Two CISOs and a security-minded friend discuss and debate topics of security and privacy, with a focus on looking at the topic from various angles, both that they support and those they don't. Sign up for our newsletter to be notified when new episodes drop, or when new projects are announced https://newsletter.greatsecuritydebate.net
Welcome to the Great Security Debate! In this episode, experts take on a multifaceted discussion about the intricacies of technology and cybersecurity. The debate navigates through the recent incident involving CrowdStrike and Microsoft, dissecting the layers of technology, processes, and the roles of different entities in maintaining security. Emphasizing the lessons learned, the debate also explores the challenges of disaster recovery, business continuity, and balancing risk in an increasingly complex digital landscape. Tune in as the hosts delve into the ramifications of over-consolidation, the implications of vendor lock-in, and the importance of maintaining a culture of quality and robust testing.
00:00 Introduction to the Great Security Debate
00:37 Layers of Technology and Finger Pointing
01:23 Disaster Recovery and Business Continuity
02:34 Market Leaders and Single Points of Failure
08:25 The Complexity of Software and Manufacturing Analogies
14:27 Kernel Access and Security Implications
23:29 BitLocker Keys and Recovery Challenges
28:05 Daily Text File Sharing
28:21 Transitioning BitLocker Management
28:45 Risk Profiles and Encryption Decisions
31:47 Team Collaboration and Lessons Learned
33:38 CrowdStrike Incident Analysis
36:18 The Importance of Response and Culture
44:10 Balancing Speed and Safety in Software
51:41 Closing Remarks and Future Plans
This episode of 'The Great Security Debate' delves into the complexities surrounding cyber insurance, discussing its impact on minimising business risks and ensuring compliance. Erik, Brian, and Dan talk about how connected systems and automation increase risks and integrates AI reliance concerns.
Insurance policies, force majeure, and government regulations get some quality discussion and debate time, revealing fears and misconceptions about standardised security controls vs. adaptive security practices. And last up: the practicality and pitfalls of self-insurance, government intervention, and the need for standardised security terminology.
Show Links:
Help support the podcast: https://ko-fi.com/distillingsecurity
Thanks for listening! We have got some exciting changes ahead including ways to support the podcast, some big announcements, new shows and conversations, and more! Thanks for listening!
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Thanks for listening!
00:00 Introduction to the Great Security Debate
00:30 The Role of Cyber Insurance
01:49 Manual Processes and Business Continuity
03:09 Manufacturing and Supply Chain Challenges
06:11 Insurance Policies and Cybersecurity
08:00 Standardization and Government Involvement
19:14 The Complexity of Cyber Warfare
22:35 Globalization and Cybersecurity
30:33 Leadership vs. Boss Mentality
33:53 The Role of Communication in Crisis
36:51 The Cost of Compliance
40:30 Global Cybersecurity Challenges
44:22 The Complexity of Online Trust
47:56 Insurance and Cybersecurity
53:07 The Future of Cyber Insurance
01:00:15 Conclusion and Final Thoughts
Mentioned in this episode:
Michigan BBQ Meet-Up July 18, 2024 on Cass Lake
Join Distilling Security on July 18th in Cass Lake, Michigan for a BBQ, food, colleagues, and fun. Thanks to event sponsors: Material Security, Orca Security, Legit Security, and Cyberhaven! Full details and registration forms are on the Distilling Security website https://distillingsecurity.com.
Michigan BBQ Meet-Up July 18, 2024 on Cass Lake
Join Distilling Security on July 18th in Cass Lake, Michigan for a BBQ, food, colleagues, and fun. Thanks to event sponsors: Material Security, Orca Security, Legit Security, and Cyberhaven! Full details and registration forms are on the Distilling Security website https://distillingsecurity.com.
oin us for a deep dive into the complex world of cybersecurity in this episode of The Great Security Debate. Our panel of experts engages in a spirited discussion covering a range of topics, from the resurgence of ransomware attacks following the onset of the Ukraine war to the implications of Broadcom's acquisition of VMware. The panelists explore the evolving threat landscape, the role of AI in both bolstering and undermining security efforts, and the need for adaptable security strategies that reduce the blast radius of potential breaches. Also, hear insights on the balance between implementing stringent security controls and maintaining user experience. Tune in for a comprehensive look at modern cybersecurity challenges and the innovative solutions being developed to combat them.
Broadcom's change of support for VMWare continues to shake the security buyer world
An increase in attacks on hypervisors
Distilling Security website
Upcoming event on July 18 2024 in Cass Lake, Michigan. Sign up for the Distilling Security newsletter to get information about the event when it is ready.
Help support the podcast: https://ko-fi.com/distillingsecurity
Show Notes:
[Research Links]
Thanks for listening! We have got some exciting changes ahead including ways to support the podcast, some big announcements, new shows and conversations, and more! Thanks for listening!
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Sorry about the audio on this one. We have got the tech back on track for the next episode. I promise!
Join the Great Security Debate as Brian, Erik, and Dan delve into 'pig slaughtering,' a scam involving rapport building to swindle victims out of money.
The discussion explores the intersections of security awareness, blockchain technology, and the ethical implications of digital tracking tools like chain analysis. Featuring real-world cases, including child exploitation traced through blockchain, and the broader debate on privacy versus legality in technology use. Are public blockchain transactions truly private?
And how can we balance innovative tech with ethical concerns? Tune in to hear all about it
Help support the podcast: https://ko-fi.com/distillingsecurity
Show Notes:
Thanks for listening!
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Editor note: This episode was recorded in the final days of 2023... but was lost to technology demons until now. One of those demons made it necessary to show the Zoom screen rather than our usual edited video cast. Sorry for the inconvenience and pain on your eyes.
