Without trust, society stagnates, economies decline, and businesses fail. This podcast series keeps abreast of the latest trends and challenges in cyber and physical security with interviews, event updates, industry suppliers & government initiatives.
We speak with Dhawal Sharma, Executive Vice President & Head of Product Strategy at Zscaler on the latest innovations in zero trust to enhance security, simplify access management, and significantly reduce legacy infrastructure costs.
Dhawal Sharma is a visionary leader and expert in cloud security who currently serves as Executive Vice President and Head of Product Strategy at Zscaler. Since joining the company in 2012, Dhawal has made significant contributions to its success by leading key product management initiatives that have strengthened the foundation of Zscaler’s solutions and transformed the way businesses approach secure digital transformation.
From 2012 to 2018, Dhawal oversaw all core product management at Zscaler, driving innovation and excellence across the company’s primary offerings. Today, he leads emerging product innovations and core platform responsibilities, focusing on cutting-edge advancements in cloud security, networking, data path optimization, IoT security, Network Function Virtualization (NFV), Network Performance Monitoring (NPM), Data Loss Prevention (DLP), and regulatory compliance. His ability to identify industry needs ahead of the curve has positioned Zscaler as a leader in cloud-native security solutions.
Dhawal’s professional journey spans two decades, during which he has held key product management, product marketing, and sales leadership roles in security, networking, compliance, and network management across both large enterprises and tech startups. Prior to Zscaler, Dhawal worked at Cisco, where he excelled in strategic roles that shaped the security and networking landscape.
An accomplished academic, Dhawal holds a Technical MBA degree with a specialization in Networking and IT Infrastructure from Symbiosis Center for IT. He also holds a Bachelor’s in Engineering degree specializing in Computer Science.
We speak with Deepen Desai, Chief Security Officer & Executive Vice President of Cyber & AI Engineering at Zscaler on the latest zero trust and AI innovations empowering organisations to secure their digital transformation journeys and stay ahead of evolving threats.
With nearly two decades of expertise in cybersecurity, Deepen is regarded as a pioneer in advancing threat intelligence, secure product development, and enterprise protection. Beyond his scope of leading cyber and AI engineering, Deepen also oversees the ThreatLabz team, a world-class security research group focused on identifying emerging threats, analyzing vulnerabilities, and delivering actionable insights to protect organizations at Zscaler. Under his leadership, Zscaler’s award-winning zero-trust architecture continues to evolve, providing businesses with robust defenses against sophisticated attack vectors like ransomware, phishing, and advanced malware.
Before joining Zscaler, Deepen held key security leadership positions at Dell SonicWALL, where he helped develop cutting-edge security solutions and strategies for businesses navigating an increasingly complex threat landscape. His breadth of experience in fields like security operations, threat research, and compliance has established him as a respected authority in the industry.
As we enter the era of agentic AI, we must also address its risks.
At Zenith Live 2025, we speak with Ed Henry, Zscaler, Senior Data Scientist and discuss agentic AI, its potential to streamline operations, and what are some of the key security challenges.
We speak with Phil Tee, Zscaler, EVP, Head of AI Innovations at Zenith Live 2025 in Las Vegas.
Phil and his team are developing new AI advancements to better secure the use of AI, enabling organizations to integrate and leverage its potential. Phil is responsible for driving AI innovations at Zscaler, leveraging their unique data assets and the latest in AI technology to push forward what’s possible in Sec and DevOps for Zscaler customers. His team’s goal is to generate novel offerings in the cyber market and ensure that our customers benefit from the remarkable pace of AI innovation.
Phil brings the experience of three decades in software and AI entrepreneurship, having founded or co-founded Micromuse, RiverSoft, Promethyan Labs, and Moogsoft. Before joining Zscaler, Phil served as the chairman and CEO of Moogsoft until its acquisition by Dell Technologies. Moogsoft was an early pioneer in the use of AI in operations, credited with founding the AIOps market segment. During his tenure, Phil was directly involved in the groundbreaking technology as a primary inventor in more than 50 patents, and authored or coauthored dozens of academic papers. Before Moogsoft, Phil’s roles at RiverSoft and Micromuse—where he invented Netcool—solidified him as a serial disrupter in operations technology.
In addition to his entrepreneurial activities, Phil has advised multiple startups and is an adjunct professor at ASU as well as a visiting researcher at the University of Sussex. Phil has an undergraduate degree in Physics and earned a doctorate in Informatics focused on Network Science and Information Theory from Sussex, where he also sits on the board of the School of Informatics.
We speak with Andreas Hartl, Senior Vice President for the Asia-Pacific and Japan (APJ) region at Zscaler. Andreas is responsible for driving the company's growth and strategic initiatives across the region.
Prior to joining Zscaler, Andreas held senior leadership positions at several leading technology companies, including Aveva, IBM & Microsoft, where he played a pivotal role in expanding market presence and achieving significant revenue growth. His extensive background in sales, business development, and strategic planning has equipped him with a deep understanding of the APJ market and its unique opportunities.
Andreas is known for his ability to build and lead high-performing teams, fostering a culture of innovation and customer-centricity. His strategic vision and execution have been instrumental in driving Zscaler's success in the region, helping organizations securely transform their digital infrastructure.
He holds a Bachelor’s in Applied Sciences, Electrical Engineering & Information Technology from Technical University of Munich as well as a Master’s from University of Applied Sciences Munich. With a strong commitment to excellence and a forward-thinking mindset, Andreas Hartl continues to shape the future of secure digital transformation in the APJ region.
We speak with Ethical Hacker Juan Francisco 'Fran' Bolivar and Sajeeb Lohani, Global TISO for Bugcrowd. Fran successfully claimed 90 bounties as a result of a ServiceNow configuration compromise, with bounties ranging between $100K and $3K.
Fran provides insight into his methodologies, learning outcomes and the challenges of being an ethical hacker.
For more information and to access more, including the Bugcrowd Report series - visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
We speak with Rajeeshwaran Moorthy of Space Marketplace at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
Raj is a strategy and technology leader specializing in space economy commercialization, future foresight, and digital transformation. His work focuses on bridging investment, policy, and technology to help organizations navigate complex challenges, develop strategic roadmaps, and capitalize on emerging opportunities—whether in corporate strategy, AI capabilities, or the evolving space economy.
Raj spoke tt WPS on Data Intelligence, AI & Surveillance in Narcotics Control which explores the complex and often overlooked issue of drug muling where individuals—sometimes coerced or deceived—find themselves transitioning from victims to accused criminals.
Space MarketPlace is a platform dedicated to the space industry, connecting a global community of space professionals, enthusiasts, and businesses. The marketplace offers a wide array of services and applications, ranging from satellite imagery and data analytics to space tourism and satellite launch services.
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv
We speak with Police Colonel David Martinez Vinluan (PNP), the Executive Director of the ASEANAPOL Secretariat at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
As the first Filipino to be appointed as Executive Director since the Secretariat’s establishment in 1981, David highlighted the pivotal role of ASEANAPOL in promoting effective regional police-to-police cooperation, proactive law enforcement responses, and principled multilateralism.
David is also a 2025 Judge for the Top Women in Security ASEAN Region Awards. In support of this initiative, the ASEANAPOL Secretariat has disseminated invitations to all ASEANAPOL Member Countries (AMCs), encouraging them to nominate exceptional women personnel who are champions in their respective fields and who have significantly contributed to advancing the WPS agenda. Through this meaningful partnership, ASEANAPOL is taking proactive steps to: Promote the Awards across all ASEANAPOL Member Countries; Facilitate formal invitations to national police organizations to support and endorse nominations; and Advocate for the creation of dedicated award categories for female police officers, ensuring their efforts and leadership are celebrated across the region.
https://womeninsecurityaseanregion.com/
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv #topwomeninsecurityASEAN
We speak with Carmen Best, Former Chief of Police Seattle at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
Carmen served with the Seattle Police Department for 28 years, beginning as an entry-level patrol officer and later becoming the first African American woman Chief of Police. Skilled in Public Safety, Infrastructure Security, Police Service, Law Enforcement, Police Administration, Management, Criminal Justice, and Crime Prevention.
Carmen serves on the Leadership Council for the United Negro College Fund (UNCF), Seattle as well as a board member for United Way of King County, Young Women’s Christian Association - King County, a member of the St. Jude Advisory Council for Seattle, and the Seattle University Criminal Justice Advisory Committee and member of the Human and Civil Rights Committee (HCRC) for the International Association of Chiefs of Police (IACP). A former member of the IACP Board of Directors - a group with which she maintains affiliation. Additionally, she is a contributor to MSNBC, CNBC and NBC News affiliates.
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv
We speak with Associate Professor Lyndel Bates, School of Criminology and Criminal Justice and the Griffith Criminology Institute at Griffith University at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
Associate Professor Lyndel Bates has research and teaching interests predominantly in road policing, road safety and traffic law enforcement, the intersection of criminology and health and translating research into policy. Lyndel has expertise in report writing, critical analysis, and project design and management. She is an award winning researcher who has presented her work to both national and international conferences. She has also published her research findings in a number of international peer reviewed journals.
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv
We speak with Vince Hawkes, former Commissioner, Ontario Provincial Police of the International Association of Chiefs of Police (IACP) in his role as Director of International Engagement and Partnerships, speaking at the 2025 World Police Summit in Dubai, UAE.
The International Association of Chiefs of Police (IACP) is the world’s largest and most influential professional association for police leaders. With more than 34,000 members in over 170 countries, the IACP is a recognized leader in global policing, committed to advancing safer communities through thoughtful, progressive police leadership. Since 1893, the association has been serving communities by speaking out on behalf of law enforcement and advancing leadership and professionalism in policing worldwide.
Representing IACP, Vince contributed to two panel discussions; capacity building and capabilities sharing, and another on training and exchange in transnational crime response that highlighted the IACP/UAE Ministry of Interior Police Academy Exchange Program. In addition, the IACP staffed a booth to connect with global attendees, sharing information about membership and services.
Vince Hawkes joined the IACP on January 28, as Director, Global Policing in the Office of the Executive Director. Prior to joining the IACP, he served as Commissioner, Deputy Commissioner and worked in other capacities at Ontario Provincial Police, located in Orillia Ontario. Ontario Provincial is
of one of North America’s largest deployed police services comprised of approximately 6,200 uniform members, 2,800 civilian employees and 850 auxiliary members. Vince was responsible for the strategic vision and organizational priorities linked to the provincial government’s policing mandate and the Police Services Act. He also oversaw frontline policing and policing coordination at the local, provincial, national and international committee levels. In addition, he served on the
Board of Directors for the International Association of Chiefs of Police and the State & Provincial Executive Committee (IACP Division).
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv
We speak with John Kilburn, Regional Industry Leader of SAS, Silver Sponsor at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
As the Regional Industry Leader – Law Enforcement and Public Safety at SAS, John leads the development and strengthening of partnerships with Law Enforcement and Public Safety agencies across emerging markets in EMEA and the Asia Pacific region. The role involves driving SAS engagement with heads of investigation, agency leaders, and transformation officers, assisting to revolutionize their digital investigative and intelligence culture through the rationalisation and adoption of cutting-edge technology.
With a distinguished 27-year career in Law Enforcement, John served as a Detective Senior Sergeant with the Queensland Police Service, where he specialized in criminal investigations, security intelligence, and counter-terrorism.
In the late 1960s, eight Southern universities came together to develop a general purpose statistical software package to analyze agricultural data. NC State had always been a leader in developing code for analyzing agricultural data. It was a natural fit to house the project at the university’s Cox Hall because the mainframe there could process enormous amounts of data.
The resulting program – the Statistical Analysis System – gave SAS both the basis for its name and its corporate beginnings.
Since then, SAS has grown to become one of the largest privately held software companies in the world.
MySecurity Media were media partners to the WPS 2025. #Worldpolicesummit #wps2025 #mysecuritytv
Blue Biometrics (Blue) was founded in Australia in September 2017, to develop world class contactless biometric technology, for dual use national security and commercial applications. Blue now also operates companies in the UK and the USA. Prior to founding Blue, the co-founders were involved in pioneering contactless technology.
Blue Biometrics is now delivering to law enforcement the next generation of LEA Blue, software that enables smartphone cameras as contactless fingerprint scanners, ideal for field identification in policing.
We speak with CEO and Founder, Kenneth King at the World Police Summit 2025, held at the Dubai World Trade Centre 13-15 May.
MySecurity Media were media partners to the WPS 2025.
We speak with Hafis Murty, Head of Product Development with AVM Cloud as sponsors to the Cyber Security Asia 2025 Conference, Kuala Lumpur 21-22 April.
Recognized as one of the premier cloud solution providers in Malaysia, AVM Cloud Sdn Bhd has been at the forefront of cloud computing services since 2010. Throughout the past decade, AVM Cloud has established its reputation as Malaysia's foremost Enterprise Cloud Solution Provider, standing shoulder to shoulder with leading global counterparts.
AVM Cloud's robust infrastructure is supported by three state-of-the-art datacentres located within Malaysia, enabling us to offer a comprehensive range of public and virtual private cloud services with expertise in Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Advanced Analytics.
We speak with Siva Dharmaraj, CEO and Founder of Cloud Destinations, a Silicon Valley-based IT leader with partners in Malaysia.
Cloud Destinations has expanded its global footprint, strengthening its presence in the Southeast Asian market and fostering international collaboration in the fields of Digital Transformation, Cloud Computing, Data Engineering, IT security & Software Services.
Cloud Destinations were sponsor to Cyber Security Asia 2025, Kuala Lumpur 21 - 22 April
We speak with Aaron Tay, Technical Solutions Consultant with Manage Engine, as sponsors for the Cyber Security Asia 2025 conference in Kuala Lumpur, 21-22 April.
ManageEngine is a division of Zoho Corporation that offers comprehensive on-premises and cloud-native IT and security operations management solutions for global organizations and managed service providers. Established and emerging enterprises rely on ManageEngine's real-time IT management tools to ensure the optimal performance of their IT infrastructure, including networks, servers, applications, endpoints, and more. ManageEngine has 18 data centers, 20 offices and 200+ channel partners worldwide to help organizations tightly align their business to IT.
We speak with Fabian Lim, Business Development Manager for V Gallant.
As sponsors for the Cyber Security Asia 20205 conference in Kuala Lumpur, 21-22 April, VCI Global introduced V Gallant CyberSecure, an AI-driven, military-grade cybersecurity solution designed for enterprises.
With encrypted backups, real-time threat detection, and AI-accelerated encryption, businesses can now protect their data and ensure operational continuity.
For more information visit https://vgallant.ai/
After three lead episodes we review the key outcomes from the series with our esteemed speakers:
Zeynep Soylu - Sydney Chapter President
Chirag Joshi - Sydney Chapter Board Member
Abby Zhang (pending) - Auckland Chapter Board Member
Bharat Bajaj - ISACA Melbourne Board Director
Jason Wood - Auckland Chapter former President
This week's State of Cybersecurity, Privacy & Trust episode outcomes may be summerised to the following key points:
For the full series visit: https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta.
We present the third session with the State of Trust – Critical to the success of every business
Speakers
Jamie Norton - ISACA Board Member
Jason Wood - Auckland Chapter former President
Reshma Devi - Melbourne Chapter Board Member
Evan Rowse – Vanta
A copy of the VANTA report is available here https://mysecuritymarketplace.com/vanta
A copy of the ISACA report - State of Digital Trust 2024 is available here https://www.isaca.org/resources/reports/state-of-digital-trust-2024
Trust is critical to the success of every business. But building, scaling and demonstrating trust is getting harder for Australian organisations. To meet customer expectations, security leaders and their teams must address complex threats, a growing compliance burden, and increasing risk from their third-party vendor footprint. The rapid adoption of AI technologies only adds to the challenge, requiring more oversight and governance.
Vanta’s second annual State of Trust Report uncovers key trends across these areas of security, compliance and the future of trust. Based on a survey of 2,500 IT and business leaders (with 500 of the respondents from Australia), our research found that more than half (58%) of Australian organisations say that security risks for their business have never been higher.
More than 5,800 digital trust professionals shared their insights for ISACA’s State of Digital Trust research and give their perspectives on:
SPONSOR: Vanta’s trust management platform takes the manual work out of your security and compliance process and replaces it with continuous automation—whether you’re pursuing your first framework or managing a complex program.
For more on the Security & Risk Professional Insight Series visit https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/
For more on IPRAAC – visit Indo-Pacific Robotics, Autonomy, AI and Cyber Conference 7-9 October 2025 – Perth, Western Australia - https://indopacificroboticsconference...
For more information on our sponsor – VANTA – visit https://mysecuritymarketplace.com/vanta
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta.
This session focuses on The State of Privacy - A Challenging Landscape: Lack of training or poor training tops reasons for privacy failures
Speakers
Safia Kazi - ISACA Global - Report Author
Jo Stewart-Rattray - ISACA Oceania Ambassador
Privacy professionals are under growing pressure as they face budget cuts, resource challenges and changes in regulations. According to ISACA's State of Privacy 2025 survey report, almost half (48 percent) expect a budget decrease in the next year and 73 percent indicate expert-level privacy professionals are the most difficult to hire, adding to the stress of keeping data safe and meeting compliance requirements.
The new research from ISACA, the leading global professional association helping individuals advance their careers in digital trust fields, reflects insights from more than 1,600 privacy professionals worldwide.
The study found that 63 percent of privacy professionals say their role is more stressful now than it was five years ago, with 34 percent indicating it is significantly more stressful. They cite the main causes of this stress as the rapid evolution of technology (63 percent), compliance challenges (61 percent) and resource shortages (59 percent).
To find out more visit https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/
To find out more on Vanta visit https://mysecuritymarketplace.com/vanta
Special Virtual Episodes with ISACA Leaders: State of Cyber (Part 1) - Maintaining readiness in a complex threat environment
Speakers:
Jamie Norton - ISACA Board Member
Chirag Joshi - Sydney Chapter Board Member
Abby Zhang - Auckland Chapter Board Member
Jason Wood - Auckland Chapter former President
Bharat Bajaj - ISACA Melbourne Board Director
For the full series visit: https://mysecuritymarketplace.com/security-amp-risk-professional-insight-series-2025/
OVERVIEW
According to ISACA research, almost half of companies exclude cybersecurity teams when developing, onboarding, and implementing AI solutions.
Only around a quarter (26%) of cybersecurity professionals or teams in Oceania are involved in developing policy governing the use of AI technology in their enterprise, and nearly half (45%) report no involvement in the development, onboarding, or implementation of AI solutions, according to the recently released 2024 State of Cybersecurity survey report from global IT professional association ISACA.
Key Report Findings
Security teams in Oceania noted they are primarily using AI for:
Automating threat detection/response (36% vs 28% globally);
Endpoint security (33% vs 27% globally);
Automating routine security tasks (22% vs 24% globally); and
Fraud detection (6% vs 13% globally).
Additional AI resources to help cybersecurity and other digital trust professionals
o EU AI Act white paper
o Examining Authentication in the Deepfake Era
SYNOPSIS
ISACA's 2024 State of Cybersecurity report reveals that stress levels are on the rise for cybersecurity professionals, largely due to an increasingly challenging threat landscape. The annual ISACA research also identifies key skills gaps in cybersecurity, how artificial intelligence is impacting the field, the role of risk assessments and cyber insurance in enterprises' security programs, and more.
The demand for cybersecurity talent has been consistently high, yet efforts to increase supply are not reflected in the global ISACA IS/IT-community workforce. The current cybersecurity practitioners are aging, and the efforts to increase staffing with younger professionals are making little progress. Left unchecked, this situation will create business continuity issues in the future.
Shrinking budgets and employee compensation carry the potential to adversely affect cybersecurity readiness much sooner than the aging workforce, when the Big Stay passes. Declines in vacant positions across all reporting categories may lead some enterprises to believe that the pendulum of power will swing back to employers, but the increasingly complex threat environment is greatly increasing stress in cybersecurity teams; therefore, the concern is not if, but when, employees will reach their tipping point to vacate current positions.
In today’s security world, there are numerous security solutions that can limit access to company data and IT resources and lock down access. However, when it comes to using AI apps and their back-end models, the answer is not so simple. In this session we take a deep-dive into the challenge that Cisco saw looming on the horizon years ago and has culminated in a brand-new solution called Cisco AI Defence.
In today’s security world, there are numerous security solutions that can limit access to company data and IT resources and lock down access. However, when it comes to using AI apps and their back-end models, the answer is not so simple.
We speak with Carl Solder, Chief Technology Officer - Cisco Australia/New Zealand and get his insights into the challenge that Cisco saw looming on the horizon years ago and has culminated in a brand-new solution called Cisco AI Defence.
Prior to this role, Carl was Cisco’s Vice President of Engineering for the Enterprise Networking and Cloud Engineering organisation at Cisco HQ in San Jose, California. In this role he was responsible for Technical Strategy for the Enterprise Network and Cloud portfolio. His portfolio included the Catalyst Routing, Switching and Wireless platforms, the Intent Based Networking Software Innovations around Automation, Assurance, Machine
Learning and Artificial Intelligence as well as the Policy, Identity and Segmentation Software solutions that include Cisco’s Identity Services Engine (ISE).
Through his time at Cisco, Carl has also held various Engineering leadership roles in Cisco HQ San Jose and served as a Distinguished Engineer working on early developments in the area of Mass Scale Data Centre Architectures, OpenFlow and Software Defined Networking.
With more than 35 years of technical, business and sales leadership experience in the ICT industry, Carl has a diverse ICT background that provides great insight into emerging market transitions.
Further Reading/Watching
Cisco AI summit: https://www.ciscoaisummit.com/
AI defence: https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2025/m01/cisco-unveils-ai-defense-to-secure-the-ai-transformation-of-enterprises.html
OWASP Top Ten vulnerabilities for AI white paper -https://genaisecurityproject.com/resource/owasp-top-10-for-llm-applications-2025/
Vanta is the first ever enterprise-ready trust management platform – one place to automate compliance workflows, centralize and scale your security program, and build and manage trust with customers and partners.
We speak with Jadee Hanson, Chief Information Security Officer (CISO) for Vanta. Security is at the heart of what Vanta does —helping customers improve their security and compliance posture - and this starts with their own.
For further information visit https://mysecuritymarketplace.com/vanta/
We speak with Wayne Selk of the Global Technology Industry Association, or GTIA during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
GTIA was formerly CompTIA. The renaming is the result of the sale of the Computing Technology Industry Association’s CompTIA brand in combination with its training and certification business, which will now operate as a separate for-profit company under the CompTIA name. As a result, the existing membership-based trade association, now known as GTIA, continues to operate with the same mission of service to the IT industry.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
Visit gtia.org for details.
We speak with Matthé Smit, Chief Product Officer of Inforcer during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
We speak with Kieran Human, Special Projects Engineer with ThreatLocker during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
Kieran ran a hands-on lab to teach what a Rubber Ducky is and how to create and deploy your own payload.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
We speak with Rob Allen, Chief Product Officer of Threatlocker during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
We speak with Slava Konstantinov, macOS Lead Architect of Threatlocker during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
How vulnerable do you think your Macs are to Malware? Mac expert Slava Konstantinova uncovers the hidden data and security risks lurking in your macOS browsers and apps.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
We speak with Danny Jenkins, CEO & Founder of Threatlocker during Zero Trust World 2025, held annually in Orlando, Florida with IT professionals from 28 countries in attendance.
Zero Trust World 2025 aims to empower IT professionals to embrace a default-deny security posture and build stronger, more resilient cybersecurity frameworks. Attendees gain a deeper understanding of both known and unknown cyber threats and gain actionable strategies to secure their environments and elevate their cybersecurity efforts. Plus, it's a unique opportunity to network and collaborate with the brightest minds in the industry.
This session focused on gaining insights in the latest developments and capabilities for establishing and maintaining situational awareness across the maritime domain, with a focus on security, sustainability and space-earth observation.
For Reference to the Maritime Domain and related activities – welcome to refer to the following links:
https://www.iala.int/technical/mass/
https://smartsatcrc.com/smartsat-crc-and-nz-government-announce-four-new-joint-research-projects-under-the-australia-new-zealand-collaborative-space-program/
https://unseenlabs.space/our-product/
DISCUSSION KEY POINTS
Future of Maritime Autonomous Surface Ships (MASS)
Imagery utilization and availability (TPED) / configuration
On board processing for tip/cue scenarios
Algorithmic considerations for efficient ship detections (optical and SAR)
Synthetic aperture radar (SAR) missions – Australia - NZ
Thomas Southall, Committee Manager
INTERNATIONAL ORGANIZATION FOR MARINE AIDS TO NAVIGATION (IALA)
Thomas is Committee Manager for the International Organization for Marine Aids to Navigation (IALA) directing the technical output aligning deliverables with the organization’s Strategic Vision and Committee Work Programme.
He is also a Trustee and Fellow of the Royal institute of Navigation awarded to him in recognition for his contribution to improved Vessel Traffic Services practice, training and development of policy at national and international levels. He has recently been admitted into the Fraternity of the United Kingdom’s Trinity House as Younger Brother in recognition of his experience and achievements.
He was representative for the International Harbour Masters Association to IALA where he served as participant and Chair of the VTS Operations Working Group. In this role and as IALA Technical Officer, he made significant contribution to the adoption of the new IMO Resolution on VTS.
Before joining IALA, Tom worked for the Australian Maritime Safety Authority as a maritime advisor. Previously, he oversaw the Port of London Authorities' VTS and led a commercial training organization. Tom served as a Navigational Officer in the Merchant Navy.
Dr Carl Seubert, Chief Research Officer
SMARTSAT CRC
Dr Carl Seubert joined SmartSat in May 2021, after nine years NASA Jet Propulsion Laboratory (JPL) as a Senior Aerospace Engineer. After graduating First Class Honours in Aerospace Engineering from the University of Sydney, Dr Seubert completed a Master of Science degree in Aerospace Engineering from the Missouri University of Science and Technology (USA) and a PhD in Aerospace Engineering from the University of Colorado Boulder (USA).
As NASA JPL’s Manager of Formation Control Testbed and Guidance and Control Engineer, Dr Seubert led research and technology development for spacecraft formation flight, future Earth observation missions and precise planetary landing. This includes designing the spacecraft pointing control algorithms and software for the upcoming Europa Clipper mission and the next Mars lander mission.
Kevin Jones, CTO & VP Product
CATALYST (PCI GEOMATICS)
Kevin has a background in remote sensing applications, and began his career working on the RADARSAT-1 mission in Canada. Throughout his career, he has developed and delivered earth observation based solutions to clients globally spanning many applications areas. With the advent of AIS data, Kevin managed the implementation of near real time ship detect service that fused / correlated detections with known ship positions. At CATALYST, we are working to make the deep & rich algorithm stack available for efficient processing of earth observation imagery to enable innovative data as a service solutions for several application areas.
Rachid Nedjar, Chief Strategy & Marketing Officer
UNSEENLABS
Rachid NEDJAR is the Head of Marketing at Unseenlabs. In this role, he focuses on developing tailored content and solutions to Unseenlabs customers involved in maritime security. Prior to joining Unseenlabs, Rachid had been working for Le Poool, giving support and consulting to early stage technological companies or in the process of growth.
Transforming healthcare through innovations in extreme environments.
Humans operating in extreme environments often conduct their operations at the edges of the limits of human performance. Sometimes, they are required to push these limits to previously unattained levels. As a result, their margins for error in execution are much smaller than that found in the general public. These same small margins for error that impact execution may also impact risk, safety, health, and even survival. Thus, humans operating in extreme environments have a need for greater refinement in their preparation, training, fitness, and medical care. (Source: Optimizing human performance in extreme environments through precision medicine: From spaceflight to high-performance operations on Earth)
This session discusses the latest developments in Space & Earth medical science and research with leaders in this specialist, exciting and critically important domain of humans in space.
Panelists:
In the lead up to Zero Trust World 2025 we speak with Rob Allen, Chief Product Officer, ThreatLocker.
ThreatLocker protects endpoints and data from zero-day malware, ransomware, and other malicious software, and provides solutions for easy onboarding, management, and eliminates the lengthy approval processes of traditional solutions. Visit https://www.threatlocker.com/why-threatlocker
ZTW provides plenty of opportunity to learn, develop your skills, and network. Visit https://ztw.com/ #ztw #ztw25
Rob Allen is a seasoned IT professional with over two decades of experience helping businesses embrace technology while navigating its evolving challenges. His career began with a strong technical foundation—working as a system administrator, technician, and engineer—which gave him a unique understanding of both the technical and operational needs of businesses.
Rob spent his early career with an Irish-based MSP, where he served as a trusted advisor to hundreds of small and medium enterprises across diverse industries. During this time, he gained invaluable insight into the challenges faced by many businesses, particularly in the realms of security and cyber resilience.
Joining ThreatLocker in 2021 as VP of Operations for EMEA, Rob's deep technical expertise and commitment to customer success fueled the company’s expansion across the region. Rob currently serves as ThreatLocker Chief Product Officer, driving the development and delivery of innovative security solutions, empowering businesses to safely operate in an increasingly complex threat landscape. Now a recognized expert in cyber and ransomware remediation, Rob has been on the frontlines helping organizations recover from attacks and implement proactive defenses to secure their futures.
Group-IB has released a fascinating case investigation on deep fake fraud.
Group-IB’s Fraud Protection team published a report on how threat actors use deepfake technology to bypass biometric security in financial institutions, including facial recognition and liveness detection. It also details how they recently assisted a major Indonesian financial institution in identifying over 1,100 deepfake fraud attempts.
Criminals used AI-generated deepfake photos to bypass the institutions digital KYC process. Fraudsters are increasingly using deepfake technology to bypass biometric security systems in financial institutions. These criminals are using AI-altered deepfake images, emulators, app cloning, and even virtual cameras to breach multiple layers of security.
We speak with Yuan Huang, Group-IB’s Cyber Fraud Analyst for APAC and discuss the significant social and financial impact of deepfake fraud, with recent losses in Indonesia alone estimated at $138.5 million USD.
The advanced deepfake techniques include app cloning, AI-powered face-swapping and virtual camera applications and we discuss the growing challenges financial institutions face in detecting AI-driven deepfakes and proactive measures financial institutions must take to mitigate risks caused by evolving deepfake technology.
For more information visit https://www.group-ib.com/blog/deepfake-fraud/
For more on the Women in Security ASEAN Region Awards visit https://womeninsecurityaseanregion.com/
Learn what ethical hackers can teach us about the next era of artificial intelligence.
We speak with Michael Skelton, VP of Operations and Sajeeb Lohani, Global TISO for Bugcrowd on the latest edition of 'Inside The Mind Of A Hacker'.
We're also joined by CJ Fairhead who is a Senior Penetration Tester, OSCP Certified, Security obsessed and tinkerer of things. Passionate about combining years of Internal IT experience with his security knowledge for Red Team engagements, CJ is involved in the Bug Bounty scene and works on giving back to the community through tool development, blog posts or just general advice.
In the latest edition of ITMOAH, dive inside the minds of 1000 hackers and see your organization from a new perspective, with the latest analysis on security researchers and their transformative use of generative AI.
For more information and to access more, including the Bugcrowd Report series - visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
We speak with Paul Tyrer, Global VP of IT Channel Ecosystem, Schneider Electric about the impact of AI on Data Centers in the coming years. Generative AI is expected to grow by US$158.6 billion by 2028, according to #canalys
The growth of AI presents data center companies with opportunities to innovate, expand their service offerings, and cater to the evolving needs of AI-driven applications and enterprises. However, it also comes at a cost. Global data center capacity is projected to grow by over 120 GW by 2030, fuelled by AI demand, with energy consumption expected to double to ~1,400 TWh, compared to 1% of today's total. This growth outpaces current power demand trends, posing capacity and sustainability challenges. It requires data center companies to adapt in order to meet the evolving power needs of AI-driven applications effectively and sustainably.
Recorded by MySecurity Media as media partners to the Canalys APAC Forum, Bali, 2-4 December 2024.
We speak with Craig Patterson, Senior Vice President of Global Channels at Aryaka Networks, where he leads the company's channel strategy worldwide, enabling alignment across partner sales and marketing teams and programs in North America, Europe, Africa and the Middle East (EMEA) and Asia-Pacific (APAC).
Patterson joined Aryaka Networks as Channel Chief and Vice President of Sales - Americas in September 2021 where he led go-to-market strategies within the agent, reseller and distribution channels in North America, including the launch of the Aryaka Accelerate Global Partner Program. Prior to Aryaka, Patterson was the West Division Vice President for Lumen's indirect channel. In this role, he led all sales and revenue strategy for a $1 billion organization within the Lumen Channel Partner Program and managed more than 100 sales professionals. Before joining Lumen, Patterson was a founding member of the Level 3 Channel Partner Program, where he grew revenue from $0 to $500 million over 15 years
Aryaka has an increasing focus on channels in the APAC region with a commitment and investment in the region in terms of expanding the Aryaka team and partner recruitment. Aryaka have recently hired two senior additions to the team in Hong Kong and Singapore, to gain increased traction in the regional with partners and customers. Aryaka as an organization are doubling down on the SASE market with their partners in APAC
Recorded by MySecurity Media as media partners to the Canalys APAC Forum, Bali, 2-4 December 2024. #pax8 #mysecuritytv #canalys
We speak with Dina Mathers, Chief Information Security Officer, Carvana alongside Nick Mckenzie, Chief Information & Security Officer with Bugcrowd.
Dina Mathers, who leads Information Security at Carvana - was recently awarded the CISOs Top 100 Accelerated CISOs Award which recognizes leaders who are shaping the future of cybersecurity.
Carvana engages Bugcrowd for bug bounty and vulnerability assessments, with Dina giving candid insights into the scalability, business value and assurances that the Bugcrowd platform provides.
Carvana (NYSE: CVNA) is an industry pioneer for buying and selling used vehicles online. As the fastest growing used automotive retailer in U.S. history, its proven, customer-first ecommerce model has positively impacted millions of people's lives through convenient, accessible and transparent experiences.
Carvana allows customers to browse a nationwide inventory and purchase a vehicle from the comfort of their home entirely online, benefiting from a 7-day money back guarantee, home delivery and more. Customers also have the option to sell or trade-in their vehicle online in seconds.
For more information visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Context is a B Corp™ Certified market intelligence and analytics service provider for the technology industry.
CONTEXT forecasts, analytics and data-management solutions are embedded in the information systems of the world's major technology companies. They track over $200 billion of sales transactions for the global ITC channel every year. Their team of more than 400 staff operates from locations including London, Berlin, Paris, Madrid, Milan, Warsaw, Johannesburg, Istanbul, Dubai, Chicago, Buenos Aires, São Paulo, Mumbai, Auckland, Singapore, Seoul, Taipei, and Tokyo.
We speak with CEO and Founder Howard Davies in Bali at the 2024 Canalys APAC Forum.
As part of our Bugcrowd Leadership Series, we speak with Dave Gerry, Chief Executive Officer of Bugcrowd on his most recent visit to Sydney and the region. His visit for Cybercon in Melbourne also follows with the company recently securing a USD50 million capital growth facility from the Silicon Valley Bank and also appointing Trey Ford, as chief information security officer for the Americas.
We also refer to the latest edition of ITMOAH, which dives inside the minds of 1,000 hackers and the latest analysis on security researchers and their transformative use of generative AI.
For more on the CxO Perspectives and Hack the Hacker Series with Bugcrowd visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Are you prepared for a cyber-attack? Whether you’re managing a national or state-wide critical infrastructure organisation, or you’re a small rural provider with a lean team, the stakes are higher than ever for Australia’s Energy and Utility operators.
Recorded on 20 November 2024 this webinar discusses the SOCI Act 2018 and the Essential Eight Framework, equipping you with practical strategies to strengthen your organisation's cyber resilience.
Speakers:
Tony Campbell - Principal, Security Consulting & Advisory, Kinetic IT
Gayatri Prasad - Information Security Manager, Kinetic IT
Heath Moodie - Senior OT Threat Intelligence Analyst, Dragos
Moderator: Chris Cubbage - Executive Director & Editor of MySec.TV
For more information visit www.kineticit.com.au
To register for the series visit: https://mysecuritymarketplace.com/security-risk-professional-insight-series-kinetic-it/
Fortifying Australia’s Data Resilience and Security Luncheon held 31 October 2024 at the National Press Club in Canberra gathered industry leaders, government officials and cybersecurity experts to explore Australia’s pressing cyber security challenges.
As one of the most attacked countries in the world, Australia faces significant threats that demand urgent attention and innovative solutions. This event will focus on the sovereignty of Australian cyber and data residency, emphasising the need for robust strategies to protect our digital landscape.
