Ivanti Insights: Recent Episodes

Ivanti

Cybersecurity and technology are changing fast. Ivanti Insights is a podcast that stays ahead of it all so leaders like you can stay ahead, too. Get updated on the latest trends and issues affecting organizations around the world like ransomware, phishing, mobile attacks and more. Learn about what's top of mind for industry leaders and gain a clearer understanding of the rapidly evolving threat landscape. Each episode features actionable insights and expert commentary from Ivanti security experts to help you prevent and navigate cyber threats in the world of on-premises and remote work.

View Details

Securin CEO Ram Movva joins the show to talk all things vulnerability intelligence: how to prioritize according to risk, how to manage your external attack surface and emerging trends in ransomware and security.

  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Ivanti's Chris Goettl (VP of Product, Patch Management) welcomes back Robert Waters (Lead PMM, Exposure Management) to cover the dreaded costs of a cyberattack, and how organizations can work to proactively avoid them by addressing three strategic imperatives: attack surface, vulnerability prioritization, and data silos.

  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Ivanti's Robert Waters (Lead PMM, Exposure Management) is back with Chris Goettl (VP of Product, Patch Management) for the last of our three episodes covering Verizon's 2024 Data Breach Investigations Report, covering the third-most popular attack vector in breaches today: exploit vulnerabilities. And while they may be #3 in prevalence, they're #1 in Chris and Robert's hearts.

To view Verizon's report, head to:
https://www.verizon.com/business/resources/reports/dbir/

  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Ivanti's Chris Goettl (VP of Product, Patch Management) welcomes back Robert Waters (Lead PMM, Exposure Management) for a follow-up on Verizon's 2024 Data Breach Investigations Report, discussing the two main attack vectors used in most breaches -- phishing and credential attacks -- and how your organization should go about defending itself.

To view Verizon's report, head to:
https://www.verizon.com/business/resources/reports/dbir/

  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Ivanti's Chris Goettl (VP of Product, Patch Management) welcomes Robert Waters (Lead PMM, Exposure Management) as they discuss the key takeaways from Verizon's latest annual Data Breach Investigations Report: persistent risk from credentials, more and more sophisticated phishing attacks, and the rising prevalence of vulnerability exploits.

To view the report yourself, head to:
https://www.verizon.com/business/resources/reports/dbir/

  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

What does CSO stand for at your organization?

Is it short for Chief Security Officer... or Chief Scapegoat Officer?

In this episode, Ivanti CSO Daniel Spicer talks about how he never thought he'd be a CSO, and the unique pressures that security executives face from their own internal leadership teams and external regulations or (worse) insurance companies.

Listen in as Daniel and Ashley dig into:

  • What counts as a "breach" -- legally and ethically -- and the conflicting pressures to either report or not.
  • How hackers try to bluff their way into a breach...
  • ... and how "breach coach" insurance lawyers may or may not try to pressure teams out of reporting incidents they should.
  • Where to find the best internal allies to help you stand up to undue pressures and maintain your ethical high grounds.
  • The #1 thing security leaders should do during their interview process to make sure they're signing on with the right organization
  • How -- if you do get fired due to a breach -- it's not the end of your career as a security professional.

  • Next episode going live June 29, 2023!

    • New episodes publish around the second and fourth Thursdays each month.
  • For all show notes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Daniel Spicer is back! Following up on last episode's discussion on the security risks of overemployment, Ivanti's Chief Security Officer returns to clear up the age-old myth of security tools being abused for employee investigations. Join Daniel, Chris and Ashley as they discuss:

  • What is (and most definitely is not) allowed in an employee investigation -- especially if the Security Team is requested to assist
  • User and management's misconceptions about security data, and how it's less "Big Brother," and more "Death by Data"
  • The invaluable technique of using HR and Legal both to cover your asks and avoid abuse of security tools during investigations
  • How you're more likely to investigate an employee due to a media outlet's DMCA request than overemployment
  • What a manager's "tipping point" is to request a more robust employee investigation, and what would trigger Security to get involved

Join us for another episode in which empathetic management and a sympathetic legal department might be the best security tools you'll ever deploy when it comes to cracking down on bad employee behavior -- well, that, and a solid VPN / MDM combo.

  • Next episode going live June 29, 2023!
    • New episodes publish around the second and fourth Thursdays each month.
  • For all show notes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Chris and Ashley use the current overemployment media trend as an example case study on evaluating security risks versus potential organizational impact. 

