We know it can be challenging to secure your business, especially when you have limited time.
The Get Cyber Resilient Show, brought to you by Mimecast, is the perfect way to stay up-to-date with the latest cyber developments across Australia and New Zealand. From cyber security to cyber awareness, your hosts Daniel McDermott and Garrett O'Hara will bring you insights and real stories from IT and Security Leaders, just like you.
Don’t get angry at downtime and data breaches, Get Cyber Resilient!
The end of the cyber road. This week we say goodbye to the Get Cyber Resilient show. Dan, Gar and Vinh take one last look behind the cyber news.
In this episode, we start with Australian Prime Minister Anthony Albanese’s answer to cyber resiliency; we then jump over to the world of OT and how Schneider Power metres have been disclosing that they transmit user IDs and passwords in plain text. In our last deep dive, we review the appointment of Australia’s first Cyber Security Coordinator. As always, we wrap with a lightning round of the latest breaches and vulnerabilities to make the headlines.
A big thank you goes out to everyone behind the show and also you, our listeners that have either been with us from the beginning or only found us recently; we appreciate every one of you for your support over the years.
In this episode, Gar sits down with Belinda Noel, Chief Growth Officer at Secolve. Belinda talks us through the expanding world of Operational Technology (OT) and Cyber Security, looking at its growing importance and need for attention. We look at the differences and overlap between IT, OT and IOT, and how each play their part, the immaturity of OT security and why it hasn't been a priority and the threats which are bringing it to the forefront of cyber concerns.
Useful Links:
OT Brisbane Meet Up https://www.linkedin.com/events/otcybersecuritymeetupbrisbane7057209152976162816/comments/
OT Cyber Security at EnergyAustralia: https://www.linkedin.com/posts/secolve_secolve-cybersecurity-otsecurity-activity-7052441794709487616-GPec/?utm_source=share&utm_medium=member_desktop
On this week’s news episode, Dan, Gar and Vinh are taking another look behind the cyber news, starting with Toyota, and customer information that has been publicly accessible forover 6 years. Next we dive into the supply chain attack impacting many high profile British brands that is linked to a Russian cyber gang, we then discuss how the government is exploring regulations for Artificial intelligence technologies. We wrap up the episode with a lightning round of the latest breaches and vulnerabilities to make headlines.
This week we are joined by Matt Wilcox, Founder and CEO at FifthDomain. In this conversation, Matt and Gar discuss the growing gap in our local cyber workforce and the initiatives needed to fix the problem. Matt explains the ways we can ensure cyber training is most effective for those coming into the workforce, and the role Government and industry leaders can play in standardising cyber education.
On this week’s episode, Gar and Vinh are taking a look behind the cyber news, kicking off with the twitter hacker extradition in the US, we then discuss the snake espionage infrastructure that cyber agencies have detected in over 50 countries.
Staying global, we look at how the EU is going hard on cyber labelling for the cloud services, then back at home, we cover the Capita ransomware attack costs, Microsoft patches and the trading halt for Australian company TechnologyOne. As always, we wrap up with a lightning round of the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
We’re back for the first episode of Season 10! In this Behind the Cyber News episode we kick off with a look into the United Nations Cyber Crime Treaty and its implications on global law enforcement. We then review the Top 5 Most Dangerous cyberattacks for 2023 as announced by the SANS Technology Institute at the RSA Conference, we then move back to local headlines with the Federal Government and Minister Clare O’Neil warning that Australia faces a ‘dystopian’ future of cyber attacks targeting the fabric of our society. We then wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
This week we are joined by Dr Andrew Reeves, Director at Cybermindz and a psychologist. In this conversation, Andrew talks us through the Cybermindz organisation, the data that came has been uncovered in his research on mental health in cyber and the nine attributes that point to what is different in the world of stress and burnout in cyber and what that can cost a company and a country.
Andrew also walks us through the cognitive heuristics and biases attackers use to gain access to systems, and how to align your security alertness (aka awareness) program to work with the mindsets, values and motivations of employees.
Find out more about Andrews work here: https://www.linkedin.com/in/andrewreevescyber/
On this week’s episode; Dan, Gar and Vinh kick off with a look behind the latest high profile, large scale breach – Latitude Financial. We then pivot to a review of the latest misuse of AI, fooling voice recognition systems used to verify identity by Centrelink and the ATO, we also discuss the possibility that the federal government is considering making the tech sector bear more liability for insecure products. As always, we wrap up the episode with a lightning round of the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
On this week's episode Gar talks with David Higgins, former CISO for Kiwibank.
In this conversation, David takes us through what AI and ChatGPT mean for cyber, providing a clear understanding of what it is and what it isn’t. He also provides insights into what it means for both the attackers and protectors, as well as what is hype, what is real and where does it lead us. To wrap the episode, we cover a topic that is very important to David, people.
On this week’s episode, the team are back to look behind the cyber news, starting with the announcement from the Home Affairs Department to restructure in order to give government a ‘cyber spine’. We investigate the plan from the European Central bank to run stress tests on cyber resilience across Europe’s top banks in response to the sharp rise in cyber attacks. To wrap up the show, we discuss the new “bootkit” malware called BlackLotus and the risk it poses as well as a lightning round of the latest breaches and vulnerabilities to make the headlines.
On this week’s episode, Gar sits down with Mimecast Co-Founder and CEO, Peter Bauer.
Peter talks through his journey in cyber and the genesis of Mimecast, how he navigated the ups and the down, how he maintained an entrepreneurial mindset and culture as the company grew. We then cover what Peter sees as the biggest emerging risks in cyber, and the importance of cyber strategy at a board level.
On this week’s episode Dan, Gar and Vinh take another look behind the cyber news, we kick off by looking into the breach at cryptocurrency exchange Coinbase. We then dive into the recent Attorney General’s review of the privacy act and the recommendations made to further help protect people from worsening cybersecurity threats. We then look into AI powered chatbots and how they can be hacked to reveal information that is meant to be kept out of the public domain, and we wrap up the show with the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
We are joined this week by Dan Elliott, Principal for Cyber Security Risk Consulting at Zurich, member of CyAN (Cybersecurity Advisors Network) and former intelligence officer.
In this episode, Dan walks us through the evolution of cyber insurance and how organisations should think about cyber insurance. We wrap the interview with Dan’s perspective on security convergence and its benefits.
On this week’s episode Dan, Gar and Vinh take another look behind the cyber news, covering the proposal to institute a government wide ban on Chinese-linked cameras as well as delving into the hottest topic in tech on the planet at the moment, ChatGPT and its impact on cybersecurity. We then pivot into a deep dive review of the new industry group formed to boost national critical infrastructure resilience and wrap up the show with the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
In our first interview of season 9 we are joined by Grant Chisnall, CEO and Founder of Left of Boom and host of the Crisis Talks podcast. In this episode, Grant covers the changes he has seen in crisis preparation and management, how organisations change after being through a crisis event and also the importance of people vs process when crisis events happen.
And we're back, for the first episode of 2023! Dan, Gar and Vinh return to the mics and take us behind the latest cyber news making headlines. In this episode we cover the newly formed global Ransomware taskforce being led by Australia, we dive into how an outage at the Federal Aviation Administration (FAA) in the US sent the nation into travel chaos, and how revenue from Ransomware attacks fell by over $300 million dollars in value in 2022. We then wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of out latest articles:
Or subscribe to our free monthly newsletter!
For our last episode in 2022, we look forward into the new year and hear from the team and some previous guests who give their Cyber Predictions for 2023.
Guests include:
For a look back at the year that was, keep an eye out on getcyberresilient.com for our This Year in Security special!
Wishing our listeners a very Merry Christmas and Happy New Year. Thanks for listening and until next time in Feb 2023, stay safe.
On this week’s Behind the News episode; Dan, Gar and Vinh kick off by taking a look into a ‘false subscription callback scam’ from a group called Luna Moth. We then review the latest attack on LastPass and breached customer details; we continue with another win for the good guys, this time with the arrest of nearly 1,000 suspects. We then wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
On this week’s ep, the team kick off with a review of the latest developments and impacts from the Medibank and Optus breaches. We then investigate the Thales data breach that wasn’t through their IT systems as well as another win for the good guys with the arrest of 59 suspected scammers across Europe. We then wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
On this week’s Behind the News episode, the team discuss the ongoing fallout from the Optus and Medibank breaches, as well as looking into the latest victim, Harcourts Melbourne. We then pivot to the take down of an international cybercriminal in the Netherlands and an attack on a German copper smelter and the implication it could have locally. We then wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
On this week's episode Gar talks with Shishir Singh, Executive VP and CTO at BlackBerry Cyber Security. Shishir is a globally recognised cybersecurity expert with a career spanning 30+ years.
In this conversation we discuss BlackBerry's pivot into cyber, IOT and protecting EV's. We then talk through the findings in BlackBerry’s 2022 Threat Report, including the vulnerabilities that SMBs are facing.
