Cyber Security & Cloud Podcast: Recent Episodes

cscp

Welcome to the Cyber Security & Cloud Podcast #CSCP where we will explore the dark secret of cloud and cyber.

The podcast focuses on people and their stories and explores the human element that brings so many people together

Some episode will be for the well-seasoned cybersecurity veteran but most are about stories of infosec people and how they reach where they are now.

The focus and various stream of the podcast is Cybersecurity, Cloud Security, Application Security Social Engineering, and community building

View Details

Join us for an engaging episode as we welcome James Berthoty, a seasoned cybersecurity professional with a diverse background spanning sysadmin, DevOps, and security engineering roles. James takes us through his journey across different organizations, including his current role at PagerDuty, where he tackles the intricate challenges of FedRAMP compliance. Listen in as James shares insights on the rapid evolution of the Application Security (AppSec) industry, driven by the need for infrastructure professionals to interact with application code in today’s API-driven cloud environment. We also explore the disparity in innovation recognition among security solution providers and the difficulties of staying current in this fast-paced industry.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

We also discuss the complex challenges of managing visibility and actionability within cybersecurity, particularly in handling software vulnerabilities. Learn about the evolution of patch management and the inefficiencies of the Common Vulnerabilities and Exposures (CVE) system, which often leads to false positives. This conversation sheds light on the market's tendency to prioritize quantity over quality in vulnerability detection tools and the potential shift towards more precise, less noisy solutions. Effective testing and benchmarking tools, like insecure testing repositories and OWASP projects, are also highlighted as a means to enhance the reliability of security tools. Finally, we explore the broader landscape of security tools and frameworks, including the stringent requirements of FedRAMP and the balance between flexible and opinionated tools. Through case studies and real-world examples, we discuss the significance of asset management, the evolving landscape of security tools, and the importance of transparency in marketing. The episode wraps up with a look at managing open-source supply chain risks and the crucial role of entities like Tidelift in providing paid maintenance services, reflecting the industry's shift towards better security practices. Don't miss this comprehensive exploration of the current state and future trends in the cybersecurity and software security industry.

Episode Highlights:

•Application Security and ASPM: We delve into the complex challenges of Application Security Posture Management (ASPM), focusing on managing visibility and actionability within cybersecurity, particularly in handling software vulnerabilities.

•Vulnerability Management: Learn about the evolution of patch management and the inefficiencies of the Common Vulnerabilities and Exposures (CVE) system, which often leads to false positives.

•Effective Testing Tools: This conversation sheds light on effective testing and benchmarking tools, like insecure testing repositories and OWASP projects, to enhance the reliability of security tools.

•FedRAMP and Security Tools: Explore the stringent requirements of FedRAMP and the balance between flexible and opinionated tools in the broader landscape of security frameworks.

•Asset Management: Through case studies and real-world examples, we discuss the significance of asset management in vulnerability management and the evolving landscape of security tools.

•Open Source Supply Chain Risks: The episode wraps up with a look at managing open-source supply chain risks and the crucial role of entities like Tidelift in providing paid maintenance services, reflecting the industry’s shift towards better security practices.

What's Inside This Episode:* 00:54 - Host Introduction: Francesco Cipollone introduces the episode and guest James Berthoty. * 01:27 - Guest Introduction: James Berthoty shares his background and journey in cybersecurity. * 02:07 - Managed Detection Response Insights: James discusses his experience and insights from working in managed detection response. * 05:16 - AppSec Industry Evolution: Discussion on the rapid changes in AppSec and the impact of new technologies. * 09:28 - The Challenge of Vulnerability Management: Francesco and James delve into the complexities of modern vulnerability management. * 12:32 - Tool Integration and Market Trends: The conversation shifts to the integration of various security tools and market trends. * 20:21 - Security Operations Challenges: The struggle of handling CSPM alerts and the role of security operations. * 27:01 - Asset Management Importance: The critical role of asset management in vulnerability management and its implications. * 31:48 - Market Evolution and Tool Adaptation: Discussion on how security tools need to adapt to evolving market demands. * 35:50 - Reachability Analysis and SBOM: The importance of reachability analysis and the challenges of maintaining secure software supply chains. * 44:50 - Positive Outlook on Security Discussions: Concluding thoughts on the positive impact of increased security discussions and market involvement. * 46:09 - Closing Remarks: Francesco wraps up the episode and provides information on how to follow James Berthoty.

Connect with James Berhoty* Website: Latiotech * LinkedIn: James Berthoty

James Berthoty is a passionate security professional writer and creator of Latio Tech, dedicated to transforming security teams into integral contributors to product development, embodying the true essence of DevSecOps. As a former Security Engineer at PagerDuty, James leverages his extensive experience in sysadmin, DevOps, and cloud security to drive innovative security practices and ensure robust application security.

Driven by his mission to connect people with the right products, James founded Lacio Tech, a platform that provides insights and reviews on emerging security technologies and startups. His hands-on experience in both startup environments and large enterprises equips him with a unique perspective on the challenges and solutions in the cybersecurity landscape.

Residing in Tampa, Florida, James balances his professional life with his personal passions. He lives with his wife, Alexxus, and their three children. By day, he leads DevSecOps initiatives at ReliaQuest, and by night, he pursues a PhD in Philosophy and indulges in video gaming. His commitment to continuous learning and his multifaceted interests make him a dynamic and influential figure in the cybersecurity community.

Connect with James:

Follow Cyber Security and Cloud Podcast* Website: Cyber Security and Cloud Podcast * LinkedIn: Cyber Security and Cloud Podcast LinkedIn * Twitter: @podcast_cyber * YouTube: Cyber Security and Cloud Podcast YouTube * iTunes: Cyber Security and Cloud Podcast on iTunes * Spotify: Cyber Security and Cloud Podcast on Spotify

Hashtags#Cybersecurity #AppSec #ProductSecurity #ProdSec #ASPM

View Details

Join us as we explore the evolving application security landscape with Marius Poskus, VP of Glow Financial Services and a seasoned cybersecurity professional. In this episode, we delve into the increasing adoption of open-source code and AI in startup development, examining the potential impacts on code security amid rapid innovation pressures. Marius shares his insights on the cultural shifts required for effective DevSecOps practices, the prolonged timelines for meaningful change, and the disruptions caused by changing CISOs. We also touch on the challenges of maintaining consistent application security programs in a dynamic leadership environment, the proliferation of tools, and the importance of measuring their effectiveness. Listen in as we unravel the complexities of managing application security within development environments.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

We highlight the significance of providing contextual insight and effective communication to address security issues meaningfully. By prioritizing critical issues that offer the most significant risk reduction, we advocate for a strategic approach to security management. Marius also emphasizes understanding the root causes of vulnerabilities to enhance overall practices and mitigate future risks. Finally, we discuss translating risk into business language, emphasizing temporality and criticality to align security efforts with business priorities.

What's Inside This Episode:* 00:00 - Introduction: Francesco Cipollone introduces the podcast and guest, Marius Poskus, VP at Glow Financial Services. * 00:50 - Marius's Introduction: Marius discusses his background and roles, including his YouTube channel and upcoming consultancy. * 02:04 - Industry Overview: Marius talks about the evolving landscape of application security and the impact of AI. * 03:25 - Secure Code Development: The challenges of rushing code to market and understanding governance and risks. * 04:19 - Application Security Programs: The cultural shift needed for DevSecOps and the impact of CISO tenure on security programs. * 06:15 - Tooling and Measurement: The prevalence and challenges of security tools in organizations. * 07:00 - Compliance and Standardization: The role of emerging standards and frameworks in driving security practices. * 09:01 - Asset Management and Application Security: Tracking code across different environments and the complexity of asset management. * 10:48 - Ownership and Attribution: Identifying ownership and responsibility for code and vulnerabilities. * 13:00 - Contextual Insight: Providing rich information and context to development teams for better security understanding. * 15:18 - Measuring Security Tooling: The need for better measurement and understanding the root cause of issues. * 17:00 - Risk Management: Prioritizing issues based on risk and translating security issues into business risks. * 18:45 - Advice for CISOs: Building business expectations, creating positive narratives, and transforming security from a cost center to a revenue generator. * 21:57 - ROI of Security: Measuring the ROI of security through risk reduction and effective communication. * 23:38 - Positive Industry Outlook: Marius's optimistic view on the industry's trajectory towards better security practices. * 25:19 - Closing Remarks: Final thoughts on staying updated with industry changes and innovations. Where to find more about Marius and his work. * 26:09 - Outro: Francesco thanks Marius and encourages listeners to build security programs with insight.

Connect with Marius Poskus* LinkedIn: Marius Poskus * Podcast: Cyber Diaries Episode

About MariusWith over a decade of cybersecurity experience, I am the Global Vice President and Chief Information Security Officer at Glow Financial Services Limited, a leading fintech company that offers innovative and customer-centric solutions. My mission is to build and execute a comprehensive cybersecurity strategy that aligns with the business goals and enterprise risk management of Glow, while ensuring compliance with ISO27001 and other relevant standards.

I lead a high-performing team of cybersecurity professionals who deliver cutting-edge solutions across various domains, such as cloud security, DevSecOps, AppSec, threat hunting, penetration testing, and red and purple teaming. I have successfully implemented a 24/7 Security Operations Centre, a cloud adoption model, and an AppSec program that enhance the security posture and resilience of Glow's global operations. I am also passionate about sharing my knowledge and insights on cybersecurity topics as a public speaker, a non-executive director, and a mentor.

Follow Cyber Security and Cloud Podcast* Website: Cyber Security and Cloud Podcast * LinkedIn: Cyber Security and Cloud Podcast LinkedIn * Twitter: @podcast_cyber * YouTube: Cyber Security and Cloud Podcast YouTube * iTunes: Cyber Security and Cloud Podcast on iTunes * Spotify: Cyber Security and Cloud Podcast on Spotify

Hashtags#Cybersecurity #AppSec #ProductSecurity #ProdSec #ASPM

View Details

Join us in this insightful episode of the Cybersecurity and Cloud Podcast, where host Francesco Cipollone sits down with the pioneer of threat modeling, Adam Shostack. Dive into the intricacies of Application Security Posture Management (ASPM), effective threat modeling practices, and the innovative solutions offered by Phoenix Security. Gain valuable knowledge on how to improve your organization's security posture and stay ahead of evolving threats.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

We delve into threat modeling and software security, touching on the profound implications of the White House's recent report on memory-safe programming languages. We also dissect the systemic challenges of self-regulation in the cybersecurity market, especially in the aftermath of significant incidents like the SolarWinds attack. Adam shares his valuable insights on CISA's latest strategies to tackle vulnerabilities at their origin, emphasizing the critical need for proactive and systemic solutions in bolstering cybersecurity practices. In another segment, we examine the complexities surrounding software security regulation and self-regulation in both the US and Europe. Drawing parallels to the automotive industry, we discuss how software companies are held accountable for the components they use, similar to how car manufacturers are responsible for their parts. The conversation highlights the Biden administration's executive order requiring vendors to self-attest to software security when selling to the US government and compares this to established regulatory frameworks like SEC regulations. We also address the balance between proactive and reactive regulatory measures, referencing historical efforts such as Microsoft's Trustworthy Computing initiative and discussing the unique challenges faced by sectors like medical devices, where security and functionality must be meticulously balanced.

Key Discussion Points:

  • Threat Modeling and Application Security: An in-depth look at threat modeling and its crucial role in enhancing application security.
  • White House Report on Memory-Safe Programming Languages: Exploring the implications of the recent White House report and its impact on software security practices.
  • Self-Regulation vs. Government Regulation: Analysis of the challenges and benefits of self-regulation in the cybersecurity market, particularly post-SolarWinds.
  • CISA’s Strategies on Vulnerability Management: Insights into CISA's proactive approaches to tackling vulnerabilities at their origin.
  • US and European Software Security Regulations: Comparing US and European approaches to software security regulation and the accountability of software companies.
  • Biden Administration’s Executive Order: The requirement for vendors to self-attest to software security and its broader implications.
  • Historical Context: Reflecting on past efforts like Microsoft's Trustworthy Computing initiative and their relevance today.
  • Balancing Security and Functionality: The unique challenges faced by sectors like medical devices in maintaining both security and functionality.

What's Inside This Episode:

  • 00:01 - Introduction: Francesco Cipollone introduces the podcast and guest, Adam Shostack, a leader in threat modeling and application security.
  • 00:22 - Role in Threat Modeling: Adam discusses his contributions to the field of threat modeling and the importance of simplifying and organizing the process.
  • 02:00 - Background and Career: Adam shares his extensive experience in application security, including his work at Microsoft and current role at Shostack and Associates.
  • 03:00 - State of Application Security and Threat Modeling: Discussion on the current state of application security and the significance of the White House report on memory-safe programming languages.
  • 04:00 - Regulatory Influences and Vulnerability Management: Insights into how government regulations are influencing application security and the challenges in managing vulnerabilities.
  • 06:00 - Historical Context of Software Security: Reflection on historical security practices and the evolution of software security.
  • 08:00 - SolarWinds SEC Lawsuit: Detailed discussion on the SEC lawsuit against SolarWinds and the importance of accurate security statements.
  • 10:00 - Challenges in Implementing Security Measures: The difficulties organizations face in implementing effective security measures and the necessity of having a comprehensive asset inventory.
  • 12:00 - Government Regulations and Market Self-Regulation: Debate on the effectiveness of market self-regulation versus government mandates in shaping the future of application security.
  • 14:00 - Balancing Profit and Security: The conflict between maintaining profit margins and investing in security, and the role of commercial support in sustaining open-source software security.
  • 16:00 - Open Source Software and Commercial Support: Discussion on the need for commercial support for open-source software and the impact of regulations on the open-source community.
  • 18:00 - Self-Regulation in Software Security: The role of self-attestation in software security and the thin line between self-regulation and government mandates.
  • 20:00 - Responsibilities of CISOs and Corporate Accountability: The critical responsibilities of CISOs in communicating security risks and how regulatory measures push for better accountability.
  • 22:00 - Microsoft's Security Evolution: Reflection on Microsoft's journey in improving software security and the importance of initiatives like the Security Development Lifecycle (SDL).
  • 24:00 - EU AI Act and Its Implications: Brief overview of the EU AI Act and its impact on high-risk applications.
  • 26:00 - Dark Gemini and Modern Threats: Teaser for a future episode on Dark Gemini, an advanced AI used for nefarious purposes, and its implications for threat modeling and vulnerability management.
  • 28:00 - Weaponization of Vulnerabilities: Discussion on the rapid weaponization of vulnerabilities and the need for systemic fixes in software security.
  • 30:00 - Closing Thoughts: Summary of the discussion on ASPM, threat modeling, and Phoenix Security, emphasizing the positive impact of ongoing changes in security practices.
  • 33:00 - Positive Message and Conclusion: Adam’s positive message about the future of software security and Francesco’s emphasis on the importance of proactive measures. Information on where to find more about Adam Shostack and his work.

Connect with AdamAdam Shostack Adam is the author of Threat Modeling: Designing for Security and Threats: What Every Engineer Should Learn from Star Wars. He’s a leading expert on threat modeling, a consultant, expert witness, and game designer. He has decades of experience delivering security. His experience ranges across the business world from founding startups to nearly a decade at Microsoft.

His accomplishments include:

  • Helped create the CVE. Now an Emeritus member of the Advisory Board.
  • Fixed Autorun for hundreds of millions of systems.
  • Led the design and delivery of the Microsoft SDL Threat Modeling Tool (v3).
  • Created the Elevation of Privilege threat modeling game.
  • Co-authored The New School of Information Security.

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

Follow us on social media to get the latest episodes:

  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Resources and Links:

  • Adam Shostack's About Page
  • Elevation of Privilege Game
  • The New School of Information Security
  • Threat Modeling: Designing for Security (Amazon UK)
  • Threats: What Every Engineer Should Learn from Star Wars (Amazon UK)
  • The New School of Information Security (Amazon UK)
  • Phoenix Security
  • Cybersecurity and Cloud Podcast

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

Listen in as we navigate the crucial role of threat modeling in the landscape of application security with our esteemed guest, Irene Michlin, the application security lead at Neo4j. Together, we peel back the layers of integrating a developer's insight into the security process and how it fortifies the software development lifecycle. Irene's journey from coding to consulting paints a vivid picture of the security challenges and triumphs faced in today's agile environments.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

We also dissect the often misunderstood concept of security theater and the varying impact of regulatory demands across businesses of different scales, all while highlighting the need for a risk-based approach to vulnerability management. During our conversation, we touch upon the symbiotic relationship between threat modeling and agile development, sharing anecdotes that demystify the practice and affirm its teachable nature.

With Irene's rich background, we discuss how embedding security prompts into daily engineering tasks can make threat modeling more actionable, seamlessly blending it with development workflows. Our chat is a testament to the evolution of generational AI, where its jack-of-all-trades persona is on the cusp of becoming a specialized force with proper data training—showcasing the multifaceted potential of AI in cybersecurity and beyond.

Wrapping up the episode, we share our admiration for an innovative Neo4j blog post that elegantly combines general AI with knowledge graphs, a read we highly recommend to those intrigued by the intersection of technology and security. The discussion reaffirms the importance of balancing agility with thoroughness in threat modeling to ensure robust cybersecurity postures.

As we conclude, we remind our listeners of the power of staying informed and proactive in the digital age, inviting them to engage with our community through our social media giveaway and to stay tuned for more insights on navigating the ever-evolving world of cybersecurity.

What's Inside This Episode:

  • 00:01 - Introduction: Francesco Cipollone introduces the podcast and guest, Irene Michlin, application security lead at Neo4j.
  • 00:22 - Sponsorship Mention: Acknowledgment of Phoenix Security's sponsorship.
  • 00:25 - Episode Topic Introduction: Francesco and Irene dive into the importance of threat modeling in application security.
  • 01:07 - Guest Introduction: Irene Michlin shares her journey from software development to application security leadership.
  • 02:59 - Impact of Developer Background on Security: Discussion on how Irene's developer experience enhances her approach to security.
  • 03:54 - Challenges in Security Implementation: Insights into the real-world challenges of integrating security into agile development projects.
  • 05:42 - State of the Industry: Irene's perspective on the current state and future of application security.
  • 07:40 - Security Theater and Compliance: Addressing the pitfalls of security theater and the role of regulatory demands.
  • 09:40 - Reachability Analysis Debate: Pros and cons of reachability analysis in application security.
  • 11:44 - Generative AI in Security: Exploring the potential and challenges of AI in enhancing application security practices.
  • 13:53 - AI-based Threat Modeling: How AI can be leveraged for effective threat modeling while reducing errors.
  • 15:36 - Practical Application of Threat Modeling: Making threat modeling actionable through daily engineering tasks.
  • 20:20 - Security Prompts: Introduction of security prompts to integrate threat modeling into development workflows.
  • 23:15 - Comprehensive vs. Incremental Threat Modeling: Balancing detailed and incremental approaches for robust security.
  • 29:01 - PR Change and Code Scanning: Importance of both PR change scans and full scans in maintaining security.
  • 32:34 - Integrating Vulnerability Management and Threat Modeling: Bridging the gap between these two critical aspects of application security.
  • 36:00 - Closing Message: Encouragement for security professionals to stay positive and seek mentorship.
  • 37:31 - Resources and Contacts: How to connect with Irene and access additional resources.

Connect with Irene Michlin* Connect with Irene Michlin: LinkedIn | Twitter (Legacy: X) * Neo4j Blog: Explore insights on using AI and knowledge graphs for security. * Threat Modeling Manifesto: Discover principles and practices in threat modeling.

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

Follow us on social media to get the latest episodes:

  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

Join us for an in-depth discussion on the challenges and strategies of Application Security Program Management (ASPM) in today's fast-evolving tech landscape. Francesco Cipollone welcomes guest Akira Brand, a seasoned application security engineer and cybersecurity consultant, to explore practical insights into securing applications in the cloud and beyond. We also examine the shift in terminology from AppSec to product security and delve into Akira's unique background in opera singing, which empowers her to convey complex technical subjects with remarkable clarity.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

In this engaging session, curiosity takes center stage as a catalyst for teaching and learning within the tech world. I share my personal experiences and the joy found in the creative struggle of technical writing and documentation. Akira and I discuss the importance of a systematic approach, whether in threat modeling or honing educational techniques. We celebrate the power of curiosity-driven engagement and invite you to reflect on your learning processes. Wrapping up with a focus on threat modeling, we emphasize its significance in application security programs and the importance of business engagement in the risk assessment process. We debate the effectiveness of various motivational strategies, from incentives to potential legal implications for security professionals. As we close, we challenge you to incorporate threat modeling practices into your security measures and participate in our social media challenge. Stay vigilant and join us for a discussion that blends practical insights with forward-thinking perspectives in the ever-evolving landscape of cybersecurity.

What's Inside This Episode:

  • 00:04 - Sponsor Message: Phoenix Security Limited
  • 00:54 - Introduction by Host, Francesco Cipollone
  • 01:29 - Akira Brand discusses her background and transition to application security
  • 07:40 - Deep dive into application security program fundamentals and threat modeling
  • 25:20 - Discussion on fostering a positive security culture within organizations

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

Don't Miss This Engaging Discussion on Cybersecurity Trends and Strategies: Tune into this enlightening episode to equip yourself with the knowledge and insights needed to navigate the ever-changing landscape of cybersecurity. Whether you're a professional in the field, a business leader, or just keen on enhancing your cybersecurity awareness, this episode is packed with valuable information to help you understand the nuances of securing applications and infrastructures in a digitally-driven world.

Resources Mentioned* CIS Security Controls * NIST Framework * OWASP Guidelines

Connect with Akira Brand* LinkedIn: https://www.linkedin.com/in/akirabrand/ * Personal Website: www.akirabrand.com

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

Follow us on social media to get the latest episodes:

  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

This episode features guest Izar Tarandach, a seasoned security architect with extensive experience in application security, cloud security, and the development of comprehensive security frameworks. Our discussion navigates through the latest trends in application security, the pivotal role of DevSecOps, and the strategic integration of security practices within modern business environments.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

As our conversation progresses, we turn our focus to the critical issue of third-party risk in software development. Aizhar and I examine how high-profile cases have shone a light on the vulnerabilities in the software supply chain and the urgent need for developers to embrace secure coding practices. We discuss the shift toward a security-centric development culture and the importance of establishing business-driven security objectives and realistic service level agreements.

Tune in to hear our insights on how the industry is moving beyond the quest for a silver bullet in security tools to a more robust approach that ingrains security into the core responsibilities of developers. In our final chapter, Aizhar and I tackle the delicate balance between ethics, regulation, and business imperatives in cybersecurity. We delve into how regulations can drive security priorities, the risk of a false sense of security, and the vital role of threat modeling in the software development lifecycle. Our discussion highlights the need for a holistic approach that merges the foresight provided by threat modeling with adherence to regulations, fostering a security-conscious culture across all industries. Don't miss this engaging episode where we dissect the evolution of threat modeling and its integral role in protecting our digital world.

What's Inside This Episode:

  • 00:02 - Introduction to Cybersecurity and Cloud Podcast: Francesco introduces the series and outlines what listeners can expect from this enlightening episode.
  • 00:53 - Greetings and New Developments in Threat Modeling: Discover the latest advancements in threat modeling and their implications for cybersecurity.
  • 01:35 - Introducing Izar Tarandach: Learn about Izar's journey and his significant contributions to the field of security architecture.
  • 02:09 - Recent Trends in Application Security: A detailed discussion on the transformation in application security spurred by innovations in cloud technology.
  • 02:54 - Challenges Facing Today's CISOs: Insight into the pressures and challenges CISOs face with rising security stakes.
  • 03:30 - Reevaluating Security Protocols: We analyze how traditional security protocols are being reshaped in today's tech landscape.
  • 04:49 - The Role of DevSecOps: Understanding the integration of security into DevOps practices and its impact on software development.
  • 05:47 - Concept of "Shift Everywhere": Izar critiques the broad application of the "shift everywhere" concept within security strategies.
  • 06:56 - The Evolution of Security Integration: Discussion on how security is becoming embedded in all phases of product development.
  • 08:13 - The Dilemma of Security Buzzwords: Evaluating how new security terminologies affect industry focus and policy development.
  • 09:28 - The Realistic View of Security Practice: A candid look at the progression from idealistic to pragmatic approaches in security practices.
  • 11:25 - Addressing Third-Party Risks: Examination of third-party risks and their impact on the software supply chain.
  • 13:28 - Third-Party Risk Management: A Case Study: Insights from high-profile cases highlighting the importance of managing third-party vulnerabilities.
  • 15:23 - Integrating Security into Business Objectives: How organizations are embedding security objectives into business strategies.
  • 16:47 - Seeking Solutions in Security: A shift from seeking singular security solutions to adopting comprehensive, integrated approaches.
  • 18:18 - Advocating for Risk-Based Approaches: The importance of adopting risk-based strategies over traditional security measures.
  • 19:44 - Educating Developers on Security Importance: The critical role of educating developers on security as a fundamental aspect of software development.

Sponsored by Phoenix Security: This episode is brought to you by Phoenix Security, leaders in vulnerability management from code to cloud. Take control of your security with Phoenix and see firsthand how to prioritize and act on critical vulnerabilities with a free 14-day license available at Phoenix Security - Request a Demo.

Don't Miss This Engaging Discussion on Cybersecurity Trends and Strategies: Tune into this enlightening episode to equip yourself with the knowledge and insights needed to navigate the ever-changing landscape of cybersecurity. Whether you're a professional in the field, a business leader, or just keen on enhancing your cybersecurity awareness, this episode is packed with valuable information to help you understand the nuances of securing applications and infrastructures in a digitally-driven world.

Izar Tarandach

  • Linkedin: https://www.linkedin.com/in/izartarandach/
  • Twitter: https://twitter.com/izar_t?lang=en-GB
  • Books: https://www.oreilly.com/pub/au/7898
  • Github: https://github.com/izar
  • Threat Modelling Con: https://www.threatmodelingconnect.com/general-discussion-32/i-m-izar-tarandach-and-if-you-have-questions-i-may-have-answers-148
  • Speaker profile: https://conferences.oreilly.com/software-architecture/sa-ny-2019/public/schedule/speaker/324717.html

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

A dev perspective on application security:

Dive deep into the pivotal nexus of cybersecurity, application security, and software development in our latest podcast episode featuring Josh Goldberg, a renowned figure in the TypeScript ecosystem. This episode sheds light on the evolving realm of secure coding practices, acknowledging the progress achieved while recognizing the challenges that lie ahead. Join us as we unravel the nuanced role of artificial intelligence in software development, moving beyond the hype to establish grounded expectations for this sophisticated tool.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

Our discussion ventures into the dynamic landscape of the tech job market, sparking a thought-provoking debate on the value of junior versus senior developers in building a resilient digital future. We also underscore the critical role of checklists in enhancing product development, inspired by insights from "The Checklist Manifesto." By integrating accessibility audits and security consultations, we reveal how checklists can transform development processes, ensuring products are secure and accessible from the start.

The conversation extends to the cutting-edge application of AI in threat modeling, highlighting the importance of strategic objectives that place security and accessibility at the forefront. We further explore the essential art of communication within organizations and its pivotal role in seamless security integration. This dialogue emphasizes the significance of leadership in cultivating an environment where trust and verification coalesce, promoting a culture of thorough security checks and balances.

As we dissect the concept of Service Level Agreements (SLAs), our discussion illuminates their dual function as both security mechanisms and corporate assurances, advocating for the early adoption of security measures in business strategies. Experience firsthand how security features, like multi-factor authentication, can serve not just as protective measures but as compelling marketing and product differentiators.

Don't miss this enriching conversation that bridges the gap between cybersecurity practices and software development, offering invaluable insights for professionals navigating the intricate landscape of tech innovation.

Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

  • 00:02: Introduction and sponsorship message from Phoenix Security Limited.
  • 00:53: Welcoming Josh Goldberg, an open source advocate in the TypeScript ecosystem, to the podcast.
  • 01:37: Josh shares his journey into enhancing software quality and security through open-source contributions.
  • 02:01: Analyzing the current landscape of application security and the ongoing challenges for developers.
  • 03:20: The potential of artificial intelligence in revolutionizing secure code practices and its limitations.
  • 04:28: Addressing the scarcity of developer resources and the impact on application security.
  • 07:21: Strategies for integrating essential security practices into development teams with constrained resources.
  • 10:13: Emphasizing the importance of establishing measurable success metrics in secure software development.
  • 13:02: The imperative of fostering effective communication between security and development teams for a robust security posture.
  • 18:08: Discussing the evolution of security tools and the significance of early integration in the development process (Shift Left).
  • 21:32: The role of risk management in aligning business objectives with security imperatives.
  • 25:04: Expressing optimism for the future of tech with advancements in tools and platforms facilitating better security integration.
  • 32:35: Josh's parting thoughts on leveraging ESLint plugins for vulnerability detection and the hopeful reduction of common security flaws.
  • 36:00: Conclusion of the conversation with a focus on the collective progress in cybersecurity and application development.
  • 38:10: Final words from Francesco Cipollone, encouraging listeners to engage with security within their development practices.