They cover: 

  • How overemployment existed before remote work
  • Weighing the various security implications of overemployment — including shadow IT and insider threats
  • How far an organization should go to remediate security risks due to unknown overemployed employees... and the cultural trade offs organizations may be required to make.

  • Next episode going live May 25, 2023!

    • New episodes publish around the second and fourth Thursdays each month.
  • For all show notes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Chris (finally!) adds his insights to the 2023 Press Reset cybersecurity research report, especially how its findings impact vulnerability and patch prioritization processes — do you shoot for mission critical systems, active exploits, or something else first? — and why asset visibility lies at the core of every security framework on the planet.

  • Next episode going live May 25, 2023!
    • New episodes publish around the second and fourth Thursdays each month.
  • For all show notes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

JR Robinson, Head of Platform at generative AI startup Writer, joins VP of Endpoint Security Product Management Chris Goettl and Ashley Stryker to discuss current generative AI use cases for security teams that go beyond just chat bots.

(Please. For everyone’s sanity… go beyond chat bots.)

They’ll also preview a deeper webinar discussion with Chief Security Officer Daniel Spicer on the risks and rewards generative AI offers security teams at every organization, airing on April 26 — save your spot and bring your questions to "Generative AI for Infosec and Hackers: What Security Teams Need to Know!"

  • Next episode going live April 11, 2023!
    • New episodes publish around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on LinkedIn (linkedin.com/company/Ivanti)

View Details

Daniel and Ashley review the latest research report from Ivanti -- Press Reset: A 2023 Cybersecurity Status Report -- including prioritizing phishing and DDoS attacks, security ROI challenges, and why organizations should never increase their cybersecurity budget by sacrificing their IT allocations.

Download the full report at Ivanti.com/CybersecurityReport

  • Next episode drops February 16, 2023!
  • New episodes publish around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

It's vendor risk versus reward!

Chris and Amanda educate Ashley on the core considerations, processes and requirements for robust vendor risk management programs... including when to be afraid of your IoT devices, especially those pesky Roomba vacuums and oh-so-convenient self-cleaning litter boxes.

Remember to address these three components, no matter if your vendor is a major IT software provider or just your friendly neighborhood paper salesman:

  1. What data are you granting your vendor?
  2. What can they access?
  3. Due diligence and 200+ item questionnaires are everything.
  4. Next episode drops February 16, 2023!
  5. New episodes publish around the second and fourth Thursdays each month.
  6. For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  7. Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

IT Director Tony Miller goes toe-to-toe with Chief Security Officer Daniel Spicer to justify – or condemn! – IT and cybersecurity posts found on Reddit, featuring a legendary story about hackers that patched endpoints faster than the company itself. #PatchHacks

Plus, Ashley frets about the impact of a new security policy on her personal devices, creating an impromptu case study on the importance of explaining (or just reading) new security policies.

  • Next episode drops February 16, 2023!
  • New episodes publish around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

Daniel, Chris, Amanda and Ashley revisit the coordinated disclosure conversation from Episode 25 and apply the prisoner’s dilemma thought experiment to create a (more?) perfect vendor disclosure policy.

  • Find shownotes for this episode at Ivanti.com/SecurityInsights-30
  • Next episode drops February 16, 2023!
  • New episodes publish around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

Amanda and Ashley talk about their experiences as women in the cybersecurity and technology industries. (Spoiler alert: it’s on the up-and-up!)

  • Find shownotes for this episode at Ivanti.com/SecurityInsights-29
  • Next episode drops December 15, 2022!
  • New episodes publish around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

Amanda and Chris share stories proving why your data really is more secure in the cloud than the average on-premises server closet – and what organizations should worry more about when it comes to data security.

  • New episodes bimonthly around the second and fourth Thursdays each month.
  • For all shownotes, resources and references, head to Ivanti.com/SecurityInsights
  • Join the conversation online on Twitter (@GoIvanti) or LinkedIn (linkedin.com/company/Ivanti)

View Details

Want to work in cybersecurity but not sure what you need? Ashley and Chris talk to three current cybersecurity experts on how they entered the industry – including Ivanti deputy CSO Amanda Wittern. (Also, bonus update on how Ashley pulled off her social engineering assignment from last episode!)

