Do boards and business leaders understand the risks? Is security improving, barely keeping up with threats, or falling painfully behind? And more importantly, if what kept us secure has stopped working, what do we need to do to fix it? Join host Brian Contos and his guests as they explore these questions on The Cyber Security Effectiveness Podcast.
If you are here looking for Cyber Security Effectiveness, we invite you to visit the feed of Mandiant’s new podcast, The Defender’s Advantage Podcast: https://www.buzzsprout.com/1762840
The new show launches this week with the same great content you've come to expect from us and even more.
Host Luke McNamara anchors our Threat Trends series, chatting with Mandiant intel analysts, consultants, and researchers, as well as external practitioners and leaders in cyber security, all through a threat-focused lens.
And Mandiant's Kerry Matre joins to host monthly conversations with Mandiant customers and industry experts who will share their experiences and stories from the frontline of cyber security as part of our new Frontline Stories series.
Stay tuned for our inaugural Threat Trends episode later this week.
Mandiant Regional Account Executive Maggie Wilder sums up customers’ viewpoints best – they are being expected to do more with less. While there has never been more awareness around cyber security, the rate of acceleration for threats has been astounding and many are feeling lost. What is an organization to do?
The Behavior Research Team isa group unique to the work on which Mandiant Security Validation prides itself: assuring customers that they are protected. Drew Holland, Manager of Threat Research at Mandiant, joins the conversation to talk about landscape trends, his career in threat research, and why he loves what he does.
Brian talks with Mandiant Advantage’s Janice Kennedy, Director of Channel Management for the Western region, to get her perspective from the partner side of security. They delve into the types of response they are seeing from the channel and how these partners are building upon their skillsets and tools.
Mandiant Regional Account Executive Toks Jowosimi is one of the few who have witnessed the maturation and evolution of Mandiant Security Validation from the beginning, and has her own unique perspective to share on its transformation. She and Brian talk reactivity vs. proactivity, today’s common use cases for security validation, and customer priorities.
One of the most common security questions that organizations ask is how to better their security posture without exceeding their tight budget -- not an easy task. Brian and Mandiant Sr. Director of Customer Engineering Morris Hicks dig into Mandiant Security Validation’s ability to help organizations optimize their existing investments and cut out unnecessary overlap.
The world of incident response has slowly been moving further from the “ninja-like” appraoch it's been known for. Purple team extraordinaire Evan Peña revisits the podcast to talk about changes to incident response, purple teaming, and the recent shift toward collaboration with other teams to eliminate today’s largest threats.
In our 100th episode, Brian brings on longtime friend and colleague Colby DeRodeff to talk about past projects, the surge of threat intelligence, and Mandiant Security Validation’s rapid expansion within the market.
To commemorate the 99th episode, Brian brings on his two co-producers -- Daniel Craig and Katie Billigmeier -- to reminisce about the podcast's beginnings, how it's grown in the past three years, and each of their favorite episodes.
Devon Goforth has been with Mandiant Security Validation (formerly Verodin) since its early startup days in 2015, and had infused his background of electrical engineering, physics, and math with an interest in cyber security. He shares not only how the company and solutions have changed, but also current influences on the threat ecosystem, risks, and hacker trends.
Board members are not only crucial for helping lead a company in the right direction, but nowadays they also offer crucial cyber security guidance. And those with a legal background, like FireEye’s Alexa King, provide an even more valuable perspective in the event of a breach and help organizations mitigate risks as an organization evolves.
Having been a board member for technology and cyber security companies since the 90s, Matt Bigge has fine-tuned the art of being an effective board member. He and Brian discuss the evolution of a board member’s role as a company changes, adapting interactions with leadership, and some words of wisdom.
Our focus on board members continues as Kara Nortman, Managing Partner at Upfront Ventures and a board member with several technology and cyber security companies, talks about her key responsibilities as a cloud-native specialist, the importance of nurturing positive relationships, and the growing trend of third-party solutions.
