frontier

17:59 The Human Element in Cyber Defense

20:12 Common Misconceptions About DDoS

23:56 Proactive Cybersecurity Measures

26:51 Future Cyber Threats and Nightmares

About A10 NetworksA10 Networks provides security and infrastructure solutions for on-premises, hybrid cloud, and edge-cloud environments. Their offerings help over 7000 customers, including global large enterprises and communications, cloud, and web service providers, ensure that business-critical applications and networks are secure, available, and efficient.

A10 Networks was founded in 2004 by Lee Chen and is based in San Jose, California. Lee Chen served as CEO until late 2019. The current CEO and President of A10 Networks is Dhrupad Trivedi, who assumed the role in December 2019.

View Details

Takeaways* #Personnelsecurity is crucial for organisations and individuals. * There is a significant talent shortage in the #cybersecurityindustry. * #AI can enhance security measures but cannot replace human instinct. * Outsourcing security functions can be beneficial for smaller organisations. * The pressure on cybersecurity roles is immense and can lead to high turnover. * AI will play a larger role in automating security responses in the future. * Understanding the risks of outsourcing versus insourcing is vital for businesses.

On this episode of #TheSecurityStrategist, host Keyari Page welcomes Tony King, Senior Vice President of International Sales at NETSCOUT. They discuss what personnel security is and why it's important for individuals and organisations to prioritise it.

To explain this, King introduces the concept of “knowledgeable instinct.” This means using both what people know and what AI can do to find and deal with cyber threats.

He emphasises that AI’s role is to be an extra “12th” player on your “football team,” making the defense that much stronger.

Listeners will gain a deeper perspective on the dynamic nature of the threat landscape, including the ways in which malicious actors leverage AI, and the continuous necessity for proactive threat prediction and prevention measures.

Tune in to understand the need for ongoing education and continuous skill development in a “never-ending chess game” of personnel security.

For the latest tech insights visit: em360tech.com

View Details

Takeaways* #Cloudmarketplaces function like a digital mall for various services. * Continuous monitoring and detection of threats are essential. * Legislation like NIST 2 and Dora impacts cloud security practices. * Zero trust methodology is advised in securing cloud connections. * Regular penetration testing and vulnerability management are necessary. * Data strategy is key when implementing #AI in cloud services. * Centralising identity management can limit security risks.

SummaryOn the #SecurityStrategistpodcast, host Keyari Page delves into the dynamic world of cloud marketplace ecosystems with Mostyn Thomas, Senior Director of Security at Pax8.

Listeners can gain a comprehensive understanding of these digital hubs where IT professionals and managed service providers (MSPs) can select from a diverse range of services.

Imagine a digital "mall," that's essentially a cloud marketplace. Within it, organisations can find "stores" that offer everything from identity and access management and cutting-edge API security.

The conversation also explores the crucial challenge of establishing secure cloud connections, where Thomas emphasises the importance of a "zero trust" security model.

This approach requires a diligent verification process for every connection and user within the cloud environment, regardless of location or perceived trustworthiness.

Tune in to learn its potential and evolving security challenges that must be addressed to ensure a safe and reliable experience for all stakeholders.

For the latest tech insights visit: em360tech.com

View Details

Takeaways* #Databackups are essential for business continuity. * The 3-2-1 backup #strategy is crucial for data protection. * Testing backup systems is necessary to ensure data recovery. * Businesses should back up all critical data sets. * #AI can assist in data classification for backups. * Avoid keeping backups in the same location as primary data. * Understanding when data became corrupted is vital for recovery.

SummaryJoin host Keyari Page as she welcomes Jon Fielding, Managing Director of Apricorn to discuss data backups.

They break down the basics of what data backups are and explain why they are so critical for businesses, especially in today's world of frequent ransomware attacks.

This episode offers practical guidance on setting up a good backup system. You'll discover how to identify your key data, prioritise its protection and avoid errors that could compromise your information.

Fielding also shares the valuable 3-2-1 backup strategy – a simple but powerful rule to minimise risk.

The discussion even touches on the potential role of AI in data backups, exploring both its benefits and the importance of maintaining human oversight.

This podcast provides actionable insights and expert guidance to help you protect your valuable data and ensure business continuity.

Tune in to gain the knowledge and confidence you need to navigate the complexities of data security!

For the latest tech insights visit: em360tech.com

View Details

Takeaways* #DDoS can mimic legitimate traffic, making detection difficult. * #Botnets are often created from compromised IoT devices. * Motivations for DDoS attacks range from hacktivism to personal grievances. * Residential IP proxy networks complicate DDoS defense. * #AI is increasingly being used in both attacks and defenses. * The future of cybersecurity will require AI-assisted solutions. * Organisations must understand their traffic to defend effectively.

SummaryIn this episode of The Security Strategist podcast, host Keyari Page leads an engaging conversation with David Warburton, Director of Threat Research at F5 Labs, focusing on Distributed Denial of Service (DDoS) attacks.

DDoS attacks are “one of the oldest cybersecurity attacks”. It’s an attempt to incapacitate a network, server, or website by overwhelming it with huge amounts of traffic.

However, despite their long history, DDoS attacks remain a significant problem. This is due to the fact that they “look like really popular, busy websites” which can lead to legitimate traffic being generated.

Warburton explains that they could be employed for a number of reasons, such as hacktivism, gaming-related conflicts, and geopolitical manipulation. A key example is of a Russian operation which used a digital attack to mimic a French protest against pension reform. This spread disinformation and created real world tension.

Tune into the latest episode to hear Warburton’s advice to businesses on tackling DDoS attacks.

For the latest tech insights visit: EM360Tech.com

View Details

"If you envision a world where what would be the most ideal way to make access management IAM decisions, to enable people to access internal things, you'd want to do a few things,” reflects Bobby DeSimone, Founder and CEO at Pomerium.

In this episode of The Security Strategies Podcast, host Alejandro Leal, cybersecurity expert and senior analyst at KuppingerCole Analysts AG speaks with DeSimone about the shifting focus in security to internal access solutions, particularly in identity and access management [IAM].

DeSimone emphasises the importance of simplifying typically complex internal access management IAM solutions. He suggests directing focus on the foundational need for secure and user-friendly access among other recommendations.

Additionally, he shares insights from his journey in the privileged access management space, discussing the limitations of traditional perimeter-based security and the need for a more comprehensive approach to identity and access.

The conversation also explores the challenges posed by client-based access solutions, the importance of context-driven access, and how Pomerium's clientless approach to device health is reforming internal access management IAM.

As threats become more sophisticated and workforces more distributed, the once impenetrable "castle and moat" approach leaves organisations vulnerable in terms of identity and access. As such, this podcast addresses the limitations of conventional access management IAM solutions and explores a modern, context-driven approach to securing internal assets.

DeSimone argues that the numerous acronyms like SASE, CASB, and PAM, while representing different facets of privileged access, ultimately fall under the umbrella of "just actually one big market under it, which is the internal identity and access market". The core challenge lies in moving beyond login-based authorization to a more granular, context-driven access model.

Watch the podcast to learn more about how to overcome traditional complexities and approach a more modern and relevant internal access management IAM solution.

Takeaways* Bobby's journey in security began with privileged access management. * Traditional perimeter-based security has significant limitations. * Organisations struggle with internal access despite strong outer defenses. * Client-based access solutions introduce administrative burdens and vulnerabilities. * Context-driven access is essential for modern security solutions. * Pomerium supports clientless device identity for easier access management. * The security landscape is evolving towards a more integrated internal access market. * Real-world applications of Pomerium show its effectiveness across industries. * CISOs should prioritize securing internal assets without traditional complexities. * Pomerium offers a flexible approach to access control on organisational terms.

Chapters00:00 Introduction to Security Strategies Podcast

01:02 Bobby's Journey in Security and PAM

03:01 Challenges of Traditional Client-Based Access Solutions

05:53 Market Segmentation and Context-Driven Access

09:02 Pomerium's Approach to Device Health and Clientless Access

12:03 Beyond the Perimeter: Real-World Applications of Pomerium

16:51 Key Takeaways for CISOs

About PomeriumPomerium is a zero-trust reverse proxy that helps enterprises manage secure application access. Authenticate, authorise, monitor, and secure user access to any application without a VPN. Access is driven by identity and context.

Pomerium allows you to use your existing identity provider, such as Okta, Active Directory, Google, Gsuite, or OneLogin to add single-sign-on authentication to any application. It enables you to add access control to any app, providing a standardised interface to do so whether an application itself has authorisation or authentication baked-in. This allows developers to focus on their apps, rather than reinventing access control mechanisms.

View Details

Takeaways

  • ExposureManagement involves assessing multiple factors, not just single scans.

  • Organisations must optimise their remediation capacity due to limited resources.
  • Visibility is crucial, but finding the most important exposure is essential.
  • TraditionalVulnerability management programs are becoming ineffective.

  • Exploitability is the key criterion for prioritising remediation efforts.
  • Automated scanning can provide rapid insights into vulnerabilities.
  • Time taken to remediate is critical for effective security management.

Summary

In this episode of the Security Strategist, Richard Stiennon, Chief Research Analyst at IT Harvest and industry leader, speaks with Marc Gaffan, the CEO of IONIX.

They explore the core challenges facing #cybersecurity professionals — particularly in a rapidly evolving digital landscape — and discuss innovative approaches to attack surface management.

Gaffan explains exposure management isn't just about looking at one scan, vulnerability, or way an organisation could be exploited. Instead, it takes a holistic approach to understand what "exposure" means for organisations.

Listen to the full conversation on how to adapt your security strategy to today's potential threats. Gaffan's expertise provides valuable guidance for any security professional looking to stay ahead of the curve.

For more tech insights visit EM360Tech.com

View Details

Takeaways

  • Peacetimesecurity is no longer sufficient in modern cloud environments.

  • AI and automation are essential for effective security management.
  • Real-time security platforms can prevent breaches before they occur.
  • Integrating security into the development process is crucial for success.
  • Key metrics include mean time to detect and remediate vulnerabilities.
  • A unified #dataarchitecture is vital for effective security operations.
  • Automation can significantly reduce analyst workload and alert fatigue.
  • Organisations should evaluate vendors based on their ability to adapt to evolving threats.

Summary

Is your organisation still relying on outdated “peacetime” security solution strategies in the face of rapidly evolving #cloudthreats? Host Brad LaPorte explores answering this question with guest Ory Segal, Technical Evangelist of Cortex Cloud, Palo Alto Networks. They discuss how the dynamic nature of modern cloud environments and increasing adoption of AI are compelling organisations to move beyond traditional "peacetime" network security measures.

In this episode of theSecurity Strategist, Segal explains the difference between securing traditional monolithic applications and modern cloud-native applications. “Modern cloud native applications, beyond the fact that it's deployed to the cloud, entails something completely different,” Segal states, stressing the complexity of various technological layers in cloud services.

Join the conversation as we discuss the shift from static security models to dynamic, real-time protection, and leveraging #AI to mitigate cloud security threats and strengthen network protection. Learn what this means for your organisation and how to adapt your cloud security solutions.

For the latest tech insights visit: EM360Tech.com

View Details

Remote Monitoring and Management (RMM) solutions are quite ambitious, promising to identify the issues before they have a chance to impact your IT operations. “A good RMM offers a combination of tools for you to do this properly,” stated Elias Moura, the Head of Product Marketing at Pulseway.

“You have automation to enable auto-remediation, built-in remote control, automated patching, mobile device management, and other features that make RMM an effective tool,” he added. “The RMM is usually the central piece to make sure that IT management is consistent and tackling different issues that your end user could face.”

In this episode of the Security Strategist podcast, host Shubhangi Dua, B2B Tech Journalist and Podcast Producer from EM360Tech speaks to Moura and Edgar Zacharjev, SVP of Product and Strategy at Pulseway.

They discuss contemporary cybersecurity threats, the importance of compliance and protocols, and the role RMM, automation, and AI in IT management. The conversation spotlights the significance of patch management, automation, and the integration of AI in cybersecurity strategies.

Real-life examples illustrate how organisations can effectively tackle security challenges, emphasising the need for a proactive approach and continuous awareness training.

Watch the podcast to learn why diligent patch management forms your initial and crucial line of defense against exploitation. Explore the power of automation in streamlining security operations, improving response times, and enhancing overall efficiency.

Takeaways* The cybersecurity landscape is constantly evolving, requiring adaptive strategies. * Compliance and protocols, while sometimes seen as hindrances, are essential for security. * Remote Monitoring and Management (RMM) is crucial for effective IT management. * Patching systems regularly is vital to prevent vulnerabilities. * Automation can significantly enhance IT efficiency and reduce manual workload. * AI is becoming integral in IT and business management, cybersecurity, but organizations must use it wisely. * Anomaly detection and user awareness training are critical components of a security strategy. * Building a unified IT stack simplifies management and enhances security. * Real-life examples demonstrate the effectiveness of proactive cybersecurity measures. * CISOs must advocate for cybersecurity investment within their organisations.

Chapters00:00 Introduction to Cybersecurity Challenges

03:10 Evolving Cybersecurity Strategies

05:58 The Importance of Compliance and Protocols

08:53 Understanding Remote Monitoring and Management (RMM)

11:50 The Role of Patching in Cybersecurity

14:58 Advancements in Automation and IT Management

17:59 AI in Cybersecurity: Opportunities and Risks

20:59 Anomaly Detection and IT Awareness Training

24:02 Real-Life Examples of Cybersecurity Solutions

27:00 Benefits of RMM for Proactive IT Management

29:51 Building a Unified IT Stack

32:51 Internal Security Practices and Protocols

36:10 Key Takeaways for CISOs

View Details

Application Programming Interface (API) is one of the most critical components of software applications which mediates communication between different applications and exchanges permissible data. APIs, as a fundamental integrant of software, are acutely important to secure, as vulnerabilities can be exploited by threat actors.

“When it comes to API-based attacks or API attacks, just within 2024, if we compare the second half of the year to the first half, there was a 188 percent surge in those types of attacks,” articulated Uri Dorot, the Senior Product Marketing Manager at Radware.

To ultimately enhance a business’s ability to detect and respond to cyber threats, securing APIs is key. These APIs are also essential in controlling access to sensitive business logic and data – acting as a key attack vector.

In this episode of the Security Strategist podcast, Chris Steffen, VP of Research at EMA is joined by Dorot. They discuss the biggest challenges facing API security particularly pertaining to business logic attacks.

The speakers address the question – Can organisations truly mitigate targeted attacks against their APIs and application business logic? Dorot breaks down the steps and provides practical security strategies to protect enterprises from not only falling into traps but also using business logic for effective protection against increasingly sophisticated threats.

Takeaways* Business logic attacks exploit legitimate API calls in illegitimate ways. * Visibility into API environments is crucial for effective security. * Organizations often lack documentation for their APIs, increasing risk. * AI tools can help discover and map API endpoints and business logic. * Business logic is complex and constantly evolving, requiring ongoing attention. * Attackers use AI to enhance their reconnaissance and exploit strategies. * Contextual understanding is key to identifying unusual access patterns. * Security solutions must adapt to the dynamic nature of applications. * Real-time/runtime mitigation is necessary to respond to evolving threats. * HTTP DDoS attacks on API-based applications require specialized behavioral-based protection.

Chapters00:00 Introduction to API Security Challenges

02:32 Understanding Business Logic Attacks

06:11 The Importance of API Visibility

12:26 AI's Role in API Security

17:52 Trends in API Security with Generative AI

21:43 Context and Granularity in Protection

28:58 Key Takeaways for Security Practitioners

About RadwareRadware is a leading cyber security solutions and application delivery solutions company globally. They provide award-winning security and availability for infrastructure, applications, and enterprise IT across physical, cloud, and software-defined data centers.

Trusted by over 12,500 enterprises and carriers worldwide to enhance digital experience, ensure business continuity, and maximise productivity with cost-effective solutions.

View Details

In this episode of the Security Strategist podcast, Chris Steffen speaks with Sudhir Reddy, the CTO of Esper, about the imperative balance between security and user experience in dedicated devices.

They discuss the unique challenges of securing these devices, the role of Mobile Device Management (MDM), compliance issues, and practical steps enterprises can take to optimise their device fleets. The conversation not only spotlights the importance of proactive security measures but also the need for organisations to address vulnerabilities in their dedicated devices.

From kiosks and point-of-sale machines to medical devices and airport check-in counters, these ubiquitous tools present idiosyncratic security vulnerabilities that demand proactive strategies.

MDM is the first line of defense. Sudhir says, “This is your interface to secure everything that's happening on the device, whether it's bits and bytes that get on the device.”

“Whether it's what peripherals are allowed on the device, what device serial numbers of peripherals are allowed to talk to the device,” he added. “All of these are things that managers of large fleets have to think about."

Tune into the podcast to hear more about dedicated device security as a critical component of a detailed security strategy and adopting a proactive, data-driven approach to help organisations mitigate risks and ensure harmonious operation of their edge device fleets.

Takeaways

  • Dedicated devices present unique security challenges compared to traditional devices.
  • The presence of humans is a key factor in security compliance issues.
  • MDM can enhance both security and user experience.
  • Compliance is crucial for devices handling sensitive data.
  • Patching and updating devices can be challenging due to downtime.
  • Proactive measures can minimise vulnerabilities before exploitation.
  • Organisations should start with smaller, manageable security issues.
  • Gradual rollout of updates can prevent widespread issues.
  • Device management should not be an afterthought.
  • There are tools available to help secure dedicated devices.

Chapters

00:00 Introduction to Dedicated Devices and Security Challenges

03:01 The Unique Landscape of Dedicated Devices

05:48 The Role of MDM in Security and User Experience

08:57 Compliance and Data Security in Dedicated Devices

12:05 Patching and Updating Challenges

15:02 Proactive Security Measures for Device Management

18:53 Practical Steps for Improving Security Posture

25:06 Final Thoughts and Key Takeaways

View Details

Welcome back to Meeting of the Minds, a podcast series that brings industry leaders together for the most engaging conversations of the year. In our inaugural episode, cybersecurity experts Christopher Steffen, Richard Stiennon, and Brad LaPorte, joined by Evgeniy Kharam, provided a comprehensive overview of the current cybersecurity landscape. They explored the complexities and challenges that organisations face in today's digital age, setting the stage for a deeper exploration of what the future holds.

This episode, Steffen, Stiennon, and LaPorte were joined by moderator Alejandro Leal, a senior analyst specialising in cybersecurity, digital identity, and AI at KuppingerCole. Throwing out the script, they took the conversation to the next level, venturing into uncharted territory and pushing the boundaries of cybersecurity.

Prepare for a no-holds-barred discussion as the analysts speculated on the disruptive forces that will shape the future of cybersecurity, dissecting everything from the intricate challenges of DOGE and securing AI to the potential paradigm shifts brought about by quantum computing.

The cybersecurity experts did not shy away from controversial topics, but instead provided their unfiltered opinions on the impact of government initiatives like DOGE and the UK's Investigatory Powers Act.

They also talked about the ethical dilemmas surrounding data privacy and security, and debated the potential consequences of a "quantum day" – the moment when quantum computing breaks current encryption standards. Brace yourself for some surprising hot takes and thought-provoking insights that will challenge your understanding of the cybersecurity landscape.

Watch the first episode of Meeting of the Minds State of Cybersecurity in 2025 podcast.

Takeaways

  • The chaotic approach to government efficiency can hinder cybersecurity efforts.
  • Bureaucracy can provide stability but also opens doors for corruption.
  • The balance between efficiency and oversight is crucial in cybersecurity.
  • Recent government actions raise concerns about privacy and security.
  • Reckless adoption of new technologies poses significant risks.
  • The cybersecurity landscape is influenced by political decisions.
  • The historical tension between privacy and state surveillance continues.
  • Court orders should be the standard for accessing private information. Lawful Intercept has led to vulnerabilities in telecom systems.
  • Businesses must use secure communication methods, even with trusted devices.
  • Sensitive data should not be stored on mobile devices.
  • Organisations should avoid using apps like WhatsApp for sensitive communications.
  • Most organisations lack basic encryption for their data.
  • Organisations must understand their data infrastructure before preparing for quantum.
  • The future of cybersecurity will require adaptability and innovative thinking.

