SecurityMetrics Podcast: Recent Episodes

SecurityMetrics

The SecurityMetrics Podcast, hosted by Jen Stone (Principal Security Analyst, QSA, CISSP, CISA), will help you understand current data security and compliance trends. Each episode will feature a different security professional offering tips and security best practices.

View Details

Confused about PCI DSS compliance standards? This video breaks down each available SAQ type, including: SAQ-A, SAQ P2PE-HW, SAQ D for Service Providers, and the newly introduced SAQ SPoC for PCI DSS 4.0.

Learn which one is right for your business based on your payment processing environment.

Learn about:

  • Different SAQ types for merchants
  • Eligibility criteria for each SAQ type
  • Factors to consider when choosing a SAQ type
  • Simplifying your PCI compliance

Listen now to learn what your business can do to protect itself from data breaches and be compliant.

PCIcompliance #paymentsecurity #merchant #smallbusiness #cybersecurity

https://www.youtube.com/watch?v=XoR0Tt8uHl4

Request a Quote for a PCI Audit ► https://www.securitymetrics.com/pci-audit

Request a Quote for a Penetration Test ► https://www.securitymetrics.com/penetration-testing

Get the Guide to PCI DSS compliance ► https://www.securitymetrics.com/lp/pci/pci-guide

Get FREE security and compliance training ► https://academy.securitymetrics.com/

Get in touch with SecurityMetrics' Sales Team ► https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place

View Details

Join Jen Stone as she chats with DevOps engineer and Day Two DevOps podcaster Kyler Middleton about her unique journey from a rural upbringing to becoming a DevOps expert. Discover how Kyler's passion for teaching led her to a career in technology, and learn about the importance of automation and documentation in building secure and efficient cloud environments.

This episode dives deep into DevOps practices, the role of Terraform, Azure vs AWS, and the challenges organizations face when adopting cloud technologies. Kyler shares valuable insights on overcoming common hurdles, fostering a blameless culture, and the future of DevOps. Don't miss this engaging conversation!

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

Request a Quote for a PCI Audit ► https://www.securitymetrics.com/pci-audit

Request a Quote for a Penetration Test ► https://www.securitymetrics.com/penetration-testing

Get the Guide to PCI DSS compliance ► https://www.securitymetrics.com/lp/pci/pci-guide

Get FREE security and compliance training ► https://academy.securitymetrics.com/

Get in touch with SecurityMetrics' Sales Team ► https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place

View Details

Worried about hotel hacking? This episode unveils the cybersecurity protocols of resorts like Atlantis. ️

Dive deep into the unique challenges of cybersecurity in hospitality, from balancing guest convenience with ironclad defenses to training a diverse workforce.

Tsega Thompson, Executive Director of Cybersecurity and Data Privacy at Atlantis Resorts, shares her insights on:

  • Getting into Cybersecurity
  • Special Challenges of Cyber in the Hotel Industry
  • Training your workforce effectively

This is your essential guide to cybersecurity in the hospitality industry, packed with valuable tips for travelers and hospitality professionals alike.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

Request a Quote for a PCI Audit ► https://www.securitymetrics.com/pci-audit

Request a Quote for a Penetration Test ► https://www.securitymetrics.com/penetration-testing

Get the Guide to PCI DSS compliance ► https://www.securitymetrics.com/lp/pci/pci-guide

Get FREE security and compliance training ► https://academy.securitymetrics.com/

Get in touch with SecurityMetrics' Sales Team ► https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place

View Details

Is your penetration testing just a compliance formality? This episode of the SecurityMetrics Podcast redefines pen testing as a strategic partnership, empowering you to get the most out of your assessments.

Join Jen Stone and James Farnsworth as they discuss:

  • The critical role of scoping: Learn how to align business needs with technical assessments for a truly impactful pen test.
  • The difference between a vulnerability scan and a penetration test
  • Unlocking report potential: Discover how to leverage pen testing reports for maximum security benefit.
  • Tips for fostering a successful collaboration with your pen testing service.

Stop seeing penetration testing as a checkbox exercise and transform it into a powerful tool for boosting your organization's security posture.

Bonus Resources:

  • PenTest FAQs:https://www.youtube.com/watch?v=EECUTDMn43U
  • James' Previous Episode: Hacking Your Career: How to Become a Penetration Tester | SecurityMetrics Podcast 95

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

This episode of the SecurityMetrics Podcast is a valuable resource for MSPs who want to learn more about HIPAA compliance and how to better serve their healthcare clients. Join Jen Stone and David Sims to learn more about how Managed Service Providers (MSPs) can empower healthcare organizations to achieve HIPAA compliance.

Learn about:

  • The challenges of data discovery and data sprawl in healthcare organizations.
  • The importance of having a documented HIPAA compliance program.
  • The difference between required and addressable HIPAA controls.
  • Choosing the right MSP for your healthcare organization
  • How to successfully collaborate with HIPAA compliance officers within healthcare organizations.
  • Why HIPAA Compliance goes beyond a BAA

Bonus Resources:
David Sims and Donna Grindle’s Podcast: Help Me With HIPAA (@Helpmewithhipaa) https://helpmewithhipaa.com/
HIPAA for MSPs: https://www.hipaaformsps.com/
American Institute of Healthcare Compliance (AIHC): https://aihc-assn.org/

SM Podcast Episodes with Donna Grindle:

  • HHS 405(d) Fundamentals: A Guide for Healthcare Providers and MSPs | SecurityMetrics Podcast 92
  • HIPAA Basics: Where to Start with Practices and Training | SecurityMetrics Podcast 63
  • HHS 405(d) - What You Need To Know | SecurityMetrics Podcast 45
  • Business Continuity during Healthcare Crisis | SecurityMetrics Podcast 6

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Struggling to automate security tasks? Feeling overwhelmed by the process?

This episode of the SecurityMetrics podcast dives deep into the world of automation with guest Molly Breen, founder and CEO of Perigee. Molly, a recognized cybersecurity and innovation expert, dismantles the myth of automation being a complex "one size fits all" solution.

In this episode, you'll learn:

  • How to identify the best manual processes to automate for maximum impact
  • Practical steps to overcome common automation friction points
  • How to leverage AI to enhance automation efforts and make them even more efficient
  • The exciting future of automation and AI in the security landscape
  • Real-world use cases that showcase the power of automation

Whether you're a security professional or simply looking to streamline workflows, this episode offers valuable insights and actionable tips to get you started.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

There are four key questions to ask about your data: Where is it? What data do you have? Who has access? What risks are associated with how the data is accessed? Tune in this week as Jen Stone sits down with award-winning entrepreneur, Ani Chaudhuri, to discuss data security and data risk management.

Listen to learn:

  • Why automation is essential for effective data security.
  • The importance of a "human-assisted" approach to data security.
  • How Ani's company helps organizations achieve data security goals.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Becoming a penetration tester in the world of cybersecurity can be more complex than you'd think, but don't let that spook you. Tune in this week as Jen Stone sits down with James Farnsworth (Team Lead / Senior Penetration Tester at SecurityMetrics) to discuss the various paths to becoming a penetration tester.

Listen to learn:

  • The best tools to learn penetration testing skills.
  • The numerous roles within the penetration testing umbrella.
  • Possible paths of education to start your penetration testing career.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune into the SecurityMetrics Podcast this week as host Jen Stone interviews Tillery, Director of Training and Education at Neuvik, to learn about the cybersecurity skills gap and how to bridge it.

Listen to learn:

  • How to attain an entry-level cybersecurity position.
  • Why companies should focus more on employee trainings.
  • The benefits of allowing employees time to learn during the workday.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune in this week as Jen Stone sits down with Ryan Leirvik (founder and CEO of Neuvik) to discuss how to effectively communicate cybersecurity risk to a board of directors.

Listen to learn:

  • How to frame cybersecurity risks in a way that aligns with business objectives and priorities.
  • How to break down complex security concepts for executives.
  • How to create a healthy relationship with executives.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune in this week as Jen Stone sits down with Donna Grindle (CEO of Kardon) to learn about the Health Industry Cybersecurity Practices (HICP) framework and how the 405(d) initiative and the Health Sector Coordinating Council (HSCC) are working together to provide free cybersecurity guidance to healthcare organizations.

Listen to learn:

  • How the HHS provides specific guidance for HIPAA compliance with HICUP.
  • How the 405(d) program provides resources and guidance for HIPAA compliance.
  • The upcoming HIPAA boot camp that is designed to teach healthcare professionals about HIPAA compliance and cybersecurity best practices.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune in this week as Jen Stone sits down with Candice Pressinger, an award-winning payment security leader, discussing the critical role acquirers play in the PCI ecosystem. This episode is a valuable resource for merchants seeking to understand acquirer roles in PCI compliance and gain insights into the broader payments industry.

