Cyber Shorts - A Podcast by ECSC Group plc: Recent Episodes

Ian Mann

Continuing our efforts to help organisations of all sizes understand their cyber security responsibilities, ECSC explore the latest cyber security trends, risks and news with insight from cyber security specialist Ian Mann and a number of special guests. More about ECSC: Founded and Established in 2000, ECSC Group plc is the UK’s longest running full-service cyber security service provider. With an extensive range of in-house developed proprietary technologies, including advanced Artificial Intelligence (AI) systems. We provide expert security breach prevention and advisory support to organisations across all sectors with a specific focus on education, retail, legal, financial and local authorities. ECSC operates from two Security Operations Centres (SOCs): one in Yorkshire, UK, and the other in Brisbane, Australia. We offer flexible 24/7/365 cyber security monitoring, detection, and response support to its clients, either as a fully managed service or to enhance an organisation’s existing cyber security systems. In addition, ECSC’s Assurance division provides guidance, certification to industry standards, and extensive testing services to allow organisations to assess their cyber security protection. ECSC is led by a highly experienced senior management team with over 80 years’ combined experience within the company, and has delivered consecutive organic growth for the last 20 years. The Company’s broad client base ranges from e-commerce start-ups to global blue-chip organisations, including 10% of the FTSE 100.

View Details

Join Ian and Fabian, our Incident Response specialist, in this gripping episode as they unravel the world of cyber security and delve into ECSC's new service offering: Active Threat Detection (ATD). Brace yourself for an informative discussion that explores the inception of this game-changing service, the alarming breach trends shaping our digital landscape, and the cutting-edge technology behind it all.

Episode Highlights:

  1. Unveiling the Origins: Discover the genesis of ECSC's groundbreaking Active Threat Detection service. Learn how an amalgamation of breach trends and emerging technology led to its creation, revolutionising the way organisations combat cyber threats.
  2. The Art of Breaching: Dive deep into the sinister world of cyber attacks and uncover the strategies that malicious actors employ to breach organisations. Gain valuable insights into the vulnerabilities present in today's interconnected digital ecosystem.
  3. Continuous Vigilance: Peer into the world of continuous scanning, a pivotal aspect of ECSC's Active Threat Detection service. Witness how state-of-the-art technology relentlessly scans and analyses network traffic and system logs, tirelessly hunting down any signs of unauthorised access.
  4. Guarding Against the Unknown: Explore the critical importance of threat intelligence, an essential component of Active Threat Detection.

As the frequency and complexity of cyber threats continue to escalate, embrace the power of Active Threat Detection with ECSC. Tune in to this enlightening episode and equip your organisation with the cutting-edge knowledge and tools required to stay one step ahead of cyber criminals. With ECSC, prevention is always possible!

Are you ready to embark on a journey towards a secure digital future? Don't miss this enlightening episode on Active Threat Detection. Subscribe now and safeguard your organisation's valuable assets.

View Details

George is back! Join George and Ian in this exciting podcast episode as they delve deep into the world of Penetration Testing and explore its colours. In this episode, they will cover the following topics:

  1. The Many Hats of Penetration Testing: While most people are familiar with white, black, and grey hats in the cyber security industry, did you know that there are actually six different hats? Listen as Ian quizzes George on his hat knowledge and discover how well he fares.
  2. Unveiling the Teams: Have you ever wondered about the significance of the Red, Blue, and Purple teams? George and Ian will shed light on these teams and the hats they wear. But that's not all – they will also reveal the existence of four other teams: White, Green, Yellow, and Orange. Tune in to uncover the meanings behind these teams and explore the type of testing each team undertakes.
  3. Purple Team Testing: Get ready for a riveting deep dive into Purple Team Testing and why it is essential for all organisations. George and Ian will provide valuable insights into what organisations should be doing to enhance their security practices.

Don't miss out on this knowledge-packed episode! Join George and Ian on this captivating journey as they unravel the fascinating colours of Penetration Testing. Hit play and expand your understanding of cyber security testing strategies.

View Details

Join Ian (ECSC's Founder & Executive Chairman) & Jack (ECSC's Testing Service Director) while they discuss everything penetration testing and how to start your career. 

