Chief of Cybersecurity: Recent Episodes

Dewayne Hart

Welcome to the Chief of Cybersecurity Podcast hosted by Dewayne Hart where we provide learning and discuss relevant information concerning the cybersecurity workforce, business development, and best practices. You can find more information for SEMAIS at www.semais.net and a list of authored publications at www.dewaynehart.com

View Details

While many online scams have originated out of older schemes, scammers are always finding new ways to play them out. Scammers love to pose as legitimate organizations like banks, hoping to trick you into handing over details, but as we’ve become accustomed to dealing with organizations online, the potential for trickery has grown exponentially.This podcast extends information on cybercrime towards scams, criminals stealing information, and persistent criminals.

View Details

In the fast-paced, high-stakes world of risk management, keeping informed about recent developments and cutting-edge trends is beyond essential. There are various insights to address cyber security management challenges and to accelerate security programs and infrastructure advances. The end state makes a firm determination whether cybercrime is outperforming cyber protection.This podcast provides insights that reflect the ever-changing aspects of technology and system disruption through cybercrime and examines how human behavior can become solid defensive shields.

View Details

Online Scams Target Veterans and Active Duty Members

The U.S. has the most robust and powerful military in the world, and though its fighting men and women can win wars, they often appear defenseless against popular online scams. In the military, you have a young population on the web. Service members are targeted by websites that claim to offer special military discounts on everything from cars to apartments for rent.

But the low-priced car never arrives, and the easy-to-find apartment they rented is already occupied. This podcast will focus on safety measures and protection standards for military personnel.

View Details

With so many important concerns occupying the time of church leaders, issues related to church computers can quickly become vulnerable. Cyber threats pose significant challenges for churches and other organizations. Any church that uses computer systems to conduct business operations should consider managing cyber risks. These attacks could create risks that mostchurches are unprepared to confront.

Some incidents may lead to temporary frustration, such as its website availability. The most serious could cause a data breach for employees and members. Identity theft, disclosure of personal information like medical records, and simple embarrassment are all potential problems that can result from a cyber attack. A church can have legal obligations to keep some information confidential, which may not be excused in a cyberattack.

This podcast will discuss why churches should raise safeguards due to the elevated criminal activity against their members and employees.

View Details

Bitcoin and other types of cryptocurrencies have exploded onto the market in recent years, and based on virtual currency's popularity, it seems to be here to stay. Cryptocurrencies are digital or virtual currencies secured by cryptography, with many using decentralized networks based on blockchain technology – an open, distributed ledger that records transactions in code. Crypto is stored in a digital "wallet" on a website, computer, or an external hard drive. To put it simply, Investopedia defines cryptocurrencies as systems that allow for secure online payments denominated in virtual "tokens."

The first cryptocurrency launched a little over a decade ago, was created by Satoshi Nakamoto, who described it as "an electronic payment system based on cryptographic proof instead of trust." Other common types of cryptocurrency include Litecoin, Namecoin, Dogecoin, Ethereum, Cardano, and others. In March 2021, there were reportedly over 18.6 million bitcoins in circulation, with a total market cap of around $927 billion.

Technology has made almost every aspect of our lives – and the lives of criminals – easier. The blockchain has fostered an ecosystem in which illicit actors can efficiently operate anonymously and internationally, stalling financial investigations and setting the stage for increased crypto crime. BitCoin has been excellent and volatile when investing, but deeper concerns, such as ransomware and financial fraud, are lurking beneath your bank account. Do you feel rich? This podcast will reveal SECRET tips to keep your cryptocurrency safe from cybercrime. By following these tips, you'll be able to keep your coins safe from hackers and thieves.

View Details

Since 2004, the President of the United States and Congress have declared October to be Cybersecurity Awareness Month, helping individuals protect themselves online as threats to technology and confidential data become more commonplace.

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA) lead a collaborative effort between government and industry to raise cybersecurity awareness nationally and internationally. 

Although it's done in October, there is a need to extend and continually practice cyber safety. This interview session brings into attention on why cyber awareness is important and how to extend learning outside of October.

View Details

Business engagements for cybersecurity have focused on being the medium between suppliers, customers, and hackers. Many organizations suffer significant security risks due to changing risk profiles and attack surfaces. The management strategies may invoke defense tactics, but unless they have an accurate indicator of their landscape, they are prone and subject to failure.This podcast discusses several gaps, security visibility, and concerns businesses must address for cyber resilience and risk reduction. Listeners will gain insight into business engagements and their cybersecurity relationships.