Dan, Gar and Vinh are back for another look behind the cyber news. In this week’s episode the team unpack another high profile breach, this time the ransomware attack on one of the country’s largest health insurers; Medibank Private. We then dive into an update on the fallout and investigations launched off the back of the Optus data breach; we also take a look at the information overload, burnout and talent retention challenges impacting SOC performance. We wrap up with a rapid fire review of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
In this week’s episode, we are joined by Troy Heland Security Engineering Lead at Verizon Asia Pacific’s Security Operation Centre. In this episode we discuss in detail the findings from this year's Mobile Security Index, including: the amount of work done on mobile, over-usage causing distractions and bad decisions.
We also talk about hot topics like the right-to-disconnect laws being passed over in Europe and data leakage through unsanctioned apps. We wrap up with how zero trust should be applied in mobile devices.
In this week's episode, Dan and Gar are back on the mics joined by our newest host, Vinh Nguyen! The team take a look behind the cyber news, starting with the biggest cybersecurity story of the year in Australia, the Optus data breach. They also discuss the latest developments of the Uber breach and the fall out of T-Mobile's data breach, including their $350 million payout. We finish off the show with a wrap of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
For our first episode of Season 8 we speak with Duncan Jones, a cybersecurity expert and Head of Cybersecurity at Quantinuum. Here, Duncan talks us through what quantum computing is, what its good and not so good at, the challenges quantum computing is facing and how they are being overcome, and its impacts globally. We also discuss future planning for cyber and wrap up by covering post-quantum encryption and how leaders should be getting ready for this now!
In our last episode for Season 7, we speak with Peter Coroneos, Founder of Cybermindz. In our conversation, we cover Peter’s incredible bio including being a globally recognised authority on cyber, we look at how he has informed policy that affects how we use the internet even today. We also discuss a variety of topics, with a focus on Peter’s very important work in supporting the humans that support cyber.
On this week's news episode, we review how the alleged criminals stung by the ANOM app sting last year are questioning the evidence’s lawfulness, then we’ll look at how prominent password management company LastPass has once again suffered a hack, we then dive into how ransomware attacks against a software company are having implications for the United Kingdom’s National Health Service. We finish with a wrap of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
On this week’s episode, we hear from Fergus Brooks, Executive Manager in Cyber Recover Planning within the finance industry. In this conversation we discuss the best way to approach the risk equation for cyber, we look at how we have gotten to where we are in terms of spend in defensive cyber. Fergus also talks to his time spent in the insurance industry and how that has helped is risk perspective. We finish by examining the understanding of impact when it comes to a successful breach with Foreseeable Maximum Loss.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
On this week's news episode, we’ll be reviewing the news of how Phishing fraudsters allegedly used a SIM box to fleece hundreds of victims. We then take a look at how the federal court of Australia has ruled that an insurer is not liable for ransomware clean-up costs, we also discuss the latest warning on a ransomware gang making million dollar demands. We then finish with a wrap up of the latest breaches and vulnerabilities to make the headlines.
Check out some of our latest articles:
Or subscribe to our free monthly newsletter!
This week we are joined by the Head of Presales and Security Specialist at Citrix, Aaron Robinson. In this episode we talk about the rise of zero trust in a hybrid working world. Aaron shares what he hearing from his customers, and provides some advice for business and cyber leaders as they balance security with employee experience and tips for secure remote working.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we take a look behind the news of how the police allege a Brisbane teenager built spyware that has been used by domestic violence perpetrators across the globe, we investigate how Microsoft have accused an Austrian firm of misusing spyware technology, we then look into how to secure the thousands of satellites now orbiting earth and their vulnerability to a cyberattack, and we wrap up with a review of the latest breaches making headlines.
Check out some of our latest articles:
To pay or not to pay: the ransomware dilemma
Securing the right doors: How to focus awareness training
This month in security: July 2022
Lee Roebig, Customer CISO for Sekuro joins the podcast this week to talk everything Zero Trust. We talk through what Zero Trust really is, its lesser known of benefits and how Zero Trust aligns with other well known frameworks.
We then delve into what type of organisation Zero Trust works for and then we round out the episode with Lee’s advice for pursuing a Zero Trust strategy.
Check out some of our latest articles:
This month in security: July 2022
How long have you got? The lifecycle of a breach
The open-source problem: convenience vs risk
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we break down the brand risk associated with compromised Social Media accounts as highlighted by the recent Disney hack, we review the crypto crash and its impact on ransomware in the short and longer term, we then look into the backlash to the facial recognition roll-out across major Australian retailers and how it could have been avoided, and we wrap up with a review of the latest breaches making headlines.
Check out some of our latest articles:
The open-source problem: convenience vs risk
What makes a great incident response plan
Could the crypto crash spell the end of ransomware?
This week we are joined by Emily Edgeley, an infosec analyst and manager turned public speaking coach. We tap into Emily’s expertise on story telling, why it’s important, how it works with specific examples for cyber. We then pivot into powerful presentations (something key for any CISO needing to get board buy in) including common presentation mistakes, messaging and how to use, or not use Powerpoint.
Check out some additional resources below recommended by Emily:
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we discuss 'Operation First Light 2022' which resulted in thousands of arrests and millions of dollars seized in a global takedown, we talk tax-time and the latest trends in this ongoing cyber challenge, discuss rules to mitigate 'SIM swap scamming', and review the latest breaches making headlines.
Check out some of our latest articles:
Why privileged access management matters more than ever
How upskilling can help beat the great talent shortage
Cyber resilience in the age of remote work
In our second Women in Cyber episode, Amy is back on the show and joined by Susie Jones CEO and Co-founder of Cynch Security, and Kistin Gunnis Operations Manager and Executive Mentor and Coach with Business in Heels.
Amy, Susie and Kistin discuss the ongoing issue of the gender pay gap and quotas, they talk about the importance of International Women's Day and the differing opinions of the day amongst women. They then share and talk to some of the most exciting aspects of working in the tech industry, as well as some of the challenges. The episode also provides some great advice for anyone, especially women, considering a career in technology.
For the latest cyber news and insights head to www.getcyberresilient.com
Geoff White, speaker, investigative journalist, author of The Lazarus Heist and co-creator of the Lazarus Heist podcast, joins the show this week to take us on his journey of going behind the news articles and unpacking some of the biggest cyber events of the past few decades.
Geoff talks to the origins and evolution of the Lazarus Hacking Group and the impacts of their biggest cyber heists, how cyberattacks still sit in a grey area of warfare, the future of cybercrime including its impact on the Metaverse, how AI and facial recognition are solving crimes, and gives us a look at the flip side of some of the world’s biggest cyber heists.
Listen to Season 1 of the Lazarus Heist Podcast here.
Head to https://geoffwhite.tech/ to pre-order The Lazarus Heist book.
Check out some of our latest articles:
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we explore what impact the change to a Labor government in Australia will have on national cyber policy, examine a 3-year-old government review calling for Australia to overhaul identity verification and make better use of biometrics, dive into the 5 key trends identified in the seminal Verizon DBIR report, and review the latest breaches and vulnerabilities making headlines.
Check out some of our latest articles:
This Month in Security: May 2022
Conti leaks shine light on ransomware’s darkest secrets
What global geopolitics means for your cybersecurity
Dan Gregory, CEO of The Impossible Institute, joins the podcast this week to talk about the effects of human behaviour in cyber. Dan explains how to work with the fact that employees won’t care as much about cyber as we do and the impacts of leadership democratisation.
We then look at how human trust has changed and how design beats discipline and motivation.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
This week we take a look behind the news that password-less security has finally arrived through the FIDO alliance, dig into the change to mandatory IoT security standards in Australia, review the latest cyber updates regarding the war in the Ukraine, review cyber’s role in the upcoming Australian election and beyond, and review the latest breaches making headlines.
Check out our latest articles:
Why the metaverse could be hacker heaven
Eat, spray, hack: how to defy brute-force password attacks
https://www.getcyberresilient.com/
Jason Duerden, Regional Director for SentinelOne ANZ, joins the podcast this week to lead us through the wonderful world of XDR (extended detection and response). Jason takes us through the evolution from Endpoint Antivirus, through EDR to what XDR means today.
We cover the overlap and the confusion with SIEM and store technologies and where all three fit in the grand scheme of things, and then peer into the crystal ball to understand Jason’s view on the future of XDR.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we look behind the use of ‘Bossware’ technology and how employers are monitoring web browsing and application use of their remote working employees, we dive into the ongoing risks in the property market with ‘payment redirection’ scams, update you on the role of cyber in the Russia-Ukraine conflict, and review the latest breaches making headlines.