Listen to learn:
-How acquirers aid merchants in PCI compliance.
-The importance of collaboration within the payments industry
-How PCI compliance serves as a strong foundation for overall security posture

Filmed at the 2023 PCI Community Meeting in Dublin, Ireland.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

HITRUST certification can be a significant undertaking. However, with the right guidance and support, organizations can overcome the challenges and establish a strong foundation for data security. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) sits down with Lee Pierce (Director of Enterprise Sales at SecurityMetrics) and Peter Briel (Founder of Privaxi, CISA, CISO, CISM, CCSFP) to discuss how organizations can better approach HITRUST compliance.

Listen to learn:

  • How HITRUST differs from HIPAA
  • How HITRUST can be beneficial to your organization
  • How SecurityMetrics and Privaxi ensure organizations are well-equipped to navigate the HITRUST journey.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

In this episode of the SecurityMetrics Podcast, Jen Stone chats with Keith O' Looney, an expert in multi-factor authentication (MFA) and PCI DSS compliance. They discuss the new requirements for MFA in PCI DSS 4.0, the challenges organizations face in implementing MFA, and how behavioral biometrics offer a unique solution. Learn how to navigate the changing landscape of cybersecurity and protect your data with robust authentication measures.

Listen to learn:

  • The new PCI DSS 4.0 requirements for multi-factor authentication (MFA), including:
  • How traditional MFA methods are becoming less secure and can create friction for users.
  • How behavioral biometrics offers a promising solution for frictionless and phishing-resistant MFA.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

PCIDSS #PCI #MFA #multifactorauthentication #cybersecurity #BPO #remoteaccess #behavioralbiometrics #SecurityMetrics #SecurityMetrics Podcast

View Details

In this episode of the SecurityMetrics podcast, Jen Stone chats with Heidi Babi (PCI Security Assurance & Compliance Sr. Lead at Mars Corporation) about managing PCI compliance in a massive, complex organization with hundreds of data flows.
Listen to learn:

  • How to break down overwhelming requirements into manageable steps and design flexible solutions for future growth.
  • How to utilize compensating controls and customized solutions to achieve robust security.
  • How to build rapport with internal teams to create a more functional and effective PCI program for your company.

Filmed at the 2023 PCI Community Meeting in Dublin, Ireland.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Join Jen Stone of SecurityMetrics as she sits down with two industry veterans, Gary Glover (VP of Assessments at SecurityMetrics) and Andy Barratt (VP of Assurance Business at Coalfire), for a lively discussion about their careers, the challenges of PCI compliance, and the unique collaboration they share through the PCI Security Standards Council's GEAR program.

Listen to learn:

  • How this vital program that brings together leading QSA companies to provide feedback and influence on PCI standards.
  • Get insights into where the PCI landscape is headed and how GEAR is shaping its evolution.
  • Discover how Gary and Andy, despite representing rival companies, find common ground and work together to improve the industry.

Filmed at the 2023 PCI Community Meeting in Dublin, Ireland.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

In this episode of the SecurityMetrics Podcast, Jeremy King (Regional VP for Europe, Middle East, and Africa at the PCI Security Standards Council) provides an overview of the recent community meeting in Dublin, Ireland, and why it is important for your business to attend the annual PCI Community Meeting.

Listen to learn:

  • How the community meeting provides a valuable opportunity to learn about the new requirements and get help with PCI implementation.
  • How assessors are playing a critical role in helping organizations prepare for the transition.
  • Why collaboration is a key theme of the PCI Community Meeting.

The podcast can be helpful for:

  • Merchants who are preparing for the PCI DSS version 4.0 transition.Assessors who are helping organizations with the transition.
  • -Anyone who wants to learn more about PCI security standards.

Filmed at the 2023 PCI Community Meeting in Dublin, Ireland.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

This episode of the Security Metrics Podcast discusses the transition from the Payment Application Data Security Standard (PA-DSS) to the Software Security Framework (SSF). The guest speaker, Jake Marcinko, is a Standards Manager at the PCI Security Standards Council and chairs the SSF working groups.

Listen to learn:

  • How the PCI Security Standards Council is continuously evolving the SSF to keep pace with emerging threats and technologies.
  • Why the SSF replaced the previous Payment Application Data Security Standard (PADSS).
  • The recent updates to SSF to address the increasing use of cloud-based applications.

Filmed at the 2023 PCI Community Meeting in Dublin, Ireland.

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

PCI SSC takes great care in working with other key technical bodies, such as EMVCo. Arman Aygen (Master of Science (MSc) in Communication Systems from EPFL (École Polytechnique Fédérale de Lausanne), MSc in Multimedia Communication Systems from EURECOM, and Bachelor of Science (BSc) in Micro Engineering from EPFL), Director of Technology, EMVCo, and Andrew Jamieson, VP, Solutions, PCI Security Standards Council, sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting Europe to discuss:

  • The mission of EMVCo and its key technical initiatives
  • How PCI SSC and EMVCo collaborate to ensure industry alignment
  • EMVCo’s work on mobile payment acceptance and PCI SSC’s work regarding security

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

The new PCI 4.0 requirements focused on managing payment page scripts are excellent because they can be used to address data leakage risks with other cybersecurity standards and regulations, such as HIPAA. John Elliott, GRC Consultant with a focus on PCI and GDPR, Security Advisor at Jscrambler, Pluralsight Author and Keynote Speaker, sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting Europe to discuss:

  • How malicious actors use scripts to steal information
  • Why PCI DSS requirements were added to deal with this threat
  • Jscrambler’s approach to payment page script management

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Application Programming Interfaces (APIs) are critical targets for malicious actors seeking to steal credit card data and other sensitive information. Any organization that uses APIs needs to learn how to protect them.

Dan Barahona, Founder of APIsec University, sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting North America to discuss:

  • What an API is
  • Why APIs are targets
  • How to keep APIs secure

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Payment page scripts in consumer browsers need to be secured as defined in these new PCI DSS 4.0 requirements. Organizations that are doing their research on the best way to meet these requirements will be interested in this episode.

Jeff Zitomer, Senior Director of Product Management, Human Security, sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting North America to discuss:

  • How to understand PCI DSS 4.0 requirements 6.4.3 and 11.6.1
  • What the risks are to payment page scripts in consumer browsers
  • Some of the solutions available to meet these requirements

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

With the required shift from PCI DSS 3.2.1 to 4.0 upon us, many organizations are concerned about their ability to successfully meet new requirements. Martin Kenney, Senior Systems Engineer/Admin, IT at InfoSend, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • How Infosend approached the shift to being assessed against PCI DSS 4.0
  • Why companies should make the shift to PCI DSS 4.0 now
  • Advice offered to others making the transition to PCI DSS 4.0

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Ethical hackers and cybercriminals are not the same thing, and it can be beneficial to establish a channel to communicate with hackers trying to alert you to vulnerabilities. Ilona Cohen, Chief Legal and Policy Officer at Hacker One, and Harley Geiger, Counsel at Venable LLP, sit down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at the PCI Community Meeting North America to discuss:

  • Hackers vs. cybercriminals
  • Vulnerability disclosure policies (VDPs) vs. bug bounties
  • PCI DSS post-disclosure obligations

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

Filmed at the 2023 PCI Community Meeting in Portland, Oregon.