Chapters

00:00 Introduction to Cybersecurity in 2025

01:30 Impact of Government Efficiency on Cybersecurity

11:09 Bureaucracy vs. Efficiency in Cybersecurity

16:56 UK Government's Demand for Encrypted Data Access

24:08 The Risks of Backdoors in Technology

27:21 Preparing for Quantum Computing

39:01 Current State of Quantum Authentication

47:07 The Future of Cybersecurity and Quantum Technology

View Details

Andrea Cullen discusses her extensive experience in cybersecurity, focusing on the gender imbalance and cultural stereotypes that have historically dominated the field. She emphasizes the importance of diversity and mentorship in fostering innovation and problem-solving within cybersecurity teams. Andrea advocates for a more inclusive approach to recruitment and highlights the need for creative thinking in addressing cybersecurity challenges. The discussion also touches on the significance of leadership in creating a welcoming environment for diverse talent.

Key takeaways

  • Cybersecurity has been male-dominated for decades.
  • Cultural stereotypes contribute to gender imbalance in tech.
  • Diversity enhances problem-solving and innovation.
  • Mentorship is crucial for underrepresented groups.
  • Leadership should model openness to mistakes.
  • Cybersecurity requires both technical and creative skills.
  • Recruitment should focus on potential, not just certificates.
  • Real-world experiences can change perceptions of cybersecurity.
  • Diverse teams lead to better solutions and outcomes.
  • Everyone has something to contribute to cybersecurity.

View Details

“Continuous threat exposure management is the new phrase for what we used to call vulnerability management programs," said J.J. Guy, CEO and Co-Founder of Sevco Security.

In this episode of The Security Strategist podcast, Richard Stiennon, Founder and Chief Analyst at IT-Harvest speaks with Guy about the evolution of vulnerability management into Continuous Threat Exposure Management (CTEM).

Guy stresses that traditional vulnerability management falls short in modern environments, which is why there's a critical shift towards CTEM. This isn't just a rebranding, it's a fundamental change in approach. As attack surfaces expand, so do the types of exposures organisations need to address. A fragmented approach to vulnerabilities leaves organisations overwhelmed.

"We've all told all auditors we've got it under control and we've all pointed to the CMDB as the tool to accommodate that control. But at the same time, we've known that the CMDB is wildly inaccurate," Guy voiced, spotlighting the need for a better system.

CTEM programs offer a structured framework, integrating the interconnectedness between vulnerabilities and devices, users, threats in the wild, and the business impact of a breach to drive more effective prioritisation, mitigation, and remediation of vulnerabilities in increasingly complex environments. As Guy says, welcome to Vulnerability Management Programs 2.0.

This is just a taste of what was discussed on the podcast. Watch the podcast for deeper insights and unconventional notions for businesses to succeed in today’s rapidly involving cybersecurity sphere.

Takeaways

  • Continuous Threat Exposure Management (CTEM) is the evolution of vulnerability management.
  • CTEM is seen as vulnerability management 2.0, adapting to the changing landscape of cybersecurity.
  • A strong asset inventory is foundational for effective CTEM.
  • Organisations often face challenges in managing multiple vulnerability assessment tools.
  • The importance of real-time, live operational views of assets cannot be overstated.
  • Threat intelligence plays a critical role in prioritizing vulnerabilities.
  • Data aggregation from multiple sources is essential for a complete inventory.
  • The industry needs to move away from compliance-oriented activities to operational ones.
  • Emerging trends indicate a consolidation of tools and deeper integrations in cybersecurity.
  • Better data leads to better decisions and outcomes for organisations.

Chapters

00:00 Introduction to Continuous Threat Exposure Management

02:52 The Evolution of Vulnerability Management

05:52 The Importance of Asset Inventory

08:54 Challenges in Vulnerability Management

11:50 Characteristics of a Strong Security Inventory

15:01 Emerging Trends in Exposure Management

17:57 Key Takeaways for CISOs

View Details

In today's deeply connected world, cybersecurity is no longer just a technical issue—it's deeply intertwined with geopolitics. This episode explores this complex relationship, talking about the ever-shifting threat space and examining how international regulations and geopolitical tensions impact organisations' cybersecurity posture.

The episode also discusses the double-edged sword of artificial intelligence in cybersecurity, acknowledging its potential to enhance defenses while also requiring skilled personnel to effectively leverage its capabilities.

It further spotlights that achieving zero risk in cybersecurity is an unrealistic goal, and enterprises must focus on building strong risk management frameworks and selecting the right security controls to mitigate potential damage.

The podcast provides valuable takeaways for businesses of all sizes, stressing the importance of continuous improvement and adaptation in the face of ever-evolving cyber threats.

Tune in for a deep dive into the intersection of geopolitics and cybersecurity. Gain valuable insights on how to navigate the complex regulatory environment, leverage the power of AI, and develop effective risk management strategies to protect your organisation in today's interconnected world.

In this episode of the EM360Tech’s The Security Strategist podcast, host Shubhangi Dua speaks with Bryan Marlatt, Chief Regional Officer at CyXcel, about the complex relationship between geopolitics and cybersecurity.

Takeaways

  • The global regulatory landscape for cybersecurity is complex and fragmented.
  • Privacy regulations are critical for enterprises to monitor and comply with.
  • AI can enhance cybersecurity processes but requires skilled personnel to leverage effectively.
  • Zero risk in cybersecurity is unrealistic; organisations must manage acceptable risk.
  • GDPR has significantly influenced how organisations approach data protection.
  • Phishing attacks remain a prevalent threat across all sectors.
  • Operational technologies are increasingly vulnerable to cyber threats.
  • Organisations need to adopt a proactive approach to cybersecurity.
  • Choosing the right security controls is essential for effective risk management.
  • Continuous improvement and adaptation are necessary in the cybersecurity landscape.

Chapters

00:00 Introduction to Geopolitics and Cybersecurity

02:29 Navigating the Complex Regulatory Landscape

05:15 The Role of AI in Cybersecurity

12:15 Understanding Acceptable Risk in Cybersecurity

18:24 Global Perspectives on Cybersecurity Regulations

23:04 Emerging Cyber Threats and Mitigation Strategies

View Details

In this conversation, Rob Demain shares his extensive background in cybersecurity and discusses the importance of neurodiversity in the field. He emphasizes how neurodiverse individuals can bring unique problem-solving skills that drive innovation in cybersecurity. The discussion also covers the significance of diversity in teams, the need for resilience in cybersecurity strategies, and the role of AI in enhancing human capabilities rather than replacing them. Rob highlights the balance between automation and human expertise, advocating for a thoughtful approach to implementing AI in organizations.

Key Takeaways

  • Neurodiversity brings unique problem-solving approaches to cybersecurity.
  • Diverse teams are essential for tackling complex cybersecurity challenges.
  • Resilience is key in responding to cyber threats effectively.
  • AI should enhance human capabilities, not replace them.
  • Organizations need clear AI strategies and policies.
  • Creating environments that nurture diverse talents is crucial.
  • Cybersecurity requires a balance between automation and human expertise.
  • Proactive resilience is necessary for effective cybersecurity.
  • Diversity of thought prevents groupthink in cybersecurity.
  • Continuous learning and adaptation are vital in the cybersecurity landscape.

Chapters

00:00 Introduction to Cybersecurity and Neurodiversity

03:01 The Role of Neurodiversity in Cybersecurity Innovation

06:05 Diversity in Cybersecurity Teams

08:58 Resilience in Cybersecurity Strategies

12:06 AI's Impact on Cybersecurity

14:59 Balancing Automation and Human Expertise

18:01 Implementing AI Strategies in Organizations

View Details

The digital warground is constantly advancing, with increasingly sophisticated malware and attack vectors challenging traditional cybersecurity defences. The critical role of AI and Zero Trust has been shaping the future of cyber defence for a while now.

It’s become absolutely necessary to adopt a zero-trust security model to protect against today's complex threats. AI too has become a powerful tool for enhancing cybersecurity measures, from threat detection to security operations, while also acknowledging its potential misuse by malicious actors.

In this episode, Danny Jenkins, CEO of ThreatLocker, discusses the intersection of cybersecurity and artificial intelligence. The conversation explores the ethical considerations surrounding AI in security, spotlighting the need for strong regulatory frameworks that foster education and responsible development rather than stifling innovation.

Join us as we unpack the vital components of building a future-proof cybersecurity strategy in the age of AI and Zero Trust.

Key Takeaways

  • AI can help identify threats but also aids attackers.
  • The threat landscape has evolved with sophisticated malware.
  • Zero trust security is essential for modern defence.
  • AI should assist in decision-making, not replace it.
  • Education on AI risks is crucial for organisations.
  • Regulatory frameworks should focus on education, not restriction.
  • AI can create unique malware easily, complicating detection.
  • Organisations must reassess their threat models regularly.
  • Collaboration and understanding are key to effective AI use.

Chapters

00:00 Introduction to Cybersecurity and AI

03:09 The Evolving Threat Landscape

06:11 Zero Trust Security: A New Mindset

09:03 AI as a Tool for Cyber Defense

12:10 Ethical Considerations in AI Security

14:50 Regulatory Frameworks and Global Collaboration

17:51 Conclusion and Future Directions

View Details

The state of cybersecurity is rapidly and constantly evolving, and the future is not necessarily certain.

In the first episode of Meeting of the Minds, three leading industry analysts – Christopher Steffen, VP of Research at EMA; Richard Stiennon, Founder and Chief Analyst at IT-Harvest; and Brad LaPorte, Morphisec CMO & Advisor at Lionfish Tech Advisors – along with moderator Evgeniy Kharam, Founder of EK Cyber & Media Consulting, explore the critical challenges and opportunities that will shape the state of cybersecurity in 2025.

They discuss the complex role of AI in security, examining both its potential to enhance defences and the new vulnerabilities it introduces. The experts also tackle the security implications of open-source technologies such as DeepSeek and the ongoing debate surrounding self-regulation within the industry.

A key focus of the conversation is the strategic approach to cybersecurity. The analysts break down the merits and drawbacks of platform solutions versus best-of-breed tools, considering the importance of maturity levels in tool selection and the integration challenges that often follow acquisitions.

The episode also explores the tension between achieving compliance and building a truly secure environment. The panel highlights the importance of moving beyond simply checking boxes and instead focus on developing strong security postures.

Join us for this vital discussion as we navigate the complex sphere of cybersecurity in 2025.

Takeaways

  • AI is both a tool and a potential vulnerability in cybersecurity.
  • Guardrails are essential to prevent misuse of AI technologies.
  • The rapid adoption of AI has outpaced the establishment of security measures.
  • Open-source AI models like DeepSeek can introduce significant security risks.
  • Self-regulation and testing are critical for organisations using AI as the trustworthiness of AI outputs is a major concern for decision-making.
  • Companies should focus on enhancing core capabilities with AI, not just adopting it for marketing.
  • Choosing between specialised tools and comprehensive platforms is a key decision for businesses. Companies that rely on platformisation are often doomed to fail.
  • Compliance does not guarantee security; many compliant companies have faced breaches.
  • Organisations should focus on quick wins in security improvements.
  • Training and staffing are crucial for effective tool management.
  • The lifespan of a CISO is short; quick gains are necessary.
  • Understanding the roadmap of existing tools can prevent unnecessary purchases.

Chapters

00:00 Introduction to Cybersecurity in 2025

02:05 The Role of AI in Cybersecurity

09:49 Vulnerabilities in AI Models

16:04 Open Source AI and Security Challenges

19:59 Best of Breed vs. Platform Solutions

22:34 The Perils of Platformisation

25:05 Maturity Levels and Tool Selection

28:07 Integration Challenges in Acquisitions

34:13 Compliance vs. Security

44:05 Proactive Security Strategies

View Details

This conversation explores the critical and ever-evolving relationship between data infrastructure and cybersecurity, shining a light on the necessity of proactive security measures in an increasingly interconnected digital world. The discussion highlights essential themes such as data resilience, the seamless integration of security and recovery strategies, and the complex role of artificial intelligence, which simultaneously bolsters and challenges cybersecurity efforts. A call to action is made for organisations to shift their perspective, viewing cybersecurity as a strategic enabler rather than a mere cost, while also emphasising the value of comprehensive employee training to maintain strong security practices.

In a captivating second act, Jim Liddle dives into the transformative potential of leveraging AI and other emerging technologies to predict and neutralise threats before they occur. By aligning cybersecurity initiatives with broader organisational objectives, he illustrates how businesses can turn security into a driver of innovation and competitive advantage. Through engaging real-world examples and actionable advice, the conversation urges listeners to abandon outdated, reactive strategies in favour of a forward-looking, resilient approach.

Key Takeaways

  • True cybersecurity leadership comes from data infrastructure.
  • Companies need to adopt a proactive approach to cybersecurity.
  • Data resilience is crucial for effective recovery from attacks.
  • AI can both enhance and complicate cybersecurity efforts.
  • Security should be integrated into the core infrastructure.
  • Training employees is essential to mitigate human error.
  • Cybersecurity can be a competitive advantage for businesses.
  • Organisations must plan for potential security breaches.
  • Immutable data architectures can prevent data loss.
  • Investing in security is investing in business growth.

Chapters

00:00 - Introduction to Cybersecurity and Data Infrastructure

02:54 - The Importance of Data Resilience in Cybersecurity

05:58 - Integrating Security and Recovery for Resilience

08:59 - AI: A Double-Edged Sword in Cybersecurity

12:11 - Transforming Cybersecurity into a Competitive Advantage

15:10 - Fostering Innovation While Ensuring Security

17:55 - Conclusion and Future Directions

View Details

Today, organisations are grappling with the critical challenge of securing APIs in an era dominated by AI integration and increasing cyber threats. APIs, the backbone of modern technology, are vital for enabling seamless communication between applications. However, as their usage grows, so do the risks associated with inadequate API management and security. These vulnerabilities can lead to unauthorised access, data breaches, and system disruptions, making API security a top priority for businesses of all sizes.

In the face of these challenges, safeguarding APIs demands more than basic measures. Organisations must adopt a comprehensive approach that integrates proactive security practices, advanced tools, and a culture of security embedded within the development lifecycle. Just as an assembly line ensures precision in manufacturing, API security must be built into every stage of application development to mitigate risks effectively.

The stakes are particularly high in this rapidly evolving landscape. As highlighted by Marco Palladino, CTO and co-founder of Kong, organisations must stay ahead of emerging trends in AI and API usage while addressing the challenges of protecting their systems. Proactive measures, such as implementing API gateways, monitoring traffic for anomalies, and employing zero-trust principles, are essential to ensure robust protection.

Key Takeaways

  • APIs are essential for connecting software and services.
  • AI integration relies heavily on APIs for functionality.
  • Effective API management is crucial for security and compliance.
  • Organisations must adopt proactive security measures for APIs.
  • Security should be integrated into the development lifecycle.
  • API-related attacks are on the rise, necessitating better security practices.
  • Automation can help identify security issues early in development.
  • The accuracy of AI responses remains a significant challenge.
  • Organisations need to balance retrieval and generation in AI applications.
  • Emerging trends in AI require organisations to adapt their API strategies.

Chapters

00:00 - Introduction to APIs and Their Importance

02:59 - The Role of APIs in AI Integration

05:50 - API Management and Security Concerns

09:00 - Best Practices for API Security

11:56 - Challenges and Threats in API Security

14:56 - Proactive Security Measures for APIs

17:45 - The Future of APIs in AI Development

21:07 - Emerging Trends in AI and API Usage

View Details

In this podcast, Sascha Giese discusses the evolving role of AI in IT teams, addressing employee perceptions, the need for regulations, and the importance of collaboration between IT and AI teams. He emphasizes that while AI may replace some jobs, it will primarily transform existing roles. The discussion also highlights the necessity of observability in IT systems to optimize performance and ensure security.

Key Takeaways

  • AI will replace some jobs, but transform most.
  • AI needs to be supervised and trained.
  • AI is more of an assistant than a replacement.
  • There is a need for government regulation for AI.
  • Tension exists between IT and AI teams due to communication breakdowns.
  • AI can improve the efficiency of the whole IT organization.
  • Tool consolidation is becoming more popular in IT.
  • Losing business can happen in minutes without observability.

Chapters

00:00 Introduction to AI and IT Teams

06:10 Regulations and Guidelines for AI

11:52 The Importance of Collaboration in IT

17:46 Security and Observability in IT

View Details

The shift to cloud computing has transformed how businesses operate, offering unmatched flexibility, scalability, and cost efficiency. However, as organisations increasingly rely on the cloud, the attack surface for cyber threats has expanded significantly.

Traditional security tools often struggle to keep up with the unique challenges of cloud environments, such as dynamic workloads, distributed systems, and multi-cloud configurations. This is where Cloud Detection and Response (CDR) becomes essential. CDR solutions are specifically designed to monitor cloud environments in real-time, identify potential threats, and provide swift responses to mitigate risks.

The importance of CDR extends beyond just preventing breaches—it’s about safeguarding critical data, maintaining business continuity, and building trust with customers and stakeholders. With the rise of sophisticated attacks like ransomware and supply chain compromises targeting cloud infrastructure, having a comprehensive CDR strategy is no longer optional but a necessity.

In this episode, Aparna Sundararajan speaks to Mohit Bhasin, Senior Product Marketing Manager at Palo Alto Networks, about the importance of CDR and the need for a holistic approach to cybersecurity.

Key Takeaways:

  • Cloud security is essential for organisational success.
  • Real-time protection is crucial to prevent attacks.
  • Organisations need a unified approach to cloud security.
  • Visibility and context are critical in security solutions.
  • Proactive risk management is necessary in cloud environments.
  • Security should be integrated into the development process.
  • Automation can enhance security team efficiency.
  • Security is an enabler of innovation, not a blocker.

Chapters:

00:00 - Introduction to Cloud Detection and Response

02:55 - Understanding Cloud Detection and Response

05:46 - Real-Time Protection and Customer Insights

09:00 - The Future of Cloud Security

11:52 - Overrated and Underrated Aspects of CDR

14:46 - Final Thoughts on Cloud Security Strategy

View Details

Effective supply chain risk management is no longer optional—it is essential for long-term business success. Disruptions from natural disasters, geopolitical tensions, or unexpected global events like pandemics can ripple through even the most carefully planned supply chains.

Companies that fail to anticipate and mitigate these risks can face costly delays, increased operational costs, and damaged reputations. By prioritising risk management, businesses can identify vulnerabilities, strengthen their supply chain resilience, and ensure that they can respond swiftly to unforeseen challenges.

Proactively managing supply chain risk offers a competitive edge in an increasingly unpredictable marketplace. It allows businesses to build stronger relationships with suppliers, improve operational efficiency, and ensure continuity of service, even in times of crisis. Implementing strategies such as diversifying suppliers, leveraging technology for better visibility, and adopting flexible logistical models can help organisations stay agile and minimise potential disruptions.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Haydn Brooks, CEO and Co-Founder of Risk Ledger, about third-party risk management and the best practices for organisations to enhance their security posture.

Key Takeaways:

  • Supply chains have become more interconnected, increasing exposure to cyber risks.
  • Hackers target corporate supply chains for financial gain and geopolitical reasons.
  • The attack surface has expanded significantly without corresponding security measures.
  • Supply chain attacks can be untargeted or targeted, with different motivations.
  • Developing security tools for supply chains is challenging due to complexity and the need for more visibility.
  • Real-world examples like Target and SolarWinds illustrate the consequences of supply chain breaches.
  • Neglecting third-party risk management can lead to reputational and operational impacts.
  • Collaboration with suppliers is essential for a unified defence against cyber threats.