  • 00:30 – Marketing Social Engineering in the Wild
  • 05:07 – Deputy CSO Amanda Wittern’s journey to InfoSec
  • 09:43 – Threat Operations Analyst Kameron Hansen’s transition to security
  • 14:05 – Cybersecurity Engineer Joshua Randall’s move to cybersecurity architecture
  • 22:42 – Transitioning non-InfoSec “soft skills” into a cyber career change

View Details

In this episode, Chris tries to convince Ashley that marketers naturally make excellent hackers, based on modern phishing attacks and techniques… And Ashley confirms his guess by revealing the lengths to which marketers will go to “spoof” natural conversation and drive their target audience to take action.

Referenced materials:

The DarkNet Diaries Podcast, Episode 69: Human Hacker - https://darknetdiaries.com/transcript/69/

Ashley’s “Social Engineering” booklist - https://www.amazon.com/hz/wishlist/ls/1INOW5WGDDUO5?ref_=wl_share

~~*

Visit us on:

LinkedIn: https://www.linkedin.com/company/ivanti/

Twitter: https://www.twitter.com/GoIvanti/

Facebook: https://www.facebook.com/GoIvanti/

Instagram: https://www.instagram.com/goivanti/

Blog: https://www.ivanti.com/blog

View Details

Security Insights welcomes its new host, Ashley Stryker, into the mix! In today's episode, Chris Goettl and Daniel Spicer break down some backlash from Microsoft customers on their failure to disclose a “ninja patch” on a vulnerability researchers found months before the fix. Listen in as the trio discuss security transparency and best practices for vendor coordinated disclosures of vulnerabilities for cloud versus on-prem products and much more!

~*~

Ivanti automates IT and security operations to discover, manage, secure and service from cloud to edge.

Visit us on:
LinkedIn: https://www.linkedin.com/company/ivanti/
Twitter: https://www.twitter.com/GoIvanti/
Facebook: https://www.facebook.com/GoIvanti/
Instagram: https://www.instagram.com/goivanti/
Blog: https://www.ivanti.com/blog

View Details

Hello and welcome back to this week’s episode of Ivanti’s Security Insights! Today Chris Goettl and Daniel Spicer go over their takeaways from the recent Gartner Security & Risk Management Summit.

Chris is the Vice President of Product Management for Advantage Endpoint Security Products while Daniel is the chief Security Officer here at Ivanti, and together they discuss trends and topics bouncing around in the security world. For more information, check out www.ivanti.com! Be sure to follow us on our socials @goivanti for more episodes like this!

~~*
Ivanti automates IT and security operations to discover, manage, secure and service from cloud to edge. 

Visit us on: 
LinkedIn: https://www.linkedin.com/company/ivanti/ 
Twitter: https://www.twitter.com/GoIvanti/ 
Facebook: https://www.facebook.com/GoIvanti/ 
Instagram: https://www.instagram.com/goivanti/ 
Blog: https://www.ivanti.com/blog

View Details

We’re back and ready to roll with this week’s episode where our host Chris Goettl interviews Chad Holmes and Daniel Brody from Cynario. Today they discuss healthcare and security through EMT devices and much more.

Watch to learn more about how cyber security is assisting healthcare innovation! For more information, check out Cynario’s website www.cynerio.com or their social media @cynerio. Be sure to follow us on our socials @goivanti for more episodes like this!

View Details

In our first episode of 2022, Chris Goettl and Daniel Spicer unpack one of last year's biggest vulnerabilities: Apache Log4j. The conversation includes:

  • What is Log4j?
  • The difficulty of detecting Log4j and developing guidance for organizations
  • Why security teams and IT teams are stuck in a Catch 22 of patching
  • The latest guidance you can use for your organization

Check out cisecurity.org and Ivanti's article on Log4j

View Details

Host Adrian Vernon sits down with Daniel Spicer to bust some cybersecurity myths! The list of myths include:

  • Passwords should be changed every 30 days
  • You shouldn't write down your password
  • Multi-factor Authentication is not secure
  • You don't need antivirus
  • VPNs keep my devices safe and secure
  • IT is responsible for all of the cybersecurity at an organization

"Stay safe, be secure, and keep smiling!"

