Encore seasons of the popular CyberWire Pro podcast hosted by Chief Analyst, Rick Howard. Join Rick and the Hash Table experts as they discuss the ideas, strategies and technologies that senior cybersecurity executives wrestle with on a daily basis. For the latest seasons ad-free along with essays, transcripts, and bonus content, sign up for CyberWire Pro.
Rick Howard, N2K’s CSO and The CyberWire’s Chief Analyst and Senior Fellow, discusses the latest developments in mapping the MITRE ATT&CK(R) wiki to your deployed security stack with guests James Stanley, section chief at the U.S. Cybersecurity and Infrastructure Security Agency, John Wunder, Department Manager for Cyber Threat Intelligence and Adversary Emulation at MITRE, and Steve Winterfeld, Akamai’s Advisory CISO. Howard, R., Olson, R., 2020. Implementing Intrusion Kill Chain Strategies by Creating Defensive Campaign Adversary Playbooks [Journal Article]. The Cyber Defense Review. URL https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/2420129/implementing-intrusion-kill-chain-strategies-by-creating-defensive-campaign-adv/ Staff, 2023. The Ultimate Guide to Sigma Rules [Blog]. THE GRAYLOG BLOG. URL https://graylog.org/post/the-ultimate-guide-to-sigma-rules/ Seuss, Dr., 1990. Oh, the Places You’ll Go! [Book]. Goodreads. URL https://www.goodreads.com/book/show/191139.Oh_the_Places_You_ll_Go_?ref=nav_sb_ss_1_14 Beriro, S., ishmael, stacy-marie, 2023. Crypto Hackers Stole Record Amount in 2022, Fueled by North Korea’s Lazarus [Podcast]. Bloomberg. URL https://www.bloomberg.com/news/articles/2023-02-23/crypto-hackers-stole-record-amount-in-2022-fueled-by-north-korea-s-lazarus cisagov, 2023. Decider: A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK® framework. [Code Repository]. GitHub. URL https://github.com/cisagov/Decider/ Hutchins, E., Cloppert, M., Amin, R., 2010. Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains [White Paper]. Lockheed Martin. URL https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf JupiterDoc, 2011. Law & Order Full Theme (High Quality) [Theme]. YouTube. URL https://www.youtube.com/watch?v=xz4-aEGvqQM Nickels, K, 2019. Introduction to ATT&CK Navigator [Video]. YouTube. URL https://www.youtube.com/watch?v=pcclNdwG8Vs Page, C., 2022. US officials link North Korean Lazarus hackers to $625M Axie Infinity crypto theft [website]. TechCrunch. URL https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/ Page, C., 2022. North Korean Lazarus hackers linked to $100M Harmony bridge theft [Website]. TechCrunch. URL https://techcrunch.com/2022/06/30/north-korea-lazarus-harmony-theft/ Staff, n.d. Lazarus Group (G0032) [Wiki]. Mitre ATT&CK Navigator. URL https://mitre-attack.github.io/attack-navigator//#layerURL=https%3A%2F%2Fattack.mitre.org%2Fgroups%2FG0032%2FG0032-enterprise-layer.json Staff, n.d. Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Group G0032 [Wiki]. MITRE ATT&CK®. URL https://attack.mitre.org/groups/G0032/ Staff, n.d. Lazarus Group [Wiki]. Tidal Cyber. URL https://app.tidalcyber.com/groups/0bc66e95-de93-4de7-b415-4041b7191f08-Lazarus%20Group Staff, January 2023. Best Practices for MITRE ATT&CK® Mapping [White Paper]. Cybersecurity and Infrastructure Security Agency (CISA). URL https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping Staff, March 2023. CISA Releases Decider Tool to Help with MITRE ATT&CK Mapping [Announcement]. Cybersecurity and Infrastructure Security Agency (CISA). URL https://www.cisa.gov/news-events/alerts/2023/03/01/cisa-releases-decider-tool-help-mitre-attck-mapping Staff, n.d. List of top Cryptocurrency Companies - Crunchbase Hub Profile [Website]. Crunchbase. URL https://www.crunchbase.com/hub/cryptocurrency-companies Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., Thomas, C.B., 2020. ATTACK Design and Philosophy March 2020 Revision [White Paper]. Mitre. URL https://www.mitre.org/sites/default/files/publications/pr-18-0944-11-mitre-attack-design-and-philosophy.pdf
Rick Howard, the CSO, Chief Analyst, and Senior Fellow at N2K Cyber, discusses the current state of cybersecurity risk forecasting with guests Fred Kneip, CyberGRX’s founder and President of ProcessUnity, and Kevin Richards, Cyber Risk Solutions President. Howard, R., 2023. Cybersecurity First Principles: A Reboot of Strategy and Tactics [Book]. Wiley. URL: https://www.amazon.com/Cybersecurity-First-Principles-Strategy-Tactics/dp/1394173083. Howard, R., 2023. Bonus Episode: 2023 Cybersecurity Canon Hall of Fame inductee: Superforecasting: The Art and Science of Prediction by Dr Phil Tetlock and Dr Dan Gardner. [Podcast]. The CyberWire. URL https://thecyberwire.com/podcasts/cso-perspectives/5567/notes Howard, R., 2022. Risk Forecasting with Bayes Rule: A practical example. [Podcast]. The CyberWire. URL https://thecyberwire.com/podcasts/cso-perspectives/88/notes Howard, R, 2023. Superforecasting: The Art and Science of Prediction [Book review]. Cybersecurity Canon Project. URL icdt.osu.edu/superforecasting-art-and-science-prediction. Howard, R., 2022. Two risk forecasting data scientists, and Rick, walk into a bar. [Podcast]. The CyberWire. URL https://thecyberwire.com/podcasts/cso-perspectives/89/notes Howard, R., Freund, J., Jones, J., 2016. 2016 Cyber Canon Inductee - Measuring and Managing Information Risk: A FAIR approach [Interview]. YouTube. URL https://www.youtube.com/watch?v=vxBpAnSBaGM Hubbard , D.W., Seiersen, R., 2016. How to Measure Anything in Cybersecurity Risk [Book]. Goodreads. URL https://www.goodreads.com/book/show/26518108-how-to-measure-anything-in-cybersecurity-risk Clark, B., Seiersen , R., Hubbard, D., 2017. “How To Measure Anything in Cybersecurity Risk” - Cybersecurity Canon 2017 [Interview]. YouTube. URL https://www.youtube.com/watch?v=2o_mAavdabg&t=93s Freund, J., Jones, J., 2014. Measuring and Managing Information Risk: A FAIR Approach [Book]. Goodreads. URL https://www.goodreads.com/book/show/22637927-measuring-and-managing-information-risk Katz, D., 2021. Corporate Governance Update: “Materiality” in America and Abroad [Essay]. The Harvard Law School Forum on Corporate Governance. URL https://corpgov.law.harvard.edu/2021/05/01/corporate-governance-update-materiality-in-america-and-abroad/ Posner, C., 2023. SEC Adopts Final Rules on Cybersecurity Disclosure [Essay]. The Harvard Law School Forum on Corporate Governance. URL https://corpgov.law.harvard.edu/2023/08/09/sec-adopts-final-rules-on-cybersecurity-disclosure/ Linden, L.V., Kneip, F., Squier, Suzie , 2022. Threats Across the Globe & Benchmarking with CyberGRX [Podcast]. Retail & Hospitality ISAC Podcast. URL https://pca.st/a49enjb1 Lizárraga, C.J., 2023. Improving the Quality of Cybersecurity Risk Management Disclosures [Essay]. U.S. Securities and Exchange Commission. URL https://www.sec.gov/news/statement/lizarraga-statement-cybersecurity-072623 Staff, 2022. Benchmarking Cyber-Risk Quantification [Survey]. Gartner. URL https://www.gartner.com/en/publications/benchmarking-cyber-risk-quantification Tetlock, P.E., Gardner, D., 2015. Superforecasting: The Art and Science of Prediction [Book]. Goodreads. URL https://www.goodreads.com/book/show/23995360-superforecasting Winterfeld, S., 2014. How to Measure Anything in Cybersecurity Risk [Book review]. Cybersecurity Canon Project. URL https://icdt.osu.edu/how-measure-anything-cybersecurity-risk