Neil Clausen, regional CISO for Mimecast in Boston joins the podcast this week to take us through SIEM detection strategies, the best use of threat intel, running tabletop exercises, and Purple Teaming. Neil is seasoned security practitioner, who along with his leadership role at Mimecast lectures at Northeastern University College onDatabase Management, Security, and other IT-related courses. He’s also been on advisory boards for McAfee and Cisco and has built and managed SOC functions.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
This week we look behind the Australian government’s budget announcement of $10 billion dollars for cyber as part of program REDSPICE, as well as the tax breaks included for small business under the Technology Investment Boost. We also look into the latest attack by global hacking group Lapsus$, the two recent Apple patches for zero-day vulnerabilities, and review the latest breaches making headlines.
We are joined by Nick Abrahams Global Co-leader Digital Transformation Practice Norton Rose Fullbright. Nick is also the founder of the successful online legal site “LawPath”, he created the world's first AI-enabled privacy chatbot “Parker”, he has a thriving career as a keynote speaker on future trends and innovation, and is the author of the best-selling Kindle books "Big Data, Big Responsibilities" and "Digital Disruption in Australia".
In this episode jam-packed with his insights on ransomware, Nick walks us through his experiences working with boards during breaches and how they can build their muscle memory on how to tackle ransom payments. Nick also stares into the crystal ball to talk us through his vision on the future of Web3.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
This week we’ll be looking behind the government’s announcement to increase the Australian Defence Force by 18,500 people with a focus on cyber personnel, the recent announcement by Google to buy Mandiant, why a deepfake of the Ukraine President Zelensky capitulating to Russian demands is so concerning, and review the latest breaches making headlines including the Cyclops Blink botnet targeting Asus routers.
This week we are joined by Sara Abak, Head of Cyber Security and Risk at Dulux Group. Sara talks us through her perspective on awareness training fatigue, strategies for cyber talent acquisition and retention, and we get some great insights on how eCrime has changed and what it has meant for security leadership.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
This week we’ll be looking behind the cyber situation in the Ukraine and the call to arms for a ‘cyber army’ to volunteer, we’ll dive into the somewhat creepy world of ‘stalkerware’, the pros and cons of data gathering from our intelligence communities, and review the latest breaches to making headlines including the impact on Toyota’s factory operations after a supply chain attack.
This week we are joined by Mimecast’s Regional CISO for APAC, Mark O’Hare, who shines a light on the three common CISO persona types (the technical, the compliance, and the risk focused), their trademark strengths and how these personas can influence an organisation. We also discuss how and why MITRE ATT&CK Framework is useful and the utility of FAIR or Factor Analysis of Information Risk - including its strengths and where it falls short.
Expert opinions and insights on the biggest events making cybersecurity headlines this past fortnight.
In this episode we look behind the breach of sensitive COVID-19 QR code check-in details in NSW, review Microsoft’s announcement to block untrusted macros, give you the latest updates on the Critical National Infrastructure Bill and Ransomware Action plan, explore the topic of reversing redacted text and its roll in data protection, and review some of the latest cyber breaches making news.
This week our guest is Peter Soulsby, Director for Security Practise at NTT. Peter’s background in finance lends a business lens on his experiences of working with organisations that have just endured a cyber security breach.
Looking behind the breach, Peter speaks about the stories the media miss, where IR plans can fail, the psychology and human side to dealing with a breach as emotions run high and low, the value of external IR teams and how they can best work with internal teams, and the popular topic of prevention vs response/recover and where we should be spending our time and money.
In our first episode for 2022, we dive into the biggest news from the end of last year - the Log4Shell vulnerability. Where is it at? And what impact will this vulnerability have on companies making use of open-source libraries for code in the future?
We also look at the cyber risks associated with the Beijing Winter Olympics, cyber warfare in the Ukraine and Russia tensions, discuss the implications and usefulness of the Australian Identify and Disrupt Act as the first warrants begin to be issued, and review some of the latest cyber breaches including the Red Cross hack.
Our cyber resilience experts look back over the cyber events and challenges that shaped the year, review some of the insights that our incredible guests have brought to the show in 2021, discuss how to be cyber resilient across the holiday season, and peer into the crystal ball to make some predictions on what the new year will bring us.
Our guest for this week’s show is Bruce McCully, CSO at Galactic Advisors and author of Level Up: The Ultimate MSP Roadmap for Security, Operations and Profitability; and Plagued: The CEO's Ultimate Guide to HIPAA Compliance and Cybersecurity.
Bruce grew an MSP from scratch, and after smoke-jumping into organisations and seeing the effects of ransomware, he transitioned his teams to be more heavily focused on security. This exposure to both incident response and forensics has led Bruce and his teams to a great understanding of what good security looks like. Galactic Advisors now have a focus on MSPs.
In an episode packed with insight and stories from the trenches we get Bruce's thoughts on how to work with MSPs, why they’re an appealing target for attackers, and how MSPs add value. We also get Bruce’s thoughts on the importance of culture, communication, and measurement in cyber security.
Plagued: The CEO's Ultimate Guide to HIPAA Compliance and Cybersecurity: https://amzn.to/3rBauuf
Level Up: The Ultimate MSP Roadmap for Security, Operations and Profitability: https://amzn.to/3GjTf4u
In this week’s news episode our resident cyber experts review the most recent cyberattacks, explore their impact, and discuss what can be learned from them. Over the past week we have seen 3 large-scale attacks including GoDaddy who announced an attack that exposed the email and customer number of 1.2 million active and inactive Managed WordPress customers, Tasmania casino operator Federal Group’s payroll system who suffered an attack on their payroll system that left employees without their regular paycheque, and production delays are likely for the giant wind turbine manufacturer Vestas after a data breach that required systems to be shut down.
We also take a closer look at the recently released Cybersecurity Workforce Study 2021which revealed the very positive news that Australia’s cyber security workforce grew 23% in 2021 with flexible work arrangements making cyber staff happier than ever.
Our guest for this week’s show is Andrew Pritchett, CIO at Grant Thornton Australia. Andrew has had a unique career that has seen him traverse through a range of industries, from sheet metal production, to 10-pin bowling, and finally to IT where he quickly rose through the ranks to CIO roles.
Andrew brings his unique perspective to this conversation centred around building a positive cybersecurity culture and how to lead change using Kotter's eight step process. Andrew walks us through this process and his principles around patience, balance, coaching, and transparency.
Read Andrew’s article on this topic here: https://bit.ly/3HIyxgj
In this week’s cyber security news, we dive straight into the latest developments in this year's highest profile cyberattack, The Colonial Pipeline ransomware attack, and the announcement of a $10 million USD bounty offered by the American government for information which can lead to the "identification or location of any individuals" in a leadership position with DarkSide.
Closer to home, we review the news and impact of what some are calling a “landmark win for privacy” as the Office of the Australian Information Commissioner (OAIC) rule out the use of AI based facial recognition, and we also explore the recent announcement from NSW Electoral Commissioner John Schmidt who has said the polling body’s cyber security won’t meet the state government’s own standards in time for the council ballots.
For the latest cyber news and insights head to www.getcyberresilient.com
This week’s show is hosted by the newest member of our podcast team, Amy Holden. Amy is joined by two extremely talented women in the technology and cybersecurity space - Berys Amor the Director of Technology at Corrs Chambers Westgarth, and Alison O'Hare who is a Senior Technical Director at Mimecast.
Amy, Berys and Alison swap stories around unconscious bias toward women, the advantages of being a female in the tech and cyber space, some of the most exciting aspects of working in the industry, along with some of the challenges as well. The episode provides some great advice for anyone, especially women, considering a career in technology.
For the latest cyber news and insights head to www.getcyberresilient.com
In this week’s cyber security news we explore the confirmation that the Russian SolarWinds hackers breached 14 of Microsoft’s resellers and service providers, we discuss the Cyber Ready Program recently announced by the Australian Federal government to support the next generation of cyber security experts, we explore why there has been a decline in insurance claims for ransomware and the implications this could have for the cyber insurance space, and the 2022 big budget increase for cyber security predicted by Gartner’s annual survey.
Questacon’s Cyber Ready Program: https://bit.ly/3muu3kJ
For the latest cyber news and insights head to www.getcyberresilient.com
Our guest this week is Dr Chase Cunningham, retired Navy Chief Cryptologist and currently the Chief Strategy Officer with Ericom Software. He has experience across a range of the three-letter agencies in the US and over 20 years experience in cyber forensics and analytic operations. He also has a PhD in isolating insider threats through combining technical precursors with human behaviour modelling. His deep technical expertise has also fed into his work as an author, with his 2020 title “Cyber Warfare: Truth, Tactics and Strategies” and more recently his move into fiction with gAbrIel.
Chase and Gar dive into digital forensics in this episode along with Chase’s insights into ransomware, the misrepresentation and misunderstanding of AI, deepfakes, the machine learning and deepfakes being used for MasterPrints, and influence attacks.