The unknown factor of cyber security risk are keeping more CEOs up at night than ever before, and many of them view it as priority number one in areas of the business to address. Jay Leek brings his perspective as former Blackstone CISO, ClearSky Security co-founder, and board member for a number of cyber security companies, where he communicates today’s risk.
As someone who has worked as a FireEye executive and been on a board member for several publicly traded companies, Julie Cullivan has been able to closely witness the dichotomy between the two. She chats with Brian about how board members can influence real cyber security development.
To see the video version of this episode on YouTube, click here.
Former RSA President & CEO Art Coviello revisits the podcast to share his wisdom for CISOs and aspiring board members, and breaks down board interactions in the private and public space.
Working as a security leader at Kyriba, an international FinTech company, Eric Adams attributes a lot of success to automation – the key to developing and growing a business. He describes this and many more ways to optimize your assets, no matter how big or small.
When it comes down to cyber security in the Federal space, US Army Reserve Colonel Jerry Chappee likens it to working on a car: your first priority should be perfecting the basics. He talks with Brian about the evolution of cyber operations, building a leadership team, and addressing vulnerabilities.
Former NSA Chief Cryptologic Technician, Retired US Navy Chief, and author Chase Cunningham is so fascinated by cyber conflict that it inspired him to create a comic book series. He and Bryan talk about the nation state interaction in cyberspace, APTs, deepfakes, and more.
Nick Andersen’s perspective and strategy skills have evolved from his time in the Marine Corps and federal government. Now CISO of Public Sector at Lumen Technologies, he reflects on his experience overseeing cyber security for energy and emergency response, statewide threat intelligence, his day-to-day duties, and more.
Brian chats with Soluble Co-founder and CEO Richard Seiersen, who recently published his second book, The Metrics Manifesto: Confronting Security with Data. They talk security operations, digital transformation, and cybersecurity’s growing presence in executive meetings.
Brian speaks with Bill Crowell, who in his career has held Director roles in many organizations including the National Security Agency (NSA), about political ties to critical infrastructure, tension between CIOs and CISOs, and his recent projects.
National Cybersecurity Center CSO and Board Member Mark Weatherford joins Brian to discuss the world of MSSPs, what the CISO’s role should be in 2021, and our fast-growing dependence on the supply chain.
Chief Research Analyst and author Richard Stiennon joins the podcast again to discuss his new book, Security Yearbook 2020, in which he characterizes the modern evolving cyber security vendor and the market today.
Past podcast guest Kathleen Moriarty returns to share about her new book, Transforming Information Security, in which she declares that security currently is too complex. She and Brian discuss other topics explored, including privacy, encryption, automation, and trends.
Brian chats with Steven Edwards, Sr. SOC Manager at Globe Life (formerly Torchmark) about cybersecurity in the insurance and finance industry. Steven covers cloud migration, use cases and mistakes he’s learned from, and relaying security strategies to non-technical consumers and members of the board.
The aviation industry has arguably been the most negatively impacted by the pandemic and has forced sudden changes on the organizations’ business models, cyber security operations, and more. United Airlines’ VP and CISO Deneen DeFiore talks about how the aviation organizations have adapted, key measurements for effectiveness, and the secret to maintaining a strong security mindset in these uncertain times.
This packed episode focuses on all things high-level intelligence. Brian speaks with JD Jack, FireEye VP of DoD/IC/Special Programs, on his past experience with aviation and national intelligence and how it has taught him to lead at FireEye. They look at today's intel gaps, the DoD’s biggest threats, and discuss tool collaboration.
Widespread digitization has pushed sales-driven car dealerships to build more dedicated security teams. Air Force Space Command veteran Chip Regan and Brian talk about how his military experience has prepared him to become AutoNation’s newest CISO, prioritizing critical objectives, communicating with other executives, and data security.
Where compliance obligations and regulations are concerned, the insurance industry can look almost identical to finance. DJ Goldsworthy, Aflac’s Director of Security Ops and Threat Management, talks about the pressure to adapt to the changing security landscape, past SIEM experiences, and recent trends.