At this luncheon, the audience heard from keynote speakers and panellists discussing vital topics, including:
The event featured an open panel discussion discussing the current cyber security landscape.
We spoke with Simon Bush, CEO of the Australian Information Industry Association (AIIA) who participated in the session.
Fortifying Australia’s Data Resilience and Security Luncheon held 31 October 2024 at the National Press Club in Canberra gathered industry leaders, government officials and cybersecurity experts to explore Australia’s pressing cyber security challenges.
As one of the most attacked countries in the world, Australia faces significant threats that demand urgent attention and innovative solutions. This event will focus on the sovereignty of Australian cyber and data residency, emphasising the need for robust strategies to protect our digital landscape.
At this luncheon, the audience heard from keynote speakers and panellists discussing vital topics, including:
The event featured an open panel discussion discussing the current cyber security landscape.
We spoke with Annie Haggar, Partner and head of cyber security for Australia at global law firm Norton Rose Fulbright who participated in the panel.
Fortifying Australia’s Data Resilience and Security Luncheon held 31 October 2024 at the National Press Club in Canberra gathered industry leaders, government officials and cybersecurity experts to explore Australia’s pressing cyber security challenges.
As one of the most attacked countries in the world, Australia faces significant threats that demand urgent attention and innovative solutions. This event will focus on the sovereignty of Australian cyber and data residency, emphasising the need for robust strategies to protect our digital landscape.
At this luncheon, the audience heard from keynote speakers and panellists discussing vital topics, including:
The event featured an open panel discussion discussing the current cyber security landscape.
We spoke with Rafe Berding, Chief Corporate Affairs Officer with AUCloud, AUCyber who chaired the session.
Fortifying Australia’s Data Resilience and Security Luncheon held 31 October 2024 at the National Press Club in Canberra gathered industry leaders, government officials and cybersecurity experts to explore Australia’s pressing cyber security challenges.
As one of the most attacked countries in the world, Australia faces significant threats that demand urgent attention and innovative solutions. This event will focus on the sovereignty of Australian cyber and data residency, emphasising the need for robust strategies to protect our digital landscape.
At this luncheon, the audience heard from keynote speakers and panellists discussing vital topics, including:
The event featured an open panel discussion discussing the current cyber security landscape.
We spoke with Samantha Maher, Head of Government Relations with AUCloud, AUCyber who participated in the session.
Jane Lo, MySecurity Media Singapore Correspondent sat down with Syed Ubaid Ali Jafri, Head of Cyber Defense and Offensive Security at Habib Bank Limited (HBL), at Tech Week Singapore, to get his insights on the sophistication of these threats. We delved into:
Motivations for Attacks on Financial Institutions:
Increasing Accessibility of Cybercrime Tools:
Role of AI in Sophisticated Cyber Attacks:
Challenges in Detecting AI-Driven Phishing and Deepfake Attacks:
Recommendations for Protection:
Recorded 10th Oct 2024, Tech Week Singapore 2024, 12.40pm.
We speak with Venafi's Chief Innovation Officer, Kevin Bocek following the acquisition by Cyberark, effective as 1 October, 2024.
Given Kevin’s role over a decade with Venafi, he gives insight into what the acquisition of Venafi means for the customers of both companies and the market.
We also discuss how the IAMs compliment each other and reflect the preference of customers to reduce the number of vendors, as well as responding to the state of play in terms of companies securing machine identities, and reflecting on the last 10 years how this will develop over the short to medium term.
We also consider the emergence of Quantum and recent news that scientists have cracked a shortened RSA encryption.
Recorded at Impact World Tour in Sydney, an identity security event, where, importantly Kevin has a key message for customers in APAC and Australia.
We sat down with Mr. Yeong to delve into the rising tensions around AI ownership, the need for more transparency, and the importance of human oversight in this rapidly changing field. Our chat took us into the fascinating convergence of quantum tech and law—paving the way for a whole new frontier in tech law. Here is a summary of the conversation under four key areas:
Mr Yeong Zee Kin holds a Master of Laws from Queen Mary University of London and completed his undergraduate law degree at the National University of Singapore. His experience as a Technology, Media and Telecommunications lawyer spans both the private and public sectors. He has spoken and published in areas relating to electronic evidence and intellectual property, as well as legal issues relating to Blockchain and AI deployment.
Zee Kin is an internationally recognized expert on AI ethics. He spearheaded the development of Singapore’s Model AI Governance Framework, which won the UNITU WSIS Prize in 2019. He is currently a member of the OECD Network of Experts on AI (ONE AI). In 2019, he was a member of the AI Group of Experts at the OECD (AIGO), which developed the OECD Principles on AI. These principles have been endorsed by the G20 in 2019. He was also an observer participant at the European Commission’s High-Level Expert Group on AI, which fulfilled its mandate in June 2020.
Zee Kin is also a well-regarded expert on data privacy issues. He has contributed to publications on legal issues relating to data privacy and has spoken at many well-recognised international and domestic platforms on this topic.
Recorded 12th September 2024 3pm. Tech Law Fest, Singapore.
We speak with Chirag Joshi, Founder and CISO at 7 Rules Cyber – an innovative cyber security advisory and thought leadership company. He is a multi-award winning, seasoned cyber security executive with extensive experience leading cyber security and risk management programs in multiple countries across various industries. These include financial services, government, energy, higher education, and consulting. Chirag is the author of the two-bestselling books – “7 Rules to Become Exceptional at Cyber Security” and “7 Rules to Influence Behaviour and Win at Cyber Security Awareness." Chirag is featured in the prestigious CSO30 list of top cyber security executives in Australia. He is a Board Director and Vice President at ISACA Sydney. He is a well-known keynote speaker and has presented at numerous leading international and regional conferences and forums. Chirag has led teams and multi-million-dollar cyber transformation initiatives. He has experience in both IT and OT environments and managing cyber security through mergers and acquisitions.
Cyber Security Asia 2024 took place on 7 – 8 October 2024 at ParkRoyal Hotel, Kuala Lumpur – bringing together top experts and practitioners for in-depth talks, and exclusive networking opportunities. It is a platform for the development of partnerships and strategies and highlights the latest technologies that are ensuring the safety and security of government, industry and individual.
#7rulecyber #mysecuritytv #CSA2024
We speak with Shahmeer Amir, CEO & Co-Founder of SpeeQR and his activities in hacking satellite transmissions.
Shahmeer stands as a globally recognized Entrepreneur, world renowned public speaker and Ethical Hacker, awarded Entrepreneur of the year 2024 for founding multiple startups including Speeqr and also ranking as the third most accomplished bug hunter globally. Shahmeer has been invited to speak at 130 international conferences including Blackhat, DefCON, GiSec, National Security Summit, One Conference, and International Cyber Security. His expertise has been instrumental in assisting over 400 Fortune companies, such as Facebook, Microsoft, Yahoo, and Twitter, in resolving critical security issues within their systems. Shahmeer's entrepreneurial ventures in the technology realm have led to the establishment of multiple startups, with his current role involving the leadership of Speeqr, and involvement in Veiliux and Authiun. He serves as the Cyber Security Advisor to the Ministry of Finance in the Government of Pakistan. His involvement spans various projects, including Deep Sea Tracking, Digital Transformation of Legislation, and the Digitization of Pakistani Cultural Content. As a testament to his influence in the tech industry, he holds a position on the Forbes Technology Council.
Cyber Security Asia 2024 took place on 7 – 8 October 2024 at ParkRoyal Hotel, Kuala Lumpur – bringing together top experts and practitioners for in-depth talks, and exclusive networking opportunities. It is a platform for the development of partnerships and strategies and highlights the latest technologies that are ensuring the safety and security of government, industry and individual.
#mysecuritytv #austaraliainspacetv #csa2024 #spacecyber
We speak with Craig Ford who has over 20+ year ICT and Cyber professional with experience in all three Blue team, Red team and Purple teams across my career with more recently senior consulting and CISO engagements. He is the Head Unicorn (Cofounder and Director) for Cyber Unicorns. Cyber Unicorns is a cyber security consultancy with a big difference; we are on a mission to educate everyday people on how to be safer in this online world we all live in. Yes, we offer the usual cyber security consulting such as vCISO, cyber security strategy and maturity uplift but we do it all with education in mind. People are the key to improving cyber security safety around the world. He is Australia’s best-selling author of three different book series with a total of six books with more in the works. These series are A Hacker I Am, Foresight and The Shadow World.
Cyber Security Asia 2024 took place on 7 – 8 October 2024 at ParkRoyal Hotel, Kuala Lumpur – bringing together top experts and practitioners for in-depth talks, and exclusive networking opportunities. It is a platform for the development of partnerships and strategies and highlights the latest technologies that are ensuring the safety and security of government, industry and individual.
#csa2024 #mysecuritytv #cyberunicorns
We speak with Anita Jacobson, Managing Director and Marina Yahya, Business Advisor at Alpine Integrated Solution Sdn Bhd in the lead up to the Top Women in Security ASEAN Region Awards 2024, Malaysia Awards Dinner.
The Inaugural Asia International Security Summit & Expo (AISSE) 2024 at the Putrajaya International Convention Centre (PICC) will be held from 20th to 22nd January 2025.
AISSE 2025 is rapidly shaping up to become one of the world's most vital internal security events. It is hosted by the Ministry of Home Affairs and Royal Malaysia Police, and is jointly organised by Alpine Integrated Solution Sdn Bhd and Royal Malaysian Police Cooperative Limited.
AISSE is designed as a vital rendezvous point for law enforcement, security, and policing bodies to engage, network and exchange intelligence and expertise and at the same time synergise with security experts, technicians and strategists.
In addition to a high-tech showcase of the latest advanced technological solutions for law enforcement, security and policing, AISSE will feature the first-ever ASEAN+ Security High Roundtable Meeting 2025, comprising approximately 100 high-level delegates, including Ministers of Home Affairs, Internal Security, Interior and Chiefs of Police. These distinguished delegates and their entourage will also be programmed to visit booths of security companies, engage in networking sessions, and attend bilateral meetings.
Besides these Foreign VIP delegations, the event will naturally attract the entire ‘who's who’ from all relevant Ministries, Agencies and Bodies of the Malaysian Government, who will be in attendance throughout the three-day event.
The Inaugural Cybercrime Prevention Summit will also be held in conjunction with AISSE, in collaboration with the National Cyber Security Agency of Malaysia (NACSA). Another notable element of AISSE is that there will be approximately 30 forum sessions which will be run over the three-day period covering all areas of internal security and policing.
For more information on Asia's Premium Security Showcase, AISSE 2025, please visit www.aisse.my
For the Women in Security ASEAN Region Awards visit https://womeninsecurityaseanregion.com/
We sat down with Cassie Crosley to explore the complexities of supply chain risks, particularly within the realm of operational technology (OT).
Comprehensive Supply Chain Security - Crosley detailed the various stages in the supply chain—design, development, and fabrication—where both deliberate and accidental abuses can occur. Each stage presents unique risks, such as compromised design specifications, development flaws, or issues during fabrication. She emphasized that securing the software supply chain requires a holistic approach that goes beyond protecting just software; it must also include firmware and hardware. For example, when working with an Intel chip, securing both the software and firmware associated with that chip is critical. Firmware, which operates at a low level on hardware, is vital for overall system security. Any vulnerabilities in firmware can significantly compromise the entire system, making it essential to secure it alongside software and hardware.
Challenges in Secure by Design - Crosley also noted that while "secure by design" principles often originate from an IT perspective, they may not seamlessly translate to OT environments. This disparity creates challenges, as certain IT security measures, like multi-factor authentication (MFA), may not be practical or necessary in OT due to specific operational needs. Additionally, OT devices are often multi-generational, increasing the risk of outdated security designs. OT systems, such as programmable logic controllers (PLCs) used in industrial settings, have distinct requirements and constraints, necessitating tailored security approaches.
Automated Patching Issues - Crosley highlighted that automated patching in OT environments can pose safety concerns and lead to downtime. Unlike IT systems where automated updates are common, OT systems often require careful, manual handling to avoid disrupting critical processes. Automated patching can interfere with vital safety mechanisms, underscoring the need for controlled and deliberate update management.
SBOM (Software Bills of Materials) - Crosley pointed out that while generating accurate Software Bills of Materials (SBOMs) for modern technologies is relatively straightforward, it becomes more complex for multi-generational OT products due to outdated build practices and the limitations of current scanning tools. While scanners effectively identify open-source components, they struggle with proprietary or commercial libraries, and discrepancies in version identification can be problematic, particularly if certain versions have known vulnerabilities.
Role of AI in Software Development – She also pointed out how AI can quickly analyze vast amounts of data, identifying risks and correlations between projects that would take humans much longer to detect. For example, AI can track a maintainer's contributions across multiple projects to spot potential security risks, such as involvement in both malicious and non-malicious projects. AI is also increasingly offering developers precise guidance on addressing specific vulnerabilities. Instead of generic suggestions, AI now recommends the best code modifications for a given context, speeding up development and enhancing code security.
Supplier Assessment - Crosley advised that supplier assessments should focus on specific aspects of vulnerability management and product security rather than generic compliance questions. It's crucial to inquire about suppliers' vulnerability management practices and their methods for ensuring product security. She emphasized the importance of transparency from suppliers regarding their manufacturing processes, product variations, and supply chain details, advocating for detailed questions to effectively understand and mitigate risks.
Positive Cultural Shift - Crosley shared an encouraging trend where companies are increasingly prioritizing supply chain security. A notable example is a supplier that created a position for a Product Security Officer after facing rigorous scrutiny, reflecting a positive shift towards more robust supply chain security practices.
Cassie Crossley, Vice President, Supply Chain Security in the global Cybersecurity & Product Security Office at Schneider Electric, is an experienced cybersecurity technology executive in Information Technology and Product Development and author of “Software Supply Chain Security: Securing the End-to-End Supply Chain for Software, Firmware, and Hardware”. She has many years of business and technical leadership experience in supply chain security, cybersecurity, product/application security, software/firmware development, program management, and data privacy.
We sat down with Tim Conway and Robert Lee, two leading cybersecurity experts, to discuss pressing issues in OT cybersecurity.
CrowdStrike Lessons Learned
Tim and Robert began by examining the CrowdStrike incident from July 2024. They highlighted the dangers of over-relying on trusted technology without sufficient testing and verification, and the importance of integrating resilience into systems and avoiding a one-size-fits-all security approach.
Cyber Threat Landscape
Robert discussed the rise of sophisticated malware like Fuxnet, Frostygoop and Pipe Dream, designed to target OT systems. Fuxnet was a highly targeted attack aimed at disrupting critical infrastructure in Russia, while Frostygop used similar techniques against Ukraine. In contrast, Pipe Dream serves as a more versatile attack framework applicable to various OT systems.
He underscored an important lesson: even if specific malware isn't reused, studying its tactics can improve our prevention, detection, and response strategies. The key takeaway: threats to OT environments are growing, with increasingly targeted efforts from a range of actors.
Critical Control – ICS Network Visibility
Tim and Robert addressed the challenges of gaining visibility into OT devices. Tim noted that OT environments are diverse and require more than a one-size-fits-all approach. Each environment has unique characteristics that must be considered. While attackers exploit both commonalities and specific features, defenders must balance the need for visibility with the risk of disrupting operations. Legacy systems without modern security features further complicate these efforts. Despite historical challenges in visibility due to limited capabilities and resistance to change, recent technological advances have improved the situation. However, new technologies, such as encryption, introduce additional complexities. A balanced approach, using critical controls as a framework, is essential for prioritizing security efforts and adapting to evolving needs.
Critical Control – Incident Response Plan
Tim and Robert highlighted that many organizations lack specific incident response plans for OT, relying instead on general IT plans. Backup plans for power outages often do not address cyber attack scenarios. Effective OT incident response requires a tailored plan that includes data collection, safety procedures, and appropriate tools. In addition, maturity in incident response involves having a detailed, operationally integrated plan that addresses various scenarios, including handling outages and restoring systems without SCADA support.
OT and IT Convergence
Tim and Robert discussed several crucial aspects of OT security. They noted that the increasing interconnection between IT and OT systems has elevated the risk of attacks transitioning from IT to OT environments. Additionally, remote access, often used for vendor support, presents a significant security threat.
They emphasized the distinct characteristics of OT systems, which necessitate specialized security approaches. Treating OT and IT as identical can lead to dangerous oversimplifications and vulnerabilities. Therefore, security measures must be tailored to the specific needs of OT environments, considering their safety, physical constraints, and unique risks.
Tim and Robert also touched on cyber-informed engineering. Key takeaways include recognizing common attack vectors from IT systems, implementing distinct security strategies for OT, and avoiding the assumption that OT and IT are the same. Tailoring security measures to the specific needs and constraints of OT environments is essential for effective protection.
Celebrating Wins
Finally, Tim and Robert highlighted the importance of celebrating cybersecurity successes, such as defending against VOLTZITE. Recognizing and celebrating these victories can boost morale and encourage teams to continue their efforts.
Tim Conway, Senior Instructor, https://www.sans.org/profiles/tim-conway/
Tim serves as the Technical Director of ICS and SCADA programs at SANS, and he is responsible for developing, reviewing, and implementing technical components of the SANS ICS and SCADA product offerings. A recognized leader in CIP operations, he formerly served as the Director of CIP Compliance and Operations Technology at Northern Indiana Public Service Company (NIPSCO), where he was responsible for Operations Technology, NERC CIP Compliance, and the NERC training environments for the operations departments within NIPSCO Electric.
Robert M. Lee, Fellow, https://www.sans.org/profiles/robert-m-lee/
SANS fellow Robert M. Lee brings to the classroom one of the most valuable and respected of credentials: real-world experience. Robert is the CEO and founder of his own company, Dragos, Inc., that provides cyber security solutions for industrial control system networks.
Further viewing; https://youtu.be/BiUpuRk6pvA?si=xQcx9oiJOxQu0n7H
This episode dives into OT Cybersecurity and discusses:
SCADA, ICS & IIoT Cybersecurity
How do we define an OT-related cyber incident?
What are the leading standards and guidelines for managing OT Cybersecurity and resilience?
Threat intelligence and suitable ISAC models
Vendor platform insights and cyber maturity landscape
Speakers include:
Daniel Ehrenreich, Secure Communications and Control Experts
Lesley Carhart, Director of Incident Response - Dragos
Ilan Barda, Founder - Radiflow
Rahul Thakkar, Team Lead, System Engineering, ANZ, Forescout
Dean Frye, Solutions Architect ANZ, Nozomi Networks
To visit and subscribe to the full series visit https://mysecuritymarketplace.com/security-risk-professional-insight-series/
Further reading:
https://mysecuritymarketplace.com/reports/your-guide-to-nis2-compliance/
https://www.forescout.com/research-labs/ot-iot-routers-in-the-software-supply-chain/
https://cyberriskleaders.com/critical-infrastructure-organisations-remain-poorly-prepared-against-cyber-attacks/
In March 2024, the Australian Senate resolved that the Select Committee on Adopting Artificial Intelligence (AI) be established to inquire into and report on the opportunities and impacts for Australia arising out of the uptake of AI technologies in Australia. The committee intends to report to the Parliament on or before 19 September 2024.
More than 40 Australian AI experts made a joint submission to the Inquiry. The submission from Australians for AI Safety calls for the creation of an AI Safety Institute. “Australia has yet to position itself to learn from and contribute to growing global efforts. To achieve the economic and social benefits that AI promises, we need to be active in global action to ensure the safety of AI systems that approach or surpass human-level capabilities.” “Too often, lessons are learned only after something goes wrong. With AI systems that might approach or surpass human-level capabilities, we cannot afford for that to be the case.”
This session has gathered experts and specialists in their field to discuss best practice alignment of AI applications and utilisation to safety and cybersecurity requirements. This includes quantum computing which is set to revolutionise sustainability, cybersecurity, ML, AI and many optimisation problems that classic computers can never imagine. In addition, we will also get briefed on: OWASP Top 10 for Large Language Model Applications; shedding light on the specific vulnerabilities LLMs face, including real world examples and detailed exploration of five key threats addressed using prompts and responses from LLMs; Prompt injection, insecure output handling, model denial of service, sensitive information disclosure, and model theft; How traditional cybersecurity methodologies can be applied to defend LLMs effectively; and How organisations can stay ahead of potential risks and ensure the security of their LLM-based applications.
Panelists
Dr Mahendra Samarawickrama
Director | Centre for Sustainable AI
Dr Mahendra Samarawickrama (GAICD, MBA, SMIEEE, ACS(CP)) is a leader in driving the convergence of Metaverse, AI, and Blockchain to revolutionize the future of customer experience and brand identity. He is the Australian ICT Professional of the Year 2022 and a director of The Centre for Sustainable AI and Meta61. He is an Advisory Council Member of Harvard Business Review (HBR), a Committee Member of the IEEE AI Standards, an Expert in AI ethics and governance at the Global AI Ethics Institute (GAIEI), a member of the European AI Alliance, a senior member of IEEE (SMIEEE), an industry Mentor in the UNSW business school, an honorary visiting scholar at the University of Technology Sydney (UTS), and a graduate member of the Australian Institute of Company Directors (GAICD).
Ser Yoong Goh
Head of Compliance | ADVANCE.AI | ISACA Emerging Trends Working Group
Ser Yoong is a seasoned technology professional who has held various roles with multinational corporations, consulting and also SMEs from various industries. He is recognised as a subject matter expert in the areas of cybersecurity, audit, risk and compliance from his working experience, having held various certifications and was also recognised as one of the Top 30 CSOs in 2021 from IDG.
Shannon Davis
Principal Security Strategist | Splunk SURGe
Shannon hails from Melbourne, Australia. Originally from Seattle, Washington, he has worked in a number of roles: a video game tester at Nintendo (Yoshi’s Island broke his spirit), a hardware tester at Microsoft (handhelds have come a long way since then), a Windows NT admin for an early security startup and one of the first Internet broadcast companies, along with security roles for companies including Juniper and Cisco. Shannon enjoys getting outdoors for hikes and traveling.
Greg Sadler
CEO | Good Ancestors Policy
Greg Sadler is also CEO of Good Ancestors Policy, a charity that develops and advocates for Australian-specific policies aimed at solving this century’s most challenging problems. Greg coordinates Australians for AI Safety and focuses on how Australia can help make frontier AI systems safe. Greg is on the board of a range of charities, including the Alliance to Feed the Earth in Disasters and Effective Altruism Australia.
Lana Tikhomirov
PhD Candidate, Australian Institute for Machine Learning, University of Adelaide
Lana is a PhD Candidate in AI safety for human decision-making, focussed on medical AI. She has a background in cognitive science and uses bioethics and knowledge about algorithms to understand how to approach AI for high-risk human decisions
Chris Cubbage
Director - MYSECURITY MEDIA | MODERATOR
For more information and the full series visit https://mysecuritymarketplace.com/security-risk-professional-insight-series/
In this interview, we sat down with Greg Smith (Head of Global Product and Solution Marketing, Certinia) to get his insights into the stages of data maturity within the AI adoption journey.
Greg advices that a key distinction in the nature of data handling between generative and predictive AI. Unlike predictive AI, which primarily analyzes existing data, generative AI creates new data from existing information. This fundamental shift necessitates a robust data strategy aligned with AI objectives to maximize the technology's potential.
The maturity model outlines a progression from fragmented data usage to a sophisticated, integrated approach. Organizations initially leverage external data for efficiency gains, but internal data becomes crucial for deeper insights and influencing business metrics. As AI adoption matures, a focus on closed-loop systems emerges, where predictions are continuously refined based on real-world outcomes. This journey involves both technological and cultural transformations, with early stages emphasizing technology and later stages prioritizing cultural changes such as data governance and AI skill development.
The ultimate goal is to transition from efficiency gains to improved decision-making and scaled impact.
Greg Smith, Head of Global Product and Solution Marketing, Certinia.
A primary focus of Greg’s is to help services organizations of any size run a more efficient, profitable, and data-driven services organization.
Recorded at SuperAI Singapore, 6th June 2024, 2.30pm.
We speak with Nick McKenzie, CI&SO and Sunil Joshi, Head of Digital & Communication Solutions, APJC, Orange Business about the CISO perspectives in the Asia Pacific Region.
For the full interview and to join the series visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Nick McKenzie, CI&SO with Bugcrowd & Sumit Bansal, VP Asia Pacific & Japan, BlueVoyant discuss CxO perspectives on supply chain defence and Third Party Risk Management (TPRM).
To join the series visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Unlock the secrets of effective threat management with cybersecurity experts plus representatives from the Hacker community. This series will dive into the realm of cybersecurity and cybercrime analytics as our line-up of hackers and technologists debate the crucial role ethical hacking plays in fortifying digital defences.
This includes exploring the 'living off the land' strategies, offensive best practices, and insights on harnessing the ethical hacker's prowess to stay one step ahead in the ever-evolving threat landscape. Don't miss this illuminating series on proactive cybersecurity measures that can redefine the way organizations safeguard their digital assets.
Casey Ellis, Chief Strategy Officer with Bugcrowd was originally a hacker before becoming an entrepreneur, pioneering crowdsourced cybersecurity. He has advised the US Department of Defence, Australian and UK intelligence communities, plus US House and Senate legislative initiatives including pre-emptive protection of cyberspace ahead of the 2020 presidential elections.
Saj Lohani, is a celebrated Whitehat hacker and in the Hacker Hall of Fame for Amazon, Yahoo, Github, AT&T, US Defense and others. At Bugcrowd his role is Global TISO & Snr Director, Cybersecurity.
To join the series visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Hot on the heels of Bugcrowd recently achieving Unicorn status, following their recent USD $102 million fund raise, Bugcrowd's CEO Dave Gerry and founder and Chief Strategy Officer, Casey Ellis outline Bugcrowd’s vision for the future and plans for growth and expansion throughout the Asia Pacific region in 2024/5 and beyond.
Dave Gerry has been in the AppSec market for nearly a decade and has held key leadership positions within several cybersecurity companies such as WhiteHat Security, Veracode, Sumo Logic, and The Herjavec Group. Dave is passionate about building programs that are repeatable, scalable, and predictable, helping to drive customer business outcomes and technical value.
Casey Ellis was originally a hacker before becoming an entrepreneur, pioneering crowdsourced cybersecurity. He has advised the US Department of Defence, Australian and UK intelligence communities, plus US House and Senate legislative initiatives including pre-emptive protection of cyberspace ahead of the 2020 presidential elections.
To join the series visit https://mysecuritymarketplace.com/bugcrowd-register-to-access/
Prior to Joining Seaco as CIO, Damian Leach held the position of Chief Technology Officer for Workday Asia Pacific and Japan. Prior to his CTO position at Workday Damian spent 13 years in the Banking and Finance industry in Global Technology roles, most recently working for Standard Chartered Bank based in Singapore. Damian led the Digital Transformation program for the Bank to move to the cloud and pioneered Voice Biometric technologies for the retail Banking customers.
Prior to coming to Asia, Damian spent many years managing professional services teams to develop core banking interactive technology systems in Europe.
Damian is a certified AI professional having studied AI Bias and Governance at NTU and also completed an EMBA in Business Administration focused on Asian Leadership and Entrepreneurship with overseas segments in Wharton Penn university and UC Berkley HaaS.
In his spare time Damian coaches, mentors, and is a panelist on startups / innovation contest across Asia.
In this interview, Damian shares the highlights of how Seaco, a global company HQ in Singapore leverages a network of shipping ports and depots and has over 3million TEUs in circulation. The Seaco IT team in partnership with the business are running a series of experiments with AI and Big data to help it adapt to stay ahead of the curve. While there is a lot of hype surrounding AI, Damian emphasizes the importance of understanding the core business problems before jumping to technology solutions.
He introduced the ACE framework (Analytics, Conversational, and Experience) which can help pinpoint the most relevant business cases for AI adoption. For instance, at Seaco, they evaluated 30 potential use cases and narrowed it down to 3 that deliver the biggest boost to productivity and revenue.
However, successful AI adoption goes beyond technology. Damian highlights the importance of employee and stakeholder buy-in. This means addressing fears of job displacement and showcasing how AI can actually enhance productivity. For example, he explains how success stories from pilot projects can pave the way for realizing the technology's full impact.
He also emphasizes fostering a culture of "psychological safety" where employees feel comfortable experimenting with new technologies. Looking to the future, he acknowledged that AI presents both opportunities and challenges for business leaders. As such, it’s essential to have a clear vision and strategy in place, along with a commitment to ongoing learning and development for his employees.
Recorded 29th May 2024, ATxSG Singapore Expo, 12.30pm.
In this interview at SINCON 2024, Dr. Joshua James, a Regional Counter Cyber Crime Coordinator for the United Nations Office on Drugs and Crime (UNODC), shared his insights on the Regional Counter-cybercrime programme at UNODC.
Dr. James argued that while law enforcement agencies are getting better at responding to cybercrime, the cyber criminals are also getting better at what they do. This is because cybercrime is a business for them, and they invest heavily in security measures to protect their operations.
He believes that the key to defeating cybercrime is for governments to see their citizens as assets rather than liabilities. If people are viewed as assets, then more will be invested in educating them and giving them the tools they need to protect themselves online.
He also said that international cooperation is essential in the fight against cybercrime. The current system for international cooperation, called mutual legal assistance, was created before the internet and is not effective for cybercrime. New tools and methods for international cooperation are needed.
In conclusion, Dr. James said that he is confident that cybercrime can be defeated, but it will take a lot of work from governments and citizens alike.
Recorded 23rd May 2024, 10.30am, SINCON 2024, Singapore.
Dr. Joshua James is the United Nations Office on Drugs and Crime (UNODC) Regional Counter-Cybercrime for Southeast Asia and the Pacific, based in Bangkok, Thailand. He and his team implement counter-cybercrime programme in the region through capacity building and awareness programmes at all levels of government. He has worked as a seconded researcher with the Irish Police Computer Crimes Investigation Unit, INTERPOL’s Financial and High-Tech Crime Unit, and the Korean National Police. He has also worked closely with public and private sector groups to raise awareness about cybersecurity and cybercrime issues. He completed his Bachelor’s degree in Network Security from Purdue University, and his PhD in Computer Science with a focus on automating human inference in investigations from University College Dublin.
In this interview, we speak with Mac Munsayac, Head of Customer Experience at Philippine Airlines, to explore the transformative role of AI in the aviation industry. Mac elaborates on the integration of generative AI and tools to enhance customer interactions by providing personalized, proactive, and frictionless experiences, especially in scenarios involving flight disruptions and service-related concerns.
He underscores the significance of recognizing AI's limitations and stresses the necessity of human intervention in high-risk tasks to ensure accuracy and reliability. Training employees effectively and maintaining ongoing communication are crucial to successfully implementing AI. Mark highlights that starting with high-volume, less complex pain areas allows for immediate impact and smoother adoption.
Using the example of checking flight statuses—a high-volume but straightforward task—he illustrates how AI can significantly reduce customer queries and improve service efficiency. This approach serves as a training ground, gradually extending AI's application to more complex scenarios. Mark also touches on the importance of defining clear metrics for operational efficiency, customer experience, and cost savings to measure AI's success.
Ultimately, he advises organizations to adopt a phased approach, beginning with manageable tasks to build trust and progressively enhancing AI capabilities. This ensures that AI is leveraged effectively to improve customer experiences and operational efficiency while managing risks and expectations realistically.
Mac Munsayac, Head of Customer Experience, Philippine Airlines: A dynamic leader with 20 years of diverse leadership experience spanning global finance, business process outsourcing, and aviation. Currently serving as the head of PAL Customer Experience, he excels in fostering innovation, problem-solving, and maximizing organizational performance. In this capacity, he oversees initiatives aimed at enhancing passenger satisfaction, streamlining services, and elevating the overall customer journey. Beyond his professional pursuits, Mac is an avid traveler, deeply passionate about immersing himself in diverse cultures and experiences.
Recorded 8 May 2024, 3pm, World Tour Essentials Asia 2024, Singapore Marina Bay Sands Convention Centre #mysecuritytv
As Vice President and CTO, Solutions, for Salesforce ASEAN, Gavin Barfield leads a team of Salesforce engineers across the region to develop and drive integrated technology solutions for Salesforce customers. Gavin works closely with customers in ASEAN on their digital transformations, bringing together the full value of the Salesforce platform to drive positive business outcomes.
A seasoned IT veteran with over 20 years of experience, Gavin has a deep technology background in areas like IT infrastructure, enterprise architecture, cybersecurity, and program management for a variety of industries. Prior to joining Salesforce, he has held C-level positions managing IT and transformation for some of Southeast Asia’s largest companies, such as Ayala Corporation and Meralco. Gavin also brings many years of experience in management consulting into his work for customers.
Gavin has a passion for emerging technologies and he regularly speaks at international conferences and other forums on the future of disruptive technologies and how they affect people and work.-
In this interview, Gavin discusses how, to drive AI adoption and reap the benefits of AI, businesses need accurate, complete data and humans in the driver’s seat. He highlights several key points:
• Trust and Value Gaps: Two main barriers to AI adoption are the trust gap and the value gap. Trust in generative AI is essential, as companies need to ensure that AI outputs are accurate, unbiased, and secure.
• Human at the Helm: Gavin emphasizes the importance of having humans oversee AI operations. AI should complement human work by enhancing capabilities while maintaining transparency and trust with customers.
• Quality Data: AI systems need to be grounded in high-quality, trusted data. Many companies struggle with AI outputs due to a lack of trust in the data used to train these models.
• Use Case Awareness: Understanding the appropriate use cases for AI is crucial. Companies need to educate employees and align AI implementations with specific business problems to maximize benefits.
• Governance and Training: Effective governance and training are necessary to build trust in AI. Organizations should focus on data accuracy, transparency, and the role of AI as a supportive tool, not a replacement for humans.
• Security and Privacy: Protecting customer and company data is paramount. Salesforce has implemented a trust layer that masks personal information, uses secure gateways, and ensures data is not retained by large language models (LLMs).
• Future of AI: Gavin anticipates that within a year, the AI landscape will evolve with more specialized LLMs tailored to specific industries and regions. Trust, security, and embedding AI into everyday workflows will remain critical factors for successful AI adoption.
Recorded 8th May 2024, 12noon, Singapore Marina Bay, Salesforce World Tour Essentials 2024 Singapore
In this interview at Black Hat Asia 2024, we spoke with Adrian Wood and Mary Walker, security engineers from Dropbox, about the critical issues surrounding AI security, backdoors, and malware.
Adrian and Mary explained that many users rely on pre-existing machine learning (ML) models from public repositories rather than creating their own. This introduces vulnerabilities similar to those found in open-source software. Using in-house data requires careful handling to avoid bias and unintended consequences, while third-party models can be compromised.
They emphasized that downloading and running models from the internet can introduce malware. Attackers can backdoor models to alter their functions or insert malicious code, posing significant threats, especially in sensitive industries.
Adrian and Mary also stressed the importance of understanding the ML environment, ensuring proper logging, and having incident response plans in place. Companies should prepare by conducting tabletop exercises and securing their supply chains.
For more educational information on machine learning: https://gist.github.com/5stars217/236bab5d1d8d50e9785a4136aca8cf20
Dropbox, Security Engineer - Adrian Wood, aka threlfall, currently works for Dropbox on their red team. He has worked as a red team consultant for WHITEHACK, a company he founded, and later as a lead engineer for an offensive security research team at a US bank. His research recently has been in supply chain attacks on CI/CD and ML systems, which includes maintaining the offsec ml playbook and has presented on these topics at DEFCON 30, 31, the DEFCON AI village, Cackalackycon and more.
Dropbox, Security Engineer - Mary Walker, aka mairebear, currently works for Dropbox on their threat intelligence team; she splits her time at work between research (primarily focused on ML) and building tooling to help her team move faster. She's previously worked at a major online retailer on their malware analysis and forensics team, a US bank on their red team, and an energy company in their SOC. Her background is primarily in DFIR and malware analysis, with a keen interest in production environments.
Recorded 18th April 2024, 4.30pm, BlackHat Asia 2024, Singapore
Now in its fourth year we'll be starting this year's series at a heightened time of risk and significant activity across the security domain - the opening episodes will be discussing how these events impact private security and emergency services and what may be the broader requirements and implications.
To open the series, which will run regular episodes of live webinars, pre-recorded interviews and in-person events, we wanted to open with the current state of play – regional conflicts in the Middle East and Europe with a steadily growing risk of an Indo-Pacific conflict and how this will and may impact on the private security and emergency management sector.