Rick Howard, The CSO, Chief Analyst, and Senior Fellow at N2K Cyber, discusses the current state of Distributed Denial of Service (DDOS) prevention with CyberWire Hash Table guests Steve Winterfeld, Akamai’s Field CSO, and Jim Gilbert, Akamai’s Director Product Management, and Rick Doten, the CISO for Healthcare Enterprises and Centene. Howard, R., 2023. Cybersecurity First Principles: A Reboot of Strategy and Tactics [Book]. Wiley. URL: https://www.amazon.com/Cybersecurity-First-Principles-Strategy-Tactics/dp/1394173083. Azure Network Security Team, 2023. 2022 in review: DDoS attack trends and insights [Website]. Microsoft Security Blog. URL https://www.microsoft.com/en-us/security/blog/2023/02/21/2022-in-review-ddos-attack-trends-and-insights/ Howard, R., 2014. Fatal System Error [Book Review]. Cybersecurity Canon Project. URL https://icdt.osu.edu/fatal-system-error Mashable, 2019. The World’s First Cyber Crime: The Morris Worm [KERNEL PANIC] [Video]. YouTube. URL https://www.youtube.com/watch?v=o2dj2gnxjtU (accessed 8.8.23). Montgomery, D., Sriram, K., Santay, D.J., 2022. Advanced DDoS Mitigation Techniques [Website]. NIST. URL https://www.nist.gov/programs-projects/advanced-ddos-mitigation-techniques. Schomp, K., Bhardwaj, O., Kurdoglu, E., Muhaimen, M., Sitaraman, R.K., 2020. Akamai DNS: Providing Authoritative Answers to theWorld’s Queries [Conference Paper]. Proceedings of the Annual conference of the ACM Special Interest Group on Data Communication on the applications, technologies, architectures, and protocols for computer communication. URL https://groups.cs.umass.edu/ramesh/wp-content/uploads/sites/3/2020/07/sigcomm2020-final289.pdf Sparling, C., Gebhardt, M., 2022. The Relentless Evolution of DDoS Attacks [Blog]. Akamai Technologies. URL https://www.akamai.com/blog/security/relentless-evolution-of-ddos-attacks. Staff, January 2023. The Evolution of DDoS: Return of the Hacktivist [Akamai White Paper]. FS-ISAC. URL https://www.fsisac.com/akamai-ddos-report. Staff , 2023. 2023 The Edge Ecosystem [White Paper]. AT&T Cybersecurity. URL https://cybersecurity.att.com/resource-center/infographics/2023-securing-the-edge. Winterfeld, S., 2023. Ransomware on the Move: Evolving Exploitation Techniques and the Active Pursuit of Zero-Days [Website]. Akamai Technologies. URL https://www.akamai.com/blog/security/ransomware-on-the-move-evolving-exploitation-techniques Radware, 2012. DNS Amplification Attack [Video. YouTube. URL https://www.youtube.com/watch?v=xTKjHWkDwP0 Chickowski, E., 2020. Types of DDoS attacks explained [Website]. AT&T Cybersecurity. URL https://cybersecurity.att.com/blogs/security-essentials/types-of-ddos-attacks-explained Nilsson, J., 2010. The Book of Numbers: A History of the Telephone Book [Website]. The Saturday Evening Post. URL https://www.saturdayeveningpost.com/2010/02/book-numbers
Rick Howard, the CSO, Chief Analyst, and Senior Fellow at N2K Cyber, discusses the meaning of quantum computing through a cybersecurity perspective with CyberWire Hash Table guests Dr. Georgian Shea, Chief Technologist at the Foundation for Defense of Democracies, and Jonathan Franz, the Chief Information Security Officer at ISC2. Research contributors include Bob Turner, Fortinet’s Field CISO – Education, Don Welch, New York University CIO, Rick Doten, CISO at Healthcare Enterprises and Centene, and Zan Vautrinot, Major General - retired. Howard, R., 2023. Cybersecurity First Principles: A Reboot of Strategy and Tactics [Book]. Wiley. URL: https://www.amazon.com/Cybersecurity-First-Principles-Strategy-Tactics/dp/1394173083. Deen, S., 2008. 007 | Quantum of Solace | Theme Song [Video]. YouTube. URL https://www.youtube.com/watch?v=YMXT3aJxH_A Dungey, T., Abdelgaber, Y., Casto, C., Mills, J., Fazea, Y., 2022. Quantum Computing: Current Progress and Future Directions [Website]. EDUCAUSE . URL https://er.educause.edu/articles/2022/7/quantum-computing-current-progress-and-future-directions. France, J., 2023. Quantum Compute and CyberSecurity, in: ISC2 Secure Summits. France, J., 2023. The Race Against Quantum: It’s Not Too Late to be the Tortoise that Beat the Hare [Essay]. Infosecurity Magazine. URL https://www.infosecurity-magazine.com/opinions/race-quantum-tortoise-beat-hare/. Shea, Dr.G., Fixler, A., 2022. Protecting and Securing Data from the Quantum Threat [Technical Note]. Foundation for the Defense of Democracies. URL https://www.fdd.org/wp-content/uploads/2022/12/fdd-ccti-protecting-and-securing-data-from-the-quantum-threat.pdf
Rick Howard, The CSO, Chief Analyst, and Senior Fellow at N2K Cyber, discusses cybersecurity first principle strategies with CJ Moses, CISO of AWS. Howard, R., 2023. Cybersecurity First Principles: A Reboot of Strategy and Tactics [Book]. Wiley. URL: https://www.amazon.com/Cybersecurity-First-Principles-Strategy-Tactics/dp/1394173083. Staff, 2022. AWS Security Profile: CJ Moses, CISO of AWS [Bio]. Amazon Web Services. URL https://aws.amazon.com/blogs/security/aws_security_profile_cj_moses_ciso_of_aws/
The 2014 OPM hack: We can use cyber sand tables to enhance our cybersecurity first principle defenses since the concept, in various forms, have been used by military commanders, coaches, and athletes since the world was young. The show puts the OPM hack on the cyber sand table to see what might have been done differently. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic. To access CyberWIre Pro only bonus material for CSO Perspectives, listen here.