Josh Goldberg

Hi, I’m Josh! I’m an independent full time open source developer. I work on projects in the TypeScript ecosystem, most notably typescript-eslint: the tooling that enables ESLint and Prettier to run on TypeScript code. I’m also the author of the O’Reilly Learning TypeScript book, a Microsoft MVP for developer technologies, and an active conference speaker. My personal projects range from static analysis to meta-languages to recreating retro games in the browser. Also cats.

Connect with Josh [bsky / GitHub / Mastodon / Twitter / Twitch / www]

Josh is an independent open source developer and so have no company logos. If you really need one, the main project I help maintain is https://typescript-eslint. * Cyber Security and Cloud Podcast hosted by Francesco Cipollone * Twitter @FrankSEC42 * Linkedin: linkedin.com/in/fracipo * #CSCP #cybermentoringmonday cybercloudpodcast.com * Social Media Links
Follow us on social media to get the latest episodes: * Website: http://www.cybercloudpodcast.com/ * Linkedin: https://www.linkedin.com/company/35703565/admin/ * Twitter: https://twitter.com/podcast_cyber * Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/ * You can listen to this podcast on your favourite player: * Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 * Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

What does it take to get into application security from pentesting? Will AI replace the role of product security? How do you start an application security program and write a book about it?

Join us on the Cybersecurity and Cloud Podcast as we welcome the insightful Raj Umadas, head of InfoSec at Ackblue, for a vibrant discussion on the varied pathways into the field of application security. Listen in as Raj shares his unique journey from networking to the realms of software and hardware design, ultimately leading to his passion for security. We debate whether a background in pentesting is a must for app sec success or if one can climb the ranks from the blue team, all while emphasizing the significance of team diversity over homogeneity.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

Venture into the world of risk assessment and pen testing with us, where we unpack the complexities of cybersecurity through the lens of protective controls and real-world testing experiences. Hear about my time at leading companies like Etsy, Squarespace, and Spotify, where I tackled the balancing act of risk, remediation, and resource allocation. This chapter casts a spotlight on the intricate dance between security leaders and CISOs, underlining the necessity of clear communication and the advantage of technical savvy in these pivotal roles. Finally, tune in as we discuss the ever-evolving role of the CISO and the rise of the DevSecOps culture within the tech industry. Reflect with us on the historical context of software development and how it's transformed into an ongoing nurturing process, necessitating a fusion of development, operations, and security expertise. We also navigate the challenges of regulatory frameworks in the wake of monumental security breaches, fostering a conversation on how industry leaders and regulatory bodies can work together towards safer development practices. Don't miss out on these captivating insights with Raj Umadas as we navigate the ever-changing cybersecurity landscape. Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

  • 00:02: Introduction and sponsorship message from Phoenix Security Limited.
  • 00:53: Welcoming Rajendra Umadas to the show; background introduction.
  • 01:25: Rajendra's journey into cybersecurity.
  • 04:12: Discussion on application security and team building.
  • 07:33: Exploring product security and its impact.
  • 13:32: Navigating the challenges of risk management and pen testing.
  • 18:00: The evolving landscape of software and hardware security.
  • 25:21: DevSecOps and the future of cybersecurity.
  • 36:01: Closing thoughts on the progression of cybersecurity and its positive outlook.
  • 38:10: Final advertisement and call to action for listeners.

Raj Umadas

  • Linkedin: https://www.linkedin.com/in/rajumadas/
  • Cyber Security and Cloud Podcast hosted by Francesco Cipollone
  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec #aspm

View Details

Will AI replace the role of product security? How do you start an application security program and write a book about it? One of the best Application Security mind Derek Fisher is with us today.

Join us on a captivating journey as Derek, a mastermind in product security and a prolific author, shares his expertise on setting up a fortified application security program. We start by unraveling the critical first steps, emphasizing the value of understanding your organization's current cybersecurity landscape and the unique risks it faces. Listen in as we discuss the significance of collaboration between security and engineering teams to pinpoint vulnerabilities and fortify our digital defenses.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

In our thought-provoking conversation, we tackle the concept of product ownership and the dynamic nature of risk assessment. Derek enlightens us on the challenges of aligning business acumen with technological realities in the context of application security. We also engage in a spirited debate about the various forms of code analysis and the significance of exploitability in the management of risk. It's a discussion that balances the technical intricacies with strategic insights, essential for anyone invested in securing their products. Shifting gears, we explore the innovative realm of 'shifting smart' in application security, moving beyond the traditional 'shift left' paradigm. Discover the benefits and limitations of integrating security tools early in the development cycle and the vital role dynamic environments play in unearthing actionable vulnerabilities. Wrapping up, we delve into the exciting and complex intersection of AI and cybersecurity, pondering the dual-edged sword of advanced technologies like generative AI. Derek offers a nuanced perspective on the future of secure coding and vulnerability management, a must-listen for anyone navigating the evolving cybersecurity landscape. Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

  • 00:02: Introduction to Cybersecurity and Cloud Podcast
  • 00:55: The Essence of Application Security Programs
  • 02:19: Journey to Authoring on Application Security
  • 02:38: Building a Robust Application Security Program
  • 03:36: Application Security: A Collaborative Effort
  • 04:22: Assessment and Direction in Application Security Programs
  • 06:52: The Role of Software Bill of Materials (SBOM) in Cybersecurity
  • 09:32: Defining a Product in the Context of Application Security
  • 13:23: Enhancing Software Security Supply Chain Visibility
  • 15:35: Understanding Product Risks and Vulnerability Management
  • 18:31: Evolving Application Security Techniques: SAST, DAST, RASP
  • 27:32: AI's Role in Application Security and Beyond
  • 25:07: Encouraging Secure Online Practices Among Young Users
  • 30:33: The Future of AI in Cybersecurity
  • 32:33: Closing Thoughts and Positive Outlook for Cybersecurity Professionals

Derek Fisher

  • Linkedin: https://www.linkedin.com/in/derek-fisher-sec-arch/
  • Application Security Program Handbook: A Guide for Software Engineers and Team Leadershttps://www.amazon.co.uk/Application-Security-Program-Handbook-Engineers/dp/163343981X
  • Cyber Security and Cloud Podcast hosted by Francesco Cipollone
  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec

View Details

Will AI replace the role of product security? This is an enlightening conversation with David Matousek exploring the intersection between automation and product security in application security.

Join us on this enlightening journey with David Matousek, as we explore the intriguing world of product security within the cybersecurity realm. Listen in as David, with his wealth of experience transitioning from a technical developer to a product director, unveils the significance of perceiving application security as an enterprise-level product. The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

Discover how this approach not only streamlines the development process but also cultivates a customer-centric mindset towards developers, leading to a more cohesive and less cumbersome compliance environment. David's insights provide a fascinating perspective on the symbiotic relationship between security and platform teams, paving the way for a more secure and efficient path to application production. Venture further into the cybersecurity landscape as we tackle the complexities of vulnerability prioritization and the evolution of network security. Our discussion with David delves into the nuanced balance of automated and manual processes in identifying and managing security risks, highlighting the irreplaceable value of human expertise amidst the rise of machine learning and AI. Emphasizing the importance of multi-faceted developer skills, including communication and collaboration, we shed light on how these abilities can significantly enhance an organization's security posture. So, gear up for a session that not only broadens your understanding of cybersecurity but also inspires professional growth in this dynamic field. Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

  • 00:02: Introduction to Cybersecurity and Cloud Podcast
  • 00:57: Unraveling Product vs. Application Concepts
  • 01:43: David Matousek's Journey in Cybersecurity
  • 04:04: Transition to Product Security
  • 07:02: Embedding Security in Development Tools
  • 09:14: Evolution from Application to Product Security
  • 11:53: Managing Vulnerabilities at Scale
  • 14:43: Promoting a Culture of Shareable Code
  • 17:00: Balancing Automation and Manual Security Practices
  • 19:51: Dependency Management and Security Context
  • 22:53: Communicating Cybersecurity Value to Business

David Matousek

  • Linkedin: https://www.linkedin.com/in/davidmatousek/
  • Cyber Security and Cloud Podcast hosted by Francesco Cipollone
  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #productsecurity #prodsec

View Details

This is an enlightening conversation with Michael Smith exploring the intersection between vulnerabilities, DDoS and WAF technologies.

Join us as we reconvene with cybersecurity virtuoso Michael Smith, Field CTO at Verkara, for a rerecording further to explore the fascinating intersection of cybersecurity and cloud technology. Listen in as Michael brings his wealth of experience from military intelligence to web application development to the table, shedding light on how engineering and integration teams navigate regulations and government sector compliance.The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

Our conversation ventures into the complexities of application security and the strategic utilization of vulnerabilities. Venture into the murky waters of cyberattacks with us as we discuss how vulnerabilities can be harnessed for DDoS attacks, causing chaos at both the network and application layers. Hear about Phoenix Security Limited's role in software security and how unvalidated pagination can be exploited to strain databases and servers. We wrap up this segment by contrasting the precision of these attacks with broader network-level DDoS strategies, offering insight into crafting robust cybersecurity defenses.Cap off this episode with a crucial discussion on the ethical dimensions of technology. Discover the challenges of differentiating between benign and malicious bot activity, and how technologies like domain fronting have dual purposes. We stress the importance of vigilance and responsibility in the tech sphere, where the same tools can secure or compromise systems. Remember to stay engaged with the content by checking your logs for anomalies and sharing your thoughts for a chance to win an Amazon gift card. Michael's insights are a reminder of the persistent evolution and nuanced nature of cybersecurity in our interconnected world. Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

  • 00:02: Introduction to Cybersecurity and Cloud Podcast
  • 00:53: Host and Guest Introduction
  • 01:40: Michael Smith's Journey in Cybersecurity
  • 03:23: Shift Towards Security
  • 04:22: The Evolution of Cybersecurity Roles
  • 06:58: Challenges in IoT and Hardware Security
  • 08:22: Insights from Akamai and Handling Major Incidents
  • 09:58: The Evolution of Cybersecurity Threats
  • 11:35: The Current State of Cybersecurity
  • 14:49: The Future of Cybersecurity and Emerging Threats
  • 17:22: Leveraging Vulnerabilities for DDoS Attacks
  • 22:51: Addressing Sophisticated Cybersecurity Threats
  • 26:27: Advanced Cybersecurity Techniques and Challenges
  • 29:00: The Importance of Collaboration in Cybersecurity
  • 33:58: Closing Thoughts and Positive Takeaways
  • 39:01: Outro and Acknowledgments
  • Micahel Smith
  • Linkedin: https://www.linkedin.com/in/rybolov/
  • Cyber Security and Cloud Podcast hosted by Francesco Cipollone
  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #appsec #waf

View Details

This is an enlighting conversation with Jay Jacobs - Exploring the Future of Vulnerability Management and Data Science

Unlock the secrets of cybersecurity's intricate dance with data science as I, Francesco Cipollone, sit down with tech wizard J Jacobs, co-founder of Cyanthia. Prepare to be captivated by J's inspiring tech odyssey, from his youthful fascination with computing to his trailblazing efforts in quantifying cyber risk. We navigate his professional voyage, spanning IT, pen testing and cryptography, revealing how his deep dive into data science has revolutionized our approach to cyber threats. J also imparts his wisdom on the crucial role of statistics and key management in cryptography, offering priceless insights for anyone invested in fortifying their digital defenses.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

The journey of vulnerability assessment tools takes center stage as I recount the sophisticated evolution of the Exploit Prediction Scoring System (EPSS). From its humble beginnings as a logistic regression to becoming a powerful API, EPSS serves as a beacon for security professionals looking to quantify the once nebulous concept of risk. The discussion illuminates the delicate dance between utility and data privacy, the quest for a universal risk score, and the aspirational future of EPSS, incorporating additional variables to refine its predictive precision. Finally, J and I tackle the real-world implications of vulnerability management through the lens of EPSS.

We dissect the interplay between EPSS scores and CVSS ratings, using the Log4Shell incident to emphasize the critical need for broader threat intelligence. By acknowledging the system's limitations and the nuances within open-source vulnerability analysis, we champion the importance of narrative in data interpretation. With a call to action, we invite the cybersecurity community to join forces, enhancing our collective defense through dialogue and open-source innovation.

Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

(03:41 - 04:47) Exploring Cryptography and Managing Key Security (66 Seconds)(07:41 - 08:52) Epss (71 Seconds)(11:46 - 12:56) The Beauty of EPSS and Application Security Angle (70 Seconds)(18:02 - 19:16) Exploring EPSS Scores and Vulnerabilities (74 Seconds)(25:27 - 27:09) EPSS and Its Challenges in AppSec (102 Seconds)(31:03 - 32:04) Improving Scanning Tools and Analyzing Vulnerabilities (62 Seconds)* Jay Jacobs * Linkedin: https://www.linkedin.com/in/jayjacobs1/ * Twitter: https://twitter.com/jayjacobs * Cyentia: https://twitter.com/cyentiainst * EPSS: https://www.first.org/epss/#:~:text=The%20Exploit%20Prediction%20Scoring%20System,be%20exploited%20in%20the%20wild. * YL Profile: https://www.ylventures.com/people/caleb-sima/ * Cyber Security and Cloud Podcast hosted by Francesco Cipollone * Twitter @FrankSEC42 * Linkedin: linkedin.com/in/fracipo * #CSCP #cybermentoringmonday cybercloudpodcast.com * Social Media Links
Follow us on social media to get the latest episodes: * Website: http://www.cybercloudpodcast.com/ * Linkedin: https://www.linkedin.com/company/35703565/admin/ * Twitter: https://twitter.com/podcast_cyber * Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/ * You can listen to this podcast on your favourite player: * Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 * Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #ai, #cloud, #appsec

View Details

This is an enlighting conversation with Caleb Sima a returning guest on the podcast - Bridging Offense and Defense in Cybersecurity and AI Promise for the Future.

Join us for the return of an esteemed guest, Caleb, for an engaging conversation with cybersecurity veteran Caleb Sima on our latest podcast episode. Caleb, known for his significant contributions to application security and executive roles in leading tech companies, shares his profound insights into the ever-changing world of cybersecurity. He highlights the importance of mastering offensive skills for effective defence, drawing on his vast experience to advocate for a mindset that aligns with understanding and countering attackers.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

This episode also delves into the critical foundations of cybersecurity, emphasizing the need for a broad spectrum of knowledge, including networking, engineering, and programming. We explore building securely, drawing insightful parallels between everyday safety mechanisms and the integrated security required in organizational infrastructures. Through this discussion, we uncover how intuitive security measures, akin to those in vehicles or smartphones like iPhones, can be mirrored in the seamless security systems within companies.

We further discuss the transformational challenges facing security professionals, evolving from defenders to builders, and the vital role of education in this paradigm shift. It's a thought-provoking exploration of proactive and resilient security approaches to enhance user experience without compromising on protection.

Tune in to this enlightening episode to equip yourself with the knowledge and insights needed to navigate the evolving landscape of cybersecurity.

01:40 - Caleb Sima: Caleb shares his extensive background in cybersecurity, beginning in the 90s and spanning various roles and accomplishments.

03:34 - Francesco Cipollone: Discussion on the evolving landscape of cybersecurity and its implications for newcomers to the field.

04:19 - Caleb Sima: Caleb's advice to newcomers in cybersecurity emphasises the importance of understanding offensive security and mastering foundational knowledge.

07:44 - Francesco Cipollone: Francesco reflects on Caleb's approach, discussing the potential biases and the importance of a foundational understanding.

08:12 - Caleb Sima: Caleb underscores the necessity of understanding attacks to identify fundamental security problems and prioritize risks.

10:50 - Caleb Sima: Insight into the relationship between effective security foundations, risk management, and compliance.

11:27 - Francesco Cipollone: A discussion on the concepts of security and safety and their interchangeability.

11:39 - Caleb Sima: Caleb's perspective on transitioning from a focus on security to a broader concept of safety.

16:21 - Caleb Sima: The importance of minimizing damage in security incidents and the need for balanced approaches in threat identification, detection, and response.

17:15 - Caleb Sima: The role of security in organizational decision-making and the importance of integrating security from project inception.

21:11 - Francesco Cipollone: Highlighting the shift in security perspectives and the importance of proactive approaches to cybersecurity.

23:04 - Caleb Sima: Caleb discusses the gaps in awareness and knowledge within security teams and the importance of prioritizing security measures.

24:15 - Caleb Sima: Exploring the role of technology in building security foundations and the potential of AI and ML in addressing security challenges.

27:59 - Francesco Cipollone: Reflections on the cultural shift and the growing emphasis on collective responsibility in security.

29:53 - Caleb Sima: Caleb's categorization of AI's role in cybersecurity, focusing on securing AI technologies and utilizing AI to solve cybersecurity challenges.

34:18 - Francesco Cipollone: Discussion on protecting data from AI systems and considerations in data usage and monetization.

36:00 - Caleb Sima: Caleb speculates on the future of data usage restrictions and their potential impact on the internet landscape.

37:13 - Caleb Sima: Caleb concludes with a positive outlook on the growth of talent and knowledge in cybersecurity and the importance of ongoing education and awareness.

  • Caleb Sima
  • Linkedin: https://www.linkedin.com/in/calebsima/
  • Twitter: https://twitter.com/csima
  • Other: https://www.nbcnews.com/id/wbna6713649
  • Blog: https://medium.com/csima/from-founder-to-ciso-my-unconventional-journey-and-the-road-ahead-2fbc262a59be
  • YL Profile: https://www.ylventures.com/people/caleb-sima/
  • Cyber Security and Cloud Podcast hosted by Francesco Cipollone
  • Twitter @FrankSEC42
  • Linkedin: linkedin.com/in/fracipo
  • CSCP #cybermentoringmonday cybercloudpodcast.com

  • Social Media Links
    Follow us on social media to get the latest episodes:
  • Website: http://www.cybercloudpodcast.com/
  • Linkedin: https://www.linkedin.com/company/35703565/admin/
  • Twitter: https://twitter.com/podcast_cyber
  • Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/
  • You can listen to this podcast on your favourite player:
  • Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463
  • Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Cybersecurity, #ai, #cloud, #appsec

View Details

Overcoming the Cybersecurity Talent Shortage: Innovation, Culture, and Self-Care with Jitendra AroraJoin us for a transformative discussion with Jitendra Arora, the non-South Europe CISO at Deloitte, as we unravel the narrative around the talent shortage in cybersecurity. Jitendra brings a fresh perspective that emphasizes the need for creativity and open-mindedness in talent sourcing. We dissect the "buy versus build" model, where he advocates for nurturing and developing skills in individuals from diverse backgrounds, not just hiring seasoned professionals.The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

Our second chapter addresses the art of fostering a positive organizational culture. We share experiences and insights about the daily efforts required to build a values-based culture, especially during challenging times like the pandemic. Our conversation evolved to discuss the role of a supportive work environment in attracting and retaining talent. Lastly, we explore the essence of self-care and personal development in the high-stress world of cybersecurity. Our discourse underscores the need for balance and provides useful tips on handling stress, offering a refreshing look at life in the cybersecurity field. Tune in for a meaningful conversation that goes beyond the usual.* 00:02 - Ads and Introduction: Introduction to the podcast, sponsored by Phoenix Security Limited. * 00:59 - Host Introduction: Host Francesco Cipollone introduces the episode's focus on team and skill growth in cybersecurity. * 01:38 - Guest Introduction: Jitendra Arora discusses his cybersecurity background and industry insights. * 02:51 - Industry Challenges: Discussion about the talent shortage in cybersecurity. * 06:23 - Addressing Talent Shortage: Emphasizing innovative hiring and the value of diverse backgrounds. * 09:44 - Academia Engagement: Importance of connecting with students and teaching resilience. * 12:07 - Supportive Work Culture: Developing a nurturing work environment in cybersecurity. * 16:03 - Advertisement Break: Promotional segment for Phoenix Security Limited. * 16:44 - Talent Retention: The role of workplace culture in attracting and retaining cybersecurity talent. * 18:54 - Leader's Role: Leaders fostering a positive and supportive workplace in cybersecurity.

Jitender Arora

Linkedin: https://www.linkedin.com/in/jarora/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Cybersecurity, #TalentShortage, #TalentSourcing, #Organizational Culture, #Pandemic, #Self-Care, #Personal Development, #Leadership, Creativity, #Open-mindedness, #Buy vs Build, #Diversity, #Skills, #Dialogue, #Profession, Virtual Hallway, Feedback, #Strategic Objectives, #Purpose, Belonging, #Stress, #Emotions, Life Skills, #Mentorship, #Speaking Opportunities, #Support Structure, #Personal Balance

View Details

Get ready to embark on a captivating journey into application security with our guest, Chris Ghigliotty, Director of Security Engineering at JustWorks. A man of many talents, Chris hails from a background in teaching and writing, which lends him a unique perspective on the importance of communication within the cybersecurity industry. We promise you this isn't your regular security conversation. We are tearing down the walls of complexity, transforming intricate risk language into digestible business matters.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

As we navigate through the intricacies of building an application security program, we assure you, no stone will be left unturned. Learn how to control the narrative, comprehend your company's current state and engage with your customers in a meaningful manner. This isn't just another industry podcast; we're here to show you how to demonstrate the program's inherent value, approach investment strategically, and champion ROI as the lifeline of your security program. We've got a powerhouse of insights lined up, especially on program effectiveness, measured in terms of training developers to make security decisions.

Drawing the curtains on this episode, we shift gears to focus on the impact of developer training on security. We'll help you identify training outcomes and integrate them into your development process. Our discourse deep-dives into the value of security in products, with special attention to user experience and security features as product differentiators. Remember, folks, curiosity is the key that unlocks the door to the security industry for new generations. So, join us, and let's make security not just a necessity, but a narrative that everyone can understand and appreciate.

00:59 - Christian Ghigliotty's Introduction: Francesco introduces Christian Ghigliotty, spotlighting his expertise in application security and transformation.

01:55 - Background in Cybersecurity: Christian shares his journey into cybersecurity, culminating in his current role at JustWorks, where he oversees application security and posture management.

02:22 - Entry into Cybersecurity: Christian's unconventional path into cybersecurity highlights the diverse skill sets valuable in application security.

03:56 - Communication in Application Security: The importance of effective communication in application security, essential for explaining complex security concepts and gaining organizational buy-in.

04:55 - Overcoming Communication Challenges: Addressing the challenge of making technical application security topics accessible and understandable to non-technical stakeholders.

06:14 - Storytelling in Security: The critical role of narrative in application security to justify security measures, investments, and posture management strategies.

08:00 - Establishing an Application Security Program: Key considerations in starting an application security program, including understanding organizational needs and aligning with business strategies.

09:45 - Investment in Application Security: Long-term investment perspective in application security and posture management, emphasizing the need for measurable returns and strategic alignment with business goals.

11:22 - Measuring Program Effectiveness: The challenge of quantifying the effectiveness of application security programs and the role of developer training in enhancing security posture.

14:45 - Sponsor Message: Phoenix Security, focusing on software security and supply chain visibility.

15:27 - Developer Empowerment in Security: Strategies for empowering developers to prioritize application security in their work, highlighting the importance of business support for security initiatives.

17:00 - Building Development Team Relationships: The significance of fostering strong relationships with development teams to create a culture that values application security and good security posture.

19:24 - Tailoring Security to Teams: Customizing application security approaches to meet the unique challenges and needs of different development teams.

21:40 - Business Buy-In for Security: Exploring effective strategies to secure business buy-in for application security programs and discussing relevant metrics for measuring success.

23:05 - Product Metrics in Application Security: Using product metrics to evaluate the impact of security features on application security and posture management.

25:25 - Enhancing User Experience: Improving user experience in security measures to ensure better adherence to security protocols in application development.

27:17 - Security as a Differentiator: Discussing the potential of positioning application security as a unique selling point, enhancing customer trust and product value.

29:01 - Closing Remarks: Christian shares an optimistic outlook on the future of application security and encourages new talent to join the field.

30:14 - Contact Information: How to find more about Christian Ghigliotty's work in application security.

Christian Ghigliotty

Linkedin: https://www.linkedin.com/in/ghigliottyc

Github: https://github.com/ghigliottyc

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Christopher Russell is the CISO at tZERO Group, a Mesh Security advisor, and a NightDragon Advisor. He is currently getting a PhD in Cybersecurity with a focus on Blockchain Security at DSU. His military intel background helps him keep cool under even the most stressful work situations. In this episodes, Francesco and Chris discuss identity and security in relation to blockchain and digital currency. With decades of experience, Chris has an acute sense of risk and threat

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

0:00 Introduction

1:20 Chris’ background in military

7:40 Military VS cooperate mentality

10:08 Risk management

15:05 MFA and identity

21:00 Zero day

22:00 Social engineering and ransomeware

26:50 Mesh Security

28:48 Identity in blockchain and digital currency

31:50 Public wallets

34:00 Positive message

35:48 Connect with Chris

38:28 Outro

Christopher Russell

https://www.linkedin.com/in/christopher-russell-5a9b20a7/

Twitter @cr00ster

Github : https://github.com/cr00ster

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Steve Springett is the Director of Product Security at ServiceNow, helping 4,000+ developers build secure and resilient software. He’s a leader of multiple OWASP projects including Dependency Track, SCVS, and Cyclone DX. In this conversation, Steve and Francesco discuss the term SBOM (software bill of materials), the importance of regulations, and the state of the industry.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

0:00 Introduction

1:35 Steve’s background

2:35 State of the industry

7:00 Breach fatigue

10:00 Shift left, shift smart

13:45 How to make asset management sexy again

17:10 Threat modeling

20:00 Regulation

26:00 Security metrics

28:15 OWASP projects—SBOM platform

34:14 Final positive message

36:09 Get connected

37:20 Outro

Steve Springett

https://www.linkedin.com/in/stevespringett/

https://infosec.exchange/@stevespringett

Twitter @stevespringett

https://dependencytrack.org/

https://scvs.owasp.org/

https://cyclonedx.org/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Christophe Parisel is a Senior Cloud security architect at Société Générale. He has extensively researched risk vulnerability and native cloud security. He specializes in IaaS, PaaS, and devSecOps. Two of his major contributions to the Cloud are Azure Firewall and Azure Policy. When asked, he says he’s is optimistic about the future of Cloud security and is proud of the progress made within the last five years.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

0:00 Introduction

1:40 Christophe’s background

5:10 Cloud security research

8:40 Adoption VS security

10:07 Cloud shared responsibility model

14:52 CVSS (Common Vulnerability Scoring System)

19:00 Vulnerabilities

20:20 Environmental score

21:30 Measuring vulnerability of cloud provider

25:55 Odds of a cloud breach

29:50 Final positive message

32:10 Get connected

33:00 Outro

Christophe Parisel

https://www.linkedin.com/in/parisel/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Travis McPeak is a security generalist with over a decade of experience working at several companies including Databricks, Netflix, IBM, HP, and Symantec. He’s the Co-Founder and CEO of Resourcely, whose goal is to create a paved road to secure, efficient, and easy to manage cloud infrastructure. In this conversation, Travis shares his biggest takeaway from working at Netflix, the problem with overusing JIRA, and the importance of making security a shared responsibility between developers and security ops.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://phoenix.security/request-a-demo/ for a free 14-day licence.

0:00 Introduction

1:26 Travis’ background

2:10 View of industry

4:00 Netflix “paved road”

5:20 Lemur

8:00 Security at small orgs

11:36 Reactive security with JIRA

14:35 Measuring security

18:16 Inflection point

20:48 Demystifying the paved road

24:30 DevSecOps

30:40 Unifying the objective, shared responsibility

33:40 Resourcely— Cloud infrastructure

36:20 Get connected

37:00 Positive Message

38:27 Outro

Travis McPeak

https://www.linkedin.com/in/travismcpeak/

https://www.resourcely.io/

https://www.resourcely.io/post/guardrails-and-paved-roads

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Nathan is the manager of the application security team at Intuit Mailchimp. He has over 7 years of experience in application security working at both startups and Fortune 500 companies. In that time, Nathan has been both an engineer and a leader. His primary focus has been on building out application security programs by implementing scalable processes and efficient methodologies. Nathan holds a Master’s in Digital Forensics and CyberSecurity from John Jay College of Criminal Justice and a Bachelor’s in Music Composition from University of the Arts.