For the latest cyber news and insights head to www.getcyberresilient.com
In this week’s cyber security news, we discuss the ramifications of the hack and data breach on the popular streaming service Twitch that resulted in hackers releasing source code and details of creator payments. We also review the latest attack on our health industry with the hack of Macquarie Health Corporation, the news that New South Wales will be extending DMARC for all local councils, and the implications of new laws that will require Australian companies to report ransomware attacks.
This week we are featuring an interview focused on ransomware and conducted by a Senior Analyst from the Economist, Wade Islan. Wade’s guest is Ciaran Martin, Professor of Practice in the Management of Public Organisations.
Prior to joining Oxford, Ciaran was the founding Chief Executive of the UK National Cyber Security Centre, part of GCHQ. Ciaran brings his expert analysis to this conversation and provides his perspective on what board members should know about ransomware, steps organisations can take to protect themselves, the value of human versus the technical controls and processes, resource considerations for best outcomes, the nuances in ransomware for different countries, the politics and global collaboration required to fight the problem, and what the future of ransomware will likely look like.
The big story for this week’s podcast is the recent news that the Federal Bureau of Investigation held the keys for the REvil ransomware attacks that have affected hundreds of businesses but held back in providing them to affected organisations. Was the FBI’s decision unethical or was it the right move?
We also discuss the announcement from the Victorian Government to commit over $50M to uplift their cyber security and resilience posture, the VMware vCenter instances that are under active attack, and the ongoing Pegasus spyware saga that has now been found on the phone of 5 French cabinet ministers.
For the latest cyber news and insights head to www.getcyberresilient.com
Gar is joined this week by Anthony Caruana, CEO of Media-Wize and all-around media guru. Anthony has spent time working as a writer, presenter, facilitator, journalist, media trainer and been a consultant for some massive companies.
Anthony talks us through what good crisis communications can do as part of an incident response, how to approach comms when the media will be involved, the thinking around crisis comms for different organisation sizes and verticals, what order comms should happen in, who are the best spokespeople, DIY vs external support for comms, and some incredible stories from the comms crisis trenches.
For the latest cyber news and insights head to www.getcyberresilient.com
In this week’s news update our team of cyber experts unpack and discuss this year’s newly published AustralianCyber Threat Report. The ACSC received over 67,500 cybercrime reports last year - that equates to one in every eight minutes!
The team also explore the potential legislation that will force banks and insurers to pay out victims of data breaches, how a local council (City of Stonnington) are bringing their systems back online two weeks after an attempted cyber attack, and also the zero day patch released by Apple last week to patch a security flaw across all its devices.
For the latest cyber news and insights head to www.getcyberresilient.com
Gar is joined this week by David Fairman, Chief Security Officer APAC for Netskope, venture partner for SixThirty, and advisor for Istari Global. He has also been a CSO for NAB, as well as Group Chief Information Security Officer for Royal Bank of Canada and spent time in JP Morgan and Royal Bank of Scotland.
David shares his experience and thoughts on the difference in approach and outcome between cyber security and cyber resilience, the creation of a risk aware culture in an organisation and how to fight complacency. Gar and David also discuss zero trust, digital risk vs cyber risk, and the integration of fraud, cyber and physical into a broader enterprise security approach
For the latest cyber news and insights head to www.getcyberresilient.com
This week our cyber experts discuss the implications of the new Australian Identify and Disrupt Bill that was seemingly rushed through senate last week and grants police powers to spy on criminal suspects online, disrupt their data and take over their accounts. The team also take a closer look at how the smishing scam ‘Flubot’ has evolved to now mimic parcel delivery text messages, and give you the lowdown on the new ransomware encryption technology ‘LockFile’.
In a very special episode, Gar is joined by Amy Holden from Mimecast and her friend Laura Jeffery who bravely shares her up-close and personal experience of how she became the victim of a business email compromise scam.
Laura walks us through the stomach dropping moment when she realised $65,000 in payments to a supplier for her home build had gone to cyber criminals. She talks about how the attack happened, the issue of responsibility, and the incredibly frustrating legal and criminal process.
This week in cyber security news, the team explore the major outages on high-profile websites caused by content delivery networks, the strange missed calls being received by people across Australia and how to avoid the Flubot, how cybercrime gangs are attempting to recruit malicious insiders, and the latest ‘High Alert’ message sent by the ACSC regarding the vulnerability affecting BlackBerry’s QNX RTOS.
For the latest cyber news and insights head to www.getcyberresilient.com
Our guest this week is Jay Hira, Security and Compliance Advisor (aka Chief Spy) at Salesforce. Jay has a broad experience having been on the tools as a pen tester, been a Senior Advisor at KPMG, Senior Consultant at IBM, Security and Risk manager at Accenture, Senior Manager at EY, and having worked cyber in finance organisations.
Gar and Jay had the opportunity to speak face to face in this episode and discus the why, when, and how surrounding the APRA CPS 234 standard and the role and value of certifications, standards and regulations. Jay also gives us his thoughts on the critical infrastructure bill, the inflection point we’re seeing in how consumers value privacy, and the zero-trust approach to cyber resilience.
For the latest cyber news and insights head to www.getcyberresilient.com
Our hot topics for this weeks cyber news episode include a conversation around the role of the ‘Big 4’ consultancies in Australia’s cybersecurity future and what the recent hiring spree at PWC and EY acquiring SecureWorx means. We review how Toll have rebuffed criticism that it allegedly acted too slowly in keeping the ASD informed during their two cyber-attacks last year. We look at Amazon’s huge $1B fine for alleged breaches of GDPR laws in Europe, and what a fine of this size means for other large tech companies. We also dive into a story that was published on Radio NZ last week that referenced information obtained from the ransomware attack on the Waikato District Health Board in May and the moral, ethical, and legal implications of such reporting.
For the latest cyber news and insights head to www.getcyberresilient.com
This week Gar is joined by Prescott Pym, Head of Managed Security Services for Verizon’s APAC SOC and still a self-confessed ‘cyberholic’. With 14 years under his belt at Verizon his experience and insights run deep.
Prescott brings his wealth of experience along with his passion for cyber resilience to this discussion focused on Verizon’s 2021 Data Breach Investigations Report. Prescott walks us through the changes to Verizon’s approach with the DBIR this year, key findings, some of the nuances in the industry and regional data such as the prevalence of social engineering in APAC, and what the data can be used for in terms of planning.
To get your copy of Verizon’s 2021 Data Breach Investigations Report please follow this link: https://vz.to/3A15sYM
For the latest cyber news and insights head to www.getcyberresilient.com
In the news this fortnight we discuss how Australia, along with a host of other countries, named China as the perpetrator of the Microsoft attack. We review how Australian organisations have been quietly paying millions in cyber ransoms. We explore how board members may soon be liable for cyber-attacks. And we deep dive into two high profile attacks - the zero-click Pegasus spyware sold to authoritarian governments, and the supply chain ransomware attacks against Kaseya.
For the latest cyber news and insights head to www.getcyberresilient.com
In a special episode focused on the cyber risks associated with upcoming Tokyo Olympics, Gar is joined by two heavy weights from Mimecast - the Director of Threat Intelligence Dr. Francis Gaffney, and Head of Risk and Resilience Carl Wearn.
In the episode we cover the risk radius of the upcoming Tokyo Olympics, the research approaches the Mimecast teams have used, and insights as to what attacks are most likely. Carl and Francis also look deep within their crystal balls to make some predictions on what they feel will be the largest threats for businesses and large events over the next 5 to 10 years.
For the latest cyber news and insights head to www.getcyberresilient.com
While Gar O’Hara and your regular podcast hosts take a short 2-week break, we put together some of our favourite segments from past episodes that we think deserve another listen.
The episode features Beverly Roche who talks to Gar about how humans need to be at the centre of AI and cyber security, Sunil Saale on the balance between security and enabling employees, Nigel Hedges on the value of automation in cyber security and Chirag Joshi on how to get cyber awareness support and buy-in from upper management.
For the latest cyber news and insights head to www.getcyberresilient.com
Gar O’Hara and your regular podcast hosts are taking a well-deserved break for a couple of weeks, so we’ve selected some our favourite segments from past episodes that we think deserve another listen.
These highlights include Joseph Carson on Estonia’s data embassies, Jenny Radcliffe on breaching physical security, Jess Lee on the impact and solutions for CISO and cyber security professionals burnout, and Mark O’Hare on what keeps the CISO of a cybersecurity company up at night.
For the latest cyber news and insights head to www.getcyberresilient.com
Our guest on the show this week is Joseph Blankenship, Vice President and Research Director at Forrester. Joseph helps clients develop security strategies and make informed decisions to protect against cyberattacks. His research focuses on security monitoring, threat detection, insider threat, phishing prevention, operations, and management.
Show host Gar O’Hara and Joseph discuss analyst firms and how to get the most from them, insider threats and how zero trust thinking aligns with email security, and Joseph takes out his crystal ball to make some predictions on what the future holds for cybersecurity and what he’s most excited about.