View Details

The shift to remote education and online learning has prompted many schools to increase their digital protection. Before COV19, online education entities and K-12 learned through classroom instructions. Since the change, many K-12 students are learning from home, and college students' enrollment has increased.

Both come at a cybersecurity cost, but there is a need for remote learning. How safe are our educational systems? Well, this podcast will dissect some of the events and issues that cause concerns; and highlight protection standards. Our youths should feel safe!

View Details

We drive our cars daily and enjoy the luxury of the many features, but security risks are embedded. The cybersecurity landscape has no boundaries, and just as if healthcare, financial, and educational entities face risk – so does the automotive industry. Increasing demand for connected and semi-autonomous vehicles has led to a growing demand for connected vehicle devices in automobiles.This increased the complexity of vehicle architecture and software codings, which made cars more vulnerable to cyber-attack. The market for automotive cybersecurity solutions has been developing rapidly to safeguard vehicles from such attacks. This interview brings into focus how automobiles are at risk.

View Details

Supply chain management (SCM) is the active management of supply chain activities to maximize customer value and achieve sustainable competitive advantage. It represents a conscious effort by the supply chain firms to develop and run supply chains in the most effective & efficient ways possible. Supply chain activities cover everything from product development, sourcing, production, and logistics to the information systems needed to coordinate these activities. Many risks exist where 3rd part vendors are risks but can be controlled through active security and managing protocols that outline vendor relationships.

View Details

TikTok is working on a deal with the Biden administration that would "fully safeguard" the app in the U.S. and quell fears about the Chinese government's accessing Americans' data, according to a letter TikTok sent to nine Republican senators. This issue raises concern about having information sharing, privacy, and data protection as critical control across social media accounts. This interview considers why data protection and privacy is a business risk but can be remediated with safe practices.

View Details

With 50 percent to 90 percent of staff working remotely, organizations are now looking atremote work as the new working stylein the future. While working remotely has its benefits, one of the biggest challenges it presents is cyber security problems. Remote working has a lot of benefits, including increased productivity, improved employee mental health, and reduced costs in office space. But it also has its challenges. Your remote employees may be unknowingly putting your company's data at risk. Working from home can potentially lead to data breaches, identity fraud, and a host of other negative consequences.  This interview sessions brings to light the nuances and approaches to making remote working cyber safe.

View Details

They will see it everywhere from birth and will inevitably grow up using it. It can be extremely educational, help build skills, and be a creative outlet. It can also be dangerous — predators, hackers, and other threats use technology to hurt others. We’ll teach you how to protect your children from the wide variety of threats out there, including the over-usage of technology itself. By knowing the risks and having the tools available, you can make technology work for you and your youngsters. This interview session will make digital parenting a success!

View Details

As the U.S. military continues to expand its IT ranks, many employers have stepped up efforts to recruit military talent into their IT teams to better secure networks. As a result, online cybersecurity courses such as those at Western Governors University (WGU) have witnessed a growing interest among active-duty military students who are either looking to advance their training for military work or to break into civilian IT careers, according to Rick Benbow, a regional vice president at WGU.This interview will expand the thoughts and projections for veterans' transition into the cybersecurity career field based on industry statistics and working knowledge of cybersecurity employment.

View Details

One of the critical programs that shape cybersecurity risks is having a process that helps remediates vulnerabilities. Most users and organizations utilize various tools, analytical platforms, reporting, and various teams to help reduce risks associated with CVEs, advisories, configuration management, and asset inventories – which can become challenging. With the increasing number of vulnerable applications, systems, and advancements in AI and cloud, Vulnerability Management has surfaced as a critical element when reducing exploits and risks.In this podcast, the discussion will dissect a vulnerability management program and its lifecycle process. Listeners will gain information on the E2E process related to identification, prioritization, patch and remediation, exceptions, reporting, and continuous risk scoring.

View Details

Electronic voting machines from a leading vendor used in at least 16 states have software vulnerabilities that leave them susceptible to hacking if unaddressed. These vulnerabilities, for the most part, are not ones that could be easily exploited by someone who walks in off the street, but they are things that we should worry could be exploited by sophisticated attackers, such as hostile nation states, or by election insiders, and they would carry very serious consequences.