Chapters:

00:00 - Introduction to Supply Chain Risk Management

01:51 - Understanding the Motivation Behind Supply Chain Attacks

04:39 - Challenges in Developing Security Tools for Supply Chains

06:37 - Real-World Consequences of Supply Chain Breaches

09:23 - The Importance of Third-Party Risk Management

11:18 - Best Practices for Enhancing Third-Party Risk Management

13:37 - The Role of Automation in Risk Management

15:04 - Creating a Unified Defense Strategy with Suppliers

View Details

Today, organisations face relentless cybersecurity threats, with phishing attacks and poor password management leading the charge. These vulnerabilities can result in data breaches, financial losses, and reputational damage, making them a top concern for businesses of all sizes. Despite technological advances, many organisations struggle to keep up with increasingly sophisticated phishing techniques and the risks of weak or reused passwords.

Addressing these challenges requires more than cookie-cutter solutions—it demands a holistic approach to cybersecurity that encompasses technology, employee education, and robust policy enforcement.

The stakes are exceptionally high for small and medium-sized enterprises (SMEs). Cybercriminals often target SMEs, perceiving them as less prepared to fend off attacks. Implementing effective cybersecurity measures doesn’t have to be overwhelming or costly, but it does require understanding the risks and taking proactive steps to mitigate them.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Steven Furnell, IEEE senior member and professor of cybersecurity at the University of Nottingham.

Key Takeaways:

  • Cybersecurity posture shows little improvement year over year.
  • Phishing remains the most reported cybersecurity threat.
  • Community support is vital for SMEs in cybersecurity.
  • Transitioning to passwordless solutions is underway but not complete.
  • Biometric data should be stored securely on user devices.
  • Usability must be balanced with security in technology development.
  • Deepfake technology presents new challenges for biometric systems.

Chapters:

00:00 - Introduction to Cybersecurity Insights

01:27 - Current Cybersecurity Posture and Challenges

03:23 - Phishing and Common Cybersecurity Threats

07:09 - Supporting Small and Medium Enterprises

10:56 - Transitioning to a Passwordless Future

17:16 - Biometric Security and Its Challenges

View Details

Governments and institutions face unprecedented cyber threats challenging national infrastructure, sensitive data security, and public services. To stay ahead in emerging risks, organisations must adopt cutting-edge tools that enable proactive preparation and robust defence strategies against these risks.

Cyber ranges and digital twins are revolutionising cybersecurity by offering highly effective methods for simulating real-world attacks, testing security protocols, and providing predictive insights into potential vulnerabilities. These tools provide a safe, controlled environment for teams to practice and refine their response strategies, ensuring they can confidently tackle sophisticated cyber threats.

Cyber ranges create realistic virtual environments that mimic complex network infrastructures, enabling security teams to engage in hands-on training exercises and test their systems under simulated attack scenarios. Meanwhile, digital twins—virtual replicas of physical systems—allow for continuous monitoring and real-time analysis of critical infrastructure.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Aare Reintam, COO of CybExer Technologies, about their NATO-award-winning cyber ranges.

Key Takeaways:

  • Cyber ranges are essential for simulating real-world cyber attacks.
  • Digital twins provide a safe environment for testing and learning.
  • AI can enhance both offensive and defensive cybersecurity strategies.
  • Regular participation in cyber ranges improves team readiness.
  • Understanding interdependencies in critical infrastructure is vital.
  • Proactive measures are necessary to address cybersecurity weaknesses.

Chapters:

00:00 - Introduction to Cyber Ranges and Digital Twins

02:50 - The Role of Cyber Ranges in Cybersecurity Training

05:45 - Digital Twins: Enhancing Cybersecurity Simulations

09:06 - Adapting to Evolving Cyber Threats

12:01 - AI and Machine Learning in Cyber Ranges

14:57 - Long-term Implications of Cyber Ranges for Organizations

17:52 - Best Practices for Cyber Range Participation

21:04 - The Importance of Continuous Training for Governments

23:57 - Conclusion and Resources

View Details

Digital risk protection has become a cornerstone of organisational security. Proactive measures are essential to defend against cyber risks, from safeguarding sensitive data to mitigating external threats. Businesses must move beyond traditional cybersecurity approaches, embracing holistic digital risk strategies that protect their reputation, assets, and customers. Organisations can create resilient systems that adapt to today’s complexities by anticipating risks rather than merely reacting to them.

However, adequate digital risk protection isn’t just about technology—it requires a cultural shift. Fostering a security-first mindset means embedding security practices into every level of an organisation, from executive leadership to front-line employees. This cultural evolution goes hand in hand with compliance, as businesses align their strategies with ever-changing regulations.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Scott Walker, Cyber Security Incident Response Team manager at Orange Cyberdefense, about the continuous nature of cybersecurity efforts, highlighting the thrill and challenges of incident response.

Key Takeaways:

  • Digital risk protection is essential for organisations.
  • Cultural shifts are necessary for effective cybersecurity compliance.
  • Honesty in reporting incidents is crucial for effective response.
  • Real-time metrics are vital for measuring cybersecurity effectiveness.
  • Community support can help smaller businesses improve security.
  • Incident response is a dynamic and exciting field.
  • Understanding past threats helps in preparing for future ones.

Chapters:

00:00 - From Military to Cybersecurity: Scott Walker's Journey

01:24 - The Importance of Digital Risk Protection

05:41 - Cultural Shifts in Cybersecurity Compliance

09:00 - Building a Culture of Honesty in Cybersecurity

10:54 - The Role of Real-Time Metrics in Cyber Defense

13:41 - Community Support in Cybersecurity

15:34 - Emerging Threats: AI and Cybersecurity Resilience

19:35 - The Thrill of Incident Response

View Details

Understanding human behaviour is critical in creating secure environments, as human actions, decisions, and vulnerabilities often determine the effectiveness of security measures. By prioritising behavioural insights, organisations can anticipate potential threats and design systems that align with how people naturally act and interact.

Discussing the psychological drivers behind employee behaviour helps uncover why individuals may unknowingly bypass security protocols, highlighting the importance of addressing root causes rather than merely enforcing rules.

Security isn’t just about preventing incidents; it’s about cultivating a culture where individuals are empowered to make informed decisions. This involves fostering a "just culture," where employees feel safe reporting mistakes without fear of punishment, enabling continuous improvement. By focusing on trust, transparency, and education, organisations can instil a security-first mindset across their workforce.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to John Scott, Lead Cyber Security Researcher at CultureAI, about building trust and responsibility within security culture to mitigate cyber risks effectively.

Key Takeaways:

  • Understanding human behaviour is crucial for security.
  • Human errors are inevitable; organisations must accept this.
  • A ‘just culture’ is essential for a secure environment.
  • Leadership must model security behaviours.
  • Security should be seen as everyone's responsibility.
  • Simplifying reporting processes encourages engagement.
  • Fostering secure behaviour at home enhances workplace security.

Chapters:

00:00 - Understanding Human Behavior in Security

05:15 - The Role of Psychological Drivers

10:55 - Fostering a Security-First Mindset

17:32 - Bridging the Generational Gap in Security Awareness

25:30 - Building Trust and Responsibility in Security Culture

View Details

Hackers today rely on sophisticated techniques to collect information about their targets, combining digital stealth, social engineering, and data mining to get ahead. From scouring social media profiles to exploiting publicly available data, attackers gather intelligence that helps them pinpoint vulnerabilities and personalise attacks. Every detail—personal photos, company affiliations, online connections—can provide valuable clues for hackers, helping them craft realistic phishing attempts, exploit system weaknesses, or impersonate trusted contacts.

Understanding how hackers operate is the first line of defence in protecting your personal and business information. By exploring the methods hackers use, such as network reconnaissance, dark web monitoring, and social profiling, individuals and companies can recognise potential threats before they escalate. Awareness is power, and by knowing how hackers collect intelligence, you can adopt strategies to reduce your digital footprint, secure sensitive data, and stay one step ahead.

In this episode, Alejandro Leal, Analyst at KuppingerCole speaks to Arik Atar, Senior Threat Intelligence Researcher at Radware, about the increasing sophistication of attacks, especially during the holiday season.

Key Takeaways:

  • Threat actors are opportunists, targeting based on available information.
  • Social media is a significant source of personal information for attackers.
  • Holiday seasons see a spike in cyber attacks due to increased online activity.
  • Using separate emails for different services can minimise risk.
  • Regularly check privacy settings on social media and apps.
  • Avoid saving passwords in web browsers for better security.
  • Be cautious of seemingly legitimate offers that may involve stolen accounts.

Chapters:

00:00 - Understanding Threat Actors' Motivations

02:27 - The Role of Social Media in Cybersecurity

05:44 - Evolution of Threat Actor Behavior

09:32 - Anticipating Holiday Season Cyber Threats

12:52 - Future-Proofing Your Digital Security

View Details

As Chinese electric vehicles (EVs) rapidly gain market share across Europe, cybersecurity has become a key focus for regulators, manufacturers, and consumers alike. These advanced vehicles, packed with digital features and data-driven capabilities, also bring new cybersecurity challenges. With sophisticated connectivity features, onboard software, and data collection systems, the risk of cyber vulnerabilities is heightened, raising questions about data privacy, vehicle security, and the integrity of critical infrastructure.

The intersection of cybersecurity and the influx of Chinese EVs requires strict data protection standards, secure software protocols, and collaboration across the automotive and tech industries. European markets increasingly prioritise transparency and rigorous testing to ensure these vehicles meet robust cybersecurity standards. By addressing these challenges, Europe can continue to embrace the electric future with confidence, ensuring that cutting-edge technology goes hand-in-hand with safety and security for all.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Gianni Cuozzo, founder and CEO of Exein, about the evolution of the automotive industry, the competitive landscape shaped by Chinese manufacturers, and the cybersecurity risks associated with connected technologies in EVs

Key Takeaways:

  • EVs are fundamentally IoT systems on wheels.
  • The automotive industry has evolved from mechanical to digital to connected vehicles.
  • Chinese EVs are reshaping the competitive landscape in Europe.
  • The Cyber Resilience Act aims to enforce security standards for manufacturers.
  • Firmware updates can introduce new vulnerabilities post-certification.
  • The automotive supply chain must adhere to new security regulations.
  • Innovation in EVs must be balanced with robust security measures.

Chapters:

00:00 - Introduction to Cybersecurity and EVs

02:58 - The Evolution of the Automotive Industry

05:52 - Impact of Chinese EVs on European Market

09:06 - Cybersecurity Risks of Connected EVs

12:52 - The Cyber Resilience Act and Its Implications

17:03 - Navigating Innovation and Security in EVs

View Details

When it comes to decision-making, courage is paramount. Cybersecurity professionals must navigate high-stakes environments where swift, bold decisions can mean the difference between safeguarding critical assets and exposing vulnerabilities. This requires a willingness to act decisively, even under uncertainty, and to take calculated risks for the greater good of organizational security. Courage in this field isn’t just about individual bravery—it’s about fostering a culture where team members feel empowered to make tough calls, share unconventional insights, and drive proactive security measures.

Equally important in cybersecurity is the value of followership and resilience. Effective followership involves supporting leadership and strategic decisions, embracing a shared sense of responsibility, and prioritising team goals over individual recognition. With a combination of courageous leadership, strong followership, and resilience, organizations can build a cybersecurity posture that not only withstands attacks but continuously improves in the face of emerging threats.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks with Miguel Clark, a retired FBI special agent, about the nuances of leadership, particularly in high-pressure environments like law enforcement and the tech industry.

Key Takeaways:

  • Leadership is about placing others' needs above your own.
  • Followership is crucial for effective leadership.
  • Courage is developed by confronting fears.
  • Mistakes are opportunities for learning and growth.
  • Long-term organizational health requires valuing team contributions.
  • Effective communication is essential for leadership success.
  • Preparation for crises is key to resilience.
  • Building a culture of trust encourages open communication.
  • Perfectionism can hinder decision-making and progress.

Chapters:

00:00 - Introduction to Leadership and Followership

02:45 - The Transition from FBI to Tech Industry Leadership

06:36 - Understanding Followership in Leadership

09:59 - Courage and Fear in Decision Making

13:34 - Learning from Mistakes and Accountability

17:52 - Long-term Health of Organizations

21:39 - Communication and Understanding in Leadership

25:56 - Preparing for Cybersecurity Breaches

30:07 - Building a Culture of Trust

33:51 - Conclusion: Resilience in Cybersecurity

View Details

With cloud attacks rising, Cloud Detection and Response (CDR) is becoming a crucial focus in modern security operations. But what exactly is CDR, and how does it fit alongside other advanced security solutions like XDR? Just as Security Operations Centers (SOCs) defend the enterprise network, they now must extend their defences to the cloud, ensuring threats are detected and addressed in real time.

However, many organisations still rely heavily on Posture Management and "Shift Left" strategies to secure their cloud. While effective, these approaches leave gaps in protection, especially against modern attack methods. There's often an assumption that cloud security is entirely handled by the Cloud Service Provider (CSP), which leads to critical oversights.

Recent research reveals that traditional security measures often miss threats like runtime attacks and identity mismanagement. In this episode, Chris Steffen, EMA's Vice President of Research, speaks to Nathaniel "Q" Quist, Palo Alto's Cloud Threat Intelligence Manager, to discuss CDR and its benefits.

Key Takeaways:

  • Understanding the shared responsibility model is crucial for organisations.
  • Misconfigurations are a leading cause of cloud security breaches.
  • Ransomware attacks in the cloud behave differently than on-premises.
  • Identity access management is a primary target for attackers.
  • Visibility and telemetry are essential to effective security operations.
  • Hard-coded credentials pose significant risks in cloud environments.

Chapters

00:00 - Introduction to Cloud Detection and Response

02:56 - Understanding the Shared Responsibility Model

05:47 - Cloud Security Posture Management and Its Importance

09:07 - Real-World Scenarios in Cloud Security

11:53 - The Evolution of Cybersecurity Technologies

15:13 - Key Security Gaps in Cloud Environment

View Details

Ransomware attacks increasingly force organisations to pay ransom due to the significant impact on operations, data loss, and the fear of reputational damage. Semperis’s Ransomware Risk Report explores the reasons behind the high percentage of businesses making payments, which inadvertently encourages attackers to strike again. By giving in to demands, many companies fall into a dangerous cycle of repeated attacks, becoming easy targets for cybercriminals.

To mitigate this risk, it is critical to adopt an "assume breach" mindset. Organisations must be prepared for potential breaches by investing in robust recovery plans and strengthening cybersecurity measures, ensuring they can respond effectively without succumbing to ransom demands.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Simon Hodgkinson about the reasons behind the high percentage of organisations paying ransoms, the cycle of repeated attacks, and the critical importance of having robust recovery plans.

Key Takeaways:

  • Paying ransom does not guarantee recovery.
  • Business resilience is crucial during recovery.
  • Recovery plans must be robust and well-tested.
  • Identity management is a critical vulnerability.
  • Dedicated tools are necessary for identity recovery.
  • Recovery time objectives (RTO) need improvement.

Purple Knightis highlighted in the report as a key tool in detecting vulnerabilities before attackers can strike. With Purple Knight, organisations can proactively assess their defences, identify weak points, and strengthen recovery plans—helping to break the costly cycle of ransomware payments.

Chapters:

00:00 - Introduction to Ransomware and Its Impact

02:50 - Understanding the Ransom Payment Dilemma

06:03 - The Cycle of Repeated Attacks

08:55 - The Importance of Recovery Plans

12:05 - Identity Recovery and Its Challenges

14:51 - Best Practices for Ransomware Resilience

17:50 - Tools for Active Directory Recovery

21:03 - Conclusion and Key Takeaways

View Details

Companies are constantly pushing for innovation to stay competitive. Whether adopting new technologies or streamlining processes, innovation is key to growth. However, as businesses embrace digital transformation, they open themselves to new security vulnerabilities. These advancements can quickly become liabilities without proper protection, exposing companies to cyberattacks, data breaches, and other security threats.

Striking the right balance between innovation and security is essential for long-term success. Companies must prioritise cybersecurity alongside growth initiatives, ensuring that strong defences back every new technology or system.

In this episode, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks to Adeel Ahmad, Director of Technical Field Strategy at HashiCorp, and Grant Webb, Cloud Technologist, about the innovation paradox.

Key Takeaways:

  • The balance between innovation and security
  • How digital transformation introduces new vulnerabilities
  • Strategies for prioritizing cybersecurity alongside growth
  • Innovation is about change, while security is about safety.
  • Security should not be seen as a hindrance to innovation.
  • Embedding security in design can reduce friction.
  • Regulatory compliance can complicate the innovation process.
  • Shared objectives can align security and innovation efforts.
  • Building relationships between security and development teams is crucial.
  • CISOs should be integrated into the innovation process.

Chapters:

00:00 - The Innovation Paradox: An Introduction

02:53 - Balancing Innovation and Security

05:49 - Regulatory Challenges in Innovation

09:14 - Embedding Security in Organizational Culture

12:07 - Lessons from HashiCorp's Experience

14:58 - Building Relationships Between Security and Development

17:52 - Creative Approaches to Security and Productivity

View Details

Ransomware has become a pervasive threat, targeting organisations of all sizes and industries. The complexities of recovery after an attack are enormous, often involving extensive data restoration, system reconfiguration, and potential business disruptions. The financial toll, reputational damage, and operational downtime can be devastating.

AI can be a powerful tool in this battle that allows organisations to spot and prevent threats more effectively, analyse vast datasets for anomalies, and automate critical security tasks.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Jim McGann, VP of Strategic Partnerships at Index Engine, about Ransomware and its consequences.

Key Takeaways:

  • Ransomware continues to be a significant threat to organisations.
  • The complexity of IT infrastructure contributes to ransomware vulnerabilities.
  • User training is crucial in preventing ransomware attacks.
  • Recovery from ransomware can take months and cost billions.
  • Organisations often confuse disaster recovery with cyber recovery.
  • AI can help identify patterns of bad actor behaviour.
  • Validating data integrity is essential for effective recovery.
  • Many organisations lack a cyber resiliency strategy.
  • Ransomware actors often return to organisations that have paid ransoms.
  • A proactive recovery strategy is necessary for minimising impact.

Chapters:

00:00 Introduction to Ransomware Challenges

01:28 Understanding the Persistence of Ransomware

05:17 Complexities of Recovery After an Attack

10:57 The Role of AI in Cybersecurity

15:31 Real-World Applications of AI in Recovery

View Details

In this episode, Luke Dash, CEO of ISMS.online, speaks to Paulina Rios Maya, Head of Industry Relations, about the current state of information security, drawing on key findings from their latest report. The discussion emphasises the growing importance of compliance in the face of rising data breaches and supply chain vulnerabilities.

They explore artificial intelligence's dual role in cybersecurity, highlighting its potential to enhance defences and the increasing threat posed by AI-driven attacks like deep fakes. Luke stresses the need for businesses, especially in sensitive industries, to foster a culture of compliance and continuous improvement in cybersecurity measures to stay ahead of evolving risks.

Key Takeaways:

  • 99% of businesses faced fines for data breaches.
  • Supply chain attacks have increased by 22%.
  • Deepfakes are now a significant security threat.
  • A culture of compliance is essential for organisations.
  • ISO 27001 is crucial for information security management.
  • Cybersecurity should be part of daily business operations.
  • Continuous improvement is critical to effective security practices.

Chapters:

00:00 Introduction to Information Security and Compliance

01:21 Key Findings from the State of Information Security Report

03:10 Addressing Supply Chain Security Risks

05:57 The Role of AI in Cybersecurity

08:19 The Rise of Deepfakes and Their Impact

10:39 Building a Culture of Compliance in Organizations

12:36 Best Practices for Compliance in Sensitive Industries

15:27 Continuous Improvement in Cybersecurity Practices

View Details

Ethical hacking, or penetration testing, plays a key role in protecting businesses from cyber threats by identifying vulnerabilities before malicious hackers can exploit them. As AI becomes more embedded in critical operations, it becomes a prime target for cybercriminals. Ethical hackers are stepping up to defend these systems, using their skills to protect sensitive data, safeguard privacy, and ensure businesses stay secure and operational.