In this episode we're joined by:
Paul Riley, Director, Foreign Risk at Curtin University
Bryan de Caries, CEO, Australian Security Industry Association
Dr Shannon Ford, Faculty of Humanties, Curtin University
Prof Sissel Jore, visiting Professor with Edith Cowan University
Webinar title: Requirements and implications on the private security sector in a phase of multi-region conflict
• Implications of war (and pre-war) in the Indo-Pacific and impacts on the private security sector
• Alignment and consistency of national security advice
• Trust in information systems and delivery/interpretation
• Current and required national response frameworks should war break out in the Indo-Pacific
• Learning outcomes from the Pandemic – what went wrong and what needs to change?
Now in its fourth year we'll be starting this year's series at a heightened time of risk and significant activity across the security domain - the opening episodes will be discussing how these events impact private security and emergency services and what may be the broader requirements and implications.
To open the series, which will run regular episodes of live webinars, pre-recorded interviews and in-person events, we wanted to open with the current state of play – regional conflicts in the Middle East and Europe with a steadily growing risk of an Indo-Pacific conflict and how this will and may impact on the private security and emergency management sector.
In this episode we're joined by:
• Dr Malcolm Davis, Senior Analyst, ASPI
• Stephen Beaumont AM, Chair, Critical Infrastructure ISAC and
• Gill Savage, Senior Fellow, ASPI
Webinar title: Requirements and implications on the private security sector in a phase of multi-region conflict
• Implications of war (and pre-war) in the Indo-Pacific and impacts on the private security sector
• Alignment and consistency of national security advice
• Trust in information systems and delivery/interpretation
• Current and required national response frameworks should war break out in the Indo-Pacific
• Learning outcomes from the Pandemic – what went wrong and what needs to change?
We speak with Alina Tan, Ethical Hacker and Security Architect based in Singapore.
Alina is a former Top 30 Women in Cybersecurity Singapore (now the Top Women in Security ASEAN Region Awards).
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
We speak with Col Francel Margareth Padilla-Taborlupa, Armed Forces of the Philippines Spokesperson.
A C4S Officer with 27 years experience in Technology and Security, Francel is an International Lecturer, Moderator/Panelist and experienced Information Technology Professional with a demonstrated history of working in the Army Management Information Center catering to IS needs for the whole Armed Forces of the Philippines.
Francel is a former Top Women in Security ASEAN Region Awards finalist and Judge.
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
We speak with THNG, Chin Hwee, Vice President, Public Safety & Security, ST Engineering and NG Yeow Boon, Deputy Chief Executive (Development), HTX at the inaugural Milipol Asia-Pacific - TechX Summit (MAP-TXS) that took place from 3 to 5 April 2024 at Sands Expo & Convention Centre, Singapore.
Co-organised by Singapore’s HTX, GIE Milipol, and Comexposium Singapore, the biennial event comes under the auspices of the Ministry of Home Affairs, Singapore and the Ministry of the Interior of France. Milipol Asia-Pacific’s trade exhibition will showcase the latest innovations in homeland security, and the TechX Summit will host prominent Government officials, industry leaders, and academia in a high-level conference.
For more information visit https://innovd.stengg.com/spotlight/milipolap-2024?utm_campaign=map24-pss&utm_source=mysec&utm_medium=banner&utm_content=static
What are the strategic directions for AI in homeland security. Attending Milipol APAC and TechX Summit 2024, we speak with Physicist and former Yale University Professor, Dimitri Kusnezov, Under Secretary for S&T, US Department of Homeland Security.
Nominated by President Biden in 2021, Dimitri Kusnezov was the deputy under secretary for artificial intelligence and technology at DoE (Energy), leading efforts to drive the use of AI and machine learning across the department’s core missions.
Australia and the United States of America signed a treaty on cooperation in science and technology (S&T) for domestic security on 21 December 2005.
Recorded 4 April, 2024 at the Sands Expo & Convention Centre, Singapore.
With the rapidly evolving challenges in global travel, trade, and security, we speak to Australian Border Force Commissioner, Michael Outram APM at the Milipol APAC and TechX Summit 2024 in Singapore.
We discuss how border security been affected by technology and the current landscape, emerging threats, and the importance of fostering collaboration between government and industry to ensure border management has the cutting-edge technologies to ensure security and efficiency.
Recorded 4 April 2024 at the Sands Expo & Convention Centre, Singapore.
Pentera is an automated pentesting platform. Validate every attack surface in your network, and test continuously to maintain control over your true security posture. Be proactive in fixing vulnerabilities, misconfigurations, leaked credentials, and privileges before they are exploited.
We speak with Jannis Utz, VP Global Sales Engineering at Pentera and get insights into Pentera's capabilities and what will be on display at Booth B20, Hall 8 at GISEC Global 2024, 23-25 April at the Dubai World Trade Centre.
In this interview, Renen Hallak, Founder and CEO, Vast Data navigates the dynamic landscape of AI adoption and evolution, tracing its trajectory from the early days in 2016 to today’s diverse applications across various business sectors.
Prior to founding VAST, Renen led the architecture and development of an all-flash array at XtremIO, from inception to over a billion dollars in revenue while acting as VP R&D and leading a team of over 200 engineers. He holds a BA and an MSc in Computer Science, both summa cum laude.
Central to Renen's discourse is the pivotal role of data transformation in unlocking value within organizations in the AI era, and how businesses leverage vast unstructured data to derive valuable insights to gain a competitive edge.
Renen also notes the challenges and opportunities presented by AI in terms of cybersecurity. He delves into the dual role of AI as both a potential vulnerability and a defense mechanism against cyber threats.
Given the significance of scalable infrastructure in supporting the growing demands of AI-driven applications, Renen highlights platforms like Vast Data, which offer scalable solutions capable of handling vast amounts of data with high performance and minimal latency.
Recorded 13 March 2024, 11am. Singapore Shangri La Hotel, Breakfast Session with VAST Data
Headquartered in Singapore, ST Engineering is a global technology, defence and engineering group with customers and partners in more than 100 countries around world.
We speak with Mr THNG Chin Hwee, Vice-President, Public Safety & Security Cluster, ST Engineering about the capabilities on display at Milipol APAC and a must see at Booth 1910.
Find out more visit
https://innovd.stengg.com/spotlight/milipolap-2024/
MySecurity Media will be coordinating a delegation at Milipol APAC 2024 - to find out more visit https://mysecuritymarketplace.com/event/milipol-asia-pacific/
Sharat Nautiyal, Director of Security Engineering, APJ, Vectra AI.
Sharat has over 15 years of experience assisting organisations in the areas of security architecture, threat detection and threat hunting. He has a strong focus on leading security engineering, security architecture, and the sales engineering team across APJ.
The global cybersecurity landscape is witnessing a concerning surge in threats, and is particularly pronounced in the Asia-Pacific region. With the imminent impact of AI-boosted cyberattacks, cybercriminal tactics like phishing and social engineering are evolving in sophistication. Moreover, the recent uptick in high-severity cyber incidents underscores the urgent need for organisations to bolster their defence strategies. The implementation of comprehensive cybersecurity protocols is paramount for businesses and organisations to effectively mitigate these evolving threats.
Vectra AI, Inc. is the leader in hybrid attack detection, investigation and response. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Vectra AI’s patented Attack Signal Intelligence empowers security teams to rapidly detect, prioritize, investigate and stop the most advanced hybrid cyber-attacks. With 35 patents in AI-driven detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI Platform and MDR services to move at the speed and scale of hybrid attackers.
Visit Booth 1810 at Milipol APAC 2024, 3 - 5 April at the Sands Expo & Convention Centre, Singapore.
We speak with Grant Wright, General Manager of Marketplace and AI Products, SEEK.
Grant leads SEEK's global AI and Analytics teams at SEEK, who build and support the AI services that power SEEK's products including search, recommendations, candidate quality and pricing; and provide internal analytics and experimentation capability to better understand the performance of our products and drive continuous improvement and innovation.
Grant brings to this role his previous experience as Strategy Director at SEEK.
Prior to joining SEEK, Grant worked at L.E.K Consulting for over 10 years where he advised organisations and governments across Australia, New Zealand and the US on strategy, performance improvement and mergers and acquisitions.
Grant holds a Bachelor of Business (Economics) & Bachelor of Computer and Information Science (Software Development) from the Auckland University of Technology, where he was awarded the New Zealand Computer Society Cup for the top Computer and Information Science Graduate.
Generative AI, particularly ChatGPT, is transforming service delivery for clients and end-users, prompting businesses to actively integrate this technology for operational refinement. Grant shares anecdotes, such as using ChatGPT to craft children's bedtime stories.
Acknowledging glimpses of success in applying generative AI to customer interactions, Grant highlights the challenges of scaling these applications. Ongoing efforts focus on optimizing technology for widespread use, particularly in customer service scenarios.
In the realm of Gen AI transforming information into intelligence, Grant provides statistical insights into the platform's extensive reach, encompassing millions of candidate profiles, billions of interactions, and a substantial volume of job applications. Gen AI's value lies in extracting insights from traditionally unstructured data like job ads and CVs, summarizing and distilling it for actionable intelligence.
Anticipating a transformative shift in user experience, Grant envisions users communicating with AI more naturally. This evolution, inclusive of voice interfaces, promises new avenues for interaction, moving away from adapting to machine language.
Delving into responsibility in AI implementation, Grant underscores the importance of responsibly handling data and biases to prevent reinforcing discriminatory outcomes through AI. Emphasizing the necessity to understand the risks associated with training data and be mindful of potential impacts on individuals affected by AI-generated decisions.
Exploring the challenges and realities of AI impact on jobs, Grant highlights the disparity between the hype around AI's impact on jobs and tangible transformations in the job market. A balanced perspective is crucial to avoid overestimating or underestimating AI's immediate effects. Jobs are perceived as bundles of tasks, and Grant emphasizes the complexity of job market transformations. While some tasks may automate, others evolve or experience increased demand. For instance, the transition from last-mile delivery to drone-based delivery illustrates how job demands can shift within industries.
In preparing for change and AI adoption, Grant advises individuals, employers, and business owners to embrace adaptability in the face of evolving technological landscapes. Individuals are encouraged to explore and experiment with AI tools in their daily lives. Employers should focus on evolving skill requirements rather than rigidly adhering to traditional hiring practices. Additionally, caution is advised in AI adoption, especially in building internal capabilities. It involves asking the right questions about underlying AI capabilities, understanding potential risks.
Recorded on 29th February 2024, 6pm, SEEK office (Wallich Street, Singapore).
We speak with Charles Chu, General Manager of Cloud Security at CyberArk in the lead up to his Australian visit in March 2024.
CyberArk has advanced capabilities for securing access to cloud services and modern infrastructure for all users, based on the company’s risk-based intelligent privilege controls.
The CyberArk Secure Cloud Access solution provides just-in-time access with zero standing privileges to cloud management consoles and services running in multi-cloud environments. These security controls enable secure access to every layer of cloud environments, while causing no disruption or change to the way developers and other users access cloud services.
Charles will be in Sydney & Melbourne - 18-22 March, 2024.
For a demo visit https://www.cyberark.com/request-demo/ or find out more at https://www.cyberark.com/contact/
Ivo de Carvalho Peixinho, Head Cybercrime Intelligence Unit, INTERPOL, has a BS degree in Computer Science at Universidade Federal da Bahia, with two post-graduations, one in Distributed Systems and another on Mechatronics. He is also a BS7799 certified auditor. Ivo has more than 10 years of experience on network security, and worked the last two years on security research and incident handling. Prior to Interpol, he works as a Forensics Expert at the Brazilian Federal Police Department.
In this interview, Ivo shared insights in 6 topics:
Information sharing challenges: Addressing conflicts between private sectors and law enforcement priorities, particularly in cases like ransomware, where the need to restore operations clashes with preserving evidence.
Data Processing Regulations: Exploring Interpol's regulations for data processing and exchange, considering cultural barriers, language differences, and data sovereignty concerns when sharing information among different countries.
Project Gateway Initiative: Understanding the process and significance of Project Gateway, a collaboration framework between Interpol and private entities, including the steps for private organizations to join this initiative.
AI's Impact on Cybersecurity: Recognizing AI as a productivity enhancer, both for defenders and attackers, and the importance of balancing technological advancements with legal frameworks in the evolving cybercrime landscape.
Training and Collaboration: Emphasizing the need for regular training sessions and exercises to foster a common understanding and language among global law enforcement agencies, crucial for effective collaboration during global cybercrime operations.
Skill Set for Investigators: Discussing the essential skills for law enforcement investigators, including self-driven motivation, the importance of work-life balance, and the role of teamwork, personal interests, and joy in maintaining stamina and perseverance in the field of cybersecurity.
Recorded 7th December, ISC2 Secure Asia Pacific 2023, 10.30am.
Dr. Yuriy Bulygin is the CEO and founder of Eclypsium, the digital supply chain security company that helps organizations protect their critical hardware, firmware, and software.
Prior to Eclypsium, Yuriy was Chief Threat Researcher and led the Microprocessor Security Analysis team at Intel Corporation, as well as the Advanced Threat Research team at Intel Security.
He is also the creator of CHIPSEC, the popular open-source firmware and hardware supply chain security assessment framework.
When enterprises started using CHIPSEC to find vulnerabilities, discover compromised firmware, or just poke around hardware systems, Yuriy founded Eclypsium with Alex Bazhaniuk.
Since then Eclypsium has been on a mission to protect devices from supply chain risks.
In this interview, Yuriy highlights the potential vulnerabilities in the firmware (software running the hardware) in today’s digital devices, and the risk posed by threat actors.
Using a typical PC as an example, which involves contributions from over 265 suppliers, each with its components and code, he notes the ubiquity of software, and liken the supply chain of such a device to a “Wild West”:
“at any point in the supply chain, at any of those links in the supply chain, a compromise may happen”, and “ all of these components and all the code that is developed by those suppliers and vendors has vulnerabilities.”
He elaborated that “even if it's OK now … 3 months from now, it can be compromised because of those vulnerabilities.”
To give an example, he referenced the recently discovered threat in the wild – “BlackLotus”, an evolution of threats based on open-source frameworks – e.g. Lojax, MosaicRegressor, Moon bounce - discovered in the past 3 to 4 years.
He highlighted the characteristics of such threats:
• These UEFI compromises allow attackers to compromise equipment remotely, for access or persistent malware installation.
• They cannot be removed by reinstalling operating system or reimaging or even replacing the hard drive.
• BlackLotus exploitation of the UEFI system vulnerabilities, particularly the Secure Boot - a fundamental security feature adopted by modern operating systems - sets it apart as an advanced threat, marking the first instance of such threats discovered "in the wild."
He explained that compromising firmware is attractive for threat actors for many reasons:
• Stay hidden: Detection and protection controls operate at the software application level and above, but there is no equivalent for firmware.
• Achieve "Persistence" - where traditional mitigation measures cannot remove the malware/threats.
• Simplicity – for example, exploiting firmware vulnerabilities to gain access is much simpler than developing a very complicated exploit chain.
• Gain high privileges – Remain hidden and persistent while gaining high level of privileges.
To mitigate against malicious firmware implants, Yuriy suggested,
(a) assess the supply chain risks (e.g. potential vulnerabilities and threats introduced during procurement and deployment),
(b) continuous monitoring of system integrity,
(c) implement specialized technologies designed for malicious firmware detection.
Recorded at Singapore International Cyber Week / Govware 2023 – 18th October 2023, 3pm.
Mr Yeong Zee Kin holds a Master of Laws from Queen Mary University of London and completed his undergraduate law degree at the National University of Singapore. His experience as a Technology, Media and Telecommunications lawyer spans both the private and public sectors. He has spoken and published in areas relating to electronic evidence and intellectual property, as well as legal issues relating to Blockchain and AI deployment.
Zee Kin is an internationally recognized expert on AI ethics. He spearheaded the development of Singapore’s Model AI Governance Framework, which won the UNITU WSIS Prize in 2019. He is currently a member of the OECD Network of Experts on AI (ONE AI). In 2019, he was a member of the AI Group of Experts at the OECD (AIGO), which developed the OECD Principles on AI. These principles have been endorsed by the G20 in 2019. He was also an observer participant at the European Commission’s High-Level Expert Group on AI, which fulfilled its mandate in June 2020
Zee Kin is also a well-regarded expert on data privacy issues. He has contributed to publications on legal issues relating to data privacy and has spoken at many well-recognised international and domestic platforms on this topic.
--
In this interview, Zee Kin shares his insights on the legal challenges in the Era of Advanced AI
Zee Kin highlighted that with the latest AI innovations, the responsibility and legal issues remain largely consistent, but the tools and technology introduce different challenges.
For instance, he shared that such concerns around content, child protection, intermediary behavior, data security, data protection, and cybercrime remain, while challenges such as detection of fake content has intensified due to increased tool accessibility and the scalability of threats.
Referring to the "Getty vs. Stability AI" case, he shared that the interesting question is the use of copyrighted data to train AI models – which is not new, and the key is to establish a proper legal basis for using such data. Data lineage and the provenance of data have always been important in legal contexts.
He also noted that these concerns have also surfaced during the recent governmental responses around the world to the latest AI innovations.
Zee Kin also highlighted the challenges with defining terms such as "fairness," "transparency," and "repeatability" – varies by context, where expectations and priorities for AI differ based on its use, such as safety and predictability in medicine, and bias and fairness in personal data applications.
Repeatability poses an additional challenge in Generative AI because every iteration of an image or summary will vary (**owing to Generative AI's statistical predictive nature).
Zee Kin also shares his views of AI's impact on job security, nothing that there will be emerging opportunities for lawyers to use AI tools for efficiency and error reduction.
Recorded at TechLaw Fest 2023, 21st Sept 2023, 3.30pm, Marina Bay Sands, Singapore.
Mr Wong Wai Meng is currently the Chief Executive Officer (Data Centres) of Data Centres & Networks Division. He has almost 30 years of experience in the Information and Communications Technology (ICT) industry and currently spearheads the company's thrust towards being one of the leading data centre developers and solution provider in Europe and Asia Pacific.
Prior to joining Keppel T&T, Mr Wong was Vice President of BT Advise BT Global Services across Asia Pacific, Middle East, Africa and Turkey (AMEA) where he managed the company's practices in business consulting, systems integration, software development, networking, mobility, collaboration and security. He was also CEO of the BT Frontline group of companies where he played a critical role in the integration of BT Frontline into BT Global Services.
Mr Wong now serves as Chair of SGTech Council, Member of the Council and Chair of Digitalisation Committee in Singapore Business Federation, and is active on various industry panels and committees.
In November 2022, he won the Top Business Leaders accolade at the Asia-Pacific Cloud & Datacentre Awards
More recently in August 2023, he was named by the Singapore Computer Society as Tech Leader of the Year 2023.
In this interview, Mr Wong shared his insights on the evolution of data centres over the last two decades, from the early computing days to today’s AI and Web3 eras, highlighting the pivotal role of connectivity in transforming how “we consume technology today”.
Noting how the shift bring to realisation of a “computer” in our palms and concepts such as “software as a service”, he said these transformations contribute to a trend from on-premises solutions to cloud-based applications. These changes in turn have driven demands for centralisation of services in the cloud, leading to the growth of data centres, and the rise of hyperscalers.
Other topics discussed include:
The impact of AI on the tech industry, and the significance of AI in the context of AI vs. AI scenarios.
Location considerations for data centres (factors such as power availability, water supply for cooling, and connectivity infrastructure being key considerations); sustainability in data centres (including energy efficiency and the use of renewable energy sources).
Cybersecurity as a holistic approach to digital trust, which goes beyond just technology and involves governance, data management, and privacy considerations.
Mr Wong wrapped up the interview by sharing how the tech industry's perpetual evolution change keep him passionately engaged throughout his career – and the promise of groundbreaking change, making each day a thrilling journey of discovery.
Recorded at Tech Week 2023, 12th October 2023, 4pm, Singapore Marina Bay Sands.
Dennis Giese is a researcher with focus on the security and privacy of IoT devices.
While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices.
His most known projects are the documentation and hacking of various vacuum robots. His current vacuum robot army consists of over 49 different models from various vendors.
Recorded on 18 October, 2023 at The Australian Cyber Conference 2023 - Melbourne with the Australian Information Security Association.
Jane Lo speaks with Ben Verschaeren, Director, Global Solutions, Sophos about cybersecurity opportunities and challenges with Generative AI.
With over 19 years in the IT industry, Ben Verschaeren is a seasoned professional based in Melbourne. He leads global strategic initiatives, educates on threat landscapes, and develops training tools focusing on real-world exploits.
Ben also directs a global sales engineering team responding to RFPs, and a software engineering team creating high-quality products for various uses. His prior roles include serving as a Solution Architect at JB HiFi, Australia's largest retailer, and at Thiess, the leading mining and construction company in Australia.
Ben’s unique blend of sales and engineering experience across diverse sectors enables him to drive tech-forward initiatives with an innovative approach, affirming his position as a key asset in the industry.
In this interview, Ben kicked off the interview by sharing his insights on drivers into the wide-spread popularity of the latest AI technology – “generative AI”.
On discussing how generative AI could transform the cybersecurity landscape, Ben acknowledged that it could help increase the productivity of cyber defenders, as an “AI” personal assistant – such as “help you write code” or “help you write query”.
However, he also cautioned that the technology also introduces new threats.
Elaborating on some of the emerging threats, he said that contrary to expectations, malware generated by LLM can be more easily detected than phishing emails and synthetic voice.
To mitigate against such threats, he suggested enhancing business processes and controls (for example, robust fund transfer authorisation, to mitigate phishing risk). He also recommended conducting user awareness training regularly to align with the fast-evolving landscape of phishing tactics, emphasising the importance of understanding the "why."
Another threat is the potential of generative AI to “hallucinate” when making recommendations for software libraries. He pointed out this issue underscores the need to maintain a SBOM (software bill of materials), and implementing quality controls throughout the software development process.
Ben also recommended that organisations looking to embrace AI, develop an “AI policy”, providing guidance in areas such as the types of data or models that to be used during training and deployment. He also shared that middleware solutions are available to anonymise the data entered in the prompt, and check that no personally identifiable information (PII) is included.
Wrapping up, Ben notes that rapid pace of generative AI development and “the landscape is changing everyday”, and advises cyber defenders to “stay on top”, “don’t be complacent”, and it is “another area where and different threats are emerging every day”.
Recorded at Cloud Expo Asia, Singapore Marina Bay Sands, 12th October 2023.
Recognised by the US Cybersecurity and Infrastructure Security Agency (CISA), Motorola Solutions has established a cyber threat Information Sharing and Analysis Organisation (ISAO) to provide public safety agencies the capabilities they need to defend against attacks.
Since January 2022, Motorola Solutions’ Public Safety Threat Alliance observed 350+ cyber attacks impacting public safety organisations worldwide, often resulting in downtime of critical services.
Cyber attacks against public safety agencies increased in both 2021 and 2022, with 2022 seeing a 700 percent increase in distributed denial of service (DDoS) attacks for public safety organisations and a 179 percent increase in hacktivist activity.
In many Australian states and territories, emergency services use the Motorola Solutions Land Mobile Radio (LMR) communication networks and devices as well as their managed services to help maintain reliable voice and data communications and keep their technology securely and optimised, 24 x 7.
However, LMR networks and other critical infrastructures can also be targeted by threat actors (e.g. critical infrastructures including utilities being targeted in the war in Ukraine)
Motorola Solutions continues to grow and invest in its portfolio of communications, software and video security products including our cyber security offerings. The ActiveEye platform monitors about 1M cyber attack events on public safety networks each month, with 98 percent auto-triaged by artificial intelligence, and the rest looked at by cybersecurity experts on our team to determine how to mitigate risks.
Among Australian customers already using these cyber services are the NSW Telco Authority for which Motorola Solutions are providing a comprehensive suite of public safety services for PSN, including network lifecycle upgrades and 24 x 7 cybersecurity, helping to keep this mission-critical technology up-to-date, secure and performing reliably in any situation.
For more information and to get involved, visit Public Safety Threat Alliance -https://www.motorolasolutions.com/psta
Brendan is a cyber security expert with more than 20 years of experience in the financial sector and U.S. intelligence community, including leadership roles as the founder and CEO of a successful startup and an executive at the National Security Agency. He has a deep knowledge of advanced cyber threat actors, threat hunting, financial sector systemic risks, and risk management best practices.
In this interview, Brendan shared his perspectives on cybersecurity skills, threats and budgets.
Reflecting on his career at the NSA from 2002 to 2013 and essential cybersecurity skills, Brendan emphasized the importance of curiosity, analytical thinking, and adaptability, which he believes are still relevant in today's cybersecurity landscape.
When it comes to the question of whether cyber threat actors possess greater expertise than cyber defenders, Brendan suggested that they strive to utilize their resources as effectively as possible to breach networks. From this standpoint, they share similarities with other criminals who possess the necessary skills to perpetuate their criminal activities.
For cyber defenders also seeking to optimise the return on investments, he noted the challenge of quantifying cybersecurity investments and the need to tailor metrics for different companies and industries.
On the topical theme of AI in cybersecurity, Brendan highlighted the potential of AI, particularly in threat intelligence characterization and customer engagement. He also mentioned the challenges of AI models and their potential use by threat actors.
He also shared his experiences starting a company and raising funds, and the value of Information Sharing and Analysis Centers (ISACs) and various industry-specific information-sharing groups.
Recorded 26th Sept 2023, 5.30pm, Asia Square Singapore.
We speak with Bugcrowd CEO Dave Gerry in Sydney as he visits Australia to meet with partners and customers.
Bugcrowd, a multi-solution crowdsourced cybersecurity platform, has also announced significant global customer momentum, highlighting the market need for Bugcrowd’s crowdsourced cybersecurity platform. The company’s rapidly growing customer base includes top brands such as ExpressVPN, Rapyd and T-Mobile, which have chosen to partner with Bugcrowd for one or more of its Bug Bounty, Penetration Testing and Vulnerability Disclosure Programs.
Serving nearly a thousand organizations worldwide, Bugcrowd empowers customers and hackers to unleash their ingenuity to protect brands and intellectual property. The company drove over 50% growth in payments to the hacker community through customer programs, amplifying a pivotal time of remarkable growth and innovation for the Bugcrowd Platform.
ExpressVPN, an industry-leading privacy and security company, chose Bugcrowd for its world-class team of hackers that had skills expertly matched to their unique scope. The company’s goal is to allow users to take control of their internet experience – with privacy and security at its core – and Bugcrowd makes this possible by streamlining the reporting, remediation, reward and disclosure processes of a public bug bounty program. ExpressVPN has been harnessing Bugcrowd’s powerful and highly-scalable Vulnerability Disclosure and Bug Bounty programs to protect their data and customers for over three years.
Bugcrowd’s latest customers include U.K.-based fintech company Rapyd, who chose Bugcrowd for its ability to support organizations around the globe in scaling their security programs to meet rapid organizational growth. During a time of major acquisitions and the need for more focused API testing, the 500+ Rapyd team transitioned to Bugcrowd in order to leverage the company’s highly specialized team of hackers that fit their exact needs. Bugcrowd’s CrowdMatch technology, which enables precise crowd matching, allows organizations to connect with the right hackers for Rapyd’s needs. In one year, the team found 40 total vulnerabilities, 15 of which were critical.
Top customers also include T-Mobile, the U.S.’ leader in 5G with the largest, fastest and most awarded 5G network in the country. T-Mobile and Bugcrowd launched a revamped public bug bounty platform to invite hackers to find vulnerabilities in T-Mobile’s applications and websites. T-Mobile evaluates the reported vulnerabilities and takes appropriate action.
Recorded 10 October, 2023.
In this interview, both John and Thian introduce the history of ISACs (formed in 1999, subsequent to the 1998 signing of U.S. Presidential Decision Directive-63), and in particular, the creation of OT-ISAC (Operational Technology Information Sharing and Analysis Centre) as one of the key trusts of the Cyber Security Agency of Singapore’s “OT Cybersecurity Masterplan 2019 to facilitate the sharing of information.
Reflecting on the journey from conceptualization to today, Thian Chin remarked that “OT-ISAC has become that safe harbour the platform for the organisations of the different parties with vested interest to different business lines come together to share, because their common goal is how do we then exchange information to reduce the risks that caused by threat actors.”
Other topics covered in the interview include:
• The types of information being shared – such as strategic threat landscape including cyber incidents and vulnerabilities, standards and best practices, and TTPs.
• Closing the cultural / communication gap between the engineers and the IT cybersecurity practitioners because “because the problem statement they're dealing with is the same. It's a threat actor out there to try to disrupt.”
• The maturing of conversations from beyond terminology such as zero trust, air gap to actual implementation
• What does success mean in information sharing - diversity of opinions – in particular, including C-suite in cybersecurity conversations, and more more stakeholders coming forward to share real-life case studies of actual incidences.
John Lee, Managing Director, Global Resilience Federation
John has more than 20 years of experiences in ICT and Information Security. He is currently the Managing Director of the Operational Technology Information Sharing Analysis Centre (OT-ISAC) that supports member organizations (public and private) in OT threat information. The centre was setup in 2019 and has members from Transport, Aviation, Maritime, Healthcare, Manufacturing, Water, Energy, Government etc. His past roles were in Information Security Governance, Risk Management, Security Operations, Infrastructure and Application Delivery. He has led teams in Asia-Pacific as well as managing global services. He is also a certified cybersecurity trainer for ISACA.
Thian Chin Lim Senior Director (Governance Group) GovTech
Thian Chin has over 20 years of experience in Information & Technology governance, risk management, resilience and compliance, and operational Technology cybersecurity.
Prior to his current appointment at GovTech, he led the Critical Information Infrastructure (CII) Division at the Cyber Security Agency of Singapore (CSA).
Before joining CSA in August 2015, he was responsible for the regional Technology Governance function in United Overseas Bank. He also led the Technology Risk function in GIC Pte Ltd from 2008 – 2013. In his earlier years, he was a manager leading a team of Information Technology auditors in Ernst & Young.
Thian Chin holds an Executive Masters in Cybersecurity from Brown University, Bachelor’s Degree in Computer Engineering from Nanyang Technological University and is an alumnus of the George C Marshall European Center for Security Studies. He is a certified CGEIT, CRISC, CISM, CISSP, CISA, CDPSE, GICSP and SABSA practitioner.
Recorded 7th Sept 2023, OT-ISAC Summit 2023, Voco Orchard, Singapore, 5pm.
Mr. Yigal Unna was appointed by Israel’s Prime Minister as the Director General of the Israel National Cyber Directorate (INCD) in 2018. In this 4 years role, until 2022, Mr. Unna reported directly to the Israeli Prime Minister and led a team of 350 employees responsible for all aspects of cyber security, including formulating policy and building technological power for operational defense of critical infrastructure. In addition to his work protecting Israel, Mr. Unna forged long-term relationships with many foreign governments and lectured around the world on cyber security.
Prior to the INCD, Mr. Unna served in the Israel Security Agency (ISA), also known as Shin Bet and Shabak, for 23 years. The ISA is Israel’s domestic intelligence service. He retired as the Director of the Cyber and Signal Intelligence Operations Division (military rank equivalent of major general).
Mr. Unna began his career as an officer in the elite Unit 8200 in the Israel Defense Forces. Unit 8200 is responsible for collecting signal intelligence and code decryption.
Overall, Mr. Unna served 33 years in Israel National security – all of them in cyber security and Data warfare.
Since retiring from public office, Mr. Unna advise to leading and promising Israeli cyber startups and growing enterprises, a venture partner in venture capital funds focusing on cyber security, and manage national cyber projects for foreign governments (Africa, Asia and eastern Europe).
Mr. Unna take part in the international advisory panel for Singapore Ministry of Transportation in Maritime, contributing his experience on cyber security aspects of Maritime.
Mr. Unna is part of the Global Cyber Group of Aspen institute, and a member of the advisory team to Krach Institute for tech diplomacy at Purdue, both US research institutions.
In this interview, Mr Unna shares with the audience his extensive experience, and his perspectives on the emerging cybersecurity issues introduced by innovations such as blockchain and AI.
Touching briefly on blockchain, Mr Unna notes that, the technology is a huge step “for managing our data and our knowledge in a better and more secure way” and will mature as we build more safeguards and applications.
As an example, he referred to the NFTs. He points out some of the lessons and possibilities introduced by the phenomenon, such as how to better secure and define assets in the future, including non-tangible assets.
On the topic of AI, Mr Unna also believes that, if history is any guide, that after the “first shock of fear and enthusiasm”, AI will be here to stay and “mankind will eventually build security and safeguards”.
However, he also points out that as with other new technologies, the AI innovation outpaces our abilities to put in appropriate safeguards. In particular, he cautions that for the first time in human history, “Intelligent and maybe even self aware machines may begin to become dangerous to mankind”.
He advises that technological companies put ethical principles before business outcomes, to fully harness the benefits of the AI while addressing the potential abuses.
Mr Unna also shares the three areas of AI that the Israel cybersecurity community is working and researching on:
(a) how cyber threat actors could exploit AI
(b) how cyber defenders could harness AI
(c) emerging threats from adversarial AI - a new playground of AI vs. AI
Wrapping up, Mr Unna shares 3 valuable cybersecurity lessons drawn from his extensive experience for defenders.
Recorded at ST Engineering’s InnoTech Conference 2023, held at Marina Bay Sands, Singapore on 5th September 2023, 4.30pm.
Our previous Webinar session with Mr Unna when in the role as Director General is available here
https://australiancybersecuritymagazine.com.au/australia-israel-counterpart-series-national-cybersecurity-strategy-insights/
Mark Orsi is the Chief Executive Officer of Global Resilience Federation, (GRF) a non-profit with the mission to develop and support threat intelligence and information sharing communities including education, operations technology, financial services, retail and hospitality, legal and professional services, energy, health, and oil and natural gas.
Launched in 2017 as a standalone company, from a former Financial Services Information Sharing and Analysis Center (FS-ISAC) division, GFR is the evolution of 1998's U.S. Presidential Decision Directive 63 and 2003's Homeland Security Presidential Directive 7 which mandated that the public and private sectors share information about cyber and physical security threats and vulnerabilities to help protect critical infrastructure.
Mr. Orsi led strategic efforts for several prominent Fortune 100 companies, working directly with CIOs and CISOs to develop, deploy, and improve security controls protecting the confidentiality, integrity, and availability of sensitive information.
Mark joined the company from JPMorgan Chase where he served as executive director and product owner for cybersecurity and technology controls. Prior to JPMorgan, Mr. Orsi served KPMG as director of cybersecurity, and Goldman Sachs as vice president of technology risk.
Mark holds an MBA from Columbia Business School, an MS in computer science from Johns Hopkins University, and a BS in Aerospace Engineering from the University of Maryland
In this interview, Mark shared the latest in artificial intelligence, and operational resiliency.
Artificial intelligence
Mark highlights how the latest AI innovations powered by large language model differ from the previous iterations of AI technologies such as democratising the cyberattacks tools used by nation state actors and leveraging dynamic datasets in training AI models.
He also notes how cyber defenders are adopting the technology to “multiply” the efforts of resources, for example, in code development and testing. He also foresees that such technology would empower cyber defenders to deliver more targeted threat intelligence.
Through a personal story, Mark illustrates how the technology lowers the barriers of entry for hacktivists and other threat actors, and the importance of exercising extra vigilance – including understanding how the third parties in the supply chain are using AI. He also notes that an “AI” SBOM (akin to the software SBOM) could help to address the AI model and data supply chain concerns.
Operational resiliency
Mark introduces the Operational Resilience Framework (ORF) launched by Global Resilience Federation’s Business Resilience Council (BRC) to solve the challenge of providing services in an impaired state.
For example, while businesses may have robust processes in place for backing up business or customer data for regulatory reasons, less attention may be paid to backup data such as system images or active directory, network configurations –which would minimize service disruptions in the face of destructive attacks and events.
He also explains that ORF was developed to be broadly applicable and is aligned with existing controls like those from NIST and ISO.
Some useful links and contacts:
Recorded 25th August 2023, 1.30pm, GRF APAC Headquarters Singapore
Mike Silverman has a unique blend of a business and technology background, with 20 years of experience in strategic, technological, financial, and change management leadership across many industries, primarily in Financial Services and Software. He enables firms to innovate, scale, and transform through increasing productivity, reducing costs, and streamlining processes and operations.
Mr. Silverman was previously the Global Head of Enterprise Technology Strategy at FIS, the world’s largest Financial Technology Company. Prior to that, he was a management consultant focusing on Corporate & IT Strategy, CxO Advisory, Merger & Acquisition Integration, Business Process Re-engineering, and more, and has held other roles in innovation and development.
Mike has an MBA with specializations in Strategy, Finance, and Leadership & Change Management; and a BSE in Computer Engineering, Cum Laude with Departmental Honors.