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Cybersecurity professionals come from all walks of life, and true professionals find ways to improve their skill sets at each step of the journey. Pentester and Security Consultant Joseph Pierini (CISSP, CISA, PCIP) sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting North America to discuss:

  • His unique entry into cybersecurity
  • How he continually found non-traditional ways to forge forward in his career
  • How introspection and communication make him a better technology professional

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

The PCI SSC relies on participating organizations to support its efforts in card payment security. Simon Turner (CISSP, CISM, CISA, VCP, ISA), Senior Manager, ISSCA Consultancy Services, BT Group (British Telecom), sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting North America to discuss:

  • The role of BT as a PCI Principle Participating Organization (PPO)
  • PCI payment security groups BT is interested in collaborating on
  • BT representation on the PCI Board of Advisors

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Large organizations are often faced with complex, wide-ranging challenges related to standards and regulations they need to meet. Wes Shattler (CISSP, CISA, CRISC, CGEIT, CDPSE), Vice President, Assurance and Testing at FIS, and Chelsea Lopez (CIA, CISA, CISSP, CRISC, PCI-ISA), Enterprise Risk Director at FIS, sat down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at PCI Community Meeting North America to discuss:

  • Elements of a mature regulatory compliance program
  • Steps you can take to create a mature compliance program in your organization
  • Challenges you might face, and how to resolve them

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

We can more easily understand the impact of artificial intelligence on privacy and security if we start with an explanation of the types of AI models in use and where they exist in applications many of us already use.  Paul Starrett, CFE, EnCE of Privacy Labs and Starrett Law, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

-Different types of machine learning
-AI governance and cyber risk
-Risks and rewards of artificial intelligence

Resources:
Privacy Labs
Starrett Law

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Artificial Intelligence (AI) is a hot topic of the year. People want to understand how it will impact their lives and how they do business. Willy Fabritius, Global Head for Strategy and Business Development - Information Security Assurance at SGS, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • Issues for companies developing or using AI
  • Concerns about privacy, transparency, and accountability
  • How regulations or certifications could be applied

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

If you’re a small or medium business, chances are good that you fill out the Self Assessment Questionnaire (SAQ) for PCI compliance, and you probably have questions.  Security Analyst Marcus Call (QSA, CISSP, CISA, Security+) sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • Common questions about PCI DSS requirements
  • Understanding which requirements are applicable to you
  • Where to go for additional help filling out the SAQ

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

If you’re a small or medium business, chances are good that you fill out the Self Assessment Questionnaire (SAQ) for PCI compliance, and you probably have questions.  Security Analyst Marcus Call (QSA, CISSP, CISA, Security+) sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • Common questions about PCI DSS requirementsUnderstanding which requirements are applicable to you
  • -Where to go for additional help filling out the SAQ

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

PCI DSS Version 4.0 includes several large changes and updates to the compliance space, especially for universities. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Michael Simpson (Principal Security Analyst, CISSP, CISA, QSA) do a deep dive on what universities need to know for PCI 4.0.

Listen to learn:

  • Updates relating to universities for PCI v4.0 requirements
  • Cybersecurity best practices
  • Tips for universities to stay secure

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Many organizations struggle to translate cyber risk to business risk. When organizations understand how to identify, quantify, and communicate risk, they give senior leadership the tools they need to apply resources to mitigate that risk. Ryan Leirvik, Founder and CEO of Neuvik Solutions and author of Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • What we mean by “risk”
  • How to identify and measure risk across the organization
  • Real-world examples of how risk can inform decision making

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Risk assessments are critical to implementing good security controls, but many organizations struggle with where to begin. Josh Hyman, Chief Information Security Officer of Black Talon Security, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • The importance of risk assessments in general
  • Risk analysis in the healthcare space
  • How to successfully conduct a risk assessment

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Early detection of unauthorized access to electronic Protected Health Information (ePHI) is critical to preventing breaches and meeting HIPAA requirements. The co-founders of SPHER, Inc., Raymond Ribble, CEO, and Robert Pruter, Chief Revenue Officer, sit down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

-Why it’s critical to know who is accessing patient data?
-How to know who is accessing critical data
-Real-world stories of unauthorized access and what to do about it

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

With the rise of Software-as-a-Service (SaaS), we are hearing more about related supply chain risks. Boris Sieklik, Senior Director of Information Security at MongoDB, sits down with Host and Principal Security Analyst Jen Stone  (MCIS, CISSP, CISA, QSA) to discuss:

  • What SaaS means in the context of the cloud
  • The risks third parties may introduce in terms of SaaS
  • How leaders can prepare to handle data leakage in these environments

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Cybersecurity and risk management are often tossed to technical teams, but when these are driven by operations, the entire organization benefits.In today's episode, Jen Stone sits with Grant Elliott (CEO and co-founder of Ostendio, and Adjunct Professor at the Pratt Institute New York) to discuss:

  • Communicating with upper-level management and set expectations on security success
  • Managing security for the long term, as opposed to one-and-done compliance
  • Creating an operational approach to cybersecurity

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

It is axiomatic in our industry that you can’t protect what you don’t know about but assembling a comprehensive asset inventory can be much more difficult than it seems. Chris Kirsch, CEO of runZero, a cyber asset management company he co-founded with Metasploit creator HD Moore, sits down with Host and Principal Security Analyst Jen Stone  (MCIS, CISSP, CISA, QSA) to discuss:

  • What asset management is and why it is important
  • First steps any organization should take to implement asset management
  • A high-level overview of some standard ways to manage asset inventory, and how runZero solves common problems

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Identity management is a critical aspect of any cybersecurity program. Creating the right roles and implementing a mature identity management lifecycle requires thoughtful collaboration between information technology and business operations. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Garret Grajek (CEH, CISSP, certified security engineer, product builder and CEO of YouAttest) sit to discuss:

  • What identity management is and why it is important
  • First steps to take to implement identity management
  • Multi-factor authentication, governance, and other critical aspects of identity security

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Critical infrastructure is under threat and has historically shown to be vulnerable. Protecting critical infrastructure is a wide-ranging effort that requires careful consideration. Tune in this week as Jen Stone  (MCIS, CISSP, CISA, QSA) and Katie Arrington (Former CISO for the Department of Defense and mother of the CMMC) discuss the current critical infrastructure landscape.

Listen to learn:

  • What organizations are critical infrastructure
  • Current threats to our critical infrastructure
  • How can CMMC can help strengthen an organization's cybersecurity stance

Katie Arrington

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

HIPAA can be a daunting topic. Organizations often wonder where to start when implementing security or what kind of training is most effective. Listen this week as Jen Stone (MCIS, CISSP, CISA, QSA) sits down with Donna Grindle of Kardon and the “Help Me with HIPAA” Podcast to discuss:

  • The work of 405(d) and how it can help your organization
  • Exciting new training available through the PriSec Bootcamp
  • Why we start with risk management in the healthcare industry

Donna's "Help Me With HIPAA" Podcast

HHS Website

Hosted by Jen Stone, Principal Security Analyst (MCIS, CISSP, CISA, QSA)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"In 2021, we had tracked about 5.9M accounts were targeted through data breaches. It's expected that at the end of 2022, we will surpass that number."

Tune in this week as Jen Stone and Heff give you the TOP data breaches of 2022. This list includes breaches caused by leaks, phishing, and poor cyber hygiene.

Listen to learn:

  • Most common breach types this year
  • Tips to help your employees stay secure
  • How to respond to a data breach

Hosted by Jen Stone (MCIS, CISSP, CISA, QSA) with guest Matthew Heffelfinger (Deputy CISO, GSTRT, CyRP (Pepperdine), GRCP, SSAP, ITIL4-F, GISF, PECB).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"A lot of people think they're doing all the right things to keep their data safe. However, there are things I see constantly that people are doing wrong, or not doing at all, to properly keep their data secure."

Your personal data that exists online is vast and private. Should a hacker steal your data, you could lose emails, hard drives, bank accounts, or even your business. Tune in this week as Jen Stone and Noah Pack give you the essentials to keep your personal data safe.

Listen to learn:
-Essentials to keep data safe
-How to help employees that are easily phished
-Keeping a secure business beyond PCI compliance

Hosted by Jen Stone (MCIS, CISSP, CISA, QSA) with guest Noah Pack (Threat Hunter/SOC Analyst, Security+, ITF+, Sophos Certified Engineer).

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Most merchants just want to get back to running their business. They don't want to deal with a whole PCI program. ISOs help streamline the user experience for the merchant, making the PCI process easier."

PCI Compliance can often be a headache, and choosing an ISO is no better! Tune in this week as Jen Stone, Scott Robinson, and Robbi Watson discuss all things ISO.

Listen to Learn:

  • What is an ISO?
  • How can ISOs help their merchants?
  • Tips for an ISO / ISO Program Best Practices

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Privacy is not about things we want to hide. Hiding implies that the other side has a right to see what I'm trying to hide. Privacy means I can control what I share."

Privacy rights are often unpinned from security, but they’re critical to recapture for our personal lives. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Adrianus Warmenhoven  (Defensive Strategist and Threat Intelligence Manager at NordVPN) in a wide-ranging conversation about privacy, security, risk, and compliance.

Listen to learn:
-How privacy and security are related
-Who should make risk-based decisions
-Regaining personal privacy in our increasingly connected world

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and David Monnier (Chief Evangelist and Team Cymru Fellow at Team Cymru) discuss attack surface management.

Subscribe to the SecurityMetrics Podcast Email!

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"The PCI Security Standards Council oversees a lot more standards than just PCI DSS. The council is very much involved with the payment lifecycle. We have standards to ensure the security of card data from start to finish."