This interview session will align how the vulnerabilities exist and what security controls are required to remediate issues outlined by the U.S. Cybersecurity and Infrastructure Agency, or CISA

View Details

Since data requirements and information sharing emerged, cybersecurity has undergone numerous developments. Policies and laws for privacy and information resource protection have transitioned the technology space to secure a variety of sectors, including healthcare corporations and government agencies. The increased need for healthcare information sharing has fueled interest in modernizing applications, clouds, data, infrastructure, and networking technologies.This podcast will discuss how the healthcare sector's security requirements have become more critical as information storage has shifted to electronic rather than hard copy. Various government agencies and healthcare organizations practices and standards will be discussed and aligned with security best practices. Listeners will gain firsthand knowledge of healthcare security standards and the cybersecurity roadmap that safeguards its resources.

View Details

Every security steward has been challenged to obtain multiple certifications, gain professional experience, and further their knowledge by attending educational institutions. Each resume includes various titles and certifications that demonstrate the cybersecurity professionals motivation and drive to succeed. Beyond the accolades and achievements, many stewards fail to roadmap and carry out project tasks.This podcast discusses those concerns by demonstrating workforce practices and their overall cybersecurity relationships. The podcast focuses on engaging security from initial employee onboarding to career progression. The outcome will balance learning, education, and career paths as a single contributor to career success.

View Details

Many security environments will need to modernize and transform their cybersecurity programs. The need is driven by technological advancements, maturity requirements, and security readiness. Organizations, security auditors, assessors, and compliance teams can benefit from various frameworks, policies, and standards. Each is distinct and offers similar but distinct cybersecurity maturation strategies. The government has implemented CMMI and other frameworks. However, some industries have yet to adopt or are evaluating whether traditional practices can achieve cybersecurity maturity. 

This podcast explores how cybersecurity maturity can help advance technology while assisting readiness programs. Each listener will gain firsthand knowledge of cybersecurity maturity through enablers such as technologies, processes, and people. The findings will highlight the importance of maturing cybersecurity programs using the "Growth Mindset"

View Details

Numerous challenges have been aimed at technologies and their security culture, ranging from risk reduction to determining security readiness. The risk profiles are evaluated and matured to compliance in each situation. Despite their progress and success, many organizations struggle to communicate that "Zero Risk"is a nebulous and risk-enabling concept. Various professionals grade risk based on events and compliance indicators.

A precise and functional security culture remediates events and expands compliance. This podcast explains why and how "Zero Risk" cultures are prone to failure. Listeners will better understand risk profiling and effective strategies to evaluate visual and non-visual data. The results will highlight why success occurs when compliance is extended to a risk-based framework.

View Details

The security involvement and protection standards align with various technology platforms, including the cloud. Many businesses and institutions have modernized and adopted cloud technologies and services. The underlying architect has made significant progress and overcome challenges, with security being a major discussion point.This podcast will examine cloud environments and their operational characteristics and highlight the cybersecurity position. Listeners will gain a more defined awareness of how cloud security operates; and be better positioned to understand its blueprint, operations, use, and protection requirements.

View Details

Sustaining protection for the nation's infrastructure is a critical component that shapes our Quality of Life (QOL). The dire need to prevent infrastructure risks is evident based on historical challenges and ransomware attacks against the energy sector. Beyond the energy sector, the nation's infrastructure also depend on chemical, water, dams, healthcare, IT, transportation, and other sectors for the country.

This podcast discusses and reinforces how the Department of Homeland Security, protection strategies, and government intervention have been challenged to remediate many weaknesses and sustain the nation's ability to operate. Listeners gain valuable information and awareness of the country's roadmap and cybersecurity involvement in Critical Infrastructure Protection (CIP).

View Details

This podcast is the first in a series of Global Podcast Studios hosted a one-on-one conversation to learn more about the Cybersecurity Mindset's direction and goals. You can get a sense of my overall thoughts and the motivation behind why the publication was written. This is a must-hear episode!

View Details

This podcast session summaries Season I and bring some high-level discussion points into the format. Listeners gain insight and information to develop the cybersecurity picture and learn how security operates. The information discussed prepares listeners to understand the cybersecurity mindset and its relationship to cybersecurity and strategies to drive their solutions. It furthers an understanding and connection into Season II: Activating Cybersecurity.