In this interview, Mike shares with the audience highlights of the FS-ISAC (financial services information sharing and analysis centre) APAC Summit 2023 – in particular, on two themes: Artificial Intelligence and Quantum Technology.
Recorded 3rd August 2023, U.S. PST 6.am. SGT 9pm.
Jane Lo, Singapore Correspondent speaks with Miao Song, Global Chief Information Officer, GLP Singapore.
Miao Song has over 23 years of global experience in various industries, with broad exposure to the Oil/ Energy/Natural Resources as well as Consumer Goods and Health Care business. Over the course of her past tenure, she received many awards such as the CIO of the Year by IDG, Leadership Excellent, Women Leader, CIO of the Year Silicon Valley, Global CIO 100, and more.
In this interview, Miao shares the highlights of her presentation, “The emergence of GenAI technology”, at the World AI Show 2023.
She notes that latest AI innovation based on LLM (large language model) is significantly different from previous “traditional” AI or machine learning. In particular, the AI LLM models, enable the generation of new content with cognitive search and text summarisation.
Noting how the new capabilities could help drive efficiency or help humans “do jobs better” (for instance, in medical diagnosis), Miao stresses such benefits need to be balanced with concerns. Some of these considerations including the impacts on jobs, the need for regulation, and security risks implications.
For companies looking to adopt the latest AI innovation, Miao points out that it is “not a simple matter of having a conversation with ChatGPT and the problem will be solved”.
Rather, there is a need to understand the space and the technology (data structure and overall technology architecture), and the business pain points, to “translate the business opportunity into technology adoption”.
She elaborates that implementing AI is different from a traditional large IT project that typically runs linearly requiring a team of consultants.
Instead, the adoption requires hands-on approach to re-iterate “test and learn” cycles - in other words, education – which requires a secure environment to learn the capabilities and limitations of AI.
From her firm’s adoption journey, Miao offers a few tips:
• the technology team be immersed in the business to build practical use cases.
• the need for data architects and engineers to design data structures and identify the data types to be fed into AI
• security professionals to implement necessary measures to mitigate potential security breaches and AI specific risks (such as model risks that could lead to fraud)
• guidelines for the organisation (for examples, restricted use of confidential company information or personal information to experiment with AI; privacy regulations that are applicable)
Wrapping up, Miao offers the view that to remain competitive, companies will have to embrace and adopt the latest AI innovations. She also offers an optimistic view that with generative AI, we can move away from “memorising” knowledge to focus on generating creative ideas.
Recorded 2nd August 1.30pm, World AI Show 2023, Singapore Marina Bay Sands.
We speak with Asjad Athick, Cyber Security Lead, APAC for Elastic who gave a presentation at CISO Melbourne earlier this week. Asjad’s presentation encompassed the concepts around ‘unleashing the full potential of AI in security operations’.
In today's rapidly evolving threat landscape, security analysts play a crucial role in protecting organizations from cyberattacks. However, the overwhelming volume of security alerts and the complexity of identifying and responding to advanced threats pose significant challenges. Enter Artificial Intelligence (AI), the game-changer in security operations.
Asjad discusses the transformative potential of AI in Security Operations Centers (SOCs) and explores how it can empower security analysts to tackle the ever-growing complexities of cybersecurity. By harnessing the power of AI, SOC teams can enhance their capabilities, augment human expertise, and gain the upper hand against adversaries.
For further information visit https://www.elastic.co/security
Mr. Dean Gefen is a Director and Founder of Red Alpha Cybersecurity, and the CEO of DART Consulting and Training. Mr. Gefen is an Israeli cybersecurity expert, with more than 15 years of operational experience. He is highly proficient in cybersecurity training and consultancy, including in establishment of cybersecurity operational units, development of extensive training and qualification processes for governments, security organisations and the private sector.
Since 2017, Mr. Gefen has been advising and working with several governments in Asia, Europe and the Middle East, training hundreds of cybersecurity professionals annually.
In this interview, Dean shares his insights on up-skilling and re-skilling in cybersecurity.
He gives his perspectives of how cybersecurity skills are built on technical foundations, and the importance of the ability to understand how the adversary think and could compromise the network. He explains this means the need for cybersecurity professional to demonstrate the non-technical aptitude for the field – including ability to learn and think creatively.
He also introduces how Red Alpha’s “Alpha Specialist Training Programme (ASTP)” – a bootcamp and industry attachment cybersecurity training program - contributes to the overall capabilities and capability building in the industry.
Wrapping up, Dean also provides his views on lessons we can take from Israel - widely viewed to be one of the best in the world with a proven track record on training skilled cybersecurity professionals - to grow the talent pipeline.
To apply to the ASTP programme,
https://www.redalphacyber.com/programme-astp (for Singapore)
https://www.redalphacyber.com/programme-astp-us (for USA)
Recorded at Red Alpha Singapore, 17th July 2023, 10am.
Roanne Monte is the CEO and Chief Product Officer of Armatec Global, a Sydney-based impact technology company serving the defence, critical infrastructure, and public and private sectors. With a steadfast commitment to a human-centred approach to product builds, Roanne leads the company in delivering innovative cyber and physical threat intelligence solutions that prioritizes user needs and drive measurable business value. As the creator and co-architect of the company’s flagship platform CapchrTM, Roanne harnesses the power of deep learning (DL), machine learning (ML), and artificial intelligence (AI) technologies to provide cutting-edge solutions that enhance security, protect critical assets, and ensure the safety of individuals and organizations.
An Australian-American raised in Sydney, Roanne holds a bachelor’s degree in computer science and psychology graduating cum laude from Harvard University and a juris doctor candidacy under an academic scholarship at Macquarie University Law School.
Roanne Monte, is set to address the Australian Security Conference about Australia’s Critical Infrastructure security. The panel will be discussing implications arising from the Security of Critical Infrastructure (SoCI) white paper, published by the Australian Security Research Centre in partnership with the Department of Home Affairs, which outlines the need for effective risk management and security planning.
For more information visit
https://securityexpo.com.au/
What has the world learned about cyber-security from the Russia Ukraine War? According to Microsoft’s ANZ National Security Officer, Mark Anderson, while the kinetic war still rages within the borders of Ukraine, the cyberwar is borderless, playing out across networks globally.
Anderson has over 28 years experience in the IT industry with 18 of those at Microsoft in various roles across the globe. He will be presenting at the Australian Security Industry Association (ASIAL) Conference at Sydney’s ICC on August 30.
According to Anderson, while Russian attackers primarily focused on Ukrainian assets, this didn’t stop those who support Ukraine from being targeted. Anderson says, that within the first 6 months of the conflict, Microsoft detected Russian network intrusion efforts on 128 organisations in 42 countries outside of Ukraine.
Mark will discuss some key insights and lessons learned including:
The destructive power of converging the three domains of cyber warfare
Despite the expectation that nation states like Russia use advanced cyber hacking techniques, this conflict surfaced the fact that everyday hacking techniques – like those used by common cyber criminals – proved sufficient for threat actors.
What is needed to ensure we continually improve our defences both from a collaboration perspective and the role of individuals and businesses.
For more information visit
https://securityexpo.com.au/
Stephen Scheeler is Australia’s most authoritative voice on digital disruption, transformation, culture & leadership. His experience at the heart of Silicon Valley is truly unparalleled, and he has a unique ability to inspire audiences of all kinds with rare insight, humour & humility.
Stephen is the former Facebook CEO for ANZ and now CEO of revolutionary artificial intelligence start up, Omniscient – the world leader in using A.I. to decode the human brain.
Backed by some of Australia’s most iconic business names – including Gina Rinehart, Gretel Packer and Will Vicars – in 2022, Omniscient won the coveted South-by-Southwest (SXSW) Innovation Award for A.I. and Machine Learning.
Stephen is also founder of global advisory The Digital CEO, and Executive-in-Residence at the Asia-Pacific’s leading business school, the Australian Graduate School of Management.
Stephen is one of Australia’s most sought-after speakers & advisors on digital disruption, transformation, culture & leadership, and the future of technology, data & A.I.
A native New Yorker, Stephen has spent over 25 years in Asia-Pacific, with deep business & cultural experience across China, Japan, SE Asia & ANZ
Stephen will be presenting 'AI, Data and the future of security, a tech CEOs view' at the Australian Security Industry Association (ASIAL) Conference at Sydney’s ICC on August 30.
Most cyber security discussions centre on financial data or national security - but what if you need to secure the secrets of the human brain?
Omniscient are "the OpenAI of the Human Brain" - the world leader in using artificial intelligence to decode the brain.
Omniscient develops technology via the study of connectomics – data-driven construction and analysis of the brain's connections. Data are converted from MRI scans into 3D visuals of electrical activity occurring in the brain. The company’s latest technology, called Quicktome, is used by neurosurgeons as a surgical planning tool offering views of brain activity for each patient.
Security of individual patient records is of obvious concern, however Omniscient’s dataset can also reveal connections leading to mental health issues such as depression or even precursors to dementia or Alzheimer's Disease. Cyber security surrounding IP protection is vital for Omniscient, and many other businesses in globally significant technology.
For more information visit
https://www.o8t.com/
https://securityexpo.com.au/
Stephen's previous interview, Episode 178, recorded 29 October 2019 is available here https://mysecuritymarketplace.com/av-media/demo-podcast/
We speak with Anirudh Chand, Head of Solutions Engineering, APJ at Fortra. Anirudh has worked in cyber security for the last 20 years, with emphasis on compliance, integrity monitoring, privilege access and vulnerability management. For the past seven years, he has been leading solution engineers for different vendors, developing teams that add intrinsic value to the organisations. He currently heads a highly skilled team of cyber security professionals for Fortra across Asia Pacific and Japan.
Founded in 1982, the company was previously known as Help/38, then HelpSystems, and in 2022 the company rebranded to Fortra. HelpSystems is known throughout the industry for its dedication to helping customers succeed by enhancing their approach to cybersecurity and automation. These days, advances in technology are often met with equally powerful cyberthreats that constantly adapt.
Fortra is focused on creating a simpler, stronger, and more straightforward future for cybersecurity by offering a portfolio of integrated and scalable solutions.
For further reading and inquiries visit
https://mysecuritymarketplace.com/fortra
Aaron is a council member and the Chief Executive (CYC) of Cyber Youth Collective. In his day job, Aaron is the Director of Business Development (Enterprise) at Wissen International, where he empowers enterprises to fortify their digital fortress, enhancing both technical safeguards and human vigilance, through a holistic and innovative approach to cybersecurity culture. Aaron has served in both public and private sectors, like the Cyber Security Agency of Singapore (CSA) and the Ministry of Education, Singapore and is passionate about developing the next generation of cybersecurity leaders.
In this interview at the Cyber Youth Summit 2023 (Singapore), Aaron shares highlights from the conference - designed by the youths, to be a platform and ecosystem to speak to industry partners, to find out more about a career in the cybersecurity industry.
He also shares his insights on approaching cybersecurity with a focus on youth in three key aspects:
a) The unique threats that youths may face in Cyber space – such as tailored social engineering tactics that target the youths
b) The special insights and skills that youths bring to the cybersecurity industry – such as abilities to step out of their comfort zones
c) Teaching cyber defense to the youths – such as going beyond the “do’s and don’ts”, to more about understanding the psychology of cyber criminals
For youths who are interested in a cybersecurity career, Aaron advises to first get “immersed” in the industry (such as attending conferences e.g. Cyber Youth Summit, and workshops). To get a practical understanding of cybersecurity as a career, Aaron suggests that youths explore internship opportunities, and participate in cybersecurity related projects. Most importantly, he also advises youths to persevere in pursuing their ambitions.
Aaron also advises industry partners to also consider a variety of education backgrounds when hiring youths for cybersecurity positions.
Recorded 23rd June 2023, 11.30am, Cyber Youth Summit 2023 Singapore, Marina Bay Sands
We speak with Dr Atif Ahmad, Associate Professor and Deputy Director for the Academic Centre of Cyber Security Excellence at the University of Melbourne and Current Visiting Associate Professor at UKM who is helping to develop Malaysia’s cyber incident response capability.
The project is funded by the Australian Department of Foreign Affairs and Trade (DFAT) and supported by the National Cyber Security Agency of Malaysia (NACSA).
The collaboration with Universiti Kebangsaan Malaysia (UKM) will see a joint team of UoM-UKM researchers build a reference model. This will assess practical cyber incident responses in organisations.
The project aims to support the development of Malaysia’s cyber-resilience. This is an objective of Australia’s Comprehensive Strategic Partnership (CSP) with Malaysia.
Phase two will commence in May 2023 and involve three case studies. It will provide a benchmarking report for Malaysian organisations and NACSA. This report will compare the practices of Malaysian organisations against a leading Australasian financial organisation.
Up to 100 cybersecurity managers and executives across several critical infrastructure sectors will be trained on how to evaluate incident-response practices.
The project will produce a reference model to assess cyber incident response practices in Malaysian organisations.
Further reading:
https://www.austrade.gov.au/news/success-stories/austrade-helps-facilitate-cybersecurity-project-between-top-australian-and-malaysian-universities
Cyber-threat intelligence for security decision-making: A review and research agenda for practice https://www.sciencedirect.com/science/article/pii/S0167404823002626?via%3Dihub
Jane Lo, Singapore Correspondent speaks with Paul Griffin, Assistant Director of Master of IT in Business & Associate Professor, Singapore Management University.
Currently Paul is in SMU teaching postgraduate and undergraduate students in IT and FinTech as an Associate Professor of Information Systems.
He gained a PhD in quantum well photovoltaics at Imperial College London in 1997 and is now researching disruptive technologies applications and impact specializing in blockchain and quantum computing.
Prior to SMU he was leading application development on global IT projects in banking for over 15 years in the UK and Asia across the financial industry.
Paul has a number of projects on-going for analysing trade finance, transaction settlement optimization and financial market stability using quantum computing. He has been advising companies since 2014 and presenting at events, judging hackathons and moderating panel discussions on FinTech.
In this interview, Associate Professor Paul gives a glimpse into developments combining two emerging technologies – blockchain and quantum.
He first introduces the Blockchain Trilemma – the idea that it's hard for blockchains to enhance scalability and speed without sacrificing de-centralization.
He notes how the combination of Quantum computers and Quantum networks can help secure communication between blockchain nodes.
In addition, he also explains how consensus – the heart of blockchain’s decentralisation premise – could be scaled up and sped up by exploiting quantum technology.
Prof Paul also briefly touches on introducing quantum technology to artificial intelligence, and how qubits (quantum bits) could be trained up to 10x faster than using classical computing infrastructure.
Recorded 7th June 2023, 1pm, Quantum Summit, Singapore Expo.
Jane Lo speaks with Dimitris Angelakis, Chief Scientist and Founder (AngelQ Quantum Computing), Principal Investigator, CQT (Centre for Quantum Technologies, Singapore).
AngelQ Quantum Computing is a quantum software and consulting company based in Singapore. AngelQ builds architecture-agnostic quantum and quantum inspired software solutions ready for company deployment. Example industries it works with are market and consumer research, finance, energy and sustainability, and supply chain.
Angelakis completed his PhD in quantum physics at Imperial College in 2002 and his thesis received the UK Institute of Physics Quantum Electronics Thesis Prize that year. Since then, he has been leading quantum computing research teams in Cambridge, Greece and Singapore. His research awards include the 2018 Google Quantum Innovation Award and the Valerie Myerscough Award from University of London.
Dimitris G. Angelakis joined CQT in 2009 as a Principal Investigator after being a regular visitor and collaborator of the quantum group since 2003. He was born and raised in a small farm in Chania, Crete, Greece, where his childhood curiosity for the wonders of nature led him to study physics in the University of Crete in Heraklion. In 1998 he was offered a PhD position in quantum optics to work with Sir Peter Knight FRS at Imperial College London supported by the Greek State Scholarship Foundation.
His PhD work in quantum light-matter interactions received the Valerie Myerscough prize in 2000, and also the Institute of Physics UK prize in 2002. In 2001 and at age 25 he was elected college research Fellow at University of Cambridge (St Catharine's JRF) and worked in the Department of Applied Mathematics and Theoretical Physics until 2007.
A year after his move to Cambridge, the Centre for Quantum Computation in Cambridge was initiated by Artur Ekert, where he joined to work in implementations of quantum simulation and computation.
In 2008 he took over a faculty appointment at his hometown Technical University of Crete, where he in now a tenured associate professor of Quantum Physics at the School of Electrical and Computer Engineering (part time since 2012).
He is known among others for his pioneering work in quantum simulators using light-matter systems. He received the Google Quantum Innovation Prize in 2018.
In this interview, Dimitris introduces the trends of Quantum Technology, pointing to the developments in 3 rapidly emerging pillars – Quantum Computing, Quantum Networks, Quantum Devices.
Focusing on the area of Quantum Computing, Dimitris elaborates on how practical problems that require optimization, simulation and machine learning solutions would benefit from the speedup afforded by quantum technology.
Hence, for organisations to be “quantum ready”, Dimitris suggests a key first step for organisations is identifying where there are existing problems relying on optimization – such as routing and navigation.
In addition, Dimitris advises that transforming such problems to be “quantum ready” entails working with a quantum technology company to incorporate machine learning, and to co-design the quantum algorithms specific to the organisation’s problem.
Dimitris also stresses that quantum technology companies are working in partnerships with quantum hardware infrastructure providers to make quantum computing easily accessible to organisations via APIs. Such accessibility removes a major misconception that many have about quantum computing – that adoption requires acquiring specialized hardware.
With the disruptive nature of quantum technology, the need to be “quantum ready” is crucial. As such, Dimitris reminds organisations that performance and speedups goals are part of an overall journey that is foremost about learning – and in this, finding the right partner and quantum startup to work with, is one of the keys to success.
Recorded 7th June 2023, 2.30pm, Quantum Technology Summit (part of ATxSG), Singapore Expo.
Jane Lo, Singapore Correspondent speaks with Yakir Kadkoda, Security Researcher and Ilay Goldman, Security Researcher with Aqua Security
Yakir Kadkoda combines his expertise in vulnerability research with a focus on discovering and analyzing new security threats and attack vectors in cloud native environments, supply chain security, and CI/CD processes. Prior to joining Aqua, Yakir worked as a red teamer.
Ilay Goldman specializes in discovering and analyzing novel security threats and attack vectors in cloud native environments, supply chain security, and CI/CD processes. Additionally, Ilay conducts research on open-source security and vulnerabilities. Prior to joining Aqua, he worked as a red teamer.
In this interview at Black Hat Asia, Yakir and Ilay explain the complexity of a modern software supply chain, and the dependency of a typical software development cycle on open-source code, and the wide array of tools and platforms.
They note that in this supply chain ecosystem, there are many vulnerable tools and platforms trusted by majority of developers.
To highlight some examples of these vulnerabilities, Yakir and Ilay divide the development flow of many organizations into different phases – Integrated Development Environments (IDEs), Source Code Managers (SCMs), Continuous Integration/ Development (CI/CD), Package management and more.
They point out, for instance, the potential of malicious IDE extensions that may be inadvertently trusted by developers, or how threat attackers could compromise accesses to package manager platforms to impersonate malicious packages.
They also share how they found tens of thousands of tokens of open source projects that have been leaked by CI/CD platforms, which could be exploited for lateral movement.
Wrapping up, they advise that software developers practice security-by-design – that whilst “security takes time”, fixing the problem later may incur even more costs and time.
Recorded 11th May 2023, 11am, Black Hat Asia 2023, Singapore Marina Bay Sands
Jane Lo, Singapore Correspondent speaks with Sandro Pinto, Associate Research Professor and Cristiano Rodrigues, PhD candidate of the University of Minho, Portugal.
Sandro holds a PhD in Electronics and Computer Engineering. Sandro has a deep academic background and several years of industry collaboration focusing on operating systems, virtualization, and security for embedded, cyber-physical, and IoT-based systems. He has published 70+ scientific papers in top-tier conferences/journals (e.g., IEEE S&P, USENIX Security) and is a skilled presenter with speaking experience in several academic and industrial conferences (e.g., Black Hat Asia, Hardwear.io, RISC-V Summit, Embedded World). Sandro is a long-term supporter of open-source projects and is currently helping several companies and institutions to make security practical at scale.
Cristiano Rodrigues is a PhD candidate at the University of Minho in Portugal, with a master's degree in Electronic and Computer Engineering. Cristiano is a driven and skilled individual with extensive expertise in ardware/software co-design, safety-critical systems, trusted execution environments for microcontrollers, Armv8-M TrustZone, and embedded security for IoT-based systems.
In this interview, Sandro and Cristiano gave highlights of their talk on a novel class of microarchitectural timing side-channel attacks affecting MCUs.
They shared that while the discovery of Spectre and Meltdown side channel attacks exposed the potential side channel attacks on hidden transient states, there is one class of computing systems apparently is resilient to these attacks: microcontrollers (MCUs).
Sandro introduced that MCUs are at the heart of embedded and IoT device (such as smart watches, IoT home devices), and as such resource constraint in terms of computing power, memory and power consumption.
As such, he said there is a common belief that MCUs are not vulnerable to such attacks as Spectre or Meltdown, as MCUs microarchitecture is intrinsically simple - compared to the more complex microprocessors powering Cloud infrastructure, server, desktops and hence more vulnerable to side channel attacks.
Sandro and Cristiano demonstrated the fallacy of this assumption through their attack on a Smart IoT lock.
By mounting a side channel (timing) attack on a Smart lock application (that for example unlock a vault or a door), they were able to retrieve the secret PIN.
Sandro also reflected on the challenges and shared some thoughts on increasing the sophistication of the attack (e.g. remote access, alleviate the need for access to code, scaling to multiple types of microcontrollers).
Wrapping up, he stressed that sharing the results of their work is part of responsible disclosure, and advised consumers who buy IoT devices with affected microcontrollers to look out for potential announcements from manufacturers. (For an example of a follow-up action from a manufacturer ARM, see: https://developer.arm.com/documentation/ka005578/latest/)
Recorded 11th May 2023, 12noon, Black Hat Asia 2023, Singapore Marina Bay Sands
Azul is the largest provider of commercial support for OpenJDK, supporting more versions of Java than any other vendor, including Oracle.
The University of Sydney has recently selected Azul as the institution’s sole Java provider, switching from Oracle Java. The announcement takes place amid major changes to Oracle Java pricing and a rapid increase in the adoption of OpenJDK-based Java runtimes. By some estimates, usage of Oracle Java has fallen from roughly 75 per cent in 2020 to 34 per cent in 2022.
We speak with Scott Sellers, President, CEO and Co-Founder of Azul, visitng Australia from the USA to meet with customers and partners.
With more than 30 years of successful leadership in building high technology companies and delivering advanced products to market, Scott provides the overall strategic leadership and visionary direction for Azul Systems. Scott has a consistent proven track record of vision, leadership, and success in enterprise, consumer and scientific markets.
Prior to co-founding Azul Systems, Scott founded 3dfx Interactive, a graphics processor company that pioneered the 3D graphics market for personal computers and game consoles. Scott served at 3dfx as Vice President of Engineering, CTO and as a member of the board of directors and delivered 7 award-winning products and developed 14 different graphics processors. After a successful initial public offering, 3dfx was later acquired by NVIDIA Corporation.
Prior to 3dfx, Scott was a CPU systems architect at Pellucid, later acquired by MediaVision. Before Pellucid, Scott was a member of the technical staff at Silicon Graphics where he designed high-performance workstations. Scott graduated from Princeton University with a bachelor of science, earning magna cum laude and Phi Beta Kappa honors. Scott has been granted 8 patents in high performance graphics and computing and is a regularly invited keynote speaker at industry conferences.
Read more - https://chiefit.me/university-of-sydney-boards-the-azul-train/
Jane Lo, Singapore Correspondent speaks with Dagmawi Mulugeta, Threat researcher with Netskope Threat Labs.
Dagmawi has his OSCP and has previously worked at Cyrisk (a subsidiary of 4A Security), Sift Security (acquired by Netskope), and ECFMG as a researcher, security engineer, and developer. He has innate interests in public CTFs, exploit development, and abuse of cloud apps.
He has his MSc in Cybersecurity from Drexel University.
In this interview, Dagmawi shared the behavioural insights found for employees preparing to leave, and how these indicators could enable organizations to protect their data more effectively.
He noted the concern that many organisations have with “flight risk” users – that is, employees that are getting ready to leave – taking corporate data with them.
A common question to address this concern, is how to efficiently identify such risks - without sifting through hundreds of alerts and spending hundreds of man-hours.
Dagmawi shared how they approached this problem by analysing anonymized data of over 4 million users from more than 200 different organizations worldwide., and some interesting key revelations:
(i) 15% of leavers used personal cloud apps (e.g. Google drive, Gmail) to take data with them
(ii) 2% were violating corporate policy (exfiltrating sensitive corporate information)
(iii) majority of the data movement happens 50 days before leaving.
Dagmawi highlighted how they identified three key signals to filter out alerts with potential flight risks:
a) volume – identifying whether the data being moved is anomalous for the individual in the organisation
b) nature of data – whether the data being moved is sensitive
c) direction – whether the cloud application is outside of the organisation’s management (e.g. google drive).
Wrapping up, Dagmawi recommended that encoding the three signals into the detection systems could help reduce the size for reviews by 43x – that is, for every 50 alerts, the signals could help to filter out the 1 or 2 concerning ones.
Recorded 11th May 2023, 3.30pm, Black Hat Asia 2023, Singapore Marina Bay Sands.
We speak with Connell Perera, NEC Australia Cyber Security Portfolio Manager.
NEC Australia offers a comprehensive range of assessments and managed security services to provide businesses and government departments with peace of mind.
NEC Security is focussed on rapidly reducing your risk with a threat focused defence, maximising your security investment through automation and machine learning, and reducing your threat landscape by applying global expertise executed by local experts.
Founded on a Zero Trust mindset, NEC Security, with our global partners, continually apply our intelligence to grow your cyber security competency and to build your confidence as a security decision-maker, backed by a complete cyber security defence underpinned by the best people, intelligence, and technology.
Protecting your assets, increasing the return on your security investment and effort all whilst reducing your risk is our trusted NEC Security approach.
To find out more visit https://www.nec.com.au/solutions/cyber-security
We speak with Dr Daniel Floreani, Principal Consultant and Director of CyberOps, a security and blockchain consultancy.
Some of Daniel's achievements during 25+ years of experience in the communications industry, in very diverse roles include:
A PhD in communications and experience in the fundamental concepts of Networking and Defence communications.
Experience in very large Defence projects and complex engineering environments.
Exposure to Business Development and Market Creation activities in Space and Internet of Things domains
The Agora High-Tech with support by CyberOps and Flinders University Present is holding the First Australian Cyber Space Forum, Tuesday 10 October 2023.
The Australian Space Cyber Forum will provide an excellent opportunity for Australian stakeholders to meet and network with key national and international space cyber experts. Participation in this forum is targeted at researchers, entrepreneurs, academics, private consultants, public employers, and others with an interest in the space and cyber sectors.
The first national edition of the Space Cyber Forum will contain a welcome introduction followed by international speakers such as Prof. Olaf Maennel from Tallinn University of Technology in Estonia, Ms. Clemence Poirer and Mr. Marco Alberti from the European Space Policy Institute in Vienna, and more to come, followed by three specific panels. Each panel will include a discussion on approaches to solving real world issues to help organisations understand what the risks are and how to start to mitigate them, now and into the future.
· Panel 1 – ‘Space Cyber – The increasing use of cyber-attacks in the space domain’,
· Panel 2 – ‘Cyberspace and Outer Space: between regulation and militarisation’,
· Panel 3 – ‘Quantum in Space and its Security Impacts’,
Registration Link: https://lnkd.in/gNkAW7et
Michael Vrettos is a senior Marine Cyber Security Expert for RINA Classification Society in Piraeus.
He is responsible for Marine Cyber Security Services and represents RINA in IACS and EMSA related activities. ( IACS – International Association of Classification Societies, EMSA – European Maritime Safety Agency)
His past experience includes working for the EU, NATO & the Defense sector. Among other things, he’s been involved in developing a Network Security Operations Center and projects on Cyber Technologies for the European Defense Agency, European Space Agency, EU & NATO.
In this interview, Michael gave an introduction to the Maritime sector, and the stakeholders in the industry who are involved in setting the cybersecurity policy and technical standards (for example, IMO (International Maritime Organisation) and IACS (International Association of Classification Societies).
He gave a glimpse into how digitalisation in shipping with applications for route optimization, fleet performance and engine automation, (to name a few) driven by increased connectivity and bandwidth along with innovations in satellite technologies, have transformed the sector, with implications for cybersecurity. Hence, in some ways, the ship is increasingly becoming part of an overall “IoT” network.
Whilst the NotPetya incident that disrupted the sector in 2017 was an important lesson, Michael also noted the additional complexity of cyber defenses due to “Operational Technology” onboard ships using sensors, PLCs (programmable logic controllers), and various software to control ships systems such as bridge, ballast, engine, navigation, etc.
For example, the “always-on” mode means that systems cannot be easily scheduled for patching or for pen-testing in order to avoid an inadvertent disruption.
Besides basic cyber hygiene and standard cyber protection at network level, Michael also noted other vessels important systems such as the AIS (automatic identification systems) and ECDIS (Electronic Chart Display and Information System) operating with proprietary software thus making difficult to install typical cyber security measures such as antivirus or antimalware.
Wrapping up, Michael shares his views on the digital evolution and emerging cyber threats, such as those introduced by AI (artificial intelligence), and the importance of not only utilizing the benefits of technology but also investing in cyber security considering the potential risks.
Recorded 25th April 2023, 10.30am, Marina Bay Sands Singapore, Singapore Maritime Week 2023.
Ong Chin Beng is the Chief Information Security Officer at MPA (Maritime Port Authority, Singapore). Prior to this, Chin Beng overseen cybersecurity across the transport sector at the Ministry of Transport. Chin Beng graduated from Mechanical Engineering at the National University of Singapore and Cybersecurity and Management at the University of Warwick.
In this interview, Chin Beng introduced the responsibilities and roles that Maritime Port Authority, Singapore (MPA) undertakes as well as the stakeholders that MPA collaborates with to develop and grow the maritime domain and Port of Singapore.
He also gave a glimpse into the rapid pace of digitalisation in the maritime sector and the benefits to improving supply chain efficiency, vessel performance, uplifting the welfare of seafarers, and aids to progression of decarbonisation goals.
As part of the designated 11 Critical Information Infrastructure under the 2018 Singapore Cybersecurity Act, Chin Beng elaborated on some of the initiatives taken by the maritime sector to respond to the regulations, support the risk management of critical information infrastructure of MPA and port operators, and enhance cyber resilience and readiness.
One example is “Exercise CyberMaritime”, which saw MPA, holding an inaugural sector-wide maritime cybersecurity exercise to put to test, the sector’s coordination on cybersecurity incident management, emergency response plans, and crisis communications – in events such as a ransomware.
Another is the establishment of “PACC-Net” (Port Authorities CIO Cybersecurity Network), a global network that involves 11 port authorities collaborating on maritime cybersecurity to facilitate early sharing of cyber threat information, such as rules of engagement and TLP (traffic light protocol).
Chin Beng also pointed out that MPA will establish the Maritime Cyber Assurance and Operations Centre (“MCAOC” - an expansion of the Maritime Cyber Operations Centre (“MSOC”) by 2025, to progressively raise cyber resilience of onshore information systems, vessel and offshore operational technology, through collaboration among industry players, research community and firms to undertake joint development projects.
Wrapping up, Chin Beng emphasized the importance of development skills and retaining talent, and shared initiatives on growing the talent pool through work with higher institutes of learning (HIL), as well as bridging the gap between “OT” and “ICT” specialists.
Recorded 27th April 2.30pm, Marina Bay Sands Singapore, Singapore Maritime Week 2023.
Interview with Errol Weiss, Chief Security Officer, Health Information Sharing & Analysis Center (H-ISAC).
Errol has over 25 years of experience in Information Security. He began his career with NSA conducting vulnerability analyses and penetrations of highly classified US Government systems and then spent ten years with consulting firms delivering information security services such as Managed Security Services, Security Product Implementations and Secure Network Designs for Fortune-100 companies.
In 1999, Errol was a key member of the team responsible for the creation, implementation and operation of the Financial Services ISAC. He’s one of the four named inventors on the patent for Trusted and Anonymous Information Sharing.
Errol was with Citigroup from 2006 to 2016 where he created and ran the Cyber Intelligence Center, a global organization that provided actionable intelligence to thousands of end-users across the entire enterprise. From 2016 to 2019, Errol was a Senior Vice President with Bank of America’s Global Information Security team where he ran the global Cyber Threat Intelligence team. During his time with Citi and Bank of America, Errol was an active user of FS-ISAC. He served on the FS-ISAC board of directors for six years, was on the FS-ISAC Threat Intelligence Committee for 10 years and volunteered on several industry committees.
Errol has a M.S. in Technical Management from Johns Hopkins University and a B.S. in Computer Engineering from Bucknell University.
In this interview, held a day after the conclusion of the inaugural APAC Health-ISAC Summit held in Singapore, Errol shared his insights on APAC cyber threats and defenses in the health sector.
Highlighting the Health-ISAC Executive Summary Annual Threat Report 2023 “Current and Emerging Healthcare Cyber Threat Landscape”, Errol also noted the evolution of ransomware threat actors and motivations, since the 2016 WannaCry ransomware that hit the U.K. Health sector with significant impacts.
He also shared his perspectives on the changing cybersecurity landscape, including cyber defense postures, the level of awareness at the board level, and regulations such as mandatory breach reporting, over the last decade.
Errol also touched on the increased sophistication of social engineering threats potentially posed by ChatGPT, flagged as a concern at the summit.
Errol wrapped up the interview with a short introduction to Health-ISAC (Information Sharing and Analysis Centre), and the membership scope and services.
Recorded 10am, 24th March 2023, Resort World Sentosa Singapore.
More information on www.h-isac.org
The WA Cyber Security Innovation Hub is excited to be delivering the second CyberWest Summit, 10-11 May, 2023 at the Pan Pacific, Perth WA. CyberWest Summit is WA’s flagship event providing cyber security education and awareness to key sectors and highlighting WA cyber security capabilities.
The conference will deliver three content streams: Critical Infrastructure & Supply Chain Cyber Uplift, Securing Local & State Government, and Cyber Skills & Education Pathways.
Troy Hunt, a world leading security researcher and commentator, will deliver a top-rated keynote on security and other technology concepts from around the world.
We speak with Cecily Rawlinson, Director of the Cyber Security Innovation Hub.
For more information visit
https://www.cyberwestsummit.com.au/
https://haveibeenpwned.com/
https://www.troyhunt.com/
Jane Lo, Singapore Correspondent speaks with Mark ter Hove, Senior Manager, UAV &UTM, Inmarsat Aviation at Geo Connect Asia (GCA) 2023.
Over a period of 28 years, Mark has worked across Commercial, Military, Business and AAM/UAM Aviation segments as well as with the world’s largest OEM’s (Airbus, Boeing, Cobham, etc) and national governments.
Mark is considered a 'Connected Aviation' industry SME in addition to understanding how to connect the dots between navigational and operational industry solutions.
Today, Mark shapes and drives the Advanced, Innovative and Urban Air Mobility market(s). Bringing together innovators, regulators, and industry whereby through the introduction of new technologies will bring positive change to global communities.
In this interview, Mark shares the latest in UAVs (uncrewed aviation vehicles) and its role in developing the next era in aviation known as Aviation 2.0.
Mark notes the diversity of use cases in Aviation 2.0, compared to “legacy” aviation which traditionally focused on transportation of passengers and cargo. Aviation 2.0 on the other hand, is driving use cases ranging from uncrewed transportation aircrafts to drones from inspection and surveillance, and delivery.
Mark also highlights key technological requirements to power Aviation 2.0, including weight considerations of satellite communication terminals and reliability of communication links.
He also notes that contrary to most perceptions, when it comes to security and safety of UAVs, much still needs to be done to address privacy concerns.
On the topic of urban mobility, Mark predicts that we will see the reality of air taxis in 5 to 6 years.
Recorded 16th March 2023, 9am SGT, Marina Bay Sands, at the third edition of Southeast Asia’s flagship geospatial and location intelligence conference Geo Connect Asia (GCA) 2023 and the co-located inaugural edition of Drones Asia, a platform designed to capture the commercial demand for aerial, unmanned and ground-based solutions amid the region’s expanding UAV ecosystem.
Interview with Sumedh Thakar, President and CEO of Qualys on his visit to Australia and New Zealand to meet with customers and partners for a cyber risk management briefing: Has the ‘Language of Risk’ Evolved Enough to Save Us All?