In this episode: 

  • Myths will be debunked,
  • How to start your career will be discussed (spoiler: it doesn't necessarily start with getting a cyber degree),
  • The different types of testing will be discussed, such as web application testing and infrastructure testing,
  • An overview of a 'typical' day in a testers work life will be shared,
  • In-house vs. consultative testing will be explained,
  • Does Social Engineering play a part in cyber security testing?,
  • The future of testing, e.g. cloud, Internet of Things (IoT), Mobile Device & App testing

View Details

Join Ian & Sarah (ECSC's Senior Cyber Consultant) as they discuss the Cyber Essentials certification and the changes that have been implemented to the scheme.

What are these changes and how do they affect you? What does this mean for your business? What do you know need to consider?

View Details

Updating The Standard

The Payment Card Industry Data Security Standard has been designed to protect customers against fraud when using their credit or debit cards and has been around for around 18 years. In that time, the threat from criminals has increased both in volume and in complexity.

To make sure the standard is appropriate for the current market and technologies, the standard has been revised and updated with a compliance date of 1 April 2024.

This podcast covers:

  • Who needs to comply with the standard (Merchants, Payment Processors, Banks)?
  • What to include in the Scope and how to reduce the Scope?
  • Some of the ways  hackers operate and skim data
  • The evolution of the standard to v.4.0
  • The role of a QSA

Want to know more? ECSC will be holding an in-person workshop on the Thursday 9th March to discuss the changes, what steps can be taken in advance and answer any questions you may have. This event is free to attend with pre-registration required. If you are interested in attending the workshop, click here or email events@ecsc.co.uk to secure your place.

View Details

This episode Ian is joined by Fabien, ECSC’s Cyber Security Incident Response Service Director, talking about all things Cyber Incident Response. Fabien has been working at ECSC for 17 years with a dedicated focus on Incidents; how to prevent them, how to contain them and how to restore access/data so BAU activities can recommence. 

The episode is broken into:

  • Incidents causes that we regularly see and hot to mitigate against these...
    • Office 365 vulnerabilities
    • Lack of MFA, MFA configurations and legacy issues
    • Ransomware
    • Patching
    • Increased exposure as a result of opening internet-facing elements
  • How ECSC define and manage incidents (Small, Medium and Large) and what tools we have to help our clients during an incident
  • Proactive measures that organisations can take including table top exercises with sessions aimed at technical IT personnel as well as management

View Details

Sadly, no grumpy George this episode. This episode Ian is joined by Jolan, ECSCs Standards Service Director, talking about ISO 27001 and the additional bolt on standards: ISO 27017 & ISO 27018. 

Some may argue that ISO 27001 is simply a list of questions with no technical requirements to prove your security, so what is the point? Join us as we discuss why organisations should adhere to ISO 27001, break down the technical jargon and explore the longer term view that the standard provides. 

Additionally, ISO 27017 (security of cloud platforms) and ISO 27018 (protecting Personal Identification Information), will be explained, what the standards mean and how they impact your business. 

View Details

This month Ian Mann and George Warrington are back, this time tackling common mistakes that lead to incidents. In our 20 years of experience, we have found that the most common causes of breaches are down to simple mistakes and human errors.

Are your systems secured with Multi-Factor Authentication? Is your password policy up to date? Are you aware which aspects of your systems are connected to the internet and which are not?

Join us as we find out which mistakes regularly cause incidents, and the best ways to remedy these mistakes.

View Details

This month Ian and George tackle the question of Cyber Security for Small to Medium Enterprises (SMEs). 

All organisations are susceptible to cyber hacks but having the fundamentals in place can help SMEs prevent basic attacks.

Join us as we discuss the cyber basics that all organisations should have in place, securing internet facing services/software, certifications, standards, patches, vulnerability scanning and much more. 

View Details

“A much bigger risk that someone steals my google account than we all die in a nuclear winter.”

Join Ian & George where they discuss all things Multi-Factor Authentication (MFA) and how having something in place is better than nothing. This episodes discusses:

  • What is MFA?
  • How to use MFA
  • The different types of MFA
  • How to hack MFA solutions
  • Emergent tech

Don't let perfection be the enemy of progress! It is easy to put off putting solutions in place which can and will protect your data because they are not a perfect solution or 'new' technologies are on the horizon.

Host: Ian Mann (CEO & Founder)

Guest: George Warrington (Senior Technical Security Engineer)