In this show, Nathan and Francesco discuss the start in application security, how to mentor new interns and bridge the skillgap and how to measure application security progress when deploying shift left methodologies in devsecops

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

2:00 - Nathan's Intro

7:30 – from music to cybersecurity and new generation

11:00 – State of application security

14:00 – Vulnerability – What is a vulnerability in software

18:00 – How do you bring in the business in appsec – Product security

12:00 - Cybersecurity technicalities - Pen-tests and regulation

16:00 - Cybersecurity and regulation in USA

19:00 - SBOM, Digital Software supply chain

20:00 – Risk for application security and business perspective

22:00 – Business categories of risk for application security

24:00 – Business criticality vs low criticality – how to talk about risk

26:00 – Prioritize work based on risk in application security

27:00 – Avoiding burnout and preventing risk – Mailchimp program of work – SPIDER

31:00 – Doing more with less in application security

33:00 – Measuring shift left effectiveness – Dentist story

37:00 – Positive message and conclusion

Nathan

Blog: https://nathancooke.com/

Linkedin: https://www.linkedin.com/in/nathancooke7/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Kevin Davis, Global CTO of AWS at Atos. Kevin has extensive experience in cloud technology, security and solutions and has a proven track record in senior roles at Cloudreach and Atos.

In this show, Kevin and Francesco discuss the move to the cloud, challenges in the cloud security pivot and how to leverage the power of the cloud for security controls.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the most important vulnerabilities and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

1.40 - Kevin Intro

3.00 - Baby Steps into the cloud

6.00 - Shared Responsibility Model

9.00 - Operational Security in the Cloud

11.00 - Traditional Security to Cloud Security

16.00 - Security Governance in Cloud

18.00 - Paradigm Shift - Segmenting units

20.00 - Cloud native Tooling and migrating from traditional to modern

23.00 - Changes in the cloud as software gotcha and pitfalls

26.00 - Consolidated technology stack & Clod environment guardrails

27.30 - Devops and job demands - what is devops in the cloud

28.00 - Security in Devops for cloud - Devsecops

29.00 - People and security - the impact of cloud transformation in cloud

33.00 - Biggest threat in the cloud, cloud security misconfiguration

35.00 - Cloud security observability, logs, AI and investigation

36.00 - Positive message

38:00 - Closing

Kevin

https://www.linkedin.com/in/relevantsoft/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Ollie Whitehouse is the founder BinaryFirefly a boutique British cyber advisory firm with a career spanning over 25 years in applied cyber attack and defence. Ollie's portfolio of advisory positions today includes science advisory positions for UK Government as a member of the Science Advisory Councils for the Home Office and Police, Industry 100 within the National Cyber Security Centre and various Non-Executive Directorships. His operational tenures include over ten and half years at NCC Group where he was Group CTO until the end of 2022, BlackBerry and Symantec. Ollie has given oral evidence to the UK Parliament Joint Committee on the National Security Strategy twice in 2017 and 2022 on matters related to cyber security.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matter most and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

2:00 - Career and dot com

3:00 - Pen-testing and philosophy

5:00 - Business and Cybersecurity and role of the cyber NED

9:00 - CISO

10:00 - Executive understanding

12:00 - Cybersecurity technicalities - Pen tests and regulation

16:00 - Cybersecurity and regulation in the USA

19:00 - SBOM, Digital Software supply chain

22:00 - Regulators, Board and how they think

26:00 - Assets, different opinions based on generation

30:00 - Non exec hands-on startups vs later stage

35:00 - policy and frameworks, and assessing, quantifying the net value of a control

40:00 - Software vs infrastructure breach why more on software

42:00 - scaling attacks with automation

46:00 - the business perspective

47:00 - Positive message

Ollie Whitehouse

https://www.linkedin.com/in/olliewhitehouse/

https://twitter.com/ollieatnowhere

https://bluepurple.binaryfirefly.com/archive

https://bluepurple.binaryfirefly.com/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links
Follow us on social media to get the latest episodes:
Website: http://www.cybercloudpodcast.com/
You can listen to this podcast on your favourite player:
Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Chris Hughes is a Proven Cloud/Cybersecurity leader with nearly 20 years of experience in the Federal and commercial industries. Chris is an active blogger, passionate about all things cyber and a published author of books like Software Transparency.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matter most and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

1:12 Introductions

4:45 regulation and federal space

6:40 Software supply chain attacks

8:40 SSDF and SBOM

11:06 Software is complex

15:00 Vulnerability to attacks, attacker mindset

17:00 Common supply chain attacks

20:00 Cloud critiques, is cloud secure?

23:00 Business Risk, Quantifications, How to measure everything,

24:00 FAIR and Quantification at scale

25:00 Method to evaluate vulnerability, CISA KEV, EPSS, How to triage

28:00 Why does the software supply chain get attention

30:00 Get connected

Chris Huges

https://www.linkedin.com/in/resilientcyber/

https://podcasts.apple.com/us/podcast/resilient-cyber/id1555928024

https://resilientcyber.substack.com/

FAIR: https://www.opengroup.org/certifications/openfair

Hot to measure anything in cyber risk: https://amzn.eu/d/hBWxJGO

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes:Website: http://www.cybercloudpodcast.com/You can listen to this podcast on your favourite player:Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Summary Transcript (auto-generated might have some typos)

Hello everyone and welcome back to the cybersecurity and cloud podcast, this is your host

Francesco and this is probably the last last episode that we do in 2022 is 29 of December 2022

we're almost on the end of the years but we managed to squeeze in a last episode with chris

Hughes and it's an absolute pleasure because we chris we've been interacting a lot of linking

teasing each other over a number of topics and we said you know it's the time to come on the

show and do a proper episode. So chris, thank you very much for coming on the show. Chris is

uh is a consultant to direct robot via and it's been in Air force previously, so it's very heavily

involved with a lot of us regulation around storm and around cybersecurity and the U. S. Has

faced a lot of change in late and today in the episode we're gonna dig in and explore this. But

before digging into the exciting topic of storm and software supply chain chris tell us a little bit

more about you, how did you start? How did you get us to the point where you are today? Yeah

definitely. I'm happy to give you some background. I start off active duty Air Force you know

prior to that I always had an interest in computers and technology but got joined the Air Force

and got put in cybersecurity and at the time I didn't really realize the opportunity. You

know you're just a young kid you know. Uh And and then like I started really taking an interest in

it because it was a fascinating career field and like I've never stopped you know I did four years in

the Air Force and then I've been a federal employee with the U. S. Government twice once with

the Navy doing cloud and deficit cops. And you know cyber security for them. And then also with

an organization known as G. S. A. The General Services Administration which probably isn't too

familiar for many. But like if you've heard of Fed ramp, I was part of the Fed ramp team

reviewing cloud services coming to the you know us federal market there as a security to me.

Um, and as you mentioned, I think we're definitely seeing like an evolution of the regulation in

this space, you know, in our, in our environment, in the public sector. You know, we've always

had things like Nist and uh, you know, risk management framework, Nist 853 and and you know,

think of Nist 871 for defense, industrial base and then see mm see that people are talking about

a lot now, thinking about, you know, not just software supply chain but supply chain risk

management in general, you're under your suppliers. That was a topic that's gotten a lot of

attention as of late and then, you know, obviously software supply chain, you know, it's not

necessarily a new topic. You know, you can date new google. Had a white paper recently,

they started like an incident from 1980 you know, for something where the United States did

something that Russia with software and it's like, wow, this issue has been around for a long

time, but it's gotten more and more attention, I think is, you know, we've seen open source

adoption kind of accelerate and go, you know, go crazy, everyone's using open source software.

Most modern applications are made of open source software and I think people are realizing like,

you know, I think prototype for example, had a study showing that in the last three years it's like

a 742% increase in software supply chain attacks. So malicious actors are paying

attention. And now I think that's making organizations regulators, you know, the industry pay

attention and try to respond to this brilliant. And then of course he moved over to cisa and kind

of has kept up that, you know, that momentum since then. So I think, you know, definitely solar

winds was kind of the watershed moment, I think from an attention perspective and then the

cyber street executive order and all the, all the activity has come after that. And as you

mentioned, like, you know, I think regulation is going to has and will continue to play a big part in

this. Like, you know, without regulation forcing the issue, suppliers are not necessarily

incentivized to provide this information that transparency and many, you know, I've been really

focused or interested in the economic factors of cyber. Many consider cyber to be a market

failure. They said, you know, regulation is required for the, for things to change. Um, and I think

it's, you know, it's hard to argue with that because if we just leave it up to the industry, they're

not going to necessarily provide this information. Why why would they, you know, just put some

additional risk or scrutiny? So, yeah, I think, I think we're definitely seeing a lot of changes And

security resolve doesn't seem like a massive cost. So if there isn't a regulation behind it, there

isn't a business justification to a ship with a bomb. I think the attack of one of the big

topic in cyber that is asset management in general. That is a huge debated and often

avoided topic in, cyber or in generally 90 is not even a cyber problem. And I think this one

kind of industry has now brought to the topic a problem that is like, what do we do with, what do

Detail (auto-generated might have some typo)

Hello everyone and welcome back to the cybersecurity and cloud podcast, this is your host Francesco and this is probably the last last episode that we do in 2022 is 29 of December 2022 we're almost on the end of the years but we managed to squeeze in a last episode with Chris Hughes and it's an absolute pleasure because we chris we've been interacting a lot of linking teasing each other over a number of topics and we said you know it's the time to come on the show and do a proper episode. So chris, thank you very much for coming on the show. Chris is uh is a consultant to direct robot via and it's been in Air force previously, so it's very heavily involved with a lot of us regulation around storm and around cybersecurity and the U. S. Has faced a lot of change in late and today in the episode we're gonna dig in and explore this. But before digging in in the exciting topic of storm and software supply chain chris tell us a little bit more about you, how did you start? How did you get us to the point where you are today? Yeah definitely. I'm happy to give you some background. I start off active duty Air Force you know prior to that I always had an interest in computers and technology but got joined the Air Force and and got put in the cybersecurity and at the time I didn't really realize the opportunity. You know you're just a young kid you know. Uh And and then like I started really taking an interest in it because it was fascinating career field and like I've never stopped you know I did four years in the Air Force and then I've been a federal employee with the U. S. Government twice once with the Navy doing cloud and deficit cops. And you know cyber security for them. And then also with an organization known as G. S. A. The General Services Administration which probably isn't too familiar for many. But like if you've heard of Fed ramp, I was part of the Fed ramp team reviewing cloud services coming to the you know us federal market there as a security to me. Uh And then you know worked at a couple different industry organizations in the D. O. D. Space, you know on the software factories and things like cloud and kubernetes and containerized environments and all those kind of things for like Space force and Air force and so on. Um and then ultimately just you know, decided to give it a chance myself and you know, co founder acquia where I'm at now with a couple of partners and you know doing cybersecurity consulting in the in the public sector but also a little bit in the commercial but definitely mostly U. S. Public sector focused and uh you know I mean outside that like you mentioned, I'm really active on linkedin. I host a show myself called Resident cyber and I'm pretty engaged with groups like cloud native Computing Foundation, Cloud Security alliance for example have contributed to several white papers and publications with them and yeah just really passionate about all things cybersecurity honestly. And there isn't a new article regulation that comes out and there is a whole competition of who can write a vlog before that and I really appreciate that because I think it is pushing everybody out to the edge to actually write even faster. Yeah there's I mean there's some awesome people out there to put out a lot of great information that I read that you know folks that you know you and I know like walter Haddock and such. So sometimes you know I enjoy writing and and for me learning like I like to read something and write about it while I'm reading it. So like if something new comes out, I like to try to quickly get an article out there and try to push other people, you know, but it's all, it's all in good fun honestly. Yeah, I think, I think it's a good, it's a good point and it's a good competition to actually write even faster and quicker, but maybe back in the day, um you know what, what made you decide to actually engage this into a full on career? You know, you started in cyber, you start going more into cyber and then, and then as a full on question, how did you saw the regulation and the industry changing? Especially in the, in the federal space of late? Yeah, I mean for me, for me initially it was, you know, just kind of happenstance, like I said, I got put into cyber, I was in the Air Force, I got out and uh you know, kind of just stuck with it just because it was easy to find a job doing what I did in the military. Um and then I saw like the economic opportunity that the career field has a great career field, you know, a lot of good job stability. It's, you know, it's very high demand for example, and I was always really interested in it and then, you know, I got married and started a family, I have four young kids and once I started having kids like, you know, my motivation to work harder to learn to grow. You know, my career just took off from that point and I've never stopped working hard since then. Um, and as you mentioned, I think we're definitely seeing like an evolution of the regulation in this space, you know, in our, in our environment, in the public sector. You know, we've always had things like Nist and uh, you know, risk management framework, Nist 853 and and you know, think of Nist 871 for defense, industrial base and then see mm see that people are talking about a lot now, thinking about, you know, not just software supply chain but supply chain risk management in general, you're under your suppliers. That was a topic that's gotten a lot of attention as of late and then, you know, obviously software supply chain, you know, it's not necessarily a new topic. You know, you can date new google. Actually had white paper recently, they started like an incident from 1980 you know, for something where the United States did something that Russia with software and it's like, wow, this issue has been around for a long time, but it's gotten more and more attention I think is, you know, we've seen open source adoption kind of accelerate and go, you know, go crazy, everyone's using open source software. Most modern applications are made of open source software and I think people are realizing like, you know, I think prototype for example, had a study showing that in the last three years it's like a 742% increase in software supply chain attacks. So malicious actors are definitely paying attention. And now I think that's making organizations regulators, you know, the industry pay attention and try to respond to this brilliant. And I think I saw as well and an almost change in that, but I saw the US taking, I mean with the change of command in caesAR, a really strong stand in the software supply chain and that's when the whole industry kind of start paying attention on O. S. S and in general on the software supply chain and start to bring with stone and the new regulations on Stone with with I think was the 22 01 or zero to that. They brought out the whole topic of vulnerability management, but not just in infrastructure, but across the software security lifecycle that really, really break the cars. Um, and, and change the paradigm on, you know, this is something that we need to pay attention now. And, and you know, when there is a regulation behind it, the whole public and private industry stopped paying attention. That's, that generated the the whole debate and topic. Um, and as you rightly say that it's not a new thing, I mean software, we've been writing software since forever, but right now we've been really paying attention to it. So what do you think was that was the kind of singularity that make everything change and us really paying attention now to solve the supply chain attacks. Yeah, I mean I think like we've talked about the momentum has been slowly growing. There's been folks like josh Corman, if you're familiar with him, who was kind of warning about this issue almost a decade ago, uh you know in the medical device community for example. But there's no arguing that, you know solar winds and the fallout from that thousands of organizations that impacted kind of like, you know, precipitated the whole follow on executive order. Uh you know things executive order on cybersecurity, which had an entire section section four dedicated software supply chain security. Uh And then out of that came a whole slew of activity where you had organizations like nice producing a new version of S. S. D. F. To secure software development framework O. M. B. Office of management and Budget. Now kind of dictating that all suppliers selling software to the federal government start to attest to align with S. S. D. F. Providing things like S. Bombs. And then you had, you know organizations like N. T. I. A. Where you had dr alan Freeman and folks, you know, working on these s bomb working groups, you know, two or three years ago uh you know building that interest, building that maturity around S bombs with their working groups with industry. And then of course he moved over to cisa and kind of has kept up that, you know, that momentum since then. So I think, you know, definitely solar winds was kind of the watershed moment, I think from an attention perspective and then the cyber street executive order and all the, all the activity has come come after that. And as you mentioned, like, you know, I think regulation is gonna has and will continue to play a big part in this. Like, you know, without regulation forcing the issue, suppliers are not necessarily incentivized to provide this information that transparency and many, you know, I've been really focused or interested in the economic factors of cyber. Many consider cyber to be a market failure. They said, you know, regulation is required for the, for things to change. Um, and I think it's, you know, it's hard to argue with that because if we just leave it up to the industry, they're not going to necessarily provide this information. Why why would they, you know, just put some additional risk or scrutiny. So, yeah, I think, I think we're definitely seeing a lot of changes And security resolve doesn't seem as a massive cost. So if there isn't a regulation behind it, there isn't a business justification to a ship with a bomb in particular. I think attack of one of the big topic in cyber that is the asset management in general. That is a huge debated and often avoided topic in, in cyber or in generally 90 is not even a cyber problem. And I think this bone kind of industry has now brought to the topic a problem that is like, what do we do with, what do we do with this asset and you know, asset of asset and who used those assets? So I think it has opened the Pandora box around asset management in the supply chain and known what's your thought around it? You know, I think you're spot on, like, you know, I've been writing and talking about this recently and just digging in and reading reading a lot about it, looking back across my own career, you know, uh, asset inventory has been a best practice for a long time. You think of black sands, critical controls, critical controls, hardware, software, asset inventory has been around for a long time and we've always sucked at it and it's always been difficult, you know, and then you bring in like, you know, the modern environment with the open source software, you know, you have managed service providers, cloud service providers, you know, software delivered as sas you know, software is increasingly complex and most modern environments and uh, you know, you look at like S bomb as you mentioned now, you kind of open that Pandora's box of, you know, it's not just like one app, it's all these components that are involved in the app and then you have all your dependencies and your transitive dependencies and it just, you know, it's a it's a very complicated issue. Yeah, we and we kind of just had been burying our head in the sand or ignoring it and pretending it didn't exist and now, you know that the light is on the issue and there's no ignoring it now and organizations are really starting to try to grapple with like, okay, how do we how do we get our hands around this? How do we understand like what our software supply chain is our components that we're using if we're a supplier, you know, what are we using our software for consumer, what's in the software that we're consuming? What are the vulnerabilities associated with that? So it's kind of open that Pandora's box like you said. Yeah, I totally agree. And I think after this bomb, there will be a whole, like you've wrote a really very important article about the SARS platform and this bowman who depend on on the dependency that is kind of on the topic as well of softer supply chain but on on chaining fundamentally talk party supply chain, there is there's a whole debate of who depends on what from a software perspective, but in general, and I think going forward is even gonna be more because of being more attack around them. What do you, what's your thought about why the Attackers focused on more on the softer side of things rather than in the infrastructure didn't get better at infrastructure and defending infrastructure assets and or have been been ignoring completely the softer aspect. Yeah, it's actually uh it's a very hotly discussed and debated topic, you know, there have been some claims, you know, even by organizations like O N D and I, which is the office Director of, what is the Director of National Intelligence in the United States, for example. You know, they kind of stated that, you know, organizations as organizations get better at doing the basics, the fundamentals, you know, Attackers have gone upstream for example, but then again, if you look at the headlines, you know, we still have fishing, we still have, you know, lack of M. F. A. So we're still very bad the fundamentals as an industry it seems. But if you look at it from the attacker's perspective, like, you know, they can target you as an individual organization or they can target your supplier and have a casket across hundreds, thousands of consumers downstream, uh and they may do that indiscriminately just, you know, whoever we get, we get whoever the consumers are, or they may look targeted, li like say solar winds and say who's using that. Okay, great, we want to get to them, let's let's target the supplier and then have that downstream impact, you know, on to the consumers downstream that we know are using them, I think it's kind of like uh you know, it's just an efficiency thing, you know, if they can see that it's way more efficient to target a supplier and have that cascading impact across the industry thousands, you know, of, of consumers versus targeting a single organization. So it's just an efficiency thing, an economy of scale thing from a malicious actors perspective. And then also I think they've realized like as an industry, we just have really poor supply chain risk management practices and so why not take advantage of it? You know, they're always looking for the most efficient way to carry out their goals, you know, so they just kind of have taken advantage of that reality. And I think you brought up a topic that really fascinated me that nowadays, attacker and and individual group works as a business. So they look at the unit of economics and what the smallest number of, of lines of code that can produce, They're gonna hit the majority of the masses. And I think they talk y more than blue team does. Yeah, no, I mean, your, your your spot on, like the, you know, malicious actors are organized, cybercrime is becoming very mature. You know, it's, it's a massive industry that generates a lot of revenue for, for, you know, like malicious actors around the world. You know, whether it's organized nation states doing it for purposes like that or just, you know, crime groups doing it to make revenue and profits. Um and as you said like they're gonna look for the most efficient way to do that, you know, you know, for all the hype of you know uh you know, things like uh advanced quantum resistant, you know, encryption for example like those kind of things like you know yes that exists, but they're gonna look for a more efficient like you know, they don't have M. F. A. Or they have like a poor password, you know, hygiene for example, they didn't match, they didn't patch known vulnerable software that has a patch available for like four years now, you know, like just take advantage of the most efficient thing they can um you know, it's just easier and makes more sense for them. This episode is brought to you by the generosity of phoenix security limited phoenix helps startups and enterprises solve complex software security, supply chain visibility by leveraging the power of correlation and contextual ization phoenix platform connects to your repositories, scanners and cloud correlates all the information and provide it's you with a prioritized list of vulnerabilities that need to be addressed. First discover how phoenix security helps ISOS and developers remove friction and maximize the use of deV sec ops professionals at phoenix dot security phoenix security correlate contextualize and act on risk with one click No and I totally agree and I think I was reading the other day, an article about the fact that 76% of ransomware is leveraging vulnerability of more than two years old? So it's it's not like zero day is not as quantum encryption breaking. I mean it was a cool topic to discuss about but it's like again attacking on the basics and I think Maybe on on the topic that you brought, we haven't been paying a lot of attention on software supply chain or in general software security and if you consider even always, always been around just 20 years. So we haven't had any standards or any kind of way to agree among us as an industry on what software is. And then on the flip side we had a lot of c so that comes from traditional, you know, fouling and securing service or software wasn't really their thing or maybe in their agenda, you know how you grow structure, the way how you structure your security strategy and your cybersecurity strategy, what do you think about that? No, I think you're you're spot on. And and you know, I actually talked to marker fi you know from the foundation and he talked about how long they've been around but how many problems we still have as an industry at the basic level. Um and then you talked about, you know like that, I think software supply can actually present something unique. You talked about like it's been two years, you know, two year old vulnerabilities, that sectors taking advantage of. Another unique thing about software supply chain attacks is like, you know, how long have we heard just patch? You gotta patch right. What happens when the patch is actually that the attack vector is poisonous? So now you're like finding the best practice that could compromise you. So that's a very difficult dichotomy there if your suppliers patches compromised. Um, and as you said, like, you know, coming from different backgrounds depending on the organization, you know, the city. So the industry that they're in, you know, the focus on software supply chain may not be there. They may be looking at security from a different angle around, you know when it comes to like you said software verse traditional security, you know this this modern ecosystem that we have of a P. I. S and SAS providers and open source software consumption a lot that's new to you know, security professionals or at least organizations haven't necessarily always paid attention to that stuff. But it's rapidly growing. The industry is changing so much so fast that you know, a lot of these things are just simply new. We haven't matured as an industry to address them quite yet. Right? And I think you share you share the attack surface the other day of software supply chain and if you compare that to mother an attack, those are completely two total different way to attack. If you better to attack fundamentally organization. So softer supply chain attacks are totally new breed and methodology and technique. I think if you come from an infrastructure, you you struggle to get ahead of the curve and and understand how a library has the same name of another library co fundamentally match or be a vulnerable to your organization versus, you know, you have a vulnerable service, a lot of security, traditional security for relate to the vulnerable server, They don't relate to a repository somewhere or an account takeover or things like that. Yeah, I think you're you're raising interesting point. I've been talking a little bit about it's like, you know, we see the big push for zero trust for example, but if you look at zero trust, at least how it's typically discussed, it's very network centric architecture centric to the organization. You know, our endpoints are authentication, you know, all those kind of things about the architecture, uh, and you may be securing all those things and doing, you know, doing those things right. And then look at like open source software consumption and you're just voluntarily pull things in that you have no understanding of the pedigree, the provenance who contributed to it. You know, if it's secure or not, if it has vulnerabilities, so you may be doing all these things right from an architectural perspective and then you just voluntarily pulling things in with, you know, you're just implicitly trusting things when you think about software supply chain, which is kind of anti pattern for zero trust. Um, so yeah, so it's a new paradigm in a way of thinking about things that we just historically haven't done as an industry. No I agree. And I think maybe back in the back in the podcast where we discussed with walter on are we still silent as an industry to think where you run software and what and how you build software. So you still have the debate between software security folks that things in a specific way and infrastructural cloud security folks. I see things in a complete way. So are we still looking at software in a compartmentalized way versus full stack way? Yeah I think it definitely could be argued you know and I've you know I kind of like you I started off in traditional I. T. And then you got into the cloud and things like that and you know I'm not a big fan of like you'll hear arguments of cloud is less secure than on prem or cloud is more secure than on prem and this simply doesn't work like that. There's a lot of factors that play the supply, the maturity of supplier. You know for example me self hosting something is not going to be in comparison to like say git hub that's used by millions of people and has a massive organization of security expertise behind it. You know there's a lot of factors that contribute to whether something is secure now it's just it's not so black and white there's a lot of gray in their nuance in there and maybe a question for you. So what do you think is, well, as a security industry, what what do you think we're facing in the next probably couple of years? Yeah, it's a good question. We have a lot of, we have a question. Yeah, we have a lot of problems, you know, it's, it's, we're coming up on 2023 as you said, it's a prediction season and you can look around and see a lot of great predictions that, you know, a lot of these things are true or will likely be true. We have a lot of problems, but you know, looking at where we're headed, I think that we have a lot of maturing to do around how we look at the software supply chain. You know, we have great things and efforts underway. Like you talked about like S bomb, of course we have to kind of competing standards there, S P D X and cyclone dX depend, you know, we'll see how adoption of both those go, how organizations go about, you know, not just producing S bomb, but like what do I do with it now? You know, like how do I, how do I aggregate all of these and look at them across the enterprise that I have and and understand and make informed decisions around risk and procurement and acquisition, how do I better get my suppliers and understand my suppliers suppliers. So it's just a very, you know, we have a complex problem set ahead of us with a lot of things to mature around. I think as you said like it's a new new paradigm for us in a lot of ways around security and there's a lot of things that we need to figure out, mature as an industry still and then that's that's all great. But it's a very complex topics and we struggle a lot to actually bring the whole organization together along on the security journey. And now we're facing kind of a singularity where we have augmenting the complexity of what we deal with for the nature of software that is complex. How do we translate all this complexity to a business decision makers and need to decide, okay, and invest X amount to actually keep on building my software secure, keep on running my organization securely. So how do we shield the organization to the amount the sheer amount of complexities that all this has? Yeah, I like I like the word that you use, I think you use the word shield the organization. I think it's like, you know, to an extent it's kind of securities responsibility to abstract away a lot of the complexity. Like, you know, we shouldn't be expecting the border business leaders to be cybersecurity experts for example. And that's where I think, you know, think of things like risk quantification if you look at how we communicate risk, it's almost all qualitative, it's very subjective, it's based on your gut instinct and experience and it doesn't really, you know, we haven't really done a great job of mature how we communicate business risk and dollars, you know, and communications that they understand as a business uh you know, we have great books like how to measure, you know, cybersecurity risk from folks like Doug Hubbard that came out many years ago and then there's already a version two coming out. But if you look at the industry like we have fair and we have things like that, but they're not really adopted very well in many organizations are not implemented at scale that I've seen in the industry. So I think as as an organization or as an industry, in terms of cyber, we again need to mature how we communicate with the business, putting things in the business terms, you know, you you often hear about the sizzle having a seat at the table and need to speak the language of the business or the business speaks dollars and cents. So we need to, we need to put that risk in that kind of terms so that they understand it, the implications of it and can make, you know, risk informed decisions about it. We shouldn't expect them to be security experts and they're not gonna understand the software supply chain when when we as a as a profession are still getting our hands around it ourselves, you know? Right. So translating fundamentally the whole traditional problem, attack vector and vulnerability and into probability of exploitation and to impact and the probability of that impact to happen. Those are terms that fundamentally any business minded person can relate to and can understand into move risk and do something about it like mitigate risk with dollar. Yeah. Yeah, I mean you're you're using the terms that like you know, I think back to a decade ago or more when I took like C. I. S. S. P and there was a likelihood and probability of exploitation and and likelihood of occurrence and like no one ever really talks about those things for some reason in the practical world, you know like we just you know knew me and others have talked about a lot on linkedin is like, you know, we talk about CVS s based scores and so very but there's no context or nuance behind it, like is it actually exploitable? How likely is it to be exploited if there is an exploit available? What's the maturity of the exploit is a proof of concept, you know, is it is it known to be exploited if you look at like resources like cisa has their known exploited vulnerability list for example or you have things like E P S s starting to grow and mature, you know to see what's the probability that this vulnerable will be exploited and then understand like organizationally what kind of factors do we have in place to mitigate the risk, you know what's our environment set up our our configurations in place that may make this vulnerability exploitable or not even exploitable and totally irrelevant for us now. So those are things that we need to really get down to the bottom of. But that all takes a lot of time, energy and effort to get you know kind of flush those details out. So it's a it's a tough challenge. No I totally agree. And you know that's that's my pet peeve. That's that's the thing that I talk about because I've been I've been in finance organization for long and that's that's all they want to talk about you know raise quantification, investing X. Amount of money to actually explore X. Amount of opportunity and you know business people don't talk vulnerability, don't talk cyber, they talk money and money against money. So I think I've seen the paradigm shift a lot around context realization, cyber risk quantification but I still haven't seen I've seen a lot of talk about it but I've seen a struggling adoption. What do you think? Yeah no I mean that's actually my experience as well as like I said like there's you know great great material out there and cyber risk quantification, we need to speak the language of the business. You know they have things like fair and the risk institute and other things like that. You know when we hear probability like E. P. S. S and so on and and putting things in the business term and quantifying it to dollars and cents. But as an industry, I I haven't seen that at scale in any large organization. Uh at least in my personal experience, you know that I've run into in the public or private sector quite yet. You know, some people have had pilot programs or efforts to try to do that, but I haven't really seen it done at scale quite yet. And I think it's uh it's got to be a hill that we climb if we're gonna move past, you know, being siloed and being part of the business, the part of the leadership team communicating in business terms and understand how we can, you know, communicate with our peers, we need regulation around it. Yeah, exactly. Maybe that's another factor that drives you know, forcing us to communicate in those terms and actually quantify things and and you know put those metrics out there because otherwise maybe we continue to go on as we have doing qualitative subjective, you know, assessments and kind of speculation. I agree chris we're coming to a close and we have a brilliant tradition in the show that is not live on a doom and gloom like we always do inside but live on a positive note. So in your opinion, how has the industry changed or what is the positive sign that that we start seeing and to leave fundamentally audience on a positive note. Yeah, I think while we've talked about a lot of the challenges and problems, you know, I think the fact that we're even talking about these is a good sign cause there's been years, like it's not as if the use of open source software or software supply chain as a concept is new. We just simply didn't address it previously as an industry. And so we're seeing a lot of momentum from groups like links, foundation, open ssf since, you know, the federal Government, the United States, we're seeing european regulations start to come out around software supply chain suppliers s bombs. So we have a lot of great momentum underway. Same thing on the cyber risk quantification. We're seeing a push for, you know, having cyber expertise in the boardroom from groups like sec, for example, I think we're moving in the right direction and and we have a lot of problems ahead of us, but that's also exciting. We have a lot of things we get to solve and tinker with and try to, you know, try to solve as an industry as professionals and that makes me interested and engaged and, you know, I hope everyone else's along on the journey and excited as I am about the opportunity. Absolutely. I've seen, I've seen the problem shift and I'm and I'm super excitable, what's after con, but if if folks want to follow more about the US set of regulation of what you talk about, where they can find more about you. Yeah, I mean for me, I'm super active as I said on linkedin, you know, just find me at chris Hughes, I think it's at resilient cyber on linkedin is my kind of guy you are l and then same thing on twitter, although I don't really use twitter too much. It's it's a little bit different than Lincoln in a different world. Um but that's that. I also have a sub stack I started a couple months ago where I talk about these topics, you know, on a weekly basis. It's resilient cyber dot substack dot com. And then I have resilient cyber the podcast as well. Um and I'm happy to connect and chat with anybody, anyone about all these topics. You know, I'm always learning myself and looking to learn from others and and pass along what I learned as I said, we're all in this together. So I'm definitely open to chat with anyone. Fantastic chris thank you so much for coming on the show and everybody, you know, there is a ton of material out there, put your organization towards adopting. I'm more mature maybe surface because it can make you more reputable and more solid even before regulation comes around because then you'll be prepared. Yeah, I mean we always talk about like just a closing note, we hear about like, you know, shifting security left, this is the opportunity to do that, wait instead of being reactive waiting for regulation to come along and then kind of encourage you to do these best practices or things that we're seeing emerge as you know, things that we should be doing, get ahead of that curve. You know, if we know we need to start quantifying cyber risk, we need to start talking about software supply chain security as an organization or business now is your opportunity to get in there and start doing those kind of things. Fantastic. Thank you very much Chris for coming on the show and everybody stay safe out there and I wish you everybody fantastic 2023.