Rick Howard, the CyberWire’s CSO and Chief Analyst, is joined by Hash Table member Amanda Fennell, the Relativity CIO and CSO, to discuss strategies and tactics to reduce digital supply chain risk. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
Rick explains the history of digital supply chains and the potential future of securing them. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
Rick Howard, the CyberWire’s CSO and Chief Analyst, chats with Steve Winterfeld, the Akamai Advisory CISO, and Errol Weiss, the Health-ISAC CSO, about recommended sources of infosec content that they found valuable in 2021. Links to content mentioned in the show: Documentaries “Kill Chain: The Cyber War on America’s Elections,” by Harri Hursti, Published by HBO, 26 March 2020. “The Perfect Weapon.” by David Sanger, Published by HBO, 16 October 2020. Podcasts “Darknet Diaries – True Stories from the Dark Side of the Internet,” by Darknetdiaries.com, 25 January 2022. “The Lazarus Heist,” BBC, 2021. Books “Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers,” by Andy Greenberg, Published by Doubleday, 7 May 2019. “This Is How They Tell Me the World Ends the Cyberweapons Arms Race,” by Nicole Perlroth, Published by Bloomsbury Publishing 9 February 2021. Author Interviews “A Conversation with Nicole Perlroth, Author of ‘This Is How They Tell Me the World Ends,’” American Writers Museum, YouTube, 2 March 2021. “Andy Greenberg - Sandworm: Lessons from the Cyberwar,” by CS3STHLM, YouTube, 25 October 2021. “Bonus: Cybersecurity Canon Hall of Fame Interview with Andy Greenberg,” By Rick Howard, The CyberWire, 12 July 12 2021. “‘Sandworm’ Author Andy Greenberg,” by David Bittner, The CyberWire, 11 November 2019. Video Content “LockPickingLawyer.” YouTube, 2022. “RSA Conference.” YouTube, 2022. Twitter Subject Matter Experts Phil Venables (@philvenables) Bonus - Gate 15 / Andy Jabbour (@Gate_15_Analyst) Errol Weiss (@errolw65) Rick Howard (@raceBannon99) News and Topic Summaries “Daily Briefing.” The CyberWire, 2022. “SmartBrief.” SmartBrief, 2018.
For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
Rick recommends podcasts and books that he found valuable in 2021, and makes the case for why reading books and listening to podcasts makes security professionals better students of the cybersecurity game. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
In this “Rick the Toolman” episode, Rick interviews Steve Winterfeld, from Akamai, on the current state and future of the Mitre ATT&CK Framework. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
In this “Rick the Toolman” episode, Rick interviews Jon Oltsik, from the Enterprise Strategy Group, on the current state and future of XDR. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
In this “Rick the Toolman” episode, Rick breaks down XDR in terms that busy security executives can understand and apply to their first principle security strategy. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
In this episode of CSO Perspectives, Rick Howard examines the MITRE ATT&CK® framework for the security executive. Rick explains how your infosec team can use it to support your intrusion kill chain strategy. More importantly, Rick describes the framework in terms that busy security executives can understand. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
The 2016 DNC hack: We can use cyber sand tables to enhance our cybersecurity first principle defenses since the concept, in various forms, have been used by military commanders, coaches, and athletes since the world was young. The show puts the DNC hack on the cyber sand table to see what might have been done differently with host Rick Howard, the CyberWire’s CSO and Chief Analyst. For a complete reading list and even more information, check out Rick’s more detailed essay on the topic.
Security compliance is a cybersecurity first principle strategy. Can security compliance add value to your organization as a first principle strategy? Or is it a distraction? In this session, we learn about the value of technology compliance and compliance technologies. Rick digs into the fundamentals of compliance and reviews case studies that reveal the potential material impact to your organization due to a compliance incident. As Rick says, “Compliance is a ticket to ride.” On the Hash Table, Tom Quinn of T. Rowe Price argues for why compliance is both good for business and good for security. Cybersecurity professional development and continued education. You will learn about: privacy and security compliance, compliance support services, the value of investing in compliance, CyberWire’s spreadsheet of cybersecurity laws and standards CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more compliance and cybersecurity first principles resources, check the topic essay.
Security compliance is a cybersecurity first principle strategy. Can security compliance add value to your organization as a first principle strategy? Or is it a distraction? In this session, we learn about the value of technology compliance and compliance technologies. Rick digs into the fundamentals of compliance and reviews case studies that reveal the potential material impact to your organization due to a compliance incident. As Rick says, “Compliance is a ticket to ride.” Cybersecurity professional development and continued education. You will learn about: privacy and security compliance, compliance support services, the value of investing in compliance, CyberWire’s spreadsheet of cybersecurity laws and standards CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more compliance and cybersecurity first principles resources, check the topic essay.
Adversary playbooks as a cybersecurity first principle strategy. They told us the adversary has an asymmetric advantage; that cyber defense has to be right every time while the offense only has to get it right once. Rick proves that proactive defense and adversary playbooks can flip that dynamic on its head. With the world of cyber defense and threat intelligence upside down, Rick and the Hash Table discuss the history of shifting the offense/defense balance, the three components of a proactive defense, and the evolution of adversary playbooks and the intrusion kill chain. with Rick Howard, the CyberWire’s CSO and Chief Analyst, joined by Ryan Olson, the Palo Alto Networks VP on Threat Intelligence (Unit 42). They discuss the history and next steps for the adversary playbook concept. Cybersecurity professional development and continued education. You will learn about: adversary playbooks and proactive defense, flipping the offense/defense balance, the 3 components of a proactive defense, ISACs and ISAOs CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more adversary playbooks and cybersecurity first principles resources, check the topic essay.
Adversary playbooks as a cybersecurity first principle strategy. They told us the adversary has an asymmetric advantage; that cyber defense has to be right every time while the offense only has to get it right once. Rick proves that proactive defense and adversary playbooks can flip that dynamic on its head. Cybersecurity professional development and continued education. You will learn about: adversary playbooks and proactive defense, flipping the offense/defense balance, the 3 components of a proactive defense, ISACs and ISAOs CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more adversary playbooks and cybersecurity first principles resources, check the topic essay.
Orchestrating the security stack is a cybersecurity first principle strategy. Our security stack has grown unwieldy. The complexity breeds vulnerability. Orchestration may be our only hope. Rick reviews SOAR/SIEM platforms, SASE, and DevSecOps strategies from the perspective of orchestrating the security stack. He discovers key methods to build zero trust, intrusion kill chain prevention, resiliency, and risk forecasting within these tools. The Hash Table identifies data governance and policy strategy as a crucial first step. They also talk about the first principles of speaking with the C-suite, as well as the darkside of automation and orchestration. With Rick Howard, the CyberWire’s CSO and Chief Analyst, joined by Bob Turner, the Fortinet Field CISO for Education, and Kevin Magee, the CSO for Microsoft Canada, discuss orchestration as a first principle strategy. Cybersecurity professional development and continued education. You will learn about: SOAR/SIEM and SASE for large scale orchestration, data governance, the three components of a good SASE platform, data materiality and gap analyses, the dark side of automation CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more orchestration and cybersecurity first principles resources, check the topic essay.
Orchestrating the security stack is a cybersecurity first principle strategy. Our security stack has grown unwieldy. The complexity breeds vulnerability. Orchestration may be our only hope. Rick reviews SOAR/SIEM platforms, SASE, and DevSecOps strategies from the perspective of orchestrating the security stack. He discovers key methods to build zero trust, intrusion kill chain prevention, resiliency, and risk forecasting within these tools. Cybersecurity professional development and continued education. You will learn about: SOAR/SIEM and SASE for large scale orchestration, data governance, the three components of a good SASE platform, data materiality and gap analyses, the dark side of automation CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more orchestration and cybersecurity first principles resources, check the topic essay.