Recorded on 16 March, 2023.
For more information visit www.qualys.com
We speak with James Sillence, Vice President, Technical Account Management, South Asia for Tanium.
____
JOIN US ON APRIL 4, 2023 for a special virtual deep-dive with Tanium - register here https://www.eventbrite.com.au/e/stay-ready-so-you-dont-need-to-get-ready-tickets-559265035777
____
Tanium defends every team, endpoint and workflow against the largest attack surface in history by delivering the industry’s first convergence of IT management and security operations with a single platform under a new category, Converged Endpoint Management (XEM).
The integrated offering links IT operations, security and risk teams from a single pane of glass to provide a shared source of truth, a unified set of controls, and a common taxonomy that brings together siloed teams for a shared purpose — to protect critical information and infrastructure.
James has over 36 years of IT experience spanning diverse areas such as Cybernetics and Control Systems, Network and Application Performance, Data Storage and most latterly, Risk and Security.
For the last 10 years, James has been leading technology teams, helping organisations get the most from the solutions that they use to manage and protect their digits assets.
JOIN US ON APRIL 4, 2023 for a special virtual deep-dive with Tanium - register here https://www.eventbrite.com.au/e/stay-ready-so-you-dont-need-to-get-ready-tickets-559265035777
Mark Stickells leads the Pawsey Supercomputing Research Centre, a critical national research infrastructure located in Perth, Western Australia.
Before joining Pawsey, Mark led joint ventures between universities, CSIRO and industry delivering national and international research and education programs for Australia’s key energy, resources and agricultural sectors.
Appointed as a Fellow of the Australian Institute of Management in WA in 2019 and a Fellow of the Australian Institute of Company Directors in 2020, Mark is also member of CEO’s for Gender Equity.
Committed to supporting diversity and inclusion initiatives in his professional and personal life, Mark is an enthusiastic advocate for Pawsey's expertise and enterprise contributing to prosperity and well-being in its region, and for the nation and internationally.
Aditi is a dynamic digital communicator and tech enthusiast, who is driven by her passion for creating diverse and inclusive cultures. She is a strong advocate for opening doors for girls and underrepresented groups.
With her deep understanding of the tech world and her drive for change and a diversity champion at the Pawsey Supercomputing Research Centre, Aditi works tirelessly to challenge the status quo and create a more inclusive and equitable community.
In this interview at SupercomputingAsia 2023 – which returned to a physical format since 2019 - Mark and Aditi shared some of the key developments at Pawsey Supercomputing Centre (Perth, Australia).
Kicking off the interview, Mark highlighted some of the initiatives in the four years at Pawsey (since the last physical format) – including Pawsey’s exascale-class system, Setonix (named after Western Australia’s marsupial, the quokka) which is the Southern Hemisphere’s most powerful, energy efficient supercomputer.
He provided some examples of how Pawsey support science (as such specialist support for international radioastronomy projects such as the multinational Square Kilometre Array) and life-saving research projects (such as advanced monitoring and predictive analysis of patients in critical care).
On the rate at which “IT” (including supercomputing) consumes energy, Mark noted some of the “energy future” work – such as novel use of battery and other technologies to accelerate efforts towards net zero supercomputing.
To provide essential compute and data infrastructure and HPC services supporting Australian researchers, Aditi pointed to the importance of talent development – including diversity and inclusivity, and internship programs for students.
Mark and Aditi also touched on the collaborations to progress the quantum computing efforts by industry and government researchers.
Wrapping up, Mark and Aditi shared how Pawsey is now part of the “exascale” community, and how Pawsey will continue to actively support collaborations and sharing to tackle challenges beyond borders.
Recorded 1st March 2023, 8.30am, SuperComputingAsia 2023, Singapore Expo.
Previous interview with Mark Stickells of the Pawsey Supercomputing Research Centre is available here https://blubrry.com/mysecurity/42779200/episode-146-high-performance-computing-hpc-and-why-it-matters-for-australia-pawsey-supercomputing-centre/
The WA Cyber Security Innovation Hub is excited to be delivering the second CyberWest Summit, 10-11 May, 2023 at the Pan Pacific, Perth WA. CyberWest Summit is WA’s flagship event providing cyber security education and awareness to key sectors and highlighting WA cyber security capabilities.
The conference will deliver three content streams: Critical Infrastructure & Supply Chain Cyber Uplift, Securing Local & State Government, and Cyber Skills & Education Pathways.
Troy Hunt, a world leading security researcher and commentator, will deliver a top-rated keynote on security and other technology concepts from around the world.
Troy Hunt created HIBP as a free resource for anyone to quickly assess if they may have been put at risk due to an online account of theirs having been compromised or "pwned" in a data breach.
For more information visit
https://www.cyberwestsummit.com.au/
https://haveibeenpwned.com/
https://www.troyhunt.com/
Recorded 8 March, 2023 for MySec.TV
Satoshi Matsuoka (https://en.wikipedia.org/wiki/Satoshi_Matsuoka) from April 2018 has been the director of Riken Center for Computational Science (R-CCS), the Tier-1 national HPC center for Japan, developing and hosting Japan’s flagship ‘Fugaku’ supercomputer which has become the fastest supercomputer in the world in all four major supercomputer rankings in 2020 and 2021 (Top500, HPCG, HPL-AI, Graph500), along with multitudes of ongoing cutting edge HPC research being conducted, including investigating Post-Moore era computing, especially the future FugakuNEXT supercomputer.
He was the leader of the TSUBAME series of supercomputers that had also received many international acclaims, at the Tokyo Institute of Technology, where he still holds a professor position, to continue his research activities in HPC as well as scalable Big Data and AI.
His longtime contribution was commended with the Medal of Honor with Purple ribbon by his Majesty Emperor Naruhito of Japan in 2022. Other accolades include the Fellow positions in societies/conferences ACM, ISC, and the JSSST; the ACM Gordon Bell Prizes in 2011 & 2021; the IEEE-CS Sidney Fernbach Award in 2014 as well as the IEEE-CS Computer Society Seymour Cray Computer Engineering Award in 2022, both being the highest awards in the field of HPC, and the only individual to receive both awards; the Technical Papers Chair and the Program Chair for ACM/IEEE Supercomputing 2009 and 2013 (SC09 and SC13) respectively as well as many other conference chairs, and the ACM Gordon Bell Prize selection committee chair in 2018.
In this interview, Professor Satoshi Matsuoka shared some of the highlights from his talk at SuperComputingAsia 2023 (Singapore), including the supercomputing developments in Japan, and Fugaku, the largest in Japan and one of the first 'exascale' supercomputers of the world.
With applications ranging from manufacturing, disaster prevention to creating new drugs, he noted that supercomputers allow us to investigate the past, and to predict the future.
To give the audience context, Professor compares Fugaku supercomputer to everyday applications such as gaming (create “virtual worlds, but much more in a scientific way”), and smart phones (20 million times more powerful than a smartphone).
In terms of power consumption, it is equivalent to running the Tokyo Disney Resort, and as such, power efficiency is critical in the overall management and operations of Fugaku – especially with carbon neutrality as a key agenda topic today.
Professor Satoshi Matsuoka also touched on cybersecurity and how privacy and anonymisiation are growing areas of focus with the increasing adoption of digital twins in medical sciences.
Wrapping up, he pointed out some short term goals for supercomputing in Japan to realise further synergies with the “IT” industry, and the efforts for the successor of Fugaku, FugakuNEXT, to be deployed around 2029.
Recorded 28th February 2023, 12noon, SuperComputingAsia 2023, Singapore Expo.
Shota Shinogi is a security researcher at Macnica (Japan), pentest tools author and CTF organizer.
He is an expert in writting malware for Red Team purpose and to evade the detection from EDR, sandbox, IPS, antivirus and other security solutions.
He has more than 10 years experience on the Cyber security industries, starting his carrier with HDD Encryption, NAC, IPS, WAF, Sandbox. He has spoken in several security/hacking conferences; Black Hat, DEF CON, BSides.
He is also contributing for the education for the next generation security engineer through the Security Camp from 2015 consecutively in Japan.
In this interview, Shinogi gave highlights of his hackathon session (as an instructor at the Global Cybersecurity Camp 2023) on PowerShell based Malware detection
He shared the key factors behind PowerShell’s potency (a default tools on Windows, file-less, and hundreds of methods to obfuscate the script, making detection even that much harder).
However, with the logging feature built by Microsoft, it is possible to build tools to detect malicious PowerShell script.
Shinogi noted the approaches that the impressive results delivered by the hackathon – there were even AI-based algorithms to filter out malicious PowerShell scripts.
Recorded 16th February 2023, 4.30pm, ASEAN Cybersecurity Centre of Excellence Singapore, at the Global Cybersecurity Camp 2023 Singapore.
DigiCert, Inc., a leading global provider of digital trust, have releases DigiCert® Trust Lifecycle Manager, a comprehensive digital trust solution unifying CA-agnostic certificate management and public key infrastructure (PKI) services.
Trust Lifecycle Manager tightly integrates with DigiCert’s best-in-class public trust issuance for a full-stack solution governing seamless management of corporate digital trust infrastructure.
The 2022 State of Digital Trust Survey revealed the cost of poor security practices, finding that almost half of consumers have stopped doing business with a company after losing confidence in its digital trust competency.
Trust Lifecycle Manager brings together:
• Certificate lifecycle management, streamlining IT operations with certificate discovery, management, notification, automation and integration.
• PKI services, streamlining identity and authentication with private certificate issuance for users, devices, servers and other IT resources, and management of the CA hierarchy.
This unified management of a company’s digital trust fabric delivers:
• A full-stack solution in a single pane of glass that offers superior performance, handling and automation, with single vendor accountability.
• Certificate profiles and tools facilitating self-service issuance.
• Flexibility for cloud, on-premises or hybrid models, enabling companies to manage their PKI use cases according to their security policy preferences.
• Centralised visibility and control over a company's certificate landscape, reducing risk of business disruption and securing identity and access across the organisation.
• Deep integration into user and enterprise technologies, supporting existing business systems and processes.
We speak with Brian Trzupek, Senior Vice President of Product at DigiCert. A crypto and security tech by day and night, Brian brings nearly two decades of expertise on many security subjects to the team. He's constantly innovating use cases for enterprise PKI.
He previously worked for more than six years as VP of Managed Identity and Authentication at Trustwave where he helped fight cybercrime, protect data, and reduce security risk. While at Trustwave, he testified before a congressional panel on the Dec. 2013 Target breach. Prior to Trustwave, he was a founder of Creduware Software, Inc., a company that automated credential password and digital certificate renewal and installation, as well as policy based application monitoring.
Trust Lifecycle Manager is generally available now as part of the DigiCert® ONE platform.
To learn more, visit www.digicert.com/trust-lifecycle-manager
Dave has 30 years of industry experience. He has extensive experience in IT security operations and management.
He is the founder of the security site Liquidmatrix Security Digest & podcast as well as the host of DuoTV and the Plaintext podcast. He is currently a member of the board of directors for BSides Las Vegas.
Previously he served on the board of directors for (ISC)2 as well as being a founder of BSides Toronto conference. Dave has been a DEF CON speaker operations goon for over 10 years. Lewis also serves on the advisory board for the Black Hat Sector Security Conference and the CFP review board for 44CON.
He is currently working towards his graduate degree at Harvard. Dave has previously written columns for Forbes, CSO Online, Huffington Post, The Daily Swig and others. For fun he is a curator of small mammals (his kids) plays bass guitar, grills, is part owner of a whisky distillery and a soccer team.
In this interview, Dave Lewis shares his highlights from his keynote presentation at SINCON 2023, the first cybersecurity conference in Singapore for the year 2023.
Globalisation and supply chain attacks - He shared his thoughts on how threat actors have exploited globalisation of supply chain: that as organisations move to a cloud-based iteration “for everything” and thereby extending targets of opportunities for the attackers. This means that we have extended from protecting the “four walls” to an “unfathomable number of walls”. In particular, as we digitalise, we have to “make sure we are not outpacing security”, and that we understand our fallback position if “there’s a global catastrophe and we have to cut off from the rest of the world.” One example is critical infrastructure, where there is “accumulated security debt” (e.g. deprecated applications) and where “stakes are higher”.
Zero trust - Dave stressed that “zero trust” is an “iterative process” and there is “no end state”. Rather, it is about reducing the risks and addressing the core fundamentals from 30 years ago – managing our core users, our network segmentation, critical applications in our environment.
Cybersecurity skills and resources - Dave also shared how we need “more adults at the table”, that maturing our cybersecurity posture requires more senior level involvement. He also advised that we need to “get away from the “sensationalisation” of the hacker culture” – that cybersecurity is not strictly the hacker sub-culture.
Cyber threat landscape - Using Wannacry as an example, Dave noted that the SMBv1 vulnerability had been known but remained unfixed for 10 years. This “security debt” was an example of how we as cybersecurity practitioners tend to “lose our focus collectively”. As we are at that “juncture where we have to figure out how we are going to mature as an industry and be able to handle these risks in a coherent fashion”, he predicted that “we will keep making the same mistakes for a while.”
Further, referencing how the ransomware have evolved since the first version by Dr Joseph Popp in 1989, he said “financial motivation will not go away, it is just how they are going to get their money.”
Recorded 5th January 2023, 11.30am, VOCO hotel, Singapore.
Rapid7 unites cloud risk management and threat detection to deliver results that secure your business and ensure you’re always ready for what comes next. Reduce your attack surface and eliminate threats with zero trade-offs.
Lee Weiner is an IT security technology leader with more than 25 years’ experience taking software products to market and managing the product lifecycle end-to-end while scaling a team.
As Senior Vice President of Cloud Security and Chief Innovation Officer at Rapid7, Lee is responsible for leading the direction and delivery of the company’s entire assessment and response product portfolio as well as its innovation initiatives.
Before joining Rapid7, Lee was VP of products at LogMeIn, Inc., a provider of cloud-based remote connectivity solutions, where he was responsible for product delivery, product management and product marketing for LogMeIn's remote support product. Lee has also held leadership roles at several software security firms, including Netegrity, Inc., IMlogic, Inc., and Symantec Corporation.
Lee received a Bachelor of Arts (BA) degree from the University of Massachusetts.
This interview follows our interview with the Rapid7 CEO and Chair of the Board, Corey Thomas during his visit to Australia and New Zealand in November 2022 - to listed to this interview visit https://mysecuritymarketplace.com/av-media/episode-343-reducing-the-attack-surface-ciso-roundtable-takeaways/
Resilience has emerged as a top priority as a staggering 70 percent of organisations surveyed said they had experienced a security event that impacted business in the past two years.
These incidents resulted in severe repercussions for the companies that experienced them, along with the ecosystem of organisations they do business with.
With stakes this high, it is no surprise that executives surveyed for the report said that security resilience is a high priority for them.
Helen Patton is an Advisory CISO at Cisco, where she shares security strategies with the security community. Previously she spent eight years as the CISO at The Ohio State University where she was awarded the 2018 ISE North American Academic/Public Sector Executive of the Year. Before joining Ohio State she spent ten years in risk and resiliency at JPMorganChase.
Helen actively encourages collaboration across and within industries, to enable better information security and privacy practices. She believes in improving diversity and inclusion in the workforce, and mentors people interested in pursuing careers in security, privacy and risk
management. She advocates for more naps and is anti-bagpipes.
Helen has a Master’s degree in Public Policy and has earned various industry certifications. She
serves on the State of Ohio CyberOhio Advisory Board, the Manufacturing and Digital USA Cybersecurity Advisory Board, and the Ohio State University College of Electrical and Computer Engineering Industry Advisory Board. She is a faculty member for the Digital Director’s Network, and the Educause Leadership Institute.
Further Reading: https://cyberriskleaders.com/70-of-australian-organisations-say-cyber-events-impact-business/
Recorded at Cisco Live, Melbourne, Thursday 8 December, 2022
On a recent visit to Australia and New Zealand, Corey Thomas, CEO and Chair of the Board for Rapid7 participated in a number of Executive Cybersecurity Roundtables with CISOs and Heads of Security in Sydney, Melbourne and Auckland, including presenting to a Cyber Risk Meetup in Melbourne.
Each session produced a lively and very productive discussion amongst some senior cybersecurity leaders representing banking, financials, property management, telecommunications, healthcare, media, distribution, service delivery and logistics.
Some of the key takeaways included the challenges of resources and skill sets, and the current threat landscape with significant breaches causing boards and ELTs to ask questions on respective cybersecurity posture and maturity.
Threat intelligence was also an area of interest and all agreed needs to be filtered and directed by the cybersecurity strategy for specific requirements and what can be actioned.
Reference was made to the ASX 200 Threat Landscape report provided by Rapid7, available here https://australiancybersecuritymagazine.com.au/reducing-the-attack-surface/
Lum Chune Yang (co-founder and CEO of SpeQtral) brings with him experience in technology and business roles in quantum, space and telecommunications sectors.
He was previously Head of Strategic Development at CQT (Centre for Quantum Technologies) with a concurrent appointment as Deputy Director, Industry Engagement and Partnerships at NUS (National University of Singapore), where he was responsible for engagements with industry and government stakeholders in commercializing technologies.
Prior to that, he was responsible for business development at SES, a global satellite operator, working with both government and commercial customers on telecommunication satellite programmes. He also spent time in China and the US as a management consultant with ZS Associates, advising MNCs on a variety of strategy, M&A and marketing topics.
He has an academic background in quantum and physics research during his early career. Chune Yang holds an MBA from INSEAD, an MSc in Physics from the Pennsylvania State University, and a BSc (Hons) in Physics from NUS
In this interview, Chune Yang shares with the audience on the launch of Southeast Asia’s first Quantum Networks Experience Centre (QNEX), and the recent trial toward setting up Quantum-Secure Networks using quantum-enabled encryptors and Quantum Key Distribution (“QKD”) system.
He explains that “what we have today in our cell phones, the semi-conductor chips, the lasers we use – all use quantum phenomena.” Quantum 2.0 or the “quantum future”, is the ability to manipulate and control each quantum, such as a photon - a single particle of light, or an atom, which leads to the implications such as quantum computers and quantum communications.
Noting that “one thing that quantum computer can do, is that it will break most of the encryption that we have today”, he points to an emerging “store and decrypt later” threat - where threat actors wiretap and store data in some data centre – to decrypt later when they want to hack into the communication.
QKD, by “embedding the secret key in particles of light and transmitting it across to the end users”, Chune Yang says, will help to secure and encrypt any communication or data that we transmit to each other.
He also shares how the QKD will be extended beyond the terrestrial implementation to space using satellites to address photon degradation challenges.
Chune Yang also stresses that we are early on the evolution of the “quantum future”, which includes quantum internet and quantum networks – concepts that are much richer than secure encryption.
Recorded 16th November 2022, 9am, SpeQtral, Fusionopolis, Singapore.
Tim serves as the Technical Director - ICS and SCADA programs at SANS, and is responsible for developing, reviewing, and implementing technical components of the SANS ICS and SCADA product offerings. Additionally, performing contract and consulting work in the areas of ICS cybersecurity with a focus on energy environments.
A recognized leader in CIP operations, he formerly served as the Director of CIP (Critical Infrastructure Protection) Compliance and Operations Technology at Northern Indiana Public Service Company (NIPSCO) and was responsible for Operations Technology, NERC CIP Compliance, and the NERC training environments for the operations departments within NIPSCO Electric.
Recognizing the need for ICS-focused cyber security training throughout critical infrastructure environments and an increased need for NERC CIP hands-on training, Tim authored and instructs the ICS curriculum's newest course ICS456 - Essentials for NERC Critical Infrastructure Protection.
Outside of SANS, Tim continues to perform contract and consulting work in the areas of ICS cyber security with a focus on the energy sector.
Before accepting the opportunity to join SANS, Tim enjoyed a 15-year career with NIPSCO (Northern Indiana Public Service Company) - one of Indiana's largest natural gas and electric companies in the state, where he held management and leadership positions as well as EMS Computer Systems Engineer responsibilities over the control system servers and the supporting network infrastructure.
During his career, Tim has served as the Chair of the RFC CIPC, Chair of the NERC CIP Interpretation Drafting Team, Chair of the NERC CIPC GridEx Working Group, and Chair of the NBISE Smart Grid Cyber Security panel.
In this interview held on-site at the SANS ICS APAC Summit and Training 2022, Tim shares his insights on the developments in ICS (Industrial Control Systems).
He starts by explaining the evolution of the term “ICS” into “cyber-physical” – from “data-at-rest, data-in-use, data-in-motion” perspective to one where “data that does something, data that means something,” or in other words, data that has a “kinetic component,” a “physics component.”
Viewed this way, cyber-physical systems could be large scale, like SCADA covering multiple states, or could be on a plant floor distributed control system, could be individual PLCs, or the IIoT (Industrial Internet of Things) which are “using small edge devices to control parts of buildings, or SMART cities or transportation.”
Tim also gives an update on the threat landscape in cyber-physical systems and how intellectual property/data theft has evolved to process manipulation. The latest is the recently discovered malware – “Pipedream,” where the modularity of the malware framework is a “force multiplier.” By piecing different malicious components, he explains that threat actors can achieve their goals without knowing their specific environments – and also across multiple sectors.
Besides the evolving threat landscape, Tim also touches on varied levels of digital adoption in the cyber-physical environment across sectors means that the SANS courses are necessarily developed for professionals coming from a variety of experiences and cover legacy, existing, and new environments.
Depending on the complexities of the infrastructure specific to the country, Tim also shares his perspectives on differing priorities and approaches when it comes to cyber protection.
Recorded on 21st November 2022, 3pm, Grand Copthorne Hotel, Singapore.
We speak with Larry Clinton, author of Cybersecurity for Business.
Larry is the president of the Internet Security Alliance. He advises industry and government on cyber policy and regularly appears in the media to provide an expert opinion. He has briefed NATO, the Organization of American States (OAS), G-20 and the US Congress. He has twice been named to the NACD 'Directorship 100' list of the most influential individuals in corporate governance. Larry is also the author of the published book, 'Cybersecurity for Business'.
The Internet Security Alliance provides thought leadership in cybersecurity and works with the US government to advocate for public policy that will advance the interests of cybersecurity.
For a copy of the book head to https://www.koganpage.com/product/cybersecurity-for-business-9781398606142
Interview recorded on MySec.TV on Friday 21 October, 2022
In this episode, we speak with Wilson Ang, a dispute resolution lawyer at Norton Rose Fulbright Singapore and head of the Asia regulatory compliance and investigations practice, as well as Jeremy Lua, a dispute resolution lawyer at Norton Rose Fulbright Singapore focusing on regulatory investigations and compliance.
Wilson focuses on strategic governance issues, including conducting internal investigations on business ethics and anti-corruption matters, often involving the US Foreign Corrupt Practices Act, the UK Bribery Act, and the Singapore Prevention of Corruption Act. Wilson has extensive experience designing and implementing compliance programs, conducting integrity due diligence reviews and handling complex and sensitive issues involving bribery, fraud, sanctions, money laundering/terrorist financing, cyber-security attacks, data breach incidents, competition law and financial services regulatory violations in Asia and beyond. Wilson's practice also involves ESG issues like modern slavery and business human rights due diligence, health and safety matters, environmental regulatory disclosures and corporate governance.
Jeremy is experienced in a broad range of complex regulatory investigations and compliance matters, focusing on data protection, cybersecurity and technology matters, often assisting clients in navigating crisis situations, such as responding to data breach and cybersecurity incidents. He has also represented and advised clients on investigations initiated by the Personal Data Protection Commission of Singapore (PDPC). Jeremy’s practice includes matters involving anti-bribery and corruption, anti-money laundering, sanctions, export controls and financial fraud, as well as ESG issues like modern slavery and business human rights due diligence. Before joining Norton Rose Fulbright, Jeremy was a Deputy Public Prosecutor at the Attorney-General's Chambers of Singapore, with a focus on technology crime.
In this podcast, Wilson and Jeremy share the latest updates in cybersecurity and data protection regulations across the Asia region, and the legal considerations that organisations need to keep in mind when developing cybersecurity and data protection measures.
The ongoing digital transformation has increased the available surface areas for threat actors to exploit, including human processes. Wilson shares an example of how Norton Rose Fulbright advised an international bank in its efforts to recover almost half a million dollars from a sophisticated attack by a threat actor, which conducted a lot of reconnaissance work to succeed with its attack.
The ongoing Razer vs Capgemini case has also put a spotlight on third-party risk in the data privacy context. Wilson provides a broad perspective on third-party IT supplier risk management, noting that “digital supply chains can be a point of weakness for the organisation. The chain reaction from a single attack on one supplier can compromise the whole network of organisations downstream”. He cautions that, however, “trying to obtain recourse is not straightforward.”
Jeremy expands on this issue, providing an overview of the breach notification obligations, including expected timeframes and considerations around the risk of harm. He advises organisations not to “jump the gun”, and instead focus on securing a reasonable level of confidence in the facts of the matter, before taking the next step.
On the prevalent threat of ransomware and the rise of the ransomware-as-a-service model, they urge organisations to take note of sanctions requirements surrounding ransomware payments—especially for those operating in multi-markets—to avoid triggering further legal issues.
Wilson and Jeremy wrap up the podcast by sharing some of the emerging cybersecurity and data protection regulations that they are tracking in the region. These include the Chinese Personal Information Protection Law and Thailand’s Personal Data Protection Act, which came into force on 1st June 2022. Wilson also shared that, when it comes to personal data breach incidents, there is increasing recognition of emotional distress as a form of actionable “loss or damage”.
Jane Lo, Singapore Correspondent speaks with Wilson Ang, Partner, Head of Asia Regulatory Compliance and Investigations practice, Norton Rose Fulbright Singapore and Jeremy Lua, Dispute Resolution Lawyer, Norton Rose Fulbright Singapore.
Cybersecurity has become too complex for most organisations. While every organisation wants the best cyber defences, few have the skilled resources to deliver them.
Almost every organisation has a strategic initiative driving their digital transformation journey. Customers need to be served digitally and remotely, rather than visiting physical locations. Employees need to remain productive despite needing to work from home. The nature of an organisations network changed fundamentally, and a much larger and more vulnerable attack surface was exposed to attackers using more sophisticated methods. The traditional response is to buy yet more cybersecurity technology further overwhelming security operations teams, which in many SME is a single person also responsible for many other IT tasks.
Despite organisations spending record budgets on cyber-defences, attackers are more successfully infiltrating networks and remaining undetected for longer. The current model isn’t working for most organisations.
That is why organisations are increasingly searching for an alternative path, that allows them to reduce risk, increase efficiency and reduce costs. Characteristics needed to achieve these 3 improvements are:
Security Operations Centre that includes proactive threat hunting and neutralization
Integrated cybersecurity defences allowing automated responses to security events, avoiding the need to involve a human thereby increasing time to response and increasing efficiency
Expert Cybersecurity Professionals available whenever required without the challenge and cost of hiring and retaining role such as incident responders, threat analysts and cyber threat hunters
Unified Management enabling the in-house team to work more efficiently at a single console
Sophos provide this Cybersecurity as a Service, built on 37 years expertise securing organisations of all sizes, geographies and industries.
We speak with Hywel Morgan, Manager, Systems Engineering for ASEAN and Korea, Sophos.
Read More
https://mysecuritymarketplace.com/sophos-cybersecurity/
Bill Nelson is the Chair of Global Resilience Federation (GRF). GRF is a non-profit association dedicated to helping ensure the resilience and continuity of critical and essential infrastructure and organizations against threats, incidents and vulnerabilities.
Previously, Nelson was the President and CEO of the Financial Services Information Sharing and Analysis Center (FS-ISAC). In his 12 years, Nelson led FS-ISAC in its response to major cyber and physical threats and vulnerabilities that affected the financial services industry, including partnering with Microsoft to take down four major botnet infrastructures. He was also responsible for creating the Sector Services Division of FS-ISAC, which was established to assist other sectors and became the genesis for launching Global Resilience Federation.
Nelson was named the fifth most influential person in the field of financial-information security by the publication Bank Info Security and he also received the prestigious RSA Award for Excellence in Information Security.
Before joining FS-ISAC, Nelson was the Executive Vice President of NACHA, the electronic payments association, where he oversaw the development of the ACH Network into one of the largest electronic payment systems in the world, processing nearly 14 billion payments by the time he transitioned to FS-ISAC.
In this podcast, Bill introduces the audience to ISACs (Information Sharing and Analysis Centre), and the formation of OT-ISAC (“Operational Technology ISAC”), which was established under Pillar 2 of Singapore’s OT Cybersecurity Masterplan launched at Singapore International Cyber Week 2019.
He stresses how is trust is important in supporting effective information sharing, and how initiatives, such as the Traffic Light protocol is critical to facilitating sharing with the appropriate audience.
Bill also highlights the prevalence of wiper malware in the Russian-Ukrainian conflict in cyber space and the impacts in Asia. With the rising threat landscape, Bill advises organisations to adopt a “defence-in-depth” approach to withstand and recover from cybersecurity incidents.
To minimize service disruptions in the face of destructive attacks and events, he also points to the need for building resiliency. Referencing GRF’s “Operational Resilience Framework”, he explains how the multi-sector working group is developing rules and implementation aids that support the organisation’s recovery of immutable data.
Interview by Jane Lo, Singapore Correspondent. Recorded on-site at OT-ISAC Summit 2022 held at the VOCO Hotel, Orchard Road, Singapore on 7th September 2022 4.30pm.
Stuart Campbell is the Information Technology Manager at Ruapehu District Council, New Zealand. Stuart, who pioneered the use of drone technology at the council, designs and leads the council’s project to use drone technology to create 3D maps of cemeteries
He is also a highly prolific writer in the past few years, all while working his full time job at the Ruapehu District Council. He also trains others in martial arts, a passion Stuart has held for decades and which inspires his writing.
In this on-site interview at the Raffles Town Club in Singapore, Stuart gives some highlights of his presentation in Singapore at AIBotics on “Drones Surveying – From Cemeteries to Modern Buildings.”
He explains how the Ruapehu District Council in New Zealand is mapping out its cemeteries using high-definition cameras on a drone. Flying the drone on a lower attitude also produces better resolution images than the legacy solution which relies on cameras at 15,000 feet.
Stuart also shares some tips and lessons, and behind the scenes challenges, giving an example of how a simple occurrence of reflection could affect the image taken by the drone camera.
While drones are fun, he advises that before jumping into implementing the technology to carefully consider the regulations such as weight and situational restrictions. He also notes other considerations for drone operators, including the types of drones, the times of day or even the climate and battery power consumption.
From a drone security and safety perspective, while Stuart shares that he has never been hacked, he confesses to having crashed a few drones.
Recorded by Jane Lo, Singapore Correspondent on-site at the Raffles Town Club in Singapore, 23rd August 2022.
Jane Lo, Singapore Correspndent speaks with Zoltán Balázs, Head of Vulnerability Research at CUJO AI. CUJO AI is a company focusing on home IoT Security.
Before joining CUJO AI he worked as a CTO for an AV tester company, an IT Security expert in the financial industry for five years, and as a senior IT security consultant at one of the Big Four companies for two years. His primary areas of expertise are penetration testing, malware analysis, computer forensics and security monitoring. He released the Zombie Browser Tool that has POC malicious browser extensions for Firefox, Chrome and Safari. He is also the developer of the Hardware Firewall Bypass Kernel Driver (HWFWBypass), the Encrypted Browser Exploit Delivery tool (#IRONSQUIRREL) and the Sandbox tester tool to test Malware Analysis Sandboxes. He found and disclosed a vulnerability in IP cameras, and this vulnerability was exploited by the Persirai botnet, running on ˜600 000 cameras.
Zoltán has been invited to give presentations at information security conferences worldwide including DEF CON, SyScan360, SAS2018, Virusbulletin, Disobey, Deepsec, Hacker Halted USA, Botconf, AusCERT, Nullcon, Hackcon, Shakacon, OHM, Nopcon, Hacktivity, and Ethical Hacking. Proud OSCE.
In this on-site interview at “Hack-in-the-Box” held at the Singapore Intercontinental Hotel, Zoltán gives some highlights of his presentation on “Web3 + Scams = It’s a Match!”
Sharing his perspective on what the Web3 world encompasses – including non-fungible tokens (NFTs) – he explains how some of the over-valuations reported in the media for NFTs may leave an impression of fraud and scams.
He also points out how some of the old fashion investment scams such as “rug pulls” and “pump and dump” still plagues the Web3 world. One common tactic, such as preying on victim’s “fear of missing out” (FOMO) on an attractive investment, can also be seen in the promotion of Bored Apes Yacht Club NFT collection.
Zoltán also outlines a highly notable scam known as the “Squid Game” rug pull, where the combination of the ease of creating tokens, and the popularity of the Netflix TV show lured victims to put money into the fraudulent investment scheme.
To avoid falling victim to one of the scams, Zoltán’s advice is “take time, don’t rush.”
Recorded on-site at the Singapore Intercontinental Hotel in Bugis, 26th August 2022, 11am Singapore Time.
Jane Lo, Singapore Correspondent speaks with David Pethes, Co-Founder, Qrucial, Head Ambassador for Eastern Europe of Polkadot.
David is a Web3 researcher and security expert that founded the largest crypto hacking competition in the world called CCTF (Crypto Capture the Flag). He is also the co-founder of QRUCIAL and has more than 10 years experience in IT penetration testing and got several global certifications. Since 2021 he is the Head Ambassador for Eastern Europe of Polkadot – a sharded protocol that enables blockchain networks to operate together seamlessly.
In this on-site interview at “Hack-in-the-Box” held at the Singapore Intercontinental Hotel, David shares some of the highlights of his presentation on “Breaking Web3: Exploitation Techniques for Cryptocurrency Hacking.”
Introducing his perspectives of what Web3 encompasses, and the history of smart contracts, David shares that Web3 world is more than just technological changes (and bitcoin). Enabled by smart contracts, he observes how Web3 presents opportunities for societal and monetary innovations.
David points to how the emerging Web3 architecture is built on both blockchain concepts as well as components from centralised computer infrastructure (such as SQL databases) in traditional architecture. Security vulnerabilities in Web3 therefore, he notes, comprise of new emerging threats, as well as the ones commonly observed in today.
David wraps up the interview with an introduction to his Crypto Capture the Flag (CCTF) contest, which provides a legitimate platform to challenge white-hat hackers to find vulnerabilities in the rapidly evolving Web3 infrastructure.
Recorded on-site at the Singapore Intercontinental Hotel in Bugis, 25th August 2022, 7pm Singapore Time.
We speak with Daniel O’Toole, Senior Adviser for Space within the Sector Team for Defence, Space and Infrastructure at the Australian Trade and Investment Commission (Austrade).
In addition to his role at Austrade, Daniel has also served as partial secondee at the Australian Space Agency since 2018. In this capacity he works on joint Austrade-Space Agency initiatives that help promote the growth of the Australian space industry through international market programs and opportunities.
Prior to joining Austrade in 2016, Daniel worked for two Japanese organisations that worked to build partnerships in Australia. He worked for the Japan Oil, Gas and Metals Organisation (JOGMEC), where he led research on issues impacting the local minerals market. He then worked for the Japan External Trade Organisation (JETRO) in Sydney, helping to connect Australian and Japanese businesses and increase two way trade and investment between Japan and Australia.
Daniel holds a Bachelor of International Studies from the University of New South Wales and a Masters of Strategic Affairs from the Australian National University.
Recorded for Australia in Space TV, Friday, 29 July 2022 (Due to a technical issue the video version is not available)
For more episodes visit www.australiainspace.com.au
Jane Lo, Singapore Correspondent speaks with Pasi Koistinen, Chief Information Security Officer (CISO), Coinhako
Pasi Koistinen is the Chief Information Security Officer (CISO) of Coinhako, Singapore’s market-leading crypto platform. Pasi drives Coinhako’s information security policies and is responsible for developing and establishing a world-class security framework to prevent, assess, and tackle internal and external threats to the company.
Previously he co-founded two cybersecurity companies, Cyber Intelligence House in Singapore and Silverskin Information security in Finland. The companies provide threat intelligence and penetration testing services. Pasi has worked as CISO, and head of security in several companies during his 23 years tenure in the field of cyber security.
In this podcast, Pasi shares his views on the cyber threat landscape in the crypto world.
He points out that the crypto world is not immune to risks observed in the banking world, such as scams, money laundering, and “old school” malware attacks to steal funds of clients.
He also notes that while attacks on crypto wallets and exchanges are notable, threat actors have been targeting the “DeFi” (decentralised finance) area within the crypto world. By exploiting, for example, design and key management weaknesses, and price discovery mechanisms flaws, threat actors have caused significant losses.