View Details

Anshuman Bhartiya has been in application security for 14 years and is currently the Principal Security Engineer at Thirty Madison. Today with Francesco, they discuss bug bounty, how security approaches differ at big companies and startups, and the state of the industry.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matter most and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

0:00 Introductions

2:37 State of industry

6:40 Big companies VS start ups

9:36 Anshuman’s blog

16:39 Mindset

17:34 Approach to security testing

24:30 Success story, bug bounty

36:00 Get connected

37:05 Outro

Anshuman Bhartiya

https://www.anshumanbhartiya.com/

https://www.linkedin.com/in/anshumanbhartiya/

Twitter @Anshuman_BH

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes:Website: http://www.cybercloudpodcast.com/You can listen to this podcast on your favourite player:Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Alex Sidorenko is an experienced risk manager, the host of Risk Awareness Week, and runs a popular blog and Youtube channel called “Risk Academy.” In 2021, Alex was named the Risk Manager of the Year by FERMA for helping save 13 million dollars in insurance premiums. Today, he breaks down the three layers of risk management— basic, standardized, and advanced. He explains that cybersecurity is still at the basic level because industry professionals haven't figured out how to quantify uncertainty to calculate risk and save money.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matter most and reduce your exposure to modern attacks. See it for yourself. Go to https://www.phoenix.security for a free 14-day licence.

0:00 Introductions

3:50 View on risk

6:36 Science of risk management

12:44 NASA study

14:18 three layers risk management—basic, standardized, advanced

18:15 Generators VS users

22:40 Cybersecurity insurance

30:10 Risk Awareness Week

35:30 Environmental risk

38:41 How to Measure Anything in Cybersecurity

43:20 Capture data

45:56 Final positive message

51:00 Outro

Alex Sidorenko

https://2022.riskawarenessweek.com/

https://linkedin.com/in/alexsidorenko

https://risk-academy.ru

https://riskacademy.blog/

https://www.youtube.com/channel/UCWE0eYucrQBo1SwKOjbkkSQ

Twitter

@alexei_sid

Books Mentioned

Superforecasting: The Art and Science of Prediction by Philip E. Tetlock

How to Measure Anything in Cybersecurity by Douglas Hubbard

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes:Website: http://www.cybercloudpodcast.com/You can listen to this podcast on your favourite player:Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Lester Chng is a Veteran who transferred his war gaming military skills to the cooperate world. After being a Naval Combat Officer with the Singapore Navy for twelve years, he runs security exercise programs for a North American financial institution. Lester prepares high-level executives for worst-case scenario security crises. He explains that exercises help buy time, space, and brain processing power during a crisis.

The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matters most and reduce your exposure to modern attacks. See it for yourself go to https://www.phoenix.security for a free 14 day licence

0:00 Introductions

0:28 Military background and current role

2:48 Simulation exercises

6:32 Involving leaders in security

9:04 Ransom 9:50 Advantages of military skills

14:15 A-ha moments

17:08 Damage control

19:00 Structuring exercise

23:30 Internal investments

26:55 Final positive message

31:00 Outro

Lester Chng

https://www.linkedin.com/in/lesterchng/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes:Website: http://www.cybercloudpodcast.com/You can listen to this podcast on your favourite player:Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Amanda Alvarez is the Senior DevSecOps Engineer at Trace3. Francesco and Amanda met online in a Meetup group called “Let’s Talk Software Security!” Today they discuss building an application security program, managing technical debt, and Amanda’s advice for avoiding burnout as a security professional.

The episode is brought to you by Phoenix Security Cloud; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matters most and reduce your exposure to modern attacks

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

3:24 State of Industry

4:00 Cloud adoption

6:57 Vulnerability mangement

9:44 AppSec, CloudSec, patch management

12:17 Asset and vulnerability management

19:52 Feedback loop

23:15 Company polities

28:40 Support from leadership

30:30 Positive message

33:30 Get connected

34:40 Outro

Amanda Alvarez

linkedin.com/in/amanda-alvarez-88759ba1

Let’s Talk Software Security!

https://www.meetup.com/lets-talk-software-security/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

Linkedin: linkedin.com/in/fracipo

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes:Website: http://www.cybercloudpodcast.com/You can listen to this podcast on your favourite player:Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Larry Maccherone is a Dev[Sec]Ops Transformation Architect at Contrast Security to create a wave of DevSecOps cultural transformation in software development and cybersecurity communities. He previously worked for five years at Comcast, leading their DevSecOps Transformation initiative. When it comes to software, Larry says security and quality are synonymous. He shares his tips and tricks for getting everyone, especially leadership, committed to security.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform; you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

1:26 Software entrepreneurship

4:18 State of the industry

8:20 Security at software startups

9:35 Work at Comcast

11:30 Control and measuring

17:15 SLA’s

22:26 Management involvement

30:18 Key takeaways— mindst

35:50 Final positive message

38:28 Outro

Larry Maccherone

https://www.linkedin.com/in/larrymaccherone/

https://www.transformation.dev/

https://www.contrastsecurity.com/

Twitter @LMaccherone

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Frank Kim is a security consultant, a startup advisor and investor, and a Fellow and Curriculum Director at SANS Institute. He’s been writing curriculum and teaching for SANS for 15 years, sculpting the next generation of CISO leaders and cloud security experts. Today on the podcast, he shares his thoughts on the industry, the gate vs guardrail mentality, and tips for public speaking.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform; you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

2:00 Early career as developer

4:04 Teaching and public speaking

7:50 State of industry

9:58 Rise of cloud and security

11:35 New generation of cyber professionals

13:46 SANS Courses

16:04 Automation and human risks

18:50 Leadership training

21:54 Blueprints for organizations

24:10 Zero trust

26:25 Advice to CISOs

28:55 Prioritize vulnerabilities

34:40 Gates VS guardrails

37:40 Steve Katz

39:40 Final positive message

41:16 Outro

Frank Kim

https://www.linkedin.com/in/frank-kim/

https://www.sans.org/profiles/frank-kim/

https://www.frankkim.net

Twitter

@fykim

Mentioned

Steve Katz https://www.securityweek.com/ciso-conversations-steve-katz-worlds-first-ciso

SANS Institue https://www.sans.org

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Dustin Lehr started his software engineer career, which piqued his interest in cyber security. He is now the Sr. Director of Platform Security at Fivetran and an innovative cyber security leader online, dedicated to bettering the industry. In this podcast, he discusses how companies can build their security teams with new talent that doesn’t have traditional and technical backgrounds. They also discuss the cost of bad security, relationship building, and security championship programs.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform; you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

1:28 Early career as a software engineer and DOD

3:12 Quality and security

4:56 State of Industry

7:20 Training and mentoring new talent

12:06 Programs and non-profits growing talent

15:30 Utilizing talent

19:56 Background in psychology and human behaviour

24:40 Security teams must provide value

26:34 Relationship building

28:25 Security tests

31:50 Cost of bad security

36:06 Helping startups

39:50 Final Positive Message

42:36 Outro

Dustin Lehr

https://www.linkedin.com/in/dustinlehr/

Twitter @DustinLehr1

"Let’s Talk Software Security!” on meetup.com

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Stephanie Dannan is an application security all rounder, and the Head of Application Security at Markel. She is a shining example of someone getting into Cyber Security without direct experience in the field and without a robust technical understanding of application development. Her background is in behavioural health, and she got a master's degree in professional counselling. In this episode, Stephanie shares valuable advice for anyone considering a career in cyber security.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform, you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

2:40 Unusual journey into cyber security

6:30 Intro to application security

8:30 State of the industry, not enough entry level positions

11:20 Communication with developers

17:44 Technical language barrier, technical or not

20:46 Advise for getting into field

25:14 Funny password story

27:14 Discussing risk

32:22 Final positive message

34:42 Connect with Stephanie

35:50 Outro

Stephanie Dannan

https://www.linkedin.com/in/stephaniedannan/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Brook Schoenfield is an Elder AppSec Diplomat, the author of seven books about software security and AppSec, a researcher, the builder and leader of four AppSec programs at major tech companies, and a Master Security Architect for consultancies. Brook talks about his long career path, concerns and hopes for the industry, and the importance of threat modelling. There are 27-28 million programmers on Earth, but Brook fears that only a million work in security.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix Security Cloud Platform, you can make vulnerability management for software and cloud SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com Get access today: https://appsecphoenix.com/demo

0:00 Introductions

4:00 27-28 mil programmers need for security

6:30 No silver bullet in software security

8:55 Brook’s career path into security

13:10 Bugs aren’t going anywhere

15:00 Next generation of InfoSec

21:06 Threat modelling, dynamic risk assessment

26:05 Story of threat modelling

28:06 Threat modelling tools

29:40 Beyond functionality, malicious attackers

32:30 Communicating with management

37:50 Tipping point, integrity

41:56 Final positive message

47:33 Outro

Brook Schoenfield

Linkedin: https://linkedin.com/in/brookschoenfield

https://brookschoenfield.com

Twitter @BrkSchoenfield

Mentioned

https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Linkedin: https://linkedin.com/in/fracipo

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Walter Haydock was a Military Officer and worked on Capitol Hill investigating the Department of Homeland Security before going to business school and eventually getting into cybersecurity. Nowadays, he builds software startup security programs to accelerate sales and renewals. He also runs a blog about the industry and is a Fellow at the Center for Security and Emerging Technology. On the podcast with Francesco, they discuss vulnerability and asset management, tools for security triage, and the future of cybersecurity.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform, you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com to get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introductions

2:11 Starting in cybersecurity

4:45 Background in government/military

7:30 Crisis management

8:55 4 techniques of risk management

10:40 Vulnerability management

15:30 Communicate risk to leaders

18:30 Are we headed in the right direction

18:50 Exploit Prediction Scoring System (EPSS)

22:22 Tools for triage

26:00 Asset management

28:46 New generation of security professionals

32:00 Qualitative VS Quantitative approach to risk

37:25 Calculating risk 38:16 Three pieces of advice

41:20 Closing words and get connected

42:55 Outro

Walter Haydock

https://www.linkedin.com/in/walter-haydock/

https://haydock.substack.com

Twitter @Walter_Haydock

Mentioned

Exploit Prediction Scoring System (EPSS)

mend.io

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Jonathan Slater is one of three Co-founders at Capslock, a cyber security education start-up tackling the cybersecurity skills gap and helping adults re-skill. CAPSLOCK has raised over £1m pre-seed funding and re-skilled over 200 UK adults in cyber security in 2021.

Jonathan's previous career as a recruiter made him realise there was a gap in the market and he sat down with the other two female co-founders and started capslock.

To note capslock is one of the rare startups, luckily more and more common, that is made for more than 50% by a female cofounder.

The episode is brought to you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Capslock Team

0.00 Introduction

0.35 Jonathan’s background

1.04 Welcome Jonathan

3.30 The state of the industry

6.30 Education catch up

7.35 The importance of soft skills

10.05 Gender diversity and unconscious bias

16.36 Measuring potential

18.40 Team based learning/diversity of thought

23.00 The curriculum

26.15 Cyber – the multidisciplinary field

27.35 Avoiding career redundancy

29.15 Start-up life

30.24 Working remotely

31.08 Maintaining good mental health

32.48 Positive message

33.50 Conclusion

Jonathan Slater

https://www.linkedin.com/company/capslockuk https://www.facebook.com/CAPSLOCKCyber/ @CAPSLOCKcyber for IG + Twitter

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Liran Tal is a Developer, Full stack, who joined forces with security professionals to fight the good battle. Github Star, Published author, DevRel and wearer of Yoda hat (hear more in the podcast)

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0.00 Introduction

0.38 LiRan’s background

1.23 Welcome LiRan

3.10 What’s with the hat?

4.15 Getting involved in the industry/ stumbling across cyber security

6.33 Cyber security is a mindset

7.20 Open source security

10.22 How organisations see through a sea of data

13.16 Infrastructure risk

14.18 The responsibility of a developer

18.41 The true core of DevSecOps – the speed of development

21.06 Risk tolerance/Investing in security

22.58 Quantifying risk

25.28 Security is a must

27.00 A systematic approach to security

30.30 Auto-remediation vs. Manual assessment

34.01 Positive message

35.10 The Big Fix

36.00 Connect with LiRan

36.23 Conclusion

Tinesh Chayya

https://www.linkedin.com/in/talliran/

https://twitter.com/liran_tal

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Tinesh Chhaya is a cybersecurity specialist, a veteran in the industry and CEO of Decipher Cyber - Jenny. Tinesh has 15 years of successful Chief Revenue Officer/cyber corporate and 5 years of start-up entrepreneurial cyber experience. He has built and exited 2 start-ups and currently sits on the board as an advisor to startups within Cyber, EdTech, Software Development and Social Tech.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0.00 Introduction

0.41 Tinesh’s background

1.39 Welcome Tinesh

2.04 Tinesh’s view on the market

3.10 Cyber security start-ups

5.22 The hot-bed of cyber investment

5.48 4 main areas of cyber searched for

9.55 Differences across the world

12.50 Partnering up with big names

21.34 The mentorship group

22.03 The absence of an accelerator

23.05 Strong community

25.37 The mental struggle

32.08 Failure and resiliency

33.19 Support mechanisms (the importance of a strong team)

35.20 Celebrating successes and failures

36.02 Positive message

37.30 Thank you

37.35 Connect with Tinesh

38.34 Conclusion

Tinesh Chayya

https://www.linkedin.com/in/tinesh-chhaya-07623097/

https://deciphercyber.com/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Karissa Breen is Cyber Communications Specialist, Security Investigative Journalist, start-up advisor, entrepreneur, and podcast host based in Sydney. She quickly rose up in the cyber field getting promoted as a Cyber Reporting Analyst, then Pen Testing Engagement Lead then started her own company. She says that better marketing and communication skills would improve many issues in the field. They discuss diversity, women in cyber, soft skills, and how the industry is rapidly changing.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:28 Karissa’s background

6:50 Promotions and rising up the ranks

8:46 Creating own company

9:50 Communicating technical terms

12:00 Lightbulb moment

16:05 Chaining role of security

17:50 Advise developing soft skills

20:27 Marketing

23:20 Women in cyber

29:10 Job requirements and diversity

33:40 Positive message

35:15 Connect with Karissa

36:09 Outro

Chris Foulon

Twitter @iamkarissabreen

linkedin.com/in/karissabreen

https://karissabreen.com

Podcast— KBKAST

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Christophe Foulon is a cyber security practitioner, career coach, speaker, and currently the Sr Manager Cyber Security Consultant at (Undisclosed) and F10 Fintech. He is the co-host of “Breaking into Cybersecurity,” a podcast that encourages people from diverse backgrounds to consider a career in security. He volunteers with two non-profits, “Boots to Books” and “The Whole Cyber Human Initiative,” that benefit veterans and lessen the talent shortage in cyber. Chris shares why mentoring and giving back is important to him.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:28 Chris’ background

2:33 Work with non-profits

5:02 Recruiting cyber workforce

8:20 Career possibilities in cyber

10:23 Veterans transition to a cuber career

12:20 Starting a podcast

15:50 Need to network

16:50 Advice for starting in security

19:15 Success stories

23:00 Mentoring

27:20 Positive Message

29:43 Connect with Chris

30:50 Outro

Chris Foulon

https://linkedin.com/in/christophefoulon

Twitter @chris_foulon

https://anchor.fm/breakingintocybersecurity

https://youtube.com/c/BreakingIntoCybersecurity

https://cpf-coaching.com

https://www.boots2books.com

https://www.wholecyberhumaninitiative.org

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Is a pleasure to host again our good friend Jim.

Jim Manico is an AppSec enthusiast, educator, the Manicode founder, an investor, Java Champion, and an OWASP leader. This passionate conversation revolves around the new OWASP Top 10, reference architecture, threat modelling, SMS authentication, and TLS certificates.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:28 Jim’s background

1:50 OWASP Top 10 Old and New

4:05 Secure design and threat modelling

9:55 Reference architecture

14:15 Follow through and scale

16:30 Security bugs

18:13 Authentication

24:32 JWT

27:45 TLS certificates

31:50 Zero trust

32:14 Positive Message

33:50 Connect with Jim

35:00 Outro

Jim Manico

Twitter @manicode

linkedin.com/in/jmanico manicode.com

manicode.com

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Aladdin Almubayed is the AppSec Engineering Technical Lead at Robinhood, previously a Senior Security Software Engineer at Netflix. After getting his master in Jordan, he moved to Silicon Valley to work at Yahoo. Francesco and Aladdin discuss the evolving industry, fostering positive relationships with developers, and identifying organizations’ crown jewels.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:28 Aladdin’s background

3:40 Masters in Jordan

6:50 Industry past 10 years

7:54 Micro-service architecture

9:44 Work at Netflix

11:08 Work at Robinhood

13:40 Challenges in security

16:00 Security nightmare story

19:40 Security revolution breaking point

21:30 Threat Modeling and Pen Testing

24:50 Creating positive opinion of security

28:36 Quantifying risk

31:26 Positive message

34:40 Connect with Aladdin

35:10 Outro

Aladdin Almubayed

https://www.linkedin.com/in/aladdin-mubaied/

Twitter @0xshellrider

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Glenn Wilson is a DevOps advocate, an agile security consultant, the founder of Dynaminet, the best-selling author of “DevSecOps: A leader’s guide to producing secure software without compromising flow, feedback and continuous improvement,” the co-organizer of DevSecOps London Gathering, the Co-Host of DevSecOps Overflow Podcast, and a member of OWASP. Francesco and Glenn discuss the industry's current state, security champions, risk considerations, and the importance of pen-testing.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

1:50 View of industry

6:12 Automation, support developers

9:12 Security language barrier

11:25 3 types of communication

14:06 Less reactive, more proactive

17:50 Business owns risk

20:36 Writing a book

26:34 Pen testing

28:28 Auditors and regulators

31:10 Positive Message

32:16 Connect with Glenn

33:44 Outro

Glenn Wilson

https://www.linkedin.com/in/glennwilson

Twitter @GlennDynaminet

https://dynaminet.com

Book—“DevSecOps: A Leader’s Guide to Producing Secure Software Without Compromising Flow, Feedback and Continuous Improvement”

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Naomi is on a secret mission to change the world of cyber and make it accessible to everybody!

Naomi Buckwalter is the Director of Information Security & IT at Beam Technologies and the founder and Executive Director of Cybersecurity Gatekeepers Foundation, a nonprofit dedicated to closing the demand gap in cybersecurity hiring. Originally an aspiring FBI agent, Naomi is passionate about stopping the war on cybercrime and is recruiting and training people of all skill levels to join the fight.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:46 Introducing Naomi

4:50 War on cyber crime

7:50 Small businesses

10:30 Ransomware

14:00 Principles of security

16:00 Hiring opera singer

19:47 Plane crash analogy

23:00 Mentoring

25:25 InfoSec drama and toxicity

29:20 Path to cyber

33:40 Positive message

35:00 Outro

Christopher Hodson

Twitter @ChrisHInfoSec

https://cybersecuritymatters.blog

https://www.linkedin.com/in/christopherjhodson/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is back with this brand new season 3

Vandana Verma is the Security Solutions Architect at Snyk, a Chapter Leader and Board Member of OWASP, an advocate for women and girls in AppSec, and the founder of Infosec Kids. Vandana explains why security teams need to be more empathetic, why she started the Spotlight Project and Infosec Kids, the importance of security champions, and her view on the future of security.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:47 Introducing Vandana

3:30 Overview of industry

6:12 Open source and application security

8:38 Cloud-native application security

11:50 Educate developers

14:40 Security champions

18:30 Application security posture management

20:24 Spotlight project

23:53 Infosec Kids

27:00 Infosec Diversity

28:54 Future of security

35:36 Final positive message

37:02 Outro

Vandana Verma

Twitter @InfosecVandana

https://linkedin.com/in/vandana-verma

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is back with this brand new season 3

Paddy Viswanathan is the CEO and founder of C3M. C3M Cloud Control is a cloud security platform that helps cloud and security teams continuously monitor and manage their cloud security posture. Frank and Paddy discuss risk assessment in the cloud, how to prevent breaches associated with a third party, and the overall state of the cyber security industry.

The episode is brought you by C3M. C3M Cloud Control is a cloud security platform that helps cloud and security teams continuously monitor and manage their cloud security posture. To know more go to www.c3m.io

0:47 Introducing Paddy

2:25 State of the industry

5:55 Risk and alert fatigue

10:21 Risk code

13:19 Security breaches

17:35 Access and authentication

18:50 Cloud assessment

23:24 Final Positive Message

26:15 Outro

Paddy Viswanathan

https://www.linkedin.com/in/paddyviswanathan/

https://www.c3m.io

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is back with this brand new season 3

Christopher Hodson is the CISO at Contentful, the former CISO of Tanium, the author of Cyber Risk Management, and an all around Cyber Security and DevSecOps expert. Francesco and Christopher discuss changes in the industry since COVID, whether coding should be a requirement to work in cyber security, and communicating technical security risks with executives.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:50 Introducing Chris

3:30 Changes due to COVID

7:05 Cloud capacity and security

11:40 Misconfigurations

13:50 Working cross-functionally

17:40 Shifting security approach

19:58 Communicating with executives

26:10 Burnout

28:35 Is coding a requirement

31:10 Final positive message

34:40 Connect with Chris

34:34 Outro

Christopher Hodson

Twitter @ChrisHInfoSec

https://cybersecuritymatters.blog

https://www.linkedin.com/in/christopherjhodson/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is Coming back with Season 3 in the new year!

As a teaser, we bring you the latest story on the blog...Log4j with Steve Wilson from Contrast Security

Steve Wilson is an Application Security expert development manager and currently and currently the head of product at Contrast. Steve joins the podcast to discuss the nightmare just unleashed, log4j, that has been affecting everyone around the cybersecurity industry and the reason why we are facing this other pandemic

We will return with a special launch in 2022 with some special guest

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:28 Introducing Steve

2:13 Cybersecurity Advice

3:15 Supply chain issues

8:30 Lg4J

12:47 Issue of Supply and software

19:16 What to do to avoid

23:07 Why we are getting it wrong

27:52 Final Positive Message

29:40 Outro

Steve Wilson

Twitter @virtualsteve

https://www.linkedin.com/in/wilsonsd/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Full Transcript

00:00.00 franksec Hello everyone and welcome back to another episode of the cyber security and cloud podcast today. We have a topic that probably nobody has ever spoken in the recent time that is Goingnna be obligation security vulnerability management but the whole thing that has taken. By the storm the industry that is fundamental log for js and today we have a special guest but before we crack on. Let let us start with our intro.

00:54.11 franksec All right? or right or right we are Back. So I'd like to welcome steel wilson that came we started chatting over over a Twitter over Twitter threadad around of course up for j. So I've reminded him on the show to actually chat a little bit about the topic and his particular take is been He's the chief product officer of contra security 1 product that we absolutely love and we saw that was quite well reacting on the log four j issue but also he is an early member of the Java team on the early ninety s. But before I talk through it. Let me welcome steve steve welcome on the show.

01:33.74 Steve Wilson Hey thank you Francisco for having me really looking forward to it. So.

01:37.60 franksec Brilliant and can you give our audience a little bit about your background. What brought you into side by you know how did you start the journey from the early days with java.

01:47.24 Steve Wilson Yeah, so um, I started out really early in my career back in the ninety s at Sun microsystems I was an early member of the Java development team. Um. Went on from working really around development tools developer tools for several years and then shifted my focus over to cloud and I spent a lot of time at large companies like oracle and citrix building cloud services and cloud infrastructure and really got exposed. To a lot of the security challenges that are out there in the industry and decided about a year ago that I wanted to really move into the cyber security industry from the inside and so I joined contrast a little over a year ago to head product development.

02:35.60 franksec Nice, fantastic. And and we need we need more more ally in Cyber especially over over these challenging time. But we have a tradition on the show that we give an overview on the industry of what's working. What's not working so what will be your take on on.

02:53.16 Steve Wilson Yeah, so um, with the area of the industry that we're really focused on looking at the security of applications and code. It's a really challenging environment out there I Think what we really see is that.

02:53.40 franksec What's going on.

03:11.40 Steve Wilson Over the past several years. The complexity in software out there means that the number of security vulnerabilities in a typical program is is escalating dramatically as they get larger and more complicated and really the fact is human brains have a hard time. Ah, dealing with the complexities in the number of paths and things that are through the code today and so you know really this industry around application security has developed there to create tools that ah people can use to make their applications more secure. But 1 of the big shifts going on now is really moving from a focus on standalone security teams working to audit applications sort of almost after they're done to really bringing that security mindset into development at the beginning. And really creating a new culture where um, security comes very early in the cycle of what's going on with code development.

04:18.55 franksec Right? And I Ah think I think we move towards that space. But as you rightfully say the number of vulnerability and the number of issues that a lot of organizations are finding are escalating over and over and over. And that's just on application security. But then you know development team and now devops teams are faced with you know the Cloud issue the Cloud misconfiguration the deployment in the Cloud then the container base container Image. You know the landscape is in my opinion becoming quite quite. Ah, intense and it' complicated for developer team and security team to have that broad spectrum of knowledge. But then you take even an executive they need to make decision of what is your target. What? what is security what security looking like or what good looks like.