View Details

Host Adrian Vernon is joined by Ivanti's Senior Vice President of Security Products Sri Mukkamala, CEO of Cyber Security Works (CSW) Aaron Sandeen, and Senior Intelligence Analyst at Cyware Neil Dennis. They break down the recent collaborative Ransomware Index Spotlight Report to make sure you are up to date on today's cybersecurity landscape. The conversation includes:

  • How the report was put together
  • What you can expect from the report
  • The importance of the collaboration
  • Surprising contexts
  • Why a yearly compliance checkpoint may not be enough
  • The possible future of ransomware
  • CYBER HYGIENE!

Check out the report at ivanti.com

View Details

Adrian gets some insight from Chris and Daniel on some recent supply chain attack events.

The conversation includes:

  • The unique agenda of nation state attacks
  • The numbers game associated with cloud services attacks
  • There are way more attacks than what get covered in the news
  • What makes an attack a "Supply Chain Attack"
  • Microsoft's recommendations for providers and customers
  • Proactive steps you can take

For more on supply chain attacks check out our episode The Human Element of Preventing Supply Chain Attacks

View Details

Host Adrian Vernon is joined by the usual cast, Daniel Spicer and Chris Goettl, to talk about Cyber Security Awareness Month and some of the best security practices from experts that have seen it all! The conversation includes:

  • When to rotate your credit cards and more!
  • Why going paperless when you can is so important, and if you can't, get a shredder!
  • Best travel cyber hygiene practices for your personal devices
  • Wifi security in the air and on the road
  • When it's appropriate to bring separate travel-only devices
  • The importance of using power packs while in airports
  • When and how to use social media while you are traveling

View Details

Host Adrian Vernon and VP of Product Management Chris Goettl break down some of the biggest headlines in the world of cybersecurity right now! The conversation includes:

  • The recent critical security flaw of Apple devices
  • How threat actors use remote code execution to mine cryptocurrency
  • Lessons learned from the SolarWinds breach
  • Actions to take as cybersecurity threats increase
  • October is Cybersecurity Awareness Month!

View Details

Host Adrian Vernon, VP of Product Managment Chris Goettl, and Chief Security Officer Daniel Spicer talk about the hottest buzzword in security right now: Zero Trust! The conversation includes:

  • What Zero Trust is and what benefits it brings to security
  • An overview of the federal government adopting the Zero Trust strategy
  • The Zero Trust maturity model
  • What it takes for a company to begin moving to Zero Trust
  • Thoughts on missing elements from the Biden executive order and what we'd like to see added or changed
  • The importance of making sure work can still get done with Zero Trust in place

View Details

Host Adrian Vernon, VP of Product Managment Chris Goettl, and Chief Security Officer Daniel Spicer give you the rundown on everything Cyber Insurance! The conversation includes:

  • What Cyber Insurance covers and why it's important
  • What you need to know to be prepared for your conversation with a broker
  • How to save MONEY on your plan
  • The Cyber Insurance grey area and avoiding fines

View Details

Host Adrian Vernon, VP of Product Managment Chris Goettl, and Chief Security Officer Daniel Spicer talk about the future of artificial intelligence and machine learning in cyber security including:

  • The beginning of AI
  • How AI and ML benefit organizations
  • How AI and bots are used to attack organizations
  • What kinds of AI will we need to stand up to those attacks? How do we get Skynet to go up against Ultron?
  • The human element behind AI and the danger of over-automation

View Details

Host Adrian Vernon, Sr. Director of Product Management Chris Goettl, and CEO of RiskSense Sri Mukkamala talk about the recent news of the Ivanti and RiskSense team up and what it means for patch management moving forward!

The conversation includes:

  • The history of RiskSense
  • The importance of "Proactive Response"
  • Some insights on the current realities in our world of vulnerabilities
  • Why the White House is encouraging a risk-based assessment strategy
  • Best practices on approaching the challenges that organizations face
  • Cyber Hygiene!

View Details

Host Adrian Vernon, Sr. Director of Product Management Chris Goettl, and VP of Security Daniel Spicer explore recent challenges concerning the rise in supply chain attacks.