The GSD Crew take a closer look at the dystopian Netflix technology movie, "Leave the World Behind"
What can confusion and chaos do in society?
Have newer generations lost their skills and capabilities necessary to live in a post-technology world?
What might we change in our lives after having watched the movie?
Help support the podcast: https://ko-fi.com/distillingsecurity
Show Notes:
[Research Links]
Thanks for listening! We have got some exciting changes ahead including ways to support the podcast, some big announcements, new shows and conversations, and more! Thanks for listening!
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate and Distilling Security, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
It's an "all rounder" episode of The Great Security Debate. Brian watched a movie, Erik watched an advertisement, and Dan was overtly cynical. Just another day in the podcast booth for these three.
A variety pack of topics ranging from recent security attacks, to AI in technology, to automotive manufacturing (go figure), to privacy, to sponsorship and vendor models at live events, and more.
Links to everything we talked about are available in the show notes.
Thanks for listening and welcome to 2024! We have got some exciting changes ahead this year including ways to support the podcast, some big announcements, new shows and conversations, and more! Thanks for listening!
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
It's not easy to sell things. It's even harder to sell to security practitioners and leaders. The Great Security Debate this week covers some angles in security tools (and selling those tools to security teams) that have taken their toll on the trust that needs to exist between those who buy and those who make the products that we use. From the software providers to the VAR (resellers) in the middle to the people and techniques used to market and sell the solutions. Some of the key topics of the discussion include:
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Thanks for listening!
This week we are debating modern AI systems, especially the commercial ones on just about everyone's lips when talking about CVs, high school term papers, and interview answers.
Large Language Models (LLMs), of which ChatGPT and Bard are two examples, are growing in prominence, but will they disrupt the technology world, or are they nothing more than just another blockchain fizzle?
In this episode:
Unrelated to AI, we also talk about what happens to all the "smart" things in your house when the internet goes out? What stops working? Way more than you might think...
We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head to https://youtube.com/@greatsecuritydebate and watch, subscribe and "like" the episodes.
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Thanks for listening!
Links:
Is OpenAI almost bankrupt?: https://www.windowscentral.com/software-apps/chatgpts-fate-hangs-in-the-balance-as-openai-reportedly-edges-closer-to-bankruptcy
Maybe not bankrupt, but has business problem: https://www.forbes.com/sites/lutzfinger/2023/08/18/is-openai-going-bankrupt-no-but-ai-models-dont-create-moats/?sh=3c8922845e22
Gartner declares LLMs at the peak of inflated expectations: https://www.gartner.com/en/newsroom/press-releases/2023-08-16-gartner-places-generative-ai-on-the-peak-of-inflated-expectations-on-the-2023-hype-cycle-for-emerging-technologies
When ChatGPT goes Bad: https://sloanreview.mit.edu/article/from-chatgpt-to-hackgpt-meeting-the-cybersecurity-threat-of-generative-ai/
https://venturebeat.com/security/how-fraudgpt-presages-the-future-of-weaponized-ai/
The Circle (Movie): https://www.imdb.com/title/tt4287320/
Amazon Sidewalk, and it's privacy issues: https://www.popsci.com/technology/amazon-sidewalks-privacy-concerns/
Idiocracy (Movie): https://www.imdb.com/title/tt0387808/
Moores law is dead:...
It's been a minute, but we are back with another Great Security Debate!
Whether it is compliance, trust, questionnaires, we all sell something to someone and security is core to that process.
In this episode, the focus is on how security integrates into the core of each of our businesses or organisations. From being part of strategic planning, the reminder that perfect being the enemy of progress, to the power in being a first mover on security and privacy topics:
Remember that you can't be "SOC2 Certified." And PFMEA is not always the answer to every question. Or is it?
We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head to https://youtube.com/@greatsecuritydebate and watch, subscribe and "like" the episodes.
Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links.
Thanks for listening!
Recorded on Saturday 29 October 2022, at the tailgate before the University of Michigan vs Michigan State University (American) football game, Brian, Erik and Dan chat about the news of the day, with more than a few correlations back to football. And we had a special guest join us, too: Zah Gonzalvo Rodriguez (https://www.linkedin.com/in/zahira-zah-rodriguez-gonzalvo-1a97692/) There was an upcoming OpenSSL vulnerability hitting the world this week. How would Software Bill of Materials (SBOM) make the response easier? A reminder of our dependence on the stability and security of some very core tools (like OpenSSL) to run our businesses. Mot to mention the fact that such tools are often within the libraries we use and don’t even realise it’s there. Similarities between football and security in the need to adjust based on what the other team shows signs of throwing at you, and further based on what they actually bring to the line. How repeatable process and inventory help make the response to these vulnerability disclosures less like a firedrill and more like standard ops. Did you know that credit ratings are being affected by information security posture and breach response? Same thing with M&A and investment valuation… if you’re not as mature in security and privacy you may see a discount taken on your value! How transparent should we be with the peer companies and the public world about our security posture (like incident response plans, and security controls in place)? And if you’re curious, you can find out what team Dan (the lifelong Badger) was supporting in the game. Congratulations to the University of Michigan in later winning this game, and to both teams for keeping the rivalry alive and spicy. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head to https://youtube.com/@greatsecuritydebate and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links. Thanks for listening!
This week’s debate comes amid a combo platter of increased analytics leading to near-immediate contact when visiting a product’s website, along with more clarity from enforcement bodies about how they will approach their respective privacy legislation. One such fine was the Sephora CCPA matter in which California Attorney General levied a $1.2M fine on the company ([https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement]) Listen in to hear Dan, Brian and Erik talk about: * Are privacy and shareholder value at odds? How does protecting the privacy of the consumer help shareholder value? * A reminder that security and privacy can serve as a business differentiator * How to deal with the reputation of a company being set by misleading headlines (and people not reading the actual article/detail)? * Does better privacy practices in companies lead to reduced data for sale on the illicit market? * Does just “saying no to data collection” by companies make for a better privacy posture? * How long should (vs. how long do) you hold onto data? * How will companies be judged in the future by how they manage data today? * Are ads themselves the source of all our problems? * Why does the push for more advertising to reduce costs increases the push for more data collection? We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you choose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you use them. We do not make our recommendations based on the availability or benefits of these affiliate links. Thanks for listening!