For the latest cyber news and insights head to www.getcyberresilient.com
In our latest news update our team of resident experts talk through the latest cyber security developments including the ransomware attack that shut down 35 hospitals in Ireland, the Australian government’s new ransomware awareness program, the Commonwealth Cyber Security Posture in 2020 report, and the 780 gigabytes of data stolen by hackers who breached Electronics Arts.
For the latest cyber news and insights head to www.getcyberresilient.com
Gar is joined this week by Jenny Radcliffe, aka the People Hacker, founder and director of Human Factor Security. Jenny is a world-renowned Social Engineer, hired to bypass security systems through a mixture of psychology, con-artistry, cunning and guile.
Jenny talks us through her experiences of physical penetration testing, her background and how that fed into her success, and how to use emotions to socially engineer people.
For the latest cyber news and insights head to www.getcyberresilient.com
Our resident cyber experts dive into the latest hacks and cyber news from Australia and around the globe - the attack that shut down Australia’s largest meat processor,the hack that compromised the New York transit authority, the audit that showed dozens of NSW local councils are without basic cyber security controls, and what the ABC and SBS are doing to boost their security following the infamous cyber-attack on Channel 9.
For the latest cyber news and insights head to www.getcyberresilient.com
Our guest this week is Ben Jones, CEO and co-founder of JumpStart Security - a company that focuses on making cybersecurity easy for small businesses.
Ben talks about the importance of simplicity for cyber, the challenges that SMB’s present, how to achieve cultural buy-in for security, and also that time he may or may not have bought a knock-off leather jacket from a scammer in Manchester.
For the latest cyber news and insights head to www.getcyberresilient.com
In our latest cyber news update our team of resident cyber experts talk through the latest cyber developments and hacks including the Colonial Gas Pipeline hack over in the US, analyse the shifting view of cyber insurance, and discuss stolen identities and where your details might be used.
For the latest cyber news and insights head to www.getcyberresilient.com
Dmitri Alperovitch joins the GCR podcast this week. Founder and former CTO at CrowdStrike, Executive Chairman of Silverado Policy Accelerator, and a man whose accolades include MIT Technology Review's ‘Top 35 Innovators Under 35’ and Fortune magazine’s ’40 under 40’.
In this very special episode, Gar and Dmitri discuss what it’s like to have a front row seat at the intersection of cyber security and politics, the importance of know-your-customer regulations, the rise of ransomware, and the imaginary “new normal” for cyber security.
For the latest cyber news and insights head to www.getcyberresilient.com
In our latest cyber news update we take a closer look at the hack that resulted in what hackers claimed was access to ‘tens of thousands’ of SIM cards that included ‘financial information, contracts and banking information’. We also discuss the proposed Australian cyber curriculum for kids aged 5 years and up, how cybercriminals are using Google search to snare unsuspecting victims for malware attacks, and the worrying statistic that over a third of New Zealanders fell victim to cybercrime last year.
For the latest cyber news and insights head to www.getcyberresilient.com
Lee Weiner leads Rapid7’s emerging products teams and the development of their cloud platform. Lee and Gar cover a range of topics and recent innovations in the sector including vulnerability management, misunderstandings on SIEM and SOAR, and what the world of SIEM and SOAR will likely bring i.e. big data, behaviour and threat analysis, and also the productivity bumps we can expect.
For the latest cyber news and insights head to www.getcyberresilient.com
In cyber news this fortnight we take a closer look at the recent attacks within Australian health facilities including the Eastern Health hack and how the Victorian State Government is taking action to become cyber resilient in the sector. We also dive into the ransomware attack blamed for Federal Group's casino pokies outage, the zero-day vulnerabilities in SonicWall’s Email Security product, and how President Biden’s administration plan to strengthen the cybersecurity of their power grid.
To say that Jo is heavily involved in the cyber security industry is an understatement. Jo has worked in security leadership positions with a host of of organisations, and has also has served in industry bodies such as AIIM and ISACA.
In this final part of our interview with Jo we dive into the topic of gender diversity. We talk about International Women’s Day, societal representation in leadership, pay gaps, period poverty, education and Jo’s work as part of the Civil Society Member of the Official Delegation to the UN’s 62nd Session of the Commission on the Status of Women.
In our latest news update the team discuss the latest cyber security attacks, hacks and trojans and how companies can better stay resilient. The GCR team explore the impact of the 9 Entertainment cyber attack, whether the 500M LinkedIn users data for sale is a hack or not, how a hacker almost poisoned the drinking water at a Kansas water utility, the way APRA is bringing cyber security into focus for our banking system, and the rise of malware for collaboration apps.
To say that Jo is heavily involved in the cyber security industry is an understatement. Jo has worked in security leadership positions with a host of of organisations, and has also has served in industry bodies such as AIIM and ISACA, and was a civil society member of the official delegation to the UN’s 62nd Session of the Commission on the Status of Women.
Jo’s experience and knowledge of the cyber security industry was simply too large for just one episode, so we have split it in two. In this first episode Jo’s provides her perspective on security leadership, reporting structures, cyber strategy and budgeting. Stay tuned for part two of this conversation where Jo and Gar have a very frank conversation about gender diversity.
The team discuss the biggest cyber news stories from the past fortnight including the impact of the Verkada CCTV data breach that allowed hackers to gain access to over 150,000 private surveillance cameras, the data breach of global information technology company SITA that provided hackers with access to passenger data from multiple airlines around the world, and how the Australian Prime Ministers office failed its own security audit after declaring the country was under attack.
UPDATE: Two days after recording this episode Nine Entertainment Co. was hit with a cyber attack causing problems with live broadcasting and print production systems. This is one of the largest cyber attacks in Australia to date, and will certainly be a topic we will deep dive into during our next news episode. For more information please visit this link: https://bit.ly/2PzXxzY
Gar O’Hara speaks with Nigel Hedges, Head of Information Security at CPA and adjunct professor of cybersecurity at Deakin University. Nigel walks us through his journey and how that’s shaped his security thinking, his approach and mindset for building and iterating security strategies, his way of communicating cybersecurity to audit and risk committees, and the value of automation and machines vs the humans in cybersecurity.
The team is back with this fortnights latest cyber security news and insights including the huge impact of the Microsoft Exchange vulnerability exploit, the Oxfam data breach that compromised personal details of its supporters, and the phishing scams targeting Aussies with fake vaccination role-out information.
Gar is joined this week by Safi Obeidullah who has a passion for enhancing employee experience and exploring the future of work. Gar and Safi talk through Zero Trust and contextual security controls, the impact transparency has on productivity, what the evolution of working models means at a macro level, and discuss what ‘digital wellness' actually means.
IT professionals, the unsung heroes during COVID - https://bit.ly/3cdhQuH
Citrix research on the future of work ‘Work 2035’ - https://bit.ly/3btyLtL
Gar and Brad bring you the latest cyber security news and insights including the tech giants criticising Australia’s critical infrastructure bill as ‘not fit for purpose’, calls for a national ransomware strategy from the Australian federal government, and the ever increasing volume and frequency of cyberattacks including the Bombardier breach.
Gar and Brad are back with the latest cyber security news and insights for 2021. In this episode the guys discuss the Accellion hack that was behind the Reserve Bank of New Zealand data breach and the dangers of supply chain hacks, how law enforcement and judicial authorities worldwide disrupted EMOTET banking trojan and took control of its infrastructure, the SocialArks leak of 214 million scraped social media profiles including private and public details for 2 million Australians, and how AI has was used to create deep fake social profiles on Twitter to attack the Belgian government’s 5G plans.
Graphika report on the Twitter clusters attack: https://public-assets.graphika.com/reports/graphika_report_fake_cluster_boosts_huawei.pdf
This week our hosts were live online, streaming on our new GCR TV YouTube channel and hosting a live audience via Zoom.
Dan, Gar and Brad take a look back over the cyber events and challenges that shaped the year, review some of the insights that our incredible guests have brought to the show in 2020, discuss how to cyber resilient across the holiday season and peer into the crystal ball to make some predictions on what 2021 will bring.
View the video from this episode on our new GCR TV YouTube channel: https://www.youtube.com/channel/UCpJWYZq9-RvCBMVZif8YgZg
This week Gar is joined by Leonie Smith aka ‘The Cyber Safety Lady’ and host of the Digital Families podcast. Leonie has had an incredibly diverse career with a pedigree in graphic design, performing arts and was the CEO of social media training and strategy company Digital Breezes. Leonie was an early adopter of the internet and the common thread in her work is meaningful communication and effecting change.
Leonie and Gar discuss the important ways parents and carers can better navigate the internet, social media and gaming but more importantly how they can help their children. Leonie also lets us know about the three things she would have us do to be safer online, where the responsibility lies for keeping children safe online, the roles of campaigns and regulations for societal level changes, how to go about keeping kids safe while gaming and how to help our kids if something awful like cyber bullying or grooming should occur.