05:11.36 Steve Wilson Yeah, well I think that in what I'll call the olden days which were really not that long ago in a Pre-cloud world. You could depend a lot more on the idea that many of your applications were hidden behind a firewall that they were.

05:11.59 franksec What's your take on that.

05:29.29 Steve Wilson Not exposed to the internet and thus less valuable in ah in a cloud-based world in a zero trust-based world more and more of your applications really are on the internet and that means that every 1 of these vulnerabilities is a potential place that you could be exploited and.

05:37.96 franksec Um.

05:47.79 Steve Wilson You know when we start working with a new customer and help them start to evaluate their applications. We'll find that that typical applications have dozens of vulnerabilities in them potentially serious ones and then you look at ah at a large corporation. They may have thousands of applications.

06:05.84 franksec Right.

06:07.73 Steve Wilson In their environment. So it's it's not uncommon to see a fortune five hundred or global 2000 company having tens of thousands of discrete vulnerabilities in their software and so from an executive point of view. The question is how do you manage that there's. Ah, sometimes a snap back reaction that says we better stop everything that we're going to that we're doing and and fix this on the other hand. Every company today is a software company. Your competitive advantage is in your software your ability to compete in the market your ability to deliver new services is dependent on that and so the challenge as a leader is how do I balance the real risk.

06:36.69 franksec Right.

06:51.50 Steve Wilson With my my need to compete in the market and deliver new value to my customers.

06:55.30 franksec Right? And you know I like your take I Really like your take on the rest because I think um because there're a lot of tooling around different areas. You know you have Cloud Security Infrastructure security container Security. You know you have your pantasy rapport coming in your read teaming just trying in different things. Your ah security lifecycle tooling that is dust must and you name me rast you know and and and more ah more of those coming and despite that every tool is is doing.

07:21.36 Steve Wilson So.

07:29.34 franksec A different level of of ah scanning and and trying to reduce the false positive I think what we're missing in a lot of program of work and a lot of these organization is the contextualization and and the Breadth of view of ah where are those kind of element deployed. That could potentially ah in my in my humble opinion simplify a lot of those kind of conversations and the conversation that traditionally happened between security team development team and executive because everybody could have an opinion on that while. If we display the complexity of the landscape nobody will be able to inform the opinion unless they're very technical. So. What do you think? steve.

08:12.42 Steve Wilson Yeah, so this this element of risk analysis is is really critical and you know log for J is a really good example of this This is this is an exploit or ah, a vulnerability that has exploits that are incredibly high risk. Right? It's ah it's a 10 out of 10 Cvs Cvss score because it's you know you're you're basically enabling complete remote code execution on your servers and it's really easy to exploit. But when you really go look at it and.

08:32.60 franksec So.

08:46.86 Steve Wilson And we've been looking at this specifically with customers. You know we estimate something like fifty fifty six percent of the Java applications out there are packaging of vulnerable um version of log for j but when you really look at it. It actually matters how you use it? um.

08:55.91 franksec Right.

09:06.14 Steve Wilson Whether your application is vulnerable and so being able to have tools that are able to analyze. Not just do you have 1 of these things the sort of Naive view. But but are you really vulnerable. That's really really critical to you being able to. For example, prioritize the work that you're going to do? What are you going to mitigate first because again, if you have thousands of applications. You know how are you going to do this all at once can't can't do this in a day this is going to be going on honestly for weeks or months. Um, so yeah, being able to really.

09:30.32 franksec Where is still not right.

09:41.79 Steve Wilson Establish risk in an urgent situation like this for triage but then more on a day-to-day basis when you're dealing with an environment where um, you know dozens hundreds or even thousands of software developers continually building New software. How do you evaluate the the risk of different. Um, Conditions vulnerabilities and really decide where you need to make compromises in terms of your development and and really lean into to securing yourself versus continuing to generate that that new business value.

10:15.40 franksec Right? up. Absolutely agree and and I think the other thing that we saw that that was working was also trying to prioritize the things that are externally exposed that is easily attackable and you know every team right now is scrambling and trying to find a way to. As you rightfully say you know if you if you belong to an enterprise that has multiple deployment even your web come could be bulletproof to log for j but maybe if we take a step back? Um I wanted to understand considering you come from that kind of environment in Java in the early days I want to understand. What happened in there. Why why are we facing with ah vulnerability that is so easy to exploit that should be really never been in the place you know something so trivial ascend a string and that string can then execute. Ah whatever rce or remote code execution. And then download whatever payload you can want and want how how are we in that situation in the year twenty twenty twelve 2.

11:19.86 Steve Wilson So um, it's it's really interesting to think back to the early days of java and so much emphasis was on creating it as a secure environment. You know, really Java pioneered these concepts like having the the security manager in the runtime that managed what permissions.

11:29.22 franksec Right.

11:39.81 Steve Wilson Things had but but a lot of that in in the inception of Java was you have to rewind so far to remember that Java was originally intended for environments like set top boxes and running applets in a browser and so the the security manager was for things like making sure that um.

11:50.79 franksec And.

11:58.32 Steve Wilson your your java applet couldn't escape the sandbox and get onto somebody's desktop um the actual security of getting something into the Java runtime environment wasn't what the team was optimizing for originally and so when when you look at this log for j. Vulnerability I think there's a couple of things that come in obviously logging is in some ways the least glamorous thing you know task that you can think of and um, you know that log this log for j library is more than 20 years old it's been

12:25.45 franksec Rise.

12:35.84 Steve Wilson You know it got created then it got donated to apache. It's been in Apache for 20 years now with ah with a very small team of honestly very dedicated folks maintaining it but but it's ah it's a small team with minimal investment and minimal tooling. And while it doesn't seem glamorous. Um, this library has been copied literally millions of times different versions of it at different points in different physical locations. So you know you think about? Okay there's a bug and I want to patch the bug. All right? Well, that's that's 1 challenge but the problem is the the offending code has been copied millions of times around the planet. So. There's there's no single place to fix it on top of that. Um, you know the the.

13:17.52 franksec Drive.

13:26.43 Steve Wilson Confluence of events that create this vulnerability and make it exploitable are pretty insidious in terms of the the snarly code path you have to go through and while the exploit is trivial. Um, the vulnerability is actually really intricate and so you know what that means is the. The first attempt that the team put out at apache to fix the vulnerability. Um it. It didn't even fix it so you know people went out and started patching to a new version of the log for j library and now they're having to go back and do it again and so in in a lot of ways I think what we're going to find is. Is people continuing to hammer on some of this and until we really get to the bottom of it and then we're going to start the long arduous process of patching this um and we have you know.

14:16.18 franksec Um, at scale.

14:19.75 Steve Wilson Certain places where they have tooling in place and they're able to execute very very quickly on it and that's you know 1 of the things we're really proud about at contrast is that I think we have tooling that in some ways was designed for the fact that someday this would happen and and it's been great to work with. Customers and and kind of feel like we're helping them. But so many places don't have that kind of tooling in place they're using. Um you know, free and open source tools to do their software composition analysis that don't have enterprise level management. They're writing scripts trying to figure this out themselves. And then you get all the way to the limit case you know you mentioned something like your webcam could be vulnerable and that's not absurd at all. We've seen out in the industry now very specific attacks where people are targeting things like s and mp where they're actually going out and looking for embedded devices.

15:00.21 franksec Yeah.

15:13.72 Steve Wilson And those embedded devices are going to have in some cases literally no way to update them.

15:19.39 franksec Right? And you know I want to cover this in detail. But before we jump on that we have to we had to have a small section for our sponsors so bear with me a second.

16:16.36 franksec All right bra and and thank you again for up Phoenix or our sponsor and and keeping us running but I wanted to to touch point on this on this particular topic because I remember Jeff ah kind of wrote a white paper like. 6 or 7 years ago and it actually presented it to black cat as well. This is not a new thing. The industry has been screamed about this is something that will happen. This is something that will be out there and and now it suddenly happened and I ah do also subscribe to your view and. To your pain in a way that code has been forked so many times and have been distributed in so many places that it becomes very very complex to fix it and we're never going to know that the the extreme expansion but maybe on on on there the more scary topics that I want. As to maybe debate if that's what was 1 library. What's stopping attacking now or poking at the other side of libraries to discover um, similar log for j kind of problems. What do you think.

17:25.19 Steve Wilson Well look the the way I'd like to say this is this has happened before and it will happen again right? if we if we rewind a few years ago to 2017 the apache struts library had a severe vulnerability in it and that is um.

17:30.97 franksec Um.

17:38.57 franksec Right.

17:44.91 Steve Wilson Ah, a less used library than log for J but the same basic concept is there popular open source library embedded in lots and lots of places with a vulnerability in it that could lead to really severe consequences and. You know what's interesting is the world remembers this vulnerability but they don't remember it as the strut's vulnerability. They remember it as the Equifax breach right? and there were many people that were breached from that. But if you don't remember this 1 about 1 hundred and fifty million people lost.

18:08.30 franksec Ah, right.

18:20.75 Steve Wilson Their their personal financial info from equifax which is 1 of the global credit rating organizations and as a result they they wound up paying four hundred and 25 million dollars in fines for not being secure. Um, but the the interesting thing here is. Um, did the world learn anything from this and they absolutely did right? if you look at the difference in response between the Struts vulnerability and the log for j vulnerability um, 1 of the reasons that Equifax was penalized so heavily. Is they could have done much better. This was for them. Not a zero day vulnerability. It was a disclosed vulnerability. It was well known. There were patches that were available and they simply did not act on it. Um.

19:01.11 franksec Um, is a well known.

19:16.79 Steve Wilson What's interesting here to see the difference. 4 years later is that the industry realized how serious this was um, you know I yeah yeah you know on thursday night last week people started.

19:23.25 franksec Um, enacted fast.

19:33.61 Steve Wilson Exploiting this in minecraft of all places you know minecraft the popular video game. Um, you know famously is written in Java you know I remember a few years ago my daughter went to coding camp over the summer and learns to write her first java programs as Minecraft extensions. So you know. Probably millions of people learned to program by hacking on minecraft and so um, in some ways. It's it's not surprising that that was the not the first place that this was exploited but the the place people realized how serious this was is people were exploiting this by.

19:56.27 franksec Um, has great.

20:05.97 franksec Right.

20:10.39 Steve Wilson Putting messages into the minecraft chat window that was how easy it was to exploit. Um, but that was happening on Thursday and thursday night you know our research team at contrast started getting information about this. Um, you know I heard something about it and I went to bed and I got up at. 5 in the morning the next morning I get up early I'm on the west coast of the us and we have teams in europe so I get up early to talk to them and I had slack messages from our our chief architect that said stevie need to call me right now and I talked to him and he said you know by Friday morning he said.

20:42.78 franksec Um.

20:49.10 Steve Wilson Steve this is the most serious thing I've ever seen. We have to help our customers get in front of this and so you know you started to see the news coming out on Friday people were reacting to it not everywhere. There's it's it's far from perfect and it's.

21:02.89 franksec It was pocket.

21:06.36 Steve Wilson Far from uniform but but the industry is jumping on this and there are let's say the more advanced shops are much better prepared. The tooling is better. It's absolutely better than it was 4 years ago and so we we have moved forward from that. But then your question is will this happen again. Of course it will um the the fact that we still build software where you know you see different different figures but up to 80 percent of the code in a typical business application is open source.

21:26.94 franksec Nope yeah.

21:40.45 Steve Wilson And so really, what people are starting to talk about you know, started before this really going back to solar winds. But the the topic around software supply chain management is now the hot topic and I think that's actually a really good way to phrase it because it makes it a bigger problem than just.

21:52.50 franksec And right.

21:59.78 Steve Wilson Thinking about managing vulnerabilities. It's about understanding where your codes coming from what's the Providence of it and being able to really understand that end to end and I think that's going to be the next step in making this better.

22:12.55 franksec So show. Will we start seeing vul be deploying stock trace. That's gonna be the next 1 gonna get it. Ah am I giving wrong suggestion of the wrong people. Ah.

22:18.64 Steve Wilson Oh my? yeah.

22:28.90 franksec Ah, you know because after after open source destins used kind of to by every single developer on earth and I'm pretty actually some of my friends actually have done this experiment of publishing exploit and poc with vulnerable code in there so you had hackers actually just blindfoldingly. Trusting a piece of software just downloading executing it with boom in there and and a callback home and it was a friendly experiment by Andy hilllabs. But um, it was quite interesting to see how blind trust was deployed on. You know piece of code running on the web that is like going outside and asking candy to a strangerr right.

23:12.17 Steve Wilson Yeah, well the um, you know the the more insidious example of this is something we started to see earlier. This year is a rise in um, a tax that it's going by different names but dependency confusion is 1 of them.

23:29.10 franksec The.

23:31.89 Steve Wilson And when you think about the way that that people's build systems and cicd systems work they're they're constantly going out on the internet and pulling down these packages from massive open source repositories where you actually you know you're you're somewhat hoping that you're getting the right thing. And actually a lot of the ways that these work you're you're only providing a general description of the package that you want and it's trying to find the 1 that's best fit and people have found that they can go and create their own version of popular open source libraries put them up in those repos and have people pull them down and um. 1 of our researchers at contrast went went did a proof of concept with this went and looked for applications that looked like they were exposed to this and actually Microsoft teams wound up being a good example now Microsoft's an investor and a partner. Um. Ah, and we're in their bug bounty Program. So we we did this all above board but we actually created some open source libraries and Microsoft pulled them down and compiled them into into their binary and it was just an example.

24:40.97 franksec Teams.

24:45.22 Steve Wilson Of How even a sophisticated software shop um can be vulnerable to this so you know they've hardened their processes since then but other people have not This is a really new example of ah of a vulnerability out there being able to divert the software supply chain. Um. To you know a Hacker's nefarious ends and so the ability of someone to go and create their own version of an open source library with some nefarious code. You know we've seen this so far largely people doing things like dumping in crypto minorers and and that's well documented. But.

25:21.90 franksec Bri yeah or run somewhere. That's I think I saw I saw a couple of days ago. Ah, payload and conti starting to deploy this as as potentially run some arrow or or run some my payload so we start seeing.

25:24.20 Steve Wilson We know there must be examples of much more defarious usage. Absolutely.

25:41.22 franksec Fundamentally ransome are going towards this and that's that's the other scary part that the industry from the Attacker prospect. This seems to have industrialized the use of this massive scale vulnerability and decimal scary factor that we had just a week or maybe 2 time to actually breathe text vulnerabilit be so time to detection and and and remediation is actually being shorted dramatically I mean our ourtistic goes from roughly 3 to fifteen days to deploy something like this at scale and it's being confirmed basically by this but it's. Think is is a scary factor and then on the other side maybe here more in the u k we saw fundamentally british airways being attacked with a much more malicious code where somebody ah fundamentally hijacked 1 of the developer trusted account and. Injected malicious code e in a library so that's that's even worse you know and I agree with you. It's it double down on the subject of controlling your supply chain but controlling how you pull in things where you're deploying and. In my humble opinion I think we've been. We've been using security in the wrong way right now and we've being putting them in the front foot and firefighting vulnerability on day in and the out and they kind of lost their way by not focusing on systemating and on strategic thing like creating. Ah, proxy for libraries or or analyzing open source of what comes in and out like what the the security team in contrast does and that's how we should be using back security for that instrumental systemic change rather than day in and out management of vulnerability.

27:26.62 Steve Wilson So yeah I mean look I think the the day-to-day management of vulnerability actually to some extent hasn't been done at all in a lot of shops right? It's been um, it's been completely pushed off to a.

27:26.89 franksec What do you think safe.

27:36.95 franksec Ah.

27:43.92 Steve Wilson Ah, periodic scanning based procedure run by the security team where you scan things on a quarterly or even yearly basis and I lived this in my last job it's 1 of the reasons I got excited about about this job opportunity when it came up was I was running a large development team. And the head of engineering came to me and said I need to cancel all the features that I promised for next quarter because the security team just ran a scan and filed a thousand jira tickets. Um, and and now there was this record of this potential vulnerability that we were obliged to deal with and it turned out. Most of them weren't real vulnerabilities almost all of them weren't um, but it wound up being a huge amount of work to so to sift through it on the other hand for for companies that really adopt this devsec ops attitude and get the right tooling in place to enable it. Um, you find a potential vulnerability maybe before you even complete your pull request to put the put the software back and it's just like any other bug if the bug gets into the code base. It's 10 times as expensive to fix it as it was for the developer to fix it on their desktop. Um, if it actually gets out to a customer It's a Hundred times more expensive and you know with security given the stakes. It's much worse than that. So um, the the real shift here is to push so much more of the responsibility down to this. To the developers but also really not make the developers responsible for it because it's hard for developers but to put the right tool chain around them that makes it easy and it really is possible with the modern tools to do that now and that's the big opportunity to change how we do development.

29:35.39 franksec Brian I agree with you. It should be It should be a collaboration between shift left and the copy is on more automation in the place because a lot of this as you rightfully say is still pretty much reactive is still pretty much that debate in Discussion. And then the endless argument between the se security team and the development team saying this is false positive. This is internal is a false positive rather than you know it's accept the risk and is different priorities and stuff like that. So. I think we can do better at thefsecops to actually remove security people on doing consistently these firefighting in this endless debate. Um, and and and automate a lot of the relationship but also the detection of um false positive based on contextual aspect and contextual information. If you can actually exploit it if it's actually visible to attack. Ah then you know we we focus on it because otherwise we're going to be always overflloded by these issues and you know look for js all similar are going to keep on piling up right.

30:42.60 Steve Wilson Absolutely I mean I think we really do have the the tools at our disposal and the processes being developed out there in the industry to to just fundamentally shift this change the game and make this so much more efficient and create. Really much more secure applications as a result. So.

31:00.59 franksec Fantastic! and I guess we we this is just a a nice input to the to the conclusion that is the positive message on our industry. So if you want to double down on that Steve what will be your positive message overall rather than we. We have the 2 and we have the technology and we can rebuild this. Ah.

31:20.62 Steve Wilson Like I think going going back to a little bit earlier I think the good news is you know this has happened before the industry has moved a tremendous distance since the Struts vulnerability for example, um, this really would be much worse. If we weren't in the position that we are now that we had better understanding of the risks better tools better processes. We have the tools out there now widely deployed to understand your your open source footprint. What's vulnerable. Um, we have the tools in place that help people upgrade and fix this. We even have tools today like like rasp tools that can protect you and we've seen evidence that these rash tools were protecting people um before day zero now. So really, we're in a position where we're moving forward.

32:09.23 franksec Um.

32:15.56 Steve Wilson So quickly that look there's no end in sight for this but really, the bar has raised dramatically and if we work together as an industry the next time this happens we'll be even better prepared.

32:27.90 franksec Fantastic. And yeah I agree with you. We've seen an enormous collaboration between teams and information out there. So I Really appreciated that collaboration and and enjoy that seeing that collaboration and the community getting together to to fix. But ah on the conclusion of the show if people want to find more about what you do day in in day out where where is the best place for them to contact you and how they can reach you yet. Stay.

32:53.99 Steve Wilson Yeah, so please so please come over check out what we're doing at the Contrastsecurity Dot Com Website. You can get all the details on all of our commercial tools. Also check out our blog there. There's a link off the front page to some free and open source tools that we've put out to help with log for J in particular so we really want people in the community to engage with us on this also feel free to reach out to me direct on linkedin.

33:23.13 franksec All right brave and everybody. Thank you very much we we understand that everybody is tired and stressed. We really hope that everybody can enjoy christmas at some stage or time and get away from the lock for j unfortunately attack it don't sleep so defend it on. Don't sleep either. But we're gonna get ahead of this together. So this is your host francesco I had the pleasure to talk with Steve wilson the chief product officer for contra security and I wish you everybody to stay safe and have a lovely christmas Thank you.

00:00.00 franksec Hello everyone and welcome back to another episode of the cyber security and cloud podcast today. We have a topic that probably nobody has ever spoken in the recent time that is Goingnna be obligation security vulnerability management but the whole thing that has taken. By the storm the industry that is fundamental log for js and today we have a special guest but before we crack on. Let let us start with our intro.

00:54.11 franksec All right? or right or right we are Back. So I'd like to welcome steel wilson that came we started chatting over over a Twitter over Twitter threadad around of course up for j. So I've reminded him on the show to actually chat a little bit about the topic and his particular take is been He's the chief product officer of contra security 1 product that we absolutely love and we saw that was quite well reacting on the log four j issue but also he is an early member of the Java team on the early ninety s. But before I talk through it. Let me welcome steve steve welcome on the show.

01:33.74 Steve Wilson Hey thank you Francisco for having me really looking forward to it. So.

01:37.60 franksec Brilliant and can you give our audience a little bit about your background. What brought you into side by you know how did you start the journey from the early days with java.

01:47.24 Steve Wilson Yeah, so um, I started out really early in my career back in the ninety s at Sun microsystems I was an early member of the Java development team. Um. Went on from working really around development tools developer tools for several years and then shifted my focus over to cloud and I spent a lot of time at large companies like oracle and citrix building cloud services and cloud infrastructure and really got exposed. To a lot of the security challenges that are out there in the industry and decided about a year ago that I wanted to really move into the cyber security industry from the inside and so I joined contrast a little over a year ago to head product development.

02:35.60 franksec Nice, fantastic. And and we need we need more more ally in Cyber especially over over these challenging time. But we have a tradition on the show that we give an overview on the industry of what's working. What's not working so what will be your take on on.

02:53.16 Steve Wilson Yeah, so um, with the area of the industry that we're really focused on looking at the security of applications and code. It's a really challenging environment out there I Think what we really see is that.

02:53.40 franksec What's going on.

03:11.40 Steve Wilson Over the past several years. The complexity in software out there means that the number of security vulnerabilities in a typical program is is escalating dramatically as they get larger and more complicated and really the fact is human brains have a hard time. Ah, dealing with the complexities in the number of paths and things that are through the code today and so you know really this industry around application security has developed there to create tools that ah people can use to make their applications more secure. But 1 of the big shifts going on now is really moving from a focus on standalone security teams working to audit applications sort of almost after they're done to really bringing that security mindset into development at the beginning. And really creating a new culture where um, security comes very early in the cycle of what's going on with code development.

04:18.55 franksec Right? And I Ah think I think we move towards that space. But as you rightfully say the number of vulnerability and the number of issues that a lot of organizations are finding are escalating over and over and over. And that's just on application security. But then you know development team and now devops teams are faced with you know the Cloud issue the Cloud misconfiguration the deployment in the Cloud then the container base container Image. You know the landscape is in my opinion becoming quite quite. Ah, intense and it' complicated for developer team and security team to have that broad spectrum of knowledge. But then you take even an executive they need to make decision of what is your target. What? what is security what security looking like or what good looks like.

05:11.36 Steve Wilson Yeah, well I think that in what I'll call the olden days which were really not that long ago in a Pre-cloud world. You could depend a lot more on the idea that many of your applications were hidden behind a firewall that they were.

05:11.59 franksec What's your take on that.

05:29.29 Steve Wilson Not exposed to the internet and thus less valuable in ah in a cloud-based world in a zero trust-based world more and more of your applications really are on the internet and that means that every 1 of these vulnerabilities is a potential place that you could be exploited and.

05:37.96 franksec Um.

05:47.79 Steve Wilson You know when we start working with a new customer and help them start to evaluate their applications. We'll find that that typical applications have dozens of vulnerabilities in them potentially serious ones and then you look at ah at a large corporation. They may have thousands of applications.

06:05.84 franksec Right.

06:07.73 Steve Wilson In their environment. So it's it's not uncommon to see a fortune five hundred or global 2000 company having tens of thousands of discrete vulnerabilities in their software and so from an executive point of view. The question is how do you manage that there's. Ah, sometimes a snap back reaction that says we better stop everything that we're going to that we're doing and and fix this on the other hand. Every company today is a software company. Your competitive advantage is in your software your ability to compete in the market your ability to deliver new services is dependent on that and so the challenge as a leader is how do I balance the real risk.

06:36.69 franksec Right.

06:51.50 Steve Wilson With my my need to compete in the market and deliver new value to my customers.

06:55.30 franksec Right? And you know I like your take I Really like your take on the rest because I think um because there're a lot of tooling around different areas. You know you have Cloud Security Infrastructure security container Security. You know you have your pantasy rapport coming in your read teaming just trying in different things. Your ah security lifecycle tooling that is dust must and you name me rast you know and and and more ah more of those coming and despite that every tool is is doing.

07:21.36 Steve Wilson So.

07:29.34 franksec A different level of of ah scanning and and trying to reduce the false positive I think what we're missing in a lot of program of work and a lot of these organization is the contextualization and and the Breadth of view of ah where are those kind of element deployed. That could potentially ah in my in my humble opinion simplify a lot of those kind of conversations and the conversation that traditionally happened between security team development team and executive because everybody could have an opinion on that while. If we display the complexity of the landscape nobody will be able to inform the opinion unless they're very technical. So. What do you think? steve.

08:12.42 Steve Wilson Yeah, so this this element of risk analysis is is really critical and you know log for J is a really good example of this This is this is an exploit or ah, a vulnerability that has exploits that are incredibly high risk. Right? It's ah it's a 10 out of 10 Cvs Cvss score because it's you know you're you're basically enabling complete remote code execution on your servers and it's really easy to exploit. But when you really go look at it and.

08:32.60 franksec So.

08:46.86 Steve Wilson And we've been looking at this specifically with customers. You know we estimate something like fifty fifty six percent of the Java applications out there are packaging of vulnerable um version of log for j but when you really look at it. It actually matters how you use it? um.

08:55.91 franksec Right.

09:06.14 Steve Wilson Whether your application is vulnerable and so being able to have tools that are able to analyze. Not just do you have 1 of these things the sort of Naive view. But but are you really vulnerable. That's really really critical to you being able to. For example, prioritize the work that you're going to do? What are you going to mitigate first because again, if you have thousands of applications. You know how are you going to do this all at once can't can't do this in a day this is going to be going on honestly for weeks or months. Um, so yeah, being able to really.

09:30.32 franksec Where is still not right.

09:41.79 Steve Wilson Establish risk in an urgent situation like this for triage but then more on a day-to-day basis when you're dealing with an environment where um, you know dozens hundreds or even thousands of software developers continually building New software. How do you evaluate the the risk of different. Um, Conditions vulnerabilities and really decide where you need to make compromises in terms of your development and and really lean into to securing yourself versus continuing to generate that that new business value.

10:15.40 franksec Right? up. Absolutely agree and and I think the other thing that we saw that that was working was also trying to prioritize the things that are externally exposed that is easily attackable and you know every team right now is scrambling and trying to find a way to. As you rightfully say you know if you if you belong to an enterprise that has multiple deployment even your web come could be bulletproof to log for j but maybe if we take a step back? Um I wanted to understand considering you come from that kind of environment in Java in the early days I want to understand. What happened in there. Why why are we facing with ah vulnerability that is so easy to exploit that should be really never been in the place you know something so trivial ascend a string and that string can then execute. Ah whatever rce or remote code execution. And then download whatever payload you can want and want how how are we in that situation in the year twenty twenty twelve 2.

11:19.86 Steve Wilson So um, it's it's really interesting to think back to the early days of java and so much emphasis was on creating it as a secure environment. You know, really Java pioneered these concepts like having the the security manager in the runtime that managed what permissions.

11:29.22 franksec Right.

11:39.81 Steve Wilson Things had but but a lot of that in in the inception of Java was you have to rewind so far to remember that Java was originally intended for environments like set top boxes and running applets in a browser and so the the security manager was for things like making sure that um.

11:50.79 franksec And.

11:58.32 Steve Wilson your your java applet couldn't escape the sandbox and get onto somebody's desktop um the actual security of getting something into the Java runtime environment wasn't what the team was optimizing for originally and so when when you look at this log for j. Vulnerability I think there's a couple of things that come in obviously logging is in some ways the least glamorous thing you know task that you can think of and um, you know that log this log for j library is more than 20 years old it's been

12:25.45 franksec Rise.

12:35.84 Steve Wilson You know it got created then it got donated to apache. It's been in Apache for 20 years now with ah with a very small team of honestly very dedicated folks maintaining it but but it's ah it's a small team with minimal investment and minimal tooling. And while it doesn't seem glamorous. Um, this library has been copied literally millions of times different versions of it at different points in different physical locations. So you know you think about? Okay there's a bug and I want to patch the bug. All right? Well, that's that's 1 challenge but the problem is the the offending code has been copied millions of times around the planet. So. There's there's no single place to fix it on top of that. Um, you know the the.

13:17.52 franksec Drive.