With the rise of AI-powered security tools, ethical hackers can analyse and respond to threats faster and more accurately than ever. However, the rapid advancement of AI also raises new challenges—automated systems can sometimes behave unpredictably, and new vulnerabilities may emerge.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Joseph Carson, Chief Security Scientist & Advisory CISO at Delinea, about the differences between superhero hackers, who use their skills for good, and villain hackers, who exploit vulnerabilities for malicious purposes.

Key Takeaways:

  • Hacking is a skillset and mindset, not inherently criminal.
  • There are two types of hackers: superheroes and villains.
  • AI is primarily used for defensive purposes in cybersecurity.
  • Data minimisation is essential for protecting user privacy.
  • Attackers are increasingly targeting individuals rather than systems.
  • Identity protection is a top priority in cybersecurity.
  • User-friendly security measures are necessary to enhance protection.

Chapters:

00:00 - Introduction to Ethical Hacking and AI's Impact

03:14 - The Dual Nature of Hackers: Heroes vs. Villains

06:33 - AI's Role in Cybersecurity: Opportunities and Threats

11:18 - Balancing User Privacy and Security

14:35 - The Role of Ethical Hackers in Cybersecurity

17:13 - Overlooked Vulnerabilities: The Human Element in Cybersecurity

View Details

Traditional security models are no longer enough. Identity and Zero Trust have become essential pillars of modern information security strategies. By focusing on “never trust, always verify,” Zero Trust ensures that no user or device is trusted by default—whether inside or outside the network—identity management, meanwhile, safeguards access by verifying who is accessing your systems and data.

Together, these approaches offer a more robust, adaptive defence against cyber threats, helping organisations protect sensitive information and mitigate risk.

In this episode of the EM360 Podcast, Chris Steffen, EMA's vice president of research, speaks to Ran Lampert, CEO and co-founder of Infinipoint, about the importance of identity when building your Zero Trust journey.

Key Takeaways:

  • Identity and device authentication are equally important in Zero Trust.
  • Compliance requirements increasingly demand device verification.
  • Quick wins in identity management can lead to immediate improvements.
  • Gradual implementation of security solutions is key to success.
  • Zero Trust is a continuous journey, not a one-time fix.
  • Integrating user and device authentication can reduce security risks.
  • The landscape of identity management is evolving rapidly.

Chapters:

00:00 - Introduction to Identity and Zero Trust

02:46 - The Evolving Landscape of Identity and Access Management

06:09 - Understanding Attack Vectors and Security Gaps

09:00 - Compliance and Regulatory Requirements

11:47 - Quick Wins in Identity and Access Management

View Details

Red teaming is a proactive cybersecurity approach where ethical hackers simulate real-world attacks to test an organisation’s defences. Unlike traditional testing, red teaming mimics sophisticated threats to expose vulnerabilities in networks, systems, and even human factors. This process helps organisations identify weaknesses, strengthen their security posture, and improve their incident response plans to stay ahead of evolving cyber threats.

An important aspect of red teaming is the interpersonal dynamics between the red team and the organisation’s internal teams. Collaboration and transparent communication are crucial to ensuring the exercise remains productive. Maintaining positive relationships during and after the tests fosters trust and encourages constructive feedback, essential for implementing security improvements without creating internal friction.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Gemma Moore, Co-founder and Director of Cyberis about the role of red teaming in developing detection and response capabilities.

Key Takeaways:

  • Red teaming involves testing people, processes, and technology.
  • Maintaining positive relationships is crucial during red team exercises.
  • Non-security stakeholders need actionable insights from red team outputs.
  • Informed consent is essential for ethical red team operations.
  • Respecting personal boundaries is important in red teaming.
  • Building relationships with blue teams fosters a collaborative environment.

Chapters:

00:00 - Introduction to Red Teaming and Cybersecurity

01:20 - Understanding Red Teams: Definition and Purpose

03:38 - Interpersonal Dynamics in Red Team Exercises

05:58 - Engaging Non-Security Stakeholders

08:43 - The Importance of Informed Consent

12:34 - Ethical Considerations in Red Teaming

17:44 - Developing Detection and Response Capabilities

20:53 - Conclusion and Resources for Further Learning

View Details

Protecting sensitive data requires a robust approach, with Data Security Posture Management (DSPM) and Data Loss Prevention (DLP) at the forefront. DSPM aligns security policies with data architecture, while DLP prevents unauthorised access and leaks.

Understanding data classification and custodianship is key to this, as it ensures that sensitive data is prioritised. Integrating AI further strengthens these strategies, offering real-time threat detection and automated protection.

In this episode, Chris Steffen VP of Research at EMA speaks to Shannon Murphy, Global Security & Risk Strategist at Trend Micro, to discuss data security management.

Key Takeaways:

  • Data Security Posture Management (DSPM) is essential for visibility.
  • Data classification is crucial for effective data security.
  • AI can enhance data discovery and classification processes.
  • Data custodianship should involve those who understand the data.
  • Continuous monitoring is necessary for effective data protection.
  • A layered defense approach is necessary against emerging threats.
  • Data security is an ongoing process, not a one-time fix.

Chapters:

00:00 - Introduction to Data Security Management

02:55 - Understanding DSPM vs DLP

06:12 - The Role of AI in Data Security

08:57 - Data Classification and Metadata

11:48 - Data Custodianship and Responsibility

15:11 - Creating a Culture of Security

17:57 - The Future of Data Security Strategies

View Details

Fraud networks are becoming more sophisticated, posing a significant threat to the financial, iGaming and crypto sectors. As fraudsters’ tactics evolve, these industries face growing challenges in identifying, disrupting, and preventing their activities.

According to Sumsub internal research, every 100th user was involved in fraudulent networks in 2023. The need for robust fraud detection and prevention, from financial institutions to crypto exchanges and online gaming platforms, has never been greater. Understanding the inner workings of fraud networks and how they evolve, is not just crucial but empowering for protecting assets and customers.

In this episode, Alvaro Garcia, Transaction Monitoring Technical Manager at Sumsub, speaks to Paulina Rios Maya, Head of Industry Relations at EM360, about how to Outsmart the Bad Guys.

Key Takeaways:

  • Fraud networks, or fraud rings, can vary in size and complexity.
  • Money mules are often unaware they are part of fraudulent schemes.
  • The iGaming industry is particularly vulnerable to bonus abuse.
  • A multi-layered approach is essential for effective fraud prevention.
  • Ongoing monitoring is crucial to catch fraud after onboarding.

Chapters
00:00 - Understanding Fraud Networks

05:17 - Money Muling and Its Impact

09:58 - Proactive Measures in Financial Sector

13:43 - Navigating Risks in the Crypto Sector

17:00 - Creative Tactics of Fraudsters

19:50 - The Role of AI in Fraud Detection

23:38 - Implementing a Multi-Layered Approach

View Details

New cybersecurity risks threaten critical data and systems as organisations increasingly adopt AI-driven technologies, particularly neural networks and Gen-AI. These advanced AI models, while powerful, are vulnerable to a range of attacks, including adversarial manipulation, data poisoning, and model inversion, where attackers can reverse-engineer sensitive data from the AI’s output. The complexity of neural networks often makes detecting and mitigating these risks difficult, leaving organisations exposed to potential breaches.

In this episode, Paulina Rios Maya, Head of Industry Relations, speaks to Peter Garraghan, co-founder and CEO (and CTO) of Mindgard, about the importance of understanding these risks, the hidden vulnerabilities in AI systems, and the best practices organisations should implement to ensure security hygiene.

Key Takeaways:

  • AI and generative AI introduce new and evolving cyber threats.
  • Understanding AI vulnerabilities is crucial for security teams.
  • AI risks manifest in ways that are different but not new.
  • Security teams must adapt their strategies to AI's opaqueness.
  • AI can be used as a vector for launching attacks.
  • Data leakage is a significant risk with AI systems.

Chapters

00:00 Introduction to Cybersecurity and AI Risks

05:13 Understanding AI Vulnerabilities and Cyber Threats

10:55 Industry-Specific Risks and Threats from AI

15:54 Best Practices for AI Security Hygiene

View Details

Traditional workforce access methods are increasingly vulnerable to account takeovers, highlighting the urgent need for zero-trust access.

Infinipoint addresses these vulnerabilities by offering one-click remediation for device security posture checks. This innovative solution ensures that only devices meeting strict security standards can access critical resources, thereby enhancing overall security.

In this episode, Paulina speaks with Ran Lampert, CEO and Co-founder of Infinipoint, about the weaknesses inherent in conventional access methods.

Key Takeaways:

  • Traditional workforce access is broken and vulnerable to account takeovers and phishing attacks.
  • Zero trust access, which combines user and device authentication, is key to defending sensitive data and resources.
  • InfiniPoint provides a solution that prevents MFA fatigue, phishing attacks, and vulnerable device access.
  • The platform offers one-click remediation for device security posture checks and allows enterprises to customise checks.

Chapters:

00:00 - Introduction and Background

03:22 - The Inception of InfiniPoint

04:46 - The Evolution of Access with COVID-19

08:07 - Vulnerable Devices and Exploitation

10:03 - The Importance of Device Authentication

11:02 - InfiniPoint's Approach to Secure Access

14:46 - Use Cases for InfiniPoint

18:36 - One-Click Remediation and Customization

20:00 - Frictionless Access and Future-Proofing

21:27 - Conclusion

View Details

As the number of connected devices grows, so does the vulnerability of our digital infrastructure. Traditional security measures need help to keep up with the increasingly sophisticated threats targeting critical networks in sectors like utilities and finance. To address these challenges, there is a pressing need for a new approach to Internet security that can create secure, isolated environments within the existing Internet infrastructure.

SCION offers a groundbreaking solution by upgrading the traditional border gateway protocol router, enabling the creation of isolation domains. These isolated networks enhance security by preventing unauthorised access and minimising potential points of failure. As more infrastructure providers adopt SCION, its possible applications in critical sectors promise everyone a safer, more resilient internet.

In this episode, Richard Stiennon, Senior Chief Research Analyst at IT-Harvest, speaks to Martin Bosshardt, CEO of Anapaya, about cyber breaches and solutions like SCION.

Key Takeaways:

  • The increasing number of connected devices and IoT is driving a rise in cyber breaches, making defence more challenging.
  • SCION offers a new approach to internet security by creating isolation domains within the existing internet infrastructure.
  • SCION allows for the secure and isolated operation of critical applications in sectors like utilities and finance.
  • The adoption of SCION by infrastructure providers and organisations holds the potential to significantly enhance internet security. By creating secure, isolated environments within the existing Internet infrastructure, SCION can effectively protect against nation-state attackers and other threats, making the internet a safer place for all.

Chapters:

00:00 - Introduction to IT Harvest and Anapaya

00:57 - Understanding Recent Cyber Breaches

02:23 - The Vulnerability of Connected Devices and IoT

03:45 - SCION: A New Approach to Internet Security

05:36 - Creating Isolation Domains with SCION

08:55 - Adoption of SCION and its Potential Applications

13:13 - Getting Started with SCION

15:09 - SCION vs. Other Solutions for Internet Security

17:05 - Conclusion and Call to Action

View Details

As cloud adoption accelerates, the demand for effective cloud threat detection solutions is snowballing. Organisations face increasing challenges in securing their cloud environments due to the complexity of modern infrastructures and cyber threats. Traditional security measures often fail to identify and respond to sophisticated cloud-based attacks, leaving businesses vulnerable to breaches, data loss, and service disruptions.

Skyhawk addresses these challenges with its cutting-edge autonomous purple team approach. By combining AI-based red teaming with continuous detection and response capabilities, Skyhawk’s solution proactively identifies and mitigates cloud threats before they cause harm. This advanced strategy ensures that organisations can maintain robust cloud security while keeping pace with the dynamic threat landscape, enabling faster, more effective threat responses with minimal manual intervention.

In this episode of the EM360 Podcast, Paulina Rios Maya, Head of Industry Relations at EM360Tech, speaks to Chen Burshan, CEO of Skyhawk Security, to discuss Cloud Threat Detection and Response and how proactivity is always better than reactivity.

Key Takeaways:

  • Cloud threat detection and response (CDR) solutions are in high demand due to the growing attack surface and non-patchable attacks in cloud environments.
  • The challenges of current CDR technologies include the overwhelming volume of alerts, the difficulty in analysing and correlating different indications of compromise, and the lack of automated response capabilities.
  • Skyhawk's CDR solution reduces noise and increases the accuracy of alerts by aggregating and correlating relevant indicators of compromise. It also enables proactive threat detection and response through simulated attacks and pre-verified automation.
  • Skyhawk's solution's advantages include reducing alert fatigue, increasing alert accuracy, enabling effective automation, and providing a proactive defense against potential attacks.

Chapters:

00:00 - Introduction and Overview of Skyhawk Security

01:51 - The Growing Demand for Cloud Threat Detection

04:10 - Challenges of Current CDR Technologies

06:01 - Skyhawk's Proactive Approach to Cloud Threat Detection

08:55 - Advantages of Skyhawk's CDR Solution

11:14 - The Time Machine Perspective and Pre-Verified Detection

13:03 - Utilizing Skyhawk's CDR Solution for Enhanced Cybersecurity

15:29 - Conclusion and Call to Action

View Details

Critical Start's Managed Detection and Response (MDR) service is designed to provide

24x7x365 monitoring, human-driven threat investigation, and flexible deployment across

IT and OT environments.

By leveraging deep technical expertise, robust API integrations, and contractual SLAs,

they offer comprehensive protection against evolving cyber threats.

Critical Start tackles attack vectors such as phishing, brute force attacks, and

vulnerability exploitation by combining advanced threat detection & response, incident

response, and proactive risk management.

These capabilities empower organizations to continuously map, monitor, and mitigate

threats, vulnerabilities, and risks—enhancing security posture.

In this episode, Paulina Rios Maya of EM360Tech interviews Tim Bandos, Field CISO

at Critical Start, about the skills needed for a SOC team and how an MDR provider

helps organizations reduce risks and improve cybersecurity resilience.

Key Takeaways:

  • Implement comprehensive monitoring and deep visibility into endpoints to enhance SOC capabilities.
  • Critical Start’s MDR service offers 24x7x365 monitoring, threat intelligence, and endpoint protection.
  • Ensure SOCs receive expected signals by monitoring endpoint security gaps and log ingestion failures
  • Leverage lessons from ongoing MDR operations by mapping telemetry to the MITRE ATT& CK® framework and deploying proactive mitigations to reduce long- term risk.

Chapters:

00:00 - Skills Needed for a SOC Team

05:05 - Deliverables of a Managed Detection and Response Service

07:21 - Common Entrance Vectors of Attack

10:37 - Proactive Defense Strategies

11:06 - Ensuring Expected Signals

12:31 - Endpoint Protection and Security Software

15:37 - Using Data and Lessons from MDR Operation

View Details

When looking for the right cybersecurity to keep your organization safe, it’s easy to get overwhelmed by the acronyms and solutions on the market today. EDR. MDR. XDR. NDR. How can organizations really identify not only what they need, but what solutions can evolve with their strategies?

In this episode of the EM360 Podcast, Chris Steffen, EMA's Vice President of Research, speaks to Kyle Falkenhagen, Secureworks’ Chief Product Officer, to discuss how organizations are investing in extended detection and response solutions as a comprehensive approach to cybersecurity.

Key Takeaways:

  • XDR (Extended Detection and Response) is a comprehensive approach that combines proactive risk reduction with reactive response. But not all solutions are equal, and it’s important to understand the distinction between basic and robust response.
  • Identity plays a critical role in cybersecurity, with many breaches having an identity component. Organizations should focus on securing their identity environment and detecting and responding to identity-based threats.
  • Balancing proactive security measures with traditional detection and response is vital for improving security posture. Organizations should look for security partners that can provide reactive and proactive capabilities.

Chapters:

00:00 - Introduction and Background

02:48 - The Role of Response in XDR

08:50 - Balancing Proactive Security and Detection & Response

11:03 - The Significance of Identity in Cybersecurity

18:51 - Integrating Threat and Exposure Data for Better Security Posture

23:23 - Conclusion

View Details

Understanding the key differences between approaches in the EU and the US can help unlock maximum value with the right security strategies. Traditional methods often fall short, but integrating Machine Learning (ML) into your security framework can transform your defence against modern threats.

Embrace a dynamic approach to security that adapts to evolving risk profiles. ML optimises your security investments and ensures that measures are tailored to specific threats, enhancing protection and efficiency.

In this episode of the Security Strategist, Chris Steffen, EMA's VP of research, speaks to Brady Harrison, Kount's Director of Customer Analytics Solution Delivery, to discuss maximising value through optimal security strategies.

Key Takeaways:

  • Finding a balance between fraud prevention and sales generation is crucial for optimising security strategies.
  • Machine learning can help businesses make informed, risk-based decisions by analysing large volumes of data in real-time.
  • Optimising security investments involves evaluating the cost-benefit trade-offs and setting appropriate risk thresholds.

Chapters:

00:00 - Introduction to the Security Strategist podcast

00:25 - Introduction to Kount and its focus on customer analytics and fraud prevention

01:49 - Differences between EU and US security strategies

05:12 - Balancing fraud prevention and sales conversion

08:59 - Optimizing security investments with machine learning

14:43 - Advantages of machine learning in security

18:31 - Setting security strategy based on machine learning

23:47 - Treating customers as good until proven otherwise

25:11 - Conclusion and call to action

View Details

In the post-pandemic world, relying solely on perimeter-based identity security is no longer sufficient. Increased cloud adoption, expanded access permissions, and the complexities of modern cloud environments have exposed vulnerabilities that traditional methods can't address. Issues like VPN weaknesses and inadequate security controls highlight the need for a new approach.

Explore the critical components of Zero Trust, including explicit verification, least privilege access, continuous monitoring, and adaptive policies. Discover how shifting to a Zero Trust framework can better protect your organisation in today’s complex and evolving landscape.

In this episode of The Security Strategist, Vivin Sathyan, Senior Technology Evangelist at ManageEngine, speaks to Alejandro Leal, Analyst at KuppingerCole, about why evolving your security strategy is essential for staying secure and resilient.

Key Takeaways:

  • A layered approach to user, application, device, and network security is crucial for comprehensive protection, reducing the overall attack surface and focusing on newer threats.
  • Common user vulnerabilities include weak authentication, insider threats, privilege escalation, misconfigured access controls, and unpatched vulnerabilities.
  • Organisations can better protect against these risks at the identity level by implementing risk assessment procedures, enforcing strong password policies, monitoring user behaviour for anomalies, and providing context-based employee training.

Chapters

00:00 Introduction and Challenges of Perimeter-Based Approach

05:09 Zero Trust: Critical Components and Differences

09:55 The Importance of a Layered Approach to Security

13:15 Common Vulnerabilities Associated with Users

18:04 Protecting Against Risks at the Identity Level

21:26 Translating the Zero Trust Philosophy into Actionable Steps with Managed Engine

View Details

Zero Trust architecture is a modern security approach that enhances protection by focusing on network segmentation and granular access control, moving away from traditional perimeter defences. This model helps prevent breaches and limits the spread of threats within a network.

While transitioning to Zero Trust can be challenging, it can be implemented gradually without disrupting existing systems. Future advancements may include a software bill of materials to verify the integrity of the code used within the network.

In this episode, William Malik, advisor at Lionfish Tech, speaks to Paulina Rios Maya, Head of Industry Relations at EM360, about Zero Trust architecture, security breaches and network segmentation.

Key Takeaways:

  • Zero Trust architecture eliminates the concept of a perimeter and focuses on network segmentation and granular access control.
  • Transitioning to the Zero Trust model can be done incrementally without disrupting the entire environment.
  • The future of Zero Trust security may involve implementing a software bill of materials to ensure the veracity of the code being used.