Auto Club Group CISO Gopal Padinjaruveetil loves to combine his passion for philosophy with cybersecurity and shares a fascinating prediction for IoT devices and the future for humans. He and Brian also discuss the meaning of maturity and cyber readiness, cyber economics, and the three basic types of security metrics.
In the time since Dave Bang appeared in 2018 as our first podcast guest, he’s pivoted his career at LyondellBasell from overseeing Information Technology (IT) to managing Operational Technology (OT). He and Brian cover IT vs. OT challenges, vendors’ perspectives on secure system environments, and using a streamlined approach to solve enterprise problems.
More organizations are keen to introduce purple teaming to their security practices but in most cases, they are not yet at the level of the business maturity needed to take that next step. Evan Pena, Director of Professional Services at Mandiant (FireEye), describes how his team uses FireEye’s premiere threat intelligence to enhance purple teaming efficiency.
Sallie Mae Sr. Director of Cybersecurity Operations Steve Lodin returns to the podcast to share his experiences introducing and maintaining cloud-based SIEM to existing infrastructure. He and Brian discuss the technicalities of transferring a mid-size financial organization to the cloud.
Sandra Joyce, FireEye SVP & Head of Global Intelligence, returns to talk with Brian about recent infamous hacker groups’ exploitation of COVID-19, why having more security tools damages your chance of surviving a breach, and gives insight into findings from the Mandiant Validation Security Effectiveness Report.
Brian chats with Dawn-Marie Hutchinson, Security Transformation Executive at global pharmaceutical company GSK, on persistent industry obstacles highlighted even more by the effects of COVID-19, addressing the global skills shortage, and perfecting your security tech stack.
Major General Earl Matthews, USAF (Ret) joins Brian on the Cybersecurity Effectiveness Podcast to discuss the latest hot topics in validation. They cover security for this year’s upcoming election and dive into the data recorded in Mandiant Validation’s 2020 Security Effectiveness Report, including that which inhibits organizations from garnering the most value from their existing products.
Visit https://www.verodin.com/podcasts/mandiant-security-effectiveness-report-takeaways-and-predictions to watch the full video.
Privacy affects all industries beyond just the obvious legal implications, and even after 20 years security vendors don’t spend enough time strengthening all factors involved. Rebecca Herold, CEO of The Privacy Professor discusses security and privacy mistakes that still pop up today, and how the education industry plays a part in data distribution.
For a computer science undergrad looking to start a cybersecurity career, good experience depends on a healthy balance between academia and extracurriculars. University of Tennessee student Julianne Cox tells Brian how she has developed her skills inside and outside of the classroom, and looks forward to increasing diversity as the next president of her school’s Women in Cyber Security (WiCS) chapter.
Although we tend to portray cybersecurity as black-and-white, good vs. bad, digital forensics and incident response investigations have revealed that it’s much more complicated. Brian chats with Cindy Murphy, President & Founder of Tetra Defense (formerly Gillware Digital Forensics), about her start in law enforcement, reacting to ransomware attackers, and the mindset of a business leader.
Security and compliance misinformation runs rampant – especially with thousands of products joining the market each year. How does a service provider cut through all that noise? Choice CyberSecurity co-founder and COO Alex Rutkovitz breaks down compliance misconceptions, separating value from product, risk assessment, and more.
Consumers may install the latest security feature on their device but perhaps the most important question is, do they know how to use it? Kyla Guru, high school senior and CEO & founder of Bits N’ Bytes Cybersecurity, deems user education a crucial aspect of security that is often overlooked in favor of the technology itself and shares how she built her own organization to empower tech users in their everyday lives.
Despite being only a couple of years old, the City of New York's cybersecurity program has quickly risen to become a model of success for cities all over the globe. Quiessence Phillips, the city’s Deputy CISO and Head of Threat Management, has spent her last few years there fortifying its SOC team. She and Brian talk “true ops” philosophy, playbook automation, and other secrets to success.
Generation Z kids have the benefit of growing up in a super-connected world with so much more available to them than other generations, but this can inhibit creativity and imagination down the road. Brian sits down with Paraben Corporation President & CEO Amber Schroader, to talk about the young new hires to digital forensics, cybercrimes in the cloud, and how her past culinary experience prepared her for her line of work.