While the crypto world is facing both traditional “old school” and emerging threats such as those specific to blockchains, Pasi reminds cyber defenders that cyber security is a risk management process requiring a multi-disciplinary approach. He cautions against assuming that “defense always succeed everywhere”, and advises the importance of identifying the company's critical assets, and building layers of defenses around these assets
With “people and endpoints being the number primary targets of attacks”, he also advises users to think about how they wish to secure their personal crypto wallets and endpoint devices such as mobile and laptops.
Most importantly, he emphasises that the evolving crypto risk landscape means that “what is considered secure today may not be true tomorrow”.
Recorded 27th June 2022 Singapore Time 11am
Jane Lo, Singapore Correspondent speaks with Christian Patouraux, CEO, and Founder of Singapore-based Kacific Broadband Satellites
Christian Patouraux has over two decades’ experience in the satellite industry.
He began his satellite career with SES, initially as a satellite engineer, procuring, launching, testing and operating 12 spacecraft, then as an independent business development consultant, playing key roles in launching broadband businesses, implementing large teleports, deploying airline and maritime broadband, and developing satellite multi-play and IPTV businesses.
He went on to develop satellite offerings for new markets in Asia Pacific as head of special projects for MEASAT. Christian was also Executive Vice President and Chief Development Officer at O3b Networks, where his work was fundamental to launching the company’s maritime business.
In 2013, he founded Kacific Broadband Satellites to bring high speed, low-cost connectivity to remote regions of the Asia Pacific, fostering greater internet usage, fueling economic growth and improvements in service delivery across covered regions.
Kacific’s first satellite, Kacific1, was launched into geostationary orbit on the 16th of December 2019. Once operational, Kacific will offer direct internet access, via wholesale channels, to government agencies, institutions, businesses, community groups and households within the satellite's total footprint area.
Christian holds a Master of Engineering from the Polytechnic school at the University of Brussels, a Master of Aeronautics / Turbomachinery from the Von Karman Institute, Belgium and an MBA from Insead.
In this podcast, Christian shares the latest developments in broadband via satellites, from technology and regulations to trends, with implications for costs and business models.
Referencing the Ukraine crisis and Elon Musk’s Starlink, he gives an overview of the key features of a low-earth orbit system (or “LEO”, launched by for example Starlink) and the geosynchronous satellite (or “GEO”), and how Kacific’s GEO satellite delivers affordable high-speed broadband access to the rural and remote parts of the world.
Christian also references the Covid-19 pandemic, which highlights to governments the critical need for rural connectivity, and how satellite broadband is able to respond to the challenge and bring communication access to less populous regions.
In addition to emergency access, Christian also summarises the trends in services provided by satellite broadband - including disaster recovery (observed in the Ukraine crisis), backup and redundancy, and the role of satellite broadband in the coming 5G era.
In comparing satellites to fiber-optic operators, he clarified that both face similar regulatory requirements. However, satellite broadband addresses certain backhaul challenges faced by fiber-optic operators in a cost efficient way, and hence offers a competitive advantage, in particular for markets in the remote and rural regions.
Recorded 23rd June 2022, 3pm (Singapore Time).
In this gripping essay, Australia’s leading strategic thinker, Hugh White explores Australia’s fateful choice to back America to the hilt and oppose China. What led both sides of politics to align with America so absolutely? Is this a case of sleepwalking to war? What tests might a new government face? White assesses America’s credibility and commitment, by examining AUKUS, the Quad, Trump and Biden. He discusses what the Ukraine conflict tells us about the future. And he argues that the US can neither contain China, nor win a war over Taiwan. So where does this leave our future security and prosperity in Asia? Is there a better way to navigate the disruption caused by China’s rise?
“Canberra’s rhetoric helps raise the risk of the worst outcome for Australia: a war between China and America, in which we are likely to be involved. Over the past decade, and without any serious discussion, Australian governments have come to believe that America should go to war with China if necessary to preserve US primacy in Asia, and that Australia should, as a matter of course, go to war with it.” —Hugh White, Sleepwalk to War
Quarterly Essay 86, Sleepwalk to War: Australia's Unthinking Alliance with America was released 27 June 2022. To obtain a copy visit https://www.quarterlyessay.com.au/essay/2022/06/sleepwalk-to-war
HUGH WHITE is the author of The China Choice and How To Defend Australia, and two acclaimed Quarterly Essays, Power Shift and Without America. He is emeritus professor of strategic studies at ANU, former Deputy Defence Secretary for Strategy, and was principal author of Australia’s Defence White Paper 2000.
Further Listening – Our previous interview with Hugh White - Episode 314 - Reality Check - Taiwan cannot be defended https://blubrry.com/mysecurity/84123792/episode-314-reality-check-taiwan-cannot-be-defended/
#hughwhite #sleepwalktowar #quarterlyessay #nationalsecurity #indopacific #uschinarelations #mysecuritytv
Jane Lo, Singapore Correspondent speaks with Dr. P.J. Blount, Lecturer in Law in the School of Law and Politics at Cardiff University.
Dr. P.J. Blount (Ph.D., M.S., Global Affairs, Rutgers University; LL.M., King's College London; J.D., University of Mississippi; B.A./A.B.J., University of Georgia) is a Lecturer in Law in the School of Law and Politics at Cardiff University. He has served as an adjunct professor for the LL.M. in the Air and Space Law at the University of Mississippi School of Law. Previously, he was a Postdoctoral Researcher at the University of Luxembourg, an adjunct professor at Montclair State University, and a Visiting Scholar at the Beijing Institute of Technology School of Law. He also completed an industrial fellowship sponsored by the Luxembourg National Research Fund wherein he split his time between SES and the University of Luxembourg research cybersecurity issues relevant to the space industry.
Blount’s primary research areas are international space law with a focus on space security and cyberspace law and governance. He has published and presented widely on the topic of space law and has given expert testimony on Space Traffic Management before the U.S. House of Representatives’ Subcommittee on Space. His book, Reprogramming the World: Cyberspace and the Geography of Global Order, was published open access with e-International Relations Press in 2019.
He is an editor of the Proceedings of the International Institute of Space Law and was formerly the Editor-in-Chief of the Journal of Space Law. He currently serves as the Executive Secretary of the International Institute of Space Law and is a licensed attorney with the State Bar of Georgia (USA).
In this podcast, Dr Blount introduces the historical and political context of the Outer Space Treaty which was negotiated in 1967. Despite the technological advances since then, Dr Blount argues that the treaty, in his view, is technologically neutral, where the intent is for it to “apply to everything” and “embrace all sorts of technologies”.
Nevertheless, technological developments force us to rethink our understanding of security. While cybersecurity adds a layer of complexity, he notes that “cybersecurity laws and regulations are not usually the answer to our problems in cybersecurity”.
However, he stresses that, cybersecurity being a risk management process means there are legal implications. For example, for a university Cube Sat, he explains how cybersecurity may play a part in the licensing and authorising process – that is, the extent of cybersecurity and risk management plans could depend on its payload and orbital dynamics.
On whether space sector should be designated as a critical infrastructure, Dr Blount advocates for more definitions, noting the potential for burdening such satellites as the educational ones with unnecessary regulations.
Where laws provide few details in how to secure assets for space sector operators, Dr Blount suggests that standards such as those developed by NIST for Commercial Satellite Operations serve as actionable guidance.
Recorded 27th June 2022, 10am London / 5pm Singapore
Exclusive Networks has joined forces with security leaders in calling on the industry to take global action in a bid to end the recruitment crisis in cybersecurity, which is currently faced with an estimated shortfall of 2.7 million professionals.
The Paris-headquartered global cybersecurity specialist is one of the founding partners supporting an initiative launched today by investment and advisory firm NightDragon and Next Gen Cyber Talent, a non-profit cyber education provider, to raise $1 million to fund cybersecurity courses for students in the US from diverse and disadvantaged backgrounds.
Exclusive will be lending its experience and expertise to the campaign having recently established a partnership with California Polytechnic State University, opening an office on campus and currently sponsoring 12 students, 9 of which are already progressing through their security certification training assignments, delivered by Exclusive and its partners. All are expected to go on to full-time roles in the industry after completing their education. On the international front, Exclusive has partnered with Guardia in Europe to launch the first private cybersecurity academy in France where it will help in the development of course content as well as providing mentoring and internship opportunities for students. Exclusive has also recently become and advisory member of the Cyber Security Coalition in Belgium, a partnership between academia, public authorities and the private sector to share specialist expertise, knowledge and information in the fight against cybercrime.
We speak with Jesper Trolle, CEO and Denis Ferrand-Ajchenbaum, Executive Board Member & SVP of Exclusive Networks to discuss the cybersecurity talent challenge and the company's involvement. Jesper is a vastly accomplished entrepreneurial channel business leader who joined Exclusive Networks as CEO in September 2020.
Since starting out in his native Denmark building successful reseller and distribution businesses, Jesper has amassed almost three decades of executive experience and worked around the world at the head of multi-billion-dollar VAD organisations. He was President of the Americas for ECS Arrow prior to joining Exclusive and holds an MBA from the Henley Business School. Denis joined Exclusive with over 30 years of experience in enterprise IT including stints at value-added distributors, resellers, and vendors.
As an Executive Board Member and SVP Global Business Development & Ecosystems, he is responsible for maximising the value and global penetration of existing vendor relationships while scouting and acquiring the next generation of Exclusive Networks’ trusted digital infrastructure portfolio. Denis is also tasked with driving the strategy for our transactional partners – global system integrators (GSIs) and worldwide reseller network – and non-transactional partners – VCs, educational institutions and international and national bodies. In addition, Denis spearheads the strategy and growth of our innovative subscription platform, X-OD.
#cybersecurity #exclusivenetworks #skills #cyberawareness
Interview with Sam Liew, President, Singapore Computer Society; Managing Partner, Government Strategic Business Group, NCS Group.
Sam is Managing Partner, Government Strategic Business Group at NCS. He leads NCS' government portfolio, which includes Public Service, Defence and Homeland Security. In addition, Sam is also driving expansion efforts to propel NCS as the go-to digital catalyst for governments and smart cities across Asia Pacific.
Prior to NCS, Sam was the Managing Director of GIC. He was Director, Technology Group and also heads GIC's Business Partner and Solutions Division. Sam was responsible for delivering GIC’s Technology, Data Analytics, and Data Science projects and initiatives.
Before GIC, Sam was Managing Director at Accenture ASEAN Technology. He also led Accenture's Asia Pacific Communications Centre of Excellence, delivering business solutions across Asia. He was also a member of Accenture's Global Technology Leadership Council and ASEAN Geographical Leadership Council.
Sam currently serves as Board Director on the Gardens by the Bay Board. Sam also sits on the Board of Singapore Management University's (SMU) School of Computing and Information Systems and Singapore Polytechnic's School of Computing. In additional, he serves as Council Member on Enterprise Singapore's IT Standards Committee. He has been conferred a Fellow by SCS.
In this podcast, Sam gives an overview of the Singapore Computer Society, and the Tech Leader Awards 2022 (presented on 6th May 2022), the nation’s tech awards which celebrates the stalwarts of excellence and innovation within Singapore’s pulsating tech industry. He also shares some highlights of the Singapore 100 Women in Tech List, another major recognition program by the SCS.
With Singapore’s emergence from the pandemic, Sam gives his take on what it means for the digital transformation trends, and a glimpse into what we may expect for Tech Leader Awards 2023.
Recorded 12th May 2022 Singapore 7am.
Highlights from BlackHat Asia 2022 keynote
Interview with George Do, Chief Information Security Officer, Gojek and GoTo Financial.
George has been working in the cybersecurity field for over 25+ years concentrating on the building and operating cybersecurity programs. He specializes in the transformation of cybersecurity, winning customer trust, and ensuring a strong cybersecurity posture for organization.
George has extensive experience in maturing global cybersecurity programs and teams, including securing applications (products and services), securing core IT infrastructure and cloud workloads, and maintaining a robust incident response capability. George leads global teams in cybersecurity, data privacy, governance, risk, compliance (GRC), and implementation of security frameworks. Working closely stakeholders across functions, the global programs he developed has ensured security is baked into products and services at birth.
Before joining Gojek and GoTo Financial, George served as the global Chief Information Security Officer (CISO) at Equinix where he built the global cybersecurity program from inception. Previous to that he worked at Exodus (Savvis / Century Link), and Tivo in senior security leadership roles. He began his career at the National Aeronautics and Space Administration (NASA) where he collaborated with senior federal officials to secure government information assets.
George serves on customer advisory boards for several cybersecurity firms and is an advisor for venture capital. He is a frequent speaker and panelist at cybersecurity industry events.
In this podcast, George shares highlights of his keynote at BlackHat Asia 2022, “Quantify Security Effectively – Moving the Security Needle From the Security Trenches to the Boardroom.”
Drawing on more than two decades of experience in the cybersecurity industry, he speaks on the value of risk quantification to gain board and senior management level buy-in to invest in cybersecurity areas that matter.
Explaining that organisation stakeholders may hold varying perceptions of what these areas, he introduces the concept of a Risk Register to prioritise the different cyber threats the organisation may face.
He also advises on applying a RACI (responsible, accountable, consultative, informed) model to address these cyber threats. Using ransomware as an illustration, he explains the importance to appoint a risk owner accountable for addressing the risk. Additionally, he stresses the importance for the board and senior management to empower the risk owner with the necessary resources.
George also notes that while there are successes at Gojek and GoTo Financial to ensure customer and partner trust and safety, online and cyber threats landscape is an on-going arms race where new threats are constantly emerging.
He wraps up the podcast by reminding the audience to avoid traps such as designing “solutions in search of problems” and adding to the technical debt by “compounding the security industrial complex”.
Recorded 13th May 2022 (BlackHat Asia 2022) Singapore 3pm.
Oliver Tavakoli is Chief Technology Officer at Vectra. Oliver is a technologist who has alternated between working for large and small companies throughout his 25-year career.
Oliver will be visiting Australia at the end of May and discussing how Ransomware will be coming to a cloud near you. Oliver points to this concept as a thought experiment on what to expect next.
Ransomware and software supply chain attacks have dominated the cybersecurity news feeds and have certainly also captured the attention of mainstream media. While supply chain attacks have already shown a clear appreciation for target organisations’ cloud footprints and have leveraged that understanding to pull off some of the more impressive attacks, almost all ransomware attacks have continued to focus primarily on traditional on-premise IT estates. This is because tools to attack these environments (Metasploit, Cobalt Strike, Bloodhound, etc.) have been available for more than a decade and that many hackers have great familiarity with these tools and that there continue to be many organisations whose environments are insufficiently hardened to withstand an attack by a moderately skilled adversary.
Two trends will drive ransomware to the cloud:
the inexorable movement of most data of value to the cloud (in this context, “cloud” is intended to cover both SaaS-delivered applications like Office 365 and public clouds like AWS and Azure) and
the gradual availability of tools (for example Rhino Security Labs Pacu) to attack clouds and hackers’ increased familiarity with them. This presentation will discuss what this combination of Ransomware and cloud is likely to look like.
Prior to joining Vectra, Oliver spent more than seven years at Juniper as chief technical officer for the security business. Oliver joined Juniper as a result of its acquisition of Funk Software, where he was CTO and better known as developer #1 for Steel-Belted Radius. Prior to joining Funk Software, Oliver co-founded Trilogy Inc. and prior to that, he did stints at Novell, Fluent Machines and IBM.
He is a technologist with experience managing larger (100+ member) teams, but with a bias towards leading small teams of smart technical individuals who want to change organisations through articulations of compelling visions, implementation of elegant architectures and building of highly collaborative technical communities. His specialties include networking architectures, systems software design, computer security principles, organisational design.
Oliver received an MS in mathematics and a BA in mathematics and computer science from the University of Tennessee.
Recorded via Singapore, Friday 20 May, 2022.
Interview with Charles Li, Chief Technology Officer, and the Chief Analyst at Team T5
Charles is the Chief Technology Officer, and the Chief Analyst at Team T5. He leads Team T5 analyst team in threat intelligence research. He has been studying cyber attacks and campaign tracking for more than 10 years. His research interests include vulnerability research, reverse engineering and APT attacks. He often publishes research and gives training courses at security conferences.
In this podcast, he shares some highlights of his team’s presentation at Black Hat Asia 2022. Focusing on the notorious Chinese threat actor groups (APT 10, APT 27, APT 41) he discussed key characteristics, such as how their motivations extend beyond espionage to monetisation, tools overlap, targets, and growing OpSec sophistication.
He also touches on the Chinese Cyber Threat landscape from the Taiwanese perspective, such as the information warfare campaigns. With shifting geopolitical landscapes increasing the frequency of cyberattacks on Taiwanese targets, he notes the Taiwanese responses in increasing cybersecurity regulations and investments.
He also shares how the Chinese government’s five-year plans and international relations shape its cyber operations – such as technical skills and tools exchange with other nation state actors, and exploitation of zero-days.
He advises cyber defenders to invest in tailored threat intelligence, to complement tools such as EDR or firewalls.
Recorded 11th May 2022 8am (Singapore Time/ Taiwanese Time).
New Macquarie University research into phone scams has identified the scripts and emotions that drive most calls.
A team of researchers from Macquarie University’s Cyber Security Hub has analysed the content of more than 100 hours of scam phone calls to identify clear call ‘stages’ and pinpoint the social engineering techniques scammers use on their victims.
The team, headed by Professor Dali Kaafar, used machine-learning techniques and natural language processing to uncover scam ‘scripts’ that use various topics and emotions. These findings will help develop better ways to detect and prevent scams which account for the human element which is critical to scammers’ success.
The team found that scripts used by scammers contain multiple paths, which can be simplified into four different stages:
Stage 1 – Introduction The scammer establishes themselves as credible and in a position of authority, then talks about a serious threat to the recipient in a matter-of-fact way – with the threat supposedly from a higher authority (eg the legal system or tax office).
Stage 2 – Assistance The scammer poses as a helpful instructor, using rapport-building conversations, ostensibly helping the recipient to resolve the supposed problem, giving step-by-step guidance to navigate to a website, install software or fill out online forms.
Stage 3 – Threat Emotions can ramp up at this stage, as the scammer reinforces threats for non-compliance, citing police, court orders, arrest warrants, jail and other negative consequences, using legal sounding terms, talking over the victim to defer questions and introducing time pressure to prevent the victim thinking it through.
Stage 4 – Payment / Close Once the scammer gets what they want – like a credit card payment or enticing the victim to download malicious software – the conversation becomes less organised, and scammers finish the call, sometimes promising to call back with confirmation.
We spoke with Professor Dali Kaafar is Executive Director of the Cyber Security Hub in the School of Computing.
Further reading: https://lighthouse.mq.edu.au/article/may-2022/Tricks-used-by-phone-scammers-exposed-in-new-study
Dr. Khatuna Mshvidobadze is a Professorial Lecturer of Cybersecurity at the George Washington University and Adjunct Professor of Cyber Security at Champlain College. She is also a Senior Fellow at the Rondeli Foundation in Tbilisi, Georgia. Earlier, she developed and taught cyber security courses for M.S. and M.P.S. programs at Utica College.
She has been Deputy Director of the Information Center on NATO in Georgia and Adviser to the Office of the Minister of Defense of Georgia. Her articles have appeared in Georgian and in English, including in Defense News, Jane's Defense Weekly, US News & World Report, Jane's Foreign Report, Radio Free Europe/Radio Liberty and more.
She has presented topics on cyber threats at different venues inside and outside of the country: The Office of the Secretary of Defense, US Department of Defense, FBI Headquarters and field offices, Department of Justice, Defense Intelligence Agency, U.S. Healthcare Sector Coordinating Council, Mitre Corporation, Raytheon BBN Technologies, NATO and EU events. She has also been a speaker at TEDx, DefCon and RSA conferences and more.
In this podcast, Dr. Khatuna Mshvidobadze traces the history of Russian information warfare doctrine, and its subset of cyber warfare, operating under an umbrella of “an integrated system of systems”.
Through examples such as the Russia-Georgia conflict of 2008 and Ukraine critical infrastructure disruptions of 2015/2016 – she elaborates how the doctrine evolved, from its foundation days in the 1970s, rooted in the military writings of Nikolai Ogarkov, then Chief of the Soviet General Staff, to today.
Laying out how the cyber troops units are structured under Russia’s military and intelligence organizations, the GRU (Military Intelligence Directorate), Foreign Intelligence Service (SVR), and Federal Security Service (FSB), she points out how they carried out the cyber intrusions, using such tactics as phishing and remote desktop protocols exploitations.
Besides state sponsored cyber-attacks, she also notes the wave of ransomware attacks launched by Russian criminal groups such as REvil and Ryuk during the Covid-19 pandemic.
Dr. Mshvidobadze highlighted how outsourcing is a key element in carrying out the attacks, where criminal groups work with Russian threat actor groups, and sometimes across national borders. One example is the information warfare campaigns prevalent during the current Russia-Ukraine conflict carried out by “GhostWriter”, which has alleged ties to Belarus, a Russian ally.
Referencing the recent supply chain attacks such as the SolarWinds and Kaseya incidents by Russian groups, she advises cyber defenders to step up defensive measures on critical infrastructure, re-assess supply chains, and build threat intelligence into cybersecurity frameworks.
Recorded with Jane Lo, Singapore Correspondent, Wednesday 27th April 2022 1pm (Italy)/ 7pm (Singapore)
According to ISACA’s new survey report, State of Cybersecurity 2022: Global Update on Workforce Efforts, Resources and Cyberoperations, organisations are struggling more than ever with hiring and retaining qualified cybersecurity professionals and managing skills gaps. The eight annual survey features insights from more than 2,000 cybersecurity professionals around the globe, and examines cybersecurity staffing and skills, resources, cyberthreats and cybersecurity maturity. We speak with Jonathan Brandt and Jenai Marinkovic on behalf of ISACA for a report deep-dive discussion.
A copy of the report is available here https://mysecuritymarketplace.com/rep...
Jonathan Brandt, CISM, CDPSE, CCISO, CISSP, CySA+, CPI, PMP
A senior information security practice manager in ISACA’s Knowledge and Research department. In this role, he contributes thought leadership by generating ideas and deliverables relevant to ISACA’s constituents. He serves ISACA® departments as a subject matter expert on information security projects and leads author management teams whenever external resources are necessary. Brandt is a highly accomplished US Navy veteran with more than 25 years of experience spanning multidisciplinary security, cyberoperations and technical workforce development. Prior to joining ISACA, Brandt was a project manager for classified critical infrastructure projects across the globe.
Jenai Marinkovic, vCTO/CISO, Tiro Security; Technology & Information Security Consultant, Beyond; member, ISACA Emerging Trends Working Group
Jenai Marinkovic is a multidisciplinary technologist and strategist with 20 years of experience in architecting, building and securing systems at scale. She has designed and operated in real-time over the top streaming ecosystems that power live sports, gaming, and entertainment. She’s also worked in biomedical manufacturing and laboratory diagnostics, healthcare tech and robotics in agriculture. Jenai’s worked with artificial intelligence, its impact on diversity and inclusion as well as improving human empathy towards machines. She has expertise in designing the next generation security experiences necessary to support digital transformation She has built and run design, architecture, innovation, engineering, security and operations teams. Her security expertise spans security architecture, engineering, defense, and forensics and invented a cyber defense framework for large scale breaches based on American football.
Jenai has worked for large enterprise brands including DIRECTV, Electronic Arts, Beckman Coulter and international investigations firms such as Kroll. About ISACA For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organisations, and enables enterprises to train and build quality teams.
ISACA is a global professional association and learning organisation that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.
Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews
Noname Security’s surge in adoption can be attributed to its proactive approach to API security throughout the full software development lifecycle. Unlike most solutions in the market today that rely solely on traffic analysis to pinpoint active attacks, Noname Security analyzes configuration, traffic and code to identify the broadest set of API vulnerabilities — including misconfigurations and design flaws.
We speak with NoName's CISO, Karl Mattson, a cybersecurity leader and innovator with over 25 years’ experience leading innovative and diverse teams of technology and security professionals in financial services, retail and federal government.
Previously, Karl served as the Chief Information Security Officer (CISO) for PennyMac Financial Services and City National Bank. He has a track record of providing CEOs, CTO and investors in cybersecurity on strategies for product, market and customer success.
Recorded 13 April 2022 #APIsecurity #noname #cybersecurity #AppSec
We attended the opening of the Dragos office in Melbourne, Australia and met with CEO and Founder, Robert Lee.
Robert Lee is a recognized pioneer in the industrial security incident response and threat intelligence community. He gained his start in security as a U.S. Air Force Cyber Warfare Operations Officer tasked to the National Security Agency where he built a first-of-its-kind mission identifying and analyzing national threats to industrial infrastructure. He went on to build the industrial community’s first dedicated monitoring and incident response class at the SANS Institute (ICS515) and the industry recognized cyber threat intelligence course (FOR578).
Forbes named Robert to its 30 under 30 (2016) list as one of the “brightest entrepreneurs, breakout talents, and change agents” in Enterprise Technology. He is a business leader but also technical practitioner. Robert helped lead the investigation into the 2015 cyber attack on Ukraine’s power grid, he and his team at Dragos helped identify and analyze the CRASHOVERRIDE malware that attacked Ukraine’s grid in 2016 and the TRISIS malware deployed against an industrial safety system in the Middle East in 2017.
Robert is routinely sought after for his advice and input into industrial threat detection and response. He has presented at major security conferences such as SANS, BlackHat, DefCon, and RSA and has testified to the Senate’s Energy and National Resources Committee. As a non-resident national security fellow at New America, Robert works to inform policy related to critical infrastructure cyber security and is regularly asked by various governments to brief to national level leaders.
Recorded April 7, 2022
Video version available at https://youtu.be/i2H3YndP8gs
For more information visit www.dragos.com
Organisations in A/NZ, and around the world, are grappling with the complexity of delivering highly distributed modern digital services, while managing the increased sophistication and volume of cyberattacks. F5’s new Distributed Cloud platform provides a set of easily deployed and managed application security and delivery services that allow organisations to apply consistent protection and policy across every application, regardless of architecture and location.
Some research estimates 39 per cent of Australian enterprises have adopted multi-cloud technologies, while across the APAC region its estimated a whopping 93 per cent of companies are embracing a multi-cloud strategy – so the trajectory of multi-cloud adoption is, quite clearly, on the up.
We speak with Jason Baden, Regional Vice President, Australia and New Zealand of F5. Based in Sydney, Jason has held this position for over four years, where he is responsible for driving F5’s local market and business growth, and positioning F5 as a strategic partner for both customers and channel partners.
For more information on the F5 Distributed Cloud Platform visit https://www.f5.com/cloud/products/platform-overview
Dr. Sarah Pearce is Director of the SKA-Low Telescope, soon to be built in Western Australia as part of the $2bn international SKA Observatory. Sarah worked at Australia’s national science agency, CSIRO, for 10 years in the fields of space and astronomy, and spent six months in early 2021 as CSIRO’s Acting Chief Scientist.
Her previous roles included senior science advisor in the UK Parliament and project manager of GridPP, the UK’s program delivering computing for particle physics. In 2020, Dr. Pearce was named Telstra NSW Business Woman of the Year and Executive of the Year at the Australian Space Awards. She is a strong advocate for diversity in science and technology.
Sarah holds a PhD in X-ray astronomy from the University of Leicester and an undergraduate degree in Physics from the University of Oxford (Worcester College).
In this podcast, Dr Pearce shares the latest development of the SKA (Square Kilometre Array) Observatory - an international ‘mega science’ radio-astronomy project. The SKAO Is an intergovernmental organisation – the second-ever in astronomy – that was officially launched in July 2021.
She highlights that SKA will be the world’s largest radio telescope facility of its kind, underpinned by the latest technologies that can help address the exciting cutting-edge challenges in astronomy, including our understanding of the cosmic dawn – the time when the first stars and galaxies in the Universe were formed.
She elaborates on the international partnerships and collaborative efforts in the project. It involves 16 countries as well as engineering consortiums across the world, who are coming together to build the two SKA telescopes, being built in remote regions of South Africa and Australia.
She explains how the existing precursor radio telescopes in Australia – the Australian SKA Pathfinder (ASKAP) with 36 antennas, and the Murchison Widefield Array (MWA) in Western Australia with more than 4,000 antennas – have contributed to planning for the SKA-Low telescope, the “low” frequency antenna array operating in the 50-350 Mhz band.
Comprising up to 130,000 antennas spreading across 65km of desert, Dr Pearce explains the telescope will be more sensitive, and able to capture images at higher resolution and faster than ever before.
Dr Pearce discusses the significance of the selection of the sites in Australia and South Africa – that the Southern hemisphere offers the best views of the Milky Way Galaxy and the remote locations of the telescopes locations ensure minimal radio interference (or “radio quiet”) at these sites. In fact, due to the amount of radio signals generated by human activities, sites visitations are very restricted.
With the data captured by the hundreds of thousands of SKA antennas expected to reach 8 terabytes per second, equivalent to more than 100,000 the average speed of home broadband, Dr Pearce points out how the “big data” aspect is also a challenge, in addition to the challenges involve in building the telescopes.
Dr Pearce rounds off the podcast by paying respects to the Wajarri Yamaji people, the traditional owners of the land on which the SKA-Low telescope will be built.
Recorded 16th March 2022 1.30pm Australia Western Time Zone/ Singapore Time
Recorded 16th March 2022 1.30pm Australia Western Time Zone/ Singapore Time
Jane Lo, Singapore Correspondent speaks with Dr. Jiasun Li, Assistant Professor of Finance, George Mason University.
Jiasun received his Ph.D. in finance from UCLA Anderson School of Management and B.S. in mathematics from Fudan University (Shanghai, China) prior to joining George Mason.
His research interest covers FinTech (including blockchain and crowdfunding), as well as the theory of the firm, governance, and market microstructure.
Dr. Li is a winner of the Yihong Xia Best paper award and the Chicago Quantitative Alliance academic paper competition, along with many other paper prizes. He has also been voted by students as "Faculty of the Year" (one recipient per year from the entire faculty).
In this podcast, Dr. Li shares with the audience, how blockchains such as bitcoin interact with the field of game theory.
Dr. Li describes the challenges to achieving the basic premise of bitcoin and blockchain as distributed systems – that is, the ability to arrive at a general agreement (consensus) without a central authority when some participants may be rogue.
By referring to the Byzantine General’s Problem – a metaphor of this challenge – he highlights how communication between participants distributed across sites is a key feature.
He unpacks how this challenge is resolved in the bitcoin blockchain within the mining process. He also points out that the incentives to motivate participation in the process naturally involve game theory, which models situations where users strategize to optimize their own payoffs.
He also shares his research on mining pools, where like in lottery pools, miners pool their resources to optimize their risk-return tradeoffs. He explains how the strategic interactions between mining pools prevent over-concentration.
On how permissioned and permissionless blockchains compare regarding the applicability of game theory models, he relates to the concept of “repeated games”, and illustrates how repeated interactions may yield a different outcome to a single-shot game.
Drawing on the distinction between “honest” (blindly following protocols) and “rational” (optimizing one's self-interest), he shares on-going work (https://business.gmu.edu/news/2626-mapping-blockchain-s-frontiers/) on aligning incentives to obtain outcomes as prescribed by desired protocols. Another emerging piece of work studies the incentives involved in “slashing” dishonest participants' crypto assets.
Referring to other famous disruptive cyber incidents in the blockchain world – such as the DAO or the 2010 bitcoin overflow – he suggests that all events could be modeled by game theory models, with trade-offs between releasing codes quickly vs spending time and resources in robust audits.
However, he cautions while game theory is a useful modeling tool, the reality is complicated and it is often difficult to capture the entire spectrum of possible actions.
Recorded 11th May 2022 6pm U.S Eastern Time / 12th May 2022 SGT
Jane Lo, Singapore Correspondent speaks with Al Geist, Corporate Research Fellow at Oak Ridge National Laboratory (“ ORNL” ). He is the chief technical officer of the Exascale Computing Project, as well as the CTO of the Leadership Computing Facility and chief scientist for the Computer Science and Mathematics Division at ORNL. He is helping lead the acquisition of the Frontier Exascale computer at ORNL. His recent research is on Exascale computing and resilience needs of the hardware and software.
At ORNL, Geist has published two books and over 200 papers in areas ranging from heterogeneous distributed computing, numerical linear algebra, parallel computing, collaboration technologies, solar energy, materials science, biology, and solid state physics.
Geist is one of the original developers of PVM (Parallel Virtual Machine), which became a worldwide de facto standard for heterogeneous distributed computing. He was also actively involved in the design of the Message Passing Interface (MPI-1 and MPI-2) standard. He was involved in the development of FT-MPI, a research prototype to explore how to make MPI applications fault tolerant.
In this podcast, Al goes behind the scenes to give the audience a glimpse into Frontier, the first Exascale supercomputer in the USA.
By referencing the highlights he presented at the Supercomputing Asia (28th Feb 2022 – 3rd March 2022, Singapore), he shares with the audience the challenges the team overcame to build Frontier. With the capabilities to perform billions of billions of floating point operations per second (“Exsacale”), Frontier joins Fugaku - the Japanese supercomputer currently ranked as the world’s fastest – in the list of high performance computers that have reached the Exascale milestone.
Besides speed, Al also explains how reliability – ability to mitigate computation failures and errors - is crucial to supercomputers in delivering results that decision makers can rely on with confidence.
Al also discusses the innovations in the cooling infrastructure to address the challenge of rising energy consumption that comes with increasing computation power. He also points to the impressive work in refitting the buildings that house Frontier – including rein-enforcing the 20,000 square feet of floor areas to withstand the weight of 8,000 pounds of supercomputer cabinets.
With applications running on Frontier that are of high sensitivity including national security implications, he also touches on security considerations – such as controls over remote access as well as physical access, and data segregation.
Looking ahead, Al shares how, by programming and coding smarter, supercomputers will continue to deliver the gains in computational speeds for a couple more generations to come, despite the slowdown in semiconductor advancements.
Recorded 7th March 2022 6pm (US Eastern Time) / 8th March 2022 7am (Singapore).
The fourteenth issue of Australian Foreign Affairs examines the rising tensions over the future of Taiwan, as China’s pursuit of “unification” pits it against the United States and US allies such as Australia. The Taiwan Choice looks at the growing risk of a catastrophic war and the outlook for Australia as it faces a strategic choice that could reshape its future in Asia.
Published on 21 February, Issue 14 examines the rising tensions over the future of Taiwan and Hugh White discusses why war over Taiwan is the gravest danger Australia has faced.
Hugh White AO is Emeritus Professor of Strategic Studies at the Australian National University. His work focuses primarily on Australian strategic and defence policy, Asia-Pacific security issues, and global strategic affairs especially as they influence Australia and the Asia-Pacific.
Hugh has served as an intelligence analyst with the Office of National Assessments, as a journalist with the Sydney Morning Herald, as a senior adviser on the staffs of Defence Minister Kim Beazley and Prime Minister Bob Hawke, and as a senior official in the Department of Defence, where from 1995 to 2000 he was Deputy Secretary for Strategy and Intelligence, and as the first Director of the Australian Strategic Policy Institute (ASPI). In the 1970s he studied philosophy at Melbourne and Oxford Universities. He was the principal author of Australia’s 2000 Defence White Paper.
His major publications include Power Shift: Australia’s future between Washington and Beijing, [2010], The China Choice: Why America should share power, [2012], Without America: Australia’s future in the New Asia [2017], and How to defend Australia [2019]
For a copy visit https://www.australianforeignaffairs.com/essay/2022/02/the-taiwan-choice
Discount Code for your copy of the Australian Foreign Affairs - 14th Ed - AFA3OFF
Western governments have issued warnings for organisations to protect their systems against possible Russian cyber attacks.
The threat potentially impacts all tiers of governments, all organisations and individuals. So what form will the Russian Cyber attacks take, there are a number of options: - Denial of Service attacks - is a cyber-attack in which the attacker seeks to make a machine or network resource unavailable by flooding the site with data; - Web-site Defacement – hacking web pages and replacing with an alternative web page usually with a political message; - Ransomware – infecting organisations with malware that spreads across the system and locks down the system until a ransom (usually in bitcoin is paid); - Hacking – stealing information that is either publicly disclosed or sold via the darknet.
The attacks may be undertaken either by parts of the Russian Government, APT (Advanced Persistent Threat) hacking groups acting on behalf of the Russian government or by patriotic hacking groups / militia (as in the 2007 cyber attacks on Estonia).