There are many standards out there to ensure the security of card data - each with a specific target to protect. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Jeremy King (Regional Head for Europe at PCI Security Standards Council) give you the entire rundown of all the PCI standards, as well as tips from the PCI council.

Listen to learn:

  • Comprehensive Review of the PCI Standards
  • Tips on Completing Compliance
  • How to Maintain Peak Card Data Security

Subscribe to the SecurityMetrics Podcast Email!

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) with guest Mike McNeil (Founder/CEO of FleetDM) and Chase Pettet (Chief Security Architect at Archer Integrated Risk Management) dive it cloud security 101.

View Details

"In order for us to meet our end objective of risk mitigation on software and applications, we have to get the developers on our side. If you do not collaborate with the developers, you're not going to be able to manage that risk"

Tune in this week as Jen Stone and Harshil Parikh discuss how to eliminate friction between development and security.

Listen to learn:

  • How to collaborate with developers
  • How collaboration can aid in cybersecurity efforts
  • How setting clear expectations can improve teamwork

Hosted by Jen Stone (MCIS, CISSP, CISA, QSA) with guest Mike McNeil (Founder/CEO of FleetDM)

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Not long ago, companies didn't allow employees to take their work devices home, or even out of the network. Companies relied on the network security for these devices. In the past few years, we have all been forced to shift and figure out - how do we still keep work secure?"

Mobile device management is a heavy lift. Security teams recognize the risks posed by laptops, tablets, smartphones, and other mobile devices. Because of our increasingly remote working environment and the ongoing challenges posed by the use of personal devices for work, many companies have needed to find other solutions to help them in their security effort.

Listen to learn:
-How to work from home securely
-Tools and software to manage remote devices
-Security solutions for your company

Hosted by Jen Stone (MCIS, CISSP, CISA, QSA) with guest Mike McNeil (Founder/CEO of FleetDM)

Notes -
-https://www.youtube.com/watch?v=UIDb6VBO9os
-https://www.loom.com/share/ecb223c0f2ff497195961a7ba5e77b2b

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"I feel like many data security professionals feel like they're doing the right thing and making a difference, but there was a huge amount that said they were burning out. 65% of cybersecurity workers said they plan on leaving their jobs in the next 12 months."

Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Thomas Kinsella (COO and Co-Founder - Tines) about the recent SOC analyst survey findings conducted by Tines.

Listen to "The Future of Security Operations" Podcast by Thomas Kinsella

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"The PCI Data Security Standard is a set of about 330 security controls that are designed to protect credit card information. For most small businesses, many of the requirements don't apply in their environment. The Self Assessment Questionnaire is a subset of the full PCI DSS standard designed to help small businesses validate their PCI compliance."

PCI 4.0 is here, and many things have changed - including the self assessment questionnaire. If you have questions about this update, you aren't alone! Tune in this week as Jen Stone and Michael Simpson break down all the pieces with the PCI 4.0 SAQ.

Listen to learn:

  • What's new in the PCI 4.0 SAQ?
  • When should I switch to the PCI 4.0 standard?
  • Will PCI 4.0 increase my security?

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Don't jump into becoming a QSA for a year and think 'I'm now going to go somewhere else and make a ton of money.' Spend some time really learning. That's the advantage to this job you can get so much experience so quickly and get exposure to so many aspects of cybersecurity."

Breaking the barrier to the cybersecurity workforce can be difficult, especially if you don't know where to start. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Gary Glover (CISSP, CISA, QSA, PA-QSA) explain the steps one should take when wanting to become a QSA (Qualified Security Assessor).

Listen to learn:
-What to learn when becoming a QSA
-Day in the life of a QSA
-Is becoming a QSA right for you?

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"The threat environment is becoming more aggressive, and the footprint that businesses need to protect is huge. Businesses need to reframe their expectations and reframe their focus."

Reading the future is hard, especially in relation to cybersecurity. However, looking at current cyber trends helps us have a better idea of what is around the corner. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Matthew Heffelfinger (Deputy CISO, GSTRT, CyRP (Pepperdine), GRCP, SSAP, ITIL4-F, GISF, PECB) dive into the TOP 10 cybersecurity trends, and predict the FUTURE.

Listen to learn:

  • How current trends tell the future of cyber
  • Cybersecurity best practices
  • Cybersecurity for small businesses.

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"If we think back to 9 years ago when the previous version came out, the world was really different then. We now have loads of new criminals who have found new ways to steal card holder data. The way we do InfoSec has changed massively in 9 years, so we definitely needed a new standard."

With PCI 4.0 just recently released, many are left with questions about the many changes in the standard. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and John Elliott (Pluralsight Author, PCI and GDPR Specialist) give you everything you need to know on PCI 4.0.

In this podcast:

  • Biggest additions and changes in PCI 4.0
  • Why was PCI 4.0 delayed?
  • Things YOU need to do to prepare for PCI 4.0

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Simply, point to point encryption is encrypting your data at the beginning, and not decrypting it until it reaches its endpoint. This protects your data while it is being transferred."

P2PE or “point-to-point encryption” can be the best way for merchants to take card present payments. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Mark Miner (Director of P2PE/PIN Assessments at SecurityMetrics) about the basics of P2PE.

Listen to learn:

  • P2PE encryption differs from other payment transaction options
  • Where to go to see listed P2PE solutions
  • What P2PE can do to protect card data and your business

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Subscribe to the SecurityMetrics Podcast!

"Hackers don't solely go after Fortune 500 companies. Almost everyone I know has some story with their Facebook getting hacked, or their bank information getting stolen. The way to tackle that is cybersecurity for yourself."

It's a common misconception that hackers only go after large companies or entities, when in reality they target normal people every day. Building your cybersecurity at home is essential to maintain a safe network from these threats. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) talks with Noah Pack (Threat Hunter/Security Operations Center Analyst, Security+, ITF+, Sophos Certified Engineer) about the best things you can do to build your home cybersecurity.

Listen to learn:
- How to set up a firewall at home
- Tips on securing your home router
- Internet safety best practices

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"How do I navigate this market, serve customers, and protect my brand reputation? At the executive level, that's the stuff they're thinking about. That trickles down to security objectives and initiatives. As a security leader, if you're in the head of your executive - what they want to do and why - then you can speak that language and drive better security."

Maintaining strong leadership is essential in cybersecurity. A good leader needs to know how to navigate their company's security needs, as well as communicate those needs to their executive level. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Christian Hyatt (CEO & Co-founder risk3sixty) discuss the in's and out's to being a successful leader in cybersecurity.

Listen to learn:

  • How to assess your company's security needs
  • Communicating cybersecurity to executives
  • 5 CISO Architypes book

Subscribe to the Podcast!

The 5 CISO Archetypes Book
Connect with Christian

View Details

HHS recently launched its new 405(d) website  to raise awareness, provide vetted cybersecurity practices, and move organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the healthcare sector.  Donna Grindle of the “Help Me with HIPAA” Podcast, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • The work of 405(d) and how it can help your organization
  • Top 5 cybersecurity threats to the healthcare industry
  • Resources available to educate yourself and your organization about privacy and security under HIPAA

SecurityMetrics Guide to HIPAA

Donna's "Help Me With HIPAA" Podcast

HHS Website

View Details

"In security, there is no 'that's not my job.' When it comes to defending the organization, security practitioners need to be able to put their egos aside, roll up their sleeves, and do what the team needs them to do to make sure the security posture of the organization continues to improve."

Whether you're looking to hire a good security practitioner, or trying to become one, there are certain attitudes and mindsets to look out for. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) and Joshua Goldfarb (Director of Product Management at F5) dive into his recent article - How to Spot an Effective Security Practitioner.

Listen to learn:
- How to communicate data security to executives
- Maintaining good relations with your security team
- Attitudes of an effective security practitioner

View Details

"If you want to engage your audience and get them involved in security rather than having to force them to do it, you need to give them something worth their time and attention."

Making trainings for any audience can be hard, especially when it's mandatory. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) chats with Ian Murphy (Founder of Cyber Off, CISSP, FBCS, CITP) about his approach to making trainings more enjoyable.

Listen to learn

  • Tips to make your trainings more enjoyable
  • How to have fun with boring topics
  • How to respond to negative feedback

Connect with Ian on LinkedIn

View Details

Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA), Matthew Heffelfinger (Director of SIEM Operations, GSTRT, CyRP (Pepperdine), GRCP, SSAP, ITIL4-F, GISF, PECB), and Forrest Barth (SOC Analyst, CISSP, CMNO, Security+) wrap up this season with the TOP 10 breaches of 2021!

Join us for SEASON 3 of SecurityMetrics Podcast this January!