We've all seen it (or been it): a new boss arrives at the company and quickly thereafter a bunch of their old colleagues get hired. It feels like they are getting the band back together at the new place. What does that say to the organisation about that leader? What does doing the opposite (pausing, growing from within) say differently? Brian, Dan and Erik discuss, debate and dissect this from a few angles, including some of the following: The power of threes: Three paths when you come in as a new leader: bring your own, nurture within, hire all new. And the three arcs of a company - startup/scrappy , growth/maturation, steady/run. Two critical skills we wish we were taught in school and earlier in work: communications and public speaking The impacts on culture on leadership and how they approach the staffing question, and how you bring people in will be the biggest impact on the culture of the organisation How can metrics hide the actual performance of the team? Are the CISO retention numbers as bad as the urban myth ? Are CISOs staying longer than we think they are? What organisational situations drive leaders to resort to bringing in the people they know and trust vs. Trusting those already there? How does growth by acquisition change the way we approach the listening and staffing of our teams and supporting our organisations? Approaches to finding people to provide new perspectives, without having already worked with them directly? How does geographic culture affect the decision on how to staff your team as a new leader in an organisation? We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availability or benefits from these affiliate links. Thanks for listening!
Are we getting subscription overload? The move to more and more subscriptions are good for those selling, but are they good for those buying, too? Do subscriptions that are offset by other non-cash costs (e.g. data collection, advertising) make the subscription fatigue less? How does that fit into the securty product world? What are the risks of making security technology only for those that can't afford it? Why are the ad-supported versions more heavily marketed than the no-ad versions? How do subscriptions encourage continuous development of software and features? What about innovation? What's a feature that is persistent and what can be revoked or shifted into a different subscription tier (take a look at Slack's recent move to make the free tier way less useful and encourage the need to move to a paid tier) Do the combinatoric vastness of features that can go on and off based on the subscriptions you buy introduce unnecessary or unsafe risk of not working well together in specific combos? What are the legalities of jailbreaking your software rather than paying to activate it by subscription? How does doing so affect liability and effectiveness of the product? We also talk about some things unrelated to subscriptions (and cars), too! * What is needed to adapt your communications (and subscription sales pitch) to VC/PE vs. the CIO/CISO at a company? East coast vs. west coast? Etc. * Tips for job candidates on where to look for public info on what a company thinks is important from security and risk (hint: it's SEC filings like the 8-K and 10-K!) Tune in to delight as Dan rants in Yiddish, and then mess up the name of some of the most popular movies of our time. Enjoy seeing (or hearing) Erik get on a soapbox stumping for Sig Sigma. Binge on Brian talking about automotive manufacturing (who knew) and for once not be broadcasting from a "train station".
It's the dog days of summer here in the northern hemisphere, and we have some episodes to make the hot, muggy days go by faster (or the drive up to the cabin in the woods to escape it all). This week Dan, Brian and Erik talk about what it takes to be a Virtual or Fractional CISO. Does someone that calls themselves one need to have had in-house CISO experience to do the job? Or do the fresh perspectives of someone that doesn't come with history benefit the organisation in a different way? Risks, challenges, and talking to Boards of Directors definitely have a strong place in the debate (and we hit on all of them) We will be back with more episodes through August and then back to our usual bi-weekly pace as we hit the autumn. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. If you're watching on YouTube, we are very sorry for the video sync issues this week! The sound is great, but one of our hosts does a very poor Milli Vanilli impression. We are writing up the root cause analysis documents and issuing CAPAs to keep it from happening agai Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availability or benefits from these affiliate links. Thanks for listening!
Dan, Brian and Erik look at how the past informs our security future, and how things we have done in the past may not get us where we need to be in the future. Join us for a live podcast recording with live audience Q&A, direct from the MCWT Executive Connection Summit. In the live recording we covered a flurry of topics focused on changing ourselves, refreshing ourselves and renewing ourselves including: * The barriers to entry to get into the security field * Experience vs. education requirements in security hiring * Changes afoot in hiring appetite as recession looms * Reporting requirements by public companies on breach or security events * Security beyond just confidentiality * Improvements that can be made to the hiring process * And lots more! Huge thanks to the wonderful team at the Michigan Council on Women in Technology (https://mcwt.org) for asking us to be part of this great event bringing the Michigan technology community together to build connections. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availability or benefits from these affiliate links. Thanks for listening!
This week on The Great Security Debate we have arrived at one of our favourite episodes of the year (and what is and will be an annual thing!) when Forrester Senior Analyst, Jess Burn, returns to the show to share this years recommendations for security programs. An overarching theme of the report is to use the captital that the CISO has acquired over the past few years and build out your program to where it needs to be. AKA, “strike while the iron is hot” More detailed topics including: - Career paths and changes in comp methodology for security teams need to change - Security Awareness needs adjustment for work for anywhere - Minimum viable security - it’s definitely not just “barely secure” And a reminder that Dan, Brian and Erik will be doing a live episode of the podcast at the upcoming Michigan Women in Technology ExecutiveManagement Conference on May 5 in Novi, Michigan. Tickets for the whole conference are now available (https://MCWT.org) and the agenda for the day is great. See you there If you want to listen to Jess’s previous episode, check out Episode 20, “It All Comes Down To Relaltionships.” https://www.greatsecuritydebate.net/20 You can find Jess on LinkedIn (https://www.linkedin.com/in/jessburn), Twitter (https://twitter.com/jessburn) and at the Forrester blog (https://go.forrester.com/blogs/author/jess_burn/). Thanks for joining us, Jess! And thanks to you for listening and watching. Special Guest: Jessica Burn.