The Australian - Lithuanian Cyber Research Network, a joint initiative of RMIT University and Mykolas Romeris University, was launched in early February 2022, by His Excellency Gabrielius Landsbergis, the Lithuanian Minister of Foreign Affairs who stated that this trip to the Asia Pacific region, which included Singapore and Australia was about “strengthening old friendships and building new ones. Political dialogue, enhanced economic cooperation, and regional security are main subjects for conversations during upcoming busy days!”
The network is the first of its kind globally and provides a platform for Australia and Lithuania to cooperate on common cyber security issues that affect both the Asia Pacific and Europe.
We speak with the Director of RMIT’s Centre for Cyber Security Research & Innovation and co-convenor of the Australian-Lithuanian Cyber Research Network, Professor Matthew Warren who said at the launch, “the network provides a platform for the two countries to undertake jointly important cyber security research. Professor Warren went on to say “The first initiative of the network will be the Australian – Lithuanian Hybrid Threat Observatory. Hybrid threats are state and non-state actors that are challenging countries and institutions they see as a threat, opponent or competitor to their interests and goals with a focus on disputing industry and society”.
As Russia commences military operations in Ukraine, we speak with Associate Professor Alexey Muraviev, National Security & Strategic Studies from Curtin University in Perth.
Dr Muraviev discusses why Russia feels “so confident” with its Ukraine deliberations, given its new partnership arrangements with China, and why China “must walk a fine line”: “Perhaps the most powerful draw card in Putin’s back pocket is China. While Russia and China have been growing closer in recent years, a summit between Putin and Chinese President Xi Jinping at the start of the Olympics sent alarm bells ringing in Western countries”.
Alexey research interests focus on problems of maritime security (modern naval power, maritime terrorism), Russia’s strategic and defence policy and military modernisation, Russia as a Pacific power, alliances in the Asia-Pacific, regional balance of power, Australian national security and defence, contemporary terrorism, future wars, and other.
Recorded 4:00pm AEDT, Thursday 24 February 2022. To watch the MySec.TV version visit https://mysecuritymarketplace.com/av-media/chinas-support-for-russia-how-far-does-it-go/
Further reading https://theconversation.com/why-vladimir-putin-is-so-confident-in-his-ukraine-strategy-he-has-a-trump-card-in-china-177534
The Australian Department of Home Affairs is in the process of overhauling Australia's electronic surveillance framework.
We speak with Dr William Stoltz following a public submission authored by Dr. Dominique Dalla-Pozza of the ANU College of Law and Dr. William A. Stoltz of the ANU National Security College and informed by an ANU CoL-NSC Joint Dialogue held in December 2021 during which a number of scholars from across the ANU.
To read the submission visit https://law.anu.edu.au/sites/all/files/public_submission_-_electronic_surveillance_reform_-_anu_college_of_law_and_national_security_college_11.02.22.pdf
This follows our interview with Dr Nick Tate, President of the Australian Computer Society - available here https://youtu.be/t_QDUhWoVYA
We speak with Dr Nick Tate, President of the Australian Computer Society (ACS). Nick is also President of the South-East Asia Regional Computer Confederation (SEARCC) and an Adjunct Professor of IT and Electrical Engineering at the University of Queensland.
The ACS has recommended the Australian Government change the way electronic surveillance is performed by the nation’s law enforcement agencies.
In a written response to the Department of Home Affairs’ Reform of Australia’s electronic surveillance framework Discussion Paper last week, ACS called on the government to stop ‘deputising’ IT professionals and technology companies.
This follows ACS’ objection to the 2018 Assistance and Access Bill requiring Australian IT companies and professionals to secretly assist in cracking electronic protections when called upon to do so by agencies.
To read more visit https://australiansecuritymagazine.com.au/call-out-to-stop-deputising-tech-companies/
To view the MySec.TV version visit https://mysecuritymarketplace.com/av-media/call-out-to-stop-deputising-tech-companies/
Interview with Dr Gay Jane P. Perez, Deputy Director General for Space Science and Technology (DDG-SST), Republic of the Philippines - Office of the President - Philippine Space Agency.
Dr. Perez serves as the Deputy Director General for Space Science and Technology (DDG-SST) at the Philippine Space Agency (PhilSA). She is also a Professor at the Institute of Environmental Science and Meteorology of the University of the Philippines Diliman.
She was a postdoctoral fellow at the NASA Goddard Space Flight Center (2010-2011). She is a graduate of the National Institute of Physics at the University of the Philippines Diliman, from which she received Bachelor of Science in Applied Physics (2003), Master of Science (2005), and Doctor of Philosophy in Physics (2009).
Dr. Perez has led various programs on satellite development in the Philippines as well as other projects that utilized satellite and remotely sensed data for environmental applications and climate studies.
Dr. Perez is a recipient of The Outstanding Women in the Nation's Service (TOWNS) Award (2019) and is the first Filipino woman to receive the ASEAN-US Science Prize for Women (2018).
Her research interests include Earth observation satellite product development, drought monitoring and forecasting, forest change detection, land cover/land use change, other satellite remote sensing applications for the environment, seasonal and climate prediction, climate change and variability, complex systems, and interdisciplinary applications of Physics.
In this podcast, Dr Perez shared the latest developments at the Philippine Space Agency, and some of the highlights she presented at GSTC 2022 (Global Science and Technology Conference 2022).
She touched on the efforts to build the downstream Space Technology infrastructure, including the challenges to ingest the immense volume of data gathered from satellites, and turned them into meaningful insights in applications ranging from hazard management to drought management.
Dr Perez also gave the listeners a glimpse into the evolution of the Philippine upstream activities, including the launch of the first Philippine satellite Diwata 1 in 2016, to today’s development of CubeSat(s) for research.
Wrapping up the podcast, Dr Perez pointed to the importance of capacity building and international partnerships, echoing the words of many in this fast growing sector: “if you want to run fast, do it alone; if you want to run far, we need to do it together.”
Recorded 10th February 2022, Singapore/Philippines Standard Time 11am.
Interview as part of the ASITII International Space Bridge Series 2022 - Register interest at www.asitti.space
New research from ISACA explores the latest trends in enterprise privacy—from privacy workforce and privacy by design to privacy challenges and the future of privacy—in its new Privacy in Practice 2022 survey report, sponsored by OneTrust.
The report, which examines responses from the global ISACA State of Privacy survey conducted in the third quarter of 2021, highlights the persistent understaffing that is impacting enterprise privacy teams. Respondents indicate that both legal/compliance (46 percent of respondents) and technical privacy roles (55 percent of respondents) at enterprises are understaffed, and the issue has only worsened since last year. Forty-one percent also report that the biggest challenge in forming a privacy program is a lack of competent resources.
We speak with Jo Stewart-Rattray, Information Security Advisory Group, ISACA and Safia Kazi, ISACA Privacy Professional Practice Advisor.
Recorded 8 February 2022 #mysecuritytv #privacy #cybersecurity #compliance #isaca
We speak with Adam Denyer-Hampton, International Lead for the Pre-Sales Engineering team at SecurityScorecard. We discuss the key security metrics and the basis for developing a Security Strategy for the Board to Monitor. We also discuss what to measure or what can be measured, as well as real-time versus intermittent monitoring.
Adam has 15 years of experience in successfully delivering large and complex IT security solutions for major global companies, across Europe and APAC, including the defence and government agencies. Prior to joining SecurityScorecard, Adam held key technical roles at companies such as SafeNet, SourceFire (part of Cisco Systems) and IT Security Experts, where he managed solution deployments and technical consultations/trainings to meet customer requirements and successfully onboard them to new solutions.
For further information and insights, attend a special virtual event with MySecurity Media & SecurityScorecard on Thursday 10 February, 1:30pm SGT - Presenting the Cyber Security Strategy to the Board of Directors - Key Metrics | Third Party Risk | Cyber Insurance - REGISTER HERE https://www.eventbrite.com/e/presenting-the-cyber-security-strategy-to-the-board-of-directors-tickets-251046265137
MySec.TV version visit https://mysecuritymarketplace.com/av-media/key-security-metrics-measuring-monitoring-the-cybersecurity-strategy/
Ransomware has captured the attention of many due to its far-reaching impacts on industrial control systems (ICS). Once a problem that only affected IT infrastructure, ransomware that now targets ICS / OT can significantly impact or even shut-down control processing, logistics, distribution, and delivery of critical goods.
We speak with Dr. Tom Winston, Director of Intelligence with Dragos Inc, based in Virginia. Dr. Winston is a Cyber Security subject matter expert focused on threats to critical infrastructure (ICS/SCADA) systems, as well as foreign cyber threat intelligence and threat analysis. Tom has extensive public and private sector experience in IT/OT threat environments to include hunting, detection engineering and reverse engineering. Tom has extensive experience in mobile devices, removable/fixed media digital forensics. Tom is also a seasoned manager of people, technology, projects, and programs. Multilingual, and with extensive experience in international relations, intelligence, and foreign policy analysis. Dr Winston has extensive private and public sector experience in IT/OT threat environments to include hunting, detection engineering and reverse engineering.
Formerly, a highly sought after and award-winning professor Dr Winston was an undergraduate and graduate student advocate and champion; student success is critical - not just in school, but after graduation as well. He built cyber security engineers one student at a time and continues to assist them even well past their graduation by providing career and other professional guidance.
Recorded 18 January 2022 courtesy of Dragos.
To view the video version visit https://mysecuritymarketplace.com/av-media/assessing-risk-in-ics-environments/
Further reading
Blog post – Tom Winston
Assessing Ransomware Risk in IT and OT Environments
https://www.dragos.com/blog/industry-news/assessing-ransomware-risk-in-it-and-ot-environments/
Blog post – Dragos
Assessment of Ransomware Event at US Pipeline Operator
https://www.dragos.com/blog/industry-news/assessment-of-ransomware-event-at-u-s-pipeline-operator/
Blog post – Sergio Caltagirone
Recent Ransomware Attacks against Governments and Critical Infrastructure
https://www.dragos.com/blog/industry-news/recent-ransomware-attacks-against-governments-and-critical-infrastructure/
Webinar recording – Tom Winston
Protect your ICS environments from Ransomware with Risk Assessments
https://www.dragos.com/resource/protect-your-ics-environment-from-ransomware/
Joseph Weiss (www.controlglobal.com/unfettered) is an industry expert on control systems and electronic security of control systems, with more than 40 years of experience in the energy industry. Mr. Weiss spent more than 14 years at the Electric Power Research Institute (EPRI), the first 5 years managing the Nuclear Instrumentation and Diagnostics Program. He was responsible for developing many utility industry security primers and implementation guidelines.
In this podcast, he shares his insights on Industrial Control System risks, from an engineer’s perspective.
By highlighting differences in concepts (such as Purdue versus OSI, Zero trust versus 100 percent trust), he explains how a control engineer’s focus on actual devices (such as sensors) is critical to safely managing control system risks. For example, while data sent from devices could be manipulated by malicious actions such as hacking, there are other threats that are yet to of focus in cybersecurity discussions. These include deliberately compromised hardware at source and hardware “drift”.
He urges the need for a paradigm shift from “cyber physical” to “physical cyber” in managing control system risks, where attention is to be paid to physical risks, supported by cyber risk management. This is what he calls “go back to the future”, to manage control system risks by engineers monitoring process anomalies, of which network is part.
Mr. Weiss serves as a member of numerous organizations related to control system security. He is also an invited speaker at many industry and vendor user group security conferences, has chaired numerous panel sessions on control system security, and is often quoted throughout the industry.
He has published over 80 papers on instrumentation, controls, and diagnostics including chapters on cyber security for Electric Power Substations Engineering and Securing Water and Wastewater Systems. He coauthored Cyber Security Policy Guidebook and authored Protecting Industrial Control Systems from Electronic Threats.
In February 2016, Mr. Weiss gave the keynote to the National Academy of Science, Engineering, and Medicine on control system cyber security.
Mr. Weiss has conducted SCADA, substation, nuclear and fossil plant control system, and water systems vulnerability and risk assessments and conducted short courses on control system security. The risk assessments include utility-scale solar farms and wind turbines. He has amassed a database of almost 12 million actual control system cyber incidents. He was a member of Transportation Safety Board Committee on Cyber Security for Mass Transit.
He was a subject matter expert to the International Atomic Energy Agency on nuclear plant control system cyber security.
Mr. Weiss has received numerous industry awards, including the EPRI Presidents Award (2002) and is an ISA Fellow, Managing Director of ISA Fossil Plant Standards, ISA Nuclear Plant Standards, ISA Industrial Automation and Control System Security (ISA99), a Ponemon Institute Fellow, and an IEEE Senior Member. He has been identified as a Smart Grid Pioneer by Smart Grid Today. He is a Voting Member of the TC65 TAG and a US Expert to TC65 WG10, Security for industrial process measurement and control – network and system security and IEC TC45A Nuclear Plant Cyber Security. Mr. Weiss was featured in Richard Clarke and RP Eddy’s book- Warning – Finding Cassandras to Stop Catastrophes. He has patents on instrumentation, control systems, and OT networks.
He is a registered professional engineer in the State of California, a Certified Information Security Manager (CISM) and Certified in Risk and Information Systems Control (CRISC).
Interview with Jane Lo, Singapore Correspondent. Recorded 9th December 2021 US California 3pm/ 10th December 2021 Singapore 7am.
Haventec, a Sydney-based award-wining cyber security company founded in 2015, has secured US$10M in capital and launched their expansion into the US market after tremendous demand for their passwordless authentication and data storage solutions.
Macquarie Group and Future Now Capital led the raise which will predominantly fund Haventec’s growth plans in the financial services, government and health sectors handling sensitive data.
We speak with CEO of Haventec David Maunsell who outlines the recent hires in the US and the strategy for the next couple of years as the company continues to grow and expand beyond Australian shores.
Recorded 21 December 2022 for MySec.TV
To view the video version visit https://mysecuritymarketplace.com/av-media/aussie-cyber-security-innovation-secures-over-us10m-for-us-expansion-plans/
Jane Lo, Singapore Correspondent speaks with Kyoung-ju Kwak is a head of TALON, CTI Group of S2W. Kyoung-ju currently works on threat intelligence.
He was previously Adjunct Professor at Sungkyunkwan University and audited the National SCADA system and the Ministry of Land with “the Board of Audit and Inspection of Korea” as an Auditor General in 2016. He currently acts as a member of the National Police Agency Cybercrime Advisory Committee.
Kay is the main author of the threat intelligence report “Campaign Rifle: Andariel, the Maiden of Anguish”, published in 2017. In the report, he firstly attributed new threat actor, Andariel. He has spoken at various international conferences such as BlackHat Europe, BlackHat Asia, Kaspersky SAS, HITCON, PACSEC, and more.
In this podcast, Kay provided insights on the cyber activities of North Korea, given his expertise in darkweb intelligence and experience in understanding the North Korea cyber threat landscape, and his firm’s (S2W) support to Interpol’s recent Operation Cyclone.
He shared his views on how North Korea cyber activities under threat actor groups such as Lazarus and Andariel (APT39), compared to other nation state actors in terms of levels of sophistication (for examples, reconnaissance and social engineering) and attacking styles.
Notwithstanding the challenges in attributions, he pointed to the extra care the cyber threat intelligence (CTI ) researchers exercised in publishing their work in reverse engineering and the risks of over disclosure.
Given North Korea high profile cyber attacks and its evolution into an advanced threat actor, he also gave his thoughts on how the nation group gained their cyber skills and expertise over the years.
Despite the relative decline of number of cyber incidents attributed to North Korea last year, and the successful efforts by Europol and Interpol, Kay cautioned cyber defenders against jumping too quickly to the conclusion of a slow-down in the cyber threat landscape of North Korea.
Recorded 10th December 2021, Korea Standard Time (9am)/Singapore (8am).
Jane Lo, Singapore Correspondent speaks with Dr. Michael McGuire, Senior Lecturer in Criminology, Surrey Centre of Cyber Security, University of Surrey (United Kingdom)
Dr Michael McGuire joined the Department as Senior Lecturer in Criminology in September 2012. Dr McGuire read Philosophy & Scientific method at the London School of Economics where he acquired a first class BSc Econ and he completed his PhD, at Kings College London. He has subsequently developed an international profile in the study of technology and the justice system and has published widely in these areas.
His first book Hypercrime: The New Geometry of Harm (Glasshouse, 2008), involved a critique of the notion of cybercrime as a way of modelling computer enabled offending and was awarded the 2008 British Society of Criminology runners up Book Prize. His most recent publication Technology, Crime & Justice: The Question Concerning Technomia (Routledge, 2012) is the first book in the field of Criminology and Criminal Justice to attempt an overview of the implication of technology for the justice system and complements a range of applied studies in this area, including a comprehensive evidence review of cybercrime for the Home Office.
Dr McGuires research interests also encompass questions relating to the impacts of the instincts and irrationality upon crime and justice and his paper “Abnormal Law” was recently included as a chapter in the three-volume series on Criminalisation (OUP) edited by Professor Anthony Duff of Stirling. He is currently completing a new monograph in this area to be titled The Criminology of Pleasure (for Taylor & Francis, 2014).
In this podcast, Dr McGuire shares insights on Nation States conflict in cyber space, with reference to his research (“Web of Profit - April 2021”). Report available here
He points to how cybercrime economies are shaping the character of Nation State conflict in cyber space, where Nation States have become both “beneficiaries of and contributors” in the US$1.5 trillion cybercrime economy, by sharing, selling and buying tools and skills.
Further to the asymmetric nature of operations in cyber space enabling smaller nations to confront larger powers, he highlights recent incidents that also underscore the emergence of multi-vector conflicts, where conventional warfare is beginning to integrate cyber abilities.
He also discusses how trends such as “cognitive hacking” of attitudes on social media and others, contribute to indications that tensions between Nation States have escalated from “cyber competition” to today’s “advanced cyber conflict”.
Amidst these developments, Dr McGuire shares challenges, including the attribution problem, in shaping policies to respond to the rising Nation State actor threats in cyber space. He also cautions the knowledge gap that exists - that our perspectives, formed by reports issued from U.S or UK, do not necessarily represent a complete picture of the threats faced by nations across the world.
Recorded 29th Nov 2021 (SGT 5pm / UK London 9am)
We speak with Ariel Zeitlin, VP, CTO Enterprise Security Group at Akamai Technologies and Chris Gibbs, Managing Director and Regional Vice President, Australia and New Zealand.
Ariel co-founded Guardicore, after spending 11 years as an officer in the Israeli Defense Forces (IDF), where he worked closely with Guardicore’s co-founder Pavel Gurvich. At Akamai, Ariel is focusing on building best in class Zero Trust platform.
Chris joined Akamai in 2021 with more than 20 years of strategic leadership experience within the technology and telecommunications sector, across both Australia and Asia-Pacific & Japan (APJ).
In September 2021, Akamai Technologies, Inc. (NASDAQ: AKAM), announced it will acquire Tel Aviv, Israel-based Guardicore. By adding Guardicore’s micro-segmentation solution into Akamai’s extensive Zero Trust security portfolio, Akamai has broadened its solution suite to provide comprehensive protections to the enterprise, defending against threat actors and the spread of malware and ransomware.
We also discuss the Apache Log4j library vulnerability, (CVE-2021-44228) that was exposed days earlier. The vulnerability, also named Log4Shell or LogJam, has a CVSS severity level of 10 out of 10. The vulnerability allows hackers to execute arbitrary code and potentially take full control of a system.
On 10 December, a Friday morning (US time), an exploit was publicly released for the critical zero-day vulnerability. Reports indicate hackers need the application to write just one string to the log. From there, hackers can remotely upload their own code to the application via the message lookup substitution function.
Millions of servers are reportedly at risk, including those used by high-profile companies, including Apple, Cloudflare, Twitter, Valve, Tencent, iCloud, Steam, and Minecraft.
Further Reading
https://www.akamai.com/resources/ebook/5-step-ransomware-defense-ebook
https://www.akamai.com/resources/white-paper/stop-the-impact-of-ransomware-white-paper
We speak with authors Dan Lohrmann and Shamane Tan following the recent release of Cyber Mayday and the Day After: A Leader's Guide to Preparing, Managing, and Recovering from Inevitable Business Disruptions.
Now available on Amazon - https://www.amazon.com/Cyber-Mayday-Day-After-Disruptions/dp/1119835305
From the Inside Flap
Digital transformation and cyber insecurity converged spectacularly in recent years, leading to some of the highest profile network security failures in modern history. From the SolarWinds hack to the Colonial Pipeline ransomware event, these incidents dramatically highlighted the need for impactful and effective leadership through a crisis.
In Cyber Mayday and the Day After, a team of veteran cybersecurity leaders delivers an incisive collection of stories, strategies, tactics, lessons, and outlooks from some of the top C-executive leaders around the world. Packed with insights from former FBI agents, NASA professionals, government Chief Information Security Officers, and high-profile executives, this book offers the practical examples and workable solutions that leaders need to succeed in the 21st century.
Cyber Mayday and the Day After is a guide to the art of communication with senior stakeholders and how to effect cultural change within organizations to adapt to a new reality that includes ransomware, online deception, and nation-state hackers. You’ll learn what you should know before a critical event occurs and what other executives wish they’d known before cyber crisis struck their organizations. You’ll also discover how executive-level responses can make or break customer trust in your company. Finally, you’ll explore how to utilize communication, coordination, and teamwork, as well as partnerships with vendors, law enforcement, and others, to tailor your crisis response for maximum damage mitigation.
Cyber Mayday and the Day After is an eye-opening, need-to-read experience that’s ideal for current or aspiring executives who seek to understand high-level leadership through a different lens. It’s also the ideal resource for managers and other leaders who want to learn invaluable lessons in communication and leadership from veteran industry professionals.
For a copy of Shamane Tan's first book - Cyber Risk Leaders - visit https://mysecuritymarketplace.com/books/cyber-risk-leaders-global-c-suite-insights-leadership-and-influence-in-the-cyber-age-by-shamane-tan/
We speak with Noushin Shabab, Senior Security Researcher with Kaspersky.
Kaspersky’s Digital Stalking in Relationships Report asked over 21,000 people their attitudes towards stalkerware, which is technology that enables a perpetrator to digitally monitor another person’s private life via a mobile device without their consent. Over a quarter (27%) of the 1,004 Australian respondents surveyed said they see no problem with stalkerware, or think it is acceptable under some circumstances. 30% of global respondents shared this sentiment, with the highest level of agreement amongst respondents in Asia-Pacific (24%) compared to Europe (10%) and the Americas (8%).
The respondents’ reasons to justify secret surveillance included: if they believe their partner is being unfaithful; if it is related to their safety; or if they believe them to be involved in criminal activity. Younger Australians surveyed are more inclined to think this activity is appropriate – 14% of 16-34 year olds compared to 4% aged over 55.
Noushin is a cybersecurity researcher based in Australia, specialising in reverse engineering and targeted attack investigations. She joined Kaspersky in 2016 as a senior security researcher in the Global Research & Analysis Team (GReAT). Her research focuses on the investigation of advanced cyber-criminal activities and targeted attacks with a particular focus on local threats in the Asia Pacific region. Prior to joining Kaspersky, Noushin worked as a senior malware analyst and security software developer focusing on rootkit analysis and detection techniques as well as APT attack investigations.
TinyCheck is a simple tool used to detect stalkerware and spyware installed on smartphones and tablets, and was developed to help non-profit organisations support survivors of domestic violence.
TinyCheck runs separate to a smartphone, on a device like a Raspberry Pi microcomputer. Using a regular Wi-Fi connection, TinyCheck scans a mobile device’s outgoing internet traffic and identifies if it is sending data to a known malicious server. It addresses a few specific problems that non-profit organisations face when they want to help a victim/survivor and check their device for stalkerware: 1) TinyCheck is unique in its ability to detect stalkerware and inform the affected user without making the perpetrator aware that such a check is being carried out. Nothing has to be installed on the device itself to perform the check. While other security solutions can also check and alert about stalkerware, they will need to be installed on the device. Therefore, there is a risk that the perpetrator will also be alerted. 2) TinyCheck enables checking any device, regardless of whether it is an iOS or Android device or any other OS. 3) It‘s an open source tool that is easily available to NPOs and affordable. The components can be bought for between 400-500 AUS dollars. It’s available now at GitHub - https://github.com/KasperskyLab/tinycheck
Our 2018 Interview with Noushin Shabab - https://mysecuritymarketplace.com/av-media/episode-118-meet-cyber-twins-noushinshbb-negarshbb-womenincyber-malware-analysis-appsec/
We speak with Jason Manar, Chief Information Security Officer, Kaseya.
In October, 2021, Kaseya announced that it hired Jason Manar as Chief Information Security Officer (CISO). Manar, who was most recently named Assistant Special Agent in Charge for the Federal Bureau of Investigation (FBI) overseeing all cyber, counterintelligence, intelligence and the language service programs for the San Diego office, will play a pivotal role in further solidifying Kaseya’s security stance.
Manar will oversee information security and compliance for Kaseya, leading the company’s cybersecurity division to identify the industry’s latest threats and vulnerabilities and intercept them. Additionally, as CISO, he will ensure compliance with security requirements associated with government regulations, which vary by global region.
Manar first became familiar with Kaseya as the Miami Cybercrime Supervisory Special Agent where he managed all FBI criminal cyber operations within the Southern District of Florida, the Caribbean and Central and South America. Prior to that, he served at FBI headquarters in the Major Crimes Unit combatting cybercriminal threats against the U.S. In that role, he built relationships with key industry partners and was instrumental in the creation of the Microsoft Cybercrime Center. Manar also served as the Safe Streets Gang & Violent Crime Task Force Coordinator for the FBI’s Springfield Division investigating drug trafficking organizations, violent crime, cybercrime and transnational organized crime. Manar graduated from Murray State University with a Bachelor of Science. Prior to joining the FBI, he served six years with the Kentucky State Police as a trooper and detective.
Recorded 23 November 2021 for MySec.TV - video session available here https://mysecuritymarketplace.com/av-media/mitigating-global-disruption-and-predictions-2022-interview-with-ciso-of-kaseya/
Jane Lo, Singapore Correspondent speaks with Rick Aldrich, Lead Cybersecurity Policy and Compliance Analyst, Booze Allen Hamilton.
Rick is a cybersecurity policy and compliance analyst for Booz Allen in its support to the U.S. Department of Defense CIO. Previously he spent over 15 years as an Air Force JAG (Judge Advocate General’s Corp) specializing in cybercrime and information operations portfolios. He was recognized as the Outstanding Professor of Law at the Air Force Academy.
Rick has multiple publications, including a chapter on information warfare in a widely used textbook. He has presented at national and international conferences and is co-author of DoD's award-winning CyberLaw digital training product.
Rick has been awarded several grants by the Institute for National Security Studies to research the legal and policy implications of cybercrime and cyberwar. He holds a B.S. in Computer Science from the Air Force Academy, a JD from UCLA, and an LLM in Intellectual Property Law from the University of Houston.
In this podcast, Rick discussed highlights of cyber law cases and regulations in the recent years in United States in 4 areas:
Key takeaways from these developments highlighted could have important implications for cybersecurity professionals across the world.
Recorded: 16th November 2021 6pm (Virginia, U.S) / 17th November 2021 7am (Singapore)
We speak with Michael Daniel, President & CEO, Cyber Threat Alliance, a nonprofit that coordinates information sharing between leading cybersecurity companies, including Cisco, McAfee, Palo Alto Networks, Symantec, Verizon and more.
Prior to joining the CTA in February 2017, Michael served from June 2012 to January 2017 as Special Assistant to President Obama and Cybersecurity Coordinator on the National Security Council Staff. In this role, Michael led the development of national cybersecurity strategy and policy, and ensured that the US government effectively partnered with the private sector, non-governmental organizations, and other nations.
Michael provides the outcomes from the Institute for Security and Technology (IST) Ransomware Task Force (RTF). Conducted in partnership with a broad coalition of experts in industry, government, law enforcement, civil society, and international organizations, the RTF released a comprehensive framework to combat ransomware.
We also hear Michael's outlook for the industry and the CTA in 2022, as well as his thoughts on Australia's Ransomware Plan.
Recorded 18 November 2021 - MySec.TV version available https://mysecuritymarketplace.com/av-media/cyber-threat-alliance-president-ceo-speaks-on-the-ransomware-task-force/
We last spoke to Michael in Sydney in 2017 - here is that interview https://australiancybersecuritymagazine.com.au/episode-9-cyber-threat-alliance-cta-president-michael-daniel-in-sydney-aisacon17/
We speak with Aleksandr Yampolskiy, Chief Executive Officer and co-Founder with SecurityScorecard, based in New York, USA.
Aleksandr Yampolskiy is a globally recognized cybersecurity innovator, leader, and expert. As co-founder and chief executive officer, Yampolskiy has led the company since its beginnings in 2013 to become one of the world’s most trusted cybersecurity brands.
His vision is to create a new language for cybersecurity by enabling people to work collaboratively across the enterprise and with external parties to build a more secure ecosystem.
Prior to founding the company, Yampolskiy was a hands-on CTO at Cinchcast and BlogTalkRadio, the largest online talk radio and podcast hosting platform. Prior to that, he led security and compliance at Gilt Groupe, where he managed all aspects of IT infrastructure security, secure application development, and PCI compliance. Yampolskiy has a B.A. in mathematics and computer science from New York University and a Ph.D. in Cryptography from Yale University.
We will be deep diving into the SecurityScorecard platform on Thursday, December 2, 2:00pm AEDT - register here https://mysecuritymarketplace.com/security-scorecard/
Recorded courtesy of SecurityScorecard - 16 November, 2021
We speak to Eva-Maria Elya, Senior Director World-Wide Channel Sales with Lookout on the market opportunities for MSPs and MSSPs who choose to partner with Lookout.
To get the most of your countless cloud apps without risking your data, you need to know exactly what’s going on. You also need to be able to detect and respond to threats and have the ability to dynamically control access. Lookout Cloud Access Security Broker (CASB) provides full visibility into the interactions between users, endpoints, cloud apps and your data. It also enables you to dynamically dial in Zero Trust access controls.
With continuous monitoring of user and entity behaviour analytics (UEBA), you can detect and respond to insider threats and advanced cyberattacks. Lookout provides advanced data loss prevention that can classify, encrypt and restrict sharing of your data on the fly so that only authorized users have access. They also perform automated assessments of all your cloud apps and infrastructure to ensure they are properly configured.
Visit www.lookout.com for more details or visit https://learnsecurity.mysecuritymarketplace.com/course/endpoint-to-cloud-security to deep dive with Don Tan, Regional Director for APJ
For the MySec.TV interview - visit https://mysecuritymarketplace.com/av-media/zero-trust-approach-us13-billion-market-opportunity/
On a Sunday morning in Sydney, the computers freeze and digital systems go down at a leading hospital. The nurses on the ground don’t know it yet, but the hospital is under cyberattack. How is this going to unfold? That was the question posed at an Australian Cyber Week hypothetical on Monday.
The hypothetical, hosted by AustCyber, is one of a series of events marking Australian Cyber Week and designed to raise cybersecurity awareness. Monday’s hypothetical included experts from the Australian Cyber Security Centre, the Global Forum on Cyber Expertise, health provider BUPA, and cyber threat intelligence firm Cybermerc.
We speak with Michelle Price, CEO of AustCyber about the outcomes from the opening two days of events and the remainder of the week's events.
Recorded October 26, 2021
Read more: https://australiancybersecuritymagazine.com.au/hypothetical-hospital-cyber-attack-highlights-cyber-risks-in-healthcare/
AUCyberWeek2021 - https://www.cyberweek2021.austcyber.com/
Video Interview version https://mysecuritymarketplace.com/av-media/aucyberweek2021-with-austcyber-ceo-michelle-price/
Related interview: AustCyberWeek Wrap-up interview https://youtu.be/njy5uk3fMCQ
Interview by Jane Lo, Singapore Correspondent with Lim Thian Chin (Director, Critical Info Infrastructure Division, Cyber Security Agency of Singapore)
Thian Chin is leading the Critical Information Infrastructure (CII) Division at the Cyber Security Agency of Singapore (CSA). The division is responsible for building the cyber resilience of the Nation’s essential services across 11 CII sectors covering government, utilities, transport and services clusters. His team works with sectoral regulators to strengthen the cyber resilience of CII owners, to promote confidence-building measures and to deepen the public-private partnership between the government and CII stakeholders. Thian Chin also represents Singapore in International and regional cybersecurity forums where he shares his knowledge on cybersecurity resiliency and capability building.
Thian Chin has over 19 years of experience in Information & Technology governance, risk management, resilience and compliance, and Operational Technology cybersecurity. Prior to joining CSA in August 2015, he was responsible for the regional Technology Governance function in United Overseas Bank. He also led the Technology Risk function in GIC from 2008 – 2013. In his earlier years, he was a Manager and had led a team of auditors in Information Technology in Ernst & Young. Thian Chin holds an Executive Masters (Cybersecurity) with Brown University, a bachelor’s degree in Computer Engineering from Nanyang Technological University and is an alumnus of the George C Marshall European Center for Security Studies. He is certified as a GICSP, CGEIT, CDPSE, CRISC, CISM, CISSP, CISA, and SABSA practitioner.
In this podcast, Thian Chin shared some highlights* on cybersecurity and operational technology (OT) at the Singapore International Cyber Week (SICW 2021), and the OT Cybersecurity Expert Panel (OTCEP), organized by the Cyber Security Agency of Singapore.
Touching on cybersecurity incidents highlighted in the “Singapore Cyber Landscape 2020” such as ransomware and supply chain, he noted the increasing complexity of the threat landscape.
He discussed some common perceptions of the cybersecurity professionals and the engineers running the operating infrastructure, including infrastructure “air gap” and cultural differences such as skills and language, and security goals (“CIA” - versus “SRP”).
Referring to one of Singapore’s largest cyber incidents in the CII sector, and the recent threats, he shared perspectives on how government policies such as the OT-ISAC, the OT Cybersecurity Code of Practice (updated in 2019) and the Cybersecurity Competency Framework (2021) help to boost cyber defenses.
With the recent release of the “Singapore Cyber Security Strategy 2021”, he also several areas of focus for the CII cybersecurity ecosystem, including structuring an approach to managing supply chain risks and building cyber resiliency profiles.
*also included highlights from OT-ISAC (Operational Technology Information Sharing and Analysis Centre) and ISACA Singapore Chapter
Recorded: 15th October 2021 (SGT 8.30am)
Today we're joined by Cybersecurity Advisors Network (CyAN) International Vice President and Zero Day Legislative Project leader, Peter Coroneos. CyAN is a Paris-based global not-for-profit association representing cybersecurity professionals in 22 countries.
They have announced the formation of a global partnership to secure legal protections for good faith (bona fide) zero day researchers.
READ MORE: https://cyberriskleaders.com/global-coalition-builds-to-protect-cyber-researchers/
The OECD* recognised the need for action in their 2021 guidance for policy makers observing: In many countries, researchers face significant legal risk when reporting vulnerabilities to vulnerability owners. Vulnerability owners can threaten researchers with legal proceedings instead of welcoming their vulnerability reports. This legal risk, aggravated when stakeholders are located across borders, creates powerful disincentives [for responsible disclosure]. * Source: https://www.oecd-ilibrary.org/docserver/0e2615ba-en.pdf
Thanks for tuning in and stay tuned for more...
Recorded Tuesday 19 October 2021 – video version is available here https://youtu.be/etf3MtxvK1c
ClearSale’s statistical technology and in-house fraud analysts have combined to create card-not-present (CNP) fraud prevention that reduces chargebacks and false positives. As the pandemic shifted consumers in many regions from in-store to online shopping and fraud attacks on ecommerce merchants increased, ClearSale’s 2020 net revenue grew by 65.7%, compared to 2019 growth of 35.5%. ClearSale has announced its July 30 initial public offering on Brazil’s B3 stock exchange generated the equivalent of US$254 million (R$1.3 billion) following the company’s historic revenue growth in 2020. The company’s 2020 net international revenue grew by 132.7% to comprise 11% of the total.
Account takeover (ATO) fraud is big business for criminals, and it’s on the rise. One study found that ATO attacks on ecommerce retailers selling physical goods increased by 378% during the second quarter of 2020, compared to the same period in 2019. What’s driving this increase? In many cases, it’s personal data that’s all too easy to find online, and it doesn’t even need to be sensitive information like passwords in order to fuel ATO attacks.
Recent news about Facebook and LinkedIn user data underscores just how much material fraudsters have at their fingertips and how they can use even publicly available information to commit fraud. In April, news broke that personal data such as phone numbers, email address, birthdates and genders from more than 500 million accounts on each of the two social networks had been collected by data-scraping tools and shared on the dark web.