Enterprise backups as a cybersecurity first principle strategy. This session covers the riveting topic of enterprise backup schemes to improve resilience. Rick discusses the value of data backups, workflow models, recent ransomware trends, and platforms for each use case. The Hash Table provides tangible enterprise backup strategies that encompass centralized, decentralized, and DevSecOps techniques, business continuity and disaster recovery plans, and engaging the Executive team in crisis scenarios and recovery training. In data backups, nothing is easy, but Rick breaks it down to first principles and makes it understandable. With Rick Howard, the CyberWire’s CSO and Chief Analyst, joined by Jerry Archer, the Sallie Mae CSO, and Jaclyn Miller, the CISO for NTT, discuss enterprise backups as a first principle strategy. Cybersecurity professional development and continued education. You will learn about: backup tools and platforms, workflow responsibilities and models, disaster recovery and business continuity plans, backups as a tool to improve resilience CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more enterprise backups and cybersecurity first principles resources, check the topic essay.
Enterprise backups as a cybersecurity first principle strategy. This session covers the riveting topic of enterprise backup schemes to improve resilience. Rick discusses the value of data backups, workflow models, recent ransomware trends, and platforms for each use case. In data backups, nothing is easy, but Rick breaks it down to first principles and makes it understandable. Cybersecurity professional development and continued education. You will learn about: backup tools and platforms, workflow responsibilities and models, disaster recovery and business continuity plans, backups as a tool to improve resilience CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more enterprise backups and cybersecurity first principles resources, check the topic essay.
Enterprise encryption is a cybersecurity first principle strategy. Encryption is like mortar to our first principle wall. It holds together resilience and zero trust for material data. Rick explains the history of famous cryptographic techniques, dives into SolarWinds as an example of zero trust and encryption failure, and identifies some strategies to help implement encryption for data at rest and data in motion. The Hash Table reveals a risk-based approach to deploying encryption and makes a solid case for extensive enterprise encryption to defend against ransomware extortion. With Rick Howard, the Cyberwire’s CSO and Chief Analyst, joined by Don Welch, the Penn State University Interim VP for IT and CIO, and Wayne Moore, the Simply Business CISO discuss Enterprise encryption as a first principle strategy. Cybersecurity professional development and continued education. You will learn about: cryptographic techniques, data at rest and in motion, encryption for data islands, open source and commercial encryption tools, protection against ransomware and extortion. CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more encryption and cybersecurity first principles resources, check the topic essay.
Enterprise encryption is a cybersecurity first principle strategy. Encryption is like mortar to our first principle wall. It holds together resilience and zero trust for material data. Rick explains the history of famous cryptographic techniques, dives into SolarWinds as an example of zero trust and encryption failure, and identifies some strategies to help implement encryption for data at rest and data in motion. Cybersecurity professional development and continued education. You will learn about: cryptographic techniques, data at rest and in motion, encryption for data islands, open source and commercial encryption tools, protection against ransomware and extortion. CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more encryption and cybersecurity first principles resources, check the topic essay.
Rick Howard, the CyberWire’s CSO and Chief Analyst, is joined by Hash Table members Gary McAlum, former USAA CSO, and Dawn Cappelli, the Rockwell Automation CISO, to discuss CxO professional development.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Helen Patton, CISO for Duo Security’s Advisory, and Nikk Gilbert, CISO for the Cherokee Nation Businesses, to discuss how to buy security products.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Ann Johnson, Microsoft’s Corporate VP on Security, Compliance, & Identity, and Ted Wagner, the SAP National Security Services CISO, t0 discuss supply chain as a new CISO responsibility.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Jerry Archer, Sallie Mae's CSO, and Greg Notch, the National Hockey League's CISO, to discuss identity as a new CISO responsibility.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Bob Turner, University of Wisconsin at Madison CISO, and Tom Quinn, T. Rowe Price CISO, to discuss IoT as new CISO responsibilities.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Helen Patton, Duo Security at Cisco Advisory CISO, Steve Winterfeld, Akamai Advisory CISO, and Marc Sachs, Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security's Deputy Director for Research, to discuss cybersecurity strategies and tactics in the energy sector.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Denise Anderson, Health-ISAC President and CEO, Errol Weiss, Health-ISAC CSO, and Rick Doten, Carolina Complete Health CISO, to discuss cybersecurity strategies and tactics in healthcare.
Rick Howard, the Cyberwire’s CSO and Chief Analyst, is joined by Hash Table members Gary McAlum, USAA’s former CSO, Jerry Archer, Sallie Mae’s CSO, and Steve Winterfeld, Akamai’s Advisory CISO, to discuss cybersecurity strategies in finance and antifraud.
Third party cloud platforms as a cybersecurity first principle strategy. As we learned from the deep dive into Azure, AWS, and GCP, none of the primary cloud providers check the box for every security first principle. To do so, Rick looks at third party cloud security providers. In this session, Rick and the Hash Table discuss big security platforms like Fortinet, Cisco, Check Point, and Palo Alto Networks. We discover that comprehensive security orchestration across all data islands is the key, so much so that Rick adds orchestration as one of the five primary first principles. With Rick Howard, the Cyberwire’s CSO and Chief Analyst and three guests: Ram Boreda, a Palo Alto Networks Field CTO, Joakim Lialias, a Product Marketing Director at Cisco, and Ashish Rajan, the host of the Cloud Security Podcast. Cybersecurity professional development and continued education. You will learn about: third party security platforms as first principle tools, cloud security orchestration, virtual firewalls and first principle strategies, converging cloud security tools into a single platform CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more third party cloud platforms and cybersecurity first principles resources, check the topic essay.
Third party cloud platforms as a cybersecurity first principle strategy. As we learned from the deep dive into Azure, AWS, and GCP, none of the primary cloud providers check the box for every security first principle. To do so, Rick looks at third party cloud security providers. In this session, Rick discusses big security platforms like Fortinet, Cisco, Check Point, and Palo Alto Networks. We discover that comprehensive security orchestration across all data islands is the key, so much so that Rick adds orchestration as one of the five primary first principles. Cybersecurity professional development and continued education. You will learn about: third party security platforms as first principle tools, cloud security orchestration, virtual firewalls and first principle strategies, converging cloud security tools into a single platform CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more third party cloud platforms and cybersecurity first principles resources, check the topic essay.
Google Cloud Platform (GCP) adoption with cybersecurity first principle strategies. In this session looking at cloud platforms through the lens of first principle thinking, Rick and the Hash Table review the Google Cloud Platform (GCP). They identify some fundamental architectural differences between GCP and the other cloud providers that make GCP more effective at zero trust. The Hash Table gives their detailed technical advice about data management and risk assessments through GCP, strategies using GCP to support cybersecurity, and define our new favorite concepts: cyber shenanigans, conditions of weirdness (COWs), and cyber COW tipping. Bob Turner joins Rick at the Cyberwire’s Hash Table to discuss securing the University of Wisconsin at Madison’s big data lake project using the Google Cloud Platform (GCP) and the GCP zero trust architecture: BeyondCorp. Cybersecurity professional development and continued education. You will learn about: GCP networking, GCP security strategy and data management, cyber shenanigans, conditions of weirdness (COWs), and cyber COW-tipping CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Google Cloud Platform and cybersecurity first principles resources, check the topic essay.