The Great Security Debate rolls on, this week looking at how governments, regulations and business values are and will shape the security posture of enterprises. Is attribution worth pursuing to the end? How can state and federal law enforcement help figure out who and what happened after an incident? Fast (agile) vs good (quality) vs cheap (cost) Are you chasing the right metrics in your organisation? Do they encourage the right behaviour? Is regulation required to make good security a greater market force? What will the regulations emerging in the US focus on? The “what”, the “why”, the “how”, or the “who”? How will they change when and how companies report material breaches? How does attribution of attack correlate to insurance coverage? How do IR firms fit into the equation? Erik, Dan and Brian also announce that the podcast is going LIVE and On the road. On May 5, Great Security Debate will be recording a live episode at the MCWT Executive Connection Summit in Novi, Michigan! More info and registration details are at https://mcwt.wildapricot.org/event-4630370. Ticket sales begin on 18 April 2022. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links. Thanks for listening!
Recently, Brian, Dan and Erik had the great fortune to do a live version of the podcast at the monthly meeting of the SIM Detroit Chapter (https://chapter.simnet.org/detroit/home). At the close of that discussion, the comment was raised as to whether or not security should be used as a competitive advantage by businesses. The topic seemed perfect for The Great Security Debate, so here we are. In this episode, we cover: Can security be used as a business differentiator? SHOULD security be used as a business differentiator? If security is added too deeply into the sales cycle does it incentivise the wrong behaviours just to make a sale? How can we quantify the value of security in the purchasing process when it is not easily attributable to direct cost saving or value? How do closed systems compare to open systems with regard to security? How does the rise of customer trust as a key organisational focus indicate the use of security as a business differentiator? Do the fears that using security as a differentiator means that the collaborative nature and history of security will disappear? We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links. Thanks for listening!
Current global events have led to increased focus on technology security. In this week's episode we debate to what extent this does or will confirm the rise of the information security roles within organisations. Our thoughts and good wishes go out to the people of Ukraine. Do current events confirm that the rise of the CISO organisation was warranted? How do CISOs sleep at night considering everything going on? How to reply to the question “what else should we be doing?” Are the attacks the primary objective or are they a smokescreen? How does the game of chess tie into to information security practises? What is the CISOs role in reducing FUD (fear, uncertainty, doubt)? Will current information it pay for acts of war? Does it raise our collective stature? Why is humility so important in the information security world? The underlying message is that while it is late in the process now to do all the steps to protect your organisation, it’s never too late to get started! We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links. Thanks for listening!
This week’s episode was sparked by a recent TechCrunch article https://techcrunch.com/2022/02/01/free-agent-series-a/ asking whether tech workers should have agents to negotiate their salaries. We took up the debate on this and a few adjacent topics including: The Great Resignation’s impact on working habits Should security practitioners and leaders be represented by “agents” to negotiate better compensation for roles? What are the ways that formal agents exacerbate bias and increase the gaps between levels? The importance of networks for getting advice to help you be your own “agent” Is it the Great Resignation or the Great Realisation? How do ethics and values play into staff’s desire to go to or stay at a company? At different levels in one’s career who can help be your agent of change? We should not be afraid to talk about our salaries and numbers And yes, those are Pączki on Brian’s hat. If you are not sure what this about, take a look at the video version on our YouTube channel https://www.youtube.com/watch?v=CAYRL1flZic We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links. Thanks for listening!
We got a message from a listener asking for some discussion about putting the data first and securing it with that mind - the inside out, rather than looking at the perimeter and infrastructure and working back toward the data - outside in. And since we love our listeners and your feedback, we took the chance to cover this topic in depth. In the process we also covered: * Data Loss Prevention - Is it possible to improve this without the painful data classification, startup work or culture change? * When doing data analysis for attacks (or fraud) you have to account for the fraud already baked in the normal you know today * We can’t meaningfully count on IP address for geography…thanks to security asking for more use of VPNs * The pros and cons and risks to ponder when securing data in on premise vs. cloud/SaaS arrangements * When is the right time to establish a security team in a growing company? And how bad will the data sprawl be when they arrive? * Will the CTO/CIO and the CISO merge into a single role? Will the CIO report to the CISO eventually? It depends, of course, on the people and the organisation * Controls today may not be the controls we need for tomorrow * We try to secure things, but there’s also important value in good use of data to improve a business * Sunk cost fallacy and Security: when to burn it all down and start over * Audit is the best friend of the CISO: a new set of eyes and accountability partner makes all the difference Dan also goes on a small tirade over the way security professionals use the term “the business” as something distinct from the security team that is absolutely part of the business itself. Enjoy that soapbox moment. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes. Some of the links in the show notes contain affiliate links that may earn a commission should you chose to make a purchase using these links. Using these links supports The Great Security Debate, so we appreciate it when you do use them. We do not make our recommendations based on the availabliity or benefits from these affiliate links. Thanks for listening!