Chapters:

00:00 - Introduction to Zero Trust Architecture

02:23 - The Importance of Network Segmentation

04:45 - Transitioning to Zero Trust

13:25 - The Future of Zero Trust

View Details

Traditional manual testing done once a year to meet your compliance requirements is no longer sufficient. The threat landscape is changing at lightning speed, and your defenses need to keep up. That’s where automated network testing comes in! It’s like having a tactical SWAT team on standby, ready to spot exploitable vulnerabilities and provide you with remediation tactics whenever you need them.

You will be able to quickly uncover weaknesses before the bad guys can exploit them. These real-world attack simulations can be run on a weekly, monthly, or quarterly basis, giving you the upper hand in bolstering your security posture.

In our latest podcast, join Richard Stiennon, Chief Research Analyst at IT-Harvest, and Alton Johnson, Founder of Vonahi Security, as they dive into why automated network pen testing is the answer to securing your network against cyber threats year-round.

Key Takeaways:

  • Pen testing is an essential part of cybersecurity, helping organisations identify vulnerabilities and improve their security posture.
  • Automated network pen testing simplifies the process and makes it more affordable and accessible for MSPs and organisations.
  • The future of pen testing involves more automation and integration with AI, with pen testers focusing on coding and web app testing.

Chapters:00:00 - Introduction and Background

02:19 - Frustrations with Pen Testing Companies

07:04 - Simplifying Pen Testing for MSPs

13:39 - Acceptance of Automated Pen Testing

15:04 - The Future of Pen Testing

19:20 - Conclusion

View Details

In cybersecurity, manual processes such as using spreadsheets for application security are becoming increasingly inadequate. These traditional methods are time-consuming and error-prone and struggle to scale with the growing volume of threat sophistication.

Automation, particularly in Software Composition Analysis (SCA), is a beacon of hope in the face of these challenges. It brings relief by streamlining the identification and response to security threats, providing a more efficient and effective solution.

In this podcast, Chris Lindsey, application security evangelist for Mend.io., and Richard Stiennon, Chief Research Analyst at IT-Harvest, discuss how SCA tools can help identify vulnerabilities and the benefits of dependency automation.

Key Takeaways:

  • Manual processes in application security are inefficient and cannot keep up with the speed of innovation.
  • Upgrading dependencies is crucial to address security vulnerabilities and reduce security debt.

Chapters:

00:00 - Introduction and Background

02:23 - The Limitations of Manual Processes in Application Security

06:40 - The Role of Software Composition Analysis in Identifying Security Threats

10:02 - The Importance of Upgrading Dependencies in Application Security

13:44 - Integrating Automation into the CI/CD Pipeline for Application Security

21:05 - MEND.IO: Scalable and Comprehensive Security Solutions

View Details

Understanding Cybersecurity Compliance: PCI DSS 4.0, NIS2, and DORA Directives Explained

Compliance with cybersecurity standards is essential for any organisation to protect sensitive information, maintain customer trust, and mitigate the risks associated with data breaches and cyber threats. Adhering to recognized frameworks and regulations, not only safeguards the integrity, confidentiality, and availability of data but also demonstrates a proactive commitment to security best practices.

Join Chris Steffen and Uri Dorot, Senior Product Marketing Manager at Radware, as they delve into the critical aspects of compliance with cybersecurity standards.

Themes

  • Compliance
  • PCI DSS 4.0
  • NIS2
  • Dora

Chapters

00:00 - Introduction and Overview

02:20 - Complying with the Latest Cybersecurity Standards: PCI DSS 4.0

09:37 - Understanding and Implementing NIST 2: Enhancing Cybersecurity in the EU

19:28 - Preparing for DORA: Operational Resilience for Financial Organisations

23:08 - Conclusion and Key Takeaways

View Details

Who knew that improv could revolutionise your cybersecurity strategies? Imagine your team, prepared and ready, responding to threats with the quick wit and adaptability of seasoned improvisers!

Communication and collaboration are the secret sauce of robust cybersecurity. Improv supercharges team communication and cranks up problem-solving skills to eleven.

In this podcast, Jeremy Strozer, Artistic Director at Wild Atlantic Theatre, and Paulina Rios Maya, Head of Industry Relations, discuss how improv can become your secret weapon against cyber criminals.

Key Takeaways:

  • Improv techniques can enhance the adaptability of cybersecurity teams during incidents.
  • Communication and collaboration are critical in cybersecurity, and improv can improve team communication.

Chapters:

00:00 - Introduction

01:33 - Becoming Interested in Improv

03:00 - Using Improv in Strategic Planning

04:49 - Playing Out Scenarios

06:39 - Improving Communication in Teams

08:06 - Identifying and Mitigating Security Threats

09:02 - Conclusion

View Details

Podcasts are revolutionising how we raise awareness about cybersecurity.

They offer an interactive and engaging way to bring essential topics like AI, zero trust, and the human element into everyday conversations. By breaking down these complex issues into relatable and exciting discussions, podcasts make cybersecurity accessible and understandable to a broader audience.

In this podcast, Chris Steffen, VP of Research at EMA and Paulina Rios Maya, Head of Industry Relations at EM360Tech, discuss the transformative power of podcasts in the cybersecurity world.

Key Takeaways

  • Podcasts are a valuable tool for educating and engaging the cybersecurity industry.
  • Cybersecurity professionals should advocate for themselves and discuss cybersecurity in accessible and engaging formats.

Chapters

00:00 - Introduction and Launching the Podcast

03:17 - Advocating for Cybersecurity and Thought Leadership

07:03 - Exploring AI and Zero Trust in Cybersecurity

09:31 - The Human Factor in Cybersecurity

13:36 - Continuous Improvement in the Cybersecurity Industry

17:40 - Conclusion and Where to Find More

View Details

Integration and communication between Cloud Security and the Security Operations Center (SOC) is now a top priority for effective security. Cloud Security teams focus on securing cloud infrastructure, managing identity and access, and ensuring data protection, while SOC teams monitor, detect, and respond to threats in real time. Effective collaboration between these teams is crucial to addressing the unique challenges and dynamic threats seen increasingly today targeting cloud platforms.

Despite their shared goal of safeguarding organisational assets, Cloud Security and SOC teams often operate in silos, leading to communication gaps and inefficiencies. Bridging this gap requires unified strategies, shared tools, and streamlined processes that enable real-time information sharing and coordinated responses. By integrating Cloud Security with the SOC, organisations can enhance threat visibility, improve incident response times, and fortify their security posture.

In this episode of the EM360 Podcast, Brad LaPorte, Advisor at Lionfish Tech Advisors, speaks to Dan Flaherty, Senior Product Marketing Manager at Palo Alto Networks, to discuss:

  • The gap between cloud security and the SOC
  • The importance of prioritizing cloud visibility for the SOC
  • A platform approach for stronger cloud security

Chapters00:00 - Introduction and Background

01:10 - Organizational Disconnect: DevSecOps vs. SOC

23:59 - The Need for a Unified, Centralized Platform

27:45 - The Future of Cloud Security: Unified, Ubiquitous, and Uninterrupted

30:33 - Conclusion

View Details

Recent research shows that 86% of security leaders today do not have the tools they need to effectively prevent account takeovers. Organizations today are using more cloud applications than ever, and with the interconnected nature of the cloud, entry into one application can result in lateral movement to others—making the time to a breach faster than ever before. So how do we detect compromised accounts before it's too late?

Abnormal Security is expanding beyond email to provide full account takeover protection for some of today's most used applications: Salesforce, Dropbox, Workday, AWS, Azure and more. By understanding cross-platform human behavior, Abnormal AI can detect anomalous activity—remediating compromised accounts no matter where or how they originate.

In this episode of the EM360 Podcast, Mick Leach, Field CISO at Abnormal Security, speaks to Jeremy Strozer, Director, Agile U Strategies and Communications, to discuss:

  • Organizational application usage
  • Account takeover concerns
  • Security team limitations
  • Visibility and controls
  • Account takeover remediation

Chapters00:00 - Introduction

00:59 - Definition and Occurrence of Account Takeovers

05:33 - Exploiting Trusted Relationships

09:43 - Leveraging AI and Behavioral-Based Detection

12:29 - API Integration and Visibility

14:53 - Customized Models for Each Organization

20:25 - Future of Account Security

22:43 - Conclusion

View Details

Today, small businesses face significant challenges. Limited resources, tight budgets, time constraints, and inadequate training often leave them vulnerable. Hackers quickly exploit these weaknesses, targeting small and medium-sized businesses (SMBs) with sophisticated threats.

Managed Service Providers (MSPs) are tasked with the daunting responsibility of safeguarding diverse client environments, each with its own unique set of platforms and security needs. Traditional security measures often fall short against the ever-evolving tactics of cyber adversaries, putting both MSPs and their clients at risk. The next generation of cybersecurity detection and response solutions offers a path forward. Leveraging artificial intelligence and machine learning, these advanced tools can predict, identify, and mitigate threats in real time. This provides robust protection against the most sophisticated cyber threats.

By adopting cutting-edge technologies like Guardz, MSPs can enhance their security posture, ensuring comprehensive protection for their clients and staying ahead of cyber adversaries. Guardz's advanced capabilities simplify the complexities of cybersecurity, making it accessible and effective even for SMBs with limited resources.

In this episode of the EM360 Podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks to Dor Eisner, CEO and Co-founder of Guardz, to discuss:

  • MSPs
  • Security Infrastructure
  • AI in security infrastructure
  • Next-generation cybersecurity

Chapters00:00 - Introduction and Background of Guardz

02:36 - Challenges for MSPs in Cybersecurity

05:25 - The Unified Approach and Automation in Guards

07:18 - Guardz' Focus on MSPs and Small Businesses

08:14 - The Power of AI in Enhancing Guards' Offering

11:30 - The Impact of Guards on the MSP Space

13:21 - Securing Small Businesses and Compliance

18:07 - Marketing Support and Bringing Business to MSPs

19:02 - Conclusion and Call to Action

View Details

The 2024 Attack Intelligence Report thoroughly analyses the latest trends, tactics, and techniques used by cyber adversaries. This year's report highlights a significant increase in sophisticated attacks, including advanced persistent threats (APTs) and highly targeted ransomware campaigns. By leveraging the MITRE ATT&CK framework, the report offers valuable insights into the evolving threat landscape, helping organisations understand the strategies and methods employed by malicious actors.

Understanding the findings of the 2024 Attack Intelligence Report is not just crucial; it's empowering for businesses aiming to bolster their cybersecurity defences. The detailed breakdown of adversary behaviours equips security teams to proactively identify vulnerabilities, implement effective countermeasures, and develop robust incident response strategies. By staying informed about the latest attack patterns and techniques, organizations can better protect their assets, data, and reputation in an increasingly complex cyber threat environment.

In this episode of the EM360 Podcast, Jeremy Strozer, Geopolitical Strategist and Cyber Intelligence Analyst, speaks to Caitlin Condon, Director of Vulnerability Intelligence at Rapid7, to discuss:

  • 2024 Attack Intelligence Report
  • zero-day exploits
  • mass compromise events
  • network edge devices
  • multi-factor authentication

Chapters00:00 - Introduction and Background of the Report

01:39 - Key Findings: Prevalence of Zero-Day Exploits

06:15 - The Evolving Nature of Ransomware

08:31 - Importance of Multi-Factor Authentication

09:01 - Addressing Common Vulnerabilities for Better Security Practices

11:21 - Tackling the Security and Human Root Causes of Cyber Threats

13:13 - Conclusion and Call to Action

View Details

As artificial intelligence (AI) becomes increasingly integral to business operations, enterprises face new risks from Shadow AI—unauthorised or unmanaged AI tools and projects that bypass standard security protocols. The potential consequences of Shadow AI are severe, introducing vulnerabilities, compromising data integrity, and leading to compliance breaches, posing significant threats to the organization's overall security framework.

For C-level executives, understanding the impact of Shadow AI is not just crucial, but it's your responsibility to safeguard your enterprise's AI investments. Unauthorized AI projects can undermine strategic initiatives and expose the company to significant risks. By implementing comprehensive governance policies, strict access controls, and continuous monitoring, you can mitigate these risks effectively. Foster a culture of security awareness and ensure regular audits to maintain compliance and protect data integrity. Proactively addressing Shadow AI not only secures your AI assets but also aligns them with your business objectives, enhancing your competitive edge and ensuring sustainable growth.

In this episode of the EM360 Podcast, Chris Steffen, VP of Research at EMA speaks to Shannon Murphy, Global Security & Risk Strategist at Trend Micro, to discuss:

  • Shadow AI
  • C-level execs
  • Zero Trust
  • AI risk
  • Security strategies

Chapters00:00 - Introduction and Background

02:06 - Challenges of Shadow AI

03:00 - Visibility in Managing AI Risks

06:18 - Protecting Against AI-Driven Threats with Zero Trust

09:03 - Zero Trust as a Journey

13:17 - Talking to CISOs: Anecdotes Becoming Trends

19:14 - Emerging Use Cases for AI in SOC Teams

20:08 - Conclusion

View Details

The most dangerous cyber attacks today have one thing in common: they target humans rather than systems. Social engineering has been a prevalent tactic for years, with a known $51B in exposed losses over the last decade. Unfortunately, these numbers will continue to rise with the proliferation of AI, and your email inboxes are your most likely target.

Abnormal Security takes a different approach to email security, understanding human behavior to protect human vulnerabilities. By baselining known behavior, the platform can understand when anomalous activity occurs and block attacks—even when these threats are text-based emails with no traditional indicators of compromise.

In this episode of the EM360 Podcast, Chris Steffen VP of Research at EMA speaks to Leach, Field CISO at Abnormal Security, to discuss:

  • AI
  • Social Engineering
  • Human behavior
  • Security Culture

View Details

Hackers use AI tools like ChatGPT to enhance their operations and manipulate large language models. They infiltrate and attack GPT by manipulating the knowledge base through coordinated bot activity.

These sophisticated cybercriminals are not just using AI tools, they are leveraging them to streamline their attacks. By exploiting the model's natural language processing capabilities, they can craft convincing phishing emails, generate fake news articles, and even create highly realistic deepfake videos.

With the ability to mimic human speech patterns and convincingly generate text, these AI-enhanced attacks pose a significant and immediate challenge for cybersecurity professionals worldwide. As the arms race between hackers and defenders escalates, experts stress the urgent need for developing robust defences and staying vigilant against these evolving threats in the digital landscape.

In this episode of the EM360 Podcast, Alejandro Leal, Analyst at KuppingerCole speaks to Arik Atar, Senior Threat Intelligence Researcher at Radware, to discuss:

  • Hacker infiltration
  • GPT Capabilities
  • Operational needs
  • Hacker skill development

View Details

The trend of platformization in the Security Operations Centre (SOC) is a game-changer in the cybersecurity landscape. It offers a holistic approach to managing and mitigating security threats. By consolidating various security tools, processes, and data sources into a unified platform, organizations can streamline operations, reduce complexity, and significantly enhance overall security outcomes.

Platformization, as demonstrated by solutions like Palo Alto's XDR platform, is a powerful tool for SOC teams. It enables them to efficiently correlate and analyse vast amounts of security data in real-time, leading to quicker detection and response to threats. With advanced analytics, machine learning, and automation seamlessly integrated, platforms like XDR empower SOC analysts to focus on higher-value tasks, such as proactive threat hunting and strategic decision-making.

In this episode of the EM360 Podcast, Brad LaPorte, Advisor at Lionfish Tech Advisors, speaks to Dan Flaherty, Senior Product Marketing Manager at Palo Alto Networks, to discuss:

  • Why security tool consolidation is happening now
  • Platformization for the SOC
  • How to approach onboarding a platform like Palo Alto Networks Cortex XDR'

Interested in learning more about XDR and Palo Alto Networks? You can find some additional resources below:

  • Break free from legacy endpoint solutions
  • A Comprehensive Guide to the 2023 MITRE Engenuity ATT&CK Evaluations
  • Palo Alto Networks named a Leader by Gartner® for Cortex XDR.

Chapters 00:00 - Introduction * 01:39 - Defining Platformization and its Benefits * 08:16 - Downsides of Implementing Multiple Tools * 09:14 - Advantages of Platformization * 29:27 - Platformization as a Solution for Security Challenges * 31:24 -* Conclusion

View Details

The alarming rate of violence against healthcare workers underscores the urgent need for comprehensive security measures within medical facilities. As incidents continue to rise, it's imperative that proactive strategies are employed to safeguard the well-being of patients, visitors and staff.

In this episode of the EM360 Podcast, Paulina Rios Maya speaks to Sheila Cook, Chief Experience Officer at the University of Illinois Hospital & Health Science System and Clete Bourdeaux, Healthcare Business Development Director for HID’s workforce identity management unit, to discuss:

  • Workplace violence
  • Evolution of security protocols within medical facilities
  • Healthcare security

View Details

GenAI has revolutionized the landscape of information security. Once reserved for experts and Ph. D.s, it is now accessible to a broader spectrum of practitioners and engineers. Its applications span from summarising data to tailoring reports, amplifying incident response, and profiling user behaviours.

By harnessing the power of generative AI, security professionals can navigate complex datasets with enhanced efficiency and precision. The importance of continuously updating AI models with fresh data cannot be overstated. It is this constant evolution that ensures the relevance and efficacy of GenAI in the face of ever-changing security challenges. As GenAI continues to advance, it holds the promise of redefining the future of security operations, ushering in an era of proactive defence and adaptive strategies against emerging threats.

In this episode of the EM360 Podcast, Chris Steffen VP of Research at EMA speaks to Jimmy Astle, Senior Director of Detection Enablement at Red Canary, to discuss:

  • GenAI
  • Uses of GenAI
  • Training of AI
  • Automation in security operations

View Details

The sheer volume and diversity of data available to organisations today offer numerous opportunities for innovation, efficiency gains, and informed decision-making. However, this abundance of data also brings with it formidable challenges, particularly concerning privacy, security, and ethical considerations.

Data is often described as new oil, so safeguarding its integrity and protecting it from unauthorised access or misuse has become paramount. Data breaches and cyberattacks have become all too common, underscoring the critical need for robust security measures and vigilant oversight. Organisations can benefit from leveraging advanced cybersecurity solutions offered by platforms like Cyera to address these challenges.

In this episode of the EM360 Podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks to Emily Heath, General Partner of VC firm Cyberstarts and former CISO of United Airlines and DocuSign, to discuss:

  • Data security
  • CISOs and compliance
  • Data classification practices
  • Data classification and AI
  • The future of data security with AI

View Details

Gone are the days of merely safeguarding school computers! Censornet, a rising star in the tech industry, has undergone a remarkable transformation. From its roots as an internet security provider for educators, it has emerged as a trailblazing force in digital risk management.

Today, Censornet offers a comprehensive suite of tools designed to confront the dynamic challenges of the digital landscape, ensuring a safer and more secure online environment for all. This evolution stems from recognising that traditional threats are no longer the sole concern. With the proliferation of Shadow IT, unauthorised applications and devices, and the rise of insider threats, organisations face a complex array of risks.

In this episode of the EM360 Podcast, Jonathan Care, Advisor at Lionfish Tech Advisors, speaks to Gareth Lockwood, VP of Product at Censornet, to discuss:

  • Inspiration behind Censornet
  • Censornet’s Capabilities
  • Censornet’s Clients
  • Shadow-IT
  • Prevention of future vulnerabilities with AI and Censornet

View Details

Amid the ever-evolving landscape of cyber threats, organisations are constantly challenged to ensure security. Conventional security methods are failing to keep up with the escalating volume and sophistication of attacks. By implementing Managed Detection and Response (MDR) with automation, Security Operations Centers (SOCs) can optimise workflows, augment analyst capabilities, and significantly enhance the organisation's overall cybersecurity defences.

Palo Alto Networks offers comprehensive MDR services, leveraging its threat intelligence and cutting-edge technology expertise. Unit 42, its esteemed threat intelligence team, is crucial in providing valuable insights into emerging threats and trends, empowering organisations to stay ahead of malicious actors.