Google Cloud Platform (GCP) adoption with cybersecurity first principle strategies. In this session looking at cloud platforms through the lens of first principle thinking, Rick Howard reviews the Google Cloud Platform (GCP). He identifies some fundamental architectural differences between GCP and the other cloud providers that make GCP more effective at zero trust. Cybersecurity professional development and continued education. You will learn about: GCP networking, GCP security strategy and data management, BeyondCorp CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Google Cloud Platform and cybersecurity first principles resources, check the topic essay.
Amazon AWS adoption with cybersecurity first principle strategies. In this second session reviewing cloud platforms through the lens of first principle thinking, Rick and the Hash Table review Amazon Web Services (AWS). They discuss how AWS supports, or doesn’t support, strategies of resilience, zero trust, intrusion kill chains, and risk assessments. The Hash Table gives their detailed technical experiences and strategies using AWS to support cybersecurity. Jerry Archer, Merritt Baer, and Mark Ryland join Rick around the Hash Table. Cybersecurity professional development and continued education. You will learn about: AWS networking and API techniques, DevSecOps in a cloud environment, AWS services and security tools, AWS strategies that support cybersecurity first principles. CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Amazon AWS and cybersecurity first principles resources, check the topic essay.
Amazon AWS adoption with cybersecurity first principle strategies. In this second session reviewing cloud platforms through the lens of first principle thinking, Rick Howard reviews Amazon Web Services (AWS). He discusses how AWS supports, or doesn’t support, strategies of resilience, zero trust, intrusion kill chains, and risk assessments. Cybersecurity professional development and continued education. You will learn about: AWS networking and API techniques, DevSecOps in a cloud environment, AWS services and security tools, AWS strategies that support cybersecurity first principles. CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Amazon AWS and cybersecurity first principles resources, check the topic essay. Selected Reading:
S1E6: 11 MAY: Cybersecurity First Principles
S1E7: 18 MAY: Cybersecurity first principles: zero trust
S1E8: 26 MAY: Cybersecurity first principles: intrusion kill chains.
S1E9: 01 JUN: Cybersecurity first principles - resilience
S1E11: 15 JUN: Cybersecurity first principles - risk
S2E7: 31 AUG: Identity Management: a first principle idea.
S2E8: 07 SEP: Identity Management: around the Hash Table.
S4E3: 25 JAN: Microsoft Azure through a first principle lens
S4E4: 01 FEB: Microsoft Azure security (Hashtable Interviews)
“5 Best Practices for Resiliency Planning Using AWS | Amazon Web Services,” Amazon Web Services, 7 October 2020.
“6 Best Practices for Increasing Security in AWS in a Zero Trust World.” by Louis Columbus, Forbes, 4 January 2019.
“About: History,” Cloud Security Alliance.
“A Brief History of AWS,” by Alec Rojasm, Media Temple, 31 August 2017.
“Amrandazz/Attack-Guardduty-Navigator.” by amrandazz, GitHub, 2021.
“AWS Networking and Security 101,” by Net Joints, YouTube Video, 2020.
“AWS Networking Fundamentals,” by Amazon Web Services, YouTube Video, 2019.
“AWS Training and Certification,” by Aws.training, 2021.
“Exposed Azure Bucket Leaked Passports, IDs of Volleyball Reporters,” by Ax Sharma, BleepingComputer, February 2021.
“How to Connect Your On-Premises Active Directory to AWS Using AD Connector | Amazon Web Services,” by Amazon Web Services, 6 July 2015.
“How to Think about Zero Trust Architectures on AWS | Amazon Web Services.” by Amazon Web Services, 20 January 2020.
“Leaky AWS S3 Buckets Are so Common, They’re Being Found by the Thousands Now – with Lots of Buried Secrets,” by Shaun Nichols, Shaun, Theregister.com, 3 August 2020.
“Network Address Translation (NAT) - GeeksforGeeks,” by GeeksforGeeks, 7 May 2018.
“Zero Trust Architectures: An AWS Perspective | Amazon Web Services,” by Amazon Web Services, 3 November 2020.
Microsoft Azure adoption with cybersecurity first principle strategies. The cloud revolution is here. How well can we implement our first principle strategies within each environment? Do we need to embrace other security platforms to get it done? In this session, Rick and the Hash Table review Microsoft Azure through the lens of first principle thinking. They review how Azure supports, or doesn’t support, strategies of resilience, zero trust, intrusion kill chains, and risk assessments. The Hash Table gives their detailed technical experiences and strategies using Azure to support cybersecurity. Two members of the CyberWire’s Hash Table of experts - Rick Doten, Carolina Complete Health CISO and Mark Simos, Microsoft’s Lead Cybersecurity Architect - discuss Microsoft Azure security through a first principle lens. Can Azure deployments satisfy our requirements for zero trust, intrusion kill chain prevention, resilience, and risk assessment? Cybersecurity professional development and continued education. You will learn about: Microsoft Azure services and security tools, infrastructure as code, Azure strategies that support cybersecurity first principles CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Microsoft Azure and cybersecurity first principles resources, check the topic essay. Selected Reading:
S1E9: 01 JUN: Cybersecurity first principles – resilience.
“A Look Back At Ten Years Of Microsoft Azure,” by Janakiram, Forbes, 3 February 2020.
“Azure AD Overview,” by John Savill, YouTube, 2020.
“Azure Security Benchmark,” msmbaldwin, Microsoft.com, 2021.
“Azure Virtual Network FAQ,” KumudD, Microsoft.com, 26 June 2020.
“Azure Virtual Network Overview,” by John Savill, YouTube, 4 February 2020.
“Microsoft Azure: Security,” Microsoft.
“Microsoft: How 'zero trust' can protect against sophisticated hacking attacks,” by Liam Tung, ZDNet, 20 January 2021.
“Secure Score in Azure Security Center,” memildin, Microsoft.com, 5 January 2021.
“Thinking about Resiliency in Azure,” by John Savill, YouTube Video, June 2019.
“Top SolarWinds Risk Assessment Resources for Microsoft 365 and Azure,” by Susan Bradley, CSO Online, 13 January 2021.
“Zero Trust Deployment Center,” by Gary Centric, Microsoft.com, 30 September 2020.
Microsoft Azure adoption with cybersecurity first principle strategies. The cloud revolution is here. How well can we implement our first principle strategies within each environment? Do we need to embrace other security platforms to get it done? In this session, Rick discusses Microsoft Azure through the lens of first principle thinking. He reviews how Azure supports, or doesn’t support, strategies of resilience, zero trust, intrusion kill chains, and risk assessments. Cybersecurity professional development and continued education. You will learn about: Microsoft Azure services and security tools, infrastructure as code, Azure strategies that support cybersecurity first principles CyberWire is the world’s most trusted news source for cybersecurity information and situational awareness. Join the conversation with Rick Howard on LinkedIn and Twitter, and follow CyberWire on social media and join our community of security professionals: LinkedIn, Twitter, Youtube, Facebook, Instagram Additional first principles resources for your cybersecurity program. For more Microsoft Azure and cybersecurity first principles resources, check the topic essay. Selected Reading:
S1E1: 6 APR: Your Security Stack is Moving: SASE is Coming.