13:26.43 Steve Wilson Confluence of events that create this vulnerability and make it exploitable are pretty insidious in terms of the the snarly code path you have to go through and while the exploit is trivial. Um, the vulnerability is actually really intricate and so you know what that means is the. The first attempt that the team put out at apache to fix the vulnerability. Um it. It didn't even fix it so you know people went out and started patching to a new version of the log for j library and now they're having to go back and do it again and so in in a lot of ways I think what we're going to find is. Is people continuing to hammer on some of this and until we really get to the bottom of it and then we're going to start the long arduous process of patching this um and we have you know.

14:16.18 franksec Um, at scale.

14:19.75 Steve Wilson Certain places where they have tooling in place and they're able to execute very very quickly on it and that's you know 1 of the things we're really proud about at contrast is that I think we have tooling that in some ways was designed for the fact that someday this would happen and and it's been great to work with. Customers and and kind of feel like we're helping them. But so many places don't have that kind of tooling in place they're using. Um you know, free and open source tools to do their software composition analysis that don't have enterprise level management. They're writing scripts trying to figure this out themselves. And then you get all the way to the limit case you know you mentioned something like your webcam could be vulnerable and that's not absurd at all. We've seen out in the industry now very specific attacks where people are targeting things like s and mp where they're actually going out and looking for embedded devices.

15:00.21 franksec Yeah.

15:13.72 Steve Wilson And those embedded devices are going to have in some cases literally no way to update them.

15:19.39 franksec Right? And you know I want to cover this in detail. But before we jump on that we have to we had to have a small section for our sponsors so bear with me a second.

16:16.36 franksec All right bra and and thank you again for up Phoenix or our sponsor and and keeping us running but I wanted to to touch point on this on this particular topic because I remember Jeff ah kind of wrote a white paper like. 6 or 7 years ago and it actually presented it to black cat as well. This is not a new thing. The industry has been screamed about this is something that will happen. This is something that will be out there and and now it suddenly happened and I ah do also subscribe to your view and. To your pain in a way that code has been forked so many times and have been distributed in so many places that it becomes very very complex to fix it and we're never going to know that the the extreme expansion but maybe on on on there the more scary topics that I want. As to maybe debate if that's what was 1 library. What's stopping attacking now or poking at the other side of libraries to discover um, similar log for j kind of problems. What do you think.

17:25.19 Steve Wilson Well look the the way I'd like to say this is this has happened before and it will happen again right? if we if we rewind a few years ago to 2017 the apache struts library had a severe vulnerability in it and that is um.

17:30.97 franksec Um.

17:38.57 franksec Right.

17:44.91 Steve Wilson Ah, a less used library than log for J but the same basic concept is there popular open source library embedded in lots and lots of places with a vulnerability in it that could lead to really severe consequences and. You know what's interesting is the world remembers this vulnerability but they don't remember it as the strut's vulnerability. They remember it as the Equifax breach right? and there were many people that were breached from that. But if you don't remember this 1 about 1 hundred and fifty million people lost.

18:08.30 franksec Ah, right.

18:20.75 Steve Wilson Their their personal financial info from equifax which is 1 of the global credit rating organizations and as a result they they wound up paying four hundred and 25 million dollars in fines for not being secure. Um, but the the interesting thing here is. Um, did the world learn anything from this and they absolutely did right? if you look at the difference in response between the Struts vulnerability and the log for j vulnerability um, 1 of the reasons that Equifax was penalized so heavily. Is they could have done much better. This was for them. Not a zero day vulnerability. It was a disclosed vulnerability. It was well known. There were patches that were available and they simply did not act on it. Um.

19:01.11 franksec Um, is a well known.

19:16.79 Steve Wilson What's interesting here to see the difference. 4 years later is that the industry realized how serious this was um, you know I yeah yeah you know on thursday night last week people started.

19:23.25 franksec Um, enacted fast.

19:33.61 Steve Wilson Exploiting this in minecraft of all places you know minecraft the popular video game. Um, you know famously is written in Java you know I remember a few years ago my daughter went to coding camp over the summer and learns to write her first java programs as Minecraft extensions. So you know. Probably millions of people learned to program by hacking on minecraft and so um, in some ways. It's it's not surprising that that was the not the first place that this was exploited but the the place people realized how serious this was is people were exploiting this by.

19:56.27 franksec Um, has great.

20:05.97 franksec Right.

20:10.39 Steve Wilson Putting messages into the minecraft chat window that was how easy it was to exploit. Um, but that was happening on Thursday and thursday night you know our research team at contrast started getting information about this. Um, you know I heard something about it and I went to bed and I got up at. 5 in the morning the next morning I get up early I'm on the west coast of the us and we have teams in europe so I get up early to talk to them and I had slack messages from our our chief architect that said stevie need to call me right now and I talked to him and he said you know by Friday morning he said.

20:42.78 franksec Um.

20:49.10 Steve Wilson Steve this is the most serious thing I've ever seen. We have to help our customers get in front of this and so you know you started to see the news coming out on Friday people were reacting to it not everywhere. There's it's it's far from perfect and it's.

21:02.89 franksec It was pocket.

21:06.36 Steve Wilson Far from uniform but but the industry is jumping on this and there are let's say the more advanced shops are much better prepared. The tooling is better. It's absolutely better than it was 4 years ago and so we we have moved forward from that. But then your question is will this happen again. Of course it will um the the fact that we still build software where you know you see different different figures but up to 80 percent of the code in a typical business application is open source.

21:26.94 franksec Nope yeah.

21:40.45 Steve Wilson And so really, what people are starting to talk about you know, started before this really going back to solar winds. But the the topic around software supply chain management is now the hot topic and I think that's actually a really good way to phrase it because it makes it a bigger problem than just.

21:52.50 franksec And right.

21:59.78 Steve Wilson Thinking about managing vulnerabilities. It's about understanding where your codes coming from what's the Providence of it and being able to really understand that end to end and I think that's going to be the next step in making this better.

22:12.55 franksec So show. Will we start seeing vul be deploying stock trace. That's gonna be the next 1 gonna get it. Ah am I giving wrong suggestion of the wrong people. Ah.

22:18.64 Steve Wilson Oh my? yeah.

22:28.90 franksec Ah, you know because after after open source destins used kind of to by every single developer on earth and I'm pretty actually some of my friends actually have done this experiment of publishing exploit and poc with vulnerable code in there so you had hackers actually just blindfoldingly. Trusting a piece of software just downloading executing it with boom in there and and a callback home and it was a friendly experiment by Andy hilllabs. But um, it was quite interesting to see how blind trust was deployed on. You know piece of code running on the web that is like going outside and asking candy to a strangerr right.

23:12.17 Steve Wilson Yeah, well the um, you know the the more insidious example of this is something we started to see earlier. This year is a rise in um, a tax that it's going by different names but dependency confusion is 1 of them.

23:29.10 franksec The.

23:31.89 Steve Wilson And when you think about the way that that people's build systems and cicd systems work they're they're constantly going out on the internet and pulling down these packages from massive open source repositories where you actually you know you're you're somewhat hoping that you're getting the right thing. And actually a lot of the ways that these work you're you're only providing a general description of the package that you want and it's trying to find the 1 that's best fit and people have found that they can go and create their own version of popular open source libraries put them up in those repos and have people pull them down and um. 1 of our researchers at contrast went went did a proof of concept with this went and looked for applications that looked like they were exposed to this and actually Microsoft teams wound up being a good example now Microsoft's an investor and a partner. Um. Ah, and we're in their bug bounty Program. So we we did this all above board but we actually created some open source libraries and Microsoft pulled them down and compiled them into into their binary and it was just an example.

24:40.97 franksec Teams.

24:45.22 Steve Wilson Of How even a sophisticated software shop um can be vulnerable to this so you know they've hardened their processes since then but other people have not This is a really new example of ah of a vulnerability out there being able to divert the software supply chain. Um. To you know a Hacker's nefarious ends and so the ability of someone to go and create their own version of an open source library with some nefarious code. You know we've seen this so far largely people doing things like dumping in crypto minorers and and that's well documented. But.

25:21.90 franksec Bri yeah or run somewhere. That's I think I saw I saw a couple of days ago. Ah, payload and conti starting to deploy this as as potentially run some arrow or or run some my payload so we start seeing.

25:24.20 Steve Wilson We know there must be examples of much more defarious usage. Absolutely.

25:41.22 franksec Fundamentally ransome are going towards this and that's that's the other scary part that the industry from the Attacker prospect. This seems to have industrialized the use of this massive scale vulnerability and decimal scary factor that we had just a week or maybe 2 time to actually breathe text vulnerabilit be so time to detection and and and remediation is actually being shorted dramatically I mean our ourtistic goes from roughly 3 to fifteen days to deploy something like this at scale and it's being confirmed basically by this but it's. Think is is a scary factor and then on the other side maybe here more in the u k we saw fundamentally british airways being attacked with a much more malicious code where somebody ah fundamentally hijacked 1 of the developer trusted account and. Injected malicious code e in a library so that's that's even worse you know and I agree with you. It's it double down on the subject of controlling your supply chain but controlling how you pull in things where you're deploying and. In my humble opinion I think we've been. We've been using security in the wrong way right now and we've being putting them in the front foot and firefighting vulnerability on day in and the out and they kind of lost their way by not focusing on systemating and on strategic thing like creating. Ah, proxy for libraries or or analyzing open source of what comes in and out like what the the security team in contrast does and that's how we should be using back security for that instrumental systemic change rather than day in and out management of vulnerability.

27:26.62 Steve Wilson So yeah I mean look I think the the day-to-day management of vulnerability actually to some extent hasn't been done at all in a lot of shops right? It's been um, it's been completely pushed off to a.

27:26.89 franksec What do you think safe.

27:36.95 franksec Ah.

27:43.92 Steve Wilson Ah, periodic scanning based procedure run by the security team where you scan things on a quarterly or even yearly basis and I lived this in my last job it's 1 of the reasons I got excited about about this job opportunity when it came up was I was running a large development team. And the head of engineering came to me and said I need to cancel all the features that I promised for next quarter because the security team just ran a scan and filed a thousand jira tickets. Um, and and now there was this record of this potential vulnerability that we were obliged to deal with and it turned out. Most of them weren't real vulnerabilities almost all of them weren't um, but it wound up being a huge amount of work to so to sift through it on the other hand for for companies that really adopt this devsec ops attitude and get the right tooling in place to enable it. Um, you find a potential vulnerability maybe before you even complete your pull request to put the put the software back and it's just like any other bug if the bug gets into the code base. It's 10 times as expensive to fix it as it was for the developer to fix it on their desktop. Um, if it actually gets out to a customer It's a Hundred times more expensive and you know with security given the stakes. It's much worse than that. So um, the the real shift here is to push so much more of the responsibility down to this. To the developers but also really not make the developers responsible for it because it's hard for developers but to put the right tool chain around them that makes it easy and it really is possible with the modern tools to do that now and that's the big opportunity to change how we do development.

29:35.39 franksec Brian I agree with you. It should be It should be a collaboration between shift left and the copy is on more automation in the place because a lot of this as you rightfully say is still pretty much reactive is still pretty much that debate in Discussion. And then the endless argument between the se security team and the development team saying this is false positive. This is internal is a false positive rather than you know it's accept the risk and is different priorities and stuff like that. So. I think we can do better at thefsecops to actually remove security people on doing consistently these firefighting in this endless debate. Um, and and and automate a lot of the relationship but also the detection of um false positive based on contextual aspect and contextual information. If you can actually exploit it if it's actually visible to attack. Ah then you know we we focus on it because otherwise we're going to be always overflloded by these issues and you know look for js all similar are going to keep on piling up right.

30:42.60 Steve Wilson Absolutely I mean I think we really do have the the tools at our disposal and the processes being developed out there in the industry to to just fundamentally shift this change the game and make this so much more efficient and create. Really much more secure applications as a result. So.

31:00.59 franksec Fantastic! and I guess we we this is just a a nice input to the to the conclusion that is the positive message on our industry. So if you want to double down on that Steve what will be your positive message overall rather than we. We have the 2 and we have the technology and we can rebuild this. Ah.

31:20.62 Steve Wilson Like I think going going back to a little bit earlier I think the good news is you know this has happened before the industry has moved a tremendous distance since the Struts vulnerability for example, um, this really would be much worse. If we weren't in the position that we are now that we had better understanding of the risks better tools better processes. We have the tools out there now widely deployed to understand your your open source footprint. What's vulnerable. Um, we have the tools in place that help people upgrade and fix this. We even have tools today like like rasp tools that can protect you and we've seen evidence that these rash tools were protecting people um before day zero now. So really, we're in a position where we're moving forward.

32:09.23 franksec Um.

32:15.56 Steve Wilson So quickly that look there's no end in sight for this but really, the bar has raised dramatically and if we work together as an industry the next time this happens we'll be even better prepared.

32:27.90 franksec Fantastic. And yeah I agree with you. We've seen an enormous collaboration between teams and information out there. So I Really appreciated that collaboration and and enjoy that seeing that collaboration and the community getting together to to fix. But ah on the conclusion of the show if people want to find more about what you do day in in day out where where is the best place for them to contact you and how they can reach you yet. Stay.

32:53.99 Steve Wilson Yeah, so please so please come over check out what we're doing at the Contrastsecurity Dot Com Website. You can get all the details on all of our commercial tools. Also check out our blog there. There's a link off the front page to some free and open source tools that we've put out to help with log for J in particular so we really want people in the community to engage with us on this also feel free to reach out to me direct on linkedin.

33:23.13 franksec All right brave and everybody. Thank you very much we we understand that everybody is tired and stressed. We really hope that everybody can enjoy christmas at some stage or time and get away from the lock for j unfortunately attack it don't sleep so defend it on. Don't sleep either. But we're gonna get ahead of this together. So this is your host francesco I had the pleasure to talk with Steve wilson the chief product officer for contra security and I wish you everybody to stay safe and have a lovely christmas Thank you.

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 2 of the interview with Sam.

Sam Stepanyan is an Application Security Architect and Consultant, an OWASP London Chapter Leader, and a WAF Specialist. Sam joins the podcast to discuss many of the opportunities for young aspiring security professionals, the big picture purpose of OWASP, and the first steps to addressing application security

This is part 2 with Sam Stepanyan, an Application Security Architect and Consultant, the OWASP London Chapter Leader, and a WAF Specialist. Sam encourages everyone in the cyber community to join a local OWASP chapter, network at conferences, and compete in games. He also shares a horror story and a success story from his career.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:47 Threat modelling

3:30 Pen testing

5:19 Cost of security

5:58 Dependency checker

7:55 GitHub community

12:20 Local chapters

14:45 Conferences, competitions, events

18:02 OWASP Zed Attack Proxy (Zap)

20:01 Positive and horror story in security

24:12 Future of cyber

25:45 Outro

Sam Stepanyan

Twitter @securestep9

https://www.linkedin.com/in/samstepanyan/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 1 of the interview with Sam.

Sam Stepanyan is an Application Security Architect and Consultant, an OWASP London Chapter Leader, and a WAF Specialist. Sam joins the podcast to discuss many of the opportunities for young aspiring security professionals, the big picture purpose of OWASP, and the first steps to addressing application security

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:47 Introducing Sam

2:15 Conversation begins

4:10 Positive message

8:10 Purpose of OWASP

10:55 Nettacker

13:40 Asset discovery

15:30 Multi-factor authentication

16:30 Google summer of code

19:49 OWASP top 10

22:46 Capital One and cloud breaches

24:02 Basics of Application Security program

30:00 Outro

Sam Stepanyan

Twitter @securestep9

https://www.linkedin.com/in/samstepanyan/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

Chani Simms is the Managing Director and Co-Founder of Meta Defense Labs LTD, a consultant, the Founder of SHe CISO, a TEDx Speaker, and an Award-winning Cybersecurity Leader. Chani shares how she prepared for her TedX talk and her thoughts on emotional intelligence and mental health in the workplace.

This is part 2 with Chani Sims. Chani explains what a Virtual CISO does, the importance of basic cyber hygiene, and the initial steps to becoming a cyber security professional. Chani’s approach to security is to operate on zero trust.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:46 Virtual CISO

5:10 Cyber hygiene

8:55 Starting in cyber

13:24 Assume breach

18:53 Twitter drama

22:10 Closing words

22:50 Out

Chani Simms

linkedin.com/in/chani-simms

metadefencelabs.com/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 1 of the interview with Chani.

Chani Simms is the Managing Director and Co-Founder of Meta Defense Labs LTD, a consultant, the Founder of SHe CISO, a TEDx Speaker, and an Award-winning Cybersecurity Leader. Chani shares how she prepared for her TedX talk and her thoughts on emotional intelligence and mental health in the workplace.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Introduction

0:46 Chani’s background

3:00 TEDx talk

8:00 Women in cyber and mental health

10:56 SHe CISO

14:00 Self-esteem

16:00 Emotional Intelligence

19:08 Managing emotion

21:20 Outro

Chani Simms

linkedin.com/in/chani-simms

metadefencelabs.com/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part two with Kevin Fielder, a CISO, NED, start-up and board advisor, researcher, and speaker based in the UK. Kevin is a CrossFit athlete who values a healthy work-life balance that allows him time for fitness and family. He answers questions about diversity in the workplace, recruiting, and the biggest challenges in his role.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Intro

0:47 Crossfit

4:36 Work-life balance

8:58 Remote working

10:50 Cognitive diversity in cyber

16:05 Working with deaf

17:50 Working under stress

20:35 Recruiter

23:50 Biggest challenge in current role

25:26 Final positive message

28:02 Outro

Kevin Fielder

https://www.linkedin.com/in/kevinfielder/

Twitter @kevin_fielder

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 1 of the interview with Kevin.

Kevin Fielder is a CISO, NED, start-up and board advisor, researcher, and speaker based in the UK. In part one of the interviews, Kevin discusses his approach to recurring and hiring new talent for junior cyber security roles, managing and leading teams with both junior and senior talent, and his own career trajectory

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Intro

0:47 Introducing Kevin

2:06 Career in cyber

5:30 Favorite area/role

7:30 Recruiting junior roles

12:00 Balancing junior and senior talent

16:09 Managing teams and technical jargon

21:16 Story leading teams

24:55 Cloud-Native DevOps

28:35 DecSecOps and engagement

Kevin Fielder

https://www.linkedin.com/in/kevinfielder/

Twitter @kevin_fielder

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 2 of the interview with Tanya Janca. In this episode, Tanya shares her passion for WoSec, her decision to leave Microsoft, giving back to the community, encouraging women to get involved in cyber security, and defines DevSecOps.

Tanya Janca is an application security evangelist, a web application penetration tester and vulnerability assessor, trainer, public speaker, ethical hacker, the Co-Leader of the OWASP Ottawa chapter, a best-selling author, and independent consultant, specializing in Cloud Security, DevSecOps, and AppSec.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Intro

0:47 WoSec

4:08 Cyber ladies in Israel

13:03 Leaving Microsoft

14:30 Mentoring Monday

17:10 Future of AppSec

24:18 Issues at conferences

27:25 What is DevSecOps

36:35 Final positive message

37:17 Outro

Tanya Janca

Twitter @shehackspurple

https://wehackpurple.com

https://www.linkedin.com/in/tanya-janca/?originalSubdomain=ca

https://www.womenofsecurity.com

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 1 of the interview with Tanya Janca.

Tanya Janca is an application security evangelist, a web application penetration tester and vulnerability assessor, trainer, public speaker, ethical hacker, the Co-Leader of the OWASP Ottawa chapter, a best-selling author, and independent consultant, specializing in Cloud Security, DevSecOps, and AppSec. In part 1 of the conversation, Tanya discusses the importance of professional mentorship, getting women involved in cyber security, conferences, online communities, and overcoming her fear of public speaking.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Intro

0:47 Introducing Tanya

1:55 Conversation begins

7:08 Women in security

13:35 Conference

17:26 Online community

18:30 Days as a software developer

20:55 Women in OWASP

24:20 Public speaking

26:48 WoSec

27:30 Outro

Tanya Janca

Twitter @shehackspurple

https://wehackpurple.com

https://www.linkedin.com/in/tanya-janca/?originalSubdomain=ca

https://www.womenofsecurity.com

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is part 2 of the interview with Jim Manico. Jim and Francesco address some of the criticisms of OWASP, discuss what makes a chapter great, and the future of cyber security.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:00 Intro

0:27 Fixing the legacy problem

7:00 Critics of OWASP

13:00 OWASP can’t be tamed

16:26 Order VS chaos

22:20 What makes a chapter great

24:04 Final positive message

26:18 Closing words

26:54 Outro

Jim Manico

Twitter @manicode

https://www.linkedin.com/in/jmanico/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

Jim Manico is the Founder and Secure Coding Instructor at Manicode Security, a member of OWASP, and an AppSec enthusiast. In part 1 of this lively conversation, they discuss Netflix, automated security, and the complex problem of fixing legacy software.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:46 Introducing Jim

2:15 Conversation begins

5:15 Painful problem of AppSec

10:10 Security and money

11:20 Security testing

12:05 Privacy laws

14:50 Automated/integrated security

15:45 DevSecOps

18:06 Netflix

19:40 OWASP

20:50 Java

26:10 Outro

Jim Manico

Twitter @manicode

https://www.linkedin.com/in/jmanico/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

Grant Ongers is on the Global Board of Directors at OWASP Foundation and has spent his entire career in DevSecOps. Grant is also the co-founder of Secure Delivery and speak with Francesco and co-host, Zoe, about DevSecOps, mentoring, and OWASP. Grant says DevSecOps is actually just DevOps done right

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:46 Introducing Grant

2:00 Conversation

2:35 Positive message

3:45 Career background

5:50 DevSecOps

9:45 CISO and CIO

11:05 Mentoring

15:55 OWASP

20:00 Valuable resources

23:10 Communication

26:00 Joining OWASP and mission

37:40 Closing words

38:15 Outro

Grant Ongers

Twitter @rewtd

https://www.linkedin.com/in/rewtd/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second part of the interviews with Vandana Verma,

Vandana Verma is a Security Relationship Leader for SNYK, an advocate for women and girls in AppSec, and on the board of OWASP. Francesco and Vandana discuss the best way to communicate the importance of security without using scare tactics and the challenges of working with clients around the world.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

In part two with Vandana Verma, the conversation continues on mentoring within the AppSec community, involving more women, and communicating the importance of cybersecurity to web designers and coders. Vandana is a Security Architect, an advocate for women and girls in AppSec, and on the board of OWASP.

0:46 Introduction

1:37 Conversation with Vandana

4:00 Streaming meetings

6:00 Spreading the word

9:04 Women in security

12:05 Mentoring in AppSec

11:20 DevSecOps and governance

20:08 Design and automation

24:52 Final positive message

25:54 Closing words

26:30 Outro

Vandana Verma

Twitter @InfosecVandana

https://www.linkedin.com/in/vandana-verma

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second part of the interviews with Vandana Verma,

Vandana Verma is a Security Relationship Leader for SNYK, an advocate for women and girls in AppSec, and on the board of OWASP. Francesco and Vandana discuss the best way to communicate the importance of security without using scare tactics and the challenges of working with clients around the world.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

0:46 Introduction

2:08 Conversation with Vandana

4:05 Importance of AppSec

8:10 Avoid scare tactics

9:20 Fix bugs early

13:44 Working globally with different cultures and timezones

16:46 Best ways to communicate

18:55 OWASP

22:40 Closing words

23:10 Outro

Vandana Verma

Twitter @InfosecVandana

https://www.linkedin.com/in/vandana-verma

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second part of the interviews with Allan Alford, Delivery CISO at NTT data and now CISO at TrustMAPP a cybersecurity startup-like AppSec Phoenix

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Allan Alford is an experienced CISO living in Texas. In part two, Allan Alford answers listener questions about getting involved in Cybersecurity, his path to becoming a CISO, he lists the pros and cons of earning an MBA, and stresses the importance of networking and mentoring. They also discuss how video gaming and role-playing games can translate to real-life leadership skills.

0:45 Recap of Part 1

1:47 Part 2 with Allan

2:20 Balancing MBA with work and life

3:10 Do you need MBA to be a CISO

7:35 Formal mentoring

11:11 Typical path to CISO

13:55 Certifications

19:28 Curiosity and video games

23:08 Final positive message

25:04 Closing words

25:40 Outro

Allan Alford, CISO, Host of Cyber Ranch Podcast

Twitter @AllanAlfordinTX

https://allanalford.com/the-cyber-ranch-podcast

https://hackervalley.com/cyberranch/

https://www.linkedin.com/in/allanalford/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the first part of 2 interviews with Allan Alford, Delivery CISO at NTT data and now CISO at TrustMAPP a cybersecurity startup like AppSec Phoenix

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Allan Alford is an experienced CISO living in Texas. In part 1 of Francesco’s interview with Allan Alford, they discuss multi-factor authentication, the role of CISO, and getting started in cybersecurity. Logical and critical thinking skills are important to work in tech, but equally so are soft and people skills, like communication, leadership, and public speaking.

1:21 Part 1 with Allan

2:30 Masters

3:16 Advice on security awareness

4:23 Multi-factor authentication

7:35 Consumer pressure for security

8:35 Kinds of CISO

10:50 Communication and leadership skills

15:34 Hiring and learning of the job

17:51 Closing words

18:20 Outro

Allan Alford, CISO, Host of Cyber Ranch Podcast

Twitter @AllanAlfordinTX

https://allanalford.com/the-cyber-ranch-podcast

https://hackervalley.com/cyberranch/

https://www.linkedin.com/in/allanalford/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second part of 2 interviews with Greg

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

In part 2 of Francesco’s interview with Greg van der Gaast, they discuss the challenges of working in the cyber security industry and how communicating more clearly and calmly can solve some of those issues. They speculate why security breaches happen and share the appropriate way to react when they do. Greg van der Gaast is a CISO, the author of "Rethinking InfoSec,” an international speaker, people enthusiast, and is passionate about creating information security programs that work.

1:30 Part 1 with Greg van der Gaast

2:46 Experiences in cyber

7:04 Risk management

10:15 Being personable

11:37 People, process, technology

13:05 Avoid toxic work environments

20:17 Closing words

20:40 Outro

Greg van der Gaast

Twitter @SidewaysGreg

https://www.linkedin.com/in/gregvandergaast/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the first part of 2 interviews with Greg

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Greg van der Gaast is a CISO, the author of "Rethinking InfoSec,” an international speaker, people enthusiast, and is passionate about creating information security programs that work. Francesco and Greg discuss the importance of communication skills and being personable in the tech field. In order to avoid a toxic and hostile work environment, everyone needs to have a better attitude, think human-first, and stay calm.

1:30 Part 1 with Greg van der Gaast

2:46 Experiences in cyber

7:04 Risk management

10:15 Being personable

11:37 People, process, technology

13:05 Avoid toxic work environments

20:17 Closing words

20:40 Outro

Greg van der Gaast

Twitter @SidewaysGreg

https://www.linkedin.com/in/gregvandergaast/

Cyber Security and Cloud Podcast hosted by Francesco Cipollone

Twitter @FrankSEC42

CSCP #cybermentoringmonday cybercloudpodcast.com

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second interview with Jane, a returning guest in season 2

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Jane Frankland and Francesco continue the conversation about inclusion, diversity, and supporting women in cybersecurity and tech, a male-dominated industry. Jane Frankland is an award-winning cybersecurity entrepreneur, author, consultant, keynote speaker, women’s activist, and market influencer

1:30 Part 2 with Jane Frankland

5:36 Listener question— tips for implementing change

11:35 Supporting women in tech

15:08 Doing the right thing

17:55 Creating an appropriate and safe workplace

19:45 HR protects company

23:30 Inclusion of people with intellectual disabilities

26:30 Final positive message

28:23 Closing words

28:50 Outro

Jane Frankland

Twitter @JaneFrankland

https://jane-frankland.com

https://www.linkedin.com/in/janefrankland/

https://www.youtube.com/user/JaneFranklandTV

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the First interview with Jane, a returning guest in season 2

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.appsecphoenix.com get a free 30-day licence quoting CSCP https://landing.appsecphoenix.com/register

Jane Frankland is an award-winning cybersecurity entrepreneur, author, consultant, keynote speaker, women’s activist, and market influencer. Jane shares her journey going from being a fashion designer to starting a successful tech company. Francesco and Jane discuss the challenges of breaking into tech, entrepreneurship, starting a business, living in the fourth industrial revolution, and diversity and inclusion in the industry.

1:15 Introducing Jane Frankland

5:20 How Jane got into cybersecurity

6:54 Penetration testing

9:45 Risks of starting a tech business

14:20 Challenges breaking into tech

19:33 Leveraging design skills

23:30 Importance of community

24:05 Abundance mindset

25:40 Women in tech

29:10 Outro

Jane Frankland

Twitter @JaneFrankland

https://jane-frankland.com

https://www.linkedin.com/in/janefrankland/

https://www.youtube.com/user/JaneFranklandTV

CSCP Links

Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

CSCP is bringing back season 1 in a newly remastered version.

This is the second interview with shamane on the subject of risk and Cyber in Australia

We explore with Shamane the cybersecurity market in Australia, events running, and the diversity subject without holding back. Hear this first part of the interview before jumping onto the next one :)

We have all heard about the talent shortfall in cybersecurity and the worrying number of jobs that remain unfilled so we talk about how we can attract and retain staff to the industry and what we can all do to nurture talent.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

This is the FIRST part of the two interviews with Shamane Tan an executive advisor at Privasec. Shamane is the organizer of the Cyber Risk meetup that exploded in popularity in Australia and now counts many locations. Shamane is also the author of a renowned book on Cybersecurity Risk with interviews with many C level execs. Also, Shamane has been speaking at TEDx

Bio

Shamane is passionate about Cyber Risk. She holds a Bachelor of Computer Engineering (Hons) and enjoys the challenge of keeping up to date with the constant evolution of technology & Cyber trends. As Privasec's APAC Executive Advisor, she desires to use her business mindset coupled with her Computer Engineering background, to help businesses bridge their gaps between technical and business spheres. In this day and age, it is crucial for companies to have in place strong & effective governance to protect their current infrastructure/ services. Throughout her career, Shamane has partnered directly with CISOs, CTOs, and Global Heads of IT, Infrastructure and Security to help both enterprises to smaller companies in APAC in their growth strategy. As the author of 'Cyber Risk Leaders' and international speaker, Shamane has frequently been invited to speak on various topics; some recent examples include: - CISO insights from around the globe - The world of the Board Directors - Befriending the Hacker - The Influencers' secret to building key relationships

You can reach Shamane at: https://www.linkedin.com/in/shamane/

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Bringing Back Season 1 All episodes of season 1 are available at: https://www.youtube.com/playlist?list=PLmfEooB4S-vXZ3OsFRrgqd9rIvd99oqI7

View Details

CSCP is bringing back season 1 in a newly remastered version

We explore with Shamane the cybersecurity market in Australia, events running, and the diversity subject without holding back. Hear this first part of the interview before jumping onto the next one :)

We have all heard about the talent shortfall in cybersecurity and the worrying number of jobs that remain unfilled so we talk about how we can attract and retain staff to the industry and what we can all do to nurture talent.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

This is the FIRST part of the two interviews with Shamane Tan an executive advisor at Privasec. Shamane is the organizer of the Cyber Risk meetup that exploded in popularity in Australia and now counts many locations. Shamane is also the author of a renowned book on Cybersecurity Risk with interviews with many C level execs. Also Shamane has been speaking at TedX

Bio

Shamane is passionate about Cyber Risk. She holds a Bachelor of Computer Engineering (Hons) and enjoys the challenge of keeping up to date with the constant evolution of technology & Cyber trends. As Privasec's APAC Executive Advisor, she desires to use her business mindset coupled with her Computer Engineering background, to help businesses bridge their gaps between technical and business spheres. In this day and age, it is crucial for companies to have in place strong & effective governance to protect their current infrastructure/ services. Throughout her career, Shamane has partnered directly with CISOs, CTOs, and Global Heads of IT, Infrastructure and Security to help both enterprises to smaller companies in APAC in their growth strategy. As the author of 'Cyber Risk Leaders' and international speaker, Shamane has frequently been invited to speak on various topics; some recent examples include: - CISO insights from around the globe - The world of the Board Directors - Befriending the Hacker - The Influencers' secret to building key relationships

You can reach Shamane at: https://www.linkedin.com/in/shamane/

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ
Linkedin: https://www.linkedin.com/company/35703565/admin/ 


Twitter: https://twitter.com/podcast_cyber 


Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Bringing Back Season 1 All episodes of season 1 are available at: https://www.youtube.com/playlist?list=PLmfEooB4S-vXZ3OsFRrgqd9rIvd99oqI7

View Details

CSCP is bringing back season 1 in a newly remastered version

This is the second of 2 episode conversation with Lisa Forte

We have all heard about social engineering but as Lisa explains it can be so much simpler than we all think and how virtually every conversation could put you in danger .......

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

This episode is broken down into two parts, this is the first part of the interview with Lisa Forte a social engineer and a fellow Italian. Lisa grew through the rank of police and then took social engineering into the commercial world.

The episode is full of stories and will keep you gripping to your chair to know more. The second episode will follow.

Bio

Lisa forte is a partner at Red Goat Cyber Security, Keynote Speaker, Vlogger, Won the “Top 100 Women In Tech” Award, Social Engineering & Insider Threats expert

As a winner of the "Top 100 Women In Tech" Award I am passionate about cybersecurity, social engineering and most importantly helping organisations establish effective and lasting cultural change amongst staff. Lisa is an established keynote speaker and gets hired to speak around the world sharing my stories and experiences of social engineering, cybercrime and wargaming. Lisa is a passionate and energetic public speaker too recently appearing at conferences such as IPExpo Europe; London Law Expo; Voxxed Days; International Security Expo; MarineTech China and Secure Computing Dublin. Lisa also does a lot of pro-bono security work for the NHS and various charities and care deeply about helping the communities we live in becoming more aware of the growing threat.

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/

Twitter: https://twitter.com/podcast_cyber 


View Details

CSCP is bringing back season 1 in a newly remastered version

This is the first of 2 episode conversation with Lisa Forte

We have all heard about social engineering but as Lisa explains it can be so much simpler than we all think and how virtually every conversation could put you in danger .......

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

This episode is broken down into two parts, this is the first part of the interview with Lisa Forte a social engineer and a fellow Italian. Lisa grew through the rank of police and then took social engineering into the commercial world.

The episode is full of stories and will keep you gripping to your chair to know more. The second episode will follow.

Bio

Lisa forte is a partner at Red Goat Cyber Security, Keynote Speaker, Vlogger, Won the “Top 100 Women In Tech” Award, Social Engineering & Insider Threats expert

As a winner of the "Top 100 Women In Tech" Award I am passionate about cybersecurity, social engineering and most importantly helping organisations establish effective and lasting cultural change amongst staff. Lisa is an established keynote speaker and gets hired to speak around the world sharing my stories and experiences of social engineering, cybercrime and wargaming. Lisa is a passionate and energetic public speaker too recently appearing at conferences such as IPExpo Europe; London Law Expo; Voxxed Days; International Security Expo; MarineTech China and Secure Computing Dublin. Lisa also does a lot of pro-bono security work for the NHS and various charities and care deeply about helping the communities we live in becoming more aware of the growing threat.

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/

Twitter: https://twitter.com/podcast_cyber 


View Details

CSCP is bringing back season 1 in a newly remastered version

Chris will join us in the new season 3 in recording

We talk all things Leadership, Risk Compliance with Chris Hodson CISO at Tanium

After 17 years in cybersecurity, as well as talking all things cyber, Chris talks about the route he took to become a CISO and opens up on how to communicate with others in a similar position.

The episode is brought you by AppSec Phoenix Ltd with the Phoenix platform you can make Vulnerability management for software and organization SMART. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

Chris is a CISO with 20 years of experience working in technology roles. I build and run security organisations that help companies reduce IT and cybersecurity risk. Chris served as a trusted advisor to executives and board members, helping them define well-balanced strategies for managing risk and improving business outcomes. I've worked as a CISO, architect, designer, engineer and DPO for market-leading companies in the energy, retail, media, technology and financial services industries.

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/

Twitter: https://twitter.com/podcast_cyber 


View Details

CSCP is bringing back season 1 in a newly remastered version

In this episode, we talk about all things cyber, from how to establish yourself in the industry and how not being allowed to play Doom when he was just eight years old led Daniel to become a hacker and eventually embark on a career in cybersecurity. Daniel is a hacker by day and by night, creator of the pwndefend CTF, Hackermouse, and many other CTFs. He is also a massive supporter of the community and one of the first to participate in the podcast

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

Bio:

Daniel is an experienced technology and security consultant and he is a mix between technical and business skills. Daniel founded Xservus as a boutique consulting services organisation that uses modern approaches to tackle the security challenges of the organization Daniel is a very active member of the cybersecurity community on Twitter and well known for disrupting status quo and demystifying LinkedIn sales pitches

You can find Daniel in discord, ranting on Twitter or working with friends in the community on CTF challenges, threat intelligence or random security research adventures. I also write on itsm.tools focusing on IT leadership and security!

Daniel also founded and helped the covid cyber response team and featured in a number of articles

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/

Twitter: https://twitter.com/podcast_cyber 


View Details

We reached the milestone of 50 Episodes on season 4 and celebrated with a live with 3 podcasts around the world. This is the recorded session of the live.

Francesco Cipollone interview three hosts of cyber podcasts— Chris Cochran of Hacker Valley Studio, Allan Alford of Cyber Ranch Podcast, Ashish Rajan of Cloud Security Podcast. The four discuss the labour of love for podcasting, hacks for growing an audience, dream guests, post-process, most memorable episodes, and scouting bigger and bigger guests. All agree that passion and consistency are key to having a successful podcast.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:00 Intro

0:47 Introducing Chris, Allan, Ashish

3:45 How similar are App Sec and Cloud Sec

4:03 Chris’s past year podcasting

5:48 Allan’s past year podcasting

7:16 Ashish’s past year podcasting

9:52 Behind the scenes

17:46 Passion and consistency

19:26 Post-process and editing

24:45 Most memorable episodes

32:08 Perks of having a podcast

35:55 Ambitions, goals, dreams guests

37:34 Business side of cyber security

41:32 Scouting guests

51:09 How to connect and final positive message

57:17 Outro

Chris Cochran— Host of Hacker Valley Studio

https://hackervalley.com Twitter @chriscochrcyber https://www.linkedin.com/in/chriscochrancyber/

Allan Alford— Host of Cyber Ranch Podcast

https://allanalford.com/the-cyber-ranch-podcast https://hackervalley.com/cyberranch/ Twitter @AllanAlfordinTX https://www.linkedin.com/in/allanalford/

Ashish Rajan— Host of Cloud Security Podcast https://www.cloudsecuritypodcast.tv Twitter @hashishrajan

Francesco Cipollone— Cyber Security and Cloud Podcast #CSCP #cybermentoringmonday cybercloudpodcast.com Twitter @FrankSEC42

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Sam Stephanyan is an independent applications security consultant and Chapter Leader of OWASP London. Sam explains the history and purpose of OWASP (The Open Web Application Security Project), a non-profit that outlines the Top 10 security concerns. Francesco and Sam also discuss Nettacker, virtual hackathons and meetups, and the various ways to explain to developers the importance of security.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:28 Introducing Sam Stepanyan

2:00 OWASP

4:32 Progress in security

12:16 Security at startups

14:15 Tools to explain security to developers

17:10 Rapid threat modelling

25:00 Open source tools

31:10 OWASP meetups and hackathons

27:14 Nettacker

41:55 Google Summer of Code paid internship

50:53 Final positive message

51:54 Connecting with Sam

52:24 Outro

Sam Stepanyan

Twitter securestep9

sam.stepanyan@owasp.org

https://securestep9.medium.com

https://www.linkedin.com/in/samstepanyan/?originalSubdomain=uk

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Karla Reffold is the COO for Orpheus, the founder of BeecherMadden, and a contributor at Forbes. Francesco and Karla discuss supply chain issues, the recent Solarwind attack and the consequences, recent security breaches, and privacy concerns while working from home.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:28 Introducing Karla

2:13 Cybersecurity Advice

3:15 Solarwind attack & Supply chain issues

8:30 Security soft skills

12:47 Breaking stereotypes of professions

19:16 Work from home privacy concerns

23:07 Risk management maturity

27:52 Final Positive Message

29:40 Outro

Karla Reffold

Twitter @karla_reffold

https://www.linkedin.com/in/karlareffold/

https://www.karlajobling.com

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Guy Podjarny is the Co-Founder and President at Snyk, who’s focused on securing open-source code. Guy is an author, speaker, podcaster, ex-CTO at Akamai, founder of Blaze, and a startup advisor and investor. Francesco and Guy discuss the state of the industry, what it means to be empathetic and empowering, and how to create a fantastic company culture.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:28 Introducing Guy

4:50 State of the industry

8:10 App Sec VS Cloud-Native App Sec

11:45 Shifts in cybersecurity

17:00 Empathy, service, and empowerment

24:50 Snyk

30:22 Vulnerability management

37:48 Journey from CTO to Security

41:45 Company culture

46:14 Diversity in cybersecurity

47:30 Final Positive Message

49:38 Outro

Guy Podjarny

Twitter @guypod

https://www.linkedin.com/in/guypo/?originalSubdomain=uk

https://snyk.io The Secure Developer Podcast https://www.devseccon.com/the-secure-developer-podcast/

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Eddie Jaude is an Open Source expert, the GitHub Star 2020, a passionate DevRel, and a YouTuber with 18,000+ subscribers. Eddie and Francesco continue their conversation about how security and developer teams can work better together. They also discuss Eddie’s growing online community and the importance of diversity and inclusion in the industry.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:38 Introducing Eddie Jaoude

3:55 Mentoring

6:50 COVID effects on Eddie’s community

10:20 Collaboration first, code second

22:10 Building a positive online presence

26:40 Diversity and inclusion

37:15 Outro

Eddie Jaude

Twitter @eddiejaoude https://www.youtube.com/c/eddiejaoude/about https://www.eddiejaoude.io/?r_done=1 https://www.eddiejaoude.io/ Instagram @eddiejaoude

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Craig Ford author of a Hacker I am, an architect turned into a hacker. Craig talks about cybersecurity, industry, working together as well as covering the basics and beginning in the cloud and cybersecurity

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

View Details

AJ Yawn is LinkedIn’s Top Voice 2020, a Veteran, and the Co-Founder and CEO at ByteCheck whose goal is to “make compliance suck less.” AJ shares what it takes to be a successful entrepreneur, taking calculated risks, and why you need to start taking advantage of LinkedIn right now before it’s too late!

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:38 Introducing AJ Yawn

3:57 Overview of the industry

7:06 Compliance and automation

10:50 From consulting to entrepreneur

13:35 Leaving the cooperate world

26:10 Networking on LinkedIn

33:00 Final Positive Message

47:00 Outro

AJ Yawn

https://www.linkedin.com/in/ajyawn/

https://www.infosecurity-magazine.com/profile/aj-yawn/ https://www.bytechek.com

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Martin Knobloch is a Global AppSec Strategist at Micro Focus and the Chapter Leader of OWASP (Open Web Application Security Project) in the Netherlands. OWASP provides free resources and tools in the field of web application security. Francesco and Martins discuss the challenges of working with DevOps and the importance of writing secure code from the start of a project. Don’t fix the symptoms, fix the cause.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30-day licence quoting CSCP https://landing.securityphoenix.com/alpha

0:38 Introducing Martin Knobloch

2:40 OWASP

9:00 Challenges with DevOps

21:05 Advice for security professionals

26:30 Need for regulation

31:00 Communicating code

37:55 SKF- Security Knowledge Framework

43:28 Final Positive Message

43:36 Outro

Martin Knobloch @knoblochmartin

https://owasp.org/www-board-candidates/martin_knobloch https://www.linkedin.com/in/martin-knobloch/?originalSubdomain=nl

OWASP SFK Security Knowledge Framework https://owasp.org/www-project-security-knowledge-framework/

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Michael Fraser is the Co-founder, CEO, and Chief Architect at Refactr, a Seattle-based DevSecOps software startup. He is an Air Force Veteran, serial entrepreneur, and expert in cloud and cybersecurity. They discuss their concern and apprehension around low code, no code, and citizen developers.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

https://www.securityphoenix.com get a free 30 day licence quoting CSCP https://landing.securityphoenix.com/register-phoenix

0:38 Introducing Michael Fraser

6:55 Interest in security and IT

11:20 Impact of pandemic

13:38 Automation

20:05 Vulnerability Mangement

22:30 Citizen developer

32:10 Low code

38:30 Final Positive Message

41:10 Outro

Michael Fraser Twitter- @itascode https://www.linkedin.com/in/itascode/

Refactr https://www.refactr.it @RefactrIT https://www.linkedin.com/company/refactr/

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://cybercloudpodcast.com

View Details

Caleb Sima started his first tech company at only nineteen years old and is currently the VP of Security at Databricks. Caleb is a technologist at heart but had to learn how to manage people as his career progressed. Caleb shares his insights on the industry, no-code tools, and venture capitalism. 

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appsecsmart

0:38 Introducing Caleb Sima

5:06 Starting Spy Dynamics

9:43 Venture capitalism

14:04 Getting hired at Databricks

20:35 Cybersecurity and Machine Learning

24:15 Zero-trust and cloud authorization

27:45 Hyper-growing Silicon Valley tech company

32:00 No-code capability

38:29 Risk management

40:50 Final Positive Message

43:36 Outro

Caleb Sima Twitter @csima https://www.linkedin.com/in/calebsima/ https://github.com/csima Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

HTTP://cybercloudpodcast.com

View Details

Ian Murphy is the Vice President of LMNTRIX and CEO CyberOff. Ian has been working in the industry for over 30 years and his goal is to make Cyber Security a little less dull. Ian shares his early interest in computers and how he’s seen the industry grow and change.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:38 Introducing Ian Murphy

3:45 Covid-related security

7:55 Being authentic and human

14:45 Making social media videos

19:06 Early interest in computers

24:00 Best way to learn

27:44 Tinkerer vs hacker

29:56 Advise to newbies

39:26 Final Positive Message

40:15 Outro

Ian Murphy Twitter @CyberIanUK https://www.linkedin.com/in/ianmurphy/?originalSubdomain=uk https://www.lmntrix.com https://cyberoff.co.uk

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://www.cybercloudpodcast.com 

View Details

Jake Moore formerly worked for the Dorset Police in the Cyber Crime & Digital Forensics Department. He is now the spokesperson for ESET and a Cyber Security Specialist. In this episode, Francesco and Jake discuss paying ransoms, the security threats raised by the pandemic, and investigating murderer’s laptops.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:38 Introducing Jake Moore

5:30 Putting a face to a company

6:40 Phishing and Smishing

10:56 Psychology Myers-Briggs

14:11 Working for the police

17:00 Working during the pandemic

24:00 To pay or not to pay the ransom

28:45 Investigating murder

39:28 Final Positive Message

40:20 Outro

Jake Moore Twitter @Jake_MooreUK https://jakemoore.uk https://www.linkedin.com/in/jakecyber/

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

HTTP://www.cybercloudpodcast.com

View Details

Sasha Rosenbaum is a Sr. Product Manager at GitHub, former developer, and the organizer of the DevOps Days conference. Francesco and Sasha vent some the frustrations of explaining security threats to developers and engineers who are more focused on creating and coding. Sasha also explains about GitHub’s CodeQL, a semantic code analysis engine. Note FYI sasha now has migrated to redhat.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:38 Introducing Sasha Rosenbaum

3:10 Communicate security issues

10:32 GitHub CodeQL

15:15 Security starts with developers and engineers

19:40 Test-able code is better

26:55 Demystifying, not fear mongering

31:02 Biggest frustrations in security

36:22 Final Positive Message

37:44 Outro

Sasha Rosenbaum Twitter @DivineOps Organizer @DevOpsDaysChi Linkedin: https://www.linkedin.com/in/sasha-rosenbaum/ https://www.sasharosenbaum.com

Cyber Security and Cloud Podcast

CSCP #cybermentoringmonday http://cybercloudpodcast.com

View Details

Working in New Zealand, Sarah Young is the Senior Program Manager for Azure Security at Microsoft. Sarah shares her insights on the cybersecurity industry— mainly that there is not enough understanding of how cloud platforms work, even among tech professionals! Sarah also speaks on being a woman in this male-dominated industry.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:38 Introducing Sarah Young

6:30 Security is not about saying no

8:30 View of the cybersecurity industry

13:00 Cloud Adoption

18:45 Microsoft vs other cloud providers

22:34 How Azure works

30:38 Women in Cybersecurity

35:56 Outro

Sarah Young

Twitter- @_sarahyo

Co-host of @AzureSecPod

Linkedin: Sarah Young Linkedin

Cyber Security and Cloud Podcast

CSCP #cybermentoringmonday cybercloudpodcast.com

View Details

Sian John is the EMEA Director of Cybersecurity Strategy at Microsoft for regions outside the US. Sian and Francesco discuss the Shared Responsibility Model, just how secure the cloud is, Office 365, and some of the internal challenges of cybersecurity.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:38 Introducing Sian John

3:05 Working at Microsoft

7:22 Shared Responsibility Model

9:00 COVID-19 effects on VPM

13:48 Regulators and GDPR fines

20:40 Detecting breaches in security

24:00 Preventing identity theft and security attacks

35:11 Diversity in cybersecurity

40:26 Final Positive Message

41:30 Outro

Sian John

Twitter @sbj24

https://www.linkedin.com/in/sian-john/?originalSubdomain=uk

Cyber Security and Cloud Podcast

CSCP #cybermentoringmonday http://cybercloudpodcast.com

View Details

Richard Greenberg is the founder and CIO of Security Advisor LLC, speaker, advisor, and founder of the ISSA-LA Women in Security Forum. Richard is always looking on the bright side and sees failures and challenges as opportunities.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

www.securityphoenix.com

0:41 Richard Greenberg background

4:55 Volunteering at ISSA-LA

9:05 Day to day changes during COVID

10:50 Cyber Security advice

15:30 Learning from failures

25:35 Assessments and pen testing

34:50 Challenges of CISOs

38:40 Final Positive Message

39:30 Outro

Links

Richard Greenberg

Twitter @RAGreenberg

http://rgreenberg.blogspot.com

https://www.linkedin.com/in/richardagreenberg/

https://www.iheart.com/podcast/the-ron-burgundy-podcast-30270227/episode/cybersecurity- 47951911/

Cyber Security and Cloud Podcast

CSCP #cybermentoringmonday

http://cybercloudpodcast.com

View Details

Ashley Taylor, a returning guest, is an information security professional and third level analyst. Having recently started a new position in a large organization, she shares how she stays calm during stressful incident response situations.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:41 Ashley Taylor’s new position 1:55 View of the industry 5:32 Hacktivism 9:20 Incident Response 11:22 Social Engineering 13:50 Cloud Security 15:45 Focus on basics 18:23 Going back to school 24:34 Keeping calm under attack 26:28 Funny story 28:30 Positive message 30:25 Outro

Links Ashley Taylor Twitter @Infosec_Taylor http://ashleytaylor.tech https://www.linkedin.com/in/ashleydtaylor/ 

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://www.cybercloudpodcast.com

View Details

Kim Crawly is an Infosec writer, researcher, and cybersecurity blogger for AT&T. Kim discusses Android VS Apple, the state of the cybersecurity industry, how she got into writing, and her upcoming book.

The episode is brought you by Security Phoenix Ltd with the AppSec Phoenix platform you can make Application Security and Software development finally easy. Follow the tag #appseceasy

0:41 Kim Crawly’s background 8:02 Kim’s interest in technology 9:35 Paying ransomware 12:24 Rise of malicious cryptominers and modular malware 14:38 Cloud Security 18:35 Blogging 24:10 Did we make technology too easy 27:06 Security and usability 29:34 Android VS IOS 32:20 Starting a career in cybersecurity 38:55 Online conferences 42:36 Final Positive Message 44:30 Outro

Links Kim Crawley Twitter @kim_craweley https://www.amazon.com/Kim-Crawley/e/B08L723KHY Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://www.cybercloudpodcast.com

View Details

Charity Wright is a USA army vet and Chinese linguist who transitioned from working in the military to a private intelligence security company. Charity’s exciting career in cybersecurity involves going undercover on the dark web and recovering stolen information. Francesco and Charity discuss some of the ethical dilemmas faced while taking down cybercriminals.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 

0:41 Charity Wright’s military background 2:20 Transition to the private security sector 10:50 Changes in the intelligence field 14:35 Job of a cyber threat analyst 18:00 Going undercover on the dark web 25:10 Ethical dilemmas 34:40 Conferences 38:20 Working for an international company 39:57 Perspective on Chinese security 43:37 Disinformation 46:30 Effects of working from home 52:56 Positive message 53:46 Closing

Links Charity Wright Twitter @CharityW4CTI https://www.crunchbase.com/person/charity-wright

Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

http://www.cybercloudpodcast.com

View Details

Chris Hadnagy is the Cheif Human Hacker of social-engineer.com, an author, Ted Talker, top social engineer, and a sponsor of Innocent Lives Foundation. Chris shares how he is helping to lock up child abusers and the human history of hacking and scams. He urges young people to consider a career in cybersecurity so that companies can remain safe.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience.

1:00 Introducing Chris Hadnagy 3:30 Innocent Life Foundation 14:43 Reporting security vulnerabilities in companies 18:25 Human history of scams and hacking 24:52 Increase in phishing, vishing, and smishing 37:44 “I told you so” learning moment 42:20 Starting a career in social enginnering 46:42 Final Positive Message 50:24 Closing

Links Chris Hadnagy Twitter @humanhacker https://www.social-engineer.com https://en.wikipedia.org/wiki/Christopher_J._Hadnagy https://www.innocentlivesfoundation.org Cyber Security and Cloud Podcast

CSCP

cybermentoringmonday

HTTP://cybercloudpodcast.com

View Details

In this episode, Francesco and Adam Shostack discuss application security and threat modelling. Adam is the author of Threat Modeling: Designing for Security. He helped create CVE (Common Vulnerabilities and Exposure) and is on the review board for Black Hat. He encourages coders and computer engineers to work smarter, not harder.

The podcast is brought to you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 

1:00 Introducing Adam Shostack 6:00 CVE (Common Vulnerabilities and Exposure) 9:46 Finding satisfaction in a job in security 15:00 Frameworks and static analysis 21:22 Threat Modeling 24:50 Work smarter, not harder 29:12 Documentation in DevOps 34:08 4 questions in Threat Modeling 41:32 Positive Message

Links Adam Shostack https://adam.shostack.org Twitter @adamshostack https://threatmodelingbook.com https://www.blackhat.com

Cyber Security and Cloud Podcast

CSCP

http://cybercloudpodcast.com

cybermentoringmonday

View Details

In this episode, we have the pleasure to speak with Geoffrey Hill an experience and fellow devsecops expert, inventor of Tuamantic and the rapid threat modelling methodology.

In this episode, we discuss the path of Geoffrey from financial, to dev, to security. Geoffrey and Francesco have an in-depth conversation about threat modelling and the “application security mafia.”

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience.

1:00 Introducing Geoffrey Hill 9:33 Rapid threat modelling 13:53 Kill chain 16:06 Probability vector 17:09 Black-Scholes model 23:44 Benefits and values of threat modelling 29:44 Application Security is sexy now 30:30 Shift to the cloud 37:30 Positive Message 41:30 Closing

Links Geoffrey Hill Twitter @GHill_security http://www.artis-secure.com/about.html https://www.linkedin.com/in/geoffrey-hill-61b7bb/ Cyber Security and Cloud Podcast

CSCP

AskInfoSec

cybercloudpodcast.com

cybermentoringmonday

View Details

Jenny Radcliffe AKA the “People Hacker,” is the Queen of Social Engineering, and host of Human Factor Security Podcast joins Francesco for an in-depth discussion on her career path in Social Engineering.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 

1:00 Introducing Jenny Radcliffe 2:38 State of the Industry 4:56 What makes a Social Engineers 10:46 Starting a career in Social Engineering 16:45 Childhood memories 26:34 Teaching Social Engineering 29:21 Body Language and NLP 35:00 Connecting with Jenny 37:08 Final Positive Message

Links Jenny Radcliffe Twitter @Jenny_Radcliffe https://humanfactorsecurity.co.uk

Cyber Security and Cloud Podcast

CSCP

cybercloudpodcast.com

cybermentoringmonday

View Details

This episode was long overdue, Stuart the master of wall sticker, the OSINT champion, an icon, a community pillar and a well renown meme is here with us to enlighten us with OSINT

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience.

Stuart Peck, AKA CyberStu, is the Director of Cyber Security Strategy at Zero Day Lab and the founder of The Many Hats Club. In this episode, Stuart shares how he got into the exciting and sneaky career of Social Engineering and the psychological tricks that scammers and hackers use to breach security.

1:00 Introducing Stuart Peck 4:48 Background in Social Engineering 10:05 Confidence in key 12:23 Defending yourself again social engineers 15:09 Phishing emails 18:15 Physical vs digital cyber attacks 21:10 Psychological tricks of social engineering 27:12 Urgency 29:18 Career path of a social engineer 34:53 Positive Message 35:48 Closing

Links Stuart Peck

Twitter: @cybersecstu

Twitter: @TheManyHatsClub

https://www.twitch.tv/themanyhatsclub https://www.linkedin.com/in/itsecurity/?originalSubdomain=uk

Cyber Security and Cloud Podcast

CSCP

cybercloudpodcast.com

cybermentoringmonday

View Details

Ray Redacted is an InfoSec Researcher and Technologist at a global firm that does connectivity and cybersecurity services. He’s also the host of Tribe of Hackers Podcast. He shares how he started his career in cybersecurity and his own security recommendations.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 

Notes:

1:00 Introducing Ray and Tribe of Hackers Podcast 15:46 Origin story Ray Redacted 24:12 Ray’s professional career and “machine learning” 28:38 Started a career in cybersecurity 30:20 Shifts in the industry causing security concerns 33:00 Phishing 43:46 Security recommendation and pie hole 46:19 Facebook is evil 49:58 PCI 55:57 Migration to cloud 10:8:23 Positive Message 10:09:30 Closing

Links Ray [Redacted] rayredacted.com @RayRedacted Cyber Security and Cloud Podcast

CSCP

AskInfoSec

http://www.cybercloudpodcast.com

cybermentoringmonday

View Details

Francesco had the honour to be joined by Matt Stamper an early riser, inspiration and published author as well as cybersecurity personality.

Matt was so kind to get Francesco a signed copy of the Books and when he was stranded in LA due to covid he had them shipped, he was a hero!

Matt Stamper is a CISO (Certified Information Systems Auditor) and Executive Advisor at EVOTEK and one of the authors of CISO Desk Reference Guide, A Practical guide to CISO. Francesco and Matt discuss the difference in privacy laws in Europe and the US. They also discuss the factors a CISO should consider when weighing a risk decision.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience.

1:00 Introducing Matt Stamper 3:36 Current state of the cybersecurity industry 6:23 Role of the CISO 10:22 Rise in ransomeware 13:00 Avoiding distractions 16:46 Risk Decisions 19:16 Integrity and transparency 23:34 European vs US Privacy laws 31:40 Barrier for entry, compliance concerns 35:11 Social Engineering 29:24 Postive message 42:13 747 Enterprise 46:40 Closing

Links Matt Stamper Twitter @mattstamperCISO https://hmgstrategy.com/network/people/matt-stamper

Cyber Security and Cloud Podcast

CSCP

http://cybercloudpodcast.com

cybermentoringmonday

View Details

Francesco had the honour to be joined by Gary an inspiration and published author as well as cybersecurity personality.

Gary Hayslip is the Chief Information Security Officer at Investment living in San Diego and part of the San Diego cybersecurity community.

Gary is a gamer extremely discipled learner and loves technology, sharing his insights from his long and accomplished career in cybersecurity.

Gary shares in this episode how business has changed since COVID and what a wartime CISO does in peacetime and how to return to normality

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience.

1:00 Introducing Gary Hayslip 3:50 Giving back and riding work/life balance 7:17 COVID effects on business 11:30 Security concerns working from home 15:40 Preventing hacks and breaches 20:26 Adjusting to working from home 31:49 Stories of application security 34:15 Advice to a new executive 36:29 Advice to students and young professionals 41:32 Mentorship 44:48 Final positive thought on cybersecurity

Links Gary Hayslip Twitter @ghayslip https://www.linkedin.com/in/ghayslip/

Cyber Security and Cloud Podcast

CSCP

http://www.cybercloudpodcast.com

View Details

In this Episode of the CSCP i have the pleasure to have back one of the amazing guest Allan Alford.

Allan Alford is a veteran CISO, author, speaker, and co-host of the Defense in Depth Podcast in Texas. Francesco and Allan discuss the many changes companies are facing during COVID. The companies with the most prepared BCP and IT teams have adjusted the smoothest into remote working, but there are still security concerns and challenges being out of the office.

Podcast Breakdown 1:00 Introducing Allan Alford 4:05 State of the Cybersecurity Industry 8:47 Telehealth 11:05 Zoom 16:34 Need for perimeters 23:37 Preparedness for COVID 31:36 Predictions about companies going back, going back to work, working remote 42:45 Positive Message on cybersecurity 46:08 Closing

Links Allan Alford https://allanalford.com Twitter @AllanAlfordinTX https://www.linkedin.com/in/allanalford/ https://cisoseries.com

Cyber Security and Cloud Podcast

CSCP

cybercloudpodcast.com

cybermentoringmonday

View Details

This episode of Cyber Security and Cloud Podcast features GitHub Star, Eddie Jaoude. Francesco and Eddie talk about the importance of clear and direct communication between clients and developers and the importance of updating code. There are many complexities in coding to ensure security and prevent hacking down the line.

1:52 Eddie’s background 5:32 Background in Open Source and GitHub 10:25 More than just good code 12:20 Eddie’s coding horror story 22:28 Cost of bad communication 29:37 Issues and opportunities of Open Source 32:10 Two factor authentication 39:48 T-shaped learning 43:46 Final positive message

Links Eddie Jaoude Twitter @eddiejaoude https://github.com/eddiejaoude https://www.youtube.com/eddiejaoude?sub_confirmation=1 https://www.linkedin.com/in/eddiejaoude/?originalSubdomain=uk

Cyber Security and Cloud Podcast

CSCP

cybercloudpodcast.com

cybermentoringmonday

View Details

Episode In this episode, we talk with Dr. Philippe De Ryck a seasoned appsec expert, an inspiration and a fantastic educator, we dive in all things application security. Philip is based in Belgium and he trains developers to protect companies through better web security. Philippe founded Pragmatic Web Security and is passionate about educating others on secure software.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

0:37 Career and background 4:00 State of the cybersecurity industry 8:08 Cheat Sheets and Resources 10:00 Training, Cyber Mentoring Monday 13:03 Explaining Application Security to customers 16:40 Training developers on security 27:11 Treating customer data as if it’s your own 35:11 Learning through experience 38:55 Final positive message

Links Philippe De Ryck

https://courses.pragmaticwebsecurity.com https://twitter.com/philippederyck https://pragmaticwebsecurity.com

https://www.linkedin.com/in/PhilippeDeRyck/

Cyber Security and Cloud Podcast

CSCP

www.cybercloudpodcast.com

cybermentoringmonday

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Episode In this episode, we talk with Emma Heffernan on how she started in Cybersecurity, the benefit of the community (OWASP and Twitter) and what to do to take the career to the next level.

You can find Emma On Linkedin: https://www.linkedin.com/in/emma-heffernan/ or on Twitter https://twitter.com/3mm4h3ff

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

BIO: A big supporter of the Irish cybersecurity movement having assisted & attended many conferences and events, some of which include helping with the running of the ZeroDaysCTF, volunteering for BSidesDublin a community-driven framework for information security community members, she is an active participate in the STEM Aspire Mentoring programme with Dell EMC. Also, the Call for Papers Team Lead & Program team organiser for OWASP Global AppSec Eu, adding that she is also a volunteer for the Dublin Chapter which consists of monthly meetups etc.

Short Bio Francesco is a Public Speaker, out of the box thinker. Francesco is a passionate advocate for security in development and has pushed for more involvement of dev. Francesco is also a keen passionate of Cloud security. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a keynote speaker, Head of the Cloud security alliance UK, and Director of the cybersecurity consultancy NSC42

Social Media Links Follow us on social media to get the latest episodes: Website: http://www.cybercloudpodcast.com/ You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 


Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

In this episode, we explore the application security programme and the human element that lead to a successful programme in ETSI marketplace

We have the honour to have Andrew Peterson Co-Founder and CEO of Signal Science

The podcast is in collaboration with the cloud security alliance UK Chapter and NSC42 Ltd (for more episode visit www.nsc42.co.uk/cscp)

Bio: Andrew Peterson is the CEO and Co-Founder of Signal Sciences. Prior to co-founding Signal Sciences, Andrew has been building leading-edge, highly performing product and sales teams across five continents for +15 years with such companies as Etsy, Google, and the Clinton Foundation. In 2016, O’Reilly published his book Cracking Security Misconceptions to encourage non-security professionals to take part in organizational security. He graduated from Stanford University with a BA in Science, Technology, and Society.

Host Bio - Francesco Cipollone

I’m Francesco, a Cybersecurity Executive/Chief Information Security Officer (CISO) who specializes in strategy and cloud security. Fueled with passion, curiosity and dissatisfaction for the status quo, I believe in protecting identities in cyberspace and creating a safer, more connected world for future generations.

I'm the director of the Cyber Security Consultancy NSC42 www.nsc42.co.uk

In my spare time, I’d love to give back to the cybersecurity community and I'm a keen contributor. I’m the co-author of several books on network and security and collaborate with a

As part of that, I’ve Director of Events for the Cloud security alliance UK and active member of ISC2. I’ve launched the #MentoringMonday community together with the support of Jane Frankland and Tanya Janca. The mentorship community is inclusive with a focus to empower women in cybersecurity as well as young minds. I am a mentor and coach in the community and I’ve launched the activity in order to help the future generation of cybersecurity expert.

I've delivered effective cybersecurity transformation for my client in Financial services such as Nationwide, Charles Taylor, Capita Asset Management, Link Asset Management.

I've also delivered a cybersecurity improvement programme for different sectors, amongst my clients: United Nations (WFP and FAO), National Lottery (Camelot), Vodafone, BT, Telecom Italia.

View Details

In this episode, we have the pleasure to talk with a friend and an inspiration. Clint is one of the nicest and most knowledgeable person I had the pleasure to chat. This concludes...for now...the series on Appsec.

Clint is a seasoned appsec and with his role in NCC Group and the collaboration in silicon valley has explored numerous subject. We met in Appsec Cali where Clint has given an amazing talk on all the tools (you can see the link below).

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

Clint Gibler (@clintgibler) is the Head of Security Research for r2c, a small startup working on giving security tools directly to developers. Previously, Clint was a Research Director at NCC Group, a global security consulting firm, where he helped companies implement security automation and DevSecOps best practices as well as performed penetration tests for companies ranging from large enterprises to new startups. Clint has previously spoken at conferences including BlackHat USA, AppSec USA/EU/Cali, BSidesSF, and DevSecCon Seattle/London/Tel Aviv/Singapore. Clint holds a Ph.D. in Computer Science from the University of California, Davis. Want to keep up with security research? Check out tl;dr sec, Clint's newsletter that contains summaries of artisanally curated, top talks and useful security links and resources from around the web. https://tldrsec.com/

Francesco is a Public Speaker, out of the box thinker. Francesco is a passionate advocate for security in development and has pushed for more involvement of dev. Francesco is also a keen passionate of Cloud security. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a keynote speaker, Head of the Cloud security alliance UK, and Director of the cybersecurity consultancy NSC42

Shows Links:

Here are some of the links I referenced, for ease of inclusion in the show notes: * https://tldrsec.com/ * My BSidesSF slides: https://docs.google.com/presentation/d/1lfEvXtw5RTj3JmXwSQDXy8or87_BHrFbo1ZtQQlHbq0/edit (updated version of the AppSec Cali talk) * See slide 153 for more links/details about scaling threat modelling * What I Learned Watching All 44 AppSec Cali 2019 Talks: - mega summary blog post - https://tldrsec.com/blog/appsec-cali-2019/ 
 * Lessons Learned from the DevSecOps Trenches - some good DevSecOps tips - https://tldrsec.com/blog/appsec-cali-2019-lessons-learned-from-the-devsecops-trenches/ * https://github.com/returntocorp/semgrep - the lightweight static analysis tool I was talking about
 * My new company: https://r2c.dev/ * So people can connect after * https://twitter.com/clintgibler
 * https://www.linkedin.com/in/clintgibler/


View Details

In this episode, we continue the chat on application security. Frank and John had a lovely conversation on Appsec, Startup and silicon valley. John is a seasoned entrepreneur and startupper. We cover the application security and the debate, what reasonable and practical and of course application security weekly.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

John Kinsella was a Silicon Valley entrepreneur until recently – moving up to Seattle in March. His background started in operations, then engineering, then consulting, then startups – almost always with a focus on computer security. Most recently he cofounded Layered Insight, which was acquired by Qualys in 2018. He ran their container security engineering until earlier this year, and he’s now scheming what’s next. He’s passionate about open source and the security community. He co-founded the Silicon Valley chapter of the Cloud Security Alliance, has been active on several CSA working groups, and from time to time mentors individuals and advises startups when he feels he can provide value.

Francesco is a Public Speaker, out of the box thinker. Francesco is a passionate advocate for security in development and has pushed for more involvement of dev. Francesco is also a keen passionate of Cloud security. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a keynote speaker, Head of the Cloud security alliance UK, and Director of the cybersecurity consultancy NSC42

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

Bringing Back Season 1 All episodes of season 1 are available at: https://www.youtube.com/playlist?list=PLmfEooB4S-vXZ3OsFRrgqd9rIvd99oqI7

View Details

In this episode, we talk with the unique Tanya Janca she hacks purple. Tanya Janca launched she hack purple some time ago and now launched the new line of more inclusive training We Hack Purple. Tanya is a friend and a reference figure for appsec around the globe.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

Tanya Janca, also known as ‘SheHacksPurple’, is the founder, security trainer and coach of https://SheHacksPurple.dev, specializing in software and cloud security. Her obsession with securing software runs deep, from starting her company, to running her own OWASP chapter for 4 years in Ottawa, co-founding a new OWASP chapter in Victoria, and co-founding the OWASP DevSlop open-source and education project. With her countless blog articles, workshops and talks, her focus is clear. Tanya is also an advocate for diversity and inclusion, co-founding the international women’s organization WoSEC, starting the online #MentoringMonday initiative, and personal mentoring, advocating for and enabling countless other women in her field. As a professional computer geek of 20+ years, she is a person who is truly fascinated by the ‘science’ of computer science.

Francesco is an Executive, Public Speaker, out of the box thinker. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a well-known speaker, Head of the Cloud security alliance UK, and Director of the cyber security consultancy NSC42

https://www.shehackspurple.dev/

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com

Youtube: https://www.youtube.com/SheHacksPurple

You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

In this episode, we have the pleasure to speak with Chloé Messdaghi, the person with the most radiant smile in all infosec. Chloe is a tough fighter for representation, diversity and rights. We discuss this and other tough subjects in the podcast together with, of course, cybersecurity and conference. You can find more of Chloe on Twitter and follow her during the uncommon journey in ITSP magazine production.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

Bio:

Chloé Messdaghi is the VP of Strategy at Point3 Security. She is a security researcher advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empowered online & offline, she is driven to fight for hacker rights. She is the founder of WeAreHackerz (formally known as WomenHackerz) & the President and co-founder of Women of Security (WoSEC), a podcaster for ITSP Magazine's The Uncommon Journey, and runs the Hacker Book Club.

Twitter https://twitter.com/ChloeMessdaghi

Linkedin: https://www.linkedin.com/in/messdaghi/

Francesco:

Public Speaker, out of the box thinker, Francesco is a passionate advocate for security in development and has pushed for more involvement of dev. Francesco is also a keen passionate of Cloud security. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a keynote speaker, Head of the Cloud security alliance UK, and Director of the cybersecurity consultancy NSC42.

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

In this episode, we have the pleasure to talk with Alyssa Miller, a developer advocate at Snyk. Alyssa has been advocating for security in the development of environment and talking at many conferences like Appsec Cali, RSA and more. We Explore with Alyssa how every Developer can make the transition into Appsec and Devsecops and how despite the new term a lot of organization were doing this long time ago. if you are in banking you want to listen to the show as we give quite few insight on appsec in the fintech and banking environments

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

As a hacker, Alyssa Miller has a passion for security which she evangelizes to business leaders and industry audiences both through her work as a cybersecurity professional and through her various public speaking engagements. Her goal is to change the way we look at the security of our interconnected way of life and focus attention on defending privacy and upholding trust. Alyssa has always had a driving curiosity to understand how the technology works and how existing technologies can be hacked to function in new ways. At the young age of 12, Alyssa got her start by taking a job as a paper carrier to save up enough money to buy her first computer. From the time she brought that computer home from Best Buy, she has taught herself new skills and pushed the capabilities of digital technologies.

Public Speaker, out of the box thinker, Francesco is a passionate advocate for security in development and has pushed for more involvement of dev. Francesco is also a keen passionate of Cloud security. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a keynote speaker, Head of the Cloud security alliance UK, and Director of the cybersecurity consultancy NSC42

View Details

In this episode, we have the pleasure to talk with Phillip Wylie a Pentester and we explore the path to Pentesting, the difference between Blue and Red team and the good things learned. We also explore the Texas cybersecurity community, the meeting and meetups. We explore the Tribe of Hacker and how it was born and evolved.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

Phillip Wylie is the Senior Red Team Lead for a global consumer products company, Adjunct Instructor at Richland College, and The Pwn School Project founder. Phillip has over 22 years of experience with the last 8 years spent as a pentester. Phillip has a passion for mentoring and education. His passion motivated him to start teaching and founding The Pwn School Project a monthly educational meetup focusing on cybersecurity and ethical hacking. Phillip teaches Ethical Hacking and Web Application Pentesting at Richland College in Dallas, TX. Phillip is a co-host for The Uncommon Journey podcast. Phillip holds the following certifications; CISSP, NSA-IAM, OSCP, GWAPT.

Phillip website: https://thehackermaker.com/ The Pwn School Project: https://pwnschool.com/ The Uncommon Journey podcast: https://www.itspmagazine.com/the-uncommon-journey-talk-show-podcast-phillip-wylie-chloe-messdaghi-alyssa-miller Twitter: https://twitter.com/PhillipWylie LinkedIn: https://www.linkedin.com/in/phillipwylie/

Francesco is an Executive, Public Speaker, out of the box thinker. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco is a well-known speaker, Head of the Cloud security alliance UK, and Director of the cyber security consultancy NSC42.

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com You can listen to this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Episode In this episode, we talk with Andy Kennedy, a veteran in the industry and an expert in compliance. We cover a lot of areas from Google Cloud, Continous Compliance and how to make security work in an organization.

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

BIO: Andy is focused on assisting clients to embrace a security-oriented culture through the application of cloud services as part of their digital transformation journey. Areas of specific interest are cloud security and data anonymisation/management solutions for big data and machine learning use cases. Based in the UK, his background and experience centre around Information Security, Software Defined Networking (SDN) and Network Function Virtualisation (NFV). Joining Google in 2017, Andy has more than 20 years of industry experience, including UK & EMEA-level management roles at VMware and Zscaler, as well as technical roles at Nicira (VMware), Juniper Networks, NetScout Systems and Goldman Sachs. Twitter: @packetdiscards Email: packetdiscards@google.com.

Francesco is an Executive, Public Speaker, out of the box thinker. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco held a number of strategic position ranging from Head of Application Security to Head of Security Architecture. Extensive experience with implementing security across multi-cloud providers (Amazon AWS, Microsoft Azure, Google Cloud). Francesco defines himself as driven to elevate the cybersecurity world one organization at a time, embracing an innovative approach to application security to protect the engineering environment. Recognized as a motivational, influential leader who guides high-performing teams to deliver projects on time and exceeding quality expectations, while instilling a culture of best practices and collaboration. Builds lasting relationships with board members and C-level executives. Delivers education and training to members at all levels of an organisation, building awareness for security initiatives while fostering a common security purpose. Internationally renowned public speaker, with multiple interviews in high-profile publications (eg. Forbes), and an author of numerous books and articles, who utilises his platform to evangelise the importance of cloud security and cutting-edge technologies on a global scale.

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com You can listen this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Episode In this episode, we talk with Joe Gray, a resident expert of OSINT and a returning guest on the podcast. Joe has a lot of interests, and we explore some of them in this podcast. We started the conversation on how to get a master at Harvard university, then we moved on Machine learning, Social engineering and how to get a car for cheap

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. 
NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

BIO: Joe Gray joined the U.S. Navy directly out of High School and served for 7 years as a Submarine Navigation Electronics Technician. Joe is currently a Senior OSINT Specialist at Qomplx, Inc. and previously maintained his own blog and podcast called Advanced Persistent Security. Joe is the inaugural winner of the DerbyCon Social Engineering Capture the Flag (SECTF) and was awarded a DerbyCon Black Badge. As a member of the Password Inspection Agency, Joe has placed 2nd in the HackFest Quebec Missing Persons CTF, 5th in the Global Missing Persons CTF IV, both powered by TraceLabs, 2nd in the BSides Atlanta OSINT CTF, and 3rd Place in the 2018 & 2019 NOLACon OSINT CTFs. Joe has independently placed 2nd in the HackFest Quebec SECTF, 4th Place in the DerbyCon OSINT CTF, and 2nd Place in Hacker Jeopardy at Hack in Paris. Joe has contributed material for the likes of TripWire, AlienVault, ITSP Magazine, CSO Online, Forbes, and Dark Reading as well as his own platforms. Joe is the author of a few OSINT tools, such as WikiLeaker and the forthcoming tools DECEPTICON and INTERCEPTICON.

Get his books on Amazon https://www.amazon.com/Joe-Gray/e/B0872CK3S3?ref_=dbs_p_pbk_r00_abau_000000

Francesco is an Executive, Public Speaker, out of the box thinker. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco held a number of strategic position ranging from Head of Application Security to Head of Security Architecture. Extensive experience with implementing security across multi-cloud providers (Amazon AWS, Microsoft Azure, Google Cloud). Francesco defines himself as driven to elevate the cybersecurity world one organization at a time, embracing an innovative approach to application security to protect the engineering environment. Recognized as a motivational, influential leader who guides high-performing teams to deliver projects on time and exceeding quality expectations, while instilling a culture of best practices and collaboration. Builds lasting relationships with board members and C-level executives. Delivers education and training to members at all levels of an organisation, building awareness for security initiatives while fostering a common security purpose. Internationally renowned public speaker, with multiple interviews in high-profile publications (eg. Forbes), and an author of numerous books and articles, who utilises his platform to evangelise the importance of cloud security and cutting-edge technologies on a global scale.

Social Media Links Follow us on social media to get the latest episodes: Website: www.cybersecuritycloudpodcast.com You can listen this podcast on your favourite player: Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 
Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ Linkedin: https://www.linkedin.com/company/35703565/admin/ 
Twitter: https://twitter.com/podcast_cyber 
Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

Podcast Intro

Welcome to the Cyber Security & Cloud Podcast, the podcast where we learn from the cybersecurity professionals how to secure your cloud code and human.

The Podcast focuses on the stories behind the professionals and the anecdotes, gotcha and other warnings that would help you in your cyber career.

The podcast is focused on people and the human element of cybersecurity

Visit us at www.cybercloudpodcast.com for all the episode and please consider supporting us by leaving a review on Apple Podcast and supporting us at www.patreon.com/cscp so we can continue to bring on amazing guests.

The podcast has the following streams

  • CISO, Cybersecurity, Leadership prospective
  • Cloud Security
  • Application Security
  • Social Engineering
  • New Starter in Cybersecurity

Episode In this episode, we talk with Ronald and Chris about how important is to build a community around you of like-minded professional. We explore the benefits of podcasting and how you get connection and conversation that normally you would achieve and our passion for a conversation with industry experts

The podcast is brought you by the generosity of NSC42 Ltd, your cybersecurity partner. Cybersecurity is a complex and different for every organization, and you need the best-tailored service to make sure your customer's data is safe and sound so that you can focus on what's important, focusing on your clients and bringing the best and safest experience. NSC42 Ltd can help you during your cloud transformation, cybersecurity assessment for your compliance checklist on-premises and on the cloud. Want to know more? Visit www.nsc42.co.uk to get your free quote.

BIO: Hacker Valley Is a podcast and community dedicated to hacking/ elevating cybersecurity careers, communities, and individual performance lead by Ron and Chris.

Chris is a cybersecurity professional and leader, with extensive experience building strong cybersecurity programs. I have a deep understanding of risk analysis, threat hunting, and threat intelligence tradecraft across industry sectors and organizations to identify and mitigate attack vectors, trends and cyber threat actors. I am known to be a trusted advisor for security leadership from the boardroom to the SOC floor.

Ron is a leader in security architecture, I assist organizations to scale security controls while reducing complexities that analyst and engineers face. He works closely with analysts, engineers, and enterprise stakeholders to provide production security workflows that are measurable and can grow at scale. Furthermore, I am committed to consistently advocating for team success. I consider myself a lifetime learner who is constantly finding ways to hone my craft in technology.

Francesco is an Executive, Public Speaker, out of the box thinker. Francesco is the Executive director of NSC42 Ltd a UK based cybersecurity consultancy. As an executive, he loves to stay close to the technology but to keep it simple. Francesco is data and result-driven Cyber Security Executive/vCISO highly regarded for planning and executing strategic infosec improvement programs that protect data and technical assets, reduce security risks, and align with long-term organisational goals. Francesco held a number of strategic position ranging from Head of Application Security to Head of Security Architecture. Extensive experience with implementing security across multi-cloud providers (Amazon AWS, Microsoft Azure, Google Cloud). Francesco defines himself as driven to elevate the cybersecurity world one organization at a time, embracing an innovative approach to application security to protect the engineering environment. Recognized as a motivational, influential leader who guides high-performing teams to deliver projects on time and exceeding quality expectations, while instilling a culture of best practices and collaboration. Builds lasting relationships with board members and C-level executives. Delivers education and training to members at all levels of an organisation, building awareness for security initiatives while fostering a common security purpose. Internationally renowned public speaker, with multiple interviews in high-profile publications (eg. Forbes), and an author of numerous books and articles, who utilises his platform to evangelise the importance of cloud security and cutting-edge technologies on a global scale.

Social Media Links

Follow us on social media to get the latest episodes:

Website: www.cybersecuritycloudpodcast.com

You can listen this podcast on your favourite player:

Itunes: https://podcasts.apple.com/gb/podcast/the-cyber-security-cloud-podcast-cscp/id1516316463 Spotify: https://open.spotify.com/show/3fg8AqP4vEi5Im8YKxazUQ

Linkedin: https://www.linkedin.com/company/35703565/admin/ Twitter: https://twitter.com/podcast_cyber Youtube https://www.youtube.com/channel/UCVgsq-vMzq4sxObVonDsIAg/

View Details

In this episode, we will talk with Thom a great experienced Ciso and now leading the adventure of a Lost CISO or CISO in recovery more. We had a good laugh of the inconsistencies of Infosec, the CISSP (pronounce it the way you want it) and the recent debate (is it a master?).

The podcast is in collaboration with the cloud security alliance UK Chapter and NSC42 Ltd (for more episode visit www.nsc42.co.uk/cscp)

Material and BIO:

Bio: https://thomlangford.com/about-me/

Websites:

  • Thomlangford.com
  • Tl2security.com
  • Hostunknown.tv

Films:

  • The Lost CISO: https://www.youtube.com/channel/UCKVpJ0-oKS0hgdLKqBttgdg?view_as=subscriber
  • Host Unknown: https://www.youtube.com/channel/UCTwY3LNRujMskBDbQvKoiBw

Guest Bio:

Thom founded (TL)2 Security and works for himself, although he regularly complains about his boss and work culture. As Chief Information Security Officer of Publicis Groupe, Thom was responsible for all aspects of information security compliance, risk compliance and compliance-compliance, as well as managing the Groupe Information Security compliance Programme. Additionally, the role was responsible for business continuity compliance across the Groupe’s global operations, and as a result, Thom buys three of everything.

Having successfully built security and IT programmes from the ground up, before tearing them down, Thom brings an often opinionated and forward-thinking view of security risk compliance, both in assessments and management, but is able to do so with humour (debatable) and pragmatism (mostly). An international public speaker and award-winning security blogger, Thom contributes to whichever industry blogs and publications will feature him.

Thom is also the sole founder of Host Unknown, a loose collective of three infosec luminaries combined into an unremarkable trio to make security education and infotainment films. Thom can be found online at both thomlangford.com and @thomlangford on Twitter.

Host Bio - Francesco Cipollone

I’m Francesco, a Cybersecurity Executive/Chief Information Security Officer (CISO) who specializes in strategy and cloud security. Fueled with passion, curiosity and dissatisfaction for the status quo, I believe in protecting identities in cyberspace and creating a safer, more connected world for future generations.

I'm the director of the Cyber Security Consultancy NSC42 www.nsc42.co.uk

In my spare time, I’d love to give back to the cybersecurity community and I'm a keen contributor. I’m the co-author of several books on network and security and collaborate with a

As part of that, I’ve Director of Events for the Cloud security alliance UK and active member of ISC2. I’ve launched the #MentoringMonday community together with the support of Jane Frankland and Tanya Janca. The mentorship community is inclusive with a focus to empower women in cybersecurity as well as young minds. I am a mentor and coach in the community and I’ve launched the activity in order to help the future generation of cybersecurity expert.

I've delivered effective cybersecurity transformation for my client in Financial services such as Nationwide, Charles Taylor, Capita Asset Management, Link Asset Management.

I've also delivered a cybersecurity improvement programme for different sectors, amongst my clients: United Nations (WFP and FAO), National Lottery (Camelot), Vodafone, BT, Telecom Italia.