Perspectives on what’s essential to developing your skills in cyber vary depending on who you ask. Some say it depends on certifications, others say experience is the key. Mari Galloway, CEO of Women’s Society of Cyberjutsu and Sr. Security Architect, discusses her motivations, recommended approach to education and certifications, and what she looks forward to in the rest of 2020.
In order to stand out as a brilliant startup in a sea of cybersecurity vendors, a few things should always be top-of-mind: a strong investor-entrepreneur relationship, awareness of other vendors, and a thorough understanding of the landscape. Roselle Safran, who is a founder & CEO of a stealth-mode startup herself, speaks to her experience with building a strong startup and offers advice for others seeking the same.
Security and e-discovery often work together closely but the key differences are subtle, with the latter being more focused on preserving evidence. Mary Mack, CEO of EDRM, elaborates on the work of those professionals, shares mistakes she’s seen and lessons learned, as well as organizations’ changing perspectives on data in the cloud.
To address the global cyber talent shortage, we must expand our outreach efforts to offer education to women and girls in third-world countries. Eileen Brewer travels to remote parts of the world equipped with a suitcase full of motherboards to teach computer workshops and inspire future engineers. She describes how listeners can get involved in similar programs and make a difference in helping to diversify the industry.
The lack of diversity in cybersecurity and technology in general is no secret, but it wasn’t always that way. Soviet-Era Russia and other eastern countries have seen more equality in certain industries, and that was a difference that guest Elena Elkina certainly noticed in her transition to American life. As Sr. Privacy & Data Protection Management Executive for Aleada Consulting, she discusses gender roles, seeking challenges, and starting her nonprofit and consulting startup.
There’s a reason why people get distracted by new tech or security solutions: what if it’s the silver bullet that solves everything with minimal effort? Unfortunately, that is seldom the case. Brian chats with Becky Pinkard, CISO of Aldermore Bank, PLC, about caution with buzzwords, sharing threat intelligence, and what lies ahead for security.
The number of company data breaches that make headlines on an almost daily basis will continue to skyrocket without signs of stopping if organizations neglect to take proper precautions to protect their assets. Dr. Chanel Suggs, known also as The Duchess of Cybersecurity, shares details of some of the latest shocking public breaches and how she stays on top of trends to help clients be better prepared and well-informed.
For gamers and users heavily dependent on high-traffic internet platforms, loss of service is destructive -- and can be symptomatic of a greater distributed denial-of-service (DDoS) attack. Charter Communications VP Mary Haynes goes in depth into its evolution over the years, tactics for mitigation, and how some gamers inadvertently end up worsening the situation.
Offensive work is all about constant improvement, upping your skills to outsmart the attackers. There are many organizations out there for learning but a relative few focus on supporting women in their endeavors. Lisa Jiggetts, Founder & President of the Women’s Society of Cyberjutsu, takes us through her passion for learning and sharing with others, addressing the cybersecurity talent shortage, and how she grew her organization to become the inclusive community it is today.
Security conferences are opportunities for security folk to come together, share experiences, and inspire one another while making new connections in the space. Kim Hakim, CEO & Founder of FutureCon, talks about her 20 years of experience hosting conferences, observing speakers’ trending topics, and the growing buzz around ransomware.
How private should personal data be? What are perspectives around who should be in control of it and can you actually get paid for your data? Brian and Monique Morrow, President of The VETRI Foundation, analyze the top data privacy threats in society today, the role of personal responsibility, and education resources.
It’s tough to know if your organization is really prepared for the aftermath of a cyber-attack, but who can offer you sound advice and planning for a strong recovery? That’s where the general counsel comes in – in-house lawyers, trusted advisors, and cybersecurity experts rolled into one. Alexa King, FireEye’s EVP, General Counsel, goes into detail about the roles she plays, how to plan effectively, and advising boards.