S1E9: 01 JUN: Cybersecurity first principles - resilience
S2E7: 31 AUG: Identity Management: a first principle idea.
S2E8: 07 SEP: Identity Management: around the Hash Table.
S3E3: 02 NOV: Securing containers and serverless functions.
S3E4: 09 NOV: Securing containers and serverless functions: around the Hash Table.
S3E5: 16 NOV: SOAR: a first principle idea.
S3E6: 23 NOV: SOAR: around the Hash Table.
“About: History,” Cloud Security Alliance.
“A Brief History of AWS,” by Alec Rojasm, Media Temple, 31 August 2017.
“A Look Back At Ten Years Of Microsoft Azure,” by Janakiram, Forbes, 3 February 2020.
“An Annotated History of Google’s Cloud Platform,” by Reto Meier, Medium, 10 February 2017.
“Azure AD Overview,” John Savill, YouTube, 2020.
“Azure Virtual Network FAQ,” KumudD, Microsoft.com, 26 June 2020.
“Azure Virtual Network Overview,” by John Savill, YouTube, 4 February 2020.
“Matrices: Cloud Matrix,” by Mitre ATT&CK.
“Microsoft Azure: Security.” by Microsoft.
“Thinking about Resiliency in Azure,” John Savill, YouTube Video, June 2019.
“Zero Trust Deployment Center,” Gary Centric, Microsoft.com, 30 September 2020.
Two members of the CyberWire’s Hash Table of experts, Gary McAlum, USAA CSO and Don Welch, Penn State CIO, join Rick Howard to discuss the SolarWinds attack. Resources:
S1E6: 11 MAY: Cybersecurity first principles.
S1E7: 18 MAY: Cybersecurity first principles: zero trust.
S1E8: 26 MAY: Cybersecurity first principles: intrusion kill chains.
S1E9: 01 JUN: Cybersecurity first principles: resilience.
S1E11: 15 JUN: Cybersecurity first principles: risk assessment.
S2E7: 31 AUG: Identity Management: a first principle idea.
S2E8: 07 SEP: Identity Management: around the Hash Table.
“Cybersecurity Canon,” by Ohio State University.
“Do I Need a Third-Party Security Audit?” By Rachel Phillips, Bleeping Computer, 2 March 2018.
“SolarWinds hack officially blamed on Russia: What you need to know,” by Laura Hautala, Cnet, 5 January 2021.
“Sunburst backdoor – code overlaps with Kazuar,” by SecureList, Kaspersky, 11 January 2021.
Rick discusses if the first principles theories prevent material impact in the real world, such as the latest SolarWinds attack. Previous episodes referenced: S1E6: 11 MAY: Cybersecurity First Principles S1E7: 18 MAY: Cybersecurity first principles: zero trust S1E8: 26 MAY: Cybersecurity first principles: intrusion kill chains. S1E9: 01 JUN: Cybersecurity first principles - resilience S1E11: 15 JUN: Cybersecurity first principles - risk S2E3: 03 AUG: Incident response: a first principle idea. S2E4: 10 AUG: Incident response: around the Hash Table. S2E7: 31 AUG: Identity Management: a first principle idea. S2E8: 07 SEP: Identity Management: around the Hash Table. Other resources: “A BRIEF HISTORY OF SUPPLY CHAIN ATTACKS,” by Secarma, 1 September 2018. “Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers,” by 365 Defender Research Team and the Threat Intelligence Center (MSTIC), Microsoft, 18 December 2020. “A Timeline Perspective of the SolarStorm Supply-Chain Attack,” by Unit 42, Palo Alto Networks, 23 December 2020. “Cobalt Strike,” by MALPEDIA. “Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon,” by Kim Zetter, Published by Crown, 3 June 2014. “Cybersecurity Canon,” by Ohio State University. “FireEye shares jump back to pre-hack levels,” Melissa Lee, CNBC, 23 December 2020. "Implementing Intrusion Kill Chain Strategies by Creating Defensive Campaign Adversary Playbooks," by Rick Howard, Ryan Olson, and Deirdre Beard (Editor), The Cyber Defense Review, Fall 2020. “Orion Platform,” by SolarWinds. “Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers,” by Andy Greenberg, Published by Doubleday, 7 May 2019. “Solarstorm,” by Unit 42, Palo Alto Networks, 23 December 2020. “The Cybersecurity Canon: Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon,” by Rick Howard, The Cybersecurity Canon Project, 28 January 2015. “Using Microsoft 365 Defender to protect against Solorigate,” by the Microsoft 365 Defender Team, 28 December 2020.
Two members of the CyberWire’s Hash Table of experts:
Gary McAlum, USAA CSO
Zan Vautrinot, Air Force Major General (retired), Board Director Wells Fargo, Battelle, and City of Hope
discuss where the CISO and CSO should fit into the organization. Resources:
“Changing CISO's Reporting Structure: Why The Debate Is Back?” BY CIO&Leader, 3 July 2019.
“Does it matter who the CISO reports to?” By Josh Fruhlinger, CSO, 30 April 2019.
Rick describes where the CISO fits into the corporate organizational structure and why it came to be that way. Resources:
“CIO Hall of Fame: Max D. Hopper,” By Richard Pastore, CIO, 15 September 1997.
“Concept of the Corporation,” by Peter F. Drucker, published Routledge, 1946.
“Durant Versus Sloan – Part 1,” by steve blank, 1 October 2009.
“EVOLUTION OF THE CISO,” by Thomas Borton, ISACA Conference, 13 March 2014.
“Max Hopper: Modernized information technology at American Airlines,” by Trading Markets, 28 Jan 2010.
“My Years with General Motors,” by Alfred P. Sloan Jr., Published by Crown Business, 1964.
“The Emergence of the CIO,” by IBM.
“Title tips: Officer titles and their meanings,” By Chelan David, Smart Business, 3 March 2016.
Three members of the CyberWire’s Hash Table of experts:
Rick Doten
Kevin Ford
Kevin Magee
discuss SOAR tools. Resources:
“A Brief History of SIEM,” by Stephen Gailey, CyberSecurity Magazine, 19 January 2020.
“Cybersecurity First Principles: DevSecOps.” by Rick Howard, CSO Perspectives, The CyberWire, 8 June 2020.
"Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains,” by Eric Hutchins, Michael Cloppert, Rohan Amin, Lockheed Martin Corporation, 2010, last visited 30 April 2020.
“Site Reliability Engineering: How Google Runs Production Systems,” by Betsy Beyer, Chris Jones, Jennifer Petoff, and Niall Richard Murphy, Published by O'Reilly Media, 16 April 2016.
“The Cybersecurity Canon: The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win,” book review by Rick Howard, Palo Alto Networks, 21 October 2016.
“The Evolution of SOAR Platforms,” by Stan Engelbrecht, SecurityWeek, 27 July 2018.
“The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win,” by Gene Kim, Kevin Behr, George Spafford, Published by IT Revolution Press, 10 January 2013.
Rick explains the network defender evolution from defense-in-depth in the 1990s, to intrusion kill chains in 2010, to too many security tools and SOAR in 2015, and finally to devsecops somewhere in our future. Resources:
“Cybersecurity First Principles: DevSecOps.” by Rick Howard, CSO Perspectives, The CyberWire, 8 June 2020.