View Details

Learn more at SecurityMetrics.com

"That's one of the reasons why our audit team is so good, because we share the wing with forensics, and we're talking about what's happening out there. Our forensics consulting isn't theoretical. It isn't some monthly magazine saying 'look out for this... this might be happening,' this IS what's happening. This is the analysis of the very data we're collecting."

It can be difficult to build cybersecurity into your budget and receive approval from senior decision makers. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Lee Pierce (Director of Sales Operations for Security Metrics) about the factors that affect costs of various cybersecurity services.

Listen to learn:
-How much cybersecurity services generally cost
-What factors can affect pricing
-How to reduce compliance assessment costs

View Details

"One thing that I learned from the circle was how to come out of my comfort zone and tell my story to other people. When it comes to something technical, I can talk for hours, but apart from that it's very hard for me. So this was one take away for me, apart from all the learnings - both technical and non-technical - that really helped me a lot."

Making your way in cybersecurity is easier if you have a team supporting you. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Aastha Sahni (Lead CyberSecurity Instructor at Flatiron School | Founder & Global Lead - Breaking Barriers Lean in Circle), Shrutirupa Banerjiee (Web Application Security Analyst| Tech Lead at Breaking Barriers Lean in Circle), and Saman Fatima (Data Engineer at Macquarie Group | Management Lead at Breaking Barriers Lean in Circle) about the work they do to invite and support others on a cybersecurity career path.

Listen to learn:
-How a team can help support your cybersecurity journey
-Strides being made at Breaking Barriers
-What the future looks like for this supportive group

Connect with our guests:
https://cyberpreserve.com/community/
https://www.linkedin.com/company/breaking-barriers-women-in-cybersecurity-lean-in-circle/

View Details

Everybody has their own path to finding the job that's right for them. It's often easy to get discouraged when you're in the middle of the path to reach your desired goal. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Luana Pascu (Cybersecurity Researcher, GSEC) about her personal journey, and how you can find the path in data security that's right for you.

Listen to learn:
- How to find your passion within cybersecurity
- Education steps to reach your desired role
- How to track your journey into the workforce

Connect with our guest: https://www.linkedin.com/in/luanapascu/

View Details

"With network segmentation, we really are looking for isolation. We want to get that 'thing' and put it into a safety deposit box where you have secure access to it. Nobody else has physical or logical access to it. That's really what we are trying to do with segmentation."

Network segmentation is often used to reduce the scope of a PCI DSS compliance assessment, but it is even more important as a security strategy for your environment.  Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Chris Skarda (PCI DSS QSA, CISSP, CISA, CCNA) about how network segmentation can support your compliance and security efforts.

Listen to learn:
-What “network segmentation” means
-How network segmentation can reduce the scope of your compliance assessment
-Why network segmentation can improve your security stance

SHOW LESS

View Details

"Zero Trust is essentially a security initiative saying that you are going to assume that attackers are present in any environment you're working in. The main goal of that is to remove implicit trust in the design and implementation of whatever you're doing."

“Zero trust” is something we hear a lot about but in many cases it seems to be a buzzword used to sell us something. However, it can be an excellent approach to security when done well. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Geoffrey Sanders (Senior Member of the Technical Staff/Situational Awareness Team, Software Engineering Institute/CERT Division, Carnegie Mellon University) about the tenets of zero trust and where to get started in implementing zero trust in your environment.

Listen to learn:

  • How privacy and security are related
  • Where to start when you need to understand how laws and regulations apply to you
  • What direction policy and legislation are taking to address cybercrime

Connect with our guest:

  • https://www.linkedin.com/in/sandersgeoffrey

Learn more:

  • SEI Website: https://www.sei.cmu.edu/
  • Zero Trust Adoption: Managing Risk with Cybersecurity Engineering and Adaptive Risk Assessment (Blog): https://insights.sei.cmu.edu/blog/zero-trust-adoption-managing-risk-with-cybersecurity-engineering-and-adaptive-risk-assessment

Zero Trust Adoption: Benefits, Applications, and Resources (Podcast): https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=737526

View Details

Preparing for a third-party security assessment or compliance audit can be a daunting experience -- especially if it’s your first time.  Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Brian Gross (VP, Product & Technology, FISERV) about how he prepared his organization to respond successfully to a PCI DSS assessment, followed by a HIPAA audit.

Listen to learn:

  • How a third-party assessment can benefit your business
  • Where to start to build your security program
  • What elements support successful completion of an audit

Learn more at SecurityMetrics.com

View Details

"Some security is better than no security. If you are a small business, and you don't have all the resources to invest in a huge cybersecurity program, that's ok! Start with the basics, such as strong passwords, the use of VPNs, and trainings on cyber threats like phishing and malware."

Privacy and security considerations can be difficult to get your arms around; when laws and regulations come into play they add another layer of complexity. Tune in this week as Jen Stone (MCIS, CISSP, CISA, QSA) speaks with Victoria E. Beckman (Lead Digital Crimes Unit Americas - Corporate, External, and Legal Affairs for Microsoft) about the relationship between privacy, security, and legal matters in our digital world.

Listen to learn:

  • How privacy and security are related
  • Where to start when you need to understand how laws and regulations apply to you
  • What direction policy and legislation are taking to address cybercrime

Connect with our guest: 
https://www.linkedin.com/in/victoriabeckman

View Details

"We all rely on service providers to keep our businesses afloat. I get asked all the time,  'How do I know that this service provider is going to be careful with my data?' Service providers can elevate our risk, while at the same time giving us really important services that we need. "

When using service providers, managing your 3rd party risk can be a challenge. Tune in this week as Jen Stone (MCIS | CISSP | CISA | QSA) talks with Paul Poh (CISSP, CISM, CRISC, CIPP/US) about how we can best manage and minimize that 3rd party risk that often comes with using these service providers.

Listen to learn:
-Things to look for when choosing a service provider.
-Keeping your data secure with your service provider.
-Things you need to know about your own security.

Paul Poh on LinkedIn - https://www.linkedin.com/in/paulpoh/

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"A lot of people don't realize, kids are smart! They know how to get around these controls that are in place. So the more informed you are as a caregiver, the more you can keep an eye on things that are going on with your kids and that they are getting the right information and aren't going to negative places."

The internet is a vast and often dangerous place. With increasing threat actors prying to target these vulnerable young ones, protecting our kid's from harmful places online is crucial to keep them safe and secure. Tune in this week as Jen Stone (MCIS | CISSP | CISA | QSA) speaks with Teressa Gehrke (Founder and CEO of PopCykol) about how we can prevent our kids from finding out the hard way the dangers of the internet.

Listen to learn:

  • How to best communicate to kids about internet safety.
  • How we can approach kids after an incident has occurred.
  • Tools and resources for every age to learn about internet security.

Visit https://www.popcykol.com/ to learn more.

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"Security is hard, even for professionals. There are a ton of things to know. As a defender, you have to be right 100% of the time. As an attacker, you kinda just have to get lucky once. If you go out there and educate people (in your company) about security, then they can become an ally for you."

Join us this week as Jen Stone(MCIS | CISSP | CISA | QSA) and Matt Halbleib (CISSP | CISA | QSA (P2PE) | PA-QSA (P2PE)) discuss all the things you can do to better prepare you and your company for a risk assessment.

Listen to learn:

  • How to better know your scope to be ready for your assessment
  • How to teach security between departments
  • How to make PCI work for you

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Subscribe to the Podcast!

With so much ransomware stories in the news this year, one would think that ransomware is a new technique used by threat actors. In reality, ransomware has been around for almost a decade, and so have the basic principles on how to protect yourself from getting hit with it.

Join Gary Glover (CISSP, CISA, QSA, PA-QSA) and Jen Stone (MCIS, CISSP, CISA, QSA) as they teach all you need to know about what ransomware is, and how to stay safe from it.

Listen to learn:

  • What is ransomware?
  • Why does ransomware seem to be so effective?
  • How can I protect my business from being vulnerable to ransomware?

Resources:
-https://www.cisa.gov/

View Details

"It's the nature of our team's roles that there's always going to be trade-offs. It's hardly ever a simple decision between A and B. So you need to lean into that and get more comfortable with ambiguity."

Having clear and open communication with your IT or security team is essential to maintaining a secure business. Although, if the correct steps are not taken, working alongside these teams can be challenging.

Tune in this week as Jen Stone (Principal Security Analyst MCIS, CISSP, CISA, QSA) and Dutch Schwartz (Strategic Lead of Amazon Web Service’ Global Security Services) talk about how to build a straight-forward, strong relationship with your IT and security teams.