In this episode of the EM360 Podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks to Ophir Karako, Software Engineer (Unit 42) at Palo Alto Networks, to discuss:

  • Palo Alto’s MDR Services
  • Operational Automation
  • Data Enrichment
  • Threat Response
  • Job security for SOC Analysts

Interested in learning more about XSOAR and Palo Alto Networks? You can find some additional resources below:

  • Enloe Medical Center Strengthens Its Security Posture and Improves Efficiency With Unit 42 MDR
  • Unit 42 Managed Detection and Response Service Datasheet
  • A Practical Guide to Deploying SecOps Automation

Chapters00:00 - Introduction and Background

00:57 - MDR Services at Palo Alto Networks

03:20 - Automation in Operations

04:16 - Automating Data Enrichment

05:13 - Intellectual Property Playbooks and Scripts

05:41 - Customized Reports for Customers

06:10 - Automated Threat Response

07:08 - Insights and Lessons Learned from Automation

07:37 - Benefits of Automation for SOC Analysts

08:06 - Collaboration with Product Experts

09:04 - Treating Automation as a CI/CD Process

10:01 - The Future of Automation in Cybersecurity

12:51 - Automation and Job Security for SOC Analysts

14:20 - Cortex XSOAR: Security Orchestration, Automation, and Response Platform

15:46 - Unit 42 MDR Service

16:16 - Conclusion

View Details

The SolarWinds breach exposed vulnerabilities within DevSecOps practices, sending shockwaves through the tech world.

The U.S. Securities and Exchange Commission (SEC) indictment against SolarWinds further emphasised the gravity of the situation, alleging the company misled investors by failing to disclose these vulnerabilities and the subsequent breach adequately.

This lack of transparency raises crucial questions about accountability and risk management in the mobile app development landscape, pushing organisations to re-evaluate their DevSecOps practices and prioritise robust security measures throughout the entire development lifecycle.

In this episode of the EM360 Podcast, Head of Podcast Production Paulina Rios Maya speaks to Richard Stiennon, Chief Research Analyst at IT-Harvest, and Tom Tovar, CEO and Co-Creator of Appdome, to discuss:

  • The SolarWinds indictment
  • The U.S. SEC 4-day rule
  • The impact on DevSecOps practices
  • BYOD and VPN security
  • The evolving role of cybersecurity
  • Building cyber resilience

View Details

The fight against cybercrime is a never-ending battle. Firewalls and antivirus software, our traditional defences, are like trusty shields—good against basic attacks but not enough. Advanced attackers can slip through the cracks, exploiting new weaknesses or mimicking harmless traffic. Thus, businesses are exposed and face potential data breaches, financial ruin, and damaged reputations.

That's where Advanced Threat Intelligence (ATI) comes in – a game-changer in the cybersecurity arsenal. Unlike our old shields, ATI offers real-time intel on the latest threats, how attackers operate, and their ever-evolving tactics.

Recognising the limitations of traditional security solutions, Radware goes beyond basic shields. Imagine a high-powered watchtower constantly scanning the digital horizon, identifying threats before they strike.

In this episode of the EM360 Podcast, Analyst Jonathan Care speaks to Arik Atar, Senior Threat Intelligence Researcher at Radware, to discuss:

  • The Current Threat Landscape
  • Modern Attacker Tactics
  • Romance Scams & Pig Butchering
  • The Radware Advantage

View Details

The cloud revolutionised how businesses operate, but managing dynamic, complex environments presents new and unique challenges.

While digital transformation has brought significant benefits, the reality is that organisations now require innovative solutions to effectively navigate intricate, hybrid, multi-cloud environments.

Evolven Software, driven by a mission to simplify complexity and mitigate risk, empowers large organisations to overcome the challenges of governing extensive hybrid ecosystems. By harnessing the power of AI/ML, Evolven enables a more secure, streamlined, and efficient cloud journey with fewer outages or compliance gaps.

In this episode of the EM360 Podcast, industry veteran Tom Croll, advisor at Lionfish Tech Advisors, speaks to Sasha Gilenson, Founder and CEO of Evolven Software, to discuss:

  • The current state of enterprise cloud architectures and the challenges in managing hybrid multi-cloud environments.
  • Why managing risk in hybrid multi-cloud environments demands a new paradigm.
  • The unique challenges large organizations face in maintaining visibility, control, and governance across their landscapes.
  • How Evolven's AI/ML-driven solution empowers enterprises to overcome this complexity, enhance security, and optimize performance.

View Details

Automated Security Validation. Involving tools, scripts and platforms to emulate true-to-life attacks, Automated Security Validation is a key part of assessing the readiness of the security infrastructure and guiding prioritized remediation.

But how does this implementation of automation really work to empower human expertise? How does all of this relate to compliance? And what words of wisdom can be given for those looking to level up their security strategy in 2024?

In this episode of the EM360 Podcast, Analyst Jonathan Care speaks to Thomas Pore, Director of Product Marketing at Pentera, as they discuss:

  • The pen-testing landscape
  • How important testing and validating are
  • Empowering human expertise and remaining compliant

View Details

It seems like VPN products are consistently the initial access vectors for ransomware groups and targetted attacks.

This was demonstrated in the recent Ivanti Connect Secure zero-day vulnerabilities, as well as Cisco when they admitted last year that Akira Ransomware was specifically targeting their VPNs.

But what is the real problem with VPNs - and are they vulnerable by design? How do they fit into wider security architectures and strategies?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Benny Lakunishok, Co-Founder and CEO of Zero Networks, to discuss:

  • The problem with VPNs
  • ‘Insecure by default’?
  • ZTNA and remote access solutions

View Details

Rapid breach response. The art of quickly reacting to a security breach or incident. Key for minimising the impact of attacks and ensuring your team is as effective as possible, rapid breach response is an important part of any security strategy.

With the rise and innovation we see in the automation space right now, how could automation be implemented into a security strategy to level up the efficacy of rapid breach response?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Devin Johnstone, Security Operations Specialist at Palo Alto Networks, to discuss:

  • Demystifying rapid breach response
  • Implementing and leveraging automation in RBR
  • Advice for SOC teams and shifting mindset

View Details

The audit process is broken. CISOs and CTOs have faced a multitude of challenges under this outdated audit landscape, and the efficacy of companies are being stunted by a system that desperately needs updating.

But how can technology be leveraged to streamline or even transform that auditing process? And what does the future of infosecurity compliance look like?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Leith Khanafseh, Managing Director of Assurance and Compliance Products at Thoropass as they discuss:

  • The old audit landscape
  • Challenges for CISOs and CTOs
  • Multiframeworks and the future of compliance

View Details

In the world of complex supply chains, it’s not enough to secure our own data but also ensuring that third party vendors we work with have robust security.

When it comes to proactively stopping threats and mitigating issues, supply chain monitoring and ensuring a secure software supply chain is crucial to keep organizations’ data safe.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Rahul Sasi, Co-Founder and CEO at CloudSEK, to discuss:

  • Current state of cloud computing security
  • Common vulnerabilities in the software supply chain
  • Remote work, cloud reliance and mitigating risk

View Details

In 2024, the conventional approach of responding to threats is dead. As cyberspace becomes more complex, interconnected, and sophisticated, companies are beginning to recognise the shift from a reactive stance to a proactive one.

This shift isn’t just a technological upgrade - it’s a fundamental change in mindset that can cause ripples throughout the business.

In this episode of the EM360 Podcast, Analyst Jonathan Care speaks to Uri Dorot, Senior Product Marketing Manager at Radware as they discuss:

  • AI-powered attacks
  • Responsive protection vs proactive protection
  • How proactivity works in practice

View Details

Using threat intelligence effectively in incident investigation is crucial for identifying, mitigating, and preventing cybersecurity threats.

By integrating relevant threat intelligence feeds, security teams gain insights into the tactics, techniques, and procedures employed by malicious actors. This aids in swift detection and response to potential incidents.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Richa Priyanka, Solutions Architect at Palo Alto Networks, to discuss:

  • Role of threat hunting in SOC
  • Typical threat intelligence feeds for incident investigation
  • The future of threat hunting

View Details

Application security is a complex, wide-ranging field.

With attackers using a wide range of attacks from credential stuffing to cookie poisoning, how can you keep up with the ever-evolving landscape?

In this episode of the EM360 Podcast, Analyst Jonathan Care speaks to Uri Dorot, Senior Product Marketing Manager at Radware, to discuss:* Main challenges in protecting applications * Growing threat landscape * Consistent security across multi-cloud and hybrid environments

View Details

Doing more with less. The art of optimising your cybersecurity strategy and resources to achieve effective protection against cyber threats.

From assessing and prioritising assets to utilising open source tools, understaffed and overstretched cybersecurity teams are looking at ways to maximise what they’re able to do.

In this episode of the EM360 Podcast, Head of Content Matt Harris speaks to Chris Cochran, Advisory CISO and Chief Evangelist at Huntress, to discuss:

  • Doing more with less - and why that’s necessary
  • Equipping teams to be proactive
  • Cybersecurity challenges specific to healthcare industry

View Details

Securing Software as a Service (SaaS) applications is crucial to protect sensitive data, ensure user privacy, and maintain the overall integrity of the service.

From data encryption and identity management to network security and a solid incident response plan, there are some crucial things to consider when employing SaaS as a part of your workflow.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Guy Guzner, CEO and Co-Founder of Savvy Security, to discuss:

  • Security challenges with SaaS
  • Key worries from CISOs and CIOs
  • The problem with existing solutions today

View Details

Enabling the business to leverage data while preventing breaches are top priorities for CxOs and boards across industries.

However, data security has long relied on legacy architectures and outdated approaches that were developed to protect data on-premises.

By harnessing artificial intelligence and machine learning to automatically learn and holistically protect a company's unique data, new AI-powered data security platforms are revolutionising data security for the cloud era.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Roland Cloutier, the former Global Chief Security Officer of TikTok & ByteDance, to discuss:

  • Social media and data privacy conversation
  • Balancing leveraging data with preventing breaches
  • Intelligently harnessing AI and ML for your data strategy

View Details

No one knows how far gen AI can go in the enterprise but we know that it will be massive. Future platforms will certainly streamline and ensure efficiency, accuracy, and impact.

But there are many questions, including whether open source models perform as well as proprietary research? Will data compliance continue to be the main challenge the industry faces? What does the right to be forgotten mean in a world where gen AI exists?

In this episode of the EM360 Podcast, Analyst Richard Stiennon and Philippe Botteri, Partner at Accel, discuss:

  • The world of data security
  • Open source models vs proprietary research
  • Data compliance today

Accel is a proud partner of Cyera, read more below about how they're addressing the most pressing problems in cloud security.

View Details

Zero Trust is a security concept and framework that assumes no trust, even among users and systems inside the corporate network.

Traditionally, network security models operated under the assumption that everything inside the corporate network could be trusted and that once someone gained access to the network, they could be trusted to access various resources.

This is no longer viable in 2023 and beyond - with the increase of sophisticated cyber attacks, denying by default has become the norm for companies looking to secure their sensitive data.

In this episode of the EM360 Podcast, Analyst Richard Stiennon is joined by Benny Lakunishok, Co-Founder and CEO of Zero Networks to discuss:* What it means to have a true zero trust strategy * Zero trust challenges * MFA and the future of network security

View Details

XDR isn’t just a fancy term or the latest trend; it represents consolidating security tools, enhancing defences against sophisticated attacks, and reducing response time to safeguard against data breaches.

Starting from a solid foundation of centralized logs, organizations can use XDR as part of their cybersecurity strategy to detect breaches across many different sources of data.

If we look specifically at the financial industry, XDR can be key in stopping attacks rapidly before they cause too much damage. Through reducing complexity and providing stack-wide visibility, SMBs within the banking sector can solve common challenges like understaffed teams and daunting compliance requirements.

In this episode of the EM360 Podcast, Head of Content Matt Harris speaks to Matthew Warner, CTO and Co-founder of Blumira, to discuss: * Security pain points in the BFSI space * The difference between EDR and XDR * Choosing the right XDR strategy for your business

View Details

It’s officially the spooky season - but something scarier than ghosts, vampires and werewolves is striking fear into the hearts of cybersecurity leaders across the globe.

The unique challenges in the security space have been forcing industry leaders to switch up the ways they operate, specifically in the MSP space.

What does it mean to be a cybersecurity leader today? How have cyber attackers been changing their approach?

In this episode of the EM360 Podcast, Analyst Richard Stiennon is joined by Chris Cochran, Advisory CISO and Chief Evangelist at Huntress, to discuss:* Current state of cybersecurity leadership * Challenges faced by CISOs and IT Directors are facing * Cybersecurity horror stories

View Details

Rapidly accelerating technology advances, the recognized value of data, and increasing data literacy are changing what it means to be "data driven."

The ability to leverage data for day-to-day activities improves decision making, and fosters better innovation, collaboration, and communication.

With deep insight into the data they have, and the confidence that their data is secure, Cyera is enabling enterprises to leverage data to create truly differentiated customer and employee experiences.

In today’s episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Yotam Segev, CEO and Co-Founder at Cyera, to discuss:

  • Data security
  • Why this is still a challenge
  • Striking a balance between creating new steams

View Details

Monitoring cyber risk is essential in today's interconnected landscape. 

Involving continuous assessment of vulnerabilities, threat detection, and response readiness, companies should be looking at the best way to protect themselves.

But is offence really the best defence? Does a proactive stance provide more of a formidable cybersecurity posture than a reactive stance? And how are the brightest minds in security mastering the art of minimising damage and downtime?

In today’s episode of the EM360 Podcast, Analyst Dr. Eric Cole is joined by Michael Quattrochi, SVP of Defensive Security at CyberMaxx, to discuss:

  • Offence fueling defence
  • Monitoring cyber risk
  • Common exploitation trends

View Details

The aftermath of a cyber attack for a business can be devastating and may have significant short-term and long-term consequences. 

The extent of the impact will depend on the nature and severity of the attack, the level of preparedness of the business, and how quickly they can respond and recover.

But how can you recover from these cyber attacks? How are critical infrastructures being targeted? And what further complications can arise when systems are downed for extended periods of time?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Alex Yevtushenko, CEO at Salvador Technologies, to discuss:

  • The aftermath of a cyber attack
  • How critical infrastructures are being targeted
  • Consequences of long downtimes

View Details

A recent Gartner report stated that companies that implement CTEM (continuous threat exposure management) will be three times less likely to suffer from a breach. 

With the objective of CTEM being the achievement of a consistent, actionable security posture, why should you bring that into your brand protection strategy? Should a proactive approach be prioritised over a reactive approach? And how can CISOs implement this while ensuring they’re compliant with incoming regulations such as DORA?

In this episode of the EM360 Podcast, Head of Content Matt Harris speaks to Jorge Montiel, Head of Pre-Sales EMEA at Red Sift, to discuss: * Continuous threat exposure management * How CISOs should approach compliance * Proactive approach vs reactive approach

View Details

From ruthlessly targeting BFSIs to leaking the personal data of cancer patients, the horror stories that surround serious cybercrime are worse than ever before. 

Getting one step ahead of cyber attacks and becoming proactive with your cybersecurity is essential to keeping your company secure, and one way to do that is adopting a deny-by-default philosophy. 

But what is deny-by-default? What are CISOs worrying about most in this current landscape? And what lessons can be learned from assuming your enterprise has already been breached?

In this episode of the EM360 Podcast, Head of Content Matt Harris speaks to Rob Allen, VP of Operations EMEA at Threatlocker, about:* Zero Trust and a deny-by-default philosophy * Assuming that the attackers are already in * Dangers of data exfiltration

View Details

Earlier this year, Gartner predicted that companies that implement Continuous Threat Exposure Management, or CTEM, will have 3x fewer incidents year-on-year. 

Visibility is critical when it comes to cybersecurity, and a programmatic approach to that visibility should include CTEM in some capacity, according to SecurityIntelligence.

But how does CTEM actually work? What problems does it solve? And how can it be seamlessly brought into to an enterprise to helps CISOs prioritise initiatives and measure progress?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Rogier Fischer, Co-Founder and CEO at Hadrian, as they explore:* Continuous threat exposure management * Benchmarking an organisation's security posture * Solving the challenges that most CISOs face

View Details

Data exfiltration has become a serious issue for companies in today’s world.

The unauthorised removal and theft of company data are becoming more commonplace as cybercriminals become more sophisticated in their attacks. 

A good Data Loss Prevention, or DLP, strategy used to be enough to help protect the enterprise from malicious attacks, but has this changed? Is DLP dead?

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Darren Williams, CEO and Founder at Blackfog, as they discuss:

  • The current state of cybersecurity
  • How companies are struggling to protect their data
  • Differences between anti data exfiltration and DLP

View Details

Physical identity plays a crucial role in security. Through biometric authentication technology like facial recognition and iris reading to fingerprint reading, physical identity is used to verify who a person is. 

The use of physical identity is becoming more and more prevalent in public places, particularly in healthcare where patient safety and security is paramount. 

In this episode of the EM60 Podcast, Analyst Dr. Eric Cole speaks to Clete Bordeaux, Director of Healthcare Business Development at HID Global and Michael Ramstack, System Senior Director of Security from Essentia Health, about:

  • Security challenges in the healthcare industry
  • Physical identity priorities
  • Why visitor management works best as part of a multi-pronged approach

View Details

Small and medium-sized enterprises (SMEs) face numerous challenges when it comes to cybersecurity.

One of the most significant challenges is the lack of resources, including budget and personnel, to invest in robust cybersecurity measures. This often leaves SMEs vulnerable to cyber threats, such as phishing attacks, ransomware, and data breaches.

Additionally, SMEs may not have the expertise to effectively implement and manage cybersecurity solutions, leaving them susceptible to cyber-attacks.

This lack of attention to cybersecurity can lead to devastating consequences for SMEs, including financial losses, reputational damage, and legal liabilities.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Matthew Warner, CTO and Co-founder at Blumira, to discuss:

  • Common cybersecurity threats that SMEs face
  • How these threats differ from those faced by larger companies
  • Implementing effective cybersecurity measures

View Details

Supply chain attacks occur when hackers compromise a third-party vendor's software or hardware, which then infects the vendor's customers. Such attacks can be devastating, as they allow the attacker to gain access to the systems and data of many organisations.

To mitigate the risks of supply chain attacks, organisations should perform due diligence on their vendors, monitor their vendor's security practices, and implement strict access controls and network segmentation.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Uri Dorot, Senior Product Marketing Manager at Radware, to discuss:

Supply chain attacks from the client side

Traditional WAF vs server protections vs client side protections

Deployment experiences

View Details

Incident response is the action taken to detect, triage, analyse, and remediate problems in software with the ultimate goal of minimising damage and restoring normal business functionality as quickly as possible. 

A well-executed incident response plan can help organisations mitigate the impact of security incidents and maintain the trust of their customers and stakeholders, but how specifically can the efficacy of an incident response program be assessed?

In this episode of the EM360 Podcast, RedMonk analyst Kate Holterhoff spoke to Fred Hebert, Staff Site Reliability Engineer at Honeycomb, as they explore:

  • Why some metrics are better than others
  • Lessons we learn from fighting forest fires
  • Incident response methodology

View Details

Machine identity is an essential part of ensuring companies maintain a good level of data security and structural integrity. 

The management of digital certificates and keys allows all internal traffic to be encrypted, seriously narrowing the attack surface of an enterprise. 

In this episode of the EM360 Podcast, Editor Matt Harris speaks to Chris Hickman, Chief Security Officer at Keyfactor, to discuss:

  • Where machine identity trends are heading
  • Why companies are paying more attention to machine identity
  • Identity as a single thread

View Details

Bot mitigation helps enterprises to identify and block unwanted bot traffic as it hits your network.

And with half of all internet traffic coming from bots (both good ones and bad ones), managing that bot traffic is critical. 