Most consumers today can learn how to use technology devices pretty quickly, but the security features used to protect them on it can often seem complicated and intimidating to the user. Former Ann Arbor county elected official and current CEO & President of Cybercrime Support Network Kristin Judge strives to help people feel confident in an “everyday” knowledge of security and provides resources for victims of cybercrime.
People love Capture the Flag (CTF) competitions for being an excellent way to put your hacking skills to the test – not only is it a lot of fun, but it forces you to use the skills you may learn in a classroom or course setting to real-world situations. Kaitlyn Bestenheider, analyst at Tevora, dives into her passion for cryptography and CTFs, core skills needed, and shares her advice for others looking to enter the field.
The number of paths available to explore cybersecurity are seemingly endless and many professionals have made the jump between industries at least once. Tammy Hawkins, on the other hand, challenged herself constantly throughout her career by learning to apply skills to industries like in agriculture, and finance. She takes listeners through her journey from IT analyst to her current role as Director of Service Technologies at Blizzard Entertainment, and how you can adapt your skills to succeed anywhere.
The current global industry talent shortage proves to be a tough challenge and while having impressive technical skills are important, showing skill in creative problem-solving and communication may put you above the rest. Join Brian and Lisa Plaggemier, CSO at MediaPRO, as they discuss a new perspective on training and awareness, the difference between training to solve a specific problem and thinking critically, and the secret to engaging your employees.
The amount of critical infrastructure security news has exploded in the past few years due to ongoing digitalization, which has caused an overall increase of dependence on IT. Isabel Muench, Head of Branch Critical Infrastructures at BSI, talks to Brian about weaving IT security into critical infrastructure and shares stories of successes and failures.
The Internet Engineering Task Force (IETF) is a large community of network designers, operators, vendors, and researchers passionate about the ever-evolving internet architecture. Security strategist, CISO, and board advisor Kathleen Moriarty chats with Brian about the fascinating research she’s done, her upcoming book, and recommendations for scaling threat intel.
An effective way to learn how to fix things in cybersecurity is to practice breaking them – once you’ve done that, you’re halfway there. Tiffany Strauchs Rad, CEO & Co-Founder of Anatrope, Inc. learned security skills like lock-picking and social engineering from her father, a former CIA agent and writer of the film Sneakers. She discusses her experience constructing a prison break zero-day, vulnerability research, and more.
Strong cybersecurity leadership is truly tested when the organization is breached and when it comes to recovering from the damage, the response and public handling of the situation is just as important as the attack itself. Brian meets with Siobhan Gorman, Partner at communications firm Brunswick Group and former Wall Street Journal correspondent, who provides listeners with key takeaways and lessons learned from incidents past.
Students pursuing a degree in cybersecurity or computer science at Tennessee Tech University gain experience from their extracurriculars just as much as academics. Dr. Ambareen Siraj, professor/director of its Cybersecurity Education Research and Outreach Center (CEROC), discusses her approach to student education, her classes’ research projects, and how they reach out to teach others in the community.
Nowadays, fraud prevention and cybersecurity go hand-in-hand. In order for financial services to succeed and thoroughly protect themselves, they must adapt and strategize according to open banking regulations. Brian talks with independent cybersecurity advisor Neira Jones about what this means for institutions of all sizes and their competitors.
Humans are often deemed the “weakest link” in security, and if organizations maintain that attitude with their employees then nothing will change. An encouraging and positive company culture can turn them into the most powerful weapon. Masha Sedova, co-founder of Elevate Security, takes listeners through the ways they can foster a more people-centered security approach for better results.
When looking at the cyber industry from a journalist’s perspective and analyzing trends and transformations over time, much can be revealed. Dark Reading Executive Editor Kelly Jackson Higgins has been observing the industry for almost 15 years and has seen the most challenging issues from the consumer and organizational sides. She recalls some of the biggest turning points in the industry’s past and areas still in desperate need for improvement.
Some form of modern technology can be found in almost every part of the world now, but some areas that lag behind may not have the resources needed to implement necessary security tools. Having grown up in the Argentinian mountains where there are few computers, Veronica Valero Sarachos, researcher at Czech Technical University, recognizes these issues and strives to give back to communities like hers by working with them to help detect threats.