Some say that Log4J is the gift that keeps on giving, much like the Jelly of the Month Club. After the initial surge of discussion a couple weeks ago there were mitigations, a vaccine and multiple iterations of official patches to keep the issue at bay and the new ones that cropped up afterwards. Brian, Dan and Erik discuss the log4j vulnerability as it relates to enterprise systems, supportability, balancing the risk of patching and the ways that open-source software are used within the enterprise. Join us this week as we cover: The Log4J vulnerability and saga in a nutshell The pros and cons of waiting to patch until there's a stable one vs. patching again with each iteration and risk my system's stability The critical need for system and application (and library) inventory and keeping up to date How best to react when the media and public discussion picks up on a vulnerability and causes a stir The challenges in the flurry of email and surveys from and to SaaS and service providers about their state on the vulnerability of the day What is the cost of "free" when it comes to running (and maintaining) open source software like Log4j How to make sure procurement departments are not just involved but include the risks of procurement decisions into the process Are the external capability assessments like SOC2 able to move beyond perfunctory review by those asking for them We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
It's a sports analogy-filled episode of The Great Security Debate, but don't let that scare you away. This week, we cover a whole host of topics, primarily focused on the ideas of simple vs. complex and best-of-breed vs. tightly integrated when dealing with technology, change, process or securing your environment. Pace of change in security is ridiculous right now How does reducing complexity and technical debt improve security and technology? (Said differently: simplicity is the heart of good security) Tech is nothing without process or people (see Episode 29 - People Process and Product (https://www.greatsecuritydebate.net/29)) Can security vendors be everything to everyone? In what environments do "suites" give better security balance than "best of breed"? What are the risks and benefits of a set of suite technologies vs. best of breed? How does securing your organisation parallel with American Football? What's changing in how we buy technology (and security technology)? Shorter contracts, even if it means less "savings"? Should we invest in security technology heavily up front to win one battle at all costs, or plan for the long-term war? Note that all American Football references were to games that had not yet been played at the time of recording. Congratulations, University of Michigan Wolverines on winning the Big Ten championship later that evening. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
In security (and elsewhere) the long game is often overlooked in lieu of short-term advances and accomplishments. From building security into the culture of an organisation to setting goals and objectives for leaders and staff, being strategic in your security approach is critical. In this episode we cover: * How to balance an organisation's drive to shareholder value over the short term with the need to invest strategically in security, privacy and compliance * What are we doing wrong by throwing technology alone at security problems (and not looking at the process or people issues along the way) * Does proceduralising security or training up staff reduce the efficiency of the organisation or set up the org for longer-term efficiency? * Degrees vs. experience? And the ever deteriorating definition of "entry level" * The impact and importance of building the time in to train entry-level staff vs. hiring "ready now" experienced people (if you can find them at all) We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
Security has truly gone mainstream. From late night television jokes to state governors not knowing how technology works, as a profession and a vocation, we have arrived. Jimmy Fallon has jokes about security on his show What are the implications of out of date security laws that define what it is to “hack” systems? Keep in mind that some were written as much as 30+ years ago! Is it security’s job to know all the tools in place? Or the business to approach security to help make their tools secure? Is viewing publicly available information or information pushed to your browser actually hacking, or is it legal/OK? Creating laws that stand the test of time is hard. And subject to lots of lobbying. CISO Liability and visibility based on the prominence of the role. Does this lead to targeting to discredit? (think: false social media profiles and deepfakes) Offensive techniques and what happens when companies go offensive against attackers? Prevention as a growing tactic by security teams - especially when life is on the line in the products we make SPAM: is it food or is it email? When is the right time to bring security into your startup? Weaving it in when it is young! We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
In the adage "people, process, technology" the technology comes last in the list for a reason as it is only as good as the people and processes that surround and support it. In this week's Great Security Debate we cover a range of topics all focused on the importance (and impacts) of the people and the process as key to the success of security technology. Said differently we can throw all the tech in the world out there, and it does no good without the other two. Around the world, in some locations government drives commercial security innovation, and in others, commercial interests drive government security adoption. Where is that innovation coming from? The recent rumblings that security insurance policies may soon come with "buy lists". What impacts on the efficacy of controls come when the tech is chosen for you. And how do we guarantee the genuineness of how such a formulary was created. What can security learn and use to teach the wider business world about availability and resilience from the current supply chain impacts taking place in manufacturing or consumer goods after COVID-19? Tune in to this week's episde to learn all about these and more. Show links below have the details of articles, items we cover in the episode. We also have a video channel on YouTube that airs the "with pictures" edition of the podcast. Please head over to https://bit.ly/gsdyoutube and watch, subscribe and "like" the episodes.
Over the past 18 months, the way we work has changed including within the security field. On this episode of The Great Security Debate, Dan, Brian and Erik dig into some of the long-term implications of working today and beyond. From remote work to in-person or hybrid : what works best? Does security have a talent shortage, and how is it exacerbated by leadership issues? Was innovation and productivity stifled during COVID by remote work? How to build strong remote teams and learning from the history of global remote teams? Does remote work help or hurt the chances for smaller orgs to get good talent? Is money the biggest driver for people in work? How does mission and team comfort play in? Can we change culture of long-standing in-person culture enough to support remote/hybrid work? Which is better to look at, certifications or experience? What role does influence play in leadership and innovation, especially in non-management roles? This episode is available in both audio and video formats. The video edition is on our YouTube channel along with a growing collection of video from previous episodes. https://youtu.be/p099pC4dh3A Get notified via email when each new episode is published, and find out about exciting new projects from The Great Security Debate team. Sign up here: https://newsletter.greatsecuritydebate.net Thanks for listening! Tell your friends and let us know your comments, feedback and ideas for future Great Security Debates.
A recent visit by US companies to the White House sparked a debate between Dan, Brian and Erik about how to improve security. Was the result useful to the cause, or useful to the marketing goals of the attendees? The risks are high, but are the responses going to move the needle? We discuss on this week's Great Security Debate. Leave some feedback, give a thumbs up, a star or whatever your favourite podcast app prefers, and tell your friends about the podcast. Thanks for being a listener!