Check out the Digital Families podcast here: https://apple.co/3kZQVVf
This week’s guest is Laurie Joyce, Head of Security Compliance at The Australian Red Cross Lifeblood. Laurie has worked in counterterrorism intelligence analysis for the Victorian Police in Australia, and has experience in enterprise compliance and risk management across a number of organisations including his current role at Red Cross Lifeblood as Head of Security Compliance.
In an episode focused on healthcare, Gar and Laurie discuss medical device compliance, the challenges of holding highly sensitive personal health info, and the Red Cross breach which is considered by many as an example of a good breach response. Laurie also walks us through his work in the Reconciliation Action Plan Working Group which ties in nicely with the fact that it was NAIDOC week when this episode was recorded.
Note: There is a brief mention of sexual violence in this episode, please be mindful that this may upset some listeners.
Gar’s guest this week is Sunil Saale, Head of Cyber and Information Security at MinterEllison. Sunil comes from a heavily technical background having worked at Tata Consultancy Services as an engineer, before progressing into IT Management for PwC Australia and finally heading up cyber at MinterEllison.
Gar and Sunil discuss COVID and how it has changed the dynamics for the Minter Ellison staff, the move into mobile work forces, what the ‘new normal’ looks like, key challenges Sunil and his team faced during the various stages of COVID transition (e.g. EUBA patterns falling apart in the early stages), the balance between security and external digital collaboration, cloud as a path to resilience, end user behaviour programs and what Sunil has learned through the COVID transition.
The Get Cyber Resilient team are back again for the October 2020 cyber news roundup!
Gar and Dan take a look back over the month that has been and the insights that our October guests brought to the show.
Brad and Dan discuss the latest in cyber security news including the fake jobseeker ads, how cyber criminals are using celebrity gossip as a lure for Australian targets, the importance of resilience even in a SaaS world, the most recent ransomware attacks and the DFAT email blast that exposed email addresses of Australians stuck overseas.
After the news, Dan and Gar jump into a discussion on hype vs utility of Artificial Intelligence and Machine Learning.
This week’s guest is Mark O’Hare – Mimecast’s CISO. Originally from South Africa, Mark has worked in IT and security in the UK, the US, the Cayman Islands and has been in Australia for nearly a decade. As Mimecast’s CISO he is at the forefront of the challenges facing CISOs in public companies.
Mark walks us through his long and winding career and provides us with some great insights in this episode. He talks about the cybersecurity issues that keep him awake at night, where and how he consumes the avalanche of information he needs to each day, regulatory influence, finding and keeping the right people, and leaves us with his ‘one important thing to do per day’ recommendation.
Gar O’Hara is joined this by Jessica Lee – founder and owner of Jessica Lee Consulting. Jess has a deep background in organisational psychology. She’s worked in nearly every vertical and before going out on her own worked for big names like Diageo, Jurlique and Universal Music. Jess was the perfect person to talk about a very, very important resilience topic – mental health and wellbeing.
We all know about CISO burnout, the stats are scary. The average tenure for a CISO is 26 months, with nearly a third reporting stress impacting their health, and an increase in the use of alcohol and medication. Jess talks us through what she is seeing in organisations during COVID, with some cracking insights on the differences between stress and burnout, how much it can cost organisations, and perhaps most important of all - how to engage in self-care.
With so many people feeling stressed, the level of uncertainty that exists for many people during this time, and with how much burnout happens in the cyber industry even during normal times, this is an important conversation.
Find out more about Jessica Lee Consulting and how they are advancing business through psychology here: https://www.jessicaleeconsulting.com
Check out the links below for more resources on mental health and wellbeing in Cyber Security
CISO stress and burnout cause high churn rate (SearchSecurity) - https://bit.ly/33Ra8mK
Why burnout is such a problem for CISOs (Forbes): https://bit.ly/3djBs0l
Positive Psychology resources from PERMA (Martin Seligman): https://bit.ly/34LJ2wK
TED Talks to listen to when feeling burned out (TED Talks): https://bit.ly/2GYn954
This week Gar is joined by Jason Duerden, Managing Director of BlackBerry Spark. From beginnings in events and hospitality, Jason says he “fumbled his way into cyber”. He started out working with a hotel group running their IT ops and security, then dived into systems integration before ultimately finding his place in cyber business operations. Jason has worked with Aquion and Cylance and now leads at BlackBerry Spark after Cylance’s acquisition.
Jason and Gar talk about the perception of vendors in cyber resilience and Jason provides some insights into how the vendor side of our industry could be improved. Jason also talks about ‘fear’ as it relates to cyber security, the messy problem of IoT, the national Cyber Security Strategy and Jason gives us his thoughts on how to better protect the SMB space.
Gar O’Hara is back again with Dan McDermott and Bradley Sing for the September 2020 monthly roundup episode.
Gar and Dan take a look back over the month that has been and the insights that our September guests brought to the show. Brad and Dan discuss the latest in cyber security news including the shutdown of the New Zealand Stock Exchange, the incredible 2,266 cyber security incidents countered by the ACSC last year, the hackers that claimed to have breached the Department of Education, the 54,000 NSW drivers licences that were potentially exposed and the world’s first recorded fatality attributed to a cyber attack.
After the news, Dan and Gar take some time to dive into detail on the governments code of practice for the Wild West of the internet, the IoT.
Gar’s guest this week is the host of the Cyber Security Café podcast and Interim CISO for Sigma Healthcare, Beverley Roche. Like many IT professionals, Beverley started on a help-desk and did training and consulting. Looking for something new, Beverley completed a postgrad in eCrime and hasn’t looked back since. Beverley has worked in a number of roles in data privacy and security for a range of companies including The Office of the Children's eSafety Commissioner, ANZ, BHP and Australia Post.
Beverly speaks about what has changed during her career – the good and the bad, the human side of cyber security and the myths. Gar and Beverly also discuss the importance of digital literacy and how to approach that in broader society, specifically during the employee lifecycle. And we round out the episode with Beverly speaking about her involvement with the Security Influence and Trust Group, their mission and outputs.
Check out the Cyber Security Café podcast here: https://apple.co/3hPmu2s
Gar is joined this week by Andrew Bycroft, CEO of iResilience and author of ‘The Cyber Intelligent Executive — Securing the Future of your Organisation’. Andrew has had an interesting career progression, moving from studying the ionosphere as a physicist to following his passion and becoming an IT manager.
From IT manager, Andrew then moved towards security and did managed security services, operations consulting, architecture and even went to the dark side to work in sales. Six years ago, Andrew started his own company to work with execs and boards to help them understand the difference between cyber security and cyber resilience and the role that culture plays in transforming organisations to solve cyber related issues.
In this episode Gar and Andrew spend some time discussing cyber security vs resilience, what we need to think about beyond People Process and Technology and the importance of communication and transparency. Andrew also details his 8 attributes for a healthy cyber culture, how to navigate the change of culture in complex organisations, resilience profiles and Andrew’s model for resilience maturity.
Get your copy of Andrew's book here: https://amzn.to/32s2I99
This week Gar is joined by Joseph Carson, Thycotic’s Chief Security Scientist and Advisory CISO. He’s the architect behind some of the worlds largest cloud environments, has worked to digitally transform cyber security education to online delivery, and now based in Estonia he has been working in areas such as digital identity.
He’s won many awards and is driven by a desire to give back to the community. Joseph walks us through what cyber resilience looks like at a country level, including how Estonia has gone about building trust with their citizens. He speaks about education for cyber security, immigration policies, data resilience through data embassies, and Jospeh outlines the jaw dropping economic benefits that an advanced digital society can achieve through removing friction.
Connect with Joseph on LinkedIn: https://www.linkedin.com/in/josephcarson/
Follow Joseph on Twitter: https://twitter.com/joe_carson
Check out Jospehs books:
https://thycotic.com/resources/wileys-dummies-cybersecurity/
https://thycotic.com/resources/wileys-privileged-access-cloud-security-for-dummies/
Gar is joined this week by Michael McKinnon, AISA Melbourne’s Deputy Chair. Michael has done it all, he was the CTO as well as the Media Spokesperson and Security Awareness Director at AVG. He worked at HackLabs in governance, pen testing, ran security awareness training and red teaming. He worked at Pure Security providing C-level advice, incident leadership and future proofing security spend. Michael also gives back to the security community with his AISA involvement.
Thanks to Michaels wide range of security experience, there’s very little you can’t ask him about. In this episode we get his perspective on the role and value of formal education and certifications in the world of cyber security, how training has evolved and where it might go, and what hiring managers are looking for. Gar and Michael also talk about the world of SMEs and reflect on the challenge of the supply chain, c-level strategy, the disconnect between business and tech, ransomware trends, incident response and digital forensics.