“FAQ,” RSA Conference, 2020.
"Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains,” by Eric Hutchins, Michael Cloppert, Rohan Amin, Lockheed Martin Corporation, 2010, last visited 30 April 2020.
“Malware? Cyber-crime? Call the ICOPs!” by Jon Oltsik, CSO, Cybersecurity Snippets, 22 June 2015.
“Market Guide for Security Orchestration, Automation and Response Solutions,” by Gartner, ID G00727304, 21 September 2020.
“MITRE ATT&CK,” by Mitre.
“The Cybersecurity Canon: The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win,” book review by Rick Howard, Palo Alto Networks, 21 October 2016.
“The Cyber Kill Chain is making us dumber: A Rebuttal,” by Rick Howard, LinkedIn, 29 July 2017.
“The Evolution of SOAR Platforms,” by Stan Engelbrecht, SecurityWeek, 27 July 2018.
“What is SOAR (Security Orchestration, Automation, and Response)?” by Kevin Casey, The Enterprisers Project, 30 October 2020.
Two members of the CyberWire’s hash table of experts:
Bob Turner: University of Wisconsin at Madison CISO
Roselle Safran: KeyCaliber’s CEO & Founder
discuss security concerns around containers and serverless functions. Resources:
“Cybersecurity first principles: intrusion kill chains,” By Rick Howard, CSO Perspectives, the Cyberwire, 26 May 2020.
“Race Flag Meanings,” by Go Ahead Take the Wheel, 2020.
“What Copernicus Knew About Cybersecurity Operations,” by Robert Turner, UW-Madison Information Technology, 27 June 2017.
Rick explains what containers and serverless functions are, why they are related, why they are the latest development in the evolution of the client server architecture, why you need to secure them, and how. Resources:
“5 ways to secure your containers,” by Steven Vaughan-Nichols, CEO, Vaughan-Nichols & Associates, 23 April 2019.
“8 technologies that will disrupt business in 2020,” by Paul Heltzel, CIO, 26 August 2019.
“A Brief History of Containers: From the 1970s Till Now,” by Rani Osnat, Aqua, 10 January 2020.
“A brief history of SSH and remote access,” by Jeff Geerling, an excerpt from Chapter 11: Server Security and Ansible, in Ansible for DevOps, 15 April 2014.
“Amazon Launches Lambda, An Event-Driven Compute Service,” by Ron Miller, TC, 13 November 2014
“Application Container Security Guide: NIST Special Publication 800-190,” by Murugiah Souppaya, John Morello, and Karen Scarfone, NIST, September 2017.
“Container Explainer,” IDG.TV, 19 August 2015.
“Container Network Security - Kubernetes Network Policies in Action with Cilium (Cloud Native),” by Fernando, Gitlab, 16 July 2020.
“Container Security,” by Synk.
“Google has quietly launched its answer to AWS Lambda,” by Jordan Novet, Venture Beat, 9 February 2016.
“Historical Computers in Japan: Unix Servers,” IPSJ Computer Museum.
“M.C. Escher Collection,” Maurits Cornelis (MC) Escher - 1898 - 1972.
“Serverless Architectures,” by Martin Fowler, martin.Fowler.com, 22 May 2018.
“Serverless vs Microservices — Which Architecture to Choose in 2020?” TechMagic, 01 JULY 2020.
“The Benefits of Containers,” by Ben Corrie, VMWARE, 16 May 2017.
“The essential guide to software containers for application development,” by David Linthicum, Chief Cloud Strategy Officer, Deloitte Consulting.
“The Invention of the Virtual Machine,” by SEAN CONROY, IDKRTM, 25 JANUARY 2018.
“What are containers and why do you need them?” By Paul Rubens, CIO, 27 JUN 2017.
“What even is a container: namespaces and cgroups,” by Julia Evans, Julia Evans Blog.
“What is a Container?” by Ben Corrie, VMWARE, 16 May 2017
“What is a Container?” by VMWARE.
Two members of the CyberWire’s hash table of experts:
Steve Winterfeld: Akamai’s Advisory CISO
Paul Calatayud: Palo Alto Networks’ Chief Security Officer for the Americas
discuss SD-WAN architecture and security. Resources:
“A History of SD-WAN,” by CATO.
“Broadband history,” by Dani Warner, USwitch, 19 July 2018.
“SD-WAN: What’s the big deal for security leadership?” by Rick Howard, CSO Perspectives, The CyberWire, 10 October 2020.
“The 6 Biggest SASE Buys of 2020 (So Far)” by Tobias Mann, SDxCentral, 26 August 2020.
“The Secret to SASE is the Right SD-WAN,” by Network World from IDG, 2020.
“What is MPLS: What you need to know about multi-protocol label switching,” by Neal Weinberg and Johna Till Johnson, Network World, 16 March 2016.
“What is SD-WAN and why do you need it? Quick Explainer Video,” by Drew Schulke, Dell, 18 October 2019.
“Your security stack is moving: SASE is coming,” by Rick Howard, CSO Perspectives, The CyberWire, 5 April 2020.
Rick discusses the history of enterprise connectivity, the benefits of SD-WAN, and the security obstacles to avoid when enterprises deploy SD-WAN today. He also makes the case for a coupling of SD-WAN and SASE. Resources:
“A Brief History of the Enterprise WAN: How little has changed in the last 15 years,” by By Andy Gottlieb, Network World, 6 April 2012.
“Bandwidth Key Words: DS1, T-1, DS2, T-2, DS3, T-3, DS4, T-4, OC-1, OC-3, OC-12, OC-48, ATM, Bandwidth Resources, MPLS, Satellite, Internet and Bandwidth Speeds: Explaining Bandwidth The Easy Way.” SolveForce.
“Broadband history,” by Dani Warner, USwitch, 19 July 2018.
“Cybersecurity Innovation Starts Here,” Lee Klarich, Palo Alto Networks, 13 November 2019.
"MEF White Paper MEF 3.0 SD-WAN Services,” MEF, November 2019.
“MEF 3.0 SD-WAN Services & Certifications – Frequently Asked Questions,” by MEF
“SD-WAN drives managed network services trends for 2020,” By Tom Nolle, CIMI Corporation, TechTarget, December 2019.
"SD-WAN Explained: The Ultimate Guide to SD-WAN Architecture,” by TectTarget
“SD-WAN (Software-defined WAN),” TechTarger
“SD-WAN vs. MPLS vs. Public Internet,” by Idan Hershkovich, CATO Networks, 28 February 2018.
“SD-WAN security explained,” by ERICKA CHICKOWSKI, AT&T Business, 25 June 2020.
“SD-WAN - What it means for enterprise networking, security, cloud computing
"Software-defined wide area networks, a software approach managing wide-area networks, offers ease of deployment, central manageability and reduced costs, and can improve connectivity to branch offices and the cloud,” By Michael Cooney, Network World, 9 October 2019.
“The 6 Biggest SASE Buys of 2020 (So Far)” by Tobias Mann, sdx central, 26 August 2020.
“The Secret to SASE is the Right SD-WAN,” by Networkworld by IDG, 2020.
“Tubes: A Journey to the Center of the Internet,” by Andrew Blum, Published January 2012 by Ecco.