View Details

There have been many concepts and information distributed concerning how to build a successful cybersecurity career. Some have had success, while others have left cybersecurity career-minded professionals with unanswered questions. This podcast session takes a high-level view of the cybersecurity career path and successful steps, actions, or strategies to become successful. It dissects resume writing, employment type, role assignments, and ideas to shape careers and perform as a security professional.

View Details

This podcast session examines users' risk contribution and behavior patterns that can cause significant disruption to enterprise cybersecurity practices. It also mentions how cyber awareness programs can succeed when positive behavioral techniques are integrated. The discussion points examine values, morals, and how the cybersecurity mindset aligns with behavioral norms. Listeners can gain information advantage in resolving negative behavioral traits before they become a risk.

View Details

Every security team has used cybersecurity tools to produce or analyze data feeds. Tools such as Splunk, Nessus, Arsigsight, McAfee ePO (Antivirus), End-Point Detection, and Response applications are available. However, the proper and efficient use outside of reporting is overlooked. This podcast session examines common pitfalls and gaps deployed that end-users and management teams deploy for in-house tools. The discussion focuses on different policy tuning, employee usage, and why users can collect hygiene data and drive defense strategies when adequately using cybersecurity tools.

View Details

Holistic defense is a traditional but rarely spoken concept when cybersecurity practices are introduced. This podcast session extracts the elements and knowledge required to drive system thinking as a holistic defense strategy. The discussions focus on the security development lifecycle and combining security integration and engineering as a defense strategy. Listeners gain an understanding of how the "Security Puzzle" and thinking holistically operate together.

View Details

Small businesses possess an individual brand and hold responsibility for protecting internal information and clients' data. This podcast session outlines the importance of protecting information assets, clients, and vendor information and projecting behavioral practices that ensure employees' buy-in to cyber awareness. Listeners and business owners gain the advantage in understanding why "Brand Protection" is a top-down approach.

View Details

This podcast addresses the growing need for digital modernization and its key objectives for cybersecurity. The discussion points outline how legacy systems and modernization concepts can reduce cyber threats and transform business operations. The critical areas discussed are automation, adaptive technology research, digitalization into the workforce, and transformation practices.

View Details

The military veteran workforce brings advanced skillsets and aligned training that models the cybersecurity culture. This podcast examines and brings to attention how their skillsets are designed with a "Cybersecurity Seed," and much of their experience is transferrable and relatable to cybersecurity. The concepts of information secrecy, intelligence gathering, and human firewall theories are discussed.

View Details

In the growing age of technology Artificial Intelligence (AI) has matured and contributed to many advances. This podcast session discusses some of those benefits and how they may transform cybersecurity and create valuable solutions. The discussion points address intelligence gathering, predictive analytics, and data process requirements used for AI platforms.

View Details

Vulnerable organizations may have varying security risks when their Vulnerability Management program lacks maturity and effectiveness. This podcast session aligns the operational standards required to administer vulnerability management taskings such as policy development, asset discovery, compliance scanning, metrics development, risk scoring, and Patch and Vulnerability Remediation P&VR standards.

View Details

The technology industry engages challenges and concerns when compliance and risk management initiatives are developed. This podcast session brings into attention and outlines why security compliance and risk management programs are failing; and what tradeoffs, security processes, and solutions are required to ensure both are successful.

View Details

Individual protection standards are sometimes misunderstood and carry varying practices that are confusing. This podcast session brings into attention user-base security standards and processes required to protect information. Listeners gain a first-hand knowledge base and critical steps needed to remain cyber-safe.

View Details

The Information Privacy podcast session focus on how privacy, safeguards, and information sharing operate as a collective methodology to protect personal, business, and critical information. Listeners gain the informational advantage at understanding protection schemes, security measures, and individual responsibility when engaging information privacy. 

View Details

This podcast session brings into existence of how having a cybersecurity mindset resolves industry problems by being cyber-focused. It provides a chance for listeners to see how their engagement and thinking process is either successful or failing best-security practices. Information relating to the inclusive culture, risk-based-thinking, hackers mindset, and situational awareness are highlighted.

View Details

This podcast session provides an overview and discussion into learning the basic functions and use of cybersecurity. Listeners gain a first-hand opportunity to see how cybersecurity operates and ideas to protect personal information. The discussion points address cybersecurity history, sectors that use its programs, and the importance of individual responsibility.