Human perception and how we process thought can make all the difference in understanding and predicting attacks. Cybersecurity expert Anita D’Amico, founder and CEO of CodeDX, uses her background in clinical psychology to lead a career conducting research studying decision-making, how human factors affect vulnerabilities, and how perception determines a specific response to an attack.
Threat models have grown to enormous complexity since the boot virus days and show no signs of slowing down. How does this affect cybersecurity at the workplace and at home? Brian talks with Lysa Myers, Security Researcher at ESET, and gets her take on adapting research, tools, and specialization to keep up with the fast pace.
No one’s path to finding a career in cybersecurity is the same, but most can agree that it all starts with education, whether formal or informal. Podcast guest Dr. Meg Layton, Director of Engineering/Cyber Security Services at Symantec, finds her passion in helping others discover their own cyber path and effectively translate their technical skills to aspects of the business.
Headline-worthy breaches seem to be hitting organizations far too often, causing organizations to second-guess their current security controls and procedures. While it’s a good thing to make sure you’re prepared, Heather Engel, Managing Partner at Strategic Cyber Partners, recommends assessing the situation from a risk perspective. She and Brian talk about cybersecurity measures as crucial to the organization as a whole, how to evaluate types of risk, and the art of managing it.
Patient safety is always top-of-mind for healthcare organizations and while the world has seen magnificent strides in the form of medical technology, maintaining security standards is now more important than ever. Marie Moe, Sr. Security Consultant at mnemonic and professor at NTNU, has dealt with the repercussions first hand. She shares a personal story about how poor encryption and security practices affected her own pacemaker device and advocates for further movement toward software security standards in medical devices.
The history of human warfare tells us that the recipe for victory is often a concoction of technology, strategy, and intelligence. Today’s guest, Sandra Joyce, is the SVP of FireEye, the world’s largest non-government cyber intelligence organization. She and Brian discuss significant trends, what to consider before publishing hard-earned intel, and the cleverest adversary tactics to date.
Awareness for mental health has risen to record heights over the past few years but it is still fairly slow in reaching the cybersecurity industry. Even in an exciting career, long work hours, a seemingly constant sense of urgency, and often high dependency on certain roles can be a cause of extreme stress if not well managed. Rick McElroy, Head of Security Strategy at Carbon Black, advocates for mental health resources within the workplace and emphasizes the importance of unplugging, exploring hobbies, and finding your support tribe.
The threat landscape is a mighty beast in and of itself -- vast and, perhaps more importantly, constantly changing. In this episode, Brian chats with industry thought leader John Pironti about using threat and security models to consistently monitor landscapes, test scenarios, and why you should prioritize risk management.
A thorough understanding of the core fundamental principles is critical for those building a career in cybersecurity. Adam Fletcher, CISO at Blackstone, argues that cloud security now falls into that list -- goals like developing a policy or translating a tool to cloud requires extensive knowledge, experience, and leadership skills. He and Brian discuss case-by-case scenarios and how to expand and develop your team given the industry-wide talent shortage.
Cloud security continues to attract more organizations seeking for better storage, but the prospect of data leakage hold some back from joining the bandwagon. Steve Lodin, Sr. Director of Cyber Operations at Sallie Mae, shares his “golden rules” for introducing it to your organization, advice for a bullet-proof migration, and lessons learned from decades of working in corporate security.
Today’s teens interact daily with technology more than ever before. Ease of access to the online world for things such as streaming, social media, and shopping comes with the big responsibility to develop smart computer habits early in life. This episode features the series’ youngest guest to date: seventh-grader Athena Contos, who shares personal examples of cyber carelessness, foundational tips for building good habits, and more.
In many ways, cybersecurity is the same way it once was over 20 years ago in terms of risk, only with different devices, activities, and added ways of access. Parry Aftab, who was one of the world’s first cyber lawyers back in the early 90s, shares her work with multiple cyber safety organizations, tips on supporting kids who fall victim to cyberbullying, and being featured in a custom cyber safety Marvel comic.