If you want to check out the new video edition of the podcast, please go to: https://youtu.be/FBBmA9YDNfQ where you can subscribe, give thumbs up and ring bells like YouTubers have been asking you to do for years. You know the drill. Also, our apologies for the hum in the audio throughout the entire episode. The problem has been identified and the source (Dan) has been taken out back and schooled on the difference between mic-level and line-level audio feeds. He promises it won't happen again... often. Now, on to the show. This week, Dan, Brian and Erik tackle the recent changes announced by Apple regarding moves to protect children from online predators and from the passing of illegal material about children. The project has three parts, each with its own benefits and concerns. We cover them each individually: First, the scanning of messages inbound to minors (Under 18s) on a Apple Family Sharing account in which images are tested for inappropriateness, blurred and the child alerted that they may be about to look at something that they may want to reconsider. If they are under 13 and decide to view the image the parents are notified. This is an opt-in programme and parents decide whether or not to join for the family. Next comes the proactive scanning of iCloud Photo Library stored at Apple. For a long time many have wondered why end-to-end encryption had not been put into iCloud, and this is a likely factor. The photos are tested against the hashes of a set of known images containing child pornography and issues are raised to the authorities. This is and has been happening on other cloud photo services including Microsoft and Flickr for some time. Finally, and most controvertially from a privacy perspective, Apple is implementing a proactive test of the hashes ofphotos stored on customers' Apple devices against this same set of known images. In the US there is no law that prevents this but runs counter to the marketing emphasis Apple has placed on the privacy of data within their devices. The method is rather intricate and strives to prevent Apple from seeing anything unless it suspects there are systemic child pornography issues at bay. These technology approaches change the game for prosecutors and law enforcement, and they expose issues earlier. But what happens when this capability gets expanded, or brought into law as mandatory for use against its citizens who speak out politically, or is taken over by bad actors? Look at the link in the show notes regarding the keys the TSA made for physical locks at the airport - every hole is a potential future vulnerability. Does the end justify the means? We discuss in depth on this week's Great Security Debate! If you want to support the efforts of The Great Security Debate, please feel free to become a patron and get some cool benefits of supporting this independent show - https://www.patreon.com/securitydebate
Get notified in an email every time a new episode of The Great Security Debate drops, or when we announce in-person episode recordings (coming soon)! Sign up for our newsletter: https://newsletter.greatsecuritydebate.net Dan, Brian, and Erik find themselves debating whether or not the new up-to-$10M reward for information regarding ransomware and other attacks will make a material difference in the upward trend in technology as a weapon. What are some non-technical examples of ransomware (hint: it involves warm weather islands and boats and flags with skulls) How will the new ransomware bounty work? Will it work at all? Who sets the definition of "minimum viable security?" Who should and who can set that definition? Can we get beyond human nature to take advantage of a situation that is beneficial to them? What other economic impacts take place if we can eliminate bad actors (other than a lot of out-of-work security practitioners?) Tune in and enjoy this episode of The Great Security Debate. Please let us know your thoughts by leaving rating feedback in your podcast app, and/or sending us an email to feedback@greatsecuritydebate.net. Thanks for listening!
Recently a lot of newsworthy security incidents have taken place. A common thread through many is not that they were sophisticated or required lots of time to plan and execute, or even that the victim had not invested in a lot of whizbang security technology which led to them not noticing the attack. The common thread much more simple: that fundamental security measures were not being taken by the organisation. Things like turning off accounts when people left the organisation, removing disused technology from the network, and the reuse of passwords by staff amongst public-facing and internal systems. The fundamentals make it easy for attackers to get into networks and systems, both enterprise and personal, and are all things that we can each work on individually and within our organisations to improve and make the attacks that much harder for the bad actors to execute. This week's episode discusses those fundamentals and how to approach them. The "slide" that is often referenced in the episode comes from a talk that Dan gave to the National Information Standards Organisation (NISO) last week on why it was so important to maintain the security of their systems. The whole presentation deck is available at http://slideshare.net/secratic/security-is-an-enabler-not-securing-is-an-inhibitor-249421889 and the specific slide is on Slide 8. Thanks for listening. You can subscribe to the podcast on your favourite podcast application or by visiting our website https://www.greatsecuritydebate.net/subscribe. Please let us know what you think by leaving a comment in the podcast application's rating section or emailing us feedback@greatsecuritydebate.net
A wide range of cause and effect discussion in this week's episode. What happens when a cellphone gets compromised for one purpose and has unrelated, follow-on consequences? Will there be material impact from the recent decrees, executive orders and vocal support by President Biden that additional focus is required on information security, ransomware and corruption? What are the downstream impacts of paying, and not paying a ransom and what happens if they are prohibited by law? Is doing the mininum amount of security OK, or is the minimum not really the required minimum? And more on the security position on data lakes, too. Join Erik, Brian and Dan as they count their pieces of flair and determine if we are the right fit to keep working at Flingers.
The news of the week includes discussion about some changes to Amazon's home devices including Echo and Ring with the activation of their Sidewalk Network on all those devices by default and the potential for both ubiquitous connectivity for IoT devices, and the possibiity of abuse of the data that is seen . Brian, Erik and Dan also talk about the impact that the launch of the new Apple Application Tracking Transparency (ATT) program which asks users if they want to be tracked (spoiler alert: they very much do not). This will impact ads and apps that depends on ads pretty heartily, and we debate the pros and cons. Enter the data lakes (troves of data just waiting to be mined by companies to find "interesting things" (or targets for attackers). We really appreciate your feedback, both through subscribing and rating on your favourite podcast application, and by email to us at feedback@greatsecuritydebate.net Thanks for listening!