Listen to learn:

  • Steps to improve interpersonal relationships within your IT department
  • How to maintain good communication between departments
  • How to approach problem solving tasks with multiple teams

Resources:

Dutch's LinkedIn: https://www.linkedin.com/in/dutchschwartz/

Dutch's Twitter: https://twitter.com/dutch_26

Download our Guide to PCI Compliance! - https://info.securitymetrics.com/pci-guide

Download our Guide to HIPAA Compliance! - https://info.securitymetrics.com/hipaa-guide

Access our free cybersecurity and compliance conference - www.securitymetrics.com/summit

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

"I have a passion to keep people safe online, especially young ones. I don't expect kids to pick up this book and understand the concepts right away, but I want to empower the adults to teach. " 

Teaching data security and internet safety to the next generation can prove to be challenging. From the complex tools to the vast vocabulary, it's no simple thing to learn. Today, Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) sits down with Curtis Brazzell as they discuss his recent endeavor to better help children learn, and parents teach about data security.

Listen to learn: 

  • Curtis's cybersecurity ABC book, "M is for Malware"
  • How to better teach our young ones how to be safe online
  • Helping to teach those just entering the data security field

Get your copy of "M is for Malware" at https://misformalware.com/

View Details

“What is managed security? It’s about trusting your business to someone else.”

Whether you call it outsourcing, partnering, or hiring, choosing an MSSP is a decision that can seriously affect a business. SecurityMetrics Director of SIEM Operations and SecurityMetrics News Host, Matt “Heff” Heffelfinger, talked with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about the many factors that go into choosing the right security firm for your business. With experience at General Electric, NBC, and TJ Maxx, Heff’s breadth of knowledge and experience allow him to see threats in the long term and help you avoid problems down the road.

Listen to learn:

  • Types of managed security (MDR versus MSSP) and what they do
  • How to determine the security services your business needs
  • Resources to help you ask the right questions, create better contracts, maintain or end relationships, and get the most from your MSSP

How to Choose the Right MSSP for Your Small to Medium Business

SecurityMetrics Threat Intelligence Center

View Details

Subscribe to the SecurityMetrics Podcast

“Is there really a shortage of skills in cybersecurity? Or are we just looking at it the wrong way?”

Director of Information Security and IT at BEEM Technologies, Naomi Buckwalter (CISSP, CISM) discovered hacking at Vanguard, where she joined a class and learned to hack from scratch. Her experiences as a software security architecture, security engineer, career advisor, mentor, and speaker have given her a broad spectrum of insight about the so-called cybersecurity “skills shortage.” In this episode, Naomi talks with Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about why mythology and gatekeeping in cybersecurity are holding the industry back and creating an uncertain future.

Listen to learn:

  • Why new professionals see barriers in cybersecurity and what industry veterans need to do to paint a better picture
  • How improving emotional intelligence and culture in the cybersecurity community can help us better fight cybercrime
  • Tips for people who want to get started in cybersecurity

View Details

“What is our responsibility as leaders of security teams? It’s doing security right from the beginning; from the design. It has to be there.” 

Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) welcomes Vandana Verma: Security Architect IBM, Vice Chair of the Global Board of Directors at OWASP, leader at InfosecGirls, and founder of Infosec Kids. As a prolific speaker and thought leader in the cybersecurity space, Vandana is vocal in the efforts to help women and youth build their communities in cybersecurity. She has trained over 10,000 diverse candidates and brings an undeniable enthusiasm and passion to security research. 

Listen to learn more about:

  • The role of cyber threat intelligence in application development.
  • Ways to gamify security to avoid a checkbox mentality and prevent costly security issues.
  • How machine learning, AI, and adaptive access are rapidly changing access security.

Vandana on Linkedin

Infosec Girls

OWASP

View Details

Dr. Oren Eytan joins Jen Stone (Principal Security Analyst, MCIS, CISSP, CISA, QSA) to discuss his experiences as a cybersecurity leader in both the military and civilian realms. After serving in the Israeli defense forces, two degrees in Electrical Engineering, and time at Motorola, Dr. Oren Eytan continues the fight against malware as the CEO of Odix. Today he helps protect businesses in all sectors, including utilities and technology.

Listen to Learn:

  • Why creative thinking is crucial to cyber security
  • Lessons learned from protecting critical infrastructure
  • The relationship between connectivity and vulnerability

Connect with Dr. Eytan on LinkedIn

Odix

View Details

Subscribe to the SecurityMetrics Podcast
There’s been a lot of chatter and anticipation about the release of PCI DSS v4.0. In this episode, SecurityMetrics VP of Assessments, Gary Glover (CISSP, CISA, QSA, PA-QSA), talks with Host Jen Stone (MCIS, CISSP, CISA, QSA) about what merchants can expect and how they should prepare right now. As part of the PCI DSS assessor community, Gary has worked with the council in special groups and on committees to develop the new PCI Data Security Standard. He has been in payment security for over 16 years and has a background in both rocket science and software development.

Listen to learn:

  • How the PCI Data Security Standard started and where it’s going
  • What the Customized Approach is and how it differs from the current approach
  • What role you and your security assessor will play as PCI DSS 4.0 is rolling out

Connect with Gary on LinkedIn

Download our Guide to PCI Compliance!

Download our Guide to HIPAA Compliance!

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

People are naturally kind and helpful. Attackers know that, and in the case of social engineering–they rely on it. This week, Senior Information Security Architect at Lucid, Nathan Cooper (CISSP, Security+) talks with Host Jen Stone (MCIS, CISSP, CISA, QSA) about the tactics hackers use to attack businesses and how you can protect your company.

Listen to learn:

  • The psychological reasons social engineering works so well and how to address them
  • Examples from the field–man traps, watering hole attacks, and tailgating
  • Tips to make security training effective while maintaining a positive and respectful environment

Learn more at https://www.securitymetrics.com/

View Details

“How do you speak to executives about cybersecurity in a way that matters to them? It comes down to the company’s mission.”

Ross Young, CISO of Caterpillar Financial Services Corporation, stops by SecurityMetrics Podcast to talk with Host and Principal Security Analyst, Jen Stone (MCIS, CISSP, CISA, QSA) about his mission to mentor the next generation of CISOs and create more understanding and harmony within the corporate security community.

Listen to learn:

  • How a company’s mission and values affect its approach to cybersecurity
  • The three things that executives care about when making decisions
  • Tips on how people can understand others in different roles in the security world

Ross Young is CISO of Caterpillar Financial Services Corporation, a SANS Instructor, Johns Hopkins University Instructor, CISO Tradecraft Podcast Co-Host, and Creator of the OWASP Threat and Safeguard Matrix (TaSM).

Connect with Ross on LinkedIn.

Additional Resources:

Download our Guide to PCI Compliance!

Download our Guide to HIPAA Compliance!

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

“The single biggest contributor to data breaches is a lack of testing. You have to be testing, you have to be reviewing, you have to have pentests.”

After experiencing a data breach as a small business owner 20 years ago, SecurityMetrics CEO Brad Caldwell (CISSP, CISA, QSA, PFI) set out to provide affordable data breach prevention and remediation to businesses of all sizes. Since then, SecurityMetrics has tested over a million systems and provided cybersecurity services and audits for tens of thousands of businesses.   

In a special episode of the podcast, Brad sits down with Host and Principal Security Analyst Jen Stone (MCIS, CCSFP, CISSP, CISA, QSA) to discuss how security complexity has evolved and what he’s learned from over 20 years in the cybersecurity and PCI compliance industry data breach investigations, and tips to keep a cool head in the wake of a data breach

Listen in to learn:

  • Common mental roadblocks people face in making security a priority
  • The number one problem with incident response plans
  • Tips to keep a cool head when experiencing a data breach

View Details

John Elliot has a knack for illuminating the relationship between security and compliance. With over ten years in information protection and compliance consulting, and as Director of Industry Standards at Mastercard, John helps explain the relevance of security and industry standards to customers and those in the wider payment ecosystem. Today he sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to reveal the three biggest myths about PCI DSS compliance and how they hinder security. 

Listen in to learn:

  • How the PCI Security Standards Council and the major card brands work together.
  • The areas of compliance that are most critical and timely to preventing data breaches.
  • Tips for organizations to make PCI “business as usual,” maintain compliance controls, and stay compliant through major changes.

Download our Guide to PCI Compliance!

Download our Guide to HIPAA Compliance!

View Details

“If we think we’re fluent in security because we’re using the same words we’ve always used, we’re in danger.”

With over 30 years in the FinTech industry, Dale Laszig has a long-range view of trends and technology that she has turned into a busy tech journalism career. Dale spoke with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) about the language of security: how the way we talk about it affects the way we approach it. Dale and Jen wax poetic to uncover the meta “matrix” that supports commerce and makes the world go ‘round. 