Financial institutions, ticket-selling sites and shopping sites are among the hardest hit, with cybercriminals employing ML and AI in these bots to scale the size of their crimes and ambitions.

In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to Uri Dorot, Senior Product Marketing Manager at Radware, to discuss:

  • The world of application protection
  • Why companies are underequipped to deal with bot attacks
  • Dedicated bot mitigation solutions

View Details

Data privacy. The ever-changing landscape of collecting and sharing personal data is complex, with attitudes and regulations constantly being updated.  So what’s happening in politics right now that could affect ¾ of the world’s data privacy rights? How are consumers reacting to all this? And why are customers struggling so much with compliance? In this episode of the EM360 Podcast, Editor https://em360tech.com/user/3673 (Matt Harris) speaks to https://www.linkedin.com/in/neilkentjones?miniProfileUrn=urn%3Ali%3Afs_miniProfile%3AACoAAAF_qwQBn7MMrVCmHZygyh-W2l9qeLIDnmk&lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_all%3BGNhzmhF0QJWdfxRAV9A5Uw%3D%3D (Neil Jones), Director of Cybersecurity Evangelism at https://em360tech.com/solution-providers/egnyte (Egnyte), to discuss:  Data privacy in US vs. UK How current events affect companies How the landscape will look in 10 years' time

View Details

A software supply chain attack is when someone infiltrates your system by attacking a third-party provider or partner with access to your data.  Recent high-profile supply chain attacks, most notably SolarWinds, has this type of attack into the public eye, and it’s clear that with more suppliers handling sensitive data than ever before, the attack surface of a typical enterprise has been changed dramatically.  In this episode of the EM360 Podcast, Analyst https://em360tech.com/user/3627 (Richard Stiennon) speaks to https://www.linkedin.com/in/suresh-bhandarkar-36277895/ (Suresh Bhandarkar), Director of Product Solution Architecture at https://em360tech.com/solution-providers/beyond-identity (Beyond Identity), to discuss: Software supply chain attacks Weaknesses in the CI/CD pipeline The issue of software code provenance

Beyond Identity cuts through the anonymity of to provide a secure, scalable way for development and GitOps teams to immutably sign and verify the author of every commit. Their author verification API in proves that what you’ve shipped is what your developers actually built—and that nothing else got added.

View Details

Identity Governance and Administration (IGA) systems are a fundamental part of an enterprises identity and access management strategy.  For companies that need functionalities like role-based access and automated approval, IGA systems can be essential in ensuring that the right people are getting access to the right things.  Sounds easy enough, but issues with adoption, sponsorship and employee access speak to the fact that plenty of things can derail a deployment.  In this episode of the EM360 Podcast, Analyst https://em360tech.com/user/3627 (Richard Stiennon) speaks to https://www.linkedin.com/in/rodlsimmons/ (Rod Simmons), VP of Product Strategy at https://em360tech.com/tech-index/omada (Omada), about: Automating already broken processes Disconnect between IGA goals and business goals Testing, testing, testing

View Details

Authentication is the art of determining whether something is what it says it is. Passwords provide a great way for customers and consumers to access their personal information but when it comes to the enterprise, newer concepts like two-factor authentication (2FA) and zero trust network access (ZTNA) may be required.  It’s been part of computing since its inception two decades ago - yet IT teams and businesses are still putting a lot of time into it. So why is authentication still such an issue?In this episode of the EM360 Podcast, Analyst Richard Stiennon speaks to https://www.linkedin.com/in/matthewlewis33/ (Matthew Lewis), Director of Product Marketing at https://em360tech.com/solution-providers/hid-global (HID Global), to explore: How the work from home movement impacted employee authentication “Passwordless” vs client-side certificates Adaptive authentication

View Details

In this podcast, Chris Steffen, Research Director at Enterprise Management Associates (EMA), joins Mark Alba, Chief Product and Strategy Officer at Anomali, to explore the ins and outs of extended detection and response (XDR) and MITRE ATT&CK framework, including how it integrates with threat intelligence and enterprise security strategies.

View Details

Attack surface management is the sustained monitoring, classifying, and inventory of a businesses IT infrastructure. It sounds as simple as asset management, but ASM is different in the way it approaches these responsibilities from an attacker’s perspective. The security of an enterprise's surface is paramount in the current era of cloud - but how can companies manage their cloud security posture management and tackle basic misconfigurations? In this episode of the EM360 Podcast, Chief Research Analyst at IT-Harvest Richard Stiennon speaks to David SooHoo, Director of Product Management at Censys, as the pair discuss:  Attack surface management vs asset management The shift of the cloud Zero-day attacks and how to mitigate them

View Details

Businesses today are under increasing pressure to level up data security as ransomware and data theft continue to rise. Data-first security solutions provide businesses with next-generation protection against exfiltration while maintaining accessibility for day-to-day operations, even during an attack. In this episode of the EM360 Podcast, https://www.linkedin.com/in/dr-eric-cole-92a164211/ (Dr. Eric Cole), CEO and Founder at https://secure-anchor.com/ (Secure Anchor Consulting) speaks to https://www.linkedin.com/in/paul-lewis-17ba987/ (Paul Lewis), CEO of https://calamu.com/ (Calamu), about: Today’s biggest threats to data The problem of data exfiltration How a data-first security approach provides next-generation protection

View Details

The Nature of Cybersecurity is undergoing rapid evolution. Cyber attacks are becoming more violent - and sophisticated. Big developments in tech over the last few years have led to some of the most shocking ransomware incidents. Are IT teams capable of keeping up, or are we leading towards cyber doomsday? In this episode of the EM360 podcast, Chief Research Analyst at IT-Harvest, Richard Stiennon speaks to Mariana Periera, Director of Email Security Products at Darktrace, to explore: How businesses can come back stronger following a threat The email supply chain and how attackers are using legitimate credentials to attack Core capabilities and the importance of augmenting with AI The true changing nature of cybersecurity

View Details

In 2021, more than half of all widespread threats began with a zero-day exploit that was targetted by threat actors before vendors could even make patches available.  With security teams now being put under immense pressure, what can organisations do to help secure their online presence against modern cyber threats? In this episode of the EM360 podcast, Content Producer Matt Harris talks to Caitlin Condon, Vulnerability Research Manager at Rapid7, as they explore:  How security teams can respond to threats more swiftly and effectively Remote working’s effect on company weakpoints How enterprises can better understand and remediate high-priority threats

View Details

When it comes to cybercrime and cybersecurity threats, social engineering attacks are unique in the way that they rely on human error versus software and operating system vulnerabilities.  This is because as technological defenses become more and more robust, cybercriminals are increasingly targeting the weakest link in the chain: people.  Using a variety of means both online and offline, unsuspecting users can be conned into compromising their security, releasing sensitive information or even transferring money.  Secureworks Adversary Group, a security consulting department within Secureworks, walk-us through various social engineering scenarios used during their attack simulations. In the third episode of this three-part podcast with Secureworks, our host Dr Eric Cole the Founder and CEO of Secure Anchor Consulting will be talking with Ben Jacob, Technical Lead at Secureworks, about: Social engineering attack techniques and their lifecycle How phishing, vishing, and spear-phishing impact industries from a social engineering standpoint What can companies offer from a training and education standpoint to help mitigate these risks Value of XDR in detecting suspicious user behaviour

View Details

Cyber insurance helps to provide critical cover for those who need protection against digital threats. While businesses are responsible for their own cybersecurity, liability coverage can help provide crucial support to help them stay afloat when the worst happens. This includes the costs of investigating a cybercrime, recovering lost data and restoring of the systems. It can even recoup the loss of income, manage reputation, and notification costs if required to notify a third party. In this third episode of a three-part series with Sophos, Senior Director Nicholas Cramer talks to Dr Eric Cole CEO and Founder of Secure Anchor Consulting about: The current state of cyber insurance Difficulty in getting policies How to better position your EDR and MDR

View Details

Cyber risk intelligence is critical for businesses that operate in the digital world. It is the collection, evaluation, and analysis of cyber threat information by those with access to all-source information. Like other areas of important business intelligence, cyber threat intelligence is qualitative information put into action to help develop security strategies and aid in identifying threats and opportunities. In the episode of the EM360 podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, speaks to Caitlin Gruenberg Director, Risk Solutions Engineer at CyberGRX as the pair explore: Third-party cyber risk management vs self-assessments Cyber risk intelligence in the wake of huge, high-profile breaches The meaning of a true risk exchange

View Details

CIAM enables organisations to securely capture and manage customer identity and profile data, as well as control customer access to certain applications and services. Usually providing a variety of features including customer registration, self-service account management, and 2FA/MFA, the best CIAM solutions ensure a secure and seamless customer experience. But how can enterprises hit a balance between security and customer friction? In the first of two EM360 analyst podcasts with Beyond Identity, Chief Research Analyst at IT-Harvest, Richard Stiennon speaks to Jing Gu, Senior Product Marketing Manager, about the role CIAMs play when it comes to managing end-user activities.

View Details

Andy Ramgobin, Principal Technology Evangelist at Technimove, talks about the Science of Cyber Security & Cyber Resiliency Periodic Table and how enterprises can fully understand the digital threat landscape

View Details

In this podcast, Richard Stiennon, Chief Research Analyst at IT-Harvest, joins Mackenzie Jackson, Developer Advocate at GitGuardian, to explore Secrets Sprawl or the phenomenon of (unwanted) secrets distribution across Git repositories and DevOps tools.

View Details

Testing application security challenges is essential to ensure that we are moving forward with cybersecurity technology, however many organisations are still unable to identify the key challenges within their infrastructure. As with most facets of life, many organisations are still rooted in traditional attitudes; they previously invested in one approach to security and they are skeptical of rocking the formula.  IT environments have, however, evolved dramatically over the last decade and organisations have moved beyond cloud migration programs and are now overhauling their applications in cloud-native ecosystems. These changes have led to strives in innovation, while also leaving space for vulnerabilities. This is where organisations need to start testing application security and building a more robust framework to protect their applications. In this podcast, Head of Content Max Kurton talks to Andreas Lehofer, Chief Product Officer at Dynatrace. Andreas runs us through: How to get a transparent view of application security How to avoid consistent, distracting security alerts The rate of evolution of IT environments in 2022.

View Details

Ensuring quality automotive products in the age of cyber crime is becoming harder and harder due to the amount of endpoints that can easily be compromised within the supply chain. Regardless of where you sit within an organisation, with the increase of hybrid working and remote work, risks of ransomware still remain at large. CyberAngel recently released a report that stated that there are vulnerabilities in Ford, Volkswagen, and Tesla Advanced Driver Systems. Furthermore, a semiconductor shortage has made profit tighter and production more difficult. If that's the case, how can we know that the products are truly reflective of quality automotive standard? What vulnerabilities in their supply chains will end up affecting the consumer and how stable are the companies that are producing quality automotive vehicles? According to this same report, 1 in 10 employees have exposed publicly accessible credentials available online. Joining us on this episode of The Next Phase of Cybersecurity is Pauline Losson, Cyber Operations Director at CybelAngel. In this episode, we will be exploring topics such as: Why automotive industries in particular are vulnerable to leaked credentials How you can ensure a strong cybersecurity strategy within your organisation The best way to prevent credentials from being leaked online The trends across North America and Western Europe.

You can also find this podcast on Spotify and Apple Podcasts under "The Next Phase of Cybersecurity."

View Details

Year on year, cybercriminals are expanding their attack toolkits and coming up with different ways to cause disruption across the enterprise. However, according to cybersecurity experts, deceptive technology can be used to effectively intercept these crimes.  Investigating this destructive attack vector in this week's episode of the Next Phase of Cybersecurity is Carolyn Crandall, Chief Security Advocate at Attivo Networks. Carolyn was first featured on the EM360 Podcast to talk about deception technology and its ability to turn the table on attackers. This time, she is here to set out how to disrupt attackers' toolkits and ultimately render them powerless.

View Details

Within any sector, the automation of processes comes with technological, social and skill-gap orientated challenges, but cybersecurity really takes the cookie. The adoption of automation has certainly been widespread, with 95% of correspondents stating that they have automated some of their processes, but it always comes with challenges. According to a report by ThreatQuotient, only 8% of correspondents had not encountered any problems when automating their cybersecurity processes. If cybersecurity automation is proving to be so flawed, why should organisations adopt it as a methodology? Improving the Automation of Processes Within CybersecurityWithin cybersecurity, the automation of processes provides technologies with a mind of their own, allowing them to intercept problems without having to rely on the variables that humans are usually compromised by. Beyond this, adversaries themselves often use automation as a way to hack into endpoints. In order to keep up with the pace of adversarial technologies and approaches, organisations are going to have to fight fire with fire. When you adjust your cybersecurity approach to include the automation of processes, cybersecurity technologies ramp up their speed in dealing with these issues. Becoming faster, and inevitably more furious, is ultimately the primary goal of threat interception. How do senior-level professionals feel about cybersecurity automation?While the vast majority of senior-level security professionals (77%) believe that automation is important, that same 23% are still struggling to see the benefits it would bring. This makes the automation of processes a rather difficult task for many entry-mid-level employees that have a stronger understanding of what will benefit their business. That said, the vast majority of  experts who are automating have strategic reasons for doing so. 34% of correspondents, for instance, stating that automation was essential for improving or maintaining security standards while 31% implemented it to improve efficiency and productivity.  In this episode of The Next Phase of Cybersecurity, Leon Ward, VP of Product Management at ThreatQuotient, walks us through the best way to overcome the technological challenges of implementing automation, the types of processes that are being automated in 2021 and why there is a lack of trust in STEM in the current digital landscape.

View Details

Building your career and starting a cybersecurity job comes with its perks, but it of course comes with its difficulties and shortcomings. Some people cite that the career can often result in low pay based on the amount of labour that's put in, while others find the career attractive but are unsure at what level to start with. One of the biggest problems facing organisations today is the lack of cybersecurity professionals available, and it absolutely could be to do with the drawbacks of having a cybersecurity job. There are other arguments to be made, however, most notably that the cybersecurity field changes with every month. New adversarial technologies and approaches plague organisations, and having someone that is fully equipped and trained to deal with these challenges is a nightmare.  According to The New York Times, there will be over 3.5 million unfilled cybersecurity jobs by the end of 2021, so what can be done about it? Joining us in this podcast are Samantha Humphries, Head of EMEA Marketing and Security Strategy at Exabeam, and Phil Jackman, Director of Dynamo North East. They will be exploring the necessities of networking for cybersecurity professionals, the steps that need to be taken to encourage more cybersecurity professionals and the difficulties facing the career today.

View Details

Implementing the best software security practices in 2021 is an absolute minefield when there are varying different softwares and technologies that all seem to be promising the same thing. For many application developers, the use of open-source libraries grants them greater freedom when developing their apps but simultaneously leaves them vulnerable. Application security remains a corner stone of the app development world, but so few developers take it as seriously as they should.  In a recent open-source edition of Veracode's State of Software Security Report, it was revealed that a shocking 70% of applications have a security flaw in an open source library on initial scan. Beyond this being a flaw within some open source software, one of the most striking statistics is that ‘79% of the time, developers never update third-party libraries after including them in a codebase'. This calls for stronger security within application security, but what steps can developers take in order to ensure the longevity of application security? In this podcast, we speak to John Smith, Manager, Solutions Architect, EMEA and APAC at Veracode. John takes us through some of the findings from this report, the vulnerabilities within open source software, the needed steps to improve application security and what awaits in the future.

View Details

Since the Facebook-Cambridge Analytica data scandal of 2018, the populous has become so accustomed to data mismanagement and even data leaks that it no longer makes the headlines. In fact, even in 2021 Facebook faced scrutiny for a data leak that revealed over 530 million people's private information, in some cases including phone numbers. Of course, legal action has been taken by individual bodies but, as many experts point out, tech giants such as Facebook and Google have the monetary capacity to hire complex legal teams that allow them to navigate around GDPR and other data violations. Data leaks are now being normalised, which causes more risk to both individuals and even organisations. The latest development comes under the bracket of 'data scraping'; a controversial topic in the technology industry. Data scraping is, in its essence, a technique that allows a computer to extract data from an output that's generated by another program. Now, data scraping in its core form is not necessarily harmful but the risk of leaks that occur from data scraping, or the purpose of data scraping, raises a lot of questions. Joining us in this episode of The Next Phase of Cybersecurity is Derek Taylor, Lead Principal Security Consultant at Trustwave. In this podcast, we explore some of the reasons why data scraping is so alarming to cybersecurity experts, how user's privacy calculus around data disclosure decisions are being manipulated, the 'privacy paradox' and reversing the normalisation of data leaks.

View Details

Cybersecurity has revolved around several different methodologies over the last decade, but the arguments for and against using an approach based on "Indicators of Compromise" remain prevalent to this day. Relying on the top indicators of compromise, or IOC, depends upon finding threats as and when they appear. New methodologies incorporate a slightly more anticipatory model, however; Indicators of Behaviour, or IOB, work to understand the common signs that could potentially lead an organisation to be struck by a cyber attack. Having a firm understanding of these topics is essential for any CISO or anyone involved in the security field, however it can be time consuming. That's why, on this episode of The Next Phase of Cybersecurity, we have interviewed https://www.linkedin.com/in/richardwuk/ (Richard Walters,) CTO at https://www.censornet.com/ (Censornet). Using his expertise, Richard walks us through the detailed differences between IOB and IOC, the ROI organisations could see from implementing an IOB based approach and how to implement the switch from IOC to IOB. 

View Details

When it comes to using a cybersecurity product, relying on new technology has often been seen as the primary objective. What cybersecurity experts are starting to realise, however, is that technology by itself has limitations; the perfect combination actually comes from having good technology and skilled professionals who know how to use it. Many security technologies rely on an alert basis; a method that notifies professionals to investigate problems as and when they appear. The problem with this is that, according to Arctic Wolf, 44% of security alerts are actually not investigated.  What cybersecurity solutions do I need to know about? Threat hunting is, as our guest today points out, the method of "proactively identifying malicious activities or security concerns within an organisation." This means that malicious activities could have previously been detected or maybe the hunter is looking for threats before they have even made their first appearance. In fact, the method of being anticipatory when it comes to cybersecurity has always proved to be more effective than being reactionary.  Our guest today is Christopher Fielder, Director of Product Marketing at Arctic Wolf. Christopher takes us through the steps of incorporating threat detection in your organisation, what the fundamental misconceptions are about threat hunting and how it can save your business more than it costs. 

View Details

From the usage of anti-money laundering software all the way to endpoint security, the enterprise space is always preparing for the next attack. Recognising the fact that as much as you train and prepare your organisation, adversaries will also continue to advance can be anxiety inducing. Yes, organisations lose billions every year to fraud and the beginning of 2021 was met with a huge influx in cybercrime, but it's the methods that the adversaries are using that is truly concerning. 

Social engineering is a method used by adversaries in the cyberspace that works by gaining the trust of their target. By impersonating a colleague, bribing or blackmailing the victim or even just assuming the voice of an authoritative figure, adversaries are coercing employees into cooperating and, potentially, into wiring money to them. It's psychological warfare and it's not slowing down; social engineering attacks make up 98% of attacks every year, so what can you do to prevent it?

Educating us in this episode of The Next Phase of Cybersecurity is Greg Hancell, Senior Manager Fraud Consultancy a OneSpan. Greg details to us the use of automation in fraud operations, how AI is saving banks and what current methods an adversary might use in conducting a social engineering attack.

View Details

As businesses become more complex it opens up numerous issues that need to be accounted for including business processes, critical business and IT functions, and third-party relationships. These factors can be hard to coordinate across departments and this lack of visibility makes it difficult to prove and report that continuity and recovery plans are in place and will work as intended. Resiliency programs allow for a proactive approach in order to address and mitigate resiliency risk to your organisation. Resiliency requires building processes and technologies that naturally adapt to adverse conditions, make mid-course corrections, and avoid any negative impacts of disruption. In this podcast, Ben Tuckwell, UK District Director at RSA Security talks about building business resiliency. To begin with, Ben explains how organisations can ensure they have optimal business continuity and processes in place. Furthermore, he explains how organisations should approach a business impact analysis to understand what is happening. Also, Ben outlines how to monitor third party ecosystems to manage related security, access, compliance, and resiliency risks. Finally, he talks about how to conduct risk assessments for understanding a vendor’s residual risk and reducing it.