The conversation includes:

  • How a supply chain can be attacked and why organizations should care
  • The reality of building systems using multiple off the shelf products and the importance of making sure those products and vendors are secure
  • Best practices around defending against supply chain attacks
  • The new cybersecurity executive order

View Details

We are taking a break this week for Ivanti's Summer of Security, but don't worry we'll be back next week! Until then, if you missed it, check out one of our favorite episodes: The Balancing Act of Staying Secure While Working From Home.
Host Adrian Vernon, Ivanti's Chef Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl discuss the new security landscape formed by the "new normal" of remote working including:

  • Ivanti's new Secure Consumer Cyber Report revealing chilling insights
  • The "Password Nirvana"
  • The importance of two-factor authentication on your personal devices

View Details

Host Adrian Vernon, Ivanti's Chief Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl cover some recent data on ransomware attacks.

The conversation includes:

  • History on the earliest known ransomware attacks
  • The recent explosion in value of ransoms
  • The concept of the trustworthy threat actor
  • How threat actors adapt to the digital landscape, quarter by quarter

View Details

Host Adrian Vernon, Ivanti's Chef Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl talk about the everywhere workplace! The conversation includes:

  • Surprising numbers from a brand new Ivanti survey
  • Perspectives on the value of the everywhere workplace
  • The role the pandemic played on more companies and workers adopting an everywhere workplace mindset
  • Prediction on what the everywhere workplace looks like moving forward
  • Views on wearing pants during remote meetings

View Details

Host Adrian Vernon and  Sr. Director of Product Management Chris Goettl get an opportunity to talk with "the world's most connect human" and author of Don't Unplug: How Technology Saved My Life and Can Save Yours Too, Chris Dancy! In this second part, the conversation includes:

  • The everywhere workplace and staying conscious about security and safety
  • GPS trackers
  • "Technology can be good, or it can be easy, but it can't be both"
  • Chris' experience with tech and solutions designed to circumvent the dreaded password
  • Understanding "We don't know how to measure what we care about, so we care about what we measure"

Visit chrisdancy.com to connect with the world most connected human!

View Details

Host Adrian Vernon and  Sr. Director of Product Management Chris Goettl get an opportunity to talk with "the world's most connect human" and author of Don't Unplug: How Technology Saved My Life and Can Save Yours Too, Chris Dancy! In this first part of two, the conversation includes:

  • Where Chris' moniker came from
  • What it means to be "the world's most connected human"
  • Why you may be more connected than you think you are
  • How unplugging, in some cases, can lead to missed personal connections
  • Understanding where tech fits in helping you obtain the things you value, such as exercise or being creative

View Details

Host Adrian Vernon, Ivanti's Chef Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl discuss the threat you probably weren't fully aware of: The QR code! The conversation includes:

  • QRurb Your Enthusiasm 2021: Why the QR code Remains a Top Security Threat and What You Can Do About It (report)
  • What a QR code is and how it works
  • How QR codes have risen in popularity with the need for "touchless" solutions during the pandemic
  • The possible vulnerabilities that could be exploited in QR codes
  • The importance of keeping your mobile device secure. Period.

View Details

Host Adrian Vernon, Ivanti's Sr. Director of Product Management Chris Goettl, and first time guest Bart Westering, Ivanti's VP of Security Engineering, discuss DevOps, DevSecOps, and more!

The conversation includes:

  • What is DevOps?
  • What is the difference between DevOps and DevSecOps?
  • Best practices around adopting or maturing your DevOps process
  • What can happen when DevOps processes fall apart

View Details

Host Adrian Vernon, Ivanti's Chef Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl discuss the new security landscape formed by the "new normal" of remote working including:

  • Ivanti's new Secure Consumer Cyber Report revealing chilling insights
  • The "Password Nirvana"
  • The importance of two-factor authentication on your personal devices

View Details

Host Adrian Vernon, Ivanti's Chef Security Officer Phil Richards, and Sr. Director of Product Management Chris Goettl discuss the inherent privacy concerns social media can bring including:

  • Understanding the newest platform: "Clubhouse"
  • How your social media data is collected and used
  • Social media privacy best practices

View Details

Host Adrian Vernon and Ivanti CSO Phil Richards discuss how companies can avoid and deal with ransomware attacks, including:

  • Training employees to not open suspicious emails and links that make networks vulnerable to ransomware
  • The security vulnerabilities of old or unpatched software
  • The pros and con of having backups
  • How to use credential management to combat privilege escalation

Connect with Phil on LinkedIn

View Details

Ivanti Senior Director of Product Management, Chris Goettl, and Chief Security Officer, Phil Richards, join host Adrian Vernon to discuss the recent cyber attack that affected many dozens of organizations around the world, including multiple U.S. government agencies.