Listen in to learn: 

  • How payments security attitudes have changed and why it matters today
  • The concept of “zero trust,” and the practical application of a security perimeter
  • Jen’s quick take as a Security Analyst on industry trends and myths

Connect with Dale:

LinkedIn

DSL Direct

dale@dsldirectllc.com

Northrop Grumman Fan

View Details

“Gaps in security are behavioral . . . find out what drives behavior at your company, and you will find your vulnerabilities.” As the Strategic Lead of Amazon Web Service’ Global Security Services Team, Dutch Schwartz talks with SecurityMetrics Podcast Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to define what CISOs need to understand about human motivation in order to strategize security programs, utilize company culture, and protect critical data.

Listen in to learn:

  • How the CISO position has changed in the last decade and how it’s currently defined.
  • The surprising differences in intellectual property between companies and the role those differences play in security.
  • Why culture and social strategy should be more important to a CISO than technology, and tips for facing company culture challenges.

Resources:

https://www.linkedin.com/in/dutchschwartz/

https://twitter.com/dutch_26

Download our Guide to PCI Compliance! - https://info.securitymetrics.com/pci-guide

Download our Guide to HIPAA Compliance! - https://info.securitymetrics.com/hipaa-guide

Access our free cybersecurity and compliance conference - www.securitymetrics.com/summit

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

When your organization has 300 Merchant IDs (MIDs) in a multi-modality environment, leading a PCI DSS compliance program is no easy task. This week, Host and Principal Security Analyst Jen Stone welcomes guest Robbyn Lennon, Senior Merchant Services Program Coordinator at the University of Arizona, along with SecurityMetrics Principal Analyst Michael Simpson to talk about large-scale PCI DSS compliance from both a QSA and a client perspective.

Robbyn explains in detail how she established a PCI DSS compliance program at the University of Arizona. With over 10 years of experience, she shares her three-part strategy: “Engagement, leadership, and encouragement.” 

  • How to reduce scope in a large PCI DSS compliance program by organizing merchants into “pods.”
  • Why a focus on leadership as opposed to management helps employees take accountability for their job processes.
  • The tools, training, and documentation you need to empower merchants and improve your PCI program.

Robbyn on LinkedIn

Learn more at SecurityMetrics.com

View Details

“It’s our friends and family–our moms and dads–who shop online and are affected when a bad guy gains access. So we take it personally,” said SecurityMetrics SOC/SIEM Director, Heff. 

Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) continues this sentiment by saying “When businesses go down, people suffer. Every business we can protect helps elevate the quality of life for the people who are associated.”

At SecurityMetrics, we monitor the threat landscape around the clock. And currently, that landscape is not only vast, it’s complex. Never have companies faced so many challenges, and hackers know it. Data protection measures need to be based on our new global landscape and the latest threats. Today, Heff, Jen, and SOC Analyst Forrest Barth discuss the threat landscape in depth and cover the five most important things you can do now to prevent an attack. Listen to this episode to learn:

  • What the “Fujiwhara Effect” is and why it can make cybersecurity feel overwhelming.
  • New terms and trends demystified: cyber empathy, vishing, endpoint definition, and Zero Trust architecture.
  • Why bringing work computers home and social engineering make for a disastrous combination.

Heff, SIEM Operations Director
Forrest Barth, Analyst

Learn more at https://www.securitymetrics.com/

View Details

“A lot of people in the security world want to talk about security, not compliance. But you can’t help secure things if you don’t know what you’re supposed to be securing,” says host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA). 

In this episode, NuSkin Data Governance Analyst, Gabrielle Harris (CIPP/E, CIPM, MSML) explains how security and compliance are permanently entwined, “Even though ‘compliance’ has a negative connotation and ‘security’ has a positive one, the truth is that compliance builds brand reputation and trust with customers. Protecting data is an ethical thing, and we would all hope that whoever is protecting ours is taking it seriously.

With experience in over 50 markets, Harris brings a big-picture understanding, a positive attitude, and a tireless work ethic to privacy programs. Listen to this episode to learn:

  • Pervasive attitudes and pitfalls that can hinder GDPR, HIPAA, and CCPA compliance
  • Critical points in your step-by-step compliance process that build rapport and respect, including whom to involve and when
  • What you need to understand about the differences between security standards and privacy law

Gabrielle Harris LinkedIn

CIPP Certification

View Details

Subscribe to the SecurityMetrics Podcast

“Something has happened.” Your company has experienced the worst: a data breach. You’ll need to answer questions. You’ll need to implement emergency operations and plans, run backup and talk to investigators. Not a convenient time to start your Incident Response Plan.

According to Dave Ellis, SecurityMetrics VP of Investigations (GCIH, PFI, QSA, CISSP), an Incident Response Plan is, in short, “What you do ahead of time, in preparation for an event that you hope never happens.” Ellis sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss in detail the phases of an IRP, along with the circumstances, variables, and options surrounding this “worst case scenario.”

Listen to learn:

  • Emergency-Mode Operations, contingency planning, and the recovery phase
  • How to get initial buy-in from your executives, C-suites, and decision makers
  • Case studies and examples from the field: the practical realities involved in maintaining a current Incident Response Plan
  • Tips to avoid, handle, and learn from data breaches, ransomware, and other types of malware

Learn more

2020 SecurityMetrics HIPAA Guide

2020 SecurityMetrics PCI Guide

View Details

When Liberty Mutual offered Craig Olsen a lateral leap from Developer to Security Analyst, he took it–and hasn’t looked back since. Now a Cybersecurity Architect, Olsen reflects on the last fifteen years and his role in the transition from one-person internal security departments, to a full-blown industry with unique technologies, solutions, and issues.

When it comes to the cloud, many companies are unsure or hesitant. Some may not even know for sure if they’re using it. Often, this is based on a lack of understanding or familiarity with cloud security.

Olsen and Host Jen Stone sit down for an in-depth discussion about cloud solutions, including:

  • What we can learn from companies who’ve experienced data breaches in the cloud
  • How to leverage the unique qualities of the cloud to improve security and support growth
  • Simple steps anyone can take to build foundational layers of security–areas like passwords, policies, encryption, and compliance

Craig Olsen on LinkedIn
Learn more

View Details

In today’s podcast, Dr. Eman El-Sheikh (Director of the Center for Cybersecurity at the University of West Florida) sits with Host and Principal Security Analyst Jen Stone to discuss how we can creatively approach cybersecurity careers from all perspectives.

“We have over half a million open cybersecurity jobs as we speak. And, unfortunately that number is trending up.”

Dr. Eman El-Sheikh is the Director of the Center for Cybersecurity at Western Florida and plays a vital role in recruiting future cybersecurity leaders. Today, she sits with Host and Principal Security Analyst Jen Stone to discuss how we can creatively approach cybersecurity careers from all perspectives.

Listen in to learn:

  • What is required for a career in cybersecurity. Do you need a degree? Certifications? Or neither?
  • How a skills-based approach can compliment–not contradict–an educational approach
  • How we as a cybersecurity industry can foster innovation and diversity while continuing education and training

“We take a multi-disciplinary approach, and our message is that regardless of what you’re interested in: programming, IT, engineering, policy, law, management, psychology, or criminal justice, there are pathways to gain cybersecurity knowledge and skills, and there are great jobs waiting for you on the other side.”

You can learn more about Eman’s work at:

Center for Cybersecurity at University at Western Florida

NIST National Initiative for Cybersecurity Education (NICE)

Learn more at Securitymetrics.com

View Details

A successful PCI DSS assessment requires a fair amount of preparation and scheduling far in advance. These activities may seem like a lot of work, but they are actually the best way to make your assessment less overwhelming, help you control time and cost, and avoid worst-case scenarios. 

With thousands of PCI DSS assessment hours between them, SecurityMetrics Principal Analysts George Mateaki (CISSP, CISA, CISM, QSA, PA-QSA) and Jen Stone (MCIS, CISSP, CISA, QSA) sit down to “talk shop” and share stories from the field. 

Listen in to learn:

  • How remote assessments work and tips to make them go more smoothly.
  • What you should do a year, 9 months, 6 months, and 3 months before your first assessment. Plus, what to do in between assessments to save time and resources.
  • An overview of the PCI audit timeline–from initial contact to signing of the report on compliance (ROC).
  • How to balance the need for functionality and access at organizations with the goal to protect data.