This week our hosts are LIVE online to celebrate the 1st birthday of Get Cyber Resilient! Dan, Gar and Brad take a look back over the biggest cyber security news in 2020, and the insights that the past 18 incredible guests have brought to the show. Our hosts then answer questions from our live audience on a range of cyber security hot topics.
Check out This year in Security 2020
Gar is joined this week by Dr Francis Gaffney, Mimecast’s Director of Threat Intelligence and Response who leads the data science research teams for threat intelligence, risk and resilience, threat intelligence analysis and strategic intelligence. Francis has had a fascinating journey that began with an honours degree in chemistry and a career teaching. He then moved to a position in government providing advice on the threats domestic chemicals posed and provided guidance on information warfare (psyops), before moving into counter terrorism and finally transitioning into cyber security.
Francis brings his considerable knowledge and expertise to this conversation surrounding cyber threat intelligence, its function and value. Gar and Francis also discuss technical vs strategic threat intelligence, how to build a threat intel team, trends for cyber attacks and a big one… the value of attribution
Gar’s guest this week is Jacqui Nelson, the CEO of Dekko Secure - an Australian software company that helps government, law enforcement, medical and legal organisations secure their workflows when working with sensitive and confidential information.
Jacqui walks Gar through her journey from an investor in Dekko to CEO, her passion for solving business problems, Dekko’s new end-to-end encrypted video conferencing software, and delve into the importance of trust – not just from a digital perspective but across every facet of business and our lives.
New AustCyber podcast: https://podcasts.apple.com/au/podcast/ozcyber-unlocked/id1524419882
Gar O’Hara is back again with Dan McDermott and Bradley Sing for the July 2020 monthly roundup episode. Brad and Dan discuss the latest in cyber security news including Cosmic Lynx, tax time ATO scams, Australia’s ranking on the most hacked countries list, and WA’s pager system exposure.
Then Dan and Gar take some time to dive into detail on the biggest news story of this month, the Twitter profiles hack.
This week Gar gets sassy (SASE) with Mike ‘Fergo’ Ferguson, Senior Sales Engineer at Netskope. Mike has been an IT geek his entire life, with a passion for computers fuelled by his father who owned a cyber cafe. Mike started in IT support and contracted out in the UK before heading to the European Central Bank in Germany, then to Australia with Websense where Mike became an SME in data leak prevention before starting his role at Netskope.
In a slightly more technical episode of the GCR podcast, Mike and Gar dive into everything Secure Access Service Edge, from a high level explanation SASE and its capabilities to what protections are possible within the architecture.
Cyber security leader, Chirag Joshi, joins Gar to discuss his career journey and what it means to be ‘cyber aware’. Chirag is the Director of ISACA’s Sydney Chapter and author of the 7 Rules to Influence Behaviour and Win at Cyber Security Awareness. Chirag has also created, rolled out and successfully managed cyber security risk awareness programs across multiple countries and is a much sought after speaker at cyber security events.
During this interview, Chirag and Gar discuss a range of topics surrounding creating awareness in your workplace, including the dangers of being boring, why you shouldn’t rely on bad news stories, why context is important, how to use you allies, and most importantly — how to get the support of upper management.
Visit Chirag’s website to get your hands on a copy of his latest book: https://www.chiragdjoshi.com
This week Gar is joined by Prescott Pym, Operations Director for Network Security at Verizon and self confessed ‘cyber-holic’. Prescott spent 7 years working at the Australian Bureau of Statistics before joining Verizon as a security analyst back in 2007. Prescott has built out SOC teams in Australia, India, Japan, Germany, Switzerland and the USA and currently runs a 70 person APAC SOC with a focus on government.
Prescott brings a wealth of experience along with his passion for cyber resilience to this discussion focused on Verizon’s 2020 Data Breach Investigations Report including how Verizon use the report, the unexpected trends the data highlights, how the tried and tested attacks are still doing damage, what the data means to small and large businesses and where these attacks are coming from.
To get your copy of the Verizon’s 2020 Data Breach Investigations Report please follow this link: https://vz.to/3hR38eI
Gar O’Hara is joined once again by Dan McDermott and Bradley Sing for the June 2020 monthly roundup episode. Gar and Dan take a look back at some of the key learnings recent guests have brought to the show, Dan and Brad discuss the latest in cyber news including the recent cyber attacks on Lion as well as Fisher & Paykel.
Gar and Dan finish up the episode by discussing by far the most dramatic cyber event this month - the Prime Minister of Australia’s announcement that the country was under cyber attack!
Gar is joined this week by Luke Francis, the Channel Director for CrowdStrike in Australia and New Zealand. Luke has over 20 years experience in global sales and marketing and has had a number of successful tenures with Dell, Citrix, and BMC Software.
In this episode, Gar and Luke discuss the CrowdStrike 2020 Global Threat Report in detail — including how the report is created, how geopolitical and socio-economic unrest is reflected in the report, COVID-19, the trends highlighted within the report and their impact on Australia and New Zealand, the rise in malware, the uptake in data exfil and its use with ransomware, and also the recommendations within the report. Luke brings his considerable experience and knowledge to the conversation and also provides some of his own insights on integration and security fabrics.
Get your copy of the CrowdStrike 2020 Global Threat Report: https://bit.ly/37FPJRW
Gar’s guest this week is Dr. Cate Jerram, principle researcher and lead academic on cyber security at the University of Adelaide Business School. Cate’s background in adult education led her to information systems research and the human and organisational aspects of cyber security. Cate also helps design and teach cyber security courses and programs as well as supervise PhD students.
Cate and Gar talk broadly on the human aspects of cyber security and the delay in organisations understanding its importance, how cyber posturing is playing into VCs desire to put money into startups, and discuss Cate’s latest research.
This week Gar is joined by Shannon Sedgwick, Senior Managing Director at Ankura. Shannon is a seasoned director with deep experience providing future-focused leadership to governments, private enterprises and boards. Shannon has spent over a decade working globally across tech, cyber security as well as government risk and compliance. Shannon isn’t afraid to share his opinion and often expresses them on broadcast media, through his regular published articles and on the Get Cyber Resilient Podcast. Gar and Shannon discuss a number of topics including navigating technologies strategies during COVID-19, the tech landscape in terms of buyers and sellers and ask what’s broken with conferences and how can they can be improved?
Ankura provide fit-for-purpose and cost optimisation analysis and review of companies technology and cybersecurity architecture and vendors to reduce complexity while maintaining governance, risk, and compliance standards, as well as identify opportunities for cost reductions. https://ankura.com/
Couch potato style cyber security event mentioned by Shannon was ComfyCon AU: https://www.comfyconau.rocks/
Gar O’Hara is back again with Dan McDermott for the May 2020 monthly roundup episode. This month Gar and Dan are also joined by Mimecast’s very own Bradley Sing who is an active contributor to the Get Cyber Resilient blog and a cyber resilience renaissance man. In this roundup episode Gar and Dan discuss some of the key learnings recent guests have brought to the show, Dan and Brad discuss the latest in cyber news and Gar and Dan finish up the episode by diving into a very popular security question — are our phones listening to us? To read the article that prompted this question, please follow the link below.
John McMahon: Is Your Phone Listening To You? We Ask The Experts - https://bit.ly/3eF6jnc
Gar O’Hara is joined this week by Phil Zongo, author of The Five Anchors of Cyber Resilience. Phil has over 15 years experience in risk management and cyber security working with some of the biggest companies out there. His focus these days is on cyber resilience and his work within the Cyber Leadership Institute which he co-founded with Jan Schreuder and Darren Argyle.
Gar and Phil dive into a range of topics over the course of this episode with some terrific insights provided by Phil on how to achieve cyber savvy workforces, key pain points for CISO’s, how to get cyber security strategy right, stakeholder management, the value of automation and of course the impact of COVID-19 on the industry.
The Five Anchors of Cyber Resilience: https://amzn.to/2y4MUN8
CISO Playbook: https://bit.ly/2T2kniw
This week Gar does a deep-dive into the security of the COVIDSafe app with the CIO of Allens, Bill Tanner. Bill has over 12 years experience in the legal industry and has some unique insights on the COVIDSafe app that were gained from evaluating the app for his staff. Bill shares his thoughts and experiences from attending a recent app teardown session conducted by Geoffrey Huntley, who is leading a local research group on COVIDSafe security and privacy. Gar and Bill explore exactly what the app does and doesn’t do, the privacy concerns as well as the legal issues surrounding it.
Security research on the COVIDSafe app: https://covidsafe.watch/
Links to some great articles and research from Allens on the COVIDSafe app
COVIDSafe: What we now know: https://bit.ly/361Jozo
COVIDSafe Bill: Good progress but theres more to do: https://bit.ly/2yWNrRu
Gar O’Hara catches up with his old colleague and cyber threat intelligence specialist, Kendal Watt. Kendal is a Senior Account Executive at Recorded Future, a company that provides businesses with real-time threat intelligence to help them proactively defend against cyber attacks.