Modern planes have come a very long way since the first commercial flight in 1914. Approximately 87,000 flights travel across the US every day, carrying passengers who expect the same level of device connectivity and as they get on the ground. Deneen DeFiore, SVP & CSO at GE Aviation, stresses the importance of maintaining customer trust and business reputation through diligence in cyber assurance and safety operations.
With all the categories defining the healthcare industry today (e.g. pharmaceuticals, providers, hospitals, etc) and sensitive data flowing between them, it can be hard to know where to start. How do we keep information secure, yet accessible to our doctors and providers? Colby DeRodeff, CTO at Verodin, shares a bit about security in the healthcare community, how far we’ve come, and where we should go from here.
Since 2011, GridEx has been a hub for security lovers to evaluate and hone their red, blue, and purple teaming skills with challenging scenarios. In this episode, Brian Contos and Michael Allgeier, Director of Critical Infrastructure Security at The Electric Reliability Council of Texas (ERCOT), comment on the appeal and value these interactive training sessions can offer major power corporations.
Cyber criminals know that the toughest of problems can be quickly solved if you work together–and especially when pulling knowledge from a collective pool of resources. What role do solutions such as encryption and SSO play against a team of hackers dedicated to stealing your data? Brian chats with Jon Inns, co-founder and CEO of Threat Status, about corporate password habits, the dark web, and surprising scam victims.
Nowadays, adversary tactics like spear-phishing are proving to be more sophisticated and deceptive than ever. Mike Fabrico’s career includes notable accomplishments as security specialist at NASDAQ and Senior Director at TrapX Security, the world leader in cyber deception technology. He breaks down deception as a strategy—not just a tool—to provide organizations with the ability to turn the tables on their opponents. And it’s much simpler than you think.
As CISO of the State of Vermont, Nick Andersen is involved in everything from healthcare to emergency management to academia. He and Brian dive into the crucial priorities, differences between protecting state and business data, and establishing third-party relationships to neutralize risk.
Richard Stiennon, serial author, industry expert, and Chief Research Analyst at IT-Harvest, recaps the short timeline of quality assurance in manufacturing and argues for the same approach it to cybersecurity as a core function of the business. Do investors and CISOs aligning their digital strategies accordingly and where exactly does ownership lie if, and when, the unexpected happens?
Amazing new developments in machine learning and artificial intelligence automate testing, reporting, and workflow. However, Lisa Huff, VP of NA Pre-Sales Engineering at Exabeam, explains its true value as a tool – not a catch-all solution. She and Brian talk customer success, newly introduced security roles, and more.
Mark Weatherford, Global Information Security Strategist at Booking Holdings and former CISO of the State of California and Colorado, has over twenty years of executive-level leadership experience in some of the world’s most important organizations. He and Brian Contos discuss misconceptions of cloud security, issues in the supply chain, and evaluating all areas of your cybersecurity environment.
Seasoned cybersecurity veteran Richard Seiersen, former SVP & CISO at LendingClub and current CEO & Co-Founder of Soluble.ai, attributes success in any career to two things: metrics and measurement. He shares his contagious passion for security, the qualities of top engineers, his latest book, and more.
Brian Contos chats with Ed Amoroso, former SVP and CSO of AT&T and current CEO of TAG Cyber LLC, about priorities and advice for building a top-notch security team. From Ed’s perspective, decision-making board members must be equipped with continuous data and have instincts that come from experience, but that can be a challenging balance to find.
As CISO for Ohio State University, Helen Patton has an acute vision for students and professors who are passionate about cybersecurity. While undergraduate university programs are succeeding in many areas, they are hindered by a lack of structure and guidance from the industry as a whole. She explains how to create a valuable student internship experience that offers diverse and relevant practical experience.
Sometimes the most interesting careers emerge from the remnants of another passion. MacKenzie Brown describes how her love of theatre led her to her current work with incident response (IR) and becoming co-founder of the Ms. Greyhat Organization. She and Brian Contos talk proactivity, cracking down on communication, and key focus points for response teams.