View Details

The need to adapt corporate IT systems to support more flexible working is not new. The response of businesses to these trends over the last two decades has been on a spectrum from highly supportive – as much flexibility as possible – to highly conservative – the risks are too great. These risks, that have held many businesses back, include the loss of control over what employees are doing and who they are interacting with, to the danger of corporate and controlled personal data getting into the wrong hands. Since the forced lockdown even the most conservative businesses have recognised the benefits of homeworking for both employees and employers. In this podcast, Bob Tarzey speaks to Kowsik Guruswamy, Chief Technology Officer at Menlo Security about the challenges related to remote working and the technology options available to support it. Kowsik explains the main risks that arise with increased home working especially for businesses who have not adopted it previously. He also explains how homeworkers can have an experience that is as secure as office workers. Finally, he outlines how to improve performance and security for home workers.

View Details

The impact of cyberattacks on organisations is widespread not only from a financial standpoint, but also the operational disruptions, damaged brand reputations, and trust within the organisation. Traditional email security solutions aren’t enough to protect businesses anymore. Processes need to be in place to actively defend against sophisticated email threats. These threats are often able to bypass defences by using numerous backdoor techniques. In this podcast, Olesia Klevchuk, Senior Product Marketing Manager at Barracuda explores different email threat types and what measures can be taken to protect organisations. To begin with, Olesia explains some of the thirteen threats we’re currently seeing and the impact of these on organisations. Then, she outlines what gateway protection is and how this can be beneficial. Further to this, she explains how API-based inbox defence is implemented and what attacks it can block. Finally, Olesia showcases the strategies that organisations can implement to stay on top of rising risks. 

View Details

The majority of organisations have been working from home for the last few months amidst the COVID-19 pandemic. This rapid change has bought many new challenges for organisations to overcome. One of these challenges has been how we secure remote users and maintain security control for the organisation. The concept of Zero Trust is emerging as the preferred remedy for addressing remote work security challenges. The fundamental goal is to avoid reliance on trusted networks and to treat every system as an untrusted host. In this podcast, Chris Steffen speaks to Krupa Srivatsan, Director of Product Marketing at Infoblox. Firstly, Krupa outlines the new trends they have seen customers face around security problems and adapting to this new form of working. Then she offers advice for security professionals dealing with remote working challenges. Also, Krupa outlines her views on Zero Trust and how it affects remote workers in relation to improving security. Finally, she explains how Zero Trust can help with compliance-related challenges. 

View Details

For organisations that want to ensure safe, scalable, and efficient access to their services, effective identity and access management solutions are essential. However, ensuring maximum security and maintaining a smooth user experience is a challenge. The more we move into the digital environment, the more each company must focus on these aspects and construct the identity and access management (IAM) programs with the users in mind. In this podcast, Kris Imbrechts, Regional Director Northern & Southern Europe at Auth0 explains the business balancing act between user experience and security. To begin with, Kris explains the current state of IAM solutions in the market and how organisations are approaching implementation. Further to this, he outlines the build vs buy strategy and the importance of a seamless and almost invisible IAM solution. Finally, Kris looks at maintaining trust in users and the considerations needed for longevity and safety when implementing apps.

View Details

Keeping your business safe requires a proactive analysis of potential online threats. This requires more than details of latest malware and software vulnerabilities. Intelligence is also required about what is happening in cyberspace that may represent a specific threat to your business. The deepest recesses of the web need probing to gathering this intelligence. Not just the clear web, the websites that we all use on a day-to-day basis, but also the dark and, where possible, deep web. In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/cwillhoite/ (Charity Wright), Cyber Threat Intelligence Advisor and https://www.linkedin.com/in/etaymaor/ (Etay Maor), Chief Security Officer at https://intsights.com/ (IntSights). Firstly, they outline some use cases for external threat intelligence and the types of risks that can be mitigated. Then, they discuss how to probe the dark web in terms of identifying threats but also using analysis effectively. Finally, they explore how IntSights uses this analysis for mitigating threats.

View Details

Manual incident response processes, insufficient workflows and difficulty hiring security personnel leave security operations teams struggling to keep up with the growing volume of alerts. SOAR solutions combine automated data gathering, security automation, case management and analytics to provide organisations the ability to speed up the incident response process. In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/codycornell/ (Cody Cornell), Co-founder and CEO at https://swimlane.com/ (Swimlane), a U.S. based independent SOAR solution provider. Cody introduces how businesses are adopting SOAR tools and explains the ease in which they are deployed. He also provides some use cases for the type of workflows that SOAR enables that were previously hard to achieve. Finally, Cody details how different sized enterprises can access and use SOAR effectively and how he sees Swimlane evolving and contributing to the industry over the coming years.

View Details

As security requirements evolve, so must the policies surrounding them. Today, businesses are responsible for updating policies consistently across all relevant security devices regardless of function and supplier. Given the sheer volume, a manual approach would be too impractical. Thus, organisations must turn to specialist products that harness automation as a means to cover more diverse security requirements and enhance security analytics and intelligence. In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/lintell/ (Andrew Lintell), Vice President and Managing Director, EMEA at https://www.firemon.com/ (FireMon). Andrew introduces the FireMon brand and how diverse the devices are that such vendors cater for. He also details the role that vendors like FireMon play in SecDevOps. As well as this, Andrew explains how FireMon helps in ensuring that organisations’ security systems are compliant and how it can prove this to the relevant regulatory bodies.

View Details

The advent of DevOps was hailed as a means to have all aspects of application deployment handled by one single team. However, over time, concerns surrounding security have begun to arise. Many feel that security should be more of a priority for Development & DevOps teams, particularly in regard to applications. On the one hand, apps are a modern necessity to drive business success. However, on the other hand, they come with a host of security problems that need special attention, necessitating DevSecOps in turn. Joining us to lend his expertise on this matter is Jeff Martin, Senior Director of Product at WhiteSource. Firstly, Jeff explains whose responsibility AppSec actually is and how organisations ultimately create DevSecOps. He then demonstrates what the typical ‘DevSecOps’ workflow should look like. Finally, he outlines the benefits of open source tools and how important security procedures are for businesses and their DevOps efforts.

View Details

Applications are a double-edged sword for businesses. On one hand, they are a modern necessity to drive business success. However, on the other, they come with a host of security problems that need special attention. Joining https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) to outline the considerations specific to application security is https://www.linkedin.com/in/planetlevel/ (Jeff Williams), Co-Founder and CTO at https://www.contrastsecurity.com/ (Contrast Security). In particular, Jeff details the threat posed by the fact that we simply aren’t very good at writing vulnerability-free software, and why this is the case. As well as this, they discuss the role of DevOps, and specifically, DevSecOps, in software development. Finally, Jeff delves into self-protecting software and how it works.

View Details

Today's increasingly digital enterprise environment means that businesses must combat more threats than ever. However, it's not just the new generation of threats that they need to worry about. Organisations must also consider the threats that have stood the test of time. In particular, credential stuffing is one that has persisted over the years. Unfortunately, the misunderstandings surrounding it makes it all-the-more difficult to mitigate. In this podcast, https://www.linkedin.com/in/shumans/ (Shuman Ghosemajumder), CTO at https://www.shapesecurity.com/ (Shape Security), lends his expertise on the matter of credential stuffing. Firstly, he recaps what credential stuffing is and why it is still prevalent to this day. Then, he discusses the impact it has on companies and the best ways for them to mitigate the risks.

View Details

Technology has enjoyed an ongoing revolution, meaning organisations today can enjoy cloud, Internet of Things, artificial intelligence, and more – all of which are significantly advantageous for business. However, as organisations begin to heavily rely on these innovations, it begs the question: how should businesses strike the balance between delivering useful, available IT services and protecting the privacy of employees and customers? In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/nbhowe/ (Nathan Howe), Director of Transformation Strategy at https://www.zscaler.com/ (Zscaler). Firstly, Nathan delves into how cloud, mobility, and crypto make up the 'unholy trinity' in cybersecurity. Then, he explores the effect of an increasingly millennial workplace, before revisiting crypto. In particular, he discusses the impact of companies not inspecting SSL and TLS and its effect on the threat landscape. Furthermore, Nathan outlines what traffic businesses have the right to inspect. He also demonstrates why Zscaler's origins in email security is still relevant today.

View Details

Digital transformation is creating a new security landscape. In particular, it has paved the way for more workforce flexibility, empowering employees to work how and when they wish. However, this introduces new security considerations that many businesses have not had to address before. Here to lend his expertise on the matter is https://www.linkedin.com/in/sudhakar-ramakrishna-a58223/ (Sudhakar Ramakrishna), CEO at https://www.pulsesecure.net/ (Pulse Secure). Sudhakar walks us through the findings of an IDG global survey sponsored by Pulse Secure, investigating the state of enterprise secure access. Then, he delves into how secure access is an enabler of digital transformation, while heightening security too. Furthermore, Sudhakar shares his guidance on what organisations need to do to drive secure access and zero trust capabilities.

View Details

Vulnerability management is a must for enterprises today. In particular, vulnerability management automation gives businesses the scalability and frequency necessary for today's landscape. Businesses should endeavour to automate where possible, although the accuracy of automation isn't always 100%. Joining us to lend his expertise on the matter is https://www.linkedin.com/in/eoinkeary/ (Eoin Keary), CEO and Founder at https://www.edgescan.com/ (Edgescan). Firstly, Eoin outlines the findings of a recent survey by Edgescan, which investigated validating false positives among cybersecurity professionals. Then, he explores the current challenges that cybersecurity professionals are facing today. Eoin also shares his guidance on overcoming these obstacles.

View Details

Cybersecurity is an unrelenting matter for organisations, and no organisation is truly immune. In particular, the threat that cyber risks pose to business is an increasing concern for IT departments and senior management alike. Thus, it is becoming increasingly important to consider how best to mitigate these risks. In this podcast, freelance IT industry analyst https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/brianrobison1/ (Brian Robison), Chief Evangelist at https://www.cylance.com/en-us/index.html (Blackberry Cylance). Brian begins by sharing his thoughts on how to prevent cyber attacks. In particular, he details Blackberry Cylance's approach of utilising computing power and AI to build a predictive model. Also, Brian outlines the role that data plays in cyber defence. Finally, Brian explains why he believes that investing in cybersecurity can provide a return for businesses.

View Details

Attacks have become part and parcel of an organisation's lifespan. However, in most cases, this is the result of the attacker being able to exploit a weakness in the organisation. Thus, organisations must do what they can to understand their vulnerabilities and their impact. But understanding and reporting common vulnerabilities and exposures (CVEs) are rigorous tasks. Therefore, companies may benefit from using tools to increase automation and reduce manual procedures. In this podcast, freelance IT industry analyst https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/benjipreminger/ (Benjamin Preminger), Senior Cyber Threat Intelligence Specialist at https://www.cybersixgill.com/ (Sixgill). Benjamin begins by outlining the differences between common vulnerabilities and exposures, and demonstrates the rate at which they are reported. He also shares his thoughts on the MITRE database and the inadequacies in their scoring. As well as this, Benjamin explores why a dynamic CVE scoring will make the patching process more manageable for security professionals.

View Details

Businesses are increasingly utilising channels such as LinkedIn and WhatsApp to enhance customer interactivity and stay connected with team members. However, the current network security infrastructure was established before their creation. As a result, third-party apps have introduced security risks that the current structure cannot account for. Thus, businesses must take extra care to ensure their channels are secure. https://twitter.com/otaviofreire (Otavio Freire), President, CTO, and Co-Founder at https://www.safeguardcyber.com/ (SafeGuard Cyber), joins us on this podcast to discuss the matter. Firstly, Otavio details the shortfalls of the current infrastructure and how this impacts companies' social and digital channels. Of course, these channels do have their in-app security and privacy settings, but Otavio outlines why these are not enough to rely on. He then goes on to explain the threats associated with social media channels. In light of these obstacles, Otavio shares his thoughts on how companies can get around the risks and make the most out of their social and digital channels.

View Details

The cybersecurity industry has significantly evolved over the last few decades. The fact that there is simply more of everything is a huge contributor to this. This includes more technologies, more people, more data sets, and so on. However, the threat landscape has also changed and become more complex. This has ultimately led to cybersecurity having to be at the forefront of enterprise risk agendas. In this podcast, https://www.linkedin.com/in/ajaken/ (Dr Andrew Aken) speaks with https://www.linkedin.com/in/nikwhitfield/?originalSubdomain=uk (Nik Whitfield), CEO and Founder at https://panaseer.com/ (Panaseer). Nik lends his expertise on establishing a cyber infrastructure. As well as this, Nik delves into the challenges that often confront organisations when trying to gain visibility into their cybersecurity controls and metrics. Finally, he discusses the pressing issue that is the cybersecurity skills gap.

View Details

The advent of DevOps was hailed as a means to have all aspects of application deployment handled by one single team. Quicker updating of applications and better accountability of developers were among the many advantages of DevOps. However, over time, concerns surrounding security have begun to arise. Many feel that security should be more of a priority for DevOps teams. In this podcast, freelance IT industry analyst Bob Tarzey speaks with https://www.linkedin.com/in/kellyshortridge/ (Kelly Shortridge), VP of Product Strategy at https://capsule8.com/ (Capsule8). Kelly outlines the DevOps process and how it affects IT security. As well as this, she advises on the tools that DevOps teams can benefit from. She also demonstrates how the ‘DevSecOps’ approach can help organisations meet compliance obligations. Finally, Kelly delves into Linux deployment and filling the gaps it comes with.

View Details

Cybersecurity is changing rapidly due to advanced AI. These changes mean security officers have to adapt and utilise AI effectively to combat numerous growing threats. A different approach is necessary to detect threats that signature technologies may have missed. Advanced end-to-end AI, allows security officers to transform their strategies from the classic reactionary cycles. In this podcast, Industry Analyst at https://451research.com/ (451 research), Eric Ogren speaks to https://www.linkedin.com/in/nicole-eagan-4377b81/ (Nicole Eagan), CEO of https://www.darktrace.com/en/ (Darktrace) and https://www.linkedin.com/in/jrtietsort/ (JR Tietsort), Visionary Security Executive at https://www.corescientific.com (CoreScientifc). They speak about the impact AI is having across all aspects of cybersecurity.

View Details

Assessing, detecting, and responding to cyber threats are not new pursuits. However, evolving technology and innovating attackers make this a more challenging endeavor. More specifically, companies must be ahead of the changing nature of the threats and act at speed once encountered. Businesses today must have the necessary skills, agility, and underlying platforms to help them mitigate these risks. In this podcast, hosted by freelance analyst Bob Tarzey, https://www.secdata.com/ (SecureData's) Chief Strategy Officer, https://www.linkedin.com/in/charl-van-der-walt/ (Charl van der Walt) lends his expertise on the matter. Firstly, he discusses how organisations should prioritise their plan of action. Then, he outlines a basic strategy that businesses should be following. Finally, he offers his guidance on how to keep ahead of the changing landscape.

View Details

The scope of digitisation and the speed of adoption has increased rapidly in the last few decades. Virtually every aspect of any business operation feels this impact from supply chains to customer relationships. This pervasive aspect has changed the risk profile for every business. Therefore, businesses have had to transform the way they assess risk. Managing digital risk requires the tools to assess where the risks lie, how to mitigate them and to measure the effectiveness of the protections put in place. Freelance IT industry analyst Bob Tarzey speaks to Peter Beardmore, Director of Marketing for Digital Risk Management Solutions at RSA. They speak about what tools are effective to assess and plan for digital risk and when to implement these ideas.

View Details

Security covers every aspect of IT infrastructure and usage, to ensure the protection of users, data and business processes. Backup and recovery tools are a way to restore lost data after any number of issues. However, security attacks can often aim to mimic such incidents for ransomware purposes. Adapting backup and recovery tools to try and provide backstops against these threats is something organizations need to be implementing. Freelance IT industry analyst Bob Tarzey speaks to https://www.linkedin.com/in/josephnoonan/ (Joe Noonan), VP of Product Management and Marketing at https://www.unitrends.com/ (Unitrends). They speak about how backup tools can adapt to prevent ransomware attacks. Also, making sure backup-sets assist any size business and different methods to make sure they do not become compromised.

View Details

With organizations poised to spend more than $5B+ on endpoint security software this year, it raises the question: What should enterprises be asking from security vendors, and how can they parse signal from all the marketing noise? In this podcast series, hosted by freelance analyst Bob Tarzey, he speaks to Ian McShane who as a former Gartner analyst focuses on the endpoint security market. Ian McShane has written extensively about the failure of antivirus vendors to defend against modern attacks, and the marketing hype surrounding “next-gen” antivirus. Part 3 - How To Map Endpoint Security To A Contemporary Security Strategy?In the previous two episodes, Bob Tarzey spoke to VP and endpoint security expert from Endgame, Ian McShane. They discussed the history of endpoint security and how to progress moving forward. In this final part of the podcast, Ian explains various aspects of how to implement endpoint security most effectively. Furthermore, making sure these security controls are kept up to standard and improve over time.

View Details

With organizations poised to spend more than $5B+ on endpoint security software this year, it raises the question: What should enterprises be asking from security vendors, and how can they parse signal from all the marketing noise? In this podcast series, hosted by freelance analyst Bob Tarzey, he speaks to Ian McShane who as a former Gartner analyst focuses on the endpoint security market. Ian McShane has written extensively about the failure of antivirus vendors to defend against modern attacks, and the marketing hype surrounding “next-gen” antivirus. Part 2 - What’s Next for Endpoint Security?In the previous episode, Bob Tarzey spoke to VP and endpoint security expert from Endgame, Ian McShane, about the history of endpoint security and why it needs to play an integral role for companies. In this second podcast, Bob and Ian look at the future of endpoint security and the next steps that need to be taken. This involves looking at whether security teams will have to learn new skills and also the importance of the MITRE ATT&CK framework.

View Details

With organizations poised to spend more than $5B+ on endpoint security software this year, it raises the question: What should enterprises be asking from security vendors, and how can they parse signal from all the marketing noise? In this three-part podcast series, hosted by freelance analyst Bob Tarzey, he speaks to Ian McShane who as a former Gartner analyst focuses on the endpoint security market. Ian McShane has written extensively about the failure of antivirus vendors to defend against modern attacks, and the marketing hype surrounding “next-gen” antivirus. Part 1 - How Endpoint Security Got To Now In this podcast, Bob Tarzey talks to VP and endpoint security expert from Endgame, Ian McShane. They discuss the history of endpoint security, the failings of signature-based anti-virus and how it is integral for all organizations.

View Details

New software code is released almost as fast as new ideas are conceived in the tech industry. This makes web applications some of the most vulnerable places online, as these are exposed to the online world and easily targeted. In the previous episode, Bob Tarzey spoke to Rapid7's Ben Glass and Jay Paz, Manager of Enterprise Security Consulting and Director of Penetration Testing and Consultant Development, respectively, about building better code to stay secure. In this second podcast Bob, Jay and Ben look at some of the supporting technology to avoid vulnerability in companies. This includes the testing of code before releasing it, the testing of deployed software, and finding safer guides to build better and stronger software.

View Details

New software code is released almost as fast as new ideas are conceived in the tech industry. While this growth is necessary, it makes web applications rather vulnerable places online, as these are exposed to the online world and easily targeted. It's time to find better methods to address application security. In this podcast, freelance analyst Bob Tarzey talks to Rapid7's Ben Glass, Manager of Enterprise Security Consulting, and Jay Paz, Director of Penetration Testing and Consultant Development, about finding better methods to address application security and building better code.