Learn more

*Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Paul Poh (CISSP, CISM, CRISC, CIPP/US) has had an interest in cybersecurity since before the internet as we know it existed. From his first exposure to the “Morris Worm” in the early ‘90s as a software engineer at Tufts University, to his current role as Partner at Radical Security, Paul’s mixture of curiosity and wisdom have helped him maintain the perspective needed to be a successful penetration tester. He shares his insights with our Host Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) on why it’s the small things that can take down an organization’s security. 

“Your Software Development, Engineering, and DevOps can all be great. But a malicious actor can still break a password, attack your source code, and insert a backdoor that would then be pushed into production. You can do a great job protecting production, but if a hacker can find something small, they will.”

Listen in to learn

  • Case studies that compare typical security measures to actual threats and vulnerabilities
  • Penetration testing requirements, preparation, tips, timing, timeline, and best practices
  • Tips for choosing a penetration testing firm and the surprising qualities that make for a good penetration tester

Paul Poh on LinkedIn

2020 SecurityMetrics PCI Guide

View Details

As a former US Air Force Cyber-Warfare Technician, Vince Romney (CISSP) has been able to leverage his unique military experience in the private sector–most recently as CTO of SK2 Technology, developing high-security encryption applications. In this episode, he joins Host Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) to explore cloud security challenges in the corporate world, but also to share the valuable insights about risk analysis and mitigation which he gained during his military service. Listen in to learn: * Common misconceptions about the security, implementation, and risk management required for cloud solutions. * How decision makers in the corporate world can apply specific risk assessment principles and methods used in the military. * Lessons learned in military operations that will help you increase the discipline, honesty, and problem-solving ability within your organization’s security program.

“You can live a much calmer life if you accept that your work is never done. Readjust your mindset to see that if you want to succeed in cybersecurity, you should be constantly engaged in learning new concepts and trying new tactics.” –Vince RomneyVince Romney on LinkedInSecurityMetrics Guide to PCI DSS Compliance

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

“We need each other. Cybersecurity is a global event and we need all the brains,” says Noreen Njoroge. “Threat actors don’t care where you are from or what your social status is. They are there to attack everybody. As cybersecurity specialists, we should also have that mindset. It’s a community effort. I have to help my brother, my sister, my coworker, my friend, know how to better defend themselves against attacks.”

Njoroge imbues that same philosophy into her cybersecurity mentoring projects. As a Security Threat Engineer at Cisco, President of North Carolina Women in Cybersecurity, and leader of the Mentors and Mentees Group for Women in Cybersecurity, she has a unique perspective on the humans who make up the cybersecurity industry. Today, she sits down with our Host and Principal Security Analyst, Jen Stone, to discuss:

  • How making more “room at the table” for diverse thinking strengthens our defensive stance and improves cybersecurity around the globe.
  • The qualities that make for a good cybersecurity analyst and how to get the most out of a mentor/mentee relationship.
  • How the industry can recruit more security analysts with diverse skills, strengths, and backgrounds.

Women in Cybersecurity (WiCyS)
2020 SecurityMetrics HIPAA Guide2020 SecurityMetrics PCI Guide

View Details

Tom Hatch, Co-founder and CTO of Salt Stack, Inc and host of "The Hacks" sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • How cybercriminal activity has become automated and widespread
  • How to use automation to help close your security gaps and reduce infrastructure management challenges
  • The need for maintaining your applications and having different types of IT individuals address security issues

"We live in the era of continual cyber warfare, and that warfare isn't just between nation states. It's between crime syndicates, crime groups, and hacker groups that seemingly spawn from nowhere. Even a handful of folks–or even a single person–can have a very big impact when they perform these attacks." Thomas Hatch

"As an assessor, I'm seeing a gap between the people that knows there's a problem, the people who have to fix the problem, and then the people who have to approve that there was a problem and that the problem has been fixed." Jen Stone

Resources:
Download our 2020 Guide to HIPAA Compliance! - https://info.securitymetrics.com/hipaa-guide-2020
Download our 2020 Guide to PCI Compliance! - https://info.securitymetrics.com/pci-guide-2020
Check out Tom's "The Hacks" podcast! - https://www.saltstack.com/the-hacks/

View Details

In healthcare, it’s common to encounter the attitude that “HIPAA is complicated.” Naturally, this leads to people finding ways to make HIPAA seem irrelevant or useless. However, this belief couldn’t be further from the truth and leads to increased risk for patients, especially during times of crisis. Donna Grindle of the “Help Me with HIPAA” Podcast, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:

  • How to address the gaps in understanding and myths about HIPAA that hinder healthcare providers
  • Various approaches to administrative safeguards like Business Contingency Plans and Disaster Recovery Plans
  • Ways to leverage the requirements of HIPAA to better protect individuals and organizations

2020 SecurityMetrics HIPAA Guide - https://info.securitymetrics.com/hipaa-guide-2020
2020 SecurityMetrics PCI Guide - https://info.securitymetrics.com/pci-guide-2020

Learn more at SecurityMetrics.com

Check out Donna's "Help Me with HIPAA" podcast! - https://www.youtube.com/channel/UCut7RuWxal0925CS2yEpSHw

*Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

Of all the types of malware, ransomware is one of most dangerous. In this episode, Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) sits down with Dave Ellis (VP Forensic Investigation, GCIH, CISSP, QSA, PFI) to discuss:

-What you should do before, during, and after a ransomware attack

-Stories from the field about ransomware attacks and responses

-The “compliance versus security” debate in the effort to prevent ransomware

“When it comes to your cybersecurity, don’t trust anything. Games, quizzes, and other fun apps seem harmless, but may very be collecting personal data or installing backdoors on systems,” says Ellis.

2020 SecurityMetrics HIPAA Guide: https://info.securitymetrics.com/hipa...

2020 SecurityMetrics PCI Guide: https://info.securitymetrics.com/pci-...

Learn more at https://www.securitymetrics.com/

Resources: https://www.securitymetrics.com/blog/...

*Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

In this episode, Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) sits down with Matt Heffelfinger (Director of SIEM Operations, GSTRT, CyRP (Pepperdine), GRCP, SSAP, ITIL4-F, GISF, PECB) and Forrest Barth (SOC Analyst, CISSP, CMNO, Security+) to discuss:

  • How threat actors are leveraging the COVID-19 crisis climate to prey on businesses and individuals
  • Current phishing and social engineering scams to watch out for and how to avoid them
  • Security awareness tips you can share with those most vulnerable to cyber scams and attacks

Resources: https://www.securitymetrics.com/blog/covid-19-cyber-attacks-threat-report-and-best-practices

2020 SecurityMetrics HIPAA Guide: https://info.securitymetrics.com/hipa...

2020 SecurityMetrics PCI Guide: https://info.securitymetrics.com/pci-...

Learn more at https://www.securitymetrics.com/

*Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

SecurityMetrics Podcast | 3
How to Prevent Formjacking and Ecommerce Skimming

In this episode, Aaron Willis (Forensic Analyst, CISSP, PFI) sits down with Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) to discuss:

  • What is formjacking/ecommerce skimming?
  • Tools to use to prevent and avoid formjacking/ecommerce skimming
  • Solutions on how to detect and track skimmers
  • What to do if your data is being skimmed

Learn more at SecurityMetrics.com/webpage-integrity-monitoring

Download our Guide to PCI Compliance! - https://info.securitymetrics.com/pci-guide-2020

Download our Guide to HIPAA Compliance!- https://info.securitymetrics.com/hipaa-guide-2020

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

View Details

In this episode, Meagan Elguera (Corporate Communications Managers) sits down with Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) to discuss:

  • Added pressure and stress covered entities may face during times of crisis
  • How using telehealth for treatment affects privacy and security amid COVID-19
  • Review of the recent bulletin from the OCR on Civil Rights, HIPAA, and Coronavirus

https://www.securitymetrics.com/
PCI Guide: https://info.securitymetrics.com/pci-guide-2020
HIPAA Guide: https://info.securitymetrics.com/hipaa-guide-2020
Get a quote: https://www.securitymetrics.com/pci
Resources: https://www.hhs.gov/sites/default/files/ocr-bulletin-3-28-20.pdf

View Details

In this episode, Jen Stone sits down with Michael Simpson (Principal Security Analyst, CISSP, CISA, QSA) to discuss:

  • Data security best practices while working from home
  • How to properly use a VPN
  • How working from home affects a PCI Assessment

https://www.securitymetrics.com/
PCI Guide: https://info.securitymetrics.com/pci-guide-2020
HIPAA Guide: https://info.securitymetrics.com/hipaa-guide-2020
Get a quote: https://www.securitymetrics.com/pci
Resources: https://www.hhs.gov/sites/default/files/ocr-bulletin-3-28-20.pdf