Kendal’s impressive cyber security career spans over 20 years and 3 continents. He has worked with a range of companies from startups to multi-nationals and advised on holistic cyber security strategy, governance and compliance including recommending the most appropriate tools to fit requirements.
During this podcast, Gar and Kendal explore the exciting threat intelligence space and discuss the deep shift that is needed in the industry to proactively get ahead of the advanced cyber threats that we are seeing today and expecting in the future.
Dan McDermott and Gar O’Hara are together again with the latest news in cyber security from Zoom Doom to the Australian Government's COVIDSafe app. The two also take a quick look back at some of the incredible guests they’ve had on the show from Craig Ford (A Hacker I Am) to Shamane Tan (Cyber Risk Meetups) and the insights that these guests have brought to the show.
In this episode of the Get Cyber Resilient podcast, Gar O’Hara speaks with the founder and CEO of KB Industries, Karissa Breen. KB Industries is a MarComms agency that specialises in Cyber Security and Technology companies. They help start-ups get established and help mid-level to enterprise companies hone their messaging. They also produce a range of written and video content along with a podcast and KBTV which showcases some of their clients groundbreaking and innovative work. Gar and Karissa discuss her journey to success along with how cyber security companies can better communicate their brand and the common problems many of them face.
Subscribe to Karissa’s podcast KBKast here: https://karissabreenindustries.com/kbkast/
In a very special catchup episode, Garrett O’Hara sits down to speak with possibly the busiest person in cyber security, Shamane Tan. Shamane is the author of Cyber Risk Leaders, founder of Cyber Risk Meetups and an Executive Advisor for Privasec. Gar and Shamane discuss her journey from IT to cyber security, the success of her meetups and the mega (virtual) c-suite series she’s running, and the state of the cyber security industry throughout APAC. Addendum: Shamane spotted that she mentioned 120 mitre attack techniques and that it's actually now over 170 (PRE-ATT &CK techniques... things move fast in the world of cyber resilience!
To get involved with Cyber Risk Meetups you can visit https://www.cyberriskmeetup.com
For a copy of Shamane’s latest book, Cyber Risk Leaders, please visit https://mysecuritymarketplace.com/books-listing
You can watch Shamane’s mega C-Suite series on the Cyber Risk Meetup Youtube channel https://bit.ly/34IGYVI
Host Garrett O’Harra catches up with Blake Deakin, Director and Principal Broker at Cyber Insurance Australia to discuss how cyber insurance is growing in popularity as the world adapts to large scale cyber attacks. Blake provides some insights into how cyber insurance works, what it covers and to what extent, the ‘gotchas’ you need to be aware of in policies, and shares tales from his extensive career in cyber insurance.
If you have any questions regarding cyber insurance, you can get in touch with Blake by visiting www.cyberinsuranceaustralia.com.au
Host Garrett O’Hara sits down with Damien Lewke, Systems Engineer at Palo Alto Networks, to chat about the huge volume of current cyber threats and also some hot topics including: hype vs practicality of machine learning and AI, tech consolidation trends, data lakes vs data graveyards, and big game hunting - hackers collaborating to attack big organisations.
In this working from home edition of the Get Cyber Resilient Show, Garret O’Hara chats with Craig Ford, author of ‘A Hacker I Am’ and Senior Security Engineer at Davichi Computer Services. Craig and Gar speak about careers in cyber security including what employers look for, mentoring and diversity in the industry, along with current cyber threats and how to get back to basics. #getcyberresilient #cyberresilience
Related links:
Craig's Book: https://www.amazon.com.au/Hacker-I-Am-Craig-Ford/dp/0648693910
For the latest cyber news and insights head to www.getcyberresilient.com
As COVID-19 continues to have a huge impact on businesses and people across the globe, hosts Dan and Gar discuss the implications the virus has on cyber security and the many ways that attackers are using this opportunity to pray upon the vulnerable. What do you stay vigilant about and how do you do this?
Related articles:
https://www.getcyberresilient.com/points-view/what-coronavirus-outbreak-can-teach-us-about-cybersecurity
https://www.getcyberresilient.com/practical-application/cybersecurity-not-immune-covid-19
Should you click on all links in emails? Our hosts Garrett O'Hara and Dan McDermott talk to Human Error about the role he plays in cyber security.
Related articles:
Watch Human Error in action: https://www.youtube.com/playlist?list=PLkxsTFLMcMvDdpeDtgFuOfjqJ5iNX_ES2
For the latest cyber news and insights head to www.getcyberresilient.com
In the first episode of the Get Cyber Resilient Show for 2020, our new host Dan McDermott and mainstay Garrett O'Hara chat about how cyber criminals are exploiting the Coronavirus, explore the recent cyber attacks on companies such as Toll, and discuss how businesses can better protect themselves and control the narrative when a breach has occurred.
Related articles:
https://getcyberresilient.com/threat-insights/how-fake-coronavirus-warning-emails-are-spreading-malware-across-australia
https://getcyberresilient.com/practical-application/small-time-nuisance-destroyer-enterprises-rise-blackwhaling
In this episode, Gregor Jeffery and Garrett O'Hara discuss downtime due to Office 365 disruption, cyber awareness training for the general public and Black Friday. Garret catches up with Safi Obeidullah, Field CTO of Citrix APJ, to talk about the concept of digital twins and driving cyber resilience through rapid response.
If you enjoyed The Get Cyber Resilient Show, head over to GetCyberResilient.com, a new online destination for cyber professionals in Australia and New Zealand.
Related articles:
Customers are the target of cybercrime this Black Friday, but your business could be the real victim
https://www.getcyberresilient.com/threat-insights/customers-are-target-cybercrime-black-friday-your-business-could-be-real-victim
O365 disruptions wreak havoc across APAC: the case for business continuity
https://www.getcyberresilient.com/practical-application/o365-disruptions-wreak-havoc-across-apac-case-business-continuity
Uni IT chiefs want an 'Aussie lamb campaign' approach to cyber awareness
https://www.itnews.com.au/news/uni-it-chiefs-want-an-aussie-lamb-campaign-approach-to-cyber-awareness-534556
In this mini-episode, hosts Gregor Jeffery and Garrett O'Hara talk through a host of interesting developments in the world of cyber security.
#1. Twitter has drafted a policy to deal with “synthetic and manipulated” media – looking for public feedback
https://www.gizmodo.com.au/2019/11/twitter-wants-the-hive-mind-to-weigh-in-on-its-deepfake-policy/
#2. Two Sydney women have been charged over their alleged involvement in a $500,000 business email compromise scam
https://www.itnews.com.au/news/two-charged-over-500000-bec-scam-533833
https://www.itnews.com.au/news/former-nsw-tafe-it-manager-sentenced-to-eight-years-jail-533902
#3. NAB security team chases down investment scam sites
https://www.itnews.com.au/news/nab-security-team-chases-down-investment-scam-sites-533763
https://www.itnews.com.au/news/privacy-fears-over-proposed-medicare-data-matching-scheme-533767
https://www.itnews.com.au/news/govt-proposes-medicare-data-matching-scheme-for-fraud-crackdown-531404
If you enjoyed The Get Cyber Resilient Show, head over to GetCyberResilient.com, a new online destination for cyber professionals in Australia and New Zealand.
The Get Cyber Resilient Show is brought to you by mimecast.com
In this mini-episode, hosts Gregor Jeffery and Garrett O'Hara come to you live from the recent Gartner IT Symposium 2019 in sunny Brisbane.
They talk about the influence that CIOs and CISOs need to wield within organisations in order to effect better cyber resilience and turn security into a competitive advantage. They also explore what ‘security fabric’ is and should be...plus more!
If you enjoyed The Get Cyber Resilient Show, head over to GetCyberResilient.com, a new online destination for cyber professionals in Australia and New Zealand.
The Get Cyber Resilient Show is brought to you by mimecast.com.
The Gartner IT Symposium: www.gartner.com/en/conferences/apac/symposium-australia
In this episode, Gregor Jeffery and Garrett O'Hara discuss an Australian cyber-criminal ring targeting Superannuation accounts, scammers using deep fakes of CEO voices and the recent PayID hack that affected the big four banks. Garret also interviews Mitch Owens, CTO at Gilbert + Tobin Lawyers.
If you enjoyed The Get Cyber Resilient Show, head over to GetCyberResilient.com, a new online destination for cyber professionals in Australia and New Zealand.
The Get Cyber Resilient Show is brought to you by mimecast.com.
Related articles:
This month in security: September 2019 https://www.getcyberresilient.com/threat-insights/month-security-september-2019
This month in security: August 2019 https://www.getcyberresilient.com/threat-insights/month-security-august-2019