According to Terry Ray, SVP and Fellow at Imperva (previously Chief Technology Officer), practices and safety around data privacy and the cloud, though slowly improving, still leave much to be desired. He and Brian Contos discuss the concept of absolute security and why businesses benefit more from calculating acceptable risk based on their unique critical assets.
Host Brian Contos sits down with cybersecurity veteran William (Bill) Crowell, former Deputy Director of the NSA and current partner at Alsop-Louie Partners, to get a picture of the major threat landscape changes over the past 15 years. While phishing attacks, advanced persistent threats (APTs), and breach monetization become more sophisticated each day, CIOs and board members must turn their focus to implementing proper network segmentation.
In a security professional’s career, a nearly perfect success rate can be quickly and detrimentally tarnished by one mistake that puts the company at risk. Raj Samani, Fellow and Chief Scientist at McAfee, shares his professional journey and explains how his choices have reflected who he is as a mentor, peer, father, husband, and author, encouraging listeners to appreciate what they have now.
While appealing new gadgets and innovative products continue to hit the market, legal firms caution organizations about the risks within IoT devices. Technology-focused trial litigator IJay Palansky forecasts the impending boom of cyber litigation in the coming years and his recommendations for avoiding the costly consequences of a data breach.
The industry-wide talent shortage makes it challenging to attract and retain top cybersecurity talent — analysts often operate understaffed and overwhelmed by the ever-growing volume of alerts to sort through. Kevin Morrison, CISO at PulteGroup, Inc. examines his culture-centric approach to structuring cybersecurity staff, maximizing skill-set efficiencies, and aligning the success of his program to core business objectives.
The Cybersecurity Effectiveness Podcast is kicking off the New Year with a forward-thinking episode featuring JASK CEO and Co-Founder Greg Martin. Hear his predictions about the key cybersecurity challenges that organizations will be facing in 2019. Learn about the ground-breaking developments in AI and SOC automation enabling security teams to combat the rising sophistication of cyber attacks at a super-human level.
Security analyst and outdoors enthusiast Tim Waldo examines the lingering effects of malware attacks like WannaCry in the healthcare sector and exposes disturbing trends that are putting patient data at risk to future outbreaks. Tim offers precise steps that organizations can take to dramatically improve the technologies and policies safeguarding sensitive information.
In this episode, host Brian Contos reconnects with an old friend and colleague, Dr. Ulf Lindqvist, who is the Senior Technical Director of SRI International’s Computer Science Laboratory. Ulf reflects on some of SRI’s most notable technology accomplishments, elaborates on the security industry movement spurred from past work with Logic Group, and predicts the future of IoT devices.
Cylance Chief Security and Trust Officer Malcolm Harkins reflects on his core leadership philosophies and the processes he implements to cultivate a professional culture of excellence. Malcolm’s background in economics and finance offers a unique perspective on the cybersecurity landscape. He walks us through his transition from working as the Chief Security & Privacy Officer at the multinational corporation, Intel, to joining the cutting-edge cybersecurity start-up, Cylance.
Brian Contos straps in with Dave Ockwell-Jenner of SITA, the world's leading air transport IT and communications specialist. Having worked in IT and aviation for about 25 years, Dave explains what makes the air transportation industry unique, perspectives that executives have toward cybersecurity, and the challenges and opportunities that analysts face as they navigate today’s threats.
In the spirit of Ada Lovelace Day coming up on October 9th, host Brian Contos chats with Verodin security analyst Ashley Zaya about her role on the Behavior Research Team (BRT) and the perspective she brings to the industry. Ashley reflects on her career in InfoSec thus far and the experiences she gained working in Boeing's fast-paced SOC. Ashley also shares valuable advice for women entering the field and one of her favorite movie soundtracks jam out to.
What do you get when you combine a surging demand for cybersecurity experts with one of the largest plastics, chemicals, and refining companies in the world? In this first episode of the Cybersecurity Effectiveness Podcast, host Brian Contos sits down with Dave Bang, the man in charge of IT Security Architecture at a multi-national chemical company, and gets his take on the industry’s attitude toward prioritizing security, current processes, and personal experience with their team in ensuring success.