We got asked by a listener to help answer the question, "Why Does My CISO Hate Me?" While we may not be privy to the exact situation in play there, we are pretty sure that no one's CISO truly hates them (but they may not be fond of all the things that everyone does all the time). In the debate today, we talk about some of the things that challenge CISOs including: Security is more than just confidentiality... there's also integrity and availability Undocumented processes and changes make it hard to figure out where things go wrong Security is a bidirectional partnership, not an Q&A/task queue from the rest of the organisation, nor the acceptor of risks Please ask questions if you are concerned about something or want more info, or even if something sort of smells fishy (or phishy). There are no such thing as stupid questions, only unasked ones. We also highlight a number of the things that CISOs and security teams can improve on to build better and stronger relationships across the organisation, too, such as: * Better listening and asking good questions * Understanding the business through servant leadership * Helping to determine what is most important to the business (and what needs to be protected) We are all heading toward a common goal, so let's work together to accomplish it! Thanks for listening. Until next time...
We open season 2 with a new format: guests! Our first guest, Jessica Burn, has been working closely with CISOs and the security industry at Forrester where she is a Senior Analyst covering the role of the CISO, Incident Response, Zero Trust Strategy and Continuous Controls Monitoring. Dan, Erik, Brian and Jess use a new Forrester report about recommendations for security programs in 2021 as the basis for the discussion (and debate), including a few major themes: The impacts of the consolidation of technology, both in security and the wider tech arena Balancing the monitoring and the privacy when tracking employees as they work remotely as a result of the pandemic Securing what you sell both because you need to, but also because it is good for your business Where are our inventories and why do we still generally fail at knowing what systems we have Of course, third party risk management. It's a mandatory "slide 3" on every board presentation, of course. We still debate, we still discuss, we still shift the discussion to automotive and manufacturing from time to time, but now we have some additional voices to add to the debate, too. Thanks so much, Jess! Special Guest: Jessica Burn.
Exactly one year ago, most of the population of the US was given the word to begin to work from home. Security and technology teams were large parts of the preparation for this change, and were also largely able to move their operations to a home office for the duration of the last twelve months. The last year has been one of constant "on", whether due to changing technology requirements that need to be worked on, increasing incident and response, 10 hours per day in front of the camera on Zoom, and filling what used to be commutes with (wait for it) even more work. Dan, Brian and Erik cover a lot of topics, including security of remote work, the mental health impacts of prolonged working remotely, looking out for ourselves and those in our lives, and reconnecting with those that we may have lost contact with over the years. The guys also share positive and negative observations about work/life from the past year, too. Please subscribe and leave ratings or feedback in your favourite podcast application! It really helps the podcast out a lot when you do!
This week we look at the security organisation through the looking glass. From within the org, the leaders and the partners and product/service providers we work with, we dig into some of the ways that security works with the rest of the business and customers, and how the needs of each org changes over time and necessitates the need for different mindsets to support those needs from a security perspective. CISO tenure, churn and average age compared to other C-levels How security applies to business value (or sometimes not in the obvious ways) What's better on an RFP response? More detail, or just yes/no answers? CISOs (and all security professionals) as storytellers Relationships with security product vendors, VARs and others selling into organisations on how to build trust and transparency and turn from selling into true partnerships Also, Dan successfully makes an automotive analogy; you can't miss that! We name drop a few friends who have shared insights that led to our comments today. Check them out and give them wave and a thanks from us! John Bingham (https://www.linkedin.com/in/johnbingham/), Chief Operating Officer at Speak by Design (https://www.speakbydesign.com) Jeff Pollard (https://www.linkedin.com/in/jpollard96/), VP & Principal Analyst at Forrester - https://twitter.com/jeff_pollard2?s=20 Enjoy the episode.
It's Valentine's Day and you get presents. Dan, Brian and Erik discuss the books, people and tools that they each love and changed their lives. None are specifically security-related, so see what's been impactful on each of them in this episode. The links are an especially big part of the episode, so take a look in your podcast app or on the site (https://www.greatsecuritydebate.net/17) to see all the recommendations and get more info about the topics and items covered.
The time for job change happens and there are a lot of things go along with it including. We cover a ton of them in this week's episode: - The reasons to make a career change - Deciding the time is right to make a change (and how do you know) - Taking our own advice when it comes to our own career change - The importance of support of family to make more drastic changes - The power of self-reflection and the need to let go of the present to achieve the future - The importance of strong personal and community networking in career growth - Impostor syndrome - Certification overload in security and privacy - Letting someone you know that it may be time for them to make a change And the quote of the day is from The Great One, Wayne Gretsky - you miss 100% of the shots you don't take!
We are 9 months into a period in which many workers, including technology and security professionals, are still doing their jobs remotely. Some have moved away from their primary homes, often without letting their company know that this has happened. As business processes catch up with this change in approach, some companies are taking steps to a) formalise work from home as a more standard offering, b) determine how to pay people wherever they are in the country/world, c) decide if in-person culture is key to their ethos, and how to deal with the new focus on remote work. In this week's debate, Brian, Erik and Dan chat look at these topics from the pros and the cons, and what it could be like if everyone stays remote, the benefits and risks of geographically independent pay scales, and more. Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at feedback@greatsecuritydebate.net (mailto:feedback@greatsecuritydebate.net) or on Twitter at https://twitter.com/securitydebate
A few weeks ago, a company called SolarWinds was discovered to have had some bad actors in placing things in their technology (code) for a while. How did it happen? What does it mean to others? We don't know all the answers yet but we do know that it means we will have to make some changes to things like those universally hated security questionnaires, and how we manage our own source code to ensure better security. Along with a discussion about how cow stomachs relate to information security, and Brian's invoking of The Art of War, there's something for everyone in this epsiode. Propeller head warning - this one's a bit more security "inside baseball" than other episodes as we dig into the recent SolarWinds technology attack and some of the ways that the technology and security practitioners can address issues that have been identified. It's still a "for everyone" episode, but we do go a little more in depth that we usually do in some parts. Let us know what you think! Please take a moment and subscribe to the podcast in your preferred podcast application, and while you are there give soime feedback, either via a rating, or a comment, or both! We want to hear your feedback and ideas, so you can also email us at feedback@greatsecuritydebate.net (mailto:feedback@greatsecuritydebate.net) or on Twitter at https://twitter.com/securitydebate
One of the ways that companies have tried to improve education and awareness about the risks of phishing is the use of phishing tests to see if colleagues click on the link or open the suspect attachment in an unsuspecting yet controled environment. If they do, some instant education comes their way. There are those that think that this approach keeps the topic at the front of everyone's mind, and there are those that think that it can have the effect of chilling the relationship between IT/Security and the rest of the organisation. There are a lot of variables in the equation like how you respond when someone clicks on the phish, how you encourage reporting of potential phishing and more, so the answer is a resounding "it depends." We also cover some of the increased security challenges that come with the now more common "working remotely," and what happens when you walk into an empty castle after having gotten past the moat and door, but there is no one inside to defend it.
A regular complaint by those who consume and use technology is that security adds friction to their process, which often means they get frustrated at the control put in their path, curse technology in general, or abandon the activity altogether. In today's episode, Dan, Erik and Brian explore the balance necessary to understand when certain controls (and the friction they add) are necessary, or can be made smoother. Each decision on reduction of friction has the potential for knock-on effects to the security, privacy and performance of the system and should be considered before making any change to the control. In some cases the conscious addition of friction is the better approach, too, especially to support transparency with users and enable meaningful, informed choices.
When bad things happen to the computers in your organisation, who is the first person you call? IT, the FBI, your general counsel, the insurance company? Today, Erik, Dan and Brian cover attacks, response and middle people negotiating with the attackers on your behalf. Other topics discussed include: - The risk of cheap IoT devices and long term support (or lack thereof), - Whose insurance policy covers the tree on your neighbour's land that falls and hits your house, - The law of unintended consequences when creating things, and - The joy of reading fake Amazon reviews
So many movies about technology and security, so little time. We start our with some of our favourite (and least favourite) security movies. We also wander into a few other areas including: data use and ethics, balancing when to let an attack happen vs. when to let it happen to not let on that you know, Shodan, Stuxnet, Wannacry and more. Check out the complete list of movies we discuss and mention in the links list below!
In what will surely become a recurring topic, the discussion turns to the short-term vs. long-term implications of privacy decisions we each make, the ethics of collecting and using data, and whether a European model of privacy (or data protection as Dan reiterates we should be calling it) would help in the US. We ask why we can't stop needing instant replies and gratification, is the value of the services we get worth the tradeoff for the data we are "paying" in order to use them, and more. Erik even beats Dan to be the first to use his "It Depends" catchphrase, so you know it's going to be a lively discussion. Privacy is on everyone's mind these days, and it's the topic of The Great Security Debate today.
The school year is upon us. This week Erik, Brian and Dan are talking about things related to security and education. First, we cover the ongoing dilemma of which is better to establish and grow your career in security: certifications or experience. We also debate how traditional education (aka degrees) fit into the equation, and how to jump in if you have neither formal experience nor education and want to join the field... you'd never have guessed but "it depends!" Finally we talk about the challenges that K12 districts have managing security and privacy in normal times, let alone in the recent rush to move to remote learning so quickly. We also spent a lot of time on mentoring and reaching out to people who are in the field for help, and some resources you can go to for info on mentoring, and the reminder that if you had mentors and those who helped you get where you are, to give back to those who will carry the torch next. Links to resources are in the links below.
Ransomware is increasing. Brian, Dan and Erik discuss the evolution of ransomware, the preparation and the response, and the debate about whether to pay the ransom or not.
On the debate today: it was overheard (over-read?) by one of the crew that security leaders and teams shoudl stop whining when security is not a “superstar” part of the business, but rather should focus on being a reliable supporting act that is there to prop up the actual “superstars.” There was a flawed comparison in this same read to the relationship between Scottie Pippen and Michael Jordan on the Chicago Bulls of the 90s. In the course of this episode we cover the “best” place for the security organisation to live, the need for CISOs and their teams to be at the table vs. the backoffce, quotes from Colin Powell and more.
Dan, Brian and Erik discuss the pros and cons of managed services for security vs. building similar capability internally, best of breed security vs. suite (for the 5th time since 1995), and education and awareness. Visit our website at https://www.greatsecuritydebate.net Contact us at feedback@greatsecuritydebate.net Follow us on Twitter at https://twitter.com/securitydebate
Dan, Brian and Erik debate the pros and cons to starting a product (or even a project) fully focused on hitting MVP (minimum viable product) or focusing more on TSP (totally secure product). Spoiler alert: it's somewhere in the middle! Also covered: the importance of support, defence vs response, and the mission of the podcast. Visit our website at https://www.greatsecuritydebate.net Contact us at feedback@greatsecuritydebate.net Follow us on Twitter at https://twitter.com/securitydebate
Dan, Brian and Erik discuss how to talk about security in ways that encourage end users to understand security and want to be part of the process, and the challenges of selling security products into security organisations. Visit our website at https://www.greatsecuritydebate.net Contact us at feedback@greatsecuritydebate.net Follow us on Twitter at https://twitter.com/securitydebate
Episode 1: Privacy Drone. Dan, Brian and Erik discuss expectation of privacy; privacy as a business enabler; transparency and ethical increase of privacy and how much should leaders and legislators understand privacy innately. Visit our website at https://www.greatsecuritydebate.net Contact us at feedback@greatsecuritydebate.net Follow us on Twitter at https://twitter.com/securitydebate