“What is MPLS: What you need to know about multi-protocol label switchinig,” By Neal Weinberg and Johna Till Johnson, NetworkWorld, 16 March 2016.
“What is SD-WAN and why do you need it? Quick Explainer Video,” Drew Schulke, Dell, 18 October 2019.
“Why SD-WAN is the next breed of WAN optimization,” By Sean Michael Kerner, TechTarget.
“X.25 – What is X.25 Networks?” By Dinesh Thakur, Computer Notes.
“Your security stack is moving: SASE is coming,” by Rick Howard, CSO Perspectives, The CyberWire, 5 April 2020.
Two members of the CyberWire’s hash table of experts, Tom Quinn: CISO - T. Rowe Price Rick Doten: CISO - Carolina Complete Health discuss red team blue team operations in the real world.
Rick discusses this history of red teaming as a concept, the inclusion of penetration tests for the early mainframe computers, and the evolution into team-on-team cyber exercises.
Three members of the CyberWire’s Hash Table of experts Helen Patton - CISO - Ohio State University Suzie Smibert - CISO - Finning Rick Doten - CISO - Carolina Complete Health discuss the things they worry about when it comes to data identity management.
Four members of the CyberWire’s hash table of experts: Tom Quinn - CISO - T. Rowe Price Associates Nikk Gilbert - CISO - Cherokee Nation Businesses Dawn Cappelli - VP of Global Security and CISO for Rockwell Automation Gary McAlum - CSO- USAA discuss the things they worry about when it comes to data loss protection.
Rick discusses data loss protection as a first principle strategy using NIST and Forrester as a guide. The new thing to consider is running a deception network.
Four members of the CyberWire’s hash table of experts: Jerry Archer - Sallie Mae CSO Ted Wagner - SAP National Security Services CISO Steve Winterfeld - Akamai Advisory CISO Rick Doten - Centene CISO discuss the things they worry about when it comes to incident response.
Rick discusses incident response as a best practice for the network defender community, talks briefly about Zoom and how well their communications plan worked earlier this year when the network defender community called their web conferencing app out on several security issues, and how poorly OPM handled their incident response when the Chinese stole the PII of every person that worked in the U.S. government. Finally, he talks about the birth of incident response and the most influential cybersecurity book ever: “The Cuckoo’s Egg.”
Four members of the CyberWire’s Hash Table of experts: Don Welch: Interim CIO of Penn State University Helen Patton: CISO for Ohio State University Bob Turner: CISO for the University of Wisconsin at Madison Kevin Ford: CISO for the State of North Dakota discuss SOC Operations in terms of intrusion kills chains, defensive adversary campaigns, insider threats, cyber threat intelligence, zero trust, SOC automation, and SOC analyst skill sets.
For the 20th anniversary of 9/11, Rick Howard, the Cyberwire’s CSO, Chief Analyst, and Senior Fellow, recounts his experience from inside the Pentagon running the communications systems for the Army Operations Center.
The idea of operations centers has been around as far back as 5,000 B.C. This show covers the history of how we got from general purpose operations centers to the security operations centers today, the limitations of those centers, and what we need to do as a community make them more useful in our infosec program.
This is the eighth and final essay in this series that discusses the development of a general purpose cybersecurity strategy for all network defender practitioners - be they from the commercial sector, government enterprise, or academic institutions - using the concept of first principles.
This is the seventh show in a planned series that discusses the development of a general purpose cybersecurity strategy for all network defender practitioners - be they from the commercial sector, government enterprise, or academic institutions - using the concept of first principles. First principles Zero trust Intrusion kill chains Resilience DevSecOps Risk assessment We are building a strategy wall, brick by brick, for a cyber security infosec program based on first principles. The foundation of that wall is the ultimate and atomic first principle: Reduce the probability of material impact to my organization due to a cyber event. That’s it. Nothing else matters. This simple statement is the pillar, on which we can build an entire infosec program. This next building block will start the second course of the wall because it directly supports all of the other strategic bricks we have already laid. This brick is called cyber threat intelligence operations.
This is the sixth episode in a planned series that discusses the development of a general purpose cybersecurity strategy for all network defender practitioners-- be they from the commercial sector, government enterprise, or academic institutions-- using the concept of first principles.
This is the fifth essay in a planned series that discusses the development of a general purpose cybersecurity strategy for all network defender practitioners-- be they from the commercial sector, government enterprise, or academic institutions-- using the concept of first principles.
This is the fourth show in a planned series that discusses the development of a general purpose cybersecurity strategy for all network defender practitioners - be they from the commercial sector, government enterprise, or academic institutions - using the concept of first principles. The first show explained what first principles are in general and what the very first principle should be for any infosec program. The second show discussed zero trust. The third show covered intrusion kill chains. This show will cover resilience.
This is part three in a series that Rick Howard, CyberWire’s Chief Analyst, is doing about building an infosec program from the ground up using a set of first principles. This episode, he talks about why intrusion kill chains are the perfect companion strategy to the passive zero trust strategy he talked about last week. The key takeaway here is that we should be trying to defeat the humans behind the campaigns collectively, not simply the tools they use independently with no context about what they are trying to accomplish.
This is part two in a series that Rick Howard, The CyberWire’s Chief Analyst, is doing about building an infosec program from the ground up using a set of first principles. This episode, he talks about why zero trust is a cornerstone building block to our first principle cybersecurity infosec program. And here is the key takeaway - building it is not as hard to do as you think.
This week's CSO Perspectives is the first in a series of shows about cybersecurity strategy. Rick Howard discusses the concept of first principles as an organizing principle and how the technique can be applied to cybersecurity to build a foundational wall of infosec practices that are so fundamental as to be self-evident; so elementary that no expert in the field can argue against them; so crucial to our understanding that without them, the infrastructure that holds our accepted best practice disintegrates like sand castles against the watery tide.
Rick Howard discusses counterintelligence operations by commercial vendors on the Dark Web and the kinds of intelligence that can be found.
Conveying risk to the company leadership, the metrics collection required to do it, how heat maps are generally bad science, and the requirement for precise modeling of the risk environment.
Rick Howard, the CyberWire’s Chief Analyst, CSO, and Senior Fellow discusses his favorite cyber novels to distract us from our current emergency situation: "Threat Vector” by Tom Clancy and Mark Greaney, “Neuromancer,” by William Gibson, “Breakpoint,” by Richard A. Clarke, and his favorite hacker novel of all time, “Cryptonomicon,” by Neal Stephenson.
Rick Howard, the CyberWire’s Chief Analyst, discusses the Artificial Intelligence hype. Listen as Rick talks about the emergence of machine learning as a key tool to the detection of cyber adversaries (and the need for big data to pursue that strategy). He also discusses the transition of SIEMS from on-prem devices to cloud-delivered services in order to facilitate the implied big data collection requirement. And, you'll hear about the emergence of XDR that may well fulfill the promise on-prem SIEMs could never deliver: real-time anomaly detection.
Rick Howard, the CyberWire’s Chief Analyst, discusses the next big thing in cybersecurity service delivery. It is called SASE, coined by Gartner last fall, and stands for Secure Access Service Edge (Cloud delivered). It flips on its head how we all consume security services today and it is the perfect solution for small to medium size businesses. In five years, it will be the primary way that all size businesses consume security products.