Facebook in particular took heat for not notifying users at the time the data-scraping incident was first reported, back in 2019. Both Facebook and LinkedIn have noted that the exposed data was shared by users and wasn’t the result of a breach of secured data. However, security experts quickly outlined a number of ways that the scraped data could be used to commit fraud.
Ralph Kooi is the Country Manager Australia at ClearSale, a full-service cloud based platform that automates Fraud Prevention, allowing businesses to increase sales while reducing risk. ClearSale is the only company that never automatically declines an order before a manual review process, which allows us to achieve industry-high approval rates while eliminating false declines and brings in additional revenue for our customers. Ralph Kooi has previously worked for several International SaaS businesses while based in Australia.
David Fletcher serves as Senior Vice President at ClearSale, a card-not-present fraud prevention operation that helps retailers increase sales and eliminate chargebacks before they happen. As a serial entrepreneur, he understands the particular pain points that affect business owners today, and how fraud management can provide real-world solutions to those problems. At ClearSale, he spearheads business development, sales, partnerships and alliances with top e-commerce organizations.
Streamed on MySec.TV on 13 October 2021 – view the video version at https://mysecuritymarketplace.com/av-media/fraud-trends-fraud-prevention-frameworks-for-merchants/
Today, we're joined by Michelle Price, CEO of AustCyber to discuss the return of the annual Australian Cyber Week, a week-long series of events and activities, this year to be held from 25-29 October 2021.
The week combines virtual and in-person sessions to generate awareness about the Australian cyber security industry and showcase local innovation. It will also support increased understanding of cyber security by debating topical issues, risks and solutions, and facilitate national and global networking.
FOR DISCOUNT TICKETS VISIT https://mysecuritymarketplace.com/event/australian-cyber-week-2021/
Thanks for tuning in and stay tuned for more... #mysecuritytv #austcyber #AUcyberweek2021 #cybersecurity
After 3 years it came down to just seconds! Interview with Leader of team CSIRO’s Data61 and CSIRO’s Robotics group leader, Dr Navinda Kottege.
Robotics experts led by Australia’s national science agency, CSIRO, have beaten teams from NASA JPL/MIT, California Institute of Technology, and Carnegie Mellon University to claim second place in a world leading robotics competition dubbed the ‘Robot Olympics’.
Organised by the US Government research agency DARPA and spanning a three-year-period, the Subterranean Challenge was designed to push the boundaries of autonomous robotic technology. Scientists were tasked with remotely running the robots in an underground environment that simulated a real-world scenario. This included locating models representing lost or injured humans, backpacks, or phones, as well as variable conditions such as pockets of gas.
The $US1 million ($AUD1.3) prize money will be reinvested into team CSIRO’s Data61’s research and development of Australian technology.
Further reading: https://drasticnews.com/australia-claims-historic-top-two-spot-in-the-robot-olympics/
2021 is shaping up to be a seminal year for Critical Infrastructure organisations when it comes to both physical and cybersecurity.
The twin imperatives of COVID-19 (and its contingent lockdowns and impact on international travel to and from Australia) and the amendments to the Critical Infrastructure Act mean that its more important than ever for the sector to get their security in order.
In this interview we talk to Genetec’s ANZ Country Manager George Moawad about how has risk management at Critical Infrastructure organisations has changed over the last 12-18 months and what are the biggest security concerns of current and prospective critical infrastructure clients.
Further Reading
Cybersecure solutions for protecting the everyday - https://www.genetec.com/trust-cybersecurity/cybersecurity
Tools to help implement a cybersecurity strategy - https://www.genetec.com/blog/cybersecurity/how-to-maintain-a-strong-cybersecurity-strategy
The ACSC Annual Cyber Threat Report 2020–21, the second unclassified annual cyber threat report since ASD became a statutory agency in July 2018, highlights the key cyber threats affecting Australian systems and networks, and uses strategic assessments, statistics, trends analysis, and case studies to describe the nature, scale, scope and impact of malicious cyber activity affecting Australian networks. It also provides advice to Australian individuals and organisations on what they can do to protect their networks from cyber threats.
Over the 2020–21 financial year, the ACSC received over 67,500 cybercrime reports, an increase of nearly 13 per cent from the previous financial year. The increase in volume of cybercrime reporting equates to one report of cyber attack every 8 minutes compared to one every 10 minutes last financial year.
As part of an Industry Sector Review and recognition of the report, we speak with Amit Chaubey, NSW Cyber Security Ambassador, Virginia Calegare, Cyber Security Advisor and Elliot Dellys, Cyber Security Advisor.
Thanks for tuning in and stay tuned for more… #mysecuritytv #acsc #cybersecurity #threatlandscape
Further Reading & Links
ACSC – cyber.gov.au
https://www.cyber.gov.au/acsc/view-all-content/reports-and-statistics/acsc-annual-cyber-threat-report-2020-21
MySecurity Marketplace – ACSC Report Post
https://mysecuritymarketplace.com/reports/acsc-annual-cyber-threat-report-2021/
MySec.TV Episode - recorded Live
https://mysecuritymarketplace.com/av-media/acsc-annual-cyber-security-threat-report-20-2021-industry-sector-review/
A landmark defence and security partnership has been agreed by the leaders of the UK, the United States and Australia which will protect and defend shared interests in the Indo-Pacific.
Under the ‘AUKUS’ alliance, the three countries will enhance the development of joint capabilities and technology sharing, as well as foster deeper integration of security and defence-related science, technology, industrial bases and supply chains. The first major initiative of AUKUS will be to deliver a nuclear-powered submarine fleet for Australia.
We speak with Dr. Malcolm Davis, Senior Analyst with the Australian Strategic Policy Institute (ASPI)in Canberra and Zack Cooper, Senior Fellow with the American Enterprise Institute (AEI) in Washington on this arrangement and the implications for Australia and Indo-Pacific.
#mysecuritytv #AUKUS #nationalsecurity #indopacific
Further Reading - Asia Pacific Security Magazine
https://www.asiapacificsecuritymagazine.com/australia-to-acquire-nuclear-powered-subs-under-new-aukus-security-partnership/
https://www.asiapacificsecuritymagazine.com/australia-uk-and-us-launch-new-security-partnership/
MySec.TV version - recorded 17 September 2021 https://mysecuritymarketplace.com/av-media/aukus-strategic-security-alliance-announcement-and-implications/
We speak with Relativity's CSO & CIO, Amanda Fennell and the APAC Managing Director, Georgia Foster for an insight into the company and trends in the APAC region.
Relativity is on the mission to help organizations organize data, discover the truth, and act on it. This is especially resonant for customers who are dealing with sensitive data, demanding investigations and complicated litigation.
The changing security threat landscape for APAC has made risk mitigation and data protection strategies more crucial than ever. Relativity’s security team, Calder7, frequently conduct research on the threat landscape to help readers stay up to date on the latest threats. Security Sandbox is a Relativity podcast aiming to help listeners learn about new fields and fortify their security programs.
The goal is to share insights and inspire a few laughs, reward curiosity, and bring a little more excitement to the day-to-day work of our industry.
Dr. Arsenia Chorti is a Professor at ENSEA (École Nationale Supérieure de l'Électronique et de ses Applications, Paris, France) and a Visiting Research Fellow at Princeton University. She is also the Head of the Information, Communications and Imaging (ICI) Group of the ETIS Lab.
She is also a chartered engineer from the Technical Chambers of Greece, and a member of the IEEE P1951.1 Working Group on Smart Cities Standardization, the IEEE INGR Working Group on Security, and the IEEE P1940 Standardization Workgroup on Standard profiles for ISO 8583 authentication services.
Her research spans the areas of wireless communications and the design of security schemes for 5G and 6G with a particular focus on physical layer security, including context aware security, wireless security, 6G and IoT, intrusion detection in IoT networks and machine learning for communications.
In this podcast, Professor Chorti gives an introduction on 6G, and how the sheer scale of applications and network delivering on a full range of diverse requirements - data rate, latency, energy and complexity constraints – will power “networks that for the first time, can ‘see’, ‘hear’ and ‘sense’.”
She cautioned how the nature of information will change, such as the volume of sensitive and private data transmitted over the air, and how the heterogeneous nature of 6G networks requires a rethink of today’s security solutions built on cryptography.
Highlighting how existing protocols could be complemented by incorporating the physical characteristics of the wireless environment (“physical layer security”), she pointed out various areas of applications. These include device authentication using the physical location information of the device, distilling entropy available in the wireless medium to generate keys. Additionally, the risks of existing physical layer attacks such as jamming would increase under 6G, and security measures would likely rely on physical layer solution.
Recorded 3rd September 2021, 4.30pm SGT/ 10.30am France.
In this episode we're joined by Ekata's APAC Team - Dan Jiao, Director Asia Pacific and Niall Whelan, Principal Field Data Scientist, Asia Pacific.
We’ll be discussing trends in eCommerce and payments, and the landscape of fraud/abuse along with the main fraud implications. We’ll also look at the data science approach to solving fraud and how friction reduction and customer experience have become paramount in the digital environment.
Register also for an upcoming deep dive session with Niall Whelan, Principal Field Data Scientist, Asia Pacific and ensuring the customer experience and validation strategy keeps pace. Register here https://learnsecurity.mysecuritymarketplace.com/course/fraud-prevention
Thanks for tuning in and stay tuned for more... #mysecuritytv #ekata #fraudprevention #cybersecurity #datascience
Recorded and streamed on MySec.TV - video version available here https://mysecuritymarketplace.com/av-media/preventing-fraud-in-the-digital-world-with-early-accurate-detection/
At the start of 2021 Kylie McDevitt left her role as Technical Director in the Australian Government and with her husband Silvio Cesare, formerly Director of Education at the University of NSW Cyber Security Centre, have transformed a warehouse in Canberra and started a hackerspace called InfoSect.
Inspired by groups like the L0pht in the USA, they have left their career roles and set out full time on their own to build a place to hangout with other hackers and do cool research. This is their story...so far!
LINKS Kylie's Blog Post http://www.networkhacked.com/2021/07/stepping-off-cliff-edge.html
WEBINAR: GOVERNMENT & PRIVATE SECTOR - Working Together for Cybersecurity Protection of Critical Infrastructure https://learnsecurity.mysecuritymarketplace.com/course/ciprotection
BSides Perth 18-19 September - https://bsidesperth.com.au/
MySec.TV Interview https://mysecuritymarketplace.com/av-media/canberras-hackerspace-analysis-of-infosect/
WatchGuard is celebrating 25 years in 2021! Today, we speak with WatchGuard's Corey Nachreiner, Chief Security Officer based in Seattle, USA and Vincent Tan, Regional Sales Director in Singapore for Southeast Asia.
Nachreiner is an authority on network security and has operated at the frontline of cyber security for 22 years, and for nearly a decade has been evaluating and making accurate predictions about information security trends. We'll also discuss the recent Kaseya ransomware attack and other 'Big Game' attacks amongst other industry and sector trends in the region and globally.
Recognized as a thought leader in IT security, Nachreiner spearheads WatchGuard's technology vision and direction, and manages WatchGuard’s corporate security. Previously, he was the director of strategy and research at WatchGuard. Nachreiner has operated at the frontline of cyber security for 22 years, and for nearly a decade has been evaluating and making accurate predictions about information security trends. As an authority on network security and internationally quoted commentator, Nachreiner's expertise and ability to dissect complex security topics make him a sought-after speaker at forums such as Gartner, Infosec and RSA. He is also a regular contributor to leading publications including CNET, Dark Reading, eWeek, Help Net Security, Information Week and Infosecurity, and co-host The 443 Security Simplified podcast.
#mysecuritytv #watchguard #threatlandscape #cybersecurity
Recorded and streamed live on MySec.TV - Friday 20 August 2021 - to watch the session visit https://mysecuritymarketplace.com/av-media/celebrating-25yrs-with-watchguard-apac-threat-landscape/
To realistically transform data protection there are complex considerations, competing priorities and some new approaches that need to be adopted.
This is an informative panel discussion with the CISO of Flybuys, Alex Loizou, Strategic Business Director of Forcepoint, Nick Savvides and hosted by Chris Cubbage of MySecurity Media.
SESSION FOCUS:
Common data protection challenges organisations are facing during security transformation projects;
Insights into the FlyBuys experience. What the Flybuys' CISO considered as part of their security transformation project, including security terminology, team changes and culture;
Key advice and takeaways for those planning or about to execute a security transformation project at their organisation.
OVERVIEW
We’re in a constant state of transformation where technology and security requirements are changing rapidly.
Over the last 18 months, organisations have seen large scale changes in terms of where employees are working from, the use of cloud applications and importantly, to our network design patterns.
While digital transformation and security management has been the core focus of this rapid change, it’s been slower moving in the data protection space, which has always been a complex area.
There are an array of considerations, competing priorities and some new approaches that need to be adopted.
Recorded 10 August 2021 courtesy of Forcepoint and Learn Security.
For the video version visit https://mysecuritymarketplace.com/av-media/data-protection-considerations-during-a-security-transformation-project-webinar-takeaway/
We speak with Paul Hadjy, CEO and Co-Founder of Horangi on how organisations in Southeast Asia can best safeguard their digital assets amid the shift to WFH and Cloud platforms.
Why Cloud Security Posture Management (CSPM) applications are considered essential today, and how these tools improve organisational risk postures by enabling proactive identification and remediation of vulnerabilities. Paul also provides insights from Southeast Asia’s cybersecurity landscape, and the key trends impacting the region’s organisations.
Recorded 28 July 2021 for MySec.TV Tech & Sec Weekly - to watch visit https://mysecuritymarketplace.com/av-media/cybersecurity-risk-due-to-misconfigured-cloud-infrastructure/
Chris Lehman is the Chief Revenue Officer at ExtraHop, where he leads global sales, sales engineering, channel sales, inside sales, and sales enablement. In his role at ExtraHop Chris brings 20 years of experience building high-growth sales organizations at scale for market-leading and market-making enterprise IT solutions.
Before joining ExtraHop, Chris served as Vice President of Americas Sales and Channel at FireEye. In this role, he was the driving force and architect of FireEye's current go-to-market strategy running a $500 million business, and leading a team of over 250 sales, channel, and business development professionals. Prior to FireEye Chris held a series of sales leadership positions at Salesforce.com and Dell/EMC.
Chris holds a B.A. in Communications from the Pennsylvania State University.
In this podcast, Chris shares highlights of the ExtraHop’s acquisition by Bain Capital Private Equity and Crosspoint Capital Partners, in a deal valued at USD $900 million.
In discussing the standard metrics behind arriving at a valuation, he stresses the importance of a “large addressable market place”. For example, ExtraHop’s recent acquisition - “growth equity investment” - that will allow the execution of growth strategies, such as geographical expansion.
Chris also introduces the different funding stages in the venture capital (“VC”) world, from seed/angel to Series A, B, C and beyond, noting the key considerations at each stage, such as partnering with venture capital firms that bring expertise in areas that can help grow the business.
For ambitious cybersecurity firms, beyond delivering value in making organisations more secure, he advises on the importance of a strong go-to-market strategy where the product vision is well aligned with marketing, sales and customer service.
Interview by Jane Lo, Singapore Correspondent. Recorded on 10th August 7am Singapore Time / [day -1] 7pm EST
We’re joined by Chris Hockings, Chief Technology Officer, IBM Security.
IBM Security has released the results of its annual Cost of a Data Breach report, based on in-depth analysis of 500+ real-world data breaches occurring over the past year. The report found that data breaches in Australia reached the highest cost in the report’s 12-year history, costing companies an average of $3.7 million per incident (nearly 10% increase over the previous year).
The average time to detect and contain a data breach was 311 days (219 to detect, 92 to contain) – which is over a week longer than reported in the prior year.
Access the report – https://mysecuritymarketplace.com/rep…
We cross to Perth and speak with Paul Haskell-Dowland, Associate Professor and Associate Dean (Computing and Security) at Edith Cowan University's School of Science.
The Pegasus spyware episode saw more than 50,000 phone numbers, and 1,000 people in 50 countries reportedly under surveillance. The spyware was developed by the Israeli company NSO Group and has been sold to government clients. It can infiltrate Android devices and Apple iOS versions up to the latest release, iOS 14.6, through a zero-click iMessage vector.
#spyware #cybersecurity #ECU #MySecurityTV
Further Reading - Impacts on India - https://www.asiapacificsecuritymagazine.com/terrorising-surveillance/
MySec.TV Video version https://mysecuritymarketplace.com/av-media/5-ways-to-defend-against-spyware-attack-on-your-smartphone/
Previous podcast with Paul Haskell-Dowland - https://mysecuritymarketplace.com/av-media/episode-189-ecu-launches-new-security-operations-centre-with-rsa-security-building-renewed-tertiary-focus-on-cybersecurity-skills-training/
Jane Lo, Singapore Correspondent speaks with Ms Lynette TAN, Chief Executive. Singapore Space and Technology Limited (SSTL).
As Chief Executive and Board Member of SSTL, Lynette develops the organisation’s industry initiatives, leads its startup accelerator programmes and drives its consulting business, identifying opportunities for government organisations, companies and individuals to make critical decisions in the growing Asian space industry. In addition to running SSTL’s very own space accelerator programme for tech startups, she is also the managing Partner of Project Cyclotron, an exclusive programme with the Singapore government that assists early stage, deep tech, space start-ups.
She is a Karman Fellow, an international award given to individuals whose achievements in space are outstanding. She is also an advisor to German space start up, MyelinS.
Lynette is active in promoting Science, Technology, Engineering and Mathematics interest amongst youths and women. For her efforts and accomplishments, she received the Lancôme Visionary Award in 2018 and was recently recognised for her “Outstanding Contributions to the Science & Technology Industry” by a leading women’s publication. She was also recognised as a Trailblazer on the inaugural “Singapore 100 Women in Tech List” in 2020 for her outstanding efforts to put Singapore on the map of the space industry and for being a pioneer in the region’s space sector.
In this podcast, Lynette shares the highlights of the space sector and the latest news, and Singapore’s role in developing the ecosystem. With the rich space heritage across the world, she stresses the importance of connecting the “best and the brightest”, the “movers, shakers, ideas and people who are going to get the job done”, to push the space technology frontier and better lives.
As the sector is expected to continue its steady growth in the coming years, Lynette discusses the focus on accelerating innovations and cultivating the talent pipeline in order to realise the sector’s ambitions.
Lynette also provides updates on recent partnerships, including Project Cyclotron - a Cap Vista and SSTL’s joint venture-building program for space and deep tech companies, and the GNSS (Global Navigation Satellite System) collaboration between SSTL and ST Engineering.
Recorded: Friday 23rd July 2021 / 7.15am (Singapore Time)
We speak with Kshira Saagar, Chief Data Officer of Latitude Financial Services about what is Data Literacy and why it is important.
Kshira has been consecutively recognised among the Top 10 Analytics Leaders in Australia, for 2019, 2020 and 2021.
He is focused on helping key decision-makers and CxOs make smarter decisions using data, and strongly believes that every organisation can become truly data-driven. This is an insightful interview about how Data is the New Oil and moves into touching on ethics, privacy and managing AI capabilities.
For the MySec.TV version visit https://mysecuritymarketplace.com/av-media/importance-of-data-literacy-insights-of-a-chief-data-officer/
#mysecuritytv #datascience #dataliteracy #chiefdataofficer #CDO #AI #ML #privacy
We speak with Rob Nobilo, Regional Sales Director with Virsec
Virsec is a San Jose, USA based company which provides an application-aware workload protection platform. Virsec is gearing up for rapid growth in the ANZ region with Rob recently joining the team.
Nobilo brings years of in-depth experience as a former Sales Director at Palo Alto Networks, looking after enterprise accounts in BFSI, retail, healthcare, utilities and mining. Prior to joining Palo Alto Networks, Nobilo spent five years at Dimension Data (now NTT) in various roles including Security Practice Manager and National Business Manager of Managed Security Services.
“Virsec is gearing up for rapid growth in the ANZ region and I am keen to continue building the team over the coming year. The cybersecurity market in ANZ is worth around A$5bn and we will keep expanding at an annual rate of 18% till 2026,” said Nobilo.
Read more https://australiancybersecuritymagazine.com.au/virsec-announces-expansion-into-the-anz-market-with-new-appointments/
Watch the Video version - https://mysecuritymarketplace.com/av-media/virsec-enters-anz-cybersecurity-market/
We speak with Phil Rodrigues, Head of Security, APJ Commercial at Amazon Web Services (AWS).
Following the Federal Government’s announcement that it is investing more than $8 million in improving the skills and availability of cyber security professionals, we look at AWS and ADAPT research that found 92% of Australian and New Zealand CISO’s report the pandemic has increased the need for security and awareness training within their organisation. Further, 44% reported the depth of their in-house security skills is good but could be better, with an additional 39% reporting in-house skills are ‘poor’ or ‘OK’."
Recorded Live on MySec.TV - episode available https://mysecuritymarketplace.com/av-media/cybersecurity-professionals-australia-invests-8-million-on-skills-and-availability/
Apologies for a network outage during the session.
#cybersecurity #AWS #cyberskills #securityawareness #mysecuritytv
Alexis Dorais-Joncas started his career in cybersecurity in 2010, when he was hired by ESET as a malware researcher. In 2015, Alexis was appointed head of ESET’s R&D branch office located in Montreal, where he and his team focus on cutting edge malware research, network security and targeted attack tracking. Their goal is to shed light on the latest trends and developments in the malware ecosystem and implement efficient and innovative countermeasures to allow ESET customers to be safe online.
Alexis is an established speaker on current cyberthreats, having spoken in front of both very technically literate audiences at events such as Bluehat and M3AAWG, and in higher level settings such as RightsCon, SERENE-RISC workshops and GoSec. He has been quoted in several security and technical media such as Wired, ITWorldCanada, DarkReading and Ars Technica, with broadcast appearances on Radio-Canada and Sky News in the UK.
In this podcast with Jane Lo, Singapore Correspondent, Alexis takes the audience behind the scenes of real cybercrime investigations ESET has been involved in. By going over success stories such as the Andromeda and Operation Windigo busts that brought down multi-million dollar criminal networks, Alexis helps shed some light on how private security companies partnerships with law enforcement agencies work.
With an excess of 350,000 new malware files observed each day, Alexis explains that one of the first steps is turning these into unique and actionable insights, using a combination of automated unpacking and decryption tools and in-depth analysis.
In sharing such threat information with law enforcement agencies, he highlights the integral role of trust, including the importance of following protocols where customers’ data are involved, and exercising caution to avoid “tipping off”.
While waiting for the “right moment to strike”, Alexis points to another important role that the private sector plays. To help the law enforcement arrest the cyber criminals and build the case for indictment and prosecution, Alexis shares how his team provides comprehensive training to the law enforcement agencies.
Alexis also discusses how the work behind Andromeda and Operation Windigo busts took up to 4 years, and how identification of victims through “sinkholing” forms part of the take down efforts.
As these two cases illustrate, with the right private-public partnerships and collaborations, Alexis stresses while cybercrime may be borderless, cyber criminals are not immune from prosecution.
Recorded: 18th June 2021, 7am Singapore/ [-1 day] 7pm Montreal
We speak with Dr John Coyne, Head of Strategic Policing and Law Enforcement at the Australian Strategic Policy Institute.
A cyber sting three years in the making culminated last week when the Australian Federal Police (AFP) executed hundreds of search warrants in Australia-wide raids.
Dubbed Operation Ironside, the AFP joined the FBI to harness an encrypted app called ANoM and feed it into underworld circles worldwide.
Since 2018, the AFP has been reading the presumed secure ANoM messages that resulted in Monday’s raids. With state police agencies, the AFP arrested 224 people on 526 charges. Simultaneous raids occurred around the world.
We discuss what may be the implications of such an operation – not just on organised crime but also on the future of policing and trust in encryption capabilities.
Further reading: https://australiancybersecuritymagazine.com.au/operation-ironside-sees-police-raids-worldwide/
Thanks for tuning in and stay tuned for more… #MySecurityTV #Police #Policing #Ironside #AFP #Encryption
MySec.TV version is available here https://mysecuritymarketplace.com/av-media/police-operation-ironside-what-are-the-implications/
Jane Lo, Singapore Correspndent interviews Professor Dr. Christian Doerr, Professor of Cyber Security and Enterprise Security, Director of the Cyber Threat Intelligence Lab, Hasso Plattner Institute (Potsdam, Germany).
Professor Dr. Christian Doerr, is the Professor of Cyber Security and Enterprise Security, and Director of the Cyber Threat Intelligence Lab, Hasso Plattner Institute in Potsdam, Germany.
He works in the broad area of network security and critical infrastructure protection, with a research focus on designing resilient network systems, localizing and estimating current threats through real-time situational awareness in networks as well as conducting threat intelligence on adversaries. While most of his work focuses on technology, he also integrates socio-technical aspects of cyber security in his research.
Professor Doerr received his Ph.D. in Computer Science and Cognitive Science from the University of Colorado, USA.
In this podcast, Professor Doerr discussed the investigation by his team into the emerging role of Bitcoin in powering advance malware, and shared insights into threat actors’ use of Bitcoin blockchain to signal the locations of the Command and Control (C&C) Infrastructure.
He highlighted key developments of the C&C evolution in the cat-and-mouse game between the cyber defenders and the threat actors. With attractive characteristics such as immutability, open-access, and high adoption rates, he pointed out how blockchain holds certain advantages over existing designs for threat actors.
While the research team was able to execute a temporary take-over of the infrastructure that cost the adversaries approximately $2 million, the threat actors, however, were able to adapt quickly and resume their malicious activities.
As detection of covert communication patterns in a blockchain is still in its infancy, Prof Doerr predicted that threat actors will increasingly blend their malicious activities with normal services using the blockchain infrastructure. Faced with such a scenario, he advised cyber defenders to bolster basic mitigation measures, including addressing the weakest link by raising user awareness.
Recorded 26th May 2021 Singapore 5.15pm/ Germany 11.15am.
Professor Doerr spoke at BlackHat Asia 2021 - MySecurity Media were media partners to the event.
WordPress set to grow to $636 billion this year, fiercely competing with eCommerce.
Today we’re interviewing WP Engine’s Country Manager, ANZ, Mark Randall and Senior Engineer and self-described “WordPress Evangelist” Ricky Blacker.
WP Engine, the #1 managed WordPress platform in the world, is launching the world’s first WordPress economy study in partnership with the University of London and Vanson Bourne. The WordPress Economy report reveals WordPress is a multi-billion-dollar industry now valued at $597 billion, compared to AI at $327 billion and eCommerce at $618 billion.
Listen to the previous interview with WP Engine – https://australiancybersecuritymagazine.com.au/wp-engine-the-future-of-websites-fake-news-dark-data/
Recorded on MySec.TV Live - June 8, 2021
Interview with Mary Jo Schrade, Assistant General Counsel and Regional Lead for Microsoft’s Digital Crimes Unit (DCU) Asia.
Disrupting one of the world’s most dangerous malware - Trickbot
Mary Jo Schrade is an Assistant General Counsel and Regional Lead for Microsoft’s Digital Crimes Unit (DCU) Asia and is based at Microsoft’s Cyber Security Center in Singapore. She oversees the initiatives, programs and strategies related to Microsoft Asia’s efforts to prevent or disrupt organized cybercrime and online tech support scams through public-private partnerships, coordinated enforcement, and customer engagements relating to cyber security and Microsoft's digital trust commitment to its customers.
In this podcast, Mary Jo gave highlights of Microsoft’s legal action in October 2020 to disrupt Trickbot, one of the world’s most pervasive malware families which was behind attacks launched by ransomware groups such as Ryuk.
Representing one of the rare cases where the disruption was coordinated by private sector organisations, this involved extensive partnerships around the world with other organisations, including FS-ISAC (financial services information sharing and analysis center), ISPs, and other cybersecurity companies.
She also shared some of the key factors and decisions behind the legal strategy, and learning lessons for cyber defenders. For smaller and medium sized organisations in Asia, she stressed that the effectiveness of protective measures, such as multi-factor authentication, cannot be underestimated.
Recorded 28th May 2021, Singapore 9am.
We speak withEvan Davidson, Vice-President, Asia Pacific & Japan and Kelvin Wee, Director for Security Engineering, APJ for SentinelOne and discuss how AI-driven innovations are disrupting the Top Right Quadrant for Endpoint Protection.
We also discuss what the Mitre Att&ck evaluation is, their methodology and why it has become one of the best sources for CISOs to choose their cybersecurity solutions. SentinelOne scored 100% for visibility in the evaluation and we cover the critical importance visibility has in providing extended detection and response capability.
Linked to the Mitre Att&ck evaluation is available via https://attackevals.mitre-engenuity.org/enterprise/participants/sentinelone/?adversary=carbanak_fin7
Recorded courtesy of SentinelOne, 27 May 2021 - MySec.TV version is available here.
We speak with ISACA on their recent annual research report, The State of Cybersecurity.
We're joined by Jenai Marinkovic, vCTO/CISO at Tiro Security and advisory board member at Beyond, and member of ISACA’s Emerging Trends Working Group and Jonathan Brandt, ISACA Information Security Professional Practices Lead.
State of Cybersecurity 2021, Part 1: Global Update on Workforce Efforts, Resources and Budgets reports the results of the annual ISACA global State of Cybersecurity Survey, conducted in the fourth quarter of 2020.
The report (www.isaca.org/state-of-cybersecurity-2021) focuses on the current trends in cybersecurity workforce development, staffing and cybersecurity budgets. The issue of cybersecurity workforce deficiencies remains unresolved, despite years of reporting on this problem from numerous resources.
Streamed May 28, 2021. Video version is available at https://youtu.be/ykzwD2CB0Jc
Thanks for tuning in and stay tuned for more... #MySecurityTV #ISACA #Cybersecurity #cyberskills
In this interview we speak with Tim Jones, Managing Director and Stefan Prandl, Chief Technology Officer of Hyprfire.
Hyprfire is an Australian cybersecurity start-up which has innovated the application of Power Law Statistical Distributions and Behavioural Analytics to achieve effective, real-time network anomaly detection.
Get a copy of the Firebug Whitepaper here www.hyprfire.com/whitepaper
#cybersecurity #networkdetection #IDS
To view the MySec.TV interview - visit https://youtu.be/JEg8z0ndtWI
Interview by Jane Lo, Singapore Correspondent with Dr. Herbert Lin, Senior research scholar, Cyber Policy and Security, Center for International Security and Cooperation; Hank J. Holland Fellow, Cyber Policy and Security, Hoover Institution; and Elected Fellow, American Association for the Advancement of Science.
In addition to his positions at Stanford University, Dr. Lin is Chief Scientist, Emeritus for the Computer Science and Telecommunications Board, National Research Council (NRC) of the National Academies, where he served from 1990 through 2014 as study director of major projects on public policy and information technology, and Adjunct Senior Research Scholar and Senior Fellow in Cybersecurity (not in residence) at the Saltzman Institute for War and Peace Studies in the School for International and Public Affairs at Columbia University; and a member of the Science and Security Board of the Bulletin of Atomic Scientists. He served on President Obama’s Commission on Enhancing National Cybersecurity.
Prior to his NRC service, he was a professional staff member and staff scientist for the House Armed Services Committee (1986-1990), where his portfolio included defense policy and arms control issues. He received his doctorate in physics from MIT.
Dr. Lin’s research interests relate broadly to policy-related dimensions of cybersecurity and cyberspace, and he is particularly interested in and knowledgeable about the use of offensive operations in cyberspace, especially as instruments of national policy.
Avocationally, Dr. Lin is a long-time folk and swing dancer and a poor magician. Apart from his work on cyberspace and cybersecurity, he is published in cognitive science, science education, biophysics, and arms control and defense policy. He also consults on K-12 math and science education.
In this podcast, Dr Lin discussed cyber influence and the modern phenomenon of misinformation, offering historical perspectives and insights into how technological tools are leveraged in today’s misinformation campaigns.
He emphasised the key differences between cyber operations and cyber enabled information operations, where the former (e.g. ransomware) targets computer systems, the latter (misinformation) targets our hearts and minds. Giving examples observed in the U.S., he noted challenges with implementing effective mitigation measures against misinformation whilst preserving the free flow of ideas.
He also addressed some commonly asked questions for deploying misinformation and information warfare as a psychological operation from a national security perspective.
With non-stop advances in technology and no-shortage of opportunities to sow misinformation, Dr. Lin also shared his thoughts on the evolution of the threat landscape.
We speak with Drago Gvozdanovic, CEO of Cynterra, based in Canberra.
In an Australian first, cybersecurity and data analysis firm Cynterra, has won a major contract to provide the Australian Government’s Digital Transformation Agency (DTA) with a new generation Secure Internet Gateway (SIG). The first of its kind SIG is based on Cynterra’s fully IRAP assessed Secure Cloud Platform (SCP), spending years in research and development to deliver an agile and scalable architecture with the ability to customise security gateways to different areas of a business.
This allows for compliance and enforcement of Government security requirements to any organisational environment.
Recorded and streamed live on Tuesday 27 April 2021 - video version available at https://mysecuritymarketplace.com/av-media/cynterra-wins-major-dta-contract-for-secure-internet-gateway/
Thanks for tuning in and stay tuned for more... #MySecurityTV #cybersecurity #cynterra #SIG #secureinternetgateway
We cross to Silicon Valley and speak with Amir Khan, President, CEO & Founder of cloud computing platform Alkira and their start-up program with Microsoft.
Alkira has announced a close collaboration with the Microsoft for Startups program, a select group of emerging businesses hand-picked by Microsoft for the benefits they offer to Microsoft Azure customers in their journey to the cloud. The select start-ups receive growth partnership and ecosystem support from Microsoft including access to technical, sales and marketing opportunities and leadership. Alkira also announced that the Alkira Cloud Services Exchange (CSX) – the core of the company’s Network Cloud platform – is now available on the Azure Marketplace.
Amir Khan is a computer networking visionary who founded and led Viptela’s market-leading, cloud-first, Software-Defined Wide Area Networking (SD-WAN) business before its acquisition by Cisco. Amir has held leadership roles at Cisco, Juniper, and Nortel. He holds 4 patents. Amir earned an MS in Electrical Engineering from the University of Colorado at Boulder, and a BS in Electrical Engineering from the University of Mississippi.
#mysecurityTV #cloudcomputing #cloudnetworking #Azure #startups #microsoft #alkira
For the full video interview, recorded Friday 23 April 2021, available here https://youtu.be/qVE06EFMHc0
We speak with Ron Gauci, CEO of the Australian Information Industry Association to discuss their call for sufficient funding into Australia's national Artificial Intelligence (AI) strategy.
The AIIA is calling on the Federal Government to allocate $250 million in the May budget to ensure Australia becomes a global leader in AI research and commercialisation and doesn’t fall behind its international peers.
When the Government does announce its National Artificial Intelligence (AI) Strategy it must come with significant funding over the $29.9 million it currently contributes over four years. The Australian Government commissioned the Artificial Intelligence: Solving problems, growing the economy and improving our quality of life, in November 2019 to assist its AI Roadmap which outlines the many opportunities and benefits available from investing in a National AI Strategy.
The AIIA is urging the Federal Government to support AI efforts, and focus on supporting R&D through to commercialisation of innovative products and services. This will help to maximise the return for Australian businesses and boost the AI sector and ensure our traditional industries remain internationally competitive including in agriculture, finance, health and manufacturing.
#artificialintelligence #AIIA #AI
For the full video interview, recorded 20 April, 2020 - available here https://youtu.be/BtlvpRcBbL8
Full release available here - https://smartcitiestech.io/2021/04/aiia-urges-morrison-government-to-fully-fund-a-national-ai-strategy/
We speak with Anthony Stevens, Founder & CEO of 6clicks.
6clicks is making a big announcement, backed by Microsoft, where the company is launching an IRAP PROTECTED assessed instance of their platform for defence and government market - 6clicks for Government.
Following their recent $5.5M capital raise, the company also announced this week that Matt Gyde, former CEO of billion-dollar global technology services company NTT Security has joined the team as Non-Executive Director.
Matt’s career in IT security spans more than 20 years, with a rich history including high-level roles with Dimension Data and Datacraft-Asia, providing him a deep understanding of how security platforms should be implemented and managed to ensure clients’ business outcomes are achieved while ensuring their risk is minimised.
This is our second interview with Anthony and looking forward to following the company's rise. Stay tuned! #6clicks #mysecuritytv
For the full video interview, recorded Friday 16 April, 2021 - available here https://youtu.be/1uOZnUB_-mk
Full media release - https://australiancybersecuritymagazine.com.au/6clicks-and-microsoft-partner-to-meet-australian-government-and